ISO/TR 20180:2026
(Main)Risk-based product quality data interchange in e-commerce
General Information
- Abstract
This document provides information on how to address product quality data interchange based on risk assessment for consumer product safety in e-commerce. This document: analyses e-commerce supply chain context; analyses product risk assessment in e-commerce; gives use cases on risk-based product quality data for interchange; presents the general process for product quality data interchange among e-commerce stakeholders.
- Status
- Published
- Publication Date
- 14-Sep-2026
- Technical Committee
- ISO/TC 154 - Processes, data elements and documents in commerce, industry and administration
- Drafting Committee
- ISO/TC 154/WG 7 - Digital business
- Current Stage
- 6060 - International Standard published
- Start Date
- 15-Sep-2026
- Completion Date
- 15-Sep-2026
Overview
ISO/TR 20180:2026 - Risk-based product quality data interchange in e-commerce is a technical report issued by the International Organization for Standardization (ISO). This guidance addresses the exchange of product quality data within the e-commerce supply chain, underpinned by risk assessment for enhanced consumer product safety. As online shopping accelerates globally, so do the challenges associated with ensuring product safety and compliance. This document provides a comprehensive review of e-commerce supply chain dynamics, methods for product risk assessment, practical use cases, and establishes a general process to facilitate seamless, risk-based product quality data interchange among stakeholders. This approach supports stakeholders-including platform operators, sellers, logistics providers, and regulatory authorities-in making informed decisions and supporting safe, compliant e-commerce transactions.
Key Topics
E-commerce Supply Chain Analysis
The document examines e-commerce from upstream suppliers through to after-sales, identifying critical stages and potential risk sources.Product Risk Assessment Methodology
It outlines how to systematically identify and analyze risks associated with consumer products traded online, focusing on risk sources and factors present at each stage.Stakeholder Roles in Data Interchange
Recognition of the multiple participants involved in data exchange, such as platform operators, sellers, logistics and warehousing services, customs, buyers, and regulatory agencies.Risk-based Data Interchange Process
Presents a structured process for exchanging product quality data, tailored to the risk level of products to ensure proportionality and efficiency.Information Packages and Datasets
Defines the organization of product quality data into information packages reflecting risk sources and factors relevant to e-commerce.
Applications
Implementing ISO/TR 20180:2026 brings several practical benefits:
Enhanced Consumer Protection:
By basing data interchange on risk assessment, stakeholders can prioritize resources and information exchange on higher-risk products, reducing the likelihood of unsafe goods reaching consumers.Efficient Regulatory Compliance:
E-commerce operators and sellers, especially SMEs, can navigate varied legal and safety requirements across regions more rapidly and accurately through standardized, risk-based data flows.Streamlined Supply Chain Operations:
Platform operators, logistics providers, and customs authorities can use risk classification to simplify checks-accelerating clearance and processing for low-risk items and focusing detailed reviews on higher-risk goods.Transparency and Trust:
Structured product quality data interchange fosters trust between buyers and sellers, and between businesses and regulators, supporting broader adoption of e-commerce.Scalable Risk Management:
The standard helps organizations design information systems that scale data collection and exchange proportionally to risk, facilitating growth without sacrificing product safety.
Common use cases for this standard include:
- Online marketplaces integrating risk-based product quality checks before listing
- Customs authorities using risk scores to prioritize inspection and documentation review
- Enabling data-driven after-sales services based on customer feedback and product incident patterns
Related Standards
ISO/TR 20180:2026 references and aligns with several other international standards to provide a comprehensive framework for quality and safety in e-commerce:
- ISO 31000: Risk management – Principles and guidelines
- ISO 10377: Consumer product safety – Guidelines for suppliers
- ISO 32110: E-commerce – Definitions and roles of participants
- ISO 9001: Quality management systems – Requirements
These related standards offer broader risk management, product safety, and quality management context, ensuring that ISO/TR 20180:2026 can be implemented as part of an integrated compliance and risk management strategy.
Keywords: e-commerce, product quality data, risk assessment, ISO standard, consumer product safety, data interchange, supply chain, regulatory compliance, information package, risk-based compliance, after-sales, stakeholders, online marketplace
Get Certified
Connect with accredited certification bodies for this standard

BSI Group
BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

NYCE
Mexican standards and certification body.
Sponsored listings
Frequently Asked Questions
ISO/TR 20180:2026 is a technical report published by the International Organization for Standardization (ISO). Its full title is "Risk-based product quality data interchange in e-commerce". This standard covers: This document provides information on how to address product quality data interchange based on risk assessment for consumer product safety in e-commerce. This document: analyses e-commerce supply chain context; analyses product risk assessment in e-commerce; gives use cases on risk-based product quality data for interchange; presents the general process for product quality data interchange among e-commerce stakeholders.
This document provides information on how to address product quality data interchange based on risk assessment for consumer product safety in e-commerce. This document: analyses e-commerce supply chain context; analyses product risk assessment in e-commerce; gives use cases on risk-based product quality data for interchange; presents the general process for product quality data interchange among e-commerce stakeholders.
ISO/TR 20180:2026 is classified under the following ICS (International Classification for Standards) categories: 35.240.63 - IT applications in trade. The ICS classification helps identify the subject area and facilitates finding related standards.
ISO/TR 20180:2026 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
Technical
Report
ISO/TR 20180
First edition
Risk-based product quality data
2026-09
interchange in e-commerce
Échange de données sur la qualité des produits selon une
approche fondée sur les risques dans le commerce en ligne
Reference number
© ISO 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 E-commerce supply chain context. 2
4.1 Overview .2
4.2 Participants .3
4.3 Key e-commerce business stages .3
5 Product risk assessment in e-commerce . 4
5.1 Overview .4
5.2 Risk identification.4
5.2.1 Overview .4
5.2.2 Risk sources .4
5.2.3 Risk factors .6
5.3 Risk analysis .7
5.3.1 Overview .7
5.3.2 Likelihood .7
5.3.3 Severity levels of potential consequences .8
5.4 Risk evaluation .8
5.5 Product risk reduction based on data interchange .9
6 Risk-based product quality data for interchange . 9
6.1 Overview .9
6.2 Information packages .9
6.3 Datasets .11
6.3.1 Examples of datasets in a bicycle helmet information package .11
6.4 Data quality . 12
6.5 Data augmentation . . 13
7 Process for quality data interchange in e-commerce . 14
Annex A (informative) Use case of risk assessment and risk-based quality interchange in
e-commerce . 19
Annex B (informative) Example of XML schema definition for risk-based product quality data
interchange in e-commerce .21
Bibliography .28
iii
Foreword
ISO (the International Organization for Standardization) is a worldwide federation of national standards
bodies (ISO member bodies). The work of preparing International Standards is normally carried out through
ISO technical committees. Each member body interested in a subject for which a technical committee
has been established has the right to be represented on that committee. International organizations,
governmental and non-governmental, in liaison with ISO, also take part in the work. ISO collaborates closely
with the International Electrotechnical Commission (IEC) on all matters of electrotechnical standardization.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of ISO documents should be noted. This document was drafted in accordance with the editorial rules of the
ISO/IEC Directives, Part 2 (see www.iso.org/directives).
ISO draws attention to the possibility that the implementation of this document may involve the use of (a)
patent(s). ISO takes no position concerning the evidence, validity or applicability of any claimed patent
rights in respect thereof. As of the date of publication of this document, ISO had not received notice of (a)
patent(s) which may be required to implement this document. However, implementers are cautioned that
this may not represent the latest information, which may be obtained from the patent database available at
www.iso.org/patents. ISO shall not be held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO’s adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT), see www.iso.org/iso/foreword.html.
This document was prepared by Technical Committee ISO/TC 154, Processes, data elements and documents in
commerce, industry and administration.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.html.
iv
Introduction
The exponential growth of e-commerce presents new challenges for stakeholders regarding consumer
product safety. Unsafe products make their way to the market, because customs and market surveillance
authorities worldwide are understaffed compared to the high volume of parcels crossing borders daily.
E-commerce platforms and sellers, especially small and medium-sized enterprises (SMEs), face challenges
in complying with legal safety rules across multiple markets due to complex, globally-sourced supply chains.
This increases the need for effective data exchange among stakeholders.
In order to protect consumers from unsafe products, it is critical for platform operators to enhance their
checks to prevent unsafe products from being offered to consumers online. Similarly, it is crucial for
sellers to provide evidence of compliance with safety and other legal requirements as a condition before
products are listed online. Relevant government agencies encourage the advanced exchange of e-commerce
specific information (e.g. product compliance and quality data) to maintain a balance between facilitating
time-sensitive e-commerce and ensuring efficient controls for product safety. Proper product quality data,
therefore, can be obtained at the earliest point in the supply chain and incrementally added and exchanged
in time by relevant parties along the supply chain in e-commerce.
For efficient exchange of these data, a top priority is to decide the minimum data needed based on product
risk level. Applying a risk-based compliance method to differentiate between low-risk and high-risk
e-commerce trade enables interchange of more targeted data – ensuring data exchange is proportionate
to risk. It is also important for all stakeholders in e-commerce to have a common understanding of the
description and structuring of the data, and its relation to existing international standards.
This document is intended for e-commerce operators, relevant service providers, authorities and the other
stakeholders.
v
Technical Report ISO/TR 20180:2026(en)
Risk-based product quality data interchange in e-commerce
1 Scope
This document provides information on how to address product quality data interchange based on risk
assessment for consumer product safety in e-commerce. This document:
— analyses e-commerce supply chain context;
— analyses product risk assessment in e-commerce;
— gives use cases on risk-based product quality data for interchange;
— presents the general process for product quality data interchange among e-commerce stakeholders.
2 Normative references
There are no normative references in this document.
3 Terms and definitions
For the purposes of this document, the following terms and definitions apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
3.1
risk
effect of uncertainty on objectives
Note 1 to entry: An effect is a deviation from the expected. It can be positive, negative or both, and can address, create
or result in opportunities and threats.
Note 2 to entry: Objectives can have different aspects and categories, and they can be applied at different levels.
[SOURCE: ISO 31000:2018, 3.1, modified — Note 3 to entry was removed.]
3.2
consumer product
product designed and produced primarily for, but not limited to, personal use, including its components,
parts, accessories, instructions and packaging
[SOURCE: ISO 10377:2013, 2.2]
3.3
risk factor
characteristic or circumstance which can contribute to, or cause, consumer vulnerability
[SOURCE: ISO 22458:2022, 3.9]
3.4
risk source
element which alone or in combination has the potential to give rise to risk (3.1)
[SOURCE: ISO 31000:2018, 3.4]
3.5
hazard
potential source of harm
Note 1 to entry: Adapted from ISO 31073:2022, 3.3.12.
3.6
level of risk
assessed magnitude of the risk (3.1)
Note 1 to entry: Adapted from ISO 31073:2022, 3.3.22.
3.7
e-commerce operator
individual or organization engaged in e-commerce
[SOURCE: ISO 32110:2023, 3.2.6, modified — Note 1 to entry was removed.]
3.8
e-commerce platform operator
organization that operates an e-commerce platform
[SOURCE: ISO 32110:2023, 3.2.7]
3.9
seller
individual or organization that sells products over open networks
[SOURCE: ISO 32110:2023, 3.2.13, modified — Notes 1 and 2 to entry were removed.]
3.10
stakeholder
person or organization that can affect, be affected by, or perceive themselves to be affected by a decision or
activity
Note 1 to entry: The term “interested party” can be used as an alternative to “stakeholder”.
[SOURCE: ISO 31000:2018, 3.3]
4 E-commerce supply chain context
4.1 Overview
E-commerce supply chain involves complex business processes covering stages from upstream supply to
after-sales and web of stakeholders, all of which can be sources of consumer product quality risk. To help
reduce these risks, it is essential to assess the risk level in the context of e-commerce supply chain and enable
the stakeholders to obtain sufficient quality data to ensure consumer product safety. Two key considerations
are the major participants involved in quality data interchange and the key e-commerce business stages.
4.2 Participants
The following stakeholders can take part in the data interchange for product quality control. Each participant
is responsible for providing or receiving product quality data according to its role. One organization can
perform more than one role in the supply chain.
— Upstream supplier: an organization or individual that provides goods to be sold online, which includes
but is not limited to, manufacturers, vendors, individual sellers, third-party suppliers, etc.
— E-commerce platform operator (see 3.8).
— Seller (see 3.9).
— Logistics service provider: an organization that provides services of transport, distribution of products
traded online, e.g. cross-border logistics and local delivery.
— Warehousing service provider: an organization that provides warehousing services for products traded
online, e.g. exporting country warehouse, importing country warehouse.
— Customs: a government regulatory authority that supervises and clears imported and exported products
across a border based on the relevant laws and administrative regulations.
— Market surveillance agencies: a government regulatory authority that supervises and manages products
based on the relevant laws and administrative regulations.
— Customs brokers: a party that provides customs declaration services for e-commerce supply chains.
— Buyers: an individual or organization that purchases products online.
4.3 Key e-commerce business stages
To support systematic risk identification (see 5.2), it is useful to examine the e-commerce supply chain
across its key business stages, as each stage presents distinct risk sources and data interchange needs. Not
all business stages apply to every product or transaction. Different stages require different types of product
quality data. Product quality risks can arise from a variety of sources at each stage, which include upstream
supply, online transaction, logistics, warehousing, customs clearance and after-sales.
— Upstream supply: in this stage, suppliers upstream of online transactions provide products or product
information to e-commerce operators for sale.
— Online transaction: this stage involves buyers purchasing products from sellers via e-commerce
platforms with key links including online display.
— Logistics: logistics service providers are responsible for transporting products in the e-commerce supply
chains, covering processes such as product packaging, handling and shipping.
— Warehousing: warehousing services (provided by warehousing operators in the exporting country,
importing country, or both) involve storing products to support subsequent transportation, with core
activities including inventory management, environmental control and product storage.
— Customs clearance: this stage requires imported or exported products to go through formalities such
as document verification and physical inspection in accordance with the customs regulations of the
importing/exporting country.
— After-sales: after-sales services refer to the support provided by e-commerce operators to customers
after order completion, including handling returns/exchanges, addressing product complaints and
collecting customer feedback and reviews.
5 Product risk assessment in e-commerce
5.1 Overview
The overall process for product quality risk assessment involves risk identification, risk analysis and risk
evaluation.
5.2 Risk identification
5.2.1 Overview
Risk identification in e-commerce is the process that involves detecting, recognizing and describing
the potential hazards that can be encountered by end-users during the various stages of an e-commerce
product lifecycle. The general approach involves first identifying risk sources, then further pinpointing the
specific risk factors associated with key stages in the e-commerce supply chains. This document provides a
list of common risk factors in the e-commerce supply chains as a non-exhaustive reference for conducting
qualitative or quantitative risk analysis.
To conduct a product quality risk assessment, it is crucial to recognize and describe the potential risk
sources and significant risk factors in e-commerce supply chain.
5.2.2 Risk sources
A risk source is the fundamental origin or root cause that gives rise to risk. The risk sources in e-commerce
can include product, provider of product or service, and related business process as shown in Figure 1.
Figure 1 — Risk sources
a) Product: the different categories, origins and other characteristics of products exhibit varying levels of
risks to consumer health and safety.
b) Provider of product or service:
1) Upstream supplier: supplier qualification (e.g. whether they hold valid production licenses,
quality management system certifications) and history of compliance with rules, regulations, and
applicable laws are key determinants of potential risks. Moreover, these two factors clearly reflect
how robust the supplier’s internal risk management and quality control capabilities are. Suppliers
with complete qualifications and a clean compliance record are more likely to take steps to ensure
product quality, while those with incomplete qualifications or a history of non-compliance have a
much higher probability of introducing substandard or unsafe products into the supply chain.
2) Seller: a seller’s non-compliance (e.g. selling products that do not meet national safety standards)
and misleading practices (e.g. concealing product defects or falsifying quality information) can
directly lead to the circulation of counterfeit or shoddy products.
3) Logistics service provider: qualification and compliance history of logistics service provider
are responsible for the physical transportation of products, which is a critical link in maintaining
product quality. Their qualification (e.g. whether they have the capacity to transport special
products like perishables or fragile goods) and compliance history (e.g. whether they follow
standardized packaging and handling procedures) directly affect whether products remain intact
during transit.
4) Warehousing service provider: warehousing service providers are in charge of product storage,
and their operations directly impact the preservation of product quality. Their qualification (e.g.
whether warehouses meet environmental standards for specific products, such as moisture-proof
requirements for electronics or low-temperature conditions for pharmaceuticals) and compliance
history (e.g. whether they implement strict inventory management to avoid mixing defective and
qualified products, and supporting traceability through accurate inventory records) determine
whether products maintain their original quality during storage.
5) Customs broker: customs brokers handle clearance procedures for multiple importers
simultaneously, acting as a “bridge” between imported products and the domestic market. Due
to their role in managing documentation verification, product declaration, and compliance with
customs regulations for multiple clients, any illegal or non-compliant behaviour (e.g. falsifying
product origin information, concealing product defects to avoid inspection) can cause similar
compliance risks for multiple importers and products.
c) Related business process:
1) Online transaction: information asymmetry (i.e. unequal access to product information) in online
product listings can be a core risk trigger in this process. When listings lack transparency (e.g.
omitting key quality indicators such as material composition or safety certifications), contain
inaccuracies (e.g. exaggerating product durability or performance), or use deceptive content (e.g.
falsifying “certified safe” labels), buyers can be misled to purchase substandard products.
2) Logistics: logistics service directly affects the physical integrity of products. Improper operations
during transportation (e.g. rough handling, inadequate packaging for fragile goods, or failure to
maintain temperature control for perishables or medications) can easily cause product damage,
deterioration, or contamination, thereby, triggering quality risks.
3) Warehousing: warehousing involves long-term or short-term storage of products, and its
management directly impacts whether products maintain their original quality. Factors such
as warehouse environmental conditions (e.g. temperature, humidity, ventilation ‒ especially
important for perishable or humidity-sensitive products) and inventory management practices (e.g.
avoiding long-term storage that can cause product deterioration, preventing mixing of defective
and qualified products) have a direct and significant impact on maintaining product quality.
4) Customs clearance: the customs clearance process can be a risk source for product quality, mainly
due to two factors: non-compliance with access requirements and delays during inspection and
documentation review. Delays in clearance or failure to identify non-compliant products during
inspection can result in quality risks for products entering the market.
5) After-sales: the after-sales process is a potential product quality risk source, primarily because it
involves post-purchase product maintenance and issue resolution ‒ improper handling here can
exacerbate quality risks or hide existing ones. After-sales services can both reduce and reveal
quality risks. These services play a key role in maintaining product quality “after delivery”: they
help resolve quality issues that arise post-purchase (e.g. replacing defective products) and ensure
customer satisfaction. Additionally, customer feedback and reviews (which reflect real usage
experiences, such as product defects or performance failures) provide direct and valuable insights
for e-commerce operators to identify potential product quality loopholes and improve quality
management.
5.2.3 Risk factors
Major risk factors are specific threats or vulnerabilities that stem from the risk sources. They are identifiable
and detailed elements that can enable more precise risk assessment.
The major risk factors in e-commerce supply chain are shown in Figure 2.
Figure 2 — Major risk factors in e-commerce
a) Risk factors from product
1) Type: potential risks can arise due to inherent properties of different categories of products, e.g.
physical feature, composition, functionality.
2) Origin: sourcing products from countries or regions with inherent systemic vulnerabilities ‒ such as
endemic diseases, weak regulatory oversight or prevalent pest infestations ‒ can pose a significant
risk to product safety and quality.
3) End use: deviation from intended use purpose, target user group or specified operating environment
can greatly increase the risk.
4) Quality attestation: potential risks can arise from insufficient attestation types (e.g. self-declaration
where third-party certification is required) or unreliable attestation content (e.g. falsified, expired
or non-applicable certificates).
b) Risk factors from provider of product or service
1) Qualification: risk can stem from insufficient, invalid or fraudulent provider credentials, including
licenses, certifications or accreditation, which are prerequisites for competent service delivery.
2) History record: a provider’s documented history of adhering to rules, regulations and applicable
laws serves as a key indicator of risk. A record of non-compliance, violations or recurring issues can
indicate a higher risk profile.
c) Risk factors from related business process
1) Online display: the presence of inaccurate, exaggerated, or misleading product information online
can lead to incorrect buyer expectations, misuse, or non-compliance with advertising standards.
2) Packaging: inadequate packaging that is unsuitable for the product or transit mode increases the
risk of physical damage, environmental spoilage or contamination.
3) Handling: improper handling methods and procedures during loading, unloading and moving can
directly lead to product damage, contamination or loss.
4) Shipping: failure to maintain required transit conditions ‒ including temperature control, humidity
levels and proper cargo securing ‒ can increase the risk of product damage or deterioration from
shock, vibration or environmental exposure.
5) Storage: failure to maintain a secure, controlled storage environment (e.g. incorrect temperature,
humidity, or pest control) can lead to damage, spoilage or cross-contamination of the stored
products.
6) Inventory management: flaws in inventory management, such as a lack of proper stock rotation,
co-mingling of different product types, or inaccurate record-keeping, can lead to the distribution of
expired or compromised goods.
7) Clearance: extended detention of goods during customs clearance due to procedural delays or the
submission of incorrect documentation, potentially damaging time-sensitive products, alongside
the failure to intercept non-compliant items.
8) Return: a high frequency of product returns due to defects, damage or not matching the description
can serve as a direct indicator of potential quality failures or issues with online display accuracy.
9) Customer review: the identification of recurring patterns in customer feedback regarding product
defects, safety concerns or performance issues can signal underlying quality or design flaws.
5.3 Risk analysis
5.3.1 Overview
Risk analysis involves the assessment of the likelihood and impact of each risk factor. Product risk analysis
methods can be qualitative, quantitative or a combination of both, depending on the information collected
and the type of analysis performed.
5.3.2 Likelihood
The likelihood of hazards occurring during the life cycle of a good traded through e-commerce is one of
the two core elements of risk assessment. Likelihood evaluation methods can use objective and subjective
probability estimation. Objective probability estimation requires a large amount of objective data and
information support. Subjective probability estimation is mainly based on experience, knowledge or expert
inference from similar events. Risk assessment can use suitable methods to set criteria for likelihood
according to actual needs and resources.
Table 1 shows an example of likelihood levels.
Table 1 — Example of likelihood levels
Likelihood Score
Description
(qualitative) (quantitative)
Almost certain Frequently occurs, ≥60 issues reported over a period of 6 months 5
Likely Often occurs, ≥30 and <60 issues reported over a period of 6 months 4
Possible Sometimes occurs, ≥6 and <30 issues reported over a period of 6 months 3
Unlikely Seldom occurs, <6 issues reported over a period of 6 months 2
Rare Rarely occurs, no issues reported over a period of 12 months 1
NOTE An “issue” is defined as a product safety and compliance regulatory action initiated by authorities to related e-commerce
operators (e.g. a customs inspection notice, violation, request for information, government inquiry).
5.3.3 Severity levels of potential consequences
E-commerce products can pose various risks to consumers, including safety hazards, health threats,
environmental concerns, non-compliance with laws and regulations and infringements of consumer rights.
The severity of these consequences reflects the extent of harm imposed on consumers and serves as a
critical factor in risk assessment. Assessors can evaluate severity by examining the degree to which a risk
factor compromises overall product quality. Alternatively, they can conduct a comprehensive analysis based
on the nature, timing and scope of the consequences. If a product is associated with multiple types of harm,
it is important to assess each type of harm individually to determine its respective severity level.
Table 2 provides a reference example of severity levels of consequences.
Table 2 — Example of severity levels of consequences
Consequence Scores
Description
(qualitative) (quantitative)
The harm is extremely serious and meets one of the following conditions:
Disastrous
(1) leading to human death, (2) threatening to spread or disseminate na-
(extremely 5
tionwide, (3) triggering widespread media coverage, causing public panic
serious)
and affecting the credibility of the government
More serious harm to meet one of the following conditions: (1) severe
disruption to consumers’ living environment that causes mass poisoning,
Critical teratogenic damage or other severe bodily injuries; (2) risk of the hazard 4
spreading across multiple regions; (3) triggering widespread negative
media coverage and public controversy
Cause certain harm, meet one of the following conditions: (1) the general
Moderate impact on human health; (2) risk of the hazard spreading in certain regions; 3
(3) triggering the media, public attention
Minor Minor impact on the consumer’s living environment or human health 2
Negligible No harm 1
5.4 Risk evaluation
Product risk evaluation involves comparing the results of the risk analysis with the established risk criteria
to prioritize risks for further risk treatment decisions. A risk matrix, combining consequence severity and
likelihood, can be applied to prioritize risks for treatment.
Based on the examples in 5.3.2 and 5.3.3, an example of risk assessment results using the risk matrix method
is given in Table 3.
The method used in the example in Table 3 is RL = L × C, i.e. the assignment of the likelihood level (L) in
Table 1 is multiplied by the assignment of the consequence severity level (C) in Table 2 to calculate the
evaluation score of the level of risk (RL).
A score less than or equal to 4 (≤4) is considered low risk, between 5 and 9 (>4 and <10) is considered
medium risk, and greater than or equal to 10 (≥10) is considered high risk.
Table 3 — Example for level of risk evaluation matrix
Consequence (C)
Negligible (1) Minor (2) Moderate (3) Critical (4) Disastrous (5)
Almost certain (5) Medium (5) High (10) High (15) High (20) High (25)
Likely (4) Low (4) Medium (8) High (12) High (16) High (20)
Likelihood
Possible (3) Low (3) Medium (6) Medium (9) High (12) High (15)
(L)
Unlikely (2) Low (2) Low (4) Medium (6) Medium (8) High (10)
Rare (1) Low (1) Low (2) Low (3) Low (4) Medium (5)
5.5 Product risk reduction based on data interchange
To help to reduce the potential product risks, it is important to make further risk treatment decisions based
on the results of the risk assessment. Targeted data interchange is one effective approach. For different
levels of product risks, the minimum amount of required data can vary based on product risk classification
in 5.4. The risk-based product quality data for interchange in e-commerce supply chain is given in Clause 6.
For low-risk products, the minimum amount of risk-based product quality data for interchange can include
basic information of product and supplier, such as product name and supplier identity, as these products
typically have minimal safety concerns and do not require extensive verification.
For medium-risk products, the minimum amount of risk-based product quality data for interchange can
include details of product quality controls, e.g. independent testing or certification programs for either
products or suppliers, or both, such as ISO 9001 certification or third-party lab testing.
For high-risk products, the minimum amount of risk-based product quality data for interchange can include
all the above data, as well as additional quality data such as verification of regulatory compliance, ongoing
monitoring, a higher sampling rate for product batches, etc.
Annex A gives a use case of risk assessment and risk-based quality data interchange in e-commerce.
6 Risk-based product quality data for interchange
6.1 Overview
The risk-based product quality data for interchange are obtained through the analysis of potential risk
sources (detailed in 5.2.2) and the identification of risk factors (outlined in 5.2.3). Because this data can
be very large and complex, it is essential to focus on the core information that shows the important risk
information clearly.
In this document, the risk-based product quality data is structured into information packages, which are
organized and refined according to different context categories. Each information package is composed
of data necessary to understand the associated risk. It can include one or more datasets or parts of
datasets, carefully selected to provide a comprehensive yet focused snapshot of risk-based product quality
data ‒ ensuring the information covers all critical dimensions while remaining concise, manageable, and
meaningful for practical use.
6.2 Information packages
Examples of risk-based information packages in e-commerce are shown in Table 4.
Table 4 — Risk-based information packages examples in e-commerce
Risk source Risk factor Information packages Description
Product Type Physical feature The tangible aspects of a product that can
be directly observable and are essential
features, such as its size, shape, weight and
colour.
Composition The materials or ingredients used to make
a product, including chemical or physical
components.
Functionality The way that a product works and what it
is designed to do. It is essentially the set
of features or capabilities that the product
provides to the user to achieve a specific
purpose or solve a particular problem.
Origin Country or region of Where a product is manufactured or grown.
origin
End use Use purpose The reason or function for which a consum-
er purchases and uses the product.
Use population The group or segment of people who are
likely to use or benefit from the product.
Use environment The context in which the product is used.
Quality attestation Self-declaration A statement made by an individual or organ-
ization confirming that the product meets
the relevant regulations.
Testing report A record of the evaluation of one or more
quality characteristics of a product or
batches of products according to specific
standards or technical requirements.
Inspection report A record of the evaluation of product com-
pliance according to relevant standards,
purchase orders, traceability requirements,
etc.
Certificate A document issued by a third party to verify
that the product complies with specific in-
dustry standards or legal requirements.
Provider of product Qualification License An official document issued by a govern-
or service ment authority that permits an individual
or organization to conduct business within
a specific geographical area (city, state or
country).
Certificate A document issued by a third party to verify
that the provider of product or service com-
plies with specific industry standards or
legal requirements.
History record Compliance record The history of a supplier’s compliance with
industry regulations, safety standards and
quality controls within their supply chain.
Noncompliance record Records of product rejection due to failure
to meet purchase requirements, record of
supplier violating industry regulations,
safety standards and quality controls within
their supply chain.
TTabablele 4 4 ((ccoonnttiinnueuedd))
Risk source Risk factor Information packages Description
Related business Online display Listing product The presentation of information about a
process information product on an e-commerce website or other
online platform.
Packaging Packaging rationality The efficiency and effectiveness of the pack-
aging design and materials in protecting
and preserving the product during trans-
portation and storage, while also minimiz-
ing the environmental impact and cost of
production.
Handling Handling rationality The efficiency, safety and cost-effectiveness
of methods, procedures, and tools used
during logistics operations such as loading,
unloading, and moving products.
Shipping Shipping conditions The terms and conditions that govern the
transportation of goods from one place to
another, including transport means, trans-
port equipment, temperature requirements,
etc.
Storage Storage conditions The specific environmental conditions in
which a product is stored to maintain its
quality and effectiveness such as tempera-
ture, humidity, light exposure, and ventila-
tion.
Inventory management Inventory management The ability to keep a certain amount of
level inventory in the warehouse according to
product features and shipment frequency
in order to fulfil the e-commerce orders
while minimizing storage costs and avoiding
stockouts, which includes timing and fre-
quency of inbound and outbound, and qual-
ity control measures to avoid quality risks
such as product deterioration, cross-con-
tamination and mixing of defective and
conforming products.
Clearance Clearance timeliness The speed at which products are cleared
through customs when crossing interna-
tional borders.
Return Return reasons The specific reasons why a buyer returns a
product to an online seller.
Customer review Negative customer The critical or unfavourable feedback given
feedback by buyers on products purchased from a
seller.
6.3 Datasets
6.3.1 Examples of datasets in a bicycle helmet information package
— Product associated:
— Physical feature: name, model, production batch, size, colour, weight.
— Composition: shell (e.g. polycarbonate), liner, straps, buckles and hardware, padding.
— Functionality: key performance parameters (e.g. ventilation), adjustment mechanisms (e.g. quick-
release buckle), additional features (e.g. integrated LED light).
— Country or region of origin: country name, country code, region.
— Use purpose: primary intended use (e.g. cycling), application context (e.g. recreational road cycling,
urban commuting), intended user role (e.g. cyclist).
— Use population: age range, head circumference, activity (e.g. non-professional cycling).
— Use environment: outdoor, temperature range.
— Self-declaration: declarant name, address, contact information, declared details about the specific
fact or circumstance, date of the declaration, signature.
— Testing report: type code, applicable object code, issuing party ID, expiry date time, issue date time,
effective date time, reference document, result description, report description.
— Inspection report: type code, applicable object code, issuing party ID, expiry date time, issue date
time, effective date time, reference document, result description, report description.
— Certificate: type code, purpose code, description, issue date time, expiry date time, issue reason
code, effective date time, applicable object code, applicable object ID, issuing party ID.
— Provider of product or service associated:
— License: entity name, address, license number, issue date time, expiry date time, type of business
activity, issuing authority.
— Certificate: type code, purpose code, description, issue date time, expiry date time, issue reason
code, effective date time, applicable object code, applicable object ID, issuing party ID.
— Compliance record: credit reports.
— Noncompliance record: customer complaints keywords.
— Business process associated:
— Listing product information associated: product name, product description, product images or
videos, quality claims.
— Shipping conditions: transport means, transport equipment, temperature control.
— Storage conditions: temperature, humidity, light exposure and ventilation.
— Inventory management level: timeliness rate for control of inbound and outbound, quality control,
carrier handover records.
— Packaging rationality: packaging o
...



