Skip to content

SMETA Audit Guide: Sedex Social Compliance

Sedex reports over 75,000 members across 180 countries, with more than 340,000 SMETA audits conducted globally. The most common non-compliance findings — working hours, wages below the legal minimum, and inadequate health and safety controls — appear consistently across the textile, electronics, and agriculture sectors. Under the UK Modern Slavery Act, brands like Marks & Spencer, Tesco, Unilever, and Primark explicitly cite SMETA audit programs in their public modern slavery statements, and the EU's CSDDD now extends similar due diligence obligations across the entire bloc. For a supplier, a lapsed or missing SMETA report increasingly means automated deselection from buyer procurement systems — often before a human reviewer ever sees the application.

SMETA (Sedex Members Ethical Trade Audit) is the most widely used social compliance audit methodology in the world. It assesses working conditions across labor standards, health and safety, environmental management, and business ethics. For suppliers in apparel, textiles, electronics, furniture, and FMCG, a current SMETA audit report is often the price of admission to the Western buyer market. On the Sustalium platform, we see the same buyer who requests a CE Declaration of Conformity now routinely asking for the most recent social audit — because procurement teams are being measured on supply chain risk, not just product compliance.

What SMETA Actually Audits

SMETA is an audit methodology, not a certification standard. An approved auditor organization conducts the audit using the SMETA framework, and the resulting report is uploaded to the Sedex platform for sharing with buyers.

SMETA comes in two configurations:

2-Pillar Audit

  • Pillar 1 — Labor Standards: Assesses compliance with the ETI Base Code, including freely chosen employment, freedom of association, safe working conditions, no child labor, living wages, reasonable working hours, no discrimination, no harsh treatment, and regular employment.
  • Pillar 2 — Health and Safety: Assesses workplace safety management systems, hazard identification, emergency preparedness, worker accommodation standards (where provided), and health and safety training.

4-Pillar Audit (Increasingly the Default)

Adds two additional pillars:

  • Pillar 3 — Environmental Assessment: Evaluates environmental management systems, waste management, energy and water use, emissions, and compliance with environmental permits — though at a less comprehensive level than a dedicated ISO 14001 audit.
  • Pillar 4 — Business Ethics: Assesses anti-bribery and corruption policies, whistleblowing mechanisms, fair competition practices, and transparency in business relationships.

Most major brands now require 4-pillar SMETA audits for all new suppliers, and an increasing number are retroactively requiring existing suppliers to upgrade from 2-pillar to 4-pillar.

The SMETA Audit Process

Step 1: Sedex Membership

The supplier joins Sedex as a member (Sedex A or AB membership depending on whether they participate in buyer relationships). Sedex membership provides access to the platform where audit reports are uploaded, self-assessment questionnaires are completed, and audit data is shared with linked buyers.

Step 2: Select an Approved Auditor

The supplier selects an audit firm from Sedex's list of approved Affiliate Audit Companies (AACs). Only audits conducted by AACs are recognized as SMETA audits. Common AACs include SGS, Bureau Veritas, Intertek, TÜV, and ALS.

Step 3: Pre-Audit Preparation

The audit firm provides a document list well in advance. Key documents include: - Employee contracts, time records, and payroll data for the previous 12 months - Health and safety policy, risk assessments, and training records - Environmental permits, waste transfer notes, and emissions records - Business ethics policy and anti-bribery register

Step 4: On-Site Audit

The audit typically takes 1–3 days depending on facility size and employee count. It includes: - Opening meeting with management - Facility walkthrough (production areas, warehouse, worker accommodation, canteen) - Document review (payroll, time records, contracts, permits) - Confidential worker interviews (selected by auditor, without management present) - Closing meeting with preliminary findings

Step 5: Corrective Action Plan (CAP)

Audit findings are classified as non-compliances (Critical, Major, or Minor) or observations. For each finding, the supplier must submit a Corrective Action Plan (CAP) within the timeframe specified by the buyer. Many buyers will not approve a supplier until all Major and Critical non-compliances are closed with verified evidence.

How Buyers Use SMETA Reports

For brands and retailers subject to modern slavery reporting (UK Modern Slavery Act, Australian Modern Slavery Act, Canadian Fighting Against Forced Labour and Child Labour in Supply Chains Act), SMETA audit reports serve as primary evidence of supply chain due diligence.

In practice, a buyer's procurement system typically: 1. Checks that the supplier has an active Sedex membership 2. Verifies the most recent SMETA audit is within the buyer's validity window (usually 12 months for new suppliers) 3. Reviews open non-compliances against the buyer's risk tolerance 4. Links the report to the buyer's internal supplier approval or risk scorecard

A supplier with no SMETA report — or an expired one — is often automatically deselected without human review.

How Sustalium Simplifies SMETA Management

Suppliers managing SMETA reports, corrective action plans, and multiple buyer requests through email, spreadsheets, and the Sedex platform alone face a documentation fragmentation problem.

Sustalium's social audit and supply chain compliance platform centralizes the supplier's social compliance documentation:

  • Unified Document Hub: Upload your SMETA audit report, CAP, supporting evidence, and non-compliance closure letters into a single structured profile. When a buyer asks, share one link — not six attachments.
  • Expiry and Audit Cycle Tracking: Sustalium tracks your current SMETA audit expiry date, CAP deadlines, and next audit window. Automated reminders prevent the lapsed-document scenario that loses buyer relationships.
  • Multi-Framework Integration: Your SMETA report sits alongside your other buyer-facing compliance documents — REACH declarations, conflict mineral reports, country-of-origin declarations, and product safety certificates. One buyer link covers multiple procurement requirements, reducing the administrative overhead of responding to repetitive data requests.
  • Buyer-Ready Compliance Pages: Generate a public URL displaying your current SMETA audit status, Sedex membership number, audit date, and CAP status — giving procurement teams instant confidence without the back-and-forth of email requests.

Never Lose a Buyer to an Expired SMETA Report Again

A missed audit renewal can silently disqualify you from buyer shortlists. Track your SMETA audit status, manage CAP deadlines, and share your compliance profile with every buyer instantly.

With Sustalium, build your social compliance profile for just €10 per document.

Share Your SMETA Report Now →

Frequently Asked Questions

Is SMETA the same as a certification?

No. SMETA is an audit methodology — it produces a report, not a certificate. There is no "pass" or "fail." The audit identifies findings, and buyers decide whether the findings are acceptable for their risk tolerance. This is different from certification standards like GOTS or ISO 27001, where a certificate is issued.

How long is a SMETA audit valid?

Most buyers accept SMETA audits for 12 months from the audit date. Some buyers may extend to 18–24 months for low-risk suppliers, but 12 months is the industry norm. A new audit is typically required before the previous one expires.

What is the difference between a full SMETA audit and a follow-up audit?

A full SMETA audit is a complete assessment of all pillars. A follow-up (or partial) audit verifies closure of non-compliances identified in a previous audit — typically for Critical and Major findings. Follow-ups are narrower in scope and shorter in duration.

Do I need a new SMETA audit if I already have a BSCI or SA8000 audit?

It depends on the buyer. Some buyers accept BSCI or SA8000 audits as equivalent to SMETA. Others specifically require SMETA methodology, as it is the most common standard on the Sedex platform. If a buyer mandates SMETA, a BSCI or SA8000 audit alone will not satisfy the requirement.



Last updated: July 16, 2026