Skip to content
Industry10 min read

Fake RCM Certificates and Supplier Compliance Fraud in Australia

How fraudsters forge RCM marks, SDoCs and AS/NZS test reports to pass Australian procurement checks, and how compliance teams catch fake RCM certificate fraud.

CheckFile Team
CheckFile Teamยท
Illustration for Fake RCM Certificates and Supplier Compliance Fraud in Australia โ€” Industry

Summarize this article with

A fake RCM certificate is a Regulatory Compliance Mark, Supplier's Declaration of Conformity (SDoC), or product test report that has been edited, fabricated, or copied from an unrelated product to prove a supplier's goods can legally be sold in Australia. Australia has no CE marking; the certification landscape a procurement team verifies instead is a self-declared RCM for electrical and radiocommunications equipment, mandatory ACCC safety standards under the Australian Consumer Law, and the AS/NZS standards published by Standards Australia that underpin most of it. This is the fraud-detection companion to our guide on vendor compliance certificate verification, which covers tax, insurance and WHS documentation; this article focuses on product-safety and conformity paperwork submitted during supplier onboarding.

This article is for informational purposes only and does not constitute legal or regulatory advice. Consult a compliance professional or product safety lawyer for guidance specific to your organisation. Legislation and guidance referenced are current as of 27 August 2026.

What an RCM and an SDoC Actually Prove

The Regulatory Compliance Mark is not issued or checked by a government body before it appears on a product. It is a self-declaration system: the supplier works out which ACMA technical standards apply, arranges testing, signs a Supplier's Declaration of Conformity, keeps the evidence in a compliance folder, and registers as a "responsible supplier" on the national EESS database before applying the mark (ACMA, Step 5: label your product). No inspector checks the physical product first.

That matters for procurement because a genuine-looking RCM label proves almost nothing alone โ€” it is the paperwork behind it, not the printed symbol, that carries evidentiary weight. A separate, often-confused regime covers mandatory product safety standards under the Australian Consumer Law, enforced by the ACCC, applying to categories such as children's products, button batteries and certain electrical goods regardless of RCM (ACCC, Product safety standards and how to comply). A supplier can hold a valid RCM registration and still breach an ACCC mandatory standard, or vice versa โ€” treating the two as interchangeable is a common onboarding mistake, unrelated to fraud.

How Fraudsters Forge or Misuse Compliance Documentation

Editing a genuine SDoC template is the most common method, because these are plain PDFs or Word documents with no watermark. A fraudster takes a real declaration from a similar product, changes the model number, standards cited, and supplier details, and presents it as current โ€” banking on the reviewer not requesting the underlying test report.

Applying an RCM label without ever registering on the EESS database is a second pattern, common with imported goods sold through online marketplaces and on-sold into commercial supply chains โ€” the mark looks identical whether or not the supplier behind it actually exists in the register.

Borrowing another supplier's compliance folder is the more deliberate variant: a genuine test report for a similar but not identical product is presented as if it covers the item being supplied. This survives casual review because the report is authentic โ€” it just does not cover the product on the purchase order.

Citing an outdated or withdrawn AS/NZS standard is a subtler fourth pattern: a declaration referencing a superseded edition can look technically compliant on paper while the product never underwent testing against the standard actually current at the time of supply (Standards Australia).

Real-World Schemes This Enables

Lithium-ion power banks and chargers are the highest-profile current example. Fire-risk recalls affecting well-known brands have run alongside a wave of unbranded imports carrying paperwork that does not match the cells actually inside the device. The ACCC estimates around 650 product recalls are notified each year, with roughly 1.7 million recalled products โ€” close to one in four Australian households โ€” still sitting unreturned in homes (ACCC, Over a million recalled products still in circulation in Australia). Each passed some onboarding checkpoint before reaching a shelf.

Construction is a second recurring pattern: forged or mismatched compliance documentation on electrical fittings, cabling and other building products lets non-conforming stock into a project before a defect surfaces, an issue the Australian Building Codes Board tracks closely (ABCB, Non-conforming building products). Head contractors verifying subcontractor and materials paperwork for construction and civil works face this at scale โ€” a single forged declaration can sit behind hundreds of units already installed before it is caught. Toy and children's product imports round out the pattern, where a forged safety declaration is often the only thing standing between a genuinely tested product and one that has never been near a laboratory.

Ready to automate your checks?

Free pilot with your own documents. Results in 48h.

Request a free pilot

Detection Techniques That Actually Work

The starting point is requesting the full compliance folder, not just the SDoC. A genuine folder includes a test report from an accredited laboratory, a risk assessment, and the signed declaration โ€” a supplier who can only produce the declaration itself has not actually demonstrated compliance.

Checking the EESS national database confirms whether the supplier is registered as a responsible supplier for the product category; an unregistered name on an SDoC is one of the clearest signs the label was applied without completing the process. Verifying the testing laboratory is accredited โ€” most credible reports cite a NATA-accredited lab or an ILAC signatory โ€” filters out reports from labs with no standing to test against the cited standard. Cross-checking the ABN against ABN Lookup is a fast independent check, and PDF metadata review often exposes a "declaration" last saved in an image editor days before submission.

