Summary
A Sedex SMETA audit explained simply: Sedex is a data-sharing platform, not a certification, while SMETA (Sedex Members Ethical Trade Audit) is the actual audit conducted against a facility, in either a 2-pillar (labour standards and health & safety) or 4-pillar (adding environment and business ethics) scope. Sedex membership alone proves nothing was verified, only a dated SMETA report, its pillar scope, and evidence that any non-conformances were closed actually substantiate a claim. This guide shows exactly what to ask for before placing an order at any volume.
“The Factory Is Audited” Isn’t an Answer
A supplier tells you their factory is “audited” and shows you a Sedex logo. You nod, because it sounds official, and move on to discussing price and lead time.
Here’s the problem: that sentence tells you almost nothing. Audited by whom? Against what criteria? When? Did the audit find anything, and if it did, was it ever fixed?
This confusion isn’t a small-brand knowledge gap that enterprise buyers have already solved; it’s a genuine, widespread conflation between two different things that happen to share a name. Sedex membership and a passed SMETA audit are not the same thing, and almost nobody explains the difference at the scale of a founder placing a 200-unit order. Most content on this topic is written either by the audit bodies themselves, in language built for compliance officers, or by enterprise procurement consultancies advising brands with dedicated sourcing teams. Neither is written for someone comparing two supplier quotes on a Tuesday afternoon. We display a Sedex mark on our self at Affix Apparel, so this is written specifically to teach you to interrogate that claim, including ours.
Sedex Is a Platform. SMETA Is the Audit. These Are Not the Same Thing.

Sedex (Supplier Ethical Data Exchange) is a global membership platform, not a standard-setting or certifying body. It exists to let suppliers store and share ethical and responsible-sourcing data with multiple buyers in one place, so a factory doesn’t need a separate audit for every brand it works with. Joining Sedex means a factory has registered on the platform and typically completed a self-assessment questionnaire (SAQ), a supplier’s own account of its practices, unverified by anyone else.
SMETA (Sedex Members Ethical Trade Audit) is the actual audit methodology, a structured, on-site assessment conducted by an approved third-party auditor, measured against the Ethical Trading Initiative Base Code and applicable local law. Crucially, SMETA is explicitly described as a verification, not a certification: it documents the degree to which a facility meets requirements at a point in time, and, worth repeating because it surprises most buyers, no pass/fail certificate is ever issued. There is no such thing as being “SMETA certified.”
The distinction that matters for your order: a factory can be a Sedex member in good standing while having never completed an SMETA audit at all. Being on the platform is a prerequisite for sharing audit data; it is not evidence that any independent party has actually walked the floor and checked anything.
Member vs. Supplier: Who’s Actually Being Checked?
Sedex distinguishes between different account types, and this distinction is exactly where the ambiguity a small brand runs into usually starts.
A member (typically a buyer or brand) uses Sedex to manage and request data from its supply chain. A supplier is the party being assessed, the factory whose practices are actually under review. When a factory says “we’re Sedex members,” that’s a statement about their account type and platform access, not a statement about audit outcomes. Ask specifically: has an SMETA audit actually been completed for this facility, and can you see the report?
2-Pillar vs. 4-Pillar SMETA: What Each Actually Examines
SMETA audits come in two scope levels, and the difference determines what’s actually been checked, not just how thorough the paperwork looks.
The 2-Pillar Audit
Covers two core areas:
- Labor standards: working hours, wages, contracts, freedom of association, discrimination, and forced and child labor protections
- Health and safety, workplace safety, fire safety, chemical handling, emergency procedures, sanitation
The 4-Pillar Audit
Covers everything in the 2-pillar scope, plus two additional areas:
- Environmental resource use, emissions, waste management, environmental permits
- Business ethics, anti-bribery, corruption prevention, conflict-of-interest controls, fair business practices
Why this matters for your order specifically: a factory citing “we’ve had an SMETA audit” without specifying pillar scope could mean either level. A 2-pillar audit tells you nothing about the facility’s environmental practices or business ethics, areas that matter increasingly to brands and customers alike. If sustainability or ethical sourcing appears anywhere in your own marketing, ask which pillar scope was actually audited before repeating any claim built on top of it.
Non-Conformances and the Corrective Action Plan Nobody Mentions

