Eurocert
Social Compliance and Audits

Preparing for brand audits: SMETA, BSCI and SA8000 compared

A comparison chart contrasting SMETA, amfori BSCI and SA8000 social-compliance audits by what they are, who runs them and what a supplier receives

A textile supplier in Bursa opens three emails in the same week. A British supermarket wants the latest SMETA report uploaded to its Sedex profile. A German importer asks for a current amfori BSCI audit. A premium apparel brand asks, almost in passing, whether the factory holds SA8000. To the sales desk the three requests read as one: prove the factory treats its people properly. To anyone who has sat through these audits, they are three different exercises with three different rulebooks, and treating them as interchangeable is how a supplier pays for the same week of disruption three times over.

Social compliance is now a condition of trading with European and North American buyers rather than a bonus. The confusion is fair, because on the factory floor the schemes overlap heavily: the same dormitory, the same fire exits, the same wage records and working-hour logs get examined whoever walks in. What changes is who owns the scheme, what the result actually is, and how long it counts for. Once those three questions are clear, you can answer a buyer without guessing, and often satisfy several customers with far less duplicated effort.

Three requests, three different kinds of thing

Begin with the distinction the marketing rarely makes plain, because it shapes everything else. One of these is an audit method, one is a monitoring programme, and only one is a certification.

SMETA, the Sedex Members Ethical Trade Audit, is a method. It tells an auditor how to examine a site and what to record, but it issues no pass, no grade and no certificate. The output is a report and a corrective action plan that sit on the Sedex platform, where the supplier chooses which customers may view them.

amfori BSCI sits in the middle. It is a monitoring system run for a club of mostly European importers and retailers. Its audit closes with a single overall rating, from A down to E, and that letter, not a certificate, is what the buyer reads. The supplier does not own a BSCI certificate to hand out: the result is attached to the producer inside amfori's own system.

SA8000 is the only true certification of the three. An accredited certification body assesses the site against the SA8000 standard and, where it conforms, issues a certificate valid for a fixed cycle with surveillance audits in between, much as an ISO certificate behaves. The supplier holds that certificate and can present it to any buyer who asks.

That single difference, a report versus a rating versus a certificate, drives almost every practical choice that follows.

Preparing for brand audits: SMETA, BSCI and SA8000 compared figure

SMETA: the shared report most retail requests really mean

When a UK or international retailer asks for an ethical audit, more often than not it means a SMETA conducted against the ETI Base Code and applicable local law. The audit comes in two shapes: a two-pillar version covering labour standards and health and safety, and a four-pillar version that adds environment and business ethics. The buyer usually states which one it expects, and asking that question early saves a second visit.

The point many suppliers miss is that SMETA produces no verdict. There is no pass, no score, no certificate to frame on the wall. Its value lies elsewhere: one audit becomes a single report on Sedex that several customers can read, which is the whole reason the platform exists. A factory audited once can share the same findings with every retailer that uses Sedex, instead of hosting a separate visit for each. SMETA itself stamps no expiry, yet most buyers treat a report as current only for a while before expecting a new one, on a far shorter rhythm than a certificate's renewal cycle. The mechanics of the visit, the document pack and the corrective-action follow-up are covered on our Sedex SMETA audit page.

amfori BSCI: the graded audit Europe's importers run

BSCI is built around amfori, a Brussels-based business association whose members are importers and retailers, many of them German, Benelux and Nordic. The relationship runs the opposite way to a certificate. The buyer is the amfori member, and the supplier is audited because that member asked for it. The audit checks the site against amfori's code of conduct, a set of eleven principles drawn from the ILO conventions, covering wages, hours, young workers, safety, freedom of association and the rest.

What sets BSCI apart is the rating. The audit ends in an overall grade from A, the strongest, down to E, and that grade carries consequences for timing. A clear A or B usually buys a longer stretch before the next full audit, while a C, D or E pulls the next visit forward and adds a follow-up audit to confirm the fixes. The tone is capacity-building rather than expulsion: a weak result starts a remediation clock, not an exit. It remains, though, a result inside amfori's platform rather than a document the supplier owns, which is why a buyer outside the amfori system cannot simply read it. The audit cycle and the way producers are linked to members are set out on our amfori BSCI audit page.

SA8000: the one that is genuinely a certificate

SA8000, from Social Accountability International, is the senior member of the family and the hardest to earn. Where SMETA and BSCI take a snapshot, SA8000 audits a working management system. It covers the same core labour standards the other two examine, then goes a step further than either: it expects the factory to run a functioning social management system that keeps those standards in place between audits, not just on the day the auditor visits.

Because it is a certification, the assurance behind it is layered. The certification body is itself accredited, under the oversight of SAAS, and the certificate runs on a fixed certification cycle with periodic surveillance audits in between, the same rhythm as ISO management-system certificates. That makes SA8000 the strongest signal of the three and the one a supplier can present unprompted, which is why factories that hold it often field fewer one-off buyer audits. The standard's elements and the certification cycle are described on our SA8000 certification page.

Which buyers ask for which

The pattern is rarely random, and reading it tells you where to spend first. British and international grocery and consumer-goods retailers lean on Sedex and SMETA, partly because the platform handles the many-suppliers-to-many-buyers problem that food supply chains create. Continental European retailers, discounters and a large share of textile and hardgoods importers run amfori BSCI, so if your order book is weighted toward Germany, Austria or the Low Countries, expect that request. SA8000 tends to come from brands that want the firmest assurance, from buyers writing it into a tender, or from suppliers who decide to lead rather than wait to be asked.

One caution outranks the rest. When a buyer says it wants "a social audit", that phrase is not specific enough to act on. Confirm the exact scheme, and for SMETA the pillar count, before booking anything, because preparing for a two-pillar SMETA and then being asked for a four-pillar result wastes the very week you were trying to protect.

Choosing a route without auditing yourself to exhaustion

The real enemy for a busy factory is not any single scheme but audit fatigue, the slow drain of hosting visit after visit for buyers who each want their own. Three habits keep that under control.

  • Map the route to your customers, not to the scheme's reputation. If most of your buyers are amfori members, BSCI is unavoidable whatever its merits. If they sit on Sedex, a single SMETA shared widely does more for you than a certificate no one asked for.
  • Do not assume the schemes substitute for one another. An SA8000 certificate will not automatically satisfy a buyer who insists on seeing a BSCI grade in amfori's own system, and a SMETA report is not a BSCI rating. They draw on the same ILO foundations, yet each buyer reads its own scheme.
  • Build upward when you can. Many factories start with SMETA because it is the most requested and the most shareable, add BSCI when a European member buyer requires it, and pursue SA8000 once their social management has matured. The management-system discipline SA8000 demands tends to leave a site well prepared for the snapshot audits too.

The practical move is to stop treating "a social audit" as one thing and start running it as a small portfolio matched to your customer base. Read each request for what it actually is, a shared report, a graded monitoring audit or an accredited certificate, and you stop paying three times for one improvement. If you are weighing which scheme to prepare for first, our specialists across the Sedex SMETA audit, the amfori BSCI audit and SA8000 certification can map the request sitting on your desk to the route that genuinely serves the buyers behind it.