When Supply-Chain Due Diligence Becomes a Sanctions Issue: China’s Countermeasure Against the RBA and the New Compliance Dilemma for Multinationals
China’s August 5, 2026 action against the Responsible Business Alliance (“RBA”) is more than a symbolic sanctions measure. The Ministry of Commerce (“MOFCOM”) placed the RBA, together with five other U.S. entities, on China’s Countermeasure List and prohibited organizations and individuals within China from engaging in relevant transactions or cooperation with them. The restriction potentially affects RBA memberships, RBA-managed audit programs, audit-report sharing, training, corrective-action programs and other China-based interactions involving the RBA. citeturn710134view0turn564639search0

The restriction should not, however, be treated mechanically as an OFAC-style blocking sanction. The August 5 order specifically imposes a prohibition on transactions and cooperation with the listed entities. It does not itself announce a general asset freeze, an across-the-board prohibition on the use of every RBA-originated standard, or an express prohibition on all data transfers to the RBA. The legal analysis therefore turns heavily on the nature of the particular interaction.

For multinational companies, the more difficult issue is the collision between Chinese law and increasingly demanding U.S. and EU supply-chain regimes. U.S. Customs and Border Protection (“CBP”) expects importers facing UFLPA scrutiny to understand and document their supply chains, while the EU Forced Labour Regulation will similarly rely on supply-chain information in investigations once it becomes applicable on December 14, 2027. citeturn428583search0turn428583search30turn702293search0

China has simultaneously strengthened its legal controls over supply-chain investigations and information collection. The 2026 State Council Regulation on Industrial and Supply Chain Security expressly provides that unlawful investigations or information-collection activities relating to industrial and supply chains conducted in China may be subject to regulatory action. MOFCOM's June 2026 implementing measures also establish a formal supply-chain security investigation mechanism. citeturn196719view1turn196719view0

Providing Chinese supply-chain information to foreign regulators presents a separate—and increasingly important—risk. Article 36 of the PRC Data Security Law prohibits organizations and individuals in China, absent approval from competent Chinese authorities, from providing data stored in China to foreign judicial or law-enforcement authorities. Article 41 of the Personal Information Protection Law contains a parallel restriction for personal information. These provisions may become particularly relevant where Chinese suppliers are asked to provide documents directly to CBP or other foreign enforcement authorities. citeturn811801search2turn811801search0

The practical answer is not to abandon forced-labor due diligence. Multinationals need to redesign it. Companies should separate legitimate supply-chain compliance from prohibited cooperation with sanctioned organizations, reduce dependence on a single audit ecosystem, build evidence in the ordinary course of business before a detention or investigation occurs, and establish a China-specific legal review process before supply-chain information is collected or transmitted for foreign enforcement purposes.
Source: | Author: Asia Compliance Forum Sanctions Working Group | Publish time: 2026-09-15 | 8 Views | 🔊 Click to read aloud ❚❚ | Share:

Key Takeaways

  • China’s August 5, 2026 action against the Responsible Business Alliance (“RBA”) is more than a symbolic sanctions measure. The Ministry of Commerce (“MOFCOM”) placed the RBA, together with five other U.S. entities, on China’s Countermeasure List and prohibited organizations and individuals within China from engaging in relevant transactions or cooperation with them. The restriction potentially affects RBA memberships, RBA-managed audit programs, audit-report sharing, training, corrective-action programs and other China-based interactions involving the RBA.

  • The restriction should not, however, be treated mechanically as an OFAC-style blocking sanction. The August 5 order specifically imposes a prohibition on transactions and cooperation with the listed entities. It does not itself announce a general asset freeze, an across-the-board prohibition on the use of every RBA-originated standard, or an express prohibition on all data transfers to the RBA. The legal analysis therefore turns heavily on the nature of the particular interaction.

  • For multinational companies, the more difficult issue is the collision between Chinese law and increasingly demanding U.S. and EU supply-chain regimes. U.S. Customs and Border Protection (“CBP”) expects importers facing UFLPA scrutiny to understand and document their supply chains, while the EU Forced Labour Regulation will similarly rely on supply-chain information in investigations once it becomes applicable.

  • China has simultaneously strengthened its legal controls over supply-chain investigations and information collection. The 2026 State Council Regulation on Industrial and Supply Chain Security expressly provides that unlawful investigations or information-collection activities relating to industrial and supply chains conducted in China may be subject to regulatory action. MOFCOM's June 2026 implementing measures also establish a formal supply-chain security investigation mechanism.

  • Providing Chinese supply-chain information to foreign regulators presents a separate—and increasingly important—risk. Article 36 of the PRC Data Security Law prohibits organizations and individuals in China, absent approval from competent Chinese authorities, from providing data stored in China to foreign judicial or law-enforcement authorities. Article 41 of the Personal Information Protection Law contains a parallel restriction for personal information. These provisions may become particularly relevant where Chinese suppliers are asked to provide documents directly to CBP or other foreign enforcement authorities.

  • The practical answer is not to abandon forced-labor due diligence. Multinationals need to redesign it. Companies should separate legitimate supply-chain compliance from prohibited cooperation with sanctioned organizations, reduce dependence on a single audit ecosystem, build evidence in the ordinary course of business before a detention or investigation occurs, and establish a China-specific legal review process before supply-chain information is collected or transmitted for foreign enforcement purposes.

1. China’s Countermeasure Against the RBA

On August 5, 2026, MOFCOM issued Order No. 2 of 2026 placing six U.S. entities on China's Countermeasure List: Applied DNA Sciences, Stratum Reservoir, Altana Technologies, the Responsible Business Alliance, Verité Group, and Human Rights in China.

MOFCOM stated that the action responded to recent U.S. measures against Chinese companies based on alleged forced labor and asserted that the six organizations had assisted or supported what China characterized as unlawful U.S. sanctions relating to Xinjiang. The order prohibits organizations and individuals within China from engaging in “relevant transactions, cooperation and other activities” with the six listed entities.

The legal basis is China's Anti-Foreign Sanctions Law (“AFSL”) and the State Council's 2025 Implementing Provisions of the AFSL. The Implementing Provisions are significant because they make clear that prohibited “transactions and cooperation” are not confined to purchases and sales of goods. They may extend to, among other areas, economic and trade activities, legal services, technology, environmental services and other forms of cooperation. The Implementing Provisions also authorize Chinese authorities to impose additional restrictions—including restrictions concerning data and personal information—and provide substantial enforcement tools against organizations that fail to implement Chinese countermeasures.

This distinction matters. The August 5 order itself does not state that every conceivable interaction with RBA is prohibited or that every document developed by RBA suddenly becomes unlawful to possess or consult. But activities involving an ongoing institutional relationship with RBA should now receive considerably greater scrutiny.

2. Why the RBA Listing Matters Operationally

RBA is not merely an advocacy organization. Its standards and assessment infrastructure are embedded in the compliance architecture of many multinational supply chains, particularly in electronics, technology and manufacturing.

Its Validated Assessment Program (“VAP”), for example, is an RBA-established compliance verification framework under which approved independent audit firms conduct facility assessments. RBA also maintains a specialized forced-labor assessment program, and one important feature of the RBA model is the ability of participating companies and facilities to share assessment results.

That creates several different legal situations that should not be conflated.

A China subsidiary paying membership dues directly to RBA, purchasing an RBA-managed assessment, uploading information through an RBA platform, participating in an RBA-administered corrective-action program or sharing facility information with RBA would appear considerably closer to the prohibited category of “transactions” or “cooperation.”

The position is less straightforward where a multinational merely uses an RBA standard as a reference point in an internally developed supplier code, or where an independent audit firm conducts an audit based on similar substantive criteria without RBA involvement. Mere reference to a publicly available standard is not necessarily the same as entering into a transaction or cooperative activity with the organization that authored it.

Likewise, the August 5 prohibition expressly addresses organizations and individuals within China. It therefore does not automatically mean that a U.S. or European parent company is prohibited by Chinese law from maintaining every relationship it has with RBA outside China. The difficulty arises where that relationship requires participation by a Chinese subsidiary, Chinese employees, Chinese suppliers or Chinese facilities.

For multinational groups, this makes entity-level and activity-level analysis considerably more important than a simple global instruction saying either “stop using RBA” or “business as usual.”

3. The UFLPA Conflict: More Evidence Is Required Just as Evidence Collection Becomes More Sensitive

The conflict is particularly acute under the U.S. Uyghur Forced Labor Prevention Act (“UFLPA”).

The UFLPA establishes a rebuttable presumption against goods mined, produced or manufactured wholly or in part in Xinjiang, or by certain listed entities. CBP has consistently emphasized that importers must exercise reasonable care, understand where and how their products are produced, and maintain sufficient supply-chain documentation to establish admissibility.

U.S. enforcement policy has increasingly emphasized visibility beyond the immediate supplier. Companies in higher-risk sectors are increasingly expected to understand multiple tiers of their supply chains and maintain credible traceability mechanisms.

The practical consequence is important: an RBA or other social-compliance audit has never been a substitute for UFLPA supply-chain tracing.

An audit may provide useful evidence concerning working conditions at a particular facility. But UFLPA questions frequently concern a different issue: where the materials, components and intermediate inputs came from and whether any upstream entity or production step creates a Xinjiang or Entity List nexus.

Accordingly, even before the RBA countermeasure, an importer relying exclusively on an RBA audit was vulnerable. The August 2026 development reinforces the need for a broader evidence architecture based on transactional records, supplier genealogy, bills of materials, production records, purchase and sales records, logistics documentation, payment records and, where appropriate, scientific traceability tools.

4. A New Question: Can the Chinese Supplier Give the Evidence to CBP?

This is where the compliance problem becomes substantially more difficult.

CBP may allow a foreign seller or other third party to submit supply-chain documentation directly in appropriate circumstances. From the U.S. perspective, direct supplier submissions can therefore be a practical way to protect confidential commercial information while allowing CBP to examine upstream records.

Chinese law creates a different question.

Article 36 of China's Data Security Law provides that, without approval from the competent Chinese authorities, organizations and individuals within China may not provide data stored in China to foreign judicial or law-enforcement authorities.

For personal information, Article 41 of the Personal Information Protection Law imposes a parallel restriction on providing personal information stored in China to foreign judicial or law-enforcement bodies without approval from competent Chinese authorities.

That distinction is highly relevant to forced-labor investigations. A response package may contain far more than commercial invoices. It can include worker rosters, personnel files, payroll information, recruitment documentation, employee interviews, labor-transfer information, identification records, attendance records, photographs and other information relating to identifiable employees.

Consequently, “sending the audit report to customs” should no longer be treated as a routine administrative step.

The relevant questions include who collected the information, where it is stored, whether personal information or sensitive personal information is involved, whether any information could constitute important data, whether the immediate recipient is a parent company or a government authority, and whether the transfer is being made in response to a foreign enforcement request.

Routing the documents through the foreign parent is also not necessarily a complete solution. Where a Chinese entity supplies information to its overseas affiliate specifically so that the affiliate can transmit the same information to a foreign enforcement agency, authorities could examine the substance of the arrangement rather than merely its formal routing.

5. China's General Cross-Border Data Rules Are More Liberal—but They Do Not Eliminate This Problem

It is equally important not to overstate Chinese restrictions.

China substantially liberalized ordinary business data transfers through the 2024 Provisions on Facilitating and Regulating Cross-Border Data Flows. Among other things, data generated in international trade, cross-border transportation, multinational manufacturing and marketing may generally be transferred abroad without using the CAC security assessment, standard contractual clauses or certification mechanisms where the transferred information does not include personal information or important data.

China has also clarified that data not identified or publicly designated as important data generally does not have to be treated as important data solely out of caution for purposes of the CAC security-assessment regime.

These reforms materially improved routine intra-group and commercial data flows.

But an important distinction remains between ordinary commercial data transfers and providing data in connection with foreign governmental investigations or enforcement.

The facilitation rules do not repeal Article 36 of the Data Security Law or Article 41 of the PIPL. A transfer that may be routine when undertaken for manufacturing, logistics or ordinary supply-chain management may require a different analysis when the purpose becomes satisfying an evidentiary demand from CBP or another foreign authority.

6. The 2026 Supply-Chain Security Rules Add Another Layer

A development that multinational compliance teams should pay particular attention to is China's new industrial and supply-chain security framework.

Effective March 31, 2026, the State Council's Regulation on Industrial and Supply Chain Security created China's first dedicated administrative-regulation framework addressing supply-chain security.

Article 13 is particularly relevant. It provides that where an organization or individual conducts investigations or other information-collection activities relating to industrial or supply chains within China in violation of Chinese laws, administrative regulations, departmental rules or other applicable requirements, competent authorities may take corresponding enforcement measures.

The regulation also provides mechanisms for Chinese authorities to investigate foreign measures or conduct that threatens China's industrial or supply-chain security and to adopt countermeasures against foreign organizations or individuals.

MOFCOM followed with its Measures for Industrial and Supply Chain Security Investigations in June 2026. Those measures authorize MOFCOM to investigate foreign actions affecting the security of Chinese supply chains and to consider impacts on, among other things, materials, technology, funding, assets, data, information, personnel and enterprises, as well as the cross-border flow of data and information.

For multinational companies, Article 13 should not be read as creating a general prohibition against legitimate corporate supply-chain audits. The provision expressly turns on information-collection activities conducted in violation of other applicable Chinese requirements.

Nevertheless, its enactment is significant.

It effectively places supply-chain investigations themselves within China's national supply-chain-security framework. A foreign buyer requesting extensive factory, employee, sub-supplier or production data can no longer assume that the exercise is merely contractual ESG due diligence. Depending on scope, purpose, methodology and downstream use, it may also raise Chinese data, privacy, national-security, anti-sanctions and supply-chain-security questions.

7. China's New Anti-Extraterritorial-Jurisdiction Regime Is an Even Clearer Warning

Another major development came in April 2026, when China adopted the Regulation on Countering Improper Foreign Extraterritorial Jurisdiction.

Under the regulation, China's Ministry of Justice, together with other authorities, may determine that a foreign measure constitutes an improper exercise of extraterritorial jurisdiction. Once such a determination is publicly made, organizations and individuals may not implement or assist in implementing that foreign measure unless permission is obtained under the regulation. Authorities may also impose restrictions involving trade, investment, transactions, data and personal information.

This is no longer merely a theoretical authority.

In May 2026, the Ministry of Justice determined that certain information demands made against Chinese entities in the EU Foreign Subsidies Regulation investigation of Nuctech constituted improper extraterritorial jurisdiction. The Ministry specifically criticized what it described as broad and unnecessary cross-border demands for information located in China and prohibited organizations and individuals from implementing or assisting the identified measures.

In August 2026, China made a similar determination concerning aspects of an EU Foreign Subsidies Regulation investigation involving JD.com, again emphasizing cross-border demands for Chinese information.

These cases are highly relevant even though they did not involve forced-labor laws.

They demonstrate a broader Chinese regulatory position: foreign regulatory investigations that compel extensive information from entities in China can, in some circumstances, become an extraterritorial-jurisdiction issue rather than merely a data-transfer issue.

As of September 15, 2026, there does not appear to be a comparable published determination specifically declaring the UFLPA, the EU Forced Labour Regulation or the CSDDD to constitute improper extraterritorial jurisdiction. Companies therefore should not treat the 2026 regulation as an automatic blocking statute against those regimes.

But the regulatory architecture now exists, and the Nuctech and JD.com cases demonstrate that Chinese authorities are prepared to use it.

That materially changes the risk assessment for future supply-chain investigations.

8. The EU Dimension: Forced Labour Regulation and CSDDD

The same tension is increasingly relevant for European companies.

The EU Forced Labour Regulation will prohibit products made with forced labor from being placed on, made available on or exported from the EU market beginning December 14, 2027. The European Commission will generally lead investigations involving suspected forced labor occurring outside the EU, while Member State authorities will play the central role in other cases. Businesses may be requested during investigations to provide information concerning how they have addressed forced-labor risks in their supply chains.

An important nuance is that the Regulation does not itself impose a universal mandatory audit or reporting obligation. Companies remain responsible for ensuring that covered products are not made with forced labor, but the methodology used to achieve that result is not prescribed as a single mandatory audit model.

That flexibility may become valuable in China.

Companies should resist the assumption that continued use of a particular branded audit program is legally required by EU law. The substantive objective—credible forced-labor due diligence—may often be achieved through alternative audit, traceability and risk-assessment methodologies that do not require prohibited cooperation with a sanctioned organization.

The Corporate Sustainability Due Diligence Directive (“CSDDD”) creates a related but distinct framework. Following the EU's 2026 reforms, the Directive's scope was narrowed substantially. Nevertheless, large multinational companies subject to the CSDDD will continue to seek information from business partners where necessary to identify and address human-rights risks.

The challenge will therefore remain: how to obtain sufficient information for European due diligence without imposing requests on Chinese suppliers that place them in conflict with Chinese law.

9. Rethinking the Traditional Audit Model

The RBA development illustrates a broader trend: supply-chain compliance can no longer be managed solely by ESG or responsible-sourcing teams.

The traditional model was comparatively simple. A multinational issued a supplier code, required suppliers to participate in an approved audit program, uploaded findings into a global platform, shared reports among customers and escalated failures through corrective-action plans.

