A defective product rarely begins with a single bad decision. Before reaching a customer, it may pass through designers, component suppliers, manufacturers, testing laboratories, importers, distributors, warehouses, retailers and online marketplaces. Each participant makes decisions about specification, materials, testing, certification, storage, labelling, traceability and sale. Product safety is therefore the accumulated result of a supply chain’s choices, controls and omissions, spread across many hands, rather than the responsibility of one factory acting alone.
Commercial distance does not eliminate responsibility. Government guidance makes it clear that organisations that manufacture, import, distribute, or sell consumer products in the UK all carry product-safety responsibilities. Manufacturers and importers must demonstrate compliance and support traceability, while sellers must not supply products they know, or should have known, are unsafe. Once products reach the market, monitoring complaints, incidents, and emerging risks becomes part of responsible supply chain management rather than an optional quality exercise.
The central question is therefore not simply who manufactured the defective item, but who had the opportunity to prevent, detect or control the risk. A purchaser may specify the product; a component supplier may introduce the defect; an importer may admit it to the market; a retailer may receive the first complaints. When products fail, liability may follow several paths simultaneously, making product safety a shared commercial, regulatory and legal responsibility across the supply chain.
Introduction — Unsafe by Design
Product safety is no longer a question confined to engineers inspecting a finished item before it leaves a factory. Modern products are assembled through international networks of designers, component manufacturers, importers, logistics providers and retailers, each capable of creating or amplifying risk. OPSS, now part of the Department for Business, Innovation, Science and Trade after the July 2026 departmental merger, estimated that businesses within its regulatory scope generated about £525 billion of turnover in 2025.
The risk is equally visible in enforcement data. During 2025-26, the UK Product Safety Database received 2,396 notifications covering 3,368 products. Of those notifications, 563 were recorded as serious risk and 259 as high risk. Fire accounted for 424 reported harm classifications, electric shock for 226 and injuries for 194. These figures are not estimates of national prevalence, but they demonstrate the breadth and persistence of unsafe or non-compliant products still reaching the market.
A product may be legally compliant when first supplied yet become hazardous through deterioration, improper maintenance, modification, counterfeit replacement parts or software changes. Conversely, an apparently well-made item may have been unsafe from the outset because a foreseeable use was overlooked, a warning was inadequate or a component failed under realistic conditions. Safety, therefore, involves design, sourcing, manufacture, conformity assessment, distribution, information, traceability, and post-market monitoring, rather than a single quality-control checkpoint.
Whirlpool’s tumble-dryer programme remains the clearest illustration of how a technical defect becomes a supply-chain and governance problem. Parliamentary evidence recorded 5.3 million affected machines manufactured for the UK market and at least 750 fires linked to the lint-related fault. In 2019, OPSS informed Whirlpool that it intended to serve a Recall Notice, after which the company recalled unmodified machines already in homes. Product safety is consequently a lifecycle obligation, not simply a factory-gate test.
What Makes a Product Unsafe?
Unsafe products arise through different failure mechanisms, and the distinction matters because it influences evidence, accountability and corrective action. A design defect may affect every unit produced; a manufacturing defect may concern one batch. Component failures can originate several tiers upstream, while contamination may occur during production, packaging, storage or transport. Investigation therefore begins by asking not merely what failed, but when, where and through whose process the hazard entered the product.
Design safety requires consideration of foreseeable behaviour, not merely ideal use. The General Product Safety Regulations 2005 require consumer products in Great Britain to be safe under normal or reasonably foreseeable conditions of use. That reaches beyond compliance with instructions: children may access battery compartments, users may overheat appliances, furniture may be climbed upon, and equipment may be assembled imperfectly. A warning cannot automatically cure a design that exposes users to an avoidable, foreseeable hazard.
CASE STUDY Manufacturing variation creates a different problem, because materials may be substituted, tolerances may drift, welds may weaken, or sterilisation may fail despite an adequate original design. The 2025 High Court dispute involving PPE supplier Medpro is an unusually clear public-sector example: the Department of Health and Social Care had paid £121,999,219.20 for surgical gowns, and the court found breaches concerning validated sterility, EN 556-1 compliance and CE marking. |
The court in that case awarded the full contract value as damages, but it also rejected DHSC’s separate £8,648,691 storage-cost claim because the supporting evidence was inadequate. The judgment shows why certification and paperwork cannot be separated from physical performance: the gowns were intended as sterile medical devices, yet testing and evidential analysis became central to determining whether the contracted product had actually been supplied. Safety failures can therefore generate two distinct battles.
Warnings and instructions form part of safety because users cannot manage risks they have not been told about. The issue is especially acute where hazards are hidden, cumulative or counter-intuitive. In 2025-26, choking accounted for 142 Product Safety Database harm classifications and chemical risks for 145. A child-resistant enclosure, clear age restriction or adequate hazard warning may therefore be as safety-critical as the material from which a product is actually made.
Digital functionality further destabilises the idea of a finished product. Connected devices can acquire new features after sale, while software faults may alter charging, temperature control, braking, sensing or automated decision-making. The Product Security and Telecommunications Infrastructure Act 2022 already imposes continuing compliance duties on manufacturers, importers and distributors of relevant connectable products. Product safety increasingly has to accommodate physical components whose real-world behaviour is partly governed by code that can change after purchase.
From Factory to Consumer — The Product Safety Chain
Product safety responsibilities begin with the manufacturer, which normally controls design, production and initial conformity assessment. Yet the finished product may incorporate batteries, electronic boards, chemicals, fasteners, packaging and software supplied by others, and each input can introduce a latent defect. Effective control, therefore, depends on approved specifications, supplier qualification, incoming inspection, change management, and traceability, so a manufacturer cannot safely treat component purchasing as a purely commercial exercise divorced from engineering risk.
Importers occupy an important position because they introduce products from outside the relevant market into the domestic supply chain. Government guidance stresses that businesses bringing goods into Great Britain from the EU may now be importers rather than distributors, carrying additional compliance responsibilities they may not have anticipated. Import status can therefore change legal exposure without changing the physical activity of buying and reselling, so procurement teams need to understand where legal responsibility attaches.
Distributors and retailers are not passive conduits. Under the General Product Safety Regulations 2005, distributors must act with due care, avoid supplying products they know or should presume to be dangerous, retain traceability documentation, and cooperate with producers and enforcement authorities. OPSS guidance likewise states that businesses selling consumer products must not sell products they know, or should have known, are unsafe. Commercial distance from the factory does not create regulatory distance from the hazard.
Fulfilment providers, warehouses and online marketplaces further complicate the chain because physical possession, contractual sale and digital presentation can reside with different organisations. In 2025-26, the removal of an online listing was recorded 594 times as a corrective action in the Product Safety Database, while 1,102 corrective actions involved the rejection of imports at the border. Product-safety interventions increasingly occur before, during and after conventional retail distribution rather than only at the point of manufacture.
The modern chain therefore operates as a sequence of safety gates rather than a simple manufacturer-to-retailer pipeline. Designers control foreseeable hazards; component suppliers control inputs; manufacturers integrate them; importers verify market entry; distributors preserve compliance; retailers face consumers; and marketplaces influence access to buyers. When any one gate fails, the next economic actor may still possess information, control or legal duties capable of preventing harm before the product ever reaches its user.
One Product, Many Potentially Responsible Parties
A single incident can engage several forms of responsibility at once. The manufacturer may face strict product-liability exposure; an importer may have regulatory duties; a retailer may owe contractual rights to the purchaser; and another participant may be liable in negligence. Those routes are not mutually exclusive, so the injured person, enforcement authority, insurer, purchaser and organisations within the supply chain may each pursue different remedies arising from the same defect.
The Consumer Protection Act 1987 illustrates that breadth in Great Britain. Liability can attach to the producer, an own-brand holder that holds itself out as producer, and qualifying importers; a supplier can become liable in specified circumstances if it fails to identify the relevant producer or supplier after a proper request. Northern Ireland has parallel provisions under the Consumer Protection (Northern Ireland) Order 1987, so identifying the contracting seller alone can miss legally significant parties.
Hastings v Finsbury Orthopaedics Ltd and Stryker UK Ltd demonstrates how componentised products complicate attribution. The claimant’s metal-on-metal hip replacement combined components manufactured by separate respondents, and the Supreme Court considered whether the resulting prosthesis was defective under the 1987 Act. The claim ultimately failed on defect, but the litigation shows how complex assemblies can simultaneously place component design, system interaction, clinical evidence, and producer responsibility before the court.
Commercial contracts then redistribute the financial consequences behind statutory liability. A retailer may compensate a consumer and seek recovery from its supplier; an importer may rely on warranties from an overseas manufacturer; insurers may exercise subrogation rights; and contribution claims may arise between defendants. Contractual indemnities can allocate costs between organisations, but they do not eliminate statutory duties to consumers or regulators, so product safety creates a network of liabilities rather than a single upstream line.
The UK Product Safety Framework
A single code does not govern UK product safety. In Great Britain, the General Product Safety Regulations 2005 set a baseline for consumer products, requiring them to be safe in normal or reasonably foreseeable use, while product-specific legislation applies where relevant. OPSS lists regimes covering areas such as toys, electrical equipment, machinery, gas appliances, cosmetics, fireworks, and personal protective equipment, resulting in an overlapping architecture in which a product’s classification determines the applicable duties.
Northern Ireland now follows a different general regime. Since 13 December 2024, Regulation (EU) 2023/988 on general product safety has applied there, replacing the 2005 Regulations for general product safety. Sector-specific EU rules also continue to operate where applicable under the Windsor Framework. A product sold throughout the United Kingdom may therefore face different regulatory routes in Great Britain and Northern Ireland, even though commercial teams may treat the UK as one sales territory.
Responsibility is also divided institutionally. OPSS, part of the Department for Business, Innovation, Science and Trade since the July 2026 merger, remains the national regulator for most consumer goods and construction products, while local Trading Standards authorities retain market-surveillance functions. The Food Standards Agency regulates food; the MHRA regulates medicines and medical devices; the DVSA oversees vehicle safety; and the Health and Safety Executive regulates workplace products.
That regulatory footprint is easier to grasp in scale. OPSS estimated 306,890 businesses were within its regulatory scope in 2025, representing about 11% of the UK business population and generating the £525 billion combined turnover already noted, while construction products, also enforced by OPSS, represented a further £109 billion market. Product regulation is consequently not a specialist concern at the margins of commerce: it governs supply chains carrying hundreds of billions of pounds.
