SMETA Audit: Pillars, Process and How It Works

A SMETA audit assesses a supplier's working conditions against the ETI Base Code. It comes in two scopes: 2-pillar (labour and health and safety) and 4-pillar (adding environment and business ethics). It is an audit methodology, not a certification, with no grade; the report lasts about 12 months.

SMETA audit: a Sedex-approved auditor reviewing a garment factory's labour, health and safety, environment and ethics on site

If you make clothing overseas, a customer will eventually ask for a SMETA audit, or you will need one to prove your factory treats its workers properly. It is the most common social audit in fashion, and it is widely misunderstood: it is not a certification, and it does not give you a pass mark.

This guide explains what a SMETA audit is, the difference between 2-pillar and 4-pillar, how the process works, and how it compares to BSCI and SA8000, as part of sourcing ethically. It sits alongside sustainable sourcing as a core supplier-vetting tool.

What is a SMETA audit?

SMETA, the Sedex Members Ethical Trade Audit, is a social audit that assesses working conditions at a supplier site. Powered by Sedex, it is the world's most widely used ethical audit, with tens of thousands of companies using the same methodology, which is exactly why brands ask for it.

It measures a site against the ETI (Ethical Trading Initiative) Base Code, the ILO conventions, and local law. The point is a single, consistent picture of labour, safety, environmental and ethical practice that a supplier can share with many customers, instead of being audited separately by each one.

Is a SMETA audit a certification?

No, and this is the most important thing to understand about it. SMETA is an audit methodology, not a certification. There is no SMETA certificate to earn and no pass or fail grade.

What a SMETA audit produces is a report: the auditor's findings across the pillars audited, any non-compliances found, and a Corrective Action Plan Report (CAPR) agreed with the site to fix them. The report is uploaded to the Sedex platform, where the supplier chooses which customers can see it. Its value is transparency and a shared format, not a badge.

SMETA 2-pillar vs 4-pillar

A SMETA audit is run to one of two scopes, and the two mandatory pillars are the same in both.

  • 2-pillar (the base): Labour Standards and Health and Safety, plus additional elements, the universal rights under the UN Guiding Principles, management systems, entitlement to work, and subcontracting and homeworking, and a short environment check. It typically takes about two days.
  • 4-pillar (the full scope): everything in the 2-pillar audit, plus an extended Environment assessment (replacing the short one) and a Business Ethics pillar. It typically takes about three days.

So the four pillars are Labour, Health and Safety, Environment and Business Ethics. Labour and Health and Safety are always mandatory; Environment and Business Ethics are what the 4-pillar audit adds. Many brands now ask suppliers for the 4-pillar version, because it is the one that covers the full ESG picture buyers increasingly expect.

What a SMETA audit checks

Across those pillars, a SMETA audit looks at the conditions that decide whether a site is a responsible place to work.

  • Labour standards: freely chosen employment (no forced labour), no child labour, freedom of association, living wages, working hours, no discrimination, and regular, documented employment.
  • Health and safety: safe and hygienic working conditions, machine and fire safety, and the systems that keep them in place.
  • Environment: in the 4-pillar audit, air emissions and greenhouse gases, chemical management, energy and water use, and waste.
  • Business ethics: anti-bribery and anti-corruption practices, in the 4-pillar audit.

In garment factories, the non-compliances auditors flag most often are familiar: excessive overtime and working hours, gaps in wage and social-insurance records, blocked or locked fire exits, missing machine guarding or protective equipment, and incomplete health-and-safety documentation. Knowing the usual failure points is the fastest way for a supplier to prepare and for a brand to read a report.

How a SMETA audit works, step by step

A SMETA audit is not just the day the auditor arrives; it is a short process with preparation on either side.

  1. Join Sedex: the site must be a registered Sedex member with an active account to have a SMETA audit and share it.
  2. Complete the SAQ: the site fills in a Self-Assessment Questionnaire on the platform before the audit.
  3. Book an approved auditor: the audit is carried out by an Affiliate Audit Company (AAC), a third party approved by Sedex, as an announced, semi-announced or unannounced visit.
  4. The on-site audit: an opening meeting, a review of documents and records, a site tour, and confidential interviews with both management and workers.
  5. The report and CAPR: findings go into the SMETA report on the Sedex platform, and any non-compliances get a Corrective Action Plan Report to close out.

