SMETA Compliance Software | Sedex Audit Evidence Management & Supplier Risk | Certivo - Certivo
SMETA (Sedex Members Ethical Trade Audit) Compliance
Ethical Supply Chain & Labor
Sedex Members Ethical Trade Audit
55,000+ Sedex Members. 300,000+ Audits Conducted. Can You Prove Ethical Compliance Across Your Entire Supplier Base?
SMETA compliance requires supplier-level evidence across labour standards, health and safety, environment, and business ethics—with corrective action plans tracked to closure. SMETA 7.0 now demands management systems maturity, not just point-in-time documentation. Customer requests for SMETA audit visibility are increasing.
Certivo automates SMETA evidence management from supplier self-assessment to audit-ready corrective action tracking.
Regulation Overview
Jurisdiction: Global (Sedex members across 180 countries; UK-headquartered)
Regulatory Body: Sedex (Supplier Ethical Data Exchange)
Regulation Number: SMETA 7.0 (released 2024), based on ETI Base Code and ILO Conventions
Effective Date: SMETA 7.0 effective 2024; Sedex founded 2004
Official Source: Sedex SMETA Audit
Key Threshold: ETI Base Code + local law + ILO Conventions
What is SMETA?
SMETA is the world's most widely used social audit methodology, developed by Sedex to assess labour standards, health and safety, environmental performance, and business ethics across global supply chains. For supply chain compliance teams, SMETA is the dominant framework through which customers evaluate ethical sourcing and supplier risk scoring.
SMETA 7.0, released in 2024, introduced a Management Systems Assessment (MSA), Collaborative Action Required (CAR) findings for complex issues, and standardized workplace requirements. Audit reports older than 24 months are no longer considered robust. Buyers increasingly require 4-pillar audits—covering environment and business ethics alongside the mandatory labour and health and safety pillars.
SMETA compliance requires site-level evidence—policies, procedures, training records, worker interviews, and corrective action documentation—from every audited supplier. When customers request SMETA audit data, your team must provide complete visibility through the Sedex platform or equivalent documentation.
Key Components / Sub-Frameworks
Obligation
- Mandatory in all SMETA audits
Pillar 1: Labour Standards
ETI Base Code covering wages, working hours, child labour, forced labour, discrimination, freedom of association - Obligation
- Mandatory in all SMETA audits
Pillar 2: Health & Safety
Workplace conditions, emergency preparedness, first aid, occupational health, chemical safety - Obligation
Included in 4-pillar SMETA audits
Pillar 3: Environment
Energy use, GHG emissions, waste management, water use, pollution prevention - Obligation
Included in 4-pillar SMETA audits
Pillar 4: Business Ethics
Anti-bribery, anti-corruption, data protection, whistleblowing, human rights policies - Obligation
New in SMETA 7.0
Management Systems Assessment (MSA)
Evaluation of site-level management maturity for identifying and resolving root causes - Obligation
Required for all Sedex members
Self-Assessment Questionnaire (SAQ)
Supplier self-reported data on Sedex platform across five ESG categories
Key Compliance Requirements
Who Must Comply
- Suppliers requested by buyers to complete SMETA audits via Sedex membership
- Manufacturers and production sites supplying to Sedex buyer members
- Companies in global supply chains where customers require ethical trade evidence
- Non-EU suppliers exporting to European retailers and brands
- Companies preparing for CSDDD, LkSG, or UK Modern Slavery Act with SMETA as evidence
- Any Sedex member site subject to 2-pillar or 4-pillar audit scope
Key Thresholds
Sedex Membership
- Required before any SMETA audit can be conducted or uploaded
2-pillar or 4-pillar scope
- Determined by buyer requirements; 4-pillar increasingly standard
24-month audit validity
- Reports older than 24 months no longer considered robust under SMETA 7.0
Corrective Action Closure
- Non-conformances require documented corrective action with auditor verification
Core Obligations
Self-Assessment Questionnaire (SAQ)Complete and maintain SAQ on Sedex platform covering labour, H&S, environment, ethicsDEADLINE:Upon Sedex membership; updated as requiredSMETA Audit (2 or 4 Pillar)On-site audit by approved Affiliate Audit Company (AAC)DEADLINE:As requested by buyer; typically every 1–3 years based on riskCorrective Action Plan (CAP)Address all non-conformances identified in audit reportDEADLINE:Timelines set per finding; verified by original auditorCollaborative Action Required (CAR)Long-term remediation for systemic issues requiring multi-stakeholder actionDEADLINE:May span multiple years; tracked through SedexData Sharing on SedexShare audit report and SAQ data with linked buyer membersDEADLINE:Ongoing; authorized by supplier
SMETA-Specific Pain Points
The Multi-Customer Audit Demand
You supply to 15 brands across the EU and UK. Seven require SMETA 4-pillar audits. Three accept SMETA 2-pillar. Two request amfori BSCI instead. Each buyer wants audit visibility through Sedex, but their specific requirements differ—some demand semi-announced audits, others require CAR resolution evidence. Your compliance team manages parallel audit preparation for the same site with no centralized system of record.
The Corrective Action Black Hole
Your SMETA audit surfaces 23 non-conformances across 8 supplier sites. Corrective action plans are tracked in spreadsheets, email chains, and the Sedex platform—but not in one place. Follow-up evidence is scattered. Three suppliers haven't responded. Two submitted evidence in formats the original auditor can't verify. Buyers request CAP status. You can't provide a real-time answer.