Enforcement is correspondingly varied. Authorities can investigate, inspect goods, obtain technical documents and use measures including suspension, withdrawal, recall and prosecution, depending on the governing legislation. The 2025-26 Product Safety Database recorded at least one corrective action for 2,072 of 3,368 notified products, with recorded actions including 611 destructions, 479 recalls from end users and 429 seizures. These figures show that non-compliance can lead directly to stock loss, operational disruption and customer remediation.
The framework is also in transition. The Product Regulation and Metrology Act 2025 created broad powers for modernised secondary legislation, while Government consultations published in March 2026 proposed a new core product-safety framework and consolidated market-surveillance approach. Those proposals were still proposals in September 2026, not a wholesale replacement already in force. Organisations must therefore comply with current legislation while preparing for a regulatory model built around clearer supply-chain accountability and modern products.
The Consumer Protection Act 1987 — Strict Product Liability
Part I of the Consumer Protection Act 1987 establishes the principal statutory product-liability regime for Great Britain. It imposes strict liability: the claimant need not prove the producer’s negligence, but must still establish a defect, damage and causation. Northern Ireland uses the parallel Consumer Protection (Northern Ireland) Order 1987; the new EU Product Liability Directive will apply to relevant Northern Ireland products placed on the market or put into service after 9 December 2026.
Under the 1987 Act, a product is defective when its safety is not such as persons generally are entitled to expect, taking all the circumstances into account. That is not the same as asking whether the product could have been safer or whether an adverse event occurred. The courts assess the safety expected from the product in context, including its presentation, reasonably expected use and the time at which it was supplied to the market.
Liability can extend well beyond the physical manufacturer. The Act covers producers, organisations presenting themselves as producers through their name or trade mark, and qualifying importers; suppliers may also face liability if, after a proper request, they fail to identify an appropriate producer or upstream supplier within a reasonable period. That structure matters most for private-label sourcing, where the commercial brand visible to the customer may differ entirely from the factory that manufactured the goods.
Recoverable damage under the statutory regime includes death and personal injury, together with qualifying damage to property intended for private use or consumption. A £275 threshold applies to property damage, and the defective product itself is not treated as compensable property damage. The regime is therefore not a general warranty scheme: it compensates specified harm caused by defective products, while purely commercial loss is usually pursued through contract, negligence or other legal routes instead.
The Supreme Court’s 2022 decision in Hastings v Finsbury Orthopaedics and Stryker UK underlines the point. Mr Hastings alleged that a metal-on-metal hip prosthesis was defective, but the courts rejected the claim because statistical evidence did not establish a defect, and inherent risk did not automatically make it defective. Strict liability removes the need to prove fault; it does not remove the claimant’s burden of proving that the statutory safety standard was not met.
Negligence — When Reasonable Care Is Not Enough
Negligence remains important where the facts concern careless design, manufacture, testing, warning or distribution. Unlike statutory strict liability, negligence requires proof of fault: a duty of care, breach of that duty, causation and legally recoverable damage. The claimant must show that the defendant failed to exercise the standard of reasonable care expected in the circumstances. Good intentions, internal procedures and regulatory certificates may all be evidence, but none automatically proves reasonable care.
The foundation remains Donoghue v Stevenson, decided by the House of Lords in 1932 after Mrs Donoghue alleged illness from ginger beer containing a decomposed snail. The manufacturer had no contract with her, yet the case established that a manufacturer could owe a duty to the ultimate consumer. Nearly a century later, the principle still matters whenever an injured person needs to look beyond the immediate seller to the organisation whose conduct created the danger.
Reasonable care is dynamic because the precautions expected depend on foreseeable risk, technical knowledge and the seriousness of potential harm. A supplier of decorative goods may require different controls from a manufacturer of medical devices, lifting equipment or children’s products. As knowledge evolves, continued reliance on an outdated test report or a historical design assumption may become unreasonable, so post-market complaints, near misses and regulator alerts can affect what a responsible organisation should investigate.
Negligence can coexist with contractual and statutory claims arising from the same facts. A defective component may trigger a consumer claim against a retailer, strict liability against a producer and negligence allegations against a designer or manufacturer. The claimant must prove that the breach caused the loss, while defendants may dispute alternative causes, misuse or later modification. Product-safety records should therefore demonstrate the compliance, reasoning and testing decisions that show reasonable care throughout the lifecycle.
Contractual Liability for Unsafe Products
Contract law operates alongside product-safety regulation by asking whether the seller supplied what was actually promised. In consumer sales, the Consumer Rights Act 2015 requires goods to be of satisfactory quality, fit for purpose and as described; safety is expressly an aspect of satisfactory quality. Consumers normally have a 30-day short-term right to reject non-conforming goods. These rights focus on the trader-consumer relationship, even where the underlying defect originated much further upstream.
Business-to-business sales are commonly governed by the Sale of Goods Act 1979 together with the parties’ own negotiated terms. Implied obligations concerning satisfactory quality and fitness may apply, but commercial contracts often include detailed specifications, inspection rights, warranties, acceptance procedures and remedies. For public authorities and large private purchasers, those express provisions can be decisive because they define the exact performance purchased and the evidence required when goods fail testing, certification or operational use.
The PPE Medpro litigation shows the financial significance of precise drafting. DHSC paid £121,999,219.20 for 25 million surgical gowns at £4.88 each. The High Court found breaches concerning a validated sterility process, EN 556-1 and CE marking. Although DHSC had not effectively rejected the gowns within the contractual machinery, it recovered the full contract value as damages because the goods could not perform the sterile-gown function for which they had been purchased.
The same judgment also demonstrates that winning on breach does not guarantee recovery of every claimed cost. DHSC sought £8,648,691 for storage between February 2021 and June 2024, but the court rejected that element on the ground that the evidential foundation was inadequate. Contract management therefore matters after a safety failure as much as before: storage invoices, disposal records, testing costs, replacement purchases, and mitigation decisions may all need to withstand detailed scrutiny years later.
Specifications should translate safety expectations into measurable contractual obligations. References to legislation and standards are useful, but purchasers may also need defined materials, prohibited substitutions, approved factories, testing protocols, sampling levels, certificates, traceability fields and notification duties. A broad promise to supply “compliant” goods can leave avoidable arguments about what compliance actually requires. Strong procurement documents connect the technical specification, quality plan, acceptance criteria and remedies so safety requirements remain enforceable throughout performance.
Contractual remedies also sit behind consumer-facing obligations. A retailer that refunds customers may seek reimbursement from its distributor; an importer may claim against an overseas manufacturer; and a public authority may pursue damages where supplied goods cannot safely perform their intended function. Indemnities, insurance requirements and liability caps influence where the financial burden ultimately rests. However, none permits a party to contract out of regulatory obligations or eliminate rights that legislation makes non-excludable.
Regulatory Liability Versus Civil Liability
Regulatory enforcement and civil liability answer different questions. A regulator asks whether legal safety requirements have been breached and what intervention is needed to protect the market; an injured person or purchaser asks whether compensation or another private remedy is available. The same facts can support both processes, but neither automatically determines the other: a recall may occur without personal-injury litigation, while a claimant may recover damages even though no regulator has prosecuted anyone.
Regulatory tools are designed primarily to stop risk. Depending on the legislation, authorities may suspend supply, prohibit placing a product on the market, require warnings, order withdrawal or recall, seize goods and prosecute offences. During 2025-26, the Product Safety Database recorded 3,986 corrective actions, including 1,102 border rejections, 611 destructions, 594 online listing removals and 479 recalls from end users, so one unsafe product can trigger intervention at several points at once.
Criminal enforcement can add direct financial and reputational consequences. In March 2024, Diva Gift Limited was sentenced after pleading guilty to supplying a toy that failed essential safety requirements. Northampton Magistrates’ Court imposed a £10,000 fine, £4,393.16 costs and a £2,000 victim surcharge, totalling £16,393.16. The figures are modest compared with a major recall, yet the case shows that documentary or design failures can move into formal prosecution.
Civil claims focus instead on loss suffered by particular claimants. Depending on the facts, compensation may be pursued through strict product liability, negligence, contract or specialist statutory causes of action, and the measure of loss may include personal injury, property damage, replacement costs or contractual losses, subject to the rules governing each cause of action. Insurance may fund defence or settlement, but regulatory compliance and civil exposure remain legally distinct and must be managed separately.
Organisations therefore need two response tracks after a serious incident. The safety team must assess risk, notifications, containment and corrective action; the legal and commercial teams must preserve evidence and analyse claims, contracts, insurance and potential recovery against suppliers. Communications must support both tracks without delaying urgent protection of users. Treating a recall solely as litigation can endanger consumers, while treating it solely as an operational problem can destroy evidence needed to defend substantial losses.
Proving That a Product Was Defective
Product-liability disputes turn on evidence. The claimant must identify the product, establish the alleged defect, prove legally recognised damage and connect that damage causally to the defect. Serial numbers, batch codes, purchase records, photographs, retained samples and incident reports may determine whether the correct product can even be examined. Where the item has been destroyed, repaired or altered, contemporaneous evidence matters because later testing may no longer reproduce its original condition.
Technical evidence requires more than showing that an accident occurred. Engineers may examine design tolerances, fracture surfaces, electrical protection, thermal behaviour or foreseeable loading; laboratories may test composition, contamination or sterility; clinicians may analyse biological causation. In A v National Blood Authority, claims concerning hepatitis C-infected blood required the High Court to assess defect by reference to the safety persons were entitled to expect, keeping scientific evidence and the legal test carefully distinct.
The metal-on-metal hip litigation provides another warning against treating adverse outcomes as proof of defect. In Gee v DePuy International, six lead claims were selected from group litigation concerning Pinnacle hip prostheses, and extensive expert evidence addressed metal wear, revision rates and biological response. The court emphasised that the statutory inquiry concerns the product’s objectively assessed safety, not simply whether it contained a flaw or a claimant was injured after receiving it.
Defences, Causation and Contributory Factors
Strict product liability is not absolute liability. Section 4 of the Consumer Protection Act 1987 gives defendants specific statutory defences, including that the defect resulted from compliance with a legal requirement, the defendant never supplied the product, the defect did not exist at the relevant time, or the state of scientific and technical knowledge was insufficient to discover it. The defendant bears the burden of establishing whichever defence it relies upon.
The development-risks defence is deliberately narrow. It concerns the state of scientific and technical knowledge at the time the product was supplied, rather than whether an individual manufacturer actually knew of the danger. In A v National Blood Authority, involving 114 claimants infected with hepatitis C through blood or blood products, the High Court held that a known but then unavoidable risk was not transformed into an undiscoverable development risk merely because screening was unavailable.
Abouzaid v Mothercare illustrates the distinction particularly well. A child suffered severe eye damage when an elasticated strap and metal buckle recoiled while a pushchair accessory was being fitted. Mothercare argued that the hazard had not previously been recognised, but the Court of Appeal rejected the development-risks defence: the defect could have been identified through a simple practical test, and no scientific or technological advance was needed for the risk to become discoverable.
Causation remains a separate hurdle. A claimant must establish that the defect caused the relevant damage, not simply that a product failed before an injury occurred. Subsequent repair, abnormal loading, poor maintenance, misuse, counterfeit replacement parts or unauthorised software modification may provide alternative explanations. An intervening act can sometimes break the causal chain; in other cases it merely contributes to the outcome, leaving responsibility divided among several actors rather than eliminated.
Foreseeable misuse is different from extraordinary misuse. Product safety is assessed against use that can reasonably be expected, so a producer cannot necessarily escape liability because a consumer behaved imperfectly. Where the claimant’s own fault contributes to the damage, section 6 of the 1987 Act applies contributory-negligence principles, permitting damages to be reduced. For component producers, a separate defence exists where the defect is wholly attributable to the subsequent product’s design or instructions.
Time Limits and Long-Tail Product Liability
Product liability can linger long after the purchasing decision has faded from operational memory. In England and Wales, claims under Part I of the Consumer Protection Act 1987 are generally subject to three years running from the later of accrual and the claimant’s relevant date of knowledge. Overlaying that is an absolute ten-year long-stop from the statutory “relevant time”, which can extinguish the right even before damage or knowledge emerges at all.
Other causes of action run on entirely different clocks. A simple contractual claim in England and Wales ordinarily has a six-year limitation period from the accrual of the claim. In contrast, an action on a speciality, including many deeds, generally has a twelve-year limitation period. Negligence claims involving latent non-personal-injury damage may engage a three-year knowledge-based period and a fifteen-year overriding long-stop. Scotland and Northern Ireland have distinct limitation and prescription regimes of their own.
The commercial consequences last still longer. Manufacturers are commonly required by product legislation to retain technical documentation for about ten years. However, sector rules vary because claims, recalls and regulatory investigations may surface long after production stops. Hastings v Finsbury Orthopaedics reached the Supreme Court in 2022 after a hip prosthesis implanted in 2009 was revised in 2012, showing how supplier exits, acquisitions and lost records can rival the original engineering evidence in importance.
The Product Regulation and Metrology Act 2025
The Product Regulation and Metrology Act 2025 received Royal Assent on 21 July 2025, with most of its provisions coming into force that day; sections 11(1) and 11(3) were expressly left to be brought into force by later commencement regulations. Its significance lies less in creating a new safety code than in giving ministers a broad statutory platform for modernisation. The Secretary of State may make product regulations to reduce or mitigate risks, ensure products operate effectively and regulate measurement.
Those powers reach deeply into the product lifecycle. Regulations may address product characteristics, manufacture, installation, components, marketing, use, packaging, storage, transport, monitoring, testing, certification, record-keeping and the provision of safety information. Importantly, the statutory concept of components can encompass intangible elements such as software, enabling the legislative architecture to respond to connected and AI-enabled products rather than assuming that safety is fixed permanently at the point of manufacture.
Online commerce is equally prominent within the new powers. The Act allows product regulations to impose requirements on online marketplaces and other persons involved in making products available, addressing a gap that became increasingly visible as overseas sellers gained direct access to UK consumers. It also permits requirements concerning product monitoring, complaints, documentation, and information about risks, shifting product-safety accountability between digital intermediaries and conventional manufacturers, importers, and distributors.
Enforcement powers can also be reshaped through secondary legislation made under the Act. Regulations may provide for investigation, entry, search, inspection, seizure, production of documents, warnings, prohibition, withdrawal and recall. They may create or widen criminal offences and provide civil sanctions, including monetary penalties. Where an offence is created under the Act’s powers, the maximum custodial penalty on indictment cannot exceed two years, allowing enforcement to become both more coherent and more flexible.
The delegated powers are substantial but not unrestricted. Regulations are made by statutory instrument; consultation is generally required; and stronger parliamentary scrutiny applies to specified uses, including powers of entry, the creation or widening of criminal offences, the amendment of primary legislation, the first use of powers concerning online marketplaces, and the first creation of a new category of regulated person. The Act also governs information sharing, cost recovery and devolved consent.
The Act has already moved beyond theory. The Noise Emission in the Environment by Equipment for Use Outdoors (Amendment and Transitional) Regulations 2025 were made under the powers conferred by it. They came into force on 13 April 2026, updating measurement methods and supporting continued recognition of relevant CE requirements in Great Britain. That first use demonstrates the model: Parliament supplies broad powers, while product-specific technical obligations are amended progressively as standards, markets and technologies evolve.
Why the Existing Product Safety Framework Is Being Rebuilt
The case for reform begins with fragmentation. The Government identifies more than 150 pieces of product-safety and legal-metrology legislation across the landscape, with several sets of rules often applying to one product. General duties sit alongside sector regimes for machinery, electrical equipment, toys, cosmetics, pressure equipment, and many other categories, developed at different times, leaving regulators and businesses to navigate overlapping powers, terminology, and procedural requirements.
The core Great Britain consumer-safety regime also dates from a different commercial era. The General Product Safety Regulations 2005 remain the baseline for many consumer goods, yet online retail has transformed market access since their introduction. Government consultation data show online sales accounted for 25.4% of UK retail sales in March 2024, compared with 10.8% ten years earlier, so products can now reach households directly from sellers with no meaningful UK establishment.
Modern products compound that structural problem further still. A connected appliance may combine imported hardware, third-party firmware, cloud services and later software updates, while an AI-enabled product may change its behaviour over its lifecycle. Traditional legislation frequently assumes identifiable physical products moving through recognisable domestic supply chains. The Government’s reform programme instead seeks rules capable of addressing new technologies, digital product information and international e-commerce without repeated bespoke statutory fixes.
Reform is therefore about effectiveness as much as it is about simplification. The March 2026 enforcement consultation said fragmented and overlapping powers can delay action, create confusion and encourage excessive reliance on criminal prosecution where a more proportionate civil response might suffice. Government proposals seek a common enforcement toolkit, clearer responsibilities and better information sharing. The ambition is not deregulation; it is to remove avoidable complexity while intervening faster on unsafe or non-compliant products.
The UK’s New Product Safety Framework — The 2026 Proposals
On 31 March 2026, the Government published proposals for a new core product-safety framework alongside a companion consultation on market surveillance and enforcement. Both consultations closed on 23 June 2026. As at September 2026, the proposals should still be treated as proposals rather than existing replacement law. Their direction is nevertheless clear: a more coherent baseline that reflects modern products, routes to market, and supply chains, while retaining strong protection against unsafe goods.
A significant proposal is to broaden the core framework beyond consumer products. The consultation envisages coverage of “business products” supplied to organisations, including public bodies and charities for their own use, subject to exclusions such as food, medicines, medical devices, military equipment and certain specialist sectors. That matters for procurement because safety obligations would no longer turn so heavily on whether the immediate purchaser is a household, a local authority or a housing provider.
The Government proposes retaining a general requirement that products be safe, but modernising what the safety assessment must consider. Relevant factors would include product characteristics, interactions with other products, vulnerable users, reasonable consumer expectations, state of the art and products attractive to children. Cybersecurity risks arising from artificial intelligence or machine learning would also be explicitly included, recognising that software behaviour can create physical safety consequences without any conventional manufacturing defect.
Standards would remain important but not conclusive under the proposals. The consultation notes that around 3,500 designated standards currently support regulatory compliance in the UK. Following a designated standard can provide a presumption of conformity with specified legal requirements, yet compliance does not prevent a product from being found dangerous where evidence shows otherwise. Certification simplifies assurance, but it cannot substitute for risk assessment, monitoring or action when experience reveals an underestimated hazard.
Product information would also become more digital under the reforms. The Government proposes a “digital by default” approach under which some required information could be provided electronically, while essential physical identifiers and warnings would remain where necessary. This could reduce the need for repeated labelling and make compliance information easier to update. However, it raises governance questions about accessibility, persistence, and authenticity, particularly since Northern Ireland’s EU rules may still require information to be physically present on packaging.
The framework is intended to work prospectively rather than only after accidents occur. Producers would be expected to monitor products, investigate complaints and maintain records, while downstream actors would have clearer duties to respond to alerts and visible non-compliance. That reflects a regulatory philosophy: placing a safe product on the market is not the end of responsibility, and safety information from returns, incidents or software behaviour may create a continuing obligation to investigate and intervene.
Accountability Throughout the Supply Chain
The 2026 consultation proposes replacing assumptions about neatly separated economic actors with three functional categories: producers, onward suppliers and online marketplaces. The categories would not be mutually exclusive, recognising that one organisation can manufacture, import, brand, warehouse, sell and facilitate sales simultaneously. Accountability would follow from what an actor actually does and the information or influence it possesses, rather than from its preferred commercial description or contractual label.
For producers, the proposed duties go beyond initial conformity assessment. They would be prohibited from supplying unsafe products and, where reasonable and proportionate, expected to undertake sample testing, provide routes for complaints, investigate safety concerns and maintain records. Onward suppliers would have to exercise due care, understand relevant hazards, check alerts and recalls, perform appropriate physical checks where they possess products, and ensure storage or transport does not compromise safety.
The emerging principle is difficult to reconcile with "we relied on our supplier" as a complete governance answer. A purchaser may rely on upstream evidence, but verification should reflect product risk, warning signs and the actor’s ability to intervene. Repeated complaints, implausible certificates, unexplained substitutions or known recalls demand action. Supply-chain accountability is strongest when contractual rights, technical assurance, complaints intelligence and regulatory monitoring reinforce one another rather than sit in separate silos.
Market Surveillance and the Future of Enforcement
Market surveillance is the bridge between product rules on paper and products actually circulating through shops, warehouses, borders and websites. OPSS acts as the national product regulator for many goods, while local Trading Standards services retain substantial enforcement responsibilities and specialist regulators cover defined sectors. The difficulty is not merely identifying unsafe products; authorities must determine which legislation applies, who has jurisdiction and which intervention can lawfully stop further supply quickly.
The operational scale is considerable. OPSS reported resolving 14,019 enforcement cases during 2025-26, including 4,598 cases where businesses were signposted to guidance, 2,749 involving advice and 1,056 in which no non-compliance was identified. It also recorded 699 online listings removed, 41 improvement plans, 190 business undertakings and 21 enforcement actions, including prohibition, withdrawal and recall notices, ranging in practice from informal guidance to compulsory market intervention.
Border activity exposes the volume of risk before goods reach consumers at all. During 2025-26, OPSS checked consignments containing more than 11.3 million goods and reported that over 2.7 million were unsafe or non-compliant, roughly one quarter of those examined. The regulator estimated avoided consumer detriment of about £81 million from unsafe goods and £209 million from non-compliant goods, and seized imported teeth-whitening products with a stated value exceeding £1 million.
The proposed enforcement framework would consolidate powers currently scattered across more than 150 legislative instruments into a common statutory toolkit. Authorities could draw on clearer powers for investigation, inspection, seizure, withdrawal, recall and other interventions without repeatedly navigating different procedural architectures. The Government also proposes mechanisms for information sharing among regulators, departments, emergency services and other specified bodies, since faster intelligence flow matters where one product appears simultaneously at ports, marketplaces and retailers.
Civil monetary penalties are another significant proposal within the reform package. The consultation considers fixed, variable and escalating penalties as alternatives to criminal prosecution, particularly where a proportionate financial sanction could secure compliance more efficiently. Importantly, it did not propose a headline percentage-of-turnover maximum or a specific universal GBP cap; seriousness, scale, impact and repeated or persistent breaches are among the factors contemplated, with criminal prosecution remaining available for the most serious conduct.
More flexible enforcement could change commercial risk calculations considerably. Product-safety failures already impose quarantine, testing, recall, storage, destruction and reputational costs before any penalty is imposed. A consolidated regime could enable faster formal intervention, while enforcement undertakings allow some breaches to be corrected without prosecution. For boards and procurement teams, the expected cost of weak compliance should include regulator intervention and operational disruption, not simply the probability of a criminal fine.
Great Britain, Northern Ireland and the European Dimension
Operating across the United Kingdom now requires businesses to distinguish regulatory geography as carefully as product category. In Great Britain, UK Conformity Assessed (UKCA) remains the domestic conformity marking for relevant regulated products, while CE marking continues to be recognised for many product types under the post-Brexit regime. Government guidance covers more than twenty product areas affected by UKCA and CE arrangements, so choosing a marking route depends on several variables at once.
Northern Ireland follows a different architecture under the Windsor Framework because relevant EU rules for manufactured products continue to apply there. Products that meet EU requirements can bear the CE marking. Where mandatory third-party conformity assessment is performed by a UK-based body for the Northern Ireland market, CE must generally be accompanied by UKNI; an EU-recognised notified body supports CE without UKNI, so UKNI functions as a market-access indicator rather than a substitute for conformity.
The divergence also extends to general product safety across the two jurisdictions. The EU General Product Safety Regulation has applied in Northern Ireland since 13 December 2024, while Great Britain continues to rely on the General Product Safety Regulations 2005 pending reform. Qualifying Northern Ireland goods can retain unfettered access to Great Britain, including goods carrying CE or CE plus UKNI where applicable, requiring a single distribution model supported by two distinct compliance analyses.
Further divergence is approaching in the law of civil liability itself. Directive (EU) 2024/2853 modernises European product liability rules, including the treatment of software, and is due to apply to relevant products placed on the Northern Ireland market or put into service there after 9 December 2026 once implemented. Great Britain continues to be governed by the Consumer Protection Act 1987 unless Parliament changes it, creating an important north-south distinction in liability exposure.
The Manufacturer — Where Responsibility Begins
Manufacturers sit at the centre of product safety because they normally determine design, materials, performance limits and production controls before downstream businesses see the goods. Great Britain guidance requires manufacturers to meet applicable design and manufacturing requirements, complete conformity procedures, prepare technical documentation and declarations where required, apply identification or conformity markings and cooperate with market-surveillance authorities. Outsourcing production does not necessarily remove manufacturer status where goods are marketed under another organisation’s name.
Design control should begin with hazards rather than certificates. Risk assessment needs to consider intended use, foreseeable misuse, vulnerable users, component interactions and the consequences of a single-point failure. Testing must challenge those assumptions using appropriate standards, worst-case configurations and representative samples. In Wilkes v DePuy International, the C-Stem hip component had undergone fatigue testing beyond the applicable British Standard requirements; its subsequent fracture did not establish that the product was defective when supplied.
Production control is equally important because an approved prototype proves little if mass-produced units drift away from it. Material specifications, tolerances, calibration, supplier controls, inspection plans and change approval help ensure conformity across subsequent batches. Technical files should preserve the reasoning behind those controls, including design documents, risk assessments and test evidence. Government guidance indicates that records are commonly required to be retained for 10 years after each product enters the Great Britain market.
Post-market surveillance closes the loop between design assumptions and real-world evidence. Complaints, warranty returns, incidents, and near misses can reveal patterns that are unavailable during pre-market testing. Vauxhall’s Zafira B experience demonstrates the governance consequences of delayed learning: a House of Commons Transport Committee investigation concluded that Vauxhall was too slow to initiate a full investigation into vehicle fires, and by February 2017, the company had reported 59 fires in vehicles that had already undergone their first recall.
The manufacturer’s responsibility is both technical and organisational. Engineers need authority to stop production or investigate abnormal failure patterns; quality teams need reliable complaint data; procurement must control component changes; and leadership needs escalation routes when uncertainty justifies precautionary action. A conformity mark may support market access, but it does not freeze the safety assessment forever, and continued supply without investigation can turn an engineering problem into a governance failure.
Component Suppliers — When the Defect Starts Further Upstream
A finished product can fail because of something its brand owner never manufactured. Batteries, airbags, printed circuit boards, fasteners, resins, coatings, sensors and software modules may originate several tiers upstream. Yet, their performance is part of the integrated product’s safety. Supplier approval, therefore, requires more than price and delivery assurance: purchasers require specifications, process controls, traceability, change notification, and evidence that critical components have been tested under conditions the finished design creates.
The DVSA’s vehicle-recall code expressly anticipates that problem. Where a safety defect involves a third-party component supplier, producers should identify that supplier and, where known, inform DVSA if other producers use the same component, so that DVSA can track the issue across the wider market. Product-liability law likewise recognises component complexity: a component producer has a defence where a defect is wholly attributable to the subsequent product’s design or to instructions from its producer.
CASE STUDY Takata airbags illustrate the potential scale of a single upstream defect. A UK Citroën C3 safety recall recorded in March 2025 covered 55,166 vehicles because chemicals in affected Takata airbags could deteriorate over time, allowing the inflator to rupture and cause serious injury. Owners were told to stop using affected vehicles when safe to do so until replacement. One supplier’s ageing mechanism can therefore create long-tail recall obligations for multiple vehicle manufacturers and distributors. |
Importing is not simply a freight, customs or purchasing function. An organisation that brings regulated goods into Great Britain can become an importer with legal duties to verify that the manufacturer has completed the required conformity assessment, prepared the required technical documentation, and applied the appropriate markings. Government guidance expressly warns that businesses bringing products from the EU into Great Britain are now likely to be importers rather than distributors, carrying additional responsibilities.
The practical consequence is that an importer cannot safely rely on a supplier’s reassurance that a product is “CE approved” or “UK compliant”. Depending on the applicable legislation, it may need to verify manufacturer details, declarations of conformity, markings, instructions and traceability before placing goods on the market. If it has reason to believe a product is non-compliant, corrective action may include bringing it into conformity, withdrawing it, or recalling it entirely.
CASE STUDY Diva Gift Limited provides a useful example of enforcement directly reaching an importer. The company imported a children’s musical crib toy from a supplier in China and sold it through eBay. OPSS testing found detachable small parts creating a high choking risk to children under 36 months. In March 2024, Northampton Magistrates’ Court imposed a £10,000 fine, £4,393.16 in costs and a £2,000 victim surcharge, resulting in a total payable of £16,393.16. |
Recent border interventions show why documentary checking matters before commercial release. In August 2026, OPSS rejected a DayPlus rechargeable polishing machine because its Declaration of Conformity did not match the product, valid technical documentation was absent, and the charger failed an electrical-strength test, creating a serious electric-shock risk. A Hengjian off-road motorbike was rejected the same month after similarly inadequate conformity evidence left a serious fire risk unresolved.
Importer responsibility is therefore a governance issue as much as a regulatory label attached to a shipment. Procurement teams need to identify who is importing, which market is being entered, which legislation applies, and what evidence must be in place before goods are released. Contracts should require complete technical documentation, valid declarations, traceability, and cooperation in recalls, but contractual promises do not replace the statutory checks that the importer itself must perform.
The Distributor — The Duty Not to Look the Other Way
Distributors occupy the middle of the chain, but their position does not make them invisible to product-safety law. Under the General Product Safety Regulations 2005 in Great Britain, a distributor must act with due care, must not supply a product it knows or ought to know is dangerous, should pass on risk information, retain traceability records and cooperate with enforcement authorities when investigation, withdrawal or recall becomes necessary for a particular product line.
That duty requires proportionate verification rather than laboratory re-engineering of every product a distributor handles. A distributor should recognise obvious non-compliance, check relevant markings and instructions, preserve information identifying its supplier, and react to alerts, recalls or credible complaints. Storage and transport also matter: damaged packaging, excessive heat, moisture, impact, contamination or poor battery handling can turn an originally compliant product into an unsafe one before it reaches the retailer.
OPSS action against Desertcart in January 2024 shows that downstream status offers little shelter once a serious hazard is known to exist. The regulator served a Withdrawal Notice regarding UPP model U004 and U004-01 e-bike batteries, which present a serious fire risk. Desertcart, identified as the distributor, was required to withdraw the batteries from sale and contact all purchasers, illustrating how responsibility can crystallise after a product has already entered distribution.
The central question is therefore what a competent distributor knew, should have known and did after receiving relevant information. A suspicious certificate, repeated returns, damaged stock or a regulator alert should trigger an investigation rather than routine resale. Commercial pressure to clear inventory cannot override safety duties. Distributors that maintain reliable supplier records, quarantine procedures, recall contacts and escalation routes are better placed both to protect customers and to demonstrate due care.
The Retailer — The Final Gatekeeper
Retailers are the final commercial gate before many products reach consumers, and they often receive the earliest evidence that something is wrong. Government guidance states that sellers must not supply consumer products they know or should have known to be unsafe. Retailers need supplier records sufficient to support traceability. They should report safety risks or consumer incidents to the manufacturer, supplier, or the relevant Trading Standards service rather than treating complaints as customer service matters.
The retailer’s advantage is proximity to real-world use of the finished product. Returns, complaints, photographs, warranty claims, and staff observations can reveal patterns that are invisible during pre-market testing. A single broken plug may be accidental; repeated reports of overheating across a model may indicate a systemic defect. Effective retailers therefore aggregate safety-relevant complaints rather than closing each transaction separately, since fragmented data can hide the early warning signs of an emerging recall.
Retail obligations also overlap with consumer law more broadly. Under the Consumer Rights Act 2015, goods supplied by a trader to a consumer must be of satisfactory quality, fit for particular purposes made known to the trader and as described; safety forms part of satisfactory quality. A retailer may therefore owe the consumer a remedy even when the defect originated overseas, while recovery against upstream suppliers remains a separate commercial exercise entirely.
Large retailers can use purchasing scale as a genuine safety control. Supplier onboarding may require test reports, declarations, technical files, approval of manufacturing sites, product change notifications and cooperation in recalls before a listing is authorised. Surveillance can then combine customer complaints, return rates, regulator alerts and periodic sampling. A defective private-label line may expose the retailer not only to refunds and reputational damage, but also to producer-level liability where branding changes legal status.
The strongest retailer response is therefore neither blind reliance on upstream certification nor an attempt to duplicate the manufacturer’s engineering function. It is a disciplined gatekeeping system that asks whether the evidence is credible, whether complaints suggest an emerging risk, and whether continued sale remains defensible. Immediate quarantine, listing suspension and escalation may prevent a small defect population from becoming a national recall, provided the retailer’s systems are actually listening for it.
Own-Brand Products and Private Labels
Private-label sourcing can transform a purchaser into something closer to a producer in law. Under the Consumer Protection Act 1987, liability can attach to a person who puts its name, trade mark or other distinguishing mark on a product and thereby holds itself out as the producer. The commercial attraction of own-branding carries a corresponding legal consequence: customers may be entitled to look directly to the brand owner when the product is defective.
The same principle appears across modern regulatory regimes. Government guidance on consumer connectable products states that an organisation marketing a product made by another person under its own name or trademark is treated as a manufacturer for the purposes of those security requirements. RoHS guidance similarly provides that an importer placing electrical or electronic equipment on the market under its own name or trademark must comply with manufacturer obligations, so rebranding changes regulatory status, not merely packaging.
For procurement teams, private-label governance should therefore resemble manufacturer oversight rather than ordinary resale. Specifications, approved factories, component controls, testing rights, change notification, technical documentation and recall cooperation become critical because the brand owner has deliberately placed its identity between the factory and the customer. A strong indemnity may recover some upstream losses, but it cannot undo reputational damage or prevent statutory liability once legislation treats the own-brander as producer or manufacturer.
Overseas Manufacturers and Complex Global Supply Chains
Global sourcing can place the physical manufacturer several contractual steps and thousands of miles away from the eventual customer. That distance complicates inspection, enforcement, service of proceedings, evidence preservation and recovery. A UK purchaser may buy from a domestic distributor that sourced through an importer, trading company or marketplace seller. At the same time, the factory itself has no UK assets, so product safety depends heavily on establishing a responsible economic actor within practical regulatory reach.
The scale of border intervention shows why that matters so much in practice. During 2025-26, OPSS-supported checks covered 11,310,080 goods entering the UK; 345,919 were determined unsafe, and 2,397,013 were non-compliant, for a combined total of 2,742,936. OPSS estimated that preventing those goods from entering circulation avoided about £81 million of detriment associated with unsafe products and approximately £209 million associated with non-compliant products entering the market.
Direct-to-consumer e-commerce weakens the traditional assumption that a UK importer will always stand between an overseas factory and the buyer. The Government’s 2026 proposals expressly identify difficulties taking action against overseas sellers and the sheer volume of non-compliant products entering through online and international supply chains. Proposed rules would therefore make the overseas seller itself the producer in certain distance-sale situations where no UK manufacturer, authorised representative, or importer exists.
The September 2026 FREESKY 540E electric-bicycle intervention illustrates the practical problem well. OPSS rejected the import after finding that a valid Declaration of Conformity had not been supplied and that there was no evidence of relevant UK conformity assessment; inadequate labelling also remained. The product, manufactured by Guangzhou Electroy Corporation in China, was assessed as presenting a serious fire risk because conformity of the electrical system could not be demonstrated to regulators.
Supply-chain contracts should therefore establish more than just price, Incoterms, and delivery dates. Buyers need factory identity, manufacturing location, access to technical files, component traceability, audit rights, change controls, insurance evidence and enforceable cooperation obligations. Where the manufacturer sits beyond easy jurisdictional reach, the solvency and responsibilities of the UK importer or distributor become commercially important, since a low purchase price can prove illusory if recovery after a national recall depends on an inaccessible counterparty.
Fulfilment Providers, Warehouses and Logistics Operators
Fulfilment providers occupy an increasingly important position between online sale and physical delivery. They may warehouse, package, address and dispatch goods without owning them, giving them operational control but not necessarily conventional seller status. In Northern Ireland, the EU General Product Safety Regulation expressly recognises fulfilment service providers. The Government’s 2026 Great Britain proposals likewise state that such businesses should fall within the proposed “onward supplier” category rather than sit entirely outside the safety chain.
That classification reflects practical influence over the product’s condition. Warehousing can expose lithium batteries to heat, water or physical damage; repacking can remove warnings or batch information; labelling errors can send the wrong safety instructions to customers; and dispatch systems can continue shipping stock after a recall begins. A fulfilment operator may not have designed the product, but its processes can preserve, worsen or help control the risk once goods enter domestic distribution.
The boundary becomes particularly blurred where one organisation stores stock, prepares listings, packages orders, manages returns and handles customer communications for an overseas seller. Those activities generate information that can quickly identify unsafe products. Under the Northern Ireland GPSR, fulfilment service providers are an expressly recognised economic-operator category. At the same time, the proposed Great Britain framework would clarify their inclusion as onward suppliers, so regulatory attention follows operational control rather than ownership labels.
Contracts with logistics providers should accordingly contain product-safety controls alongside service levels for picking accuracy and delivery speed. Recall holds, serial or batch traceability, quarantine areas, damaged-stock procedures, controlled disposal and urgent data extraction can determine whether corrective action succeeds. If a warehouse can identify every affected unit within hours, recall costs and consumer exposure may be contained; if stock is commingled or records are weak, a manageable incident can expand rapidly.
Conformity Assessment and Product Certification
Conformity assessment is the process used to demonstrate that a product meets applicable legal requirements before it is placed on the market. Depending on the legislation and risk category, the manufacturer may self-declare conformity or may need an independent approved or notified body. The assessment can involve design review, type examination, testing, production-quality controls and documentation, and its purpose is evidential: it shows how specified requirements were addressed before goods are sold.
The process should not be confused with a general certificate of safety. Product legislation sets essential requirements concerning health, safety, performance or environmental protection, while standards provide technical routes for meeting some of those requirements. Government guidance is explicit that applying a standard does not replace legal obligations. A product can follow a relevant standard yet remain unsafe because another hazard falls outside its scope or because production no longer matches the design.
Assessment routes also differ significantly by product category. Many products can rely on manufacturer self-declaration, while higher-risk categories require third-party involvement. The Government’s conformity-assessment database showed 173 UK approved bodies in September 2026, spanning multiple legislative areas, while the MHRA listed nine UK approved bodies for medical devices in July 2026. An approved body’s existence tells buyers little unless its designation covers the product, legislation and procedure concerned.
The declaration accompanying a product is equally important to the chain of evidence. It identifies the manufacturer, product, legislation, standards, and responsible signatory, creating a formal link between the marketed item and the assessment that underpins it. In August 2026, the Hengjian off-road motorbike was rejected at the border because its supplied Declaration of Conformity did not match the product, and OPSS found no valid technical documentation or production-control evidence, leaving a serious fire risk.
Conformity assessment is most effective when treated as a system rather than as a document requested at the end of procurement. Buyers should confirm the model assessed, applicable standards, laboratory scope, certificate validity, manufacturing location, and whether later component substitutions invalidate earlier evidence. A test of a single representative sample cannot indefinitely prove that every batch remains identical, so change control and ongoing production assurance are essential companions to initial certification, not optional extras.
The commercial lesson is that conformity evidence should answer a chain of questions: which legal requirements apply, which route was used, who performed independent work, which configuration was examined, and whether current stock still matches it. Missing links require investigation before acceptance. Certification can substantially reduce uncertainty, but it transfers no responsibility away from manufacturers, importers or purchasers whose own decisions determine whether credible evidence is obtained and acted upon.
UKCA, CE Marking and Recognised Standards
UKCA and CE markings indicate that the manufacturer claims the product meets applicable conformity requirements for the relevant market; neither is a general quality award nor a guarantee that failure is impossible. In Great Britain, continued recognition of current EU requirements, including CE marking, applies across 21 product regulations. UKCA remains available, while sector-specific arrangements differ for medical devices, construction products, marine equipment and transportable pressure equipment.
For many sectors of the Great Britain market, the 2024 amendments removed the previous 31 December 2024 expiry of CE recognition, allowing businesses to continue using recognised EU requirements alongside UKCA. That flexibility reduces duplicate assessment costs for organisations serving both markets, but it also makes regulatory checking more nuanced. Procurement teams cannot assume one mark answers every question; they must confirm sector, destination market, legislation, standards and assessment route.
Designated standards add a further layer of evidence. In Great Britain, a government-designated standard can create a rebuttable presumption of conformity with the essential requirements it covers. That presumption is limited: standards may address only part of the legislation, can be designated with restrictions, and never transfer responsibility away from the manufacturer. Following a standard is powerful evidence of compliance, but a real hazard can still rebut the assumption of compliance.
CE-marked goods placed on the Great Britain market under continued recognition may rely on EU harmonised standards, but the legal mechanics differ from UKCA. Guidance published in March 2026 explains that CE products following harmonised standards do not, by themselves, receive the Great Britain statutory presumption attaching to UKCA products that follow designated standards. The practical compliance outcome may still be acceptable, but the evidential routes remain distinct in law.
The safest procurement approach treats markings as the visible endpoint of an evidence chain, not the beginning and end of due diligence. Buyers should obtain the declaration, identify applicable legislation, verify approvals or notifications, review the standards, and confirm that the delivered model matches the assessed configuration. A perfectly printed CE or UKCA symbol on a non-compliant product is still only ink; lawful marking depends on the conformity work behind it.