Red flag Verification method What it reveals
RCM label present but supplier not listed as a responsible supplier Search the EESS national database Mark applied without completing self-declaration or registration
SDoC provided with no accompanying test report Request the full compliance folder from the supplier Declaration signed without underlying evidence of testing
Test report cites a testing lab with no visible accreditation Check NATA accreditation or ILAC signatory status Report may not carry evidentiary weight against the cited standard
Standard cited on the declaration has since been withdrawn or superseded Cross-check the standard number on Standards Australia's catalogue Product was tested against an outdated requirement, if tested at all
Model number on the report does not exactly match the product supplied Compare report specifications line-by-line against the purchase order Genuine report borrowed from a different, similar product
PDF creation or save date inconsistent with the claimed test date Inspect file metadata (creation software, save history) Document edited or fabricated after the date it claims to represent

What Procurement Teams Are Actually Asking

A recurring question among Australian compliance practitioners is whether a self-declared SDoC is ever "enough," or a formal third-party certificate should be demanded regardless. Self-declaration is legally sufficient for RCM-scope products โ€” there is no third-party certification requirement under that regime โ€” but it shifts the verification burden onto the buyer, which is why requesting the underlying test report, not just the mark, is the practical safeguard.

A second common question is who carries liability if a supplier's documentation turns out to be forged after the goods are on-sold. Liability under the Australian Consumer Law can attach to the importer or reseller, not only the original manufacturer, regardless of what paperwork the supplier presented โ€” the reason procurement teams push harder on verification rather than treating a supplied certificate as a liability shield.

Presenting a forged SDoC, test report, or fabricated RCM registration to induce a purchasing decision can constitute obtaining a financial advantage by deception under Divisions 134 and 135 of the Criminal Code Act 1995 (Cth), while altering or fabricating the document itself falls under the forgery offences in Divisions 144 and 145 of the same Code, both carrying substantial custodial penalties. State offences, such as those in the Crimes Act 1900 (NSW), can also apply where the conduct occurs wholly within a state.

Penalties for supplying goods that breach a mandatory safety standard under the Australian Consumer Law doubled from $50 million to $100 million per contravention for corporations, for conduct on or after 28 March 2026 (ACCC, Fines and penalties). That change sits within the Competition and Consumer Act 2010 (Cth), which houses the Australian Consumer Law as Schedule 2 and gives the ACCC its enforcement power over non-compliant products, forged or otherwise.

A Layered Approach to Detection

Manual detection methods, including routine visual review of documents, catch only around 37% of occupational fraud cases, with a median delay of 87 days before detection (ACFE, 2024 Report to the Nations). A well-edited SDoC or borrowed test report passes a quick visual check every time โ€” it only fails once someone cross-references the EESS database, the ABN, or the metadata against what the document claims.

CheckFile's approach layers structural analysis, metadata checks, and cross-document validation, built to cover 3,200+ document types and 32 jurisdictions. CheckFile also deploys an AI-generation detection layer as a complementary signal, not a replacement for cross-checking the underlying register or test report. A forged RCM declaration still needs its EESS registration, ABN, and cited standard checked against the primary source.

For a wider view of sector-specific supplier checks, our industry verification guide covers financing, construction and regulated services beyond product compliance, and our security page and pricing cover how CheckFile fits into an existing onboarding stack.

If your supplier onboarding still relies on a visual read of whatever compliance PDF a vendor has sent, CheckFile's AI-generated document detection adds AI-generation signals as a complement to your existing controls โ€” not a guarantee of catching every forgery, but a useful additional layer alongside EESS, ABN and standards-catalogue checks.

Frequently Asked Questions

Can a fake RCM certificate use a real product model number?

Yes. Fraudsters sometimes borrow a genuine test report for a similar product and present it as covering a different model, or reuse a real supplier's registration details while substituting the product being sold. Comparing the exact model number and specifications against the purchase order, not just the RCM label, is what catches this.

Does an RCM label mean a product was independently tested by ACMA?

No. RCM is a self-declaration scheme โ€” the supplier arranges its own testing, signs the declaration, and registers as a responsible supplier without government inspection of the physical product beforehand. Verifying compliance means checking the underlying test report and EESS registration, not just the printed mark.

What is the fastest way to check if a supplier's compliance certificate is genuine?

Search the supplier's name on the EESS national database, request the full compliance folder including the test report, and cross-check the ABN on ABN Lookup. This takes minutes and reveals far more than reading the certificate itself.

Who is liable if a supplier's forged compliance certificate reaches consumers?

Liability under the Australian Consumer Law can extend to the importer or reseller in the supply chain, not only the party that forged the original document โ€” a key reason procurement teams verify paperwork before onboarding rather than relying on it as a shield after the fact.

Is presenting a forged RCM certificate a criminal offence in Australia?

Yes. Using a forged declaration or test report to induce a purchasing decision can fall under the dishonesty and forgery offences in the Criminal Code Act 1995 (Cth). Separately, supplying goods that breach a mandatory safety standard now carries civil penalties of up to $100 million per contravention under the Australian Consumer Law.

Stay informed

Get our compliance insights and practical guides delivered to your inbox.

Ready to automate your checks?

Free pilot with your own documents. Results in 48h.