The Management Systems Maturity Gap
SMETA 7.0 now evaluates management system maturity—policies, procedures, training, and root cause analysis capability. This is no longer a file-readiness exercise. Suppliers with robust documentation but weak systems will receive non-conformances. Without continuous evidence of systemic improvement, your suppliers fail the new standard.
The Visibility and Reporting Burden
Buyers increasingly want not just SMETA audit results but aggregated supplier risk scoring across their supply chain. You need to report on audit coverage, non-conformance rates by category, corrective action closure rates, and overdue items—across hundreds of supplier sites. Compiling this from Sedex data, audit PDFs, and email evidence takes weeks. Manual ethical trade compliance management at this scale is unsustainable.
Certivo in Action
Certivo in Action—SMETA Workflow
GET EVIDENCE IN
Collect SMETA Audit Evidence and SAQ Data from Every Supplier—Without the Chasing
CORA launches targeted campaigns to collect SMETA audit reports, corrective action evidence, SAQ completions, and ethical trade documentation from suppliers. Automated follow-up in suppliers' native languages.
- Launch SMETA evidence campaigns to hundreds of suppliers with one click
- CORA-powered outreach requesting audit reports, CAP evidence, and policy documents
- Accept any format: PDFs, Sedex exports, Excel corrective action logs, freeform responses
- Track response rates and escalate non-responders automatically
MAKE SENSE OF IT
Know Instantly Which Suppliers Have Open Non-Conformances—and Where Evidence Gaps Exist
CORA parses SMETA audit reports, extracts non-conformance findings by pillar, validates corrective action evidence, and flags overdue or missing remediation automatically.
- CORA extracts non-conformances, CAR findings, and corrective actions from audit reports
- Automatic categorization by SMETA pillar: Labour, H&S, Environment, Business Ethics
- Real-time supplier risk scoring based on audit findings, CAP closure rates, and audit age
- Gap analysis identifying suppliers with expired audits or incomplete corrective actions
PROVE COMPLIANCE OUT
Respond to Buyer Audit Requests and Generate Compliance Reports in Hours, Not Weeks
Generate audit-ready supplier compliance packages, aggregated risk reports, and customer-specific SMETA summaries instantly from validated evidence.
- One-click supplier compliance packages with audit status, CAP evidence, and risk scores
- Customer-specific SMETA compliance summaries with full traceability
- Aggregated reporting across full supplier base by pillar, region, and risk tier
- Complete audit trail for every non-conformance, corrective action, and verification
Features Tabs
Supplier Evidence Collection
Certivo's automated campaigns achieve 95% response rates vs. 20–30% with manual outreach.
- Targeted campaigns by supplier tier, risk region, audit status, or buyer requirement
- Multi-language outreach in suppliers' native languages
- Intelligent follow-up sequences adapting to supplier behavior
- Format-agnostic: Sedex exports, PDFs, Excel, SA8000 certificates, freeform responses
Audit Data Extraction
Every SMETA audit report parsed for non-conformances, CAR findings, and corrective actions automatically—no manual data entry.
- Deep extraction of non-conformances by SMETA pillar and ETI Base Code clause
- Parses SMETA audit reports, Sedex data exports, and Affiliate Audit Company formats
- Multi-language document processing across all major supplier geographies
- Anomaly detection for inconsistent, expired, or incomplete audit documentation
Corrective Action Monitoring
Always current on corrective action status—not your last quarterly review.
- Automatic tracking of CAP timelines and closure evidence across all supplier sites
- Collaborative Action Required (CAR) escalation workflows for systemic issues
- Proactive alerts when corrective action deadlines approach or audits expire
- Historical tracking of non-conformance trends and remediation progress by supplier
Buyer Compliance Reporting
Generate SMETA compliance summaries in hours instead of weeks of manual compilation.
- One-click buyer compliance packages with audit status, CAP evidence, and risk scores
- Aggregated reporting by pillar, region, commodity, and supplier tier
- Audit coverage dashboards showing percentage of suppliers with current SMETA audits
- Response tracking for buyer due diligence requirements
Related Regulations
EU CSDDD
SMETA audit evidence supports CSDDD human rights due diligence requirements
German LkSG
LkSG requires risk analysis and preventive measures; SMETA audits provide supplier-level evidence
UK Modern Slavery Act
SMETA labour pillar assesses forced labour, child labour, and modern slavery indicators
EU Forced Labour Regulation
Product-level forced labour ban requires supply chain due diligence evidence
amfori BSCI
Parallel social audit framework with overlapping scope
SA8000 Certification
Social accountability standard with overlapping labour and H&S requirements
Key Statistics
- 4 SMETA pillars validated with automatic non-conformance categorization
- 99.2% Audit data extraction accuracy from supplier documents
- 95% Supplier response rate with CORA-powered campaigns
Frequently Asked Questions
Who needs to comply with SMETA audit requirements?
SMETA audits apply to any supplier site where a Sedex buyer member requests an audit. There is no universal size threshold—compliance is driven by customer requirements.
What happens if a supplier fails a SMETA audit?
SMETA does not have a formal pass/fail system. Instead, audits identify non-conformances (NCs) and observations that require corrective action plans (CAPs).
How does Certivo handle SMETA evidence management at scale?
Certivo collects SMETA audit reports, SAQ data, corrective action evidence, and policy documentation from hundreds of suppliers simultaneously.
Does Certivo support both SMETA 2-pillar and 4-pillar audit evidence?
Yes. Certivo manages evidence for both 2-pillar and 4-pillar SMETA audits.