Testing, Certification and Third-Party Assurance
Testing converts design assumptions into evidence by measuring how a product performs under defined conditions. Depending on the risk, laboratories may assess electrical strength, flammability, mechanical loading, chemical composition, ingress protection, sterility or other characteristics. The value of the result depends on competence, method, sample selection and traceability. A technically impressive report provides weak assurance if the laboratory lacked relevant capability or the sample cannot be reliably linked to production stock.
Accreditation helps establish that competence exists in the first place. UK government policy recognises the United Kingdom Accreditation Service as the national accreditation body, describing accreditation as “checking the checkers” because it assesses organisations that perform testing, calibration, certification and inspection. In regulated sectors, approved bodies must also hold the appropriate appointment under the relevant legislation and product scope, so buyers should verify both accreditation and designation.
Third-party assurance still has real limits worth remembering. A laboratory usually reports what happened to defined samples using specified methods; it does not guarantee that every subsequent production unit is identical, nor does a certification body assume the manufacturer’s responsibility. Sampling can miss intermittent defects, counterfeit substitutions or process drift. For high-risk products, assurance should combine type testing with factory controls, batch testing where proportionate, supplier audits and complaint monitoring.
Independent evidence becomes most valuable when it challenges convenient assumptions. In August 2026, OPSS rejected the DayPlus rechargeable polishing machine after its charger failed an electrical-strength test and the supplied declaration did not match the product. The result did more than expose defective paperwork: physical testing identified a serious electric-shock hazard. Effective assurance therefore triangulates documentation, certification, and actual performance, rather than letting a single reassuring document silence contradictory evidence.
When the Certificate Is Wrong
Certificates fail in several different ways. Some are counterfeit; others are genuine but issued outside the body’s accredited scope, relate to a different model, cite an inappropriate standard or describe a sample no longer representative of production. UKAS states that it has identified several counterfeit certificates and false accreditation claims in circulation. Procurement assurance therefore requires independent validation of the issuer, accreditation, scope, certificate number and product identity, not a visual glance at a PDF.
CASE STUDY Grenfell Tower remains one of the gravest examples of certification and assurance failure in UK history. The Inquiry’s 2024 Phase 2 report found that Celotex manipulated a 2014 fire test of its RS5000 insulation using concealed fire-resisting boards, while certification and approval processes surrounding Kingspan’s K15 product failed to expose deficiencies in supporting fire-performance evidence. Arconic likewise relied on test data concerning a more fire-retardant cladding variant than the panels ultimately supplied. |
As of September 2026, the Grenfell Tower Inquiry had identified serious failings by testing and certification bodies, including BRE’s complicity in Celotex’s manipulated 2014 fire test. The Metropolitan Police had also confirmed that files concerning up to 57 individuals and 20 organisations would be submitted to the Crown Prosecution Service by 30 September 2026, with charging decisions expected before June 2027. For procurement teams, Grenfell shows that apparently authoritative certification can coexist with flawed, manipulated or misleading evidence.
Even authentic evidence ages in ways procurement teams often overlook. A report may concern an earlier factory, component, firmware version or standard, while production changes continue unnoticed downstream. UKAS accreditation schedules define exactly which activities an organisation is competent to perform, and its electronic certificates are meant to be read alongside those schedules. An impressive logo cannot extend the scope of accreditation, so buyers should compare dates, tested models, and current schedules before relying on historical assurances.
The 2026 border reports provide a more everyday warning of the same underlying problem. FREESKY, Hengjian and DayPlus products were rejected after declarations were either invalid or did not match the goods. At the same time, physical or documentary deficiencies left serious fire or electric-shock risks unresolved. The correct response to a doubtful certification is verification, not assumption: contact the issuing body, check official registers, inspect the scope and test reports, and quarantine stock where necessary until the issue is resolved.
Supplier Assurance — Trust but Verify
Supplier assurance begins with a simple proposition: evidence supplied by a manufacturer or distributor should be tested, not merely filed away. A declaration of conformity, laboratory report or certificate is useful only if it relates to the exact product being purchased, the correct legislation, the current manufacturing site and the present configuration. Purchasers should verify identifiers, dates, standards, issuing bodies and scope, then reconcile that evidence with the goods actually delivered.
Risk should determine the depth of assurance applied to any given product. Low-risk, established products may justify documentary checks and supplier declarations. Higher-risk electrical, construction, medical, or children’s products may instead require independent testing, factory audits, batch sampling, or specialist technical review. The Government’s 2026 proposals expressly contemplate additional verification duties for onward suppliers and online marketplaces for categories presenting significant risks, including checking declarations and conformity markings before supply.
Assurance should also examine the supplier’s standing behind the paperwork itself. Accreditation schedules, approved-body designations, test-house competence, manufacturing capability, complaint history, and regulatory action can reveal weaknesses that are invisible in a certificate. A purchaser should ask whether the laboratory was competent for the specific test, whether samples were independently selected, and whether production has changed since testing took place. For critical products, audits should follow the process from incoming materials to release.
The strongest control available to procurement is triangulation across several independent sources. Procurement compares supplier documents with public registers and regulatory alerts; technical teams test whether standards and specifications are appropriate; quality teams inspect production evidence; and contract managers monitor complaints, substitutions and changes after award. Government guidance makes clear that manufacturers and importers remain responsible for safety after market placement. Trust remains commercially necessary, but verification turns trust into defensible assurance.
Traceability — Knowing Where the Product Came From
Traceability is the ability to connect a physical product with the businesses, places, batches and records that created and moved it. Government guidance recommends that products or packaging identify the manufacturer and importer, where applicable, together with a product or batch reference identifying the place and time of manufacture. Many sector regimes go further, requiring type, batch, or serial numbers and the retention of technical documentation for periods that commonly reach ten years.
The practical value becomes obvious when only part of a production run is affected by a fault. In August 2026, Bull Products and Cygnus Group recalled fire-alarm detection systems after identifying a communication fault that could delay fire detection and alarm activation. The defect was confined to a single batch of network control units (reference 2410), and not every unit in that batch was affected, so batch traceability enabled targeted corrective action.
Good traceability links more than a serial number to a purchaser’s name and address. It should identify manufacturing site, production date, critical components, supplier lots, inspection results, software or firmware version, distributor, customer and, where proportionate, installation location. That information allows investigators to ask whether failures cluster around one factory, one component batch, or one design revision, and it reduces the population that requires quarantine, testing, or recall when evidence supports a narrower group.
Traceability Beyond Tier One
Knowing the immediate supplier is only the beginning, since safety-critical components often originate deeper in the chain. A branded appliance may contain a battery cell from one country, a protection circuit from another, software from a third-party developer and a charger manufactured elsewhere. If the defect originates in any of those inputs, a purchaser recording only its Tier One distributor may struggle to identify other affected products, alternative sources or the true root cause.
The automotive sector particularly clearly demonstrates the scale of this upstream dependency. A single component can appear across several manufacturers, models and years, so recall systems need to follow component provenance rather than brand alone. UK vehicle-recall guidance expects producers to identify third-party component suppliers and, where known, tell DVSA if other producers use the same component, allowing a defect discovered in one vehicle population to trigger investigation across the wider market.
Construction products present a similar challenge because performance can depend on treatments, coatings, fixings and subcontracted processes rather than the base material alone. In 2025-26, OPSS investigated fire-rated plywood after concerns raised by the London Fire Brigade and found assurance gaps where manufacturers subcontracted the fire-retardant treatment. Four Prohibition Notices were served, halting supply and requiring recalls; OPSS noted that enhanced products commonly cost two to three times as much as standard plywood.
Traceability beyond Tier One therefore requires genuine contractual flow-down, not just a supplier list. Tier One suppliers should identify critical sub-suppliers, notify of changes, maintain batch genealogy, and preserve evidence linking components to finished products. Purchasers may also need audit rights or direct access to technical information where risk justifies it, since a supplier can otherwise change a cell manufacturer, resin formulation, software library or subcontractor. At the same time, the catalogue number remains the same throughout.
Digital systems can strengthen this chain by linking serialised finished goods to bills of materials, supplier lots, test results and revisions. However, technology cannot automatically repair weak governance. Data standards must be consistent, identifiers must survive repacking, and records must remain accessible after suppliers merge, fail or change systems. The value lies in reconstructing the product’s history quickly enough to support containment, root-cause analysis, and targeted corrective action.
The commercial objective is not unlimited visibility into every commodity a business handles. It is risk-based visibility to the point where a plausible safety failure can be traced to its origin and contained. Safety-critical batteries, structural fixings, flame-retardant treatments, pressure components and software modules generally justify deeper provenance than packaging or decorative inputs, so procurement should direct the greatest scrutiny towards components whose failure could cause serious harm to someone.
Technical Files and the Product Safety Audit Trail
A technical file is the evidential history behind a product’s claim to compliance. Depending on the applicable legislation, it may include design drawings, calculations, risk assessments, standards, test reports, bills of materials, conformity assessment evidence, declarations, instructions and production control information. Government guidance for many UKCA- and CE-regulated products requires that technical documentation be retained for the statutory period, typically 10 years after each product is placed on the market.
The file should evolve as the product itself evolves, rather than remain frozen at launch. Government guidance specifically warns economic operators to maintain procedures that preserve compliance when design, characteristics or relevant standards change. A supplier that substitutes a battery, modifies firmware or moves production to another factory may invalidate earlier testing even if the model name remains unchanged, so change-control records should explain what changed, who assessed the effect, and why continued supply was justified.
A defensible audit trail connects commercial and technical decisions across the whole lifecycle. Purchase specifications should match drawings; approved samples should match production; inspection records should identify batches; certificates should correspond to current components; and complaints should feed back into risk assessment. When an authority requests evidence, the organisation should reconstruct its rationale for compliance without relying on employees’ memories, because technical files are the operating record, not archives.
Digital Product Information and the Future of Traceability
Product information is moving from static labels and paper manuals towards digital records accessible throughout a product’s life. The Government’s March 2026 consultation proposes a “digital by default” direction for the new Great Britain framework, allowing certain producer details, safety information and instructions to be supplied digitally. Physical identifiers would remain important, particularly batch or serial information, since a digital record still needs an unambiguous link to the product in front of the user.
