Supplier certificates: manufacturing's quiet counterfeit problem
Counterfeit parts enter factories through paperwork, and deep cross referencing of every supplier certificate at receiving, on your own hardware, is the defence that works.

Counterfeit and non conforming parts enter manufacturing supply chains through the receiving desk, and the most effective defence is deep review of every supplier certificate, cross referenced against the records behind it, before a part goes anywhere near production. Automotive and aerospace quality systems already assume this discipline. IATF 16949 in automotive and AS9120 in aerospace distribution both rest on supplier certifications and material certificates that someone is supposed to verify at receiving. In practice that verification is often a glance, because a person facing a pallet of deliveries and a stack of paperwork cannot check everything against everything. That gap is manufacturing's quiet counterfeit problem.
Why do counterfeit parts keep getting past receiving inspection?
Because paperwork passes inspection more easily than parts do. Physical checks catch the dented crate and the wrong finish, but a plausible certificate sails through, and fraudulent documentation is designed to be plausible. The logo is right, the format is right, the signature looks authentic. What gives a forged certificate away is almost never its face. It is the record behind it that does not add up: a heat number no mill issued, a certificate number that does not match the purchase order, a signatory with no authority on file. Finding that mismatch takes cross referencing, and an inspector working through dozens of deliveries in a shift rarely has time to do it for every line.
What do IATF 16949 and AS9120 actually expect at receiving?
Both standards make conformity of incoming product the organisation's responsibility, not the supplier's word. IATF 16949, published by the International Automotive Task Force, requires manufacturers to verify that purchased product conforms to requirements and to monitor supplier performance, inheriting the ISO 9001 principle that certificates are evidence to be evaluated, not accepted on trust. AS9120, the SAE quality standard for aerospace stockist distributors, exists largely because parts change hands many times between manufacturer and installer, and every change of hands is a place where traceability can break or be broken. Under either regime, the moment you accept a part, your quality system owns it.
Has certificate fraud actually reached serious industries?
Yes, and aviation is the clearest recent example. In 2023 the aviation press widely reported that a parts distributor, AOG Technics, had supplied engine parts with forged release certification, and that the fraud surfaced when an engineer questioned the provenance of a single document. The details belong to aviation, but the failure mode does not. Material certificates, test reports and certificates of conformity are trusted the same way across automotive, energy, rail and general manufacturing, and counterfeit parts remain a documented risk across those supply chains. Wherever a certificate is accepted at face value, the receiving desk is an open door.
How does deep certificate review work in practice?
Our platform reads the incoming documentation package as a whole rather than as a stack of separate files. It cross references each certificate against the records behind it, drafts the receiving paperwork for the lines that reconcile, and holds every anomaly for a person to disposition. On a typical goods receipt, the checks include:
- Certificate identity against the purchase order, part number, revision and quantity actually received
- Material grade and specification against the engineering requirements on the drawing or bill of materials
- Heat, lot or batch numbers against the mill or manufacturer certificates further up the chain
- The issuing organisation and signatory against approved supplier and delegation records
- Dates, revisions and quantities across the whole package for internal coherence
When a certificate does not reconcile, the part is held before it enters stores and the anomaly goes to a quality engineer with the full cross reference laid out. The person keeps disposition and sign off. Every review, every hold and every clearance is sealed to the Open Audit Record before it runs, so the trail exists whether the part was accepted, quarantined or returned.
“A forged certificate is a supply chain attack on paper, and the defence is depth of review at the point of entry. Machines are patient enough to check every document against every record behind it. People stay in charge of what happens next.”
Why does this have to run on our own hardware?
Because your receiving documentation is a map of your business. Supplier lists, negotiated prices, bills of materials, volumes and traceability chains describe exactly what you build, who you buy from and at what cost. Sending that stream to a third party cloud service is a commercial exposure many manufacturers will not accept, and for defence adjacent suppliers it can raise export control questions too. Mickai is a Sovereign Intelligence Operating System that runs entirely on hardware you own, on premise and air gapped, so no document, prompt or result ever leaves the building. Every action is sealed to the Open Audit Record before it runs, and consequential actions wait for a person's clearance.
What does provable receiving review mean for audits and customers?
It turns quality claims into standing evidence. When a customer, certification body or regulator asks how you assure incoming product conformity, the honest answer today is often a procedure document and a sample of records assembled for the visit. With every certificate check sealed as it happened, the answer becomes the record itself: what was reviewed, what it was checked against, which anomalies were held, and who cleared each disposition. That is a stronger position in any audit, and a stronger position after an escape, when the question is whether your controls were real.
Counterfeit pressure on supply chains is not easing, and the paperwork guarding the door is only getting heavier. We expect customers and certification bodies to move from asking whether you review supplier certificates to asking whether you can prove the depth of that review. Manufacturers who put patient, sovereign cross referencing at the receiving dock will answer with evidence rather than assurance.
Frequently asked questions
What is a supplier certificate?
A supplier certificate is a document attesting that a delivered part or material conforms to requirements, such as a certificate of conformity, a mill test certificate or an aerospace release certificate. Quality systems treat it as objective evidence, which is why forging one is such an effective way to move a counterfeit part into production.
Can the system reject a suspect part automatically?
No. When a certificate does not reconcile with the records behind it, the part and its paperwork are held and the anomaly is raised to a person with the full cross reference attached. Disposition, whether acceptance, quarantine or return, always belongs to your quality engineer, and that decision is sealed to the Open Audit Record.
Does this replace receiving inspectors or quality engineers?
No. It does the first pass, the reading and cross referencing no person has time to do exhaustively, and it drafts the routine paperwork. Inspectors and quality engineers keep judgement, disposition and sign off, and spend their time on the anomalies that matter.
Do our supplier documents leave our site?
No. Everything runs on hardware you own, on premise and fully air gapped. Supplier names, prices, bills of materials and traceability records never pass to us or to any third party, and the audit trail of every review is verifiable offline on your own estate.
What is MICKAI?
MICKAI is a Sovereign Intelligence Operating System, a SIOS, that runs entirely on the customer's own hardware, on premise and air gapped. Its studios and subsystems work over a cooperative multi-model consensus substrate, and every action is sealed to the Open Audit Record, a cryptographically signed, post quantum, tamper evident record created before an action runs and verifiable offline. There are 87 studios, with ten production ready at launch and 77 in development. Mickai LTD has filed 104 UK patent applications across 2,340 claims, filed rather than granted.