
Sedex vs SMETA: what is the difference and which do you need?
Sedex and SMETA are routinely used as though they mean the same thing. They do not. Sedex is a membership platform. SMETA is an audit methodology. A buyer who asks for 'Sedex' may mean either, or both. This article explains the difference, when each applies, and how to determine what a specific buyer request actually requires.
This article is for informational purposes only and does not constitute legal advice. Consult a qualified legal professional for advice specific to your situation.
- Sedex is a membership platform. SMETA is an audit methodology. They are not different names for the same thing: A supplier can be a Sedex member without having a SMETA audit. A supplier can commission a SMETA audit without being a Sedex member. The practical consequence of confusing them is real: Sedex membership with a completed self-assessment questionnaire does not satisfy a buyer who requires an on-site audit report, and the gap only becomes clear after time and money have been spent on the wrong thing.
- A buyer asking for “Sedex” may mean any of three different things: Join the platform and complete the self-assessment questionnaire; do both and commission a SMETA audit; or commission a SMETA audit and upload the report to the platform. The most common expectation among large EU retail and food buyers is the second, but this is not universal. The correct response to any Sedex-related request is to ask the buyer directly what they specifically require before spending money on either process.
- Even a current SMETA audit may not satisfy every buyer who requires one: Audit age matters (most buyers specify a maximum of twelve to eighteen months). Pillar variant matters: a two-pillar audit covering labour and health and safety does not satisfy a buyer who has specified four-pillar coverage including environment and business ethics. Buyers occasionally have supplementary requirements beyond the standard methodology. None of these are apparent from the audit report itself.
- Neither Sedex nor SMETA addresses the full scope of what EU regulatory frameworks now require from supply chains: SMETA audit findings contribute evidence relevant to CSDDD due diligence obligations and ESRS S2 disclosures on value chain workers. They do not address greenhouse gas emissions data requirements under ESRS E1, deforestation documentation under EUDR, or CBAM requirements. Suppliers who have satisfied their buyer’s Sedex and SMETA requirements in full may still receive separate data requests for information outside the scope of either platform.
The confusion and why it matters
Supplier requests involving Sedex and SMETA are among the most commonly misread in EU supply chain compliance. A procurement team sends a message asking a supplier to “get on Sedex” or to “provide a SMETA audit.” The supplier, or their compliance team, assumes the two terms describe the same thing under different names and proceeds accordingly. Sometimes that assumption is correct. Often it is not, and the gap only becomes clear when the buyer’s requirements are not satisfied.
Sedex and SMETA are related but distinct. Sedex is a membership platform for sharing ethical trade data. SMETA is an audit methodology for assessing working conditions and other sustainability criteria at a supplier’s facility. The two overlap because SMETA audit reports are typically shared through the Sedex platform, but they are separate things with separate processes, separate costs, and separate outputs. A supplier can be a Sedex member without having a SMETA audit. A supplier can commission a SMETA audit without being a Sedex member. And a buyer who asks for one may or may not require the other.
The practical consequences of confusing them are real. A supplier who joins Sedex and completes the self-assessment questionnaire but does not commission an audit will satisfy a buyer who requires Sedex membership and SAQ completion. They will not satisfy a buyer who requires a SMETA audit report. The distinction is not minor: a SMETA audit involves selecting and paying a third-party auditor, booking a facility inspection, and waiting for a formal report. That is a meaningfully different commitment from filling in a questionnaire on a platform.
What Sedex is
Sedex is a non-profit membership organisation founded in 2004 by a group of UK retailers. Its core function is to provide a shared platform where suppliers can upload their ethical trade information once and share it with multiple buyers, rather than completing separate assessments for each buyer relationship.
Membership gives a supplier access to the Sedex platform, where they can complete the Self-Assessment Questionnaire (SAQ), upload supporting documents, and link to the buyers who have requested access to their data. The SAQ covers four areas: labour standards, health and safety, the environment, and business ethics. It is self-reported: the supplier answers questions about their policies and practices, and the responses are stored on the platform and made visible to linked buyers.
Sedex membership alone, with a completed SAQ, is a specific and bounded thing. It tells buyers that the supplier has registered on the platform, completed the self-assessment, and made their responses available for review. It does not involve any independent verification of those responses. An auditor does not visit the facility. No one confirms that what the supplier has stated about their practices is accurate.
This is an important limitation to understand clearly, both as a supplier and as a buyer who is trying to assess what their Sedex membership data actually demonstrates. The SAQ is useful for gathering structured, comparable information across large supplier portfolios. It is not a verification of conditions.
What SMETA is
SMETA stands for Sedex Members Ethical Trade Audit. It is an audit methodology, developed and maintained by Sedex, that specifies how on-site assessments of supplier facilities should be conducted and reported.
A SMETA audit is an on-site inspection carried out at the supplier’s facility by a qualified third-party auditor. The supplier selects an auditor from Sedex’s approved list and pays them directly for the audit. The auditor reviews documentation, interviews workers, and inspects facilities against the SMETA criteria. The resulting report documents findings, non-conformances, and areas for improvement in a standardised format.
SMETA comes in two variants. The two-pillar audit covers labour standards and health and safety. The four-pillar audit adds environment and business ethics. Which variant a buyer requires matters and must be confirmed before commissioning an audit: a two-pillar audit does not satisfy a buyer who has specified four-pillar coverage, and commissioning the wrong variant means repeating the process.
The SMETA report, once completed, can be uploaded to the Sedex platform and shared with all buyers the supplier is linked to. This is the efficiency case for SMETA: a single audit, conducted once, satisfies the audit requirements of multiple buyers simultaneously through the shared platform.
What a buyer asking for “Sedex” actually means
Because the two terms are so commonly conflated, a buyer request phrased as “we require Sedex” or “please get your Sedex” does not have a self-evident meaning. It could mean any of the following:
- Join the Sedex platform and complete the SAQ
- Join the Sedex platform, complete the SAQ, and commission a SMETA audit
- Commission a SMETA audit and upload the report to Sedex
In practice, the most common interpretation among large EU retail and food buyers is the second: they expect both the platform membership with a completed SAQ and an audit report. But this is not universal, and assuming without clarifying creates risk in both directions. A supplier who commissions a SMETA audit without joining Sedex may not be able to share the report in the way the buyer expects. A supplier who joins Sedex and completes the SAQ but does not commission an audit may find the buyer requires one.
The correct response to any Sedex-related request is to ask the buyer directly, before spending money or time on either process, what they specifically require. The questions to ask are:
Do they require Sedex membership and SAQ completion? Do they require a SMETA audit? If an audit is required, which pillar variant (two-pillar or four-pillar)? How recently must the audit have been conducted? Does the audit report need to be uploaded to Sedex or can it be provided directly?
These are not unreasonable questions, and a buyer running a serious supply chain sustainability programme will have clear answers. If the buyer cannot specify what they need beyond “get on Sedex,” the most risk-averse approach is to join the platform, complete the SAQ, and commission a two-pillar SMETA audit: the combination that satisfies the broadest range of requests.
When you need Sedex membership without a SMETA audit
Some buyers use Sedex as a data aggregation and risk-tiering tool. They want the SAQ data to inform their supplier risk assessments: to understand which suppliers have formal health and safety management systems, which have relevant certifications, which have disclosed prior audit findings. For this purpose, the SAQ data is the relevant input, and a SMETA audit is not required.
This pattern is more common among buyers who are conducting initial supply chain mapping, assessing suppliers at the less exposed end of their risk distribution, or using Sedex as one layer in a multi-tier assessment where higher-risk suppliers go through more rigorous processes. A buyer who has tiered their supplier base and requires SMETA audits only for Tier 1 critical suppliers may only require Sedex SAQ completion from Tier 2 and Tier 3 suppliers.
If the buyer’s request is framed in terms of registering on the platform and sharing your SAQ, without explicit mention of an audit, it is worth confirming whether an audit is required before assuming one is not. But the SAQ-only scenario is genuine and relatively common in mid-tier supplier relationships.
When you need a SMETA audit and may not need Sedex membership
Less commonly, a buyer will accept a SMETA audit report delivered directly, without requiring the report to be hosted on the Sedex platform. This can happen where the buyer is not themselves a Sedex member, or where the audit is required to satisfy a specific contractual or regulatory need rather than a platform-based supplier screening programme.
In this case, the supplier commissions the SMETA audit from a Sedex-approved auditor in the usual way, but the report is provided to the buyer outside the Sedex system. Sedex membership is not required for this, though the supplier still selects from the Sedex-approved auditor list, and the report must follow the SMETA format and methodology.
This scenario is worth raising with a buyer who is asking for a SMETA audit but where platform membership seems unclear. If the buyer simply needs the audit report and does not need platform access, the supplier avoids the membership cost. Whether this is possible depends entirely on the buyer’s programme requirements.
Why the same audit does not satisfy every buyer
Even when a supplier has a current SMETA audit report on the Sedex platform, that report may not satisfy every buyer who requires one. The reasons are procedural rather than substantive.
Audit age matters. Most buyers specify a maximum age for acceptable audit reports, typically twelve to eighteen months. An audit conducted twenty months ago does not satisfy a buyer with an eighteen-month maximum, regardless of its findings. If a supplier’s audit is approaching its limit, it is worth checking each linked buyer’s requirements before waiting to be chased.
Pillar variant matters. A two-pillar audit report does not satisfy a buyer who has specified four-pillar. The environment and business ethics pillars covered in the four-pillar variant are genuinely different in scope from the two-pillar version. Suppliers operating in sectors where environmental performance is a material buyer concern, such as food, agriculture, and chemicals, are more likely to face four-pillar requirements.
Specific buyer requirements beyond the standard methodology also matter occasionally. Some buyers have supplementary requirements for the SMETA audit, additional questions they want the auditor to address, or specific areas they want assessed in more depth. These are communicated through the buyer’s supplier code of conduct and should be confirmed before selecting an auditor.
The relationship to EU regulatory requirements
Both Sedex and SMETA are supply chain tools that predate the current EU sustainability legislative framework. Neither was designed around CSRD, CSDDD, or any other specific EU regulation. Their frameworks reflect the labour and social compliance priorities of the UK retail sector that founded and built them.
This is relevant context for understanding what they do and do not demonstrate in an EU regulatory context.
For CSDDD, SMETA audit findings are relevant to the due diligence obligation to identify adverse human rights and labour-related impacts in the supply chain. An EU company with CSDDD obligations can use SMETA reports from its suppliers as part of its evidence base for supply chain risk assessment. But CSDDD requires more than an audit snapshot. It requires ongoing due diligence processes, preventive and corrective action, functioning complaints mechanisms, and documented outcomes over time. A periodic SMETA audit contributes evidence but does not constitute a complete CSDDD due diligence programme.
For CSRD, SMETA audit reports contribute to the value chain information that informs ESRS S2 disclosures on workers in the value chain. Again, they are one input among several rather than a complete data source.
Neither Sedex membership nor a SMETA audit addresses greenhouse gas emissions data requirements under ESRS E1, deforestation documentation requirements under EUDR, or the specific due diligence statement requirements of CBAM. These are outside the scope of both platforms.
A supplier who has completed Sedex and SMETA requirements in full may still receive additional data requests from their EU buyers for emissions data, deforestation documentation, or other information that the Sedex system does not collect. The Sedex and SMETA requirements and the wider EU regulatory data requirements are separate tracks.
For a detailed explanation of what CSDDD specifically requires from supply chain participants, and how it differs from the obligations that periodic social auditing addresses, see: CSDDD explained: what the corporate sustainability due diligence directive means for supply chains.
For a comparison of how Sedex relates to EcoVadis, the other platform non-EU suppliers commonly encounter together, see: EcoVadis vs Sedex: which one does your EU buyer actually need?.
Verdandi monitors CSRD, CSDDD, EUDR, