Yes, they have to verify. Verification is necessary whether or not the component is sourced through a supplier or in-house. Verification happens after the sourcing step. And yes, you are criminally liable in the supplier case if your supplier commits fraud and you knew about it, as is the implication here.
Are they legally bound to do the verification themselves ? Seems like it would be more cost efficient to outsource that as well, which would just be prone to fraud.
I did not see it mentioned where they were aware that their suppliers were committing fraud. At these large companies the executives only look at the spreadsheets and take the contracts as fact, regardless if a third party can deliver.
If you want actual compliance, you have to send actual person (that you trust - it’s another big problem as that person can get bribed) in flesh and blood to verify everything and essentially be part of supplier team. That’s the only way.