The consultation envisages data carriers such as QR codes, with built-in safeguards for accessibility and durability. Where safety information is digital, the label should explain what can be accessed and that the information should be read before use. The Government proposes that digital information remain accessible for the product’s expected lifetime, taking into account repair and refurbishment, recognising that ordinary webpages, hosting arrangements and domain ownership may disappear long before durable products do.
Construction-product reform is moving in the same direction. The 2026 Construction Products Reform White Paper proposes that product information should be available digitally, with unique product identifiers linked through digital labels such as QR codes. The accompanying general safety consultation explains that traceability is essential to corrective action and proposes that products include the manufacturer’s identity, address, unique identifier and a data carrier, reflecting lessons from the post-Grenfell drive for reliable information.
Medical-device regulation offers another example of increasingly granular identification requirements. Draft reforms, consulted on by the MHRA in 2026, propose compulsory unique device identifiers and implant cards, intended to improve lifecycle traceability and the management of adverse events. Although medical devices sit within a specialist regime, the principle has wider relevance: reliable digital identity can connect a physical product to its manufacturer, configuration, safety notices, and maintenance history more precisely than a generic model name can.
Digitalisation also creates governance risks alongside its evident benefits. Information can be altered after sale, QR codes can be replaced, databases can become inaccessible, and cybersecurity failures can undermine trust in the record itself. Organisations therefore need controlled version histories, durable hosting, access rights and evidence showing what information was available at a particular time. The future of traceability is creating persistent, authenticated product records, not simply moving existing paperwork online.
When Records Are Missing
Missing records can turn a contained technical problem into a much larger legal and operational one almost overnight. Without purchase orders, batch numbers, certificates, test reports or distribution records, an organisation may be unable to prove which specification applied, which units were affected or which customers received them. Government guidance requires sellers to keep records identifying suppliers, while many regulated regimes require manufacturers and importers to retain declarations for approximately ten years.
The immediate safety consequence is uncertainty that spreads outward from a single missing document. If a component batch is suspected but genealogy records are missing, unaffected products may need to be quarantined alongside defective ones. If customer records are incomplete, recall communications must rely more heavily on public advertising and retailer outreach. Lost evidence also hampers root cause analysis, since investigators cannot confidently compare production dates, suppliers, test results, or design revisions.
The legal consequence can be equally severe, as the PPE Medpro litigation shows. DHSC recovered £121,999,219.20 for non-compliant surgical gowns but failed on a separate £8,648,691 storage-cost claim. The High Court held that the storage loss had not been proved adequately: the supporting spreadsheet lacked sufficient underpinning and the witness presenting it lacked personal knowledge of its preparation. Records determine both quantum and technical liability in disputes of this kind.
Record retention should therefore be designed around foreseeable disputes, recalls and regulatory enquiries, not minimal administrative convenience. Organisations need controlled repositories, ownership rules, retention schedules and auditable links between contract, specification, batch and customer. Critical evidence should survive staff turnover, outsourcing and supplier insolvency. A document that cannot be located, authenticated or connected to the affected product is practically equivalent to no document at all when decisions must be defended years later.
The First Safety Incident
The first complaint should be treated as information, not dismissed merely because it is the first one received. The immediate task is triage: establish what happened, identify the exact product and batch, preserve the item where possible, record photographs and circumstances, assess injury or property damage, and determine whether similar reports exist. A rapid initial assessment should distinguish routine quality dissatisfaction from a plausible safety event without assuming one incident proves a systemic defect.
Containment may need to begin before root cause is fully known or understood. Suspect stock can be quarantined, dispatches paused, marketplace listings suspended and replacement batches held while technical investigation proceeds. These actions are reversible if the concern proves unfounded; continued supply may not be reversible if further injuries occur. Organisations should define in advance who has the authority to stop distribution, since hesitation due to unclear approval routes can turn a question into exposure.
Evidence must be preserved immediately, before memories fade or components are discarded. The failed product, packaging, charger, instructions, photographs, purchase records, software version and environmental conditions may all matter. Investigators should avoid destructive testing until an evidence plan has been agreed where litigation is foreseeable. Supplier notifications should request the corresponding production and test records without encouraging the alteration of documents, thereby creating a contemporaneous record that can support technical conclusions and later proceedings.
Haier’s heat-pump tumble-dryer incident shows the depth a serious investigation can require in practice. In May 2025, OPSS declared a national incident involving more than 103,000 dryers presenting a fire risk. Enforcement officers, scientists, engineers and risk assessors reviewed technical documentation and examined products in OPSS laboratories. The regulator concluded that deteriorating wiring around compressor pipework containing flammable refrigerant was the root cause, and found the manufacturer’s initial modification unsatisfactory.
The first incident should also trigger a deliberate search for weak signals elsewhere in the business. Warranty returns, customer service notes, repair reports, social media complaints, insurer notifications and distributor feedback can reveal earlier events that were individually misclassified. The Vauxhall Zafira investigation illustrates the danger of fragmented signals: Parliament concluded that Vauxhall had been too slow to investigate a distinctive pattern of fires and too quick to attribute them to unauthorised repairs.
Senior escalation should depend on both potential severity and incident count, not on either alone. A single credible report involving fire, electrocution, structural failure, poisoning or a vulnerable child can justify executive attention before statistical certainty exists. The first hours should establish ownership across the safety, quality, legal, procurement and communications functions, identify notification obligations, and set decision checkpoints, since disciplined documentation matters as much as speed.
Product Safety Risk Assessment
Risk assessment translates technical evidence into a decision on which action is proportionate to the hazard. OPSS’s Product Safety Risk Assessment Methodology, PRISM, is used by Great Britain’s market-surveillance authorities for general non-food consumer products and aligns with the EU Safety Gate approach. It considers injury scenarios, severity and probability to reach a risk level, though businesses using comparable reasoning should avoid treating any numerical score as a substitute for expert judgement.
Exposure matters alongside probability in ways that are easy to underestimate. A rare failure in ten units may pose a different societal risk from the same failure rate across one million units. At the same time, the consequences differ sharply between minor irritation and a fatal fire. Vulnerable users can change the assessment because children, older people or people with disabilities may be less able to recognise hazards or escape them once a failure actually occurs.
The 2025-26 Product Safety Database demonstrates the range of risk levels regulators encounter in ordinary practice: 563 notifications were recorded as serious risk, 259 as high, 127 as medium, and 229 as low, while 1,074 had no assigned risk level at the time of notification. Fire was the most frequently recorded harm among unsafe or unsafe-and-non-compliant notifications, appearing 424 times, reinforcing the case for risk classification being evidence-led and open to revision.
Corrective Action — Repair, Warning, Withdrawal or Recall?
Corrective action should remove or reduce the risk with the least possible delay, but the appropriate measure depends on where affected products are and how serious the hazard is. A manufacturing adjustment may address unsold stock; a warning may manage a limited residual risk; withdrawal removes products from distribution channels; and recall seeks products already supplied to end users. Government guidance also recognises modification and new instructions as possible responses where they genuinely restore safety.
The distinction between withdrawal and recall is operationally important in practice. Withdrawal can prevent remaining stock from reaching consumers, while recall reaches back into homes, workplaces or installed environments. During 2025-26, the Product Safety Database recorded 249 withdrawals and 479 recalls from end users, along with 150 actions to bring products back into compliance and 71 modification programmes, so corrective action is not binary but a spectrum matched to risk.
Bull Products and Cygnus Group provide a recent example of layered action working as intended. After a fault was identified in a batch of fire-alarm network control units, remaining stock was quarantined, affected products were withdrawn, and a phased replacement programme began for all affected units, including those not yet exhibiting failures. The business also introduced enhanced end-of-line testing and redesigned the control board, addressing customers, inventory and recurrence together rather than only the symptom.
Haier’s heat-pump case shows how a first response can be found wanting and escalated further. OPSS concluded that Haier’s initial modification solution was unsatisfactory and issued a formal Notice to Warn, after which a revised modification programme was initiated for the affected population. Regulators can require stronger action wherever voluntary measures prove insufficient, and this case demonstrates that a modification programme is not necessarily the end of the corrective-action story.
The decision should be documented as carefully as the underlying technical investigation itself. Records should explain affected populations, risk classification, options considered, expected effectiveness, treatment of vulnerable users, regulator input and monitoring arrangements. Corrective action also requires exit criteria: organisations should know when a recall has reached an acceptable level of effectiveness or when additional outreach is required, since the strongest response is to remove the hazard and prevent the same failure from entering future production.
Product Recalls — Who Pays?
A recall incurs costs far beyond simply replacing the defective item itself. Businesses may need customer identification, call centres, postage, engineers, collection, warehousing, refunds, replacement stock, disposal, laboratory testing, legal advice, advertising and additional logistics. Retailers and distributors may incur their own handling costs before seeking upstream contractual recovery. Product-recall insurance can cover specified exposures, but scope, deductibles and exclusions matter, and contractual indemnities redistribute cost without removing regulatory responsibility.
Whirlpool’s washing-machine recall illustrates the scale such programmes can reach in customer-processing terms alone. By October 2021, 277,715 potentially affected customers had come forward, 209,956 affected-machine cases had been fully resolved, and 201,237 machines had been replaced free of charge. Whirlpool reported 3,359,301 visits to the recall website, while only 47% of the estimated 590,000 potentially affected machines had been registered at that point, underscoring how costs grow with both scale and the difficulty of locating users.
Who ultimately pays depends on legal rights and commercial leverage, not who caused the defect. A retailer may refund the consumer but recover against its distributor; an importer may pursue the manufacturer; insurers may exercise subrogation; and liability caps or exclusions may restrict recovery between businesses. Insolvency can leave costs stranded downstream: a June 2026 UK recall of UNU electric mopeds noted that the manufacturer, UNU GmbH, had entered insolvency, leaving owners directed to safe disposal.
Notification to Regulators
Notification is not optional once the statutory threshold has been met. Under the General Product Safety Regulations 2005 in Great Britain, producers and distributors that know a product they supplied poses risks incompatible with the general safety requirement must immediately notify the relevant enforcement authority in writing. Government guidance states that this will normally be the local Trading Standards authority, although sector-specific products may fall to OPSS, HSE, MHRA, DVSA or another regulator.
A serious-risk notification should contain enough information for authorities to act on straight away. Government guidance requires precise product identification, a full description of the risk, available traceability information and details of measures already taken to prevent harm. The Product Safety Database captures information such as importer details, batch numbers, test reports and corrective actions. Hence, a vague statement that “an issue is under investigation” is no substitute for structured evidence.
