A supplier packet lands on your desk with a certificate on top. Most buyers check two things: the logo and the standard number. Both can be real and still cover nothing you actually buy.
The two fields that decide coverage usually get skipped. The date. The scope.
A system certificate speaks to how a factory is run. A product certification speaks to one product, against one standard, at one time. Different documents.
Different coverage. The gap between them is where your defence breaks.
Before you file a certificate, find the sentence that says what it covers.
Our own documentation history makes the distinction concrete. Hebei Junze was established in 1991. On 9 December 2002 the 3.2 mm hydraulic brake hose was tested at the Tianjin Automotive Inspection and Testing Center, and on 23 December that year it was evaluated by the China Automotive Product Appraisal Center, which issued the Automotive Product Appraisal Certificate.
That is a product certification: one product, one date, one testing body. National automobile CCC (3C) mandatory safety certification followed. Ministry of Transport certification was obtained in 2005 and again in 2007.
The CQC16-491284-2018 quality management system keeps each hose in line with GB16897-2010 and SAE J1401. Separately, the company holds TS16949 and ISO9001.
Read that list again. Notice how many entries are product-specific and dated, and how few are general.
Sort any supplier packet into three types. A management system certificate - ISO9001, TS16949 - claims a process exists across the organisation. It does not name your SKU.
A product certification names a product and a standard, and carries a date. That is why a 2002 appraisal for a 3.2 mm hose tells you about that hose, not automatically about a 4.8 mm line.
A test report speaks to a batch, and only to the batch it names.
A packet with all three is not redundant. Each closes a different question. The audit question is never "do you have certificates." It is "which of these three is this one."
When a supplier sends a certificate, ask for: (1) the scope statement - the exact products and standards listed, not a summary; (2) the issuing body and whether it is a testing centre, a certification body, or a customer own audit; (3) validity - issue date, expiry, and whether it has been maintained since; (4) the product list, checked line by line against the SKUs you actually buy.
Ask your supplier for scope statements rather than certificate images, per-SKU documentation, and batch test reports that reference the standard the product is tested against.
Four questions convert a PDF into something you can defend in a meeting.
It should not say "certified" without naming the standard and the product. Red flag: a logo with no scope line.
It should not carry one date for a whole product family. Red flag: a single appraisal used to cover sizes it never named.
It should not cite a system standard as product approval. Red flag: ISO9001 offered as proof of a hose test result.
It should not expire unnoticed. Red flag: no renewal record since the original issue.
It should not arrive without the batch report for the shipment it accompanies. Red flag: the certificate is current but the batch is unaccounted for.
Reviewing a supplier documentation pack or building your own? Send us the SKUs you buy and we will return the scope statements and batch reports that sit behind them.