Quality and governance

Quality and governance.

How CIG keeps every dossier we deliver accurate, accountable and able to withstand regulatory scrutiny.

Regulatory compliance is only worth having if it holds up when it is tested. A Responsible Person accepts legal responsibility for a product on a market, and a safety report can be called on years after a product launches. Our governance keeps the work we deliver defensible at every point. The four commitments below apply to every product we handle, across all four markets we cover: the EU, the UK, Switzerland and the United States.

Under EU Regulation 1223/2009, the Responsible Person holds the Product Information File, verifies the safety report, manages notifications, reviews labelling and claims, and is the named contact for authorities during a market-surveillance check or a recall. The Product Information File must be kept for ten years after the last batch of a product was placed on the market. That is the real span of the responsibility. A dossier we produce today has to still stand up to inspection a decade from now, when the person who wrote it may no longer be at their desk and memory is no substitute for a written record. Everything on this page describes how we make that possible.

Regulatory dossiers under review, governance banner

Four commitments

The governance behind every dossier.

1

Qualified assessor sign-off

Every Cosmetic Product Safety Report is reviewed and signed by a qualified safety assessor. This is not a formality. Under EU Regulation 1223/2009, the Part B safety assessment can only be signed by a person holding a university diploma in pharmacy, toxicology, medicine, or a similar discipline recognised by an EU Member State. The assessor's name, address, qualification, date and signature form part of the report itself. Switzerland requires a qualified safety assessor on the same terms.

The conclusion the assessor signs rests on the Part A safety information: the qualitative and quantitative composition, the physico-chemical and microbiological data including challenge testing, impurities and packaging, exposure and use, the toxicological profile, and any undesirable effects. From that the assessor reasons to a Margin of Safety and a conclusion. We do not deliver a safety conclusion that a qualified assessor has not personally read and signed, and a safety report written for another market does not carry over: a US report cannot be reused as an EU CPSR, and the assessment is redone in the correct format for the market you are entering.

2

Professional-indemnity insurance

Acting as a Responsible Person means accepting real legal responsibility for a product on a market. That responsibility is continuous. It stays active for the whole time the product is on the market, not just at the moment of filing, and the Responsible Person remains the official point of contact for authorities if a problem surfaces years later.

We carry professional-indemnity insurance for the Responsible Person role, so the responsibility we take on for your brand is properly backed. Some brands are told an importer or distributor can simply be named as their Responsible Person. That works legally, but it puts the role in the hands of a party whose main business is something else, and who may not carry insurance for it or hold the dossier securely. We take the role as our own work and insure it accordingly.

3

Full audit trail

Every dossier we produce carries a complete decision log. If a regulator asks how a conclusion was reached, or why a particular ingredient was accepted at a given concentration, the record is there in writing rather than in someone's recollection. This matters most in the two markets that rely on inspection rather than a filing portal. Switzerland has no pre-market notification: cantonal laboratories carry out post-market inspections and a brand must hold a continuously up-to-date self-monitoring dossier and hand it over on request. Under MoCRA, the Responsible Person must keep safety substantiation on file for every product, and adverse-event records for years.

An incomplete or missing Product Information File is one of the recurring reasons cosmetics are pulled from the EU market. A clear, dated decision log is what keeps a file complete over the ten years it has to survive, and it is standard on every dossier we deliver.

4

Human confirmation before filing

No notification is ever submitted in your name without a person confirming it first. Notification is required before a product is placed on the market: through CPNP under Article 13 for the EU, through SCPN via OPSS for Great Britain, and through the FDA product listing under MoCRA for the United States. Each portal takes exact data, and each is legally the RP's submission to make.

Filing is a deliberate, confirmed step that a person signs off, so an error is caught before it becomes an entry a regulator sees. You review what will be filed and confirm it, and only then does it go. You stay in control of exactly what is filed for your brand and when.

What the governance covers

Three documents, each held to the same standard.

Brands often treat the safety report, the file, and the notification as one thing. They are three distinct pieces of work, and each is where a compliance problem tends to start. Our governance applies to all three.

The safety report (CPSR)

The Cosmetic Product Safety Report is the signed judgement that a product is safe for its intended use. It has two parts: Part A, the safety information gathered on the product, and Part B, the assessment and conclusion. Only a qualified safety assessor can sign Part B. This is the hard bottleneck in any cosmetic launch, and the point where our first commitment applies directly.

The Product Information File (PIF)

The PIF is the full technical file behind a product. Under Article 11 it contains the product description, the CPSR, the manufacturing method with a GMP statement to ISO 22716, proof of any claimed effect, and data on any animal testing. It is kept for ten years after the last batch was placed on the market and must be produced for authorities on request. Our audit trail is what keeps it complete over that span.

The notification

Notification tells the authority a product exists and where its file is held. It goes through CPNP for the EU, SCPN via OPSS for Great Britain, and the FDA product listing for the United States. CPNP and SCPN are separate systems that do not exchange data, so an EU notification does nothing for the UK. Each filing is confirmed by a person before it is submitted in your name.

A common assumption is that notifying one portal covers more than one market. It does not. A brand selling into both the EU and Great Britain needs a Responsible Person established in each, and a separate notification in each system. Northern Ireland follows the EU route under the Windsor Framework, not the Great Britain route. We hold every one of these files to the four commitments above, whichever markets you sell into.

Why this matters

A dossier you can put in front of a regulator with confidence.

These commitments are the reason brands can rely on what we deliver.

Most cosmetic recalls and market-surveillance findings trace back to a small set of causes: an ingredient that is prohibited or restricted, a Product Information File that is incomplete or missing, contamination, a product that was never notified, or a claim on the label that cannot be substantiated under Article 19. Governance is how each of those is caught before a product ships, not after a regulator has already found it. A signed safety report addresses the ingredient and safety questions. A complete, audited file addresses the missing-PIF failure. Confirmed filing addresses the products that simply never got notified.

What our governance gives you
Compliance accountable to a named professional.
A Responsible Person role that is properly insured.
A fully documented decision log on every file.
Filing kept under human control, confirmed before submission.
A signed compliance dossier on a desk

Together they keep your compliance accountable to a named professional, properly insured and documented, with filing under human control. That is what a CIG dossier is built to be: a file a regulator can examine and a file that holds. Every person who works on it, employee, contractor, or engaged safety assessor, works under our Code of Conduct.

FAQ

Common questions about our governance.

A qualified safety assessor. For the EU and Switzerland, that means a person holding a university diploma in pharmacy, toxicology, medicine, or a similar recognised discipline. Their name, qualification, date and signature appear in Part B of the report. The safety conclusion is always made by a named professional, not left unsigned.

No. A safety report prepared for one market does not transfer to another. Even with existing documentation, the assessment is redone in the correct format for the market you are entering, and signed by a qualified assessor for that market.

Yes. We carry professional-indemnity insurance for the Responsible Person role. Acting as the Responsible Person means accepting real legal responsibility for your product on a market, and that responsibility continues for as long as the product is sold, so it is backed by insurance rather than taken on informally.

That is what it is for. Every dossier carries a dated decision log recording how conclusions were reached and how ingredients were assessed. If an authority asks, the record is there in writing. This matters most in Switzerland, where cantonal laboratories inspect after market entry, and under MoCRA, where safety substantiation must be kept on file.

No. Every notification, whether through CPNP, SCPN or the FDA product listing, is confirmed by a person before it is submitted. You review what will be filed and confirm it first. Nothing goes to a portal in your name without that step.

The Product Information File must be kept for ten years after the last batch of a product was placed on the market, and be available to authorities on request. Our audit trail is what keeps that file complete and defensible over the full period.

No. CPNP for the EU and SCPN for Great Britain are separate systems that do not exchange data, and each market needs its own established Responsible Person. Northern Ireland follows the EU route under the Windsor Framework. We can hold the files and notifications for each market you sell into under one relationship.

Ready to sell in more markets?

Tell us your products and the markets you are entering. You will receive a fixed quote and a clear path to compliance.

In practice

Compliance, in the real world.

A signed compliance dossier archive
Audit checklist on a clipboard beside productsRecords room of maintained product files