Timing matters because notification and corrective action often occur simultaneously rather than in sequence. Businesses should not wait for perfect root-cause certainty when they already know that a supplied product is unsafe, and initial information can be updated as testing progresses. The 2026 business-notification guidance covers both consumer and non-consumer products across Great Britain and Northern Ireland, though the legal routes differ depending on the market and sector involved.
Different regimes impose additional notification duties on top of the general safety requirement. Consumer connectable-product security rules require manufacturers, importers and distributors to notify specified persons, including OPSS, of certain compliance failures, and to investigate and act on failures they know or ought to know about. In Northern Ireland, the EU General Product Safety Regulation requires notifications of dangerous products to be submitted through the Safety Business Gateway. Hence, a single reporting route rarely covers every incident.
Regulators can demand continuing information well after the first report has been submitted. Under the General Product Safety Regulations 2005, an enforcement authority can require regular progress updates by way of a formal information notice, and failure to comply without reasonable cause can itself be a criminal offence. Reporting obligations therefore extend beyond announcing the defect: authorities may expect evidence on consumer contact, remediation rates, outstanding populations and whether the chosen measure is actually working.
Good governance makes notification a rehearsed process rather than an improvised one under pressure. Organisations should maintain regulator contacts, templates, escalation thresholds, responsible officers and legal review arrangements before an incident occurs. The purpose is not to delay reporting through bureaucratic processes, but to ensure that accurate technical, commercial, and traceability information can be assembled quickly. An organisation unable to identify its regulator or affected batches within days has already revealed weaknesses in its management.
Crisis Management and Consumer Communication
A serious product-safety event rapidly crosses organisational boundaries within any business of scale. Engineering investigates root causes, quality control inspects stock, procurement engages suppliers, legal teams manage liability and privilege, customer service handles incoming reports, communications teams issue warnings, and senior management decides on risk appetite and resources. These functions must operate from a single verified incident picture, since contradictory messages can undermine both consumer action and regulatory confidence.
Consumer communication should be specific enough to drive behaviour rather than merely inform. Messages need to clearly identify affected products, explain the hazard in understandable language, state whether use must stop immediately, and provide a simple remedy. Model names alone may be insufficient where ranges contain both safe and unsafe variants, so photographs, batch numbers, purchase periods and serial-number checkers can improve identification, while contact routes must handle the surge created by national publicity.
Whirlpool demonstrates the scale of outreach required when products have been in homes for years before a recall reaches them. Following Government intervention in June 2019, 140,151 additional tumble-dryer customers came forward, and the dedicated website received more than 1.4 million visits by October 2021. OPSS required wider publicity and improved outreach to vulnerable consumers, showing that publishing a recall notice is only the beginning of a much longer communication effort.
Communication also needs credibility when the underlying evidence changes mid-recall. Haier’s 2025 heat-pump tumble-dryer incident required OPSS to advise owners of more than 103,000 affected machines to stop using and unplug them pending repair. Following a technical investigation, OPSS concluded that Haier’s initial modification was unsatisfactory and issued a formal Notice to Warn. After that, a revised modification programme began, so crisis plans must accommodate changing conclusions without earlier messaging becoming an obstacle.
The best governance structure establishes an incident leadership team with clear decision rights, documented meeting records, and a single agreed-upon source of truth. Boards or executives should receive concise information on hazards, affected populations, regulator engagement, injuries, corrective actions, customer reach, supplier recovery and financial exposure. Communications should be tested against what recipients need to do, not what the organisation wishes to say, because in a safety crisis clarity and speed are themselves control measures.
The Cost of Acting Too Late
Delay allows exposure to accumulate in ways that are rarely visible until much later. Every additional unit sold, installed or used after credible warning signs appear can increase the eventual recall population, the number of incidents, and the remediation cost, and it can weaken legal arguments that reasonable care was taken. Product-safety governance therefore has to distinguish uncertainty from inaction, since organisations can still quarantine stock, suspend sales or notify regulators while evidence develops.
CASE STUDY Vauxhall’s Zafira B experience is a stark example of that distinction being missed at the time. The company sold 234,938 affected-model vehicles with manual or no air conditioning between 2005 and 2014. By 2015, a distinctive fire pattern had emerged; the London Fire Brigade reported 120 Zafira fires since 2013. Parliament later concluded that Vauxhall had been too slow to begin a full investigation and too quick to attribute the problem to unauthorised repair. |
Whirlpool provides an even more striking illustration of long-tail escalation over a decade or more. Around 5.3 million affected tumble dryers had been manufactured for the UK market, with at least 750 lint-related fires reported to Parliament. The issue was notified to the Primary Authority in August 2015. Yet, OPSS announced its intention to compel recall only in June 2019, by which time as many as 500,000 unmodified machines were still potentially in use.
The cost of delay is therefore measured in more than just pounds sterling. It includes additional injuries, emergency service incidents, customer anxiety, executive distraction, regulatory intervention, litigation, lost sales and damaged confidence in brands or public bodies. Financial consequences eventually follow through replacement, storage, destruction, legal costs and supplier disputes, but the most important loss may be preventable harm, which no subsequent settlement or insurance payment can ever fully undo for those affected.
Summary — Safety Is a Supply Chain Responsibility
Product safety is no longer confined to the factory floor or the final inspection before goods are released. Modern products pass through complex networks of designers, component suppliers, manufacturers, importers, distributors, retailers, fulfilment providers and digital marketplaces. Each participant can influence whether a product remains safe, compliant and traceable, so when failures occur, responsibility may arise at several points simultaneously through regulation, contract, negligence or statutory product liability law.
The legal framework reflects that complexity by design, not by accident. The Consumer Protection Act 1987 provides strict liability for defective products in Great Britain, while negligence and contract law remain important where fault, specifications or commercial obligations are disputed. Sector-specific legislation, the General Product Safety Regulations 2005 and the Product Regulation and Metrology Act 2025 add further layers, so compliance depends on identifying which duties apply to each product and economic actor.
Conformity assessment, testing and certification provide essential evidence, but none should be treated as a guarantee of safety on its own. UKCA and CE markings indicate compliance with applicable requirements, not that every unit is defect-free, and certificates can be outdated, inappropriate, or fraudulent, as Grenfell demonstrated on a devastating scale. Effective supplier assurance therefore depends on verification, traceability, independent scrutiny where proportionate, and continuing control over components, factories and technical documentation.
Traceability becomes critical once a defect is suspected anywhere in the chain. Batch numbers, serial numbers, supplier records, technical files, inspection reports and component provenance allow organisations to identify affected products, isolate root causes and limit recalls. Weak records create the opposite effect: uncertainty expands the population that may require withdrawal or replacement, increases remediation costs and weakens legal evidence, so product-safety information must remain accessible long after the original procurement decision.
When an incident occurs, speed and judgement matter more than either alone. Businesses must preserve evidence, assess severity and probability, identify vulnerable users, determine whether continued supply is defensible, and choose among warning, repair, withdrawal or recall. Whirlpool, Vauxhall, Haier, Grenfell, and other cases discussed throughout this article demonstrate how delayed investigation or incomplete corrective action can magnify consumer exposure, regulatory intervention and reputational damage far beyond the original defect.
The central lesson is that safety cannot be delegated upstream or assumed from paperwork alone by any single actor. Manufacturers must control design and production; importers must verify compliance; distributors and retailers must respond to warning signs; purchasers must test supplier assurance; and every organisation needs systems capable of identifying, tracing and correcting risk. Product safety is best understood as a continuous supply-chain responsibility, extending from specification and sourcing through to eventual recall.
Additional
articles can be found at Materials Management Made Easy. This site looks at the
flow of materials to assist organisations and people in increasing the quality,
efficiency, and effectiveness of their product and service supply to the
customers' delight. ©️ Materials Management Made Easy. All rights reserved.
Sources and Further Reading
Legislation
- Consumer Protection Act 1987
- Consumer Protection (Northern Ireland) Order 1987
- Sale of Goods Act 1979
- Consumer Rights Act 2015
- General Product Safety Regulations 2005 (SI 2005/1803)
- Regulation (EU) 2023/988 on General Product Safety, as applied in Northern Ireland
- Product Security and Telecommunications Infrastructure Act 2022
- Product Regulation and Metrology Act 2025
- The Noise Emission in the Environment by Equipment for Use Outdoors (Amendment and Transitional) Regulations 2025
- Directive (EU) 2024/2853 on liability for defective products
- Building Safety Act 2022
Case Law
- Donoghue v Stevenson [1932] AC 562
- A v National Blood Authority [2001] 3 All ER 289
- Abouzaid v Mothercare (UK) Ltd [2001] EWCA Civ 348
- Wilkes v DePuy International Ltd [2016] EWHC 3096 (QB)
- Gee v DePuy International Ltd (The DePuy Pinnacle Metal on Metal Hip Litigation) [2018] EWHC 1208 (QB)
- Hastings v Finsbury Orthopaedics Ltd and Stryker UK Ltd [2022] UKSC 19
- Secretary of State for Health and Social Care v PPE Medpro Ltd [2025] EWHC 2486 (Comm)
- Office for Product Safety and Standards, “OPSS Delivery Report 2025-2026”, GOV.UK
- Office for Product Safety and Standards, UK Product Safety Database, annual statistics 2025-26
- Department for Business and Trade, “The UK’s New Product Safety Framework”, consultation, March 2026
- Department for Business and Trade, market surveillance and enforcement consultation, March 2026
- Department for Business, Innovation, Science and Trade / Ministry of Housing, Communities and Local Government, Construction Products Reform White Paper, 2026
- Grenfell Tower Inquiry, Phase 2 Report, September 2024
- Medicines and Healthcare products Regulatory Agency, consultation on unique device identification, 2026
- Driver and Vehicle Standards Agency, code of practice on vehicle safety recalls
- UK Accreditation Service (UKAS), guidance on accreditation and the identification of counterfeit certificates
- Office for Product Safety and Standards, guidance on UKCA and CE marking
Further Reading
- Christopher Hodges, “European Regulation of Consumer Product Safety” (Oxford University Press)
- Simon Whittaker, “Liability for Products: English Law, French Law and European Harmonisation” (Oxford University Press)
- Michael Jones and Anthony Dugdale (eds), “Clerk & Lindsell on Torts”, chapter on product liability (Sweet & Maxwell)
- Grenfell Tower Inquiry, published reports and evidence, grenfelltowerinquiry.org.uk
- GOV.UK, “Placing manufactured goods on the market in Great Britain” guidance
- GOV.UK, Office for Product Safety and Standards, www.gov.uk/government/organisation