How to Use FMDs to Carry Out BOM Risk Assessments

Full material declarations are one of the best resources for compliance management. Learn how FMDs help businesses understand compliance risks across their product portfolios.

How to Use FMDs to Carry Out BOM Risk Assessments

Article Highlights:

  • Rather than simply confirming whether a part complies with a single regulation, a full material disclosure (FMD) provides the detailed substance information needed to evaluate a product against all current and future regulatory requirements.
  • A BOM risk assessment is the process of analyzing every component and material within a bill of materials, with the goal of identifying substances that may pose risks. Using FMD data, manufacturers can compare the substances in each part against regulations such as RoHS, REACH, California Proposition 65, and PFAS restrictions to pinpoint instances of noncompliance.
  • Without FMDs, organizations often depend on spreadsheets, supplier emails, PDFs, and individual declarations that only answer one regulatory question at a time. This creates a number of different challenges.

Manufacturers today face a growing list of product compliance obligations. Regulations such as RoHS, REACH, California Proposition 65, and PFAS reporting laws require companies to understand exactly what substances are present in their products. For organizations with thousands of parts, manually reviewing supplier documentation is no longer practical.

This is why full material disclosures (FMDs) are arguably one of the most valuable sources of compliance data. Rather than simply confirming whether a part complies with a single regulation, an FMD provides the detailed substance information needed to evaluate a product against all current and future regulatory requirements. When paired with a structured bill of material (BOM) risk assessment, FMDs allow companies to identify material compliance risks early, prioritize supplier outreach, and continuously monitor products as regulations evolve.

This guide explains what a BOM risk assessment is, how full material disclosure data supports it, and the workflow manufacturers can use to identify compliance risks across their entire bill of materials.

What Is a BOM Risk Assessment?

A BOM risk assessment is the process of analyzing every component and material within a bill of materials, with the goal of identifying substances that may create regulatory, environmental, or supply chain compliance risks. Using full material disclosure data, manufacturers can compare the substances in each part against regulations and pinpoint instances of noncompliance.

A bill of materials risk assessment goes far beyond checking whether a supplier has marked a part as compliant. Instead, it evaluates the actual material composition of every component, allowing organizations to answer a myriad of additional questions:

  • Does this product contain restricted substances?
  • Are any substances approaching regulatory thresholds?
  • Which suppliers require updated declarations?
  • Which parts present the highest material compliance risk?
  • How will future regulatory updates affect this product?

The more detailed the material information is, the more accurate and proactive the assessment becomes.

What Is a Full Material Disclosure (FMD)?

Often referred to as an FMD, a full material disclosure is a detailed declaration that identifies the materials and substances contained within a product or component. (FMDs typically go down to the homogeneous material level.) Unlike a simple compliance certificate, an FMD provides the actual chemical composition used to manufacture a part.

Instead of stating that a product complies with RoHS or REACH, an FMD answers questions such as:

  • Which substances are present?
  • What are their concentrations?
  • Where are they located within the part?
  • Which homogeneous materials contain them?

Because the data is substance-based, rather than regulation-specific, manufacturers can analyze the same FMD to evaluate compliance against many different regulations. This makes FMDs one of the most valuable datasets available for product compliance programs.

FMD vs. SDS vs. RCD

Three different types of documents, FMDs, SDSs, and RCDs, are often confused for one another. And while they all relate to chemical information, they serve very different purposes.

  • Full Material Disclosure (FMD): Lists the materials and substances present in a finished part or component to support product compliance and BOM screening.
  • Safety Data Sheet (SDS): Communicates workplace handling, storage, transportation, and safety information for chemicals or mixtures. It is intended for occupational safety, not product compliance.
  • Regulatory Compliance Declaration (RCD): States whether a product complies with one or more specific regulations, usually without providing detailed substance composition. Can be a certificate of compliance (CoC), a Declaration of conformity (DOC), or other compliance document.

An SDS may indicate hazards associated with a chemical during manufacturing or handling, but it's not generally used to determine whether a finished electronic component complies with RoHS or REACH. Likewise, an RCD may simply state that a supplier complies with a regulation without explaining why. For comprehensive RoHS and REACH screenings, an FMD provides the detailed substance-level information needed for meaningful analysis.

Data Standards Behind FMDs

Several industry standards make FMDs easier to exchange electronically between suppliers and manufacturers.

IPC 1752A

IPC 1752A is one of the most widely adopted standards for communicating material declaration data within the electronics industry. It defines standardized declaration formats that suppliers can use when reporting substance information. Many organizations exchange this information using IPC 1752A XML, which allows compliance software to automatically import and analyze supplier declarations, rather than relying on manual data entry.

IEC 62474

IEC 62474 provides the internationally recognized declarable substance list used by many manufacturers. It defines which substances should be reported and establishes consistent terminology that improves data quality across the supply chain.

Together, IPC 1752A and IEC 62474 enable suppliers and manufacturers to exchange consistent material declarations that support automated compliance workflows.