That model increasingly crosses several legal regimes simultaneously.

A worker interview is an employment-rights tool, but it is also personal-information processing. A supplier genealogy is a forced-labor-control tool, but it may also contain commercially sensitive or potentially regulated supply-chain data. A request from headquarters may be ordinary corporate compliance, but the same request may take on a different legal character when it originates from a foreign customs detention or regulatory investigation. An audit platform may be an ESG tool in one jurisdiction but constitute prohibited cooperation with a sanctioned organization in another.

The compliance function therefore needs to move from a single global audit process toward a multi-jurisdictional evidence and governance model.

10. Practical Steps for Multinational Companies

The first priority should be to identify every China-related interaction with the RBA and the other entities covered by the August 5 countermeasure. This review should extend beyond formal contracts and membership dues to audit scheduling, platform access, assessment payments, report sharing, corrective-action management, training, consulting relationships and data transmission.

Companies should then distinguish the substantive compliance standard from the organization administering it. A multinational need not abandon responsible-sourcing principles merely because one audit organization has become subject to Chinese countermeasures. In many circumstances it should be possible to preserve equivalent or stronger substantive labor and forced-labor controls while using an independently designed assessment process that does not involve prohibited transactions or cooperation.

A second priority should be to build UFLPA and EU forced-labor evidence before an enforcement event occurs. Records generated and maintained in the ordinary course of procurement, manufacturing and logistics are generally easier to manage than an emergency demand for thousands of documents after a shipment has already been detained.

Multinationals should therefore design supplier onboarding and supply-chain management systems to preserve upstream sourcing information, production records, transaction documentation and traceability evidence at the time it is created.

Third, companies should create a formal legal gate for foreign governmental information requests involving China. A request originating from CBP, the European Commission or another foreign regulator should not simply be forwarded by the U.S. or European compliance team to the China purchasing team with an instruction to “collect everything.”

Counsel should first determine what information is actually necessary, who holds it, where it is stored, whether it contains personal information or potentially regulated data, whether a Chinese entity would be providing information directly or indirectly to a foreign enforcement authority, and whether any Chinese countermeasure or blocking measure applies.

Fourth, companies should reconsider contractual clauses that automatically require Chinese suppliers to provide unrestricted access to all books, employees, sub-suppliers and records or authorize the multinational to provide such information to any governmental authority worldwide. Those clauses increasingly risk promising more than the supplier can lawfully deliver.

A more workable approach is to require cooperation subject to applicable law, establish alternative verification mechanisms where direct transfer is restricted, and provide procedures for regulatory approvals, redaction, data minimization or independent verification where necessary.

Finally, multinational groups should separate responsibilities geographically. Foreign headquarters may continue to have compliance obligations that differ from those of a Chinese subsidiary. A global policy should therefore establish substantive forced-labor standards while allowing China-specific procedures governing data collection, external audits, interaction with designated entities and responses to foreign authorities.

11. The Broader Lesson

The RBA countermeasure should not be viewed in isolation.

China's 2025 AFSL Implementing Provisions, the 2026 Industrial and Supply Chain Security Regulation, the 2026 MOFCOM supply-chain investigation rules, the new anti-extraterritorial-jurisdiction regime, and the government's actual intervention in EU regulatory investigations point in the same direction.

China is increasingly treating supply-chain information, foreign compliance investigations and participation in overseas restrictive measures as issues that may implicate sovereignty, national security and countermeasure policy—not merely corporate compliance.

At the same time, the United States and European Union are moving in the opposite regulatory direction: requiring companies to know more about upstream production, identify forced-labor risks and, when challenged, demonstrate the provenance and conditions under which their goods were produced.

Multinationals operating across these jurisdictions are therefore facing a genuine conflict-of-laws problem.

The answer is unlikely to be either complete transparency or complete information localization. Rather, companies will need a much more deliberate architecture governing what supply-chain information is collected, by whom, for what purpose, under which legal authority, where it is stored, with whom it can be shared, and what happens when a foreign regulator requests it.

The August 2026 action against the RBA makes that transition more urgent.

For multinational companies with significant China-facing supply chains, forced-labor compliance should now be treated not simply as an ESG exercise or a customs issue, but as an integrated trade, sanctions, data, supply-chain-security and conflict-of-laws problem.

This article reflects the legal and regulatory landscape as of September 15, 2026 and is intended for general informational purposes rather than as legal advice regarding any particular transaction or investigation.