Auditing Cosmetics Compliance: ISO 22716, the Product Information File and the Responsible Person

Cosmetics are not authorised before they reach the EU market, and that absence of a pre-approval step misleads people about how regulated the sector actually is. Regulation (EC) No 1223/2009 replaces authorisation with accountability: a named Responsible Person, a complete file that must be produced on demand, and a manufacturing standard that authorities can and do ask you to evidence.

The Responsible Person is the audit subject

Every cosmetic product placed on the EU market must have a Responsible Person — a legal or natural person established in the Union who carries the compliance obligations. Those obligations include notifying the product through the Cosmetic Product Notification Portal before it is placed on the market, maintaining the Product Information File, ensuring labelling compliance, handling undesirable effects, and cooperating with competent authorities.

For non-EU brands using a third-party Responsible Person, this is the relationship an audit should examine first. The RP holds the legal exposure; if the arrangement is a name on a label with no substantive access to formulation, safety and manufacturing data, the compliance position is weaker than the paperwork suggests.

What a PIF audit actually examines

The Product Information File must be kept at the address shown on the label and be readily accessible to the competent authority. An audit tests whether it is complete, current and coherent — not merely whether it exists:

  • A description of the cosmetic product that genuinely corresponds to the product on sale
  • The Cosmetic Product Safety Report, with Part A data and Part B assessment signed by a qualified safety assessor
  • A description of the manufacturing method and a statement of compliance with good manufacturing practice
  • Proof of the claimed effect, where the nature of the claim justifies it
  • Data on any animal testing performed

The most frequent gap is drift. Formulations change, suppliers change, claims are refreshed for a campaign — and the file records the product as it was two years ago. A PIF that no longer matches the product is, for regulatory purposes, an incomplete PIF.

GMP for cosmetics: EN ISO 22716

The statement of GMP compliance in the PIF is a claim about your manufacturing, and EN ISO 22716:2007 is the applicable standard. It covers personnel, premises, equipment, raw materials and packaging, production, finished products, quality control laboratory, treatment of out-of-specification product, waste, subcontracting, deviations, complaints and recalls, change control, internal audit and documentation.

Competent authorities can ask for the audit records supporting that declaration. Where manufacturing is contracted out — as it very often is — the Responsible Person needs evidence that the contract manufacturer works to ISO 22716, and an audit programme covering those sites. A certificate held by the manufacturer is a starting point, not a substitute for oversight.

Cosmetovigilance is frequently the weakest area

The obligation to record and, where they are serious, notify undesirable effects to the competent authority is routinely under-resourced compared with the equivalent function in pharmaceuticals. An audit should test whether complaints arriving through customer service, retailers and social channels are actually screened for undesirable effects, whether assessment criteria are documented, whether notification timelines are met, and whether trends feed back into the safety assessment.

How PQRA helps

PQRA audits cosmetics compliance for brand owners, manufacturers and distributors: Responsible Person arrangements, PIF completeness and currency, safety assessment review, CPNP notification, claims substantiation, ISO 22716 audits of own and contract manufacturing sites, and cosmetovigilance process review. We work across the pharmaceutical, medical device and cosmetics frameworks, which matters for borderline and hybrid products.

To arrange a cosmetics compliance audit or review your Responsible Person arrangements, contact PQRA.

CATEGORIES:

Uncategorized

Tags:

No responses yet

Leave a Reply

Your email address will not be published. Required fields are marked *