The report is valid for about 12 months, so most brands re-audit their key suppliers on a yearly cycle and begin re-booking a few months before it expires. SMETA itself is periodically updated, and the current SMETA 7.0 keeps the same structure: the ETI Base Code, the 2- and 4-pillar scopes, and the three visit types.

SMETA vs BSCI vs SLCP vs SA8000

SMETA is one of several social-compliance tools, and the differences matter when a brand decides what to ask suppliers for.

  • SMETA (Sedex): an audit methodology with a shared report and no grade. Built on the ETI Base Code; widely accepted, which reduces duplicate audits.
  • amfori BSCI: also an audit, but it grades a site on a scale from A to E, and runs on amfori's own system rather than a shared report.
  • SLCP: not an audit at all. It is a converged assessment, a verified self-assessment that produces comparable data rather than a pass or fail, designed to cut audit fatigue.
  • SA8000: a full certification standard. Unlike SMETA, it is a pass-or-fail certificate issued by an accredited body, and it is the hardest of the four to achieve.

The short version: SMETA and BSCI are audits, SLCP is an assessment framework, and SA8000 is a certification. A SMETA report is the most commonly requested because it is shareable and widely recognised, not because it is the strictest.

How fashion brands use SMETA in sourcing

For a fashion brand, a SMETA report is a supplier-vetting and risk tool. Either the brand asks a factory to hold a current one, or the factory commissions its own to win business, and the shared report saves everyone repeating the same audit. It pairs naturally with finding the right manufacturer and with the quality checks that sit alongside it.

It also cuts audit fatigue. Because the report is shared through Sedex in one standard format, a factory audited once can show the same result to every customer that asks, instead of hosting a separate audit for each brand. The cost usually sits with the supplier, though some brands share or sponsor it for strategic partners.

The report is the start, not the end. The non-compliances and their corrective actions are the real signal, and tracking whether suppliers actually close them out, season after season, is what separates a box-ticking audit from genuine ethical sourcing.

From an audit report to a sourcing decision

A single SMETA report grades one site at one moment. The sharper signal is the pattern across your supplier base: who passes clean, which non-compliances keep recurring, and where risk is concentrated. Apshan builds the connected, sourced read on supply and compliance that informs it. See how it feeds sustainable sourcing and textile sourcing, request access, or view the plans and pricing.

Questions

What is a SMETA audit?

A SMETA (Sedex Members Ethical Trade Audit) is the world's most widely used social audit. It assesses a supplier site's labour, health and safety, environment and business ethics against the ETI Base Code and ILO conventions, and produces a shared report rather than a certificate.

What is the difference between a 2-pillar and 4-pillar SMETA audit?

Both cover the two mandatory pillars, labour standards and health and safety. A 4-pillar audit adds two more: an extended environmental assessment and business ethics. A 2-pillar audit takes about two days, a 4-pillar audit about three, and many brands now ask for the 4-pillar version.

Is a SMETA audit a certification?

No. SMETA is an audit methodology, not a certification, and there is no pass or fail grade. It produces a report of the auditor's findings plus a corrective action plan for any non-compliances, shared with customers through the Sedex platform. SA8000, by contrast, is a certification.

How long is a SMETA audit valid?

A SMETA audit report is generally valid for about 12 months. To avoid a gap, most sites and their customers start re-booking the next audit three to four months before the current report expires, keeping supplier compliance continuous.

Who can conduct a SMETA audit?

Only an Affiliate Audit Company (AAC), a third-party auditor approved by Sedex, can conduct a SMETA audit. The site must also be a registered Sedex member with an active account in order to have the audit carried out and share the report with customers.

What is the difference between SMETA and BSCI?

Both are social-compliance audits based on ILO standards, but SMETA produces a shared report with no grade, while amfori BSCI grades a site on an A-to-E scale and runs on amfori's own system. SMETA is often preferred because its shared format reduces duplicate audits across customers.

The intelligence exists before the question.

Invite-only. Request access now.