This is the single most under-explained part of the entire audit process, and it’s exactly the gap this article exists to close.
A SMETA audit doesn’t simply produce a pass or fail; it produces a list of non-conformances (NCs): specific findings where the facility doesn’t meet the Base Code or local law. Each finding gets documented in a Corrective Action Plan Report (CAPR), which records the issue, its root cause, the agreed corrective action, and a closure timeframe typically immediate, 30, 60, or 90 days depending on severity.
Here’s what almost no buyer knows to ask: a corrective action plan existing doesn’t mean the issue was actually fixed. Verification happens either through a desktop review of evidence the site uploads to the Sedex platform or, for more serious findings,, a full follow-up audit. Until that verification happens, an open non-conformance is exactly that: open, unresolved, and worth asking about directly rather than assuming “they had an audit” means everything found was already corrected.
Before accepting an audit claim, ask for:
- The audit report date and the auditor/audit company name
- Whether the scope was 2-pillar or 4-pillar
- Whether any non-conformances were raised
- The current status of any corrective action plan, closed, verified, or still open
- How that closure was verified: desktop review or follow-up audit
An Audit Is a Snapshot, Not a Guarantee
A SMETA audit, like most social compliance audits, reflects conditions observed on specific audit days, not a standing, permanent state. Follow-up audits generally can’t be scheduled beyond roughly 12 months from the original full-scope audit without being treated as an entirely new, periodic audit rather than a continuation of the same one. In practice, this means an audit report from three years ago tells you very little about current conditions, regardless of how professional the original findings looked.
This isn’t a reason to dismiss audits; it’s a reason to ask for the date on every single one and to treat a recent audit with a documented, verified corrective action history as meaningfully more trustworthy than an old audit with no follow-up at all.
How WRAP and amfori BSCI Compare
You won’t always be shown a Sedex/SMETA report; different factories, especially across different regions, favor different audit schemes. Here’s how to read whichever one lands in front of you:
WRAP (Worldwide Responsible Accredited Production) differs structurally from SMETA in one important way: WRAP does issue an actual certification, tiered as Silver, Gold, or Platinum based on re-inspection frequency (roughly every 6 months, 12 months, or 24 months, respectively). Unlike SMETA’s “verification, not certification” model, a factory either holds a current WRAP certificate or it doesn’t; ask for the certificate number and tier directly.
amfori BSCI (Business Social Compliance Initiative) operates more like SMETA than WRAP; it’s an audit methodology, not a pass/fail certification, assessing labor rights, health and safety, and business ethics through a structured on-site process. As with SMETA, the report date, scope, and any follow-up on findings matter more than the fact that a BSCI audit happened at some point. BSCI results are also typically scored on a rating scale rather than issued as a binary certificate, so ask specifically what rating or outcome level the facility achieved, not just whether an audit “happened.”
The rule that applies across all three: the name of the scheme matters less than whether you can get your hands on an actual, dated report with a documented outcome, logo recognition is not evidence. A factory proudly displaying three different audit logos on its website, none of which come with a date or a report you can review, has told you less than a factory showing you one recent, specific SMETA report with an open non-conformance and a documented plan to close it. Transparency about an imperfect result is a stronger signal than an unverifiable claim of a perfect one.
A Supplier Questionnaire Template

Use this as a starting point in your first sourcing conversation, whether you’re asking about Sedex/SMETA, WRAP, or BSCI:
- Which social compliance audit scheme has this facility completed, Sedex/SMETA, WRAP, amfori BSCI, or another?
- What was the date of the most recent audit, and who conducted it?
- If SMETA was the scope, 2-pillar or 4-pillar?
- Were any non-conformances or findings raised in that audit?
- If so, what is the current status of the corrective action plan, closed and verified, or still open?
- Can you share the audit report (or a summary) directly, rather than only a logo or badge?
- Is this audit specific to this facility, or does it cover a different site under the same parent company?
A supplier willing to answer all seven specifically and promptly is telling you something important before you’ve even discussed price. Hesitation, vagueness, or a refusal to share anything beyond a logo is worth weighing just as heavily.
What This Means at 200 Units
Enterprise brands have compliance teams that request and review audit documentation as standard procedure on every order, regardless of size. A small brand ordering 200 units doesn’t have that team, but the questions themselves cost nothing to ask, and a factory used to working with brands our size, including on uniform manufacturing programs, should be entirely comfortable answering them.
If you’re evaluating who you are as a sourcing partner as much as what a factory can produce, read more about who we are, and hold that page to the same standard of scrutiny this article just walked you through.
Ask, Don’t Assume
“The factory is audited” is the start of a conversation, not the end of one. Sedex membership tells you a platform account exists. An SMETA audit report tells you what was actually checked, when, and by whom. A corrective action plan tells you whether anything that was found got fixed and whether that fix was ever verified.
None of this requires enterprise volume or a compliance department. It requires asking seven specific questions and expecting real answers, whether you’re placing a 200-unit order or a 20,000-unit one.
Want to see this in practice? Contact us to review. Affix Apparel’s own current SMETA audit documentation directly, the same standard we’d want you to hold any supplier to.
Frequently Asked Questions
What is a Sedex audit?
There’s no such thing as a “Sedex audit” in the strict sense; Sedex is a data-sharing platform, not an audit body. The actual audit conducted through Sedex membership is called SMETA (Sedex Members Ethical Trade Audit), performed by an approved third-party auditor against the Ethical Trading Initiative Base Code and local law.
Is Sedex membership the same as being audited?
No. Sedex membership means a factory has registered on the platform and typically completed a self-assessment questionnaire, which is unverified by any third party. A SMETA audit is a separate, independent on-site assessment that a Sedex member may or may not have actually completed.
What is the difference between 2-pillar and 4-pillar SMETA?
2-pillar SMETA covers labor standards and health and safety only. 4-pillar SMETA covers those same two areas plus environment and business ethics. A factory citing an SMETA audit without specifying pillar scope may only have been assessed on the narrower 2-pillar criteria.
How long is an SMETA audit valid?
SMETA doesn’t issue a certificate with a fixed expiry, but follow-up audits generally aren’t scheduled beyond roughly 12 months after the original full-scope audit without being treated as an entirely new periodic audit. In practice, always ask for the audit date; an older report with no documented follow-up tells you little about current conditions.
What should I ask a factory about its audit?
Ask which scheme was used (Sedex/SMETA, WRAP, or amfori BSCI), the date and auditor, the pillar scope if SMETA, whether any non-conformances were raised, and the current status of any corrective action plan. Request the actual report or a summary rather than accepting a logo alone as evidence.
