Sedex is not a certification. Neither is SMETA.
There is no Sedex certificate, pass mark or approved status. Sedex is a membership platform for sharing supply chain data. SMETA is an audit methodology that produces a report. Suppliers are still regularly described as “Sedex certified”, but the distinction matters. It affects what you should ask a supplier to provide, what a customer can reasonably expect and how you assess the information you receive. A certificate confirms that a defined requirement has been met. A SMETA report records what an auditor found, including any non-conformances.
This guide explains the difference between Sedex and SMETA, what a SMETA audit produces and what ingredient buyers should check when reviewing a supplier’s report.
What Sedex Is
Sedex, the Supplier Ethical Data Exchange, is a membership organisation and an online platform. It lets suppliers store ethical and social data in one place and share it with multiple customers, rather than completing a different Q&A for every interaction.
Membership gives a supplier:
- a company and site profile on the platform
- a Self Assessment Questionnaire (SAQ) tailored to industry, size and country
- the ability to share SMETA and non-SMETA audit reports with an unlimited number of customers
- a listing in the supplier directory
- access to risk assessment tools, including Radar, which scores inherent risk by country and sector
Supplier membership is charged per site per year. At the time of writing, the published rates are £224 per site for standard membership and £374 per site for Supplier Plus. The higher tier includes greater directory visibility, visible contact details and training discounts. Check Sedex’s current pricing before budgeting or quoting these figures.
The practical value is in the ability to recycle information. For example, if you supply eight customers who all require ethical data, the platform lets you use one questionnaire and one audit report rather than eight of each. Only one customer may have asked for it, but you’ll be ready for the next.

What SMETA Is
SMETA, the Sedex Members Ethical Trade Audit, is Sedex’s social audit methodology. It is widely used in global supply chains and is usually what a customer means when asking for a “Sedex audit”.
SMETA is built on:
- the ETI Base Code, the Ethical Trading Initiative’s nine-clause standard on labour conditions
- ILO conventions
- local law in the country where the site operates
Where local law and the Base Code differ, the higher standard applies.
An important structural point: SMETA is a methodology, not a standard you are certified against. Sedex maintains it and trains auditors, but third-party audit firms carry out the audit, and the audit produces a report shared on the platform, not a certificate.
SMETA 2-pillar and 4-pillar
SMETA has two scopes, and they’re easy to confuse.
2-pillar covers:
Labour standards
Health and safety
It also includes additional elements: management systems, entitlement to work, subcontracting and homeworking, and a short environmental assessment.
4-pillar adds:
Environment, assessed in full rather than briefly
Business ethics
Most food and ingredient customers ask for the 4-pillar. It costs more and takes longer, so confirm which your customer requires before booking, and check which one a supplier’s existing report covers before accepting it as meeting a 4-pillar requirement.
The ETI Base Code
Since it underpins the whole thing, it is worth knowing what the nine clauses are:
- Employment is freely chosen.
- Freedom of association and the right to collective bargaining are respected.
- Working conditions are safe and hygienic.
- Child labour shall not be used.
- Living wages are paid*.
- Working hours are not excessive**.
- No discrimination is practised.
- Regular employment is provided***.
- No harsh or inhumane treatment is allowed.
*Clause 5 requires wages to meet national legal standards or industry benchmarks, whichever is higher.
**Clause 6 sets a standard 48-hour working week with a 60-hour cap, except in defined circumstances.
***Clause 8 targets businesses that use contracting and fixed-term arrangements to avoid employment obligations, a common finding in agricultural and processing supply chains.

What an Audit Actually Produces
A SMETA audit results in two documents: an audit report and a Corrective Action Plan Report (CAPR).
The audit report records the details and any findings, while the CAPR lists non-conformances, the agreed corrective action, and the timescale.
A SMETA audit does not result in a pass or fail. Findings vary by site, scope and audit type. A report with no non-conformances should not be accepted uncritically, but neither should it automatically be treated as evidence of a weaker audit. Buyers should review the scope, audit method and supporting detail before drawing a conclusion.
What matters when you read one:
- How many non-conformances, and how severe. Critical and major findings on Base Code clauses carry very different weight from minor administrative ones.
- Whether they have been closed; an open critical finding six months past its due date says more than the original finding did.
- Which pillars were audited, and whether that matches your requirement.
- The audit date, and whether the site has been re-audited since.
- Check whether the audit was announced, semi-announced or unannounced. The audit type affects how the findings should be interpreted, but it should be considered alongside the audit scope, site risk and customer requirements.
SMETA 7.0
Sedex released SMETA 7.0 in 2025, replacing 6.1. Two changes are most significant:
- Management Systems Assessment (MSA) replaces the old “observations” category and evaluates how mature a site’s policies and procedures are, rather than whether a document exists.
- Collaborative Action Required (CAR) is a new finding category for issues that a single site cannot fix alone and that need buyers and other parties involved. A CAR is not a supplier failure, and reading it as one misses the point of the category.
SMETA 7.0 was introduced in 2025 and replaced version 6.1 for new audits. Existing 6.1 reports did not automatically require an immediate re-audit. If your supplier questionnaire or specification still refers to 6.1 terminology, review it against the current SMETA requirements and confirm any transition arrangements with your audit provider.
Why Customers Ask For It
Section 54 of the Modern Slavery Act 2015 applies to commercial organisations that carry on business in the UK, supply goods or services and meet the applicable turnover threshold, currently £36 million. In broad terms, an in-scope organisation must publish an annual slavery and human trafficking statement, approved by the board and signed by a director. Government guidance also addresses publication on the organisation’s website and the areas a statement may cover, including supply chains, policies, due diligence, risk assessment, performance measures and training.
The Act does not require supplier audits. However, organisations reporting on supply chain due diligence need evidence of the steps they take. Sedex membership and SMETA audit data are among the tools customers may use, which is why these requests can reach ingredient suppliers that are not themselves within the £36 million threshold.

EU corporate sustainability due diligence.
The Corporate Sustainability Due Diligence Directive (CSDDD) introduces due diligence obligations for the largest companies operating in the EU. Its scope and implementation timetable have been narrowed through the EU Omnibus process, with the main company obligations expected to apply from July 2029. The revised scope focuses on EU companies with more than 5,000 employees and net worldwide turnover above €1.5 billion, together with non-EU companies generating more than €1.5 billion in the EU. These dates and thresholds are correct at the time of writing.
For most UK ingredient suppliers, CSDDD will not create a direct requirement to hold a SMETA audit. Larger customers may still ask suppliers for ethical audit data as part of their own due diligence, but the directive does not prescribe SMETA or make it a legal requirement for smaller suppliers. The practical effect is more likely to be additional supply chain questions from customers that fall within scope.
None of that makes ethical audit less relevant. Large customers will still ask, because their own due diligence depends on it. But if someone tells you CSDDD compels you to hold a SMETA audit next year, that is not what the directive says.
How It Works in Practice
- Join Sedex as a supplier member, registering each site.
- Complete the SAQ and keep it current. The information is self-declared and can be shared with linked customers. An outdated SAQ may lead customers to question whether the supplier’s ethical data is being actively maintained.
- Link to your customers on the platform so they can see your data.
- Book an audit with an approved audit firm, agreeing the pillar scope and the announcement type. Sedex does not conduct audits itself.
- The audit takes place, typically over one to several days depending on site size, and includes document review, site tour and confidential worker interviews.
- Upload the report and CAPR to the platform and share it with your linked customers.
- Close the corrective actions and upload evidence. This step is the one most often neglected and the one customers actually look at.
A SMETA report has no universal expiry date because it is not a certificate. Customers may set their own review or re-audit periods based on site risk, previous findings and internal policy. A twelve-month cycle is common in some supply chains, but suppliers should confirm the requirement with each customer.
What Buyers Should Check
Ask for the right thing. “Are you Sedex certified?” has no correct answer.
- Ask whether the supplier is a Sedex member, whether they hold a current SMETA audit, which pillars it covered, and whether you can link to it on the platform.
- Read the CAPR, not just the report. Open non-conformances are the signal.
- Check the pillars against your requirements. A 2-pillar report does not satisfy a 4-pillar specification.
- Check the audit type. Announced audits are the weakest form of evidence.
- Check the date and the site. Reports cover a specific site, not a company. A multi-site supplier may have one site audited and others not.
Remember what an audit is. A SMETA audit is a snapshot of one site over a few days. It is a useful input to a supplier approval decision, not a guarantee, and treating it as one is how buyers get caught out.
Commercial Implications
For many ingredient suppliers, Sedex membership and SMETA audit information have become part of working with larger customers. Some retailers and manufacturers require both before approving a new supplier, although the exact requirement varies by customer, product and supply chain risk.