Why FMDs Are Central to BOM Risk Assessment

Without FMDs, organizations often depend on spreadsheets, supplier emails, PDFs, and individual declarations that only answer one regulatory question at a time. This creates several challenges.

A supplier may confirm RoHS compliance but provide no information about PFAS, Proposition 65, or future REACH SVHC additions. When regulations change, manufacturers must begin another round of supplier outreach, costing them precious time and team bandwidth. An FMD streamlines this process because it captures the underlying substance data.

This allows manufacturers to:

  • Screen one dataset against multiple regulations.
  • Identify risks before products reach the market.
  • Reuse supplier data as regulations evolve.
  • Reduce repeated supplier outreach.
  • Automate compliance assessments across thousands of parts.

Compared to manually reviewing SDS documents or repeatedly requesting supplier declarations, FMD-based workflows are significantly faster and more efficient. Not to be overlooked, they also serve as a single source of truth for material compliance, cutting out the chance for discrepancies to creep in and jeopardize regulatory adherence.

How to Use FMDs to Assess BOM Risk

Step 1: Collect FMDs Across Every BOM Tier

The first step is obtaining FMDs from suppliers throughout the supply chain.

Although direct suppliers often provide declarations, many compliance risks originate deeper in the supply chain, where subcomponents and raw materials are sourced. Whenever possible, organizations should collect FMDs for every purchased component and ensure declarations cover all homogeneous materials within each part. Using standardized formats such as IPC 1752A XML greatly simplifies this process because the data can be imported directly into compliance management systems without manual transcription.

Step 2: Map Substances to Regulatory Lists

Once FMDs have been collected, every reported substance should be compared against applicable regulatory requirements.

Common regulatory lists include:

  • RoHS restricted substances
  • REACH Candidate List substances of very high concern (SVHC)
  • California Proposition 65 chemicals
  • PFAS reporting requirements
  • POPs substances
  • TSCA restrictions
  • Customer-specific restricted substance lists

Because FMDs identify actual chemical substances rather than simply indicating compliance, one declaration can be screened against many regulations simultaneously.

Step 3: Flag Restricted Substances

After regulatory mapping, organizations can identify substances that exceed applicable concentration limits, trigger reporting obligations, or are banned entirely.

For example, screening may identify the following:

  • Lead exceeding RoHS thresholds.
  • An SVHC above the REACH reporting threshold.
  • A PFAS substance requiring state reporting.
  • A Proposition 65 chemical requiring additional evaluation.
  • A substance restricted under customer specifications.

Rather than reviewing every part individually, automated screenings quickly identify only the components requiring attention. This dramatically reduces the amount of manual review needed.

Step 4: Prioritize High-Risk Parts

Not every compliance issue presents the same level of risk. Organizations should prioritize components based on several factors, including:

  • Regulatory severity
  • Concentration levels
  • Product usage
  • Supplier reliability
  • Availability of alternative suppliers
  • Business impact if a replacement becomes necessary

Special attention should also be given to multi-sourced components. Two suppliers may manufacture functionally identical parts using different materials. One supplier's version may comply with every applicable regulation, while another introduces restricted substances or future compliance risks. Evaluating every approved source individually prevents unexpected compliance issues during procurement changes.

Step 5: Monitor as Regulations Evolve

A BOM risk assessment is not a one-time activity. Regulations continue to evolve through new REACH SVHC additions, expanding PFAS reporting requirements, updated customer specifications, and changing national regulations. Instead of requesting entirely new supplier declarations each time regulations change, organizations can often reuse existing FMD data by screening it against updated substance lists. Continuous monitoring allows compliance teams to identify newly affected products much earlier and focus supplier outreach only where updated information is actually needed.

Key FMD Limitations

Although FMDs are one of the most powerful tools available for product compliance, they're not perfect.

One common challenge is supplier intellectual property protection. Some suppliers consider their material formulations proprietary and may withhold complete composition details. In these cases, manufacturers may receive partial disclosures or regulatory declarations instead of complete FMDs.

Another limitation involves process chemicals. Some chemicals are used during manufacturing but are not intentionally retained in the finished article. Depending on the reporting requirements and the supplier's disclosure practices, these substances may not appear within the FMD even though they were present during production.

Multi-sourced components also introduce complexity. Equivalent parts from different suppliers may have different material compositions, meaning every approved source should be assessed independently rather than assuming identical compliance.

Finally, obsolete data should be an ongoing concern for compliance specialists. Material formulations change, suppliers update manufacturing processes, and regulations continue evolving. An FMD that was accurate several years ago may no longer reflect the current product or regulatory landscape. Regular updates and ongoing screening are essential for maintaining confidence in compliance decisions.

Recognizing these limitations allows manufacturers to build stronger compliance programs that combine FMD data with supplier engagement, document management, and continuous regulatory monitoring.

To learn about how Z2 helps businesses carry out BOM risk assessments, schedule a free trial with one of our product experts.