Optima Bags has been audited for almost every year of its thirty-year history. ISO 9001. ISO 14001. ISO 45001. SEDEX 4-Pillar audits, some announced, some not. Buyers like Amazon and Disney don't take a factory's word for it. They send someone to check the paperwork, walk the floor, and confirm that what's written down actually matches what's happening.
That process teaches you something most businesses never learn: a policy on paper means nothing if nobody checks that it's actually being followed. An auditor doesn't ask whether you have a safety policy. They ask to see the incident log, the training records, the evidence that the policy is real.
Over the past year, while working with other business owners on their websites and marketing, we kept noticing the same gap, just in a different place. Most sites now show a cookie consent banner. Almost none of them had actually checked whether it does what it claims. Trackers that fire before a visitor makes a choice. A "reject" button that doesn't stop data from leaving the site. Ad and analytics vendors with no signed agreement covering what they're allowed to do with that data. It's the exact same failure pattern we spent three decades learning to catch in a factory, just showing up on a website instead of a production floor.
State privacy laws in the US, and GDPR in the EU, now treat this the same way a buyer compliance audit does. A banner that exists but doesn't function isn't a defense. Several companies have paid real fines in the past year for precisely this gap, a cookie tool installed, never verified.
That's why we started Optima Lab, a compliance audit practice for other businesses' websites, run with the same discipline we've applied to our own factory for thirty years. It checks what's actually running on a site, what data it sends and to whom, and backs the fix with documentation reviewed by independent counsel, not just a plugin and a policy nobody reads.
If you run a website that collects any visitor data, which is nearly every website today, it's worth checking whether your setup would survive the kind of audit we've spent thirty years passing.