Although the process may seem finished once the CE mark is affixed to a product, in reality the manufacturer's responsibility enters a new phase once the product is placed on the market: market surveillance and audit. Competent authorities check, through periodic or complaint-driven audits, whether products within CE scope genuinely carry the declared conformity. In this article we cover how CE audits work, which documents and product characteristics are examined, the sanctions that can follow an audit, and how companies can prepare for one.
How Do Market Surveillance and Audits Work?
The core philosophy of CE legislation is not that products receive approval from a state authority before being placed on the market, but that the manufacturer ensures conformity under its own responsibility. However, for this self-declaration model to remain trustworthy, products placed on the market must subsequently be audited. This audit function is carried out by a mechanism called "market surveillance." Competent authorities can audit based on a complaint, through random sampling, through risk-based prioritization, or in cooperation with customs authorities at the point of import.
Types of Audits
In practice, three main types of audits are encountered. Market surveillance audits are checks the competent authority carries out directly with the manufacturer, importer or distributor while the product is already on the market. Customs audits take place in the form of document and label checks as the product enters through the EU or Turkish customs border, and can lead to the goods being held at customs in case of suspected non-conformity. The third type is customer or business partner audits; corporate buyers in particular may request the CE file from their suppliers as part of their own internal control processes before an audit.
Documents Examined During an Audit
The first document usually requested during an audit is the EU Declaration of Conformity, because this document is a summary indicator of which legislation the product is assessed under. Following the declaration, the relevant sections of the technical file, the risk analysis report, the list of applied harmonized standards, laboratory test reports (if any), the user manual and (where applicable) the notified body certificate may be requested. Auditors pay particular attention to whether the declared standards are consistent with the test reports in the technical file, whether the hazards identified in the risk analysis have actually been mitigated in the design, and whether the user manual is complete and in the language of the target market.
Physical Checks Carried Out on the Product
In addition to document review, auditors also physically examine the product itself: whether the CE mark is affixed with the correct proportions and visibility, whether the mandatory labeling information required on the product (manufacturer name, model/type, serial number, year of manufacture) is complete, whether safety warning labels are legible, and whether physical protection devices (guards, emergency stop buttons, grounding, etc.), if any, are present. In case of serious doubt, the product may be taken as a sample and retested at an independent laboratory.
Sanctions That Can Result From an Audit
Different outcomes can arise depending on the severity of the non-conformity found. For minor deficiencies, the manufacturer may be given an opportunity to correct them within a specific period. In more serious cases, the product's placement on the market may be temporarily suspended, existing stock may be recalled from the market, or an administrative fine may be applied. If the product is found to pose a serious health and safety risk, the matter may also be notified to the market surveillance authorities of other EU member states. For details on these risks, see also our article Can a Product Be Sold Without CE Certification?.
Audit Frequency and Risk-Based Approach
Because their resources are limited, market surveillance authorities cannot audit every product at the same frequency; for this reason, modern market surveillance practice increasingly relies on a risk-based approach. High-risk product categories (for example certain machinery groups, electrical consumer products), product groups that have received numerous complaints in the past, or categories with high import volume stand out in audit prioritization. In addition, a competitor complaint, an accident report, or a safety complaint that spreads on social media can directly bring a specific product onto the audit agenda. For this reason, the assumption "audits are rare in our sector" can be misleading; audit intensity can change quickly when the risk profile changes.
Sector-Specific Audit Priorities
What is examined during audits can differ by sector. For machinery and mechanical equipment, auditors particularly focus on access distances to moving parts, the functionality of emergency stop devices, and stability performance. For electrical consumer products, grounding, insulation and overheating risks come to the fore. For devices with wireless communication features, frequency band compliance and transmission power limits are at the center of the audit. A company knowing the typical audit priorities in its own sector allows it to focus its internal control processes on these points and be better prepared for an audit.
Why Does the Company's Attitude During an Audit Matter?
The outcome of an audit process is affected not only by the completeness of the documents but also by the company's attitude during the audit. Cooperating with the auditor, providing the requested documents within a reasonable time, and accepting minor deficiencies found with a commitment to correct them rather than becoming defensive, generally makes the process easier. Conversely, delaying documents, providing incomplete information, or avoiding cooperation with the auditor can cause a minor non-conformity to turn into a larger administrative action.
Internal Audit and a Culture of Self-Checking
The best way to prepare for an audit is to internally audit your own CE file periodically, without waiting for an official audit. This internal check should cover, at least once a year, a systematic review of whether the declared standards for each product family are current, whether test reports match the current product revision, whether the user manual is up to date, and the physical application of the CE mark. Companies that build this kind of internal audit culture generally encounter far fewer surprises when faced with an official audit, because potential deficiencies have already been identified and corrected in advance. The internal audit process itself can also be regarded as evidence of the company's diligence in conformity management during a possible external audit.
Post-Audit Process and Corrective Action Follow-Up
The process is not considered finished once an audit is completed and findings are reported. The company is expected to prepare a concrete corrective action plan for each finding, share the implementation timeline of this plan with the authority, and submit documents proving the correction has actually been completed (such as a revised manual, an updated label, or a new test report). Loosely following up on corrective action can lead to the same finding resurfacing at the next audit and reduce the authority's trust in the company.
The Role of the Company's Representative During an Audit
The technical competence of the person representing the company during an audit directly affects how smoothly the process flows. Ideally this person should be someone close to the quality or engineering function who knows which standards the product was designed to, where and how the technical file is stored, which tests were carried out, and the status of the notified body process, if any. Encountering a situation like "the person who knows about this is not in the office right now" during an audit can cause the audit to drag on unnecessarily and create a negative impression with the authority. For this reason, companies are advised to clarify in advance who will be the audit point of contact for each product group and to ensure that person is well versed in the CE file.
Where Audit Readiness Fits in the CE Process
Being audit-ready is not really a separate add-on to the CE certification process but a natural extension of it; when the technical file, test reports and declaration of conformity are prepared correctly and completely, audit readiness is already largely achieved. For this reason, instead of the approach "let's get CE first, we'll think about how to prepare for an audit later," asking the question "would this document hold up if questioned during an audit?" from the very start of the process means both a more robust file and less audit stress. For a holistic view of the process alongside its other steps, see our article The CE Certification Process, Step by Step.
Relevant Directives and Standards
The legal framework for market surveillance rests on Regulation (EC) No 765/2008, which forms the general backbone of CE legislation, and Regulation (EU) 2019/1020 on Market Surveillance and Compliance of Products, which updated that regulation's market surveillance provisions. For consumer-facing products, Regulation (EU) 2023/988 on General Product Safety also regulates, in a complementary way, the powers of surveillance authorities and companies' obligations. Product-specific directives or regulations (Machinery Directive 2006/42/EC, Low Voltage Directive 2014/35/EU, Radio Equipment Directive 2014/53/EU) define which technical requirements are checked during an audit. In Türkiye, this framework is implemented at the national level, within the Customs Union, through the market surveillance and inspection (PGD) legislation carried out by the relevant ministries.
| Document Requested in an Audit | What It Proves |
|---|---|
| EU Declaration of Conformity | Which legislation the product is assessed under, and the general declaration of conformity |
| Technical file (relevant sections) | The existence of design, calculation and test evidence |
| Risk analysis report | That hazards have been systematically identified and mitigated |
| Laboratory test reports | That the declared standards are actually being met |
| User manual | That the user information obligation has been fulfilled |
| Notified body certificate (if any) | That the independent third-party assessment has been completed |
Step-by-Step Process
- Gather your product's CE file (declaration, technical file, test reports, manual) into a single accessible archive.
- Periodically review the consistency between the declared standards and the test reports in the technical file.
- Verify that the user manual matches the current product version and is in the language of the target market.
- Check that the CE mark and mandatory labeling information on the product are physically complete.
- Assign internal responsibility for tracking complaints and non-conformity reports.
- Establish a communication and archiving procedure that can present documents within a reasonable time when an audit request arrives.
- Proactively correct minor deficiencies identified without waiting for an audit.
- If you see a risk of serious non-conformity, prepare a corrective action plan in advance.
Most Common Mistakes
- Preparing the CE file only once, when the product is placed on the market, and never updating it afterward.
- Responding to an audit request late or with incomplete documents.
- Letting the user manual fall out of sync with the current product revision.
- Neglecting the physical visibility and proportions of the CE mark on the product.
- Dismissing a minor audit finding and postponing the correction.
- Keeping the technical file with a single person or in a hard-to-access system.
- Prolonging the process by avoiding cooperation with the auditing authority.
Frequently Asked Questions
Who carries out CE audits?
In Türkiye, the relevant ministries and market surveillance authorities authorized for each product group carry out the audit; customs administrations can also carry out document checks at the import stage.
Is the entire technical file requested during an audit?
Usually summary information and the EU Declaration of Conformity are requested first; in case of doubt or non-conformity, the entire technical file, including risk analysis and test reports, may be requested.
Is notice given before an audit?
Market surveillance audits are mostly carried out without prior notice; therefore companies are advised to keep their documents constantly ready and up to date, rather than waiting for the moment of the audit.
Does the technical file have to be in Turkish?
User-facing documents such as the user manual and declaration of conformity are expected to be in Turkish; the entire technical file does not always have to be in Turkish, but it must be presented in a language and format the auditing authority can reasonably review.
What happens if non-conformity is found during an audit?
Depending on the severity of the non-conformity, the manufacturer may be given time to correct it, the product's placement on the market may be temporarily suspended, the product may be recalled, or an administrative sanction may be applied.
If the CE mark is correct but the technical file is incomplete, can the product be recalled?
Yes, the CE mark being physically correct is not sufficient on its own; if supporting documents such as the technical file and declaration of conformity cannot be provided when requested, the product may be deemed non-conforming and sanctions, including recall, may be applied.
Is a laboratory test redone during an audit?
Existing test reports are usually reviewed first; however, if the authority has serious doubts, it may take the product as a sample and have it retested at an independent laboratory.
Can an importer be held responsible instead of the manufacturer during an audit?
Although the manufacturer is primarily responsible, if the importer cannot obtain or verify the manufacturer's documents, it may face administrative sanctions for its own share of obligations. See our article What Are a Machine Manufacturer's Legal Responsibilities? for details.
Is there a right to appeal an audit report?
Yes, appeal and legal remedies provided for in legislation can be pursued against administrative actions; but supporting technical justifications with solid documentation is also crucial during the appeal process.
Is the content of the user manual also checked during an audit?
Yes, whether the user manual's language, content and the minimum elements required by legislation are present is one of the points frequently checked in audits.
Are small companies exempt from audit scope?
No, audit scope is not determined by company size; any company placing a product within CE scope on the market can be subject to audit.
How can companies internally audit their own CE files?
An internal audit can be carried out by periodically (for example, once a year) and systematically reviewing, for each product family, whether the declared standards are up to date, whether test reports match the current revision, whether the user manual is current, and how the CE mark is physically applied.
Is the process completely over once an audit finding is closed?
No, documents proving the corrective action has actually been implemented must be submitted to the authority, and the process must be monitored so similar findings do not recur; otherwise the same finding may resurface in the next audit.
Conclusion
CE audits are the security mechanism that verifies whether a product a manufacturer placed on the market through self-declaration genuinely carries the declared conformity. The way to be audit-ready is not to wait for the moment of the audit, but to keep documents current and accessible from the very first day the product is placed on the market. This approach both reduces the risk of potential sanctions and strengthens the company's credibility in the market. Being audit-ready is actually an indicator of the quality of the CE process; a company whose file is open to audit at any time has generally also managed the entire process, from design to market placement, more robustly. For companies that adopt this perspective, an audit stops being a feared event and becomes a routine checkpoint that confirms existing practices.
If you're not sure how audit-ready you are, let's review your current file together. For more information, see our CE consultancy service.
Get a Free Preliminary Assessment