The commercial benefit is that the information can be reused. One audit report and one questionnaire can be shared with multiple linked customers, reducing duplicate requests and repeated form filling. The time saved will depend on how many customers use the platform and how well the supplier maintains its data.
The risk is the mirror image. An expired audit, an unanswered SAQ or a set of overdue corrective actions is visible to every linked customer at once, not just the one who asked.
In Summary
Sedex is a platform for sharing ethical supply chain data. SMETA is the audit methodology most customers mean when they ask for a Sedex audit. Neither is a certification, and no certificate exists.
For buyers, the practical distinction is straightforward. Sedex holds and shares ethical supply chain data. SMETA provides the audit methodology and resulting report. When reviewing a supplier, check the audit scope, read the CAPR and focus on whether significant findings have been addressed.
Frequently Asked Questions
SMETA reports may relate to a full initial audit, a periodic audit, a full follow-up or a partial follow-up. A desktop follow-up may also be used to verify certain corrective actions remotely through documents or photographic evidence. Follow-up work is usually narrower than an initial or periodic audit. When reviewing a report, check the audit and follow-up type carefully: a partial or desktop follow-up does not reassess the full original scope.
Neither. The audit produces a report describing what was found and a Corrective Action Plan Report listing non-conformances, agreed actions and deadlines. Almost every audit finds something. Customers assess the number and severity of findings and whether they were closed on time, not a score.
There is no formal expiry, because it is not a certificate. In practice, most customers treat a report as current for twelve months and audits are typically repeated annually. Some customers set their own cycles based on the site’s risk profile and previous findings.
Supplier membership is charged per site per year. At current published rates, standard membership is £224 per site, and Supplier Plus is £374 per site. The audit itself is a separate and considerably larger cost, quoted by the audit firm based on site size, location and whether you need 2-pillar or 4-pillar.
SMETA 7.0 was released in 2025, replacing version 6.1. The main changes are the Management Systems Assessment, which replaces the old observations category and evaluates how mature a site’s systems actually are, and Collaborative Action Required, a new finding category for issues a site cannot resolve alone. Sites audited under 6.1 do not need to re-audit immediately; new audits use 7.0. Confirm the retirement position for 6.1 with your audit provider.
Not in law. No UK legislation requires a supplier to hold a SMETA audit or to join Sedex. It becomes mandatory commercially when a customer makes it a condition of supply, which large retailers and manufacturers routinely do. The legal driver sitting behind those requests is section 54 of the Modern Slavery Act 2015, which requires organisations with a total turnover of £36 million or more to publish an annual modern slavery statement describing their due diligence. That obligation belongs to the larger company, not to you, but it is why the request arrives.
Sedex Information Exchange Ltd operates the Sedex platform. It began as a collaborative initiative between UK retailers and suppliers in 2004 and is now a commercially owned business. At the time of writing, Apax Funds holds the majority interest, with SHL Membership and LDC retaining minority interests. Its ownership is separate from how SMETA audits are conducted. SMETA draws on the ETI Base Code and ILO conventions, while approved independent audit firms carry out the audits. The ownership details and dates are correct at the time of writing.
The Ethical Trading Initiative’s nine-clause standard on labour conditions, and the basis of SMETA alongside ILO conventions and local law. The clauses cover freely chosen employment, freedom of association, safe and hygienic conditions, no child labour, living wages, working hours, no discrimination, regular employment and no harsh or inhumane treatment. Where local law and the Base Code differ, the higher standard applies.
Not directly, and the timescales are longer than commonly claimed. After the Omnibus revisions, the Corporate Sustainability Due Diligence Directive must be transposed by 26 July 2028, with obligations applying from 26 July 2029; scope is limited to companies with above 5,000 employees and €1.5 billion turnover. The revised text also restricts what those companies can demand from smaller partners. Large customers will still ask for ethical audit data because their own due diligence depends on it, but the directive itself does not impose an audit requirement on a mid-sized UK supplier.
SA8000, run by Social Accountability International, is a genuine certification with a certificate and a pass requirement. SMETA and amfori BSCI are audit methodologies that produce reports rather than certificates, though BSCI applies a graded rating that SMETA does not. Customers usually specify one, and they are not interchangeable, so check which programme your customer uses before commissioning an audit.