IC Onlineerai

Counterfeit Parts Reporting: A Practical Guide for OEM Buyers and Component Engineers

Practical guide for buyers and engineers: Counterfeit Parts Reporting: A Practical Guide for OEM Buyers and Component Engineers. Sourcing, risk, and selection notes.

Counterfeit Parts Reporting: A Practical Guide for OEM Buyers and Component Engineers

The Counterfeit Wave That's Forcing Buyers to Rethink Reporting

If you're an OEM buyer or component engineer, you've probably felt the shift. What was once a quarterly audit checkbox — "check for counterfeits" — has become a daily operational risk. The numbers are stark. According to ERAI's 2025 annual report, 60.02% of all reported counterfeit components were obsolete parts. That's not a fluke — it's a structural vulnerability. When a device goes end-of-life, the supply chain doesn't stop needing it; it just stops getting it through authorised channels. Brokers fill the gap, and counterfeiters fill the brokers' shelves.

The consequences are no longer theoretical. U.S. Customs and Border Protection (CBP) and European distributors have reported a measurable surge in counterfeit electronics breaching legitimate supply chains in early 2026, with seizures involving fake SSDs and mislabelled components that passed initial incoming inspection. Even more sobering: a batch of fake semiconductors made it into a military aircraft. They sailed through visual checks, only to fail in the field under heat stress testing — several units stopped functioning mid-operation. That's not a procurement problem; that's a catastrophic failure waiting to happen at altitude.

Here's the pattern that keeps repeating: a part arrives, passes visual inspection, maybe even passes a quick electrical test, gets installed, and fails in the field. The team scrambles, replaces the part, and moves on. The counterfeit goes unreported. Six months later, the same part number — from the same broker — surfaces in another assembly line, and the cycle repeats. CPSC recalls data shows that unreported counterfeits don't disappear; they recirculate. Every unreported suspect part is a future failure waiting for a different buyer.

What's changed is the velocity. ERAI's report shows roughly 24% of suspect counterfeits passed purely electrical testing, and 23.37% of faked brands were newly targeted manufacturers that hadn't previously appeared in counterfeit databases. Counterfeiters are getting better at cosmetic replication, and they're targeting brands that don't yet have robust detection profiles. Reporting isn't just about protecting your own production line — it's about starving the ecosystem that feeds counterfeiters their next victim.

Key Takeaway: Reporting a counterfeit part isn't a bureaucratic exercise. It's the single most effective lever you have to prevent the same fake from crippling your operations — or someone else's — next quarter. The data from Astute Group, AGS Devices, and ERAI all converge on the same point: silence is the counterfeiters' best supply chain partner.

How a Counterfeit Suspect Moves from Red Flag to Industry-Wide Alert

Most counterfeit parts don't announce themselves with a catastrophic explosion. They whisper — a slightly off-centre laser marking, a date code that doesn't match the manufacturer's format, a lead finish that looks too bright under the microscope. The moment an engineer or inspector flags that whisper, the reporting lifecycle begins. Getting from suspicion to a database entry that actually protects the industry requires a structured process — and most organisations discover they don't have one until they need it.

The typical lifecycle runs through four stages: suspicion, forensic analysis, documentation, and submission. At the suspicion stage, someone notices an anomaly — visual, dimensional, electrical, or paperwork-related. The part gets quarantined. Then comes forensic analysis: external visual inspection at 10x to 40x magnification, solvent testing for remarking, X-ray for die and wire bond anomalies, and decapsulation if warranted. JEDEC JESD243 defines the traceability requirements that separate a defensible report from a vague complaint, and AS5553A standardises the documented purchasing and product acceptance processes that make the entire chain auditable.

What makes a report actionable? Specificity. A report that says "the part looked suspicious" goes nowhere. A report that includes high-resolution photographs of die markings, lot and date codes, external packaging, and the original purchase documentation — along with failed test parameters and chain-of-custody records — triggers supplier investigations, database alerts, and sometimes customs seizures. Here's what the key data fields look like in practice:

Data FieldWhat to CaptureWhy It Matters
Manufacturer part numberExact marking on the component, including any suffix or revision codeEnables cross-referencing against known good parts and manufacturer databases
Lot/date codeAll markings on the component body and packaging label; photograph at 10x magnification minimumLot code anomalies are the single most common red flag; date codes outside the manufacturer's valid range are immediate disqualifiers
Supplier identityFull legal name, address, and contact details of the seller; whether they are franchised, authorised, or independentEstablishes the supply chain node where the counterfeit entered; ERAI and GIDEP use this to trace distribution networks
Purchase documentationPurchase order, invoice, packing slip, certificate of conformance, and any test reports provided by the supplierDocuments the contractual chain; discrepancies between the CoC and the physical part are strong evidence of misrepresentation
External packaging photosAll sides of the box, reel, tray, or tube; ESD bag markings; moisture barrier bag labels and indicator cardsPackaging inconsistencies — wrong logo, misspelled warnings, incorrect moisture sensitivity level — are frequently the giveaway
Component photographsTop, bottom, and side views at 10x to 40x; pin 1 indicator; any laser etching or ink marking; surface texture under oblique lightingVisual evidence of sanding, remarking, blacktopping, or inconsistent lead finish is admissible in supplier disputes and legal action
Test resultsElectrical test data (curve trace, functional test, X-ray, decapsulation); specify the test standard and equipment used~24% of suspect counterfeits pass basic electrical testing; advanced tests like X-ray and decap are often necessary to confirm
Chain of custodyWho handled the part, when, and under what storage conditions, from receipt through quarantine to forensic analysisRequired by AS5553 and JEDEC JESD243; a broken chain of custody makes the report legally vulnerable
Failure contextWhere and how the part failed; operating conditions (temperature, voltage, duty cycle); any field failure dataProvides critical context for assessing risk severity and prioritising the alert in databases like GIDEP

Once the evidence package is assembled, the report is submitted to one or more databases: ERAI for commercial and industrial alerts, GIDEP for defence and aerospace, or the CPSC for consumer product safety issues. The report then enters a review cycle — typically 24 to 72 hours for ERAI, longer for government portals — and, if validated, gets disseminated to the subscriber base. That's when the industry-wide protection kicks in.

Note: The quality of your evidence directly determines the speed of takedown. Reports with incomplete lot codes or blurry photos get deprioritised or rejected. Invest the time upfront in forensic-quality documentation, and the reporting system works in your favour.

ERAI, GIDEP, AS5553, or Government: Which Reporting Channel Gets the Fastest Takedown?

Not all reporting channels are built for the same mission. ERAI, GIDEP, the CPSC, and standards-based reporting under AS5553 each serve different constituencies, operate at different speeds, and offer different levels of confidentiality and enforcement. Choosing the wrong channel can mean the difference between a supplier being flagged within 48 hours and your report sitting in a queue for three weeks while counterfeit parts continue to ship. Here's how the four main pathways compare:

Comparison MetricERAIGIDEPCPSC / Government PortalsSelection Criteria & Failure Boundary
Primary audienceCommercial and industrial electronics supply chain; component buyers, distributors, and OEMsDefence and aerospace contractors; U.S. and allied military programs; requires membershipConsumer product safety; broader regulatory enforcement; public-facing recallsMatch the channel to your end market: defence parts go to GIDEP, consumer goods to CPSC, everything else to ERAI
Reporting speed (typical)24–72 hours from submission to alert dissemination3–10 business days; controlled review process before releaseWeeks to months; investigation-driven with legal thresholdsERAI is the fastest for commercial takedowns; GIDEP is slower but offers deeper investigation for military programs
ConfidentialityAllows anonymous reporting; reporter identity protectedProtects reporting organisation identity; controlled dissemination within member baseVaries by agency; CPSC allows confidential reporting but may require disclosure during enforcementIf supplier retaliation is a concern, ERAI and GIDEP offer the strongest anonymity protections
Evidence requirementsHigh-resolution photos, lot codes, supplier details, test results; flexible but thoroughness determines speedStringent; must meet AS5553 or JEDEC JESD243 documentation standards; chain of custody is mandatoryLegal-grade evidence; may require third-party lab validation and formal complaint filingGIDEP and CPSC demand more evidence upfront; ERAI is more accessible for first-time reporters
Feedback loopAlerts are publicly searchable; subscribers receive email notifications; follow-up investigation reports availableClosed-loop within member organisations; no public dissemination; detailed investigation summaries shared internallyPublic recall notices; enforcement actions are published; limited direct feedback to the reporterERAI provides the broadest industry visibility; GIDEP keeps sensitive defence data contained
Enforcement capabilityNo direct enforcement; alerts empower buyers to blacklist suppliers and trigger civil litigationNo direct enforcement; alerts can trigger contract reviews, debarment, and federal investigation referralsDirect enforcement: CPSC can mandate recalls; CBP can seize shipments; DOJ can prosecuteFor legal enforcement, government portals are the only option; ERAI and GIDEP are industry self-policing tools

In practice, many seasoned OEM buyers use a layered approach. They file the initial alert with ERAI for speed — getting the supplier flagged in the commercial database within days — and simultaneously prepare a GIDEP submission if the part touches a defence contract. Consumer product manufacturers may escalate to the CPSC only when the counterfeit creates a safety hazard that triggers mandatory reporting obligations. NTS Unitek's guidance on counterfeit parts detection reinforces that AS5553 standardises the requirements for aerospace and defence, making GIDEP reporting more structured and defensible. Industrial Automation Co.'s practical spotting guide and IFL Manufacturing's sourcing guide both highlight that the choice of reporting channel should match the component's risk profile — a fake PLC in a factory has different reporting requirements than a counterfeit IC in a missile guidance system.

Tip: If you're unsure which channel to use, start with ERAI. Its lower barrier to entry and faster turnaround mean you'll get an alert circulating while you assess whether GIDEP or CPSC escalation is warranted. The worst outcome is reporting nowhere while you deliberate.

From Detection to Documentation: A Reporting-Ready Workflow for OEM Buyers and Engineers

Embedding counterfeit reporting into your receiving inspection and procurement process isn't about adding bureaucracy — it's about building a muscle memory that kicks in the moment a red flag appears. The best workflows are invisible until they're needed, and they're built on three principles: standardise the evidence capture, reference the right standards, and preserve the chain of custody without paralysing production.

Chipsgate's procurement guide provides practical checklists that start at the receiving dock, and NTS Unitek's detection methodology walks through the forensic steps that transform a suspicion into a defensible report. Combined with the documentation frameworks from JEDEC JESD243 and AS5553A, you have everything you need to make your report stick — and to give your legal team the ammunition they need if the supplier pushes back.

Here's a step-by-step workflow that integrates reporting into your existing inspection process:

  1. Quarantine immediately. The moment a part is flagged — whether by visual inspection, electrical test anomaly, or paperwork discrepancy — segregate the entire suspect batch in a physically separate, access-controlled area. Do not mix suspect parts with known-good inventory. Label the quarantine location with the date, inspector name, and reason for hold.
  2. Photograph everything before you touch anything. Capture the external packaging from all six sides, including shipping labels, barcodes, and any carrier markings. Photograph the interior packaging — reel, tray, tube, ESD bag, moisture barrier bag, desiccant pack, and humidity indicator card. Then photograph the component itself at 10x magnification minimum, capturing top markings, pin 1 indicator, and any surface anomalies. Close inspection of die markings is often required to distinguish genuine components from high-quality counterfeits.
  3. Pull the paper trail. Retrieve the purchase order, invoice, packing slip, certificate of conformance, and any incoming inspection records. Cross-reference the lot/date code on the component against the CoC and the manufacturer's known valid date code formats. A mismatch here is often the fastest path to a confirmed counterfeit finding.
  4. Document the red flag with specificity. Don't write "looks suspicious." Write: "Laser marking font inconsistent with manufacturer's known format for date code 2247; pin 1 dimple depth 0.15 mm vs. 0.30 mm on known-good sample; lead finish shows tin whisker formation inconsistent with matte tin specification." Reference the applicable standard — AS5553 or JEDEC JESD243 — in your documentation to establish the technical basis for the finding.
  5. Run the electrical and physical tests. Curve trace against a known-good sample. Perform X-ray inspection for die size, wire bond count, and lead frame anomalies. If the part is still suspect, decapsulation is the gold standard. Remember ERAI's finding: roughly 24% of suspect counterfeits pass basic electrical testing — so a "pass" on the curve tracer doesn't clear the part.
  6. Maintain chain of custody. Document every person who handles the part from quarantine through testing, with timestamps and signatures. This isn't optional under AS5553 — it's a requirement. A broken chain of custody gives the supplier's legal team an opening to challenge the entire report.
  7. Submit the report to the appropriate channel. Based on the component's end use and your industry, file with ERAI, GIDEP, or the CPSC. Include all evidence, reference the standard you used for testing, and specify whether you're requesting confidentiality. If the part touches a military contract, you may have mandatory GIDEP reporting obligations under your contract terms.
  8. Follow up and track. Set a calendar reminder for 30 days to check the status of your report. If you haven't received acknowledgment, follow up. Reports that sit unacknowledged protect no one.

Here's a quick-reference table for the documentation package that makes your report actionable under AS5553 and JEDEC JESD243:

Evidence ElementMinimum StandardStandard Reference
Component photographs10x–40x magnification; top, bottom, side views; pin 1 indicator; oblique lighting for surface textureAS5553 §4.3.2; JEDEC JESD243 §6.2
Packaging photographsAll sides of outer and inner packaging; ESD bag markings; moisture barrier label and indicator; desiccant conditionAS5553 §4.3.1; JEDEC JESD243 §6.1
Lot/date code cross-referenceManufacturer's valid date code format verified against authorised distributor records or manufacturer documentationJEDEC JESD243 §5.3
Electrical test dataCurve trace comparison against known-good sample; functional test at nominal and boundary conditionsAS5553 §4.4; JEDEC JESD243 §6.4
X-ray inspectionDie size, wire bond count, lead frame geometry compared to known-good referenceAS5553 §4.4.2; JEDEC JESD243 §6.5
Decapsulation (if applicable)Die markings, manufacturer logo, die layout compared to known-good referenceAS5553 §4.4.3; JEDEC JESD243 §6.6
Chain of custody logSigned and timestamped record of every individual who handled the part from quarantine through testingAS5553 §4.5; JEDEC JESD243 §7
Purchase documentationPO, invoice, packing slip, CoC from supplier; any correspondence regarding the part's provenanceAS5553 §3.2; JEDEC JESD243 §5.1

Elisa Industriq's procurement guide for 2026 makes a point that deserves emphasis: counterfeit parts rarely announce themselves. The quality paperwork — CoC, test reports, traceability — is where the gaps first appear. Train your receiving inspectors to treat paperwork discrepancies with the same urgency as physical anomalies. A CoC that lists a date code the manufacturer never produced is as damning as a sanded-off laser marking.

Counterfeit Parts Reporting: What Senior Engineers and Procurement Leads Actually Ask

After 15 years in this industry, I've heard every variation of these questions. The answers aren't textbook — they're shaped by the reality of production schedules, supplier relationships, and the legal exposure that keeps procurement managers up at night. Here's what you actually need to know.

Q: We suspect a part but can't stop production. How do we report without triggering a line-down situation?

This is the most common dilemma in high-volume manufacturing. The answer is quarantine, not shutdown. Immediately segregate the suspect stock — physically move it to a locked, access-controlled area — and document the batch with high-resolution photos of the markings, packaging, and labels. Production continues with verified authentic parts from your known-good inventory or a trusted authorised distributor. In parallel, submit a preliminary report to ERAI or your internal quality system. The investigation runs on its own timeline while production stays up. The key is to never mix suspect and known-good inventory — once that line is blurred, you're in a much harder position to isolate the problem. Elisa Industriq's procurement guide reinforces that NCNR (no cancel, no return) terms and unclear provenance are the red flags that should trigger quarantine before the parts ever reach the production floor.

Q: What's the difference between reporting to ERAI, GIDEP, and the CPSC, and which one gets the fastest response?

ERAI is the industry's commercial nerve centre. It's open to all, doesn't require government membership, and typically disseminates alerts within 24 to 72 hours of a validated submission. If you want the broadest, fastest commercial takedown, ERAI is your first stop. GIDEP is defence-focused, requires membership, and operates a controlled dissemination model — alerts go only to vetted member organisations, which makes it ideal for sensitive military programs but slower (3 to 10 business days). The CPSC targets consumer product safety and operates on an investigation-driven timeline that can take weeks or months; it's the channel for safety hazards that may trigger mandatory recalls. NTS Unitek notes that AS5553 standardises the requirements for aerospace and defence, effectively making GIDEP the default reporting pathway for any part that touches a military contract. If you're a commercial OEM, start with ERAI. If you're in defence, you likely have contractual obligations to report through GIDEP as well.

Q: Does reporting a counterfeit part to authorities expose us to legal consequences if we unknowingly used it in a product?

Generally, no — good-faith reporting is encouraged and often protected under whistleblower provisions and industry practice. ERAI, GIDEP, and the CPSC all have mechanisms that protect reporters who act in good faith. However, "unknowingly" is the operative word. If your organisation failed to follow reasonable inspection practices, or if you had red flags that were ignored, the legal calculus shifts. This is why you should work with legal counsel before submitting a report — not to avoid reporting, but to ensure the report is factual, does not inadvertently admit liability, and addresses any contractual obligations you have to your end customer. The report should state what you found, what tests you ran, and what the results were — not what you think the supplier's intent was. Stick to the facts, and let the data speak.

Q: Can we file a confidential report, and will our supplier be notified?

Yes, you can file confidentially, and no, the supplier is not automatically notified. ERAI explicitly allows anonymous reporting, and GIDEP protects the identity of the reporting organisation within its controlled dissemination framework. Government portals like the CPSC also allow confidential reporting, though the level of protection varies by agency and may be challenged during enforcement actions. The practical reality: if your report leads to an investigation or a supplier blacklisting, the supplier may eventually deduce the source — especially if you're their only customer for that part number. But the initial report does not trigger automatic notification, and you can request confidentiality from all three channels. If supplier retaliation is a genuine concern, ERAI's anonymous submission option is the safest starting point.

Q: What specific evidence do we need to make a report stick under AS5553 or JEDEC JESD243?

The standards are clear on this: you need high-magnification photographs (10x to 40x) of die markings, lot and date codes, external packaging from all sides, and the original purchase documentation — purchase order, invoice, packing slip, and certificate of conformance. You must also document the test results that the part failed, specifying the test standard and equipment used. Critically, you must maintain a documented chain of custody — every person who touched the part, when, and under what conditions — from the moment it was flagged through forensic analysis. Reference the applicable standard (AS5553 or JEDEC JESD243) directly in the report to establish the technical basis. Reports that omit the chain of custody or rely on verbal descriptions instead of photographic evidence are routinely rejected or deprioritised. JEDEC JESD243 §7 is explicit about traceability requirements, and AS5553A §4.5 ties the entire documentation package to purchasing and product acceptance processes. Follow the framework, and your report won't just be credible — it'll be actionable.

References & Further Reading

Reporting counterfeit parts is not a compliance checkbox — it's a supply chain survival skill. Every report you file protects not just your own production line but every other buyer who might otherwise walk into the same trap. The tools, standards, and databases are in place. The missing piece in most organisations is the internal workflow that turns a suspicious part into a documented, submitted, and tracked alert. Build that workflow, train your team on it, and use it. The counterfeiters are counting on your silence. Don't give it to them. For mixed BOM sourcing with flexible MOQ and verified supply chains, explore the options at IC-Online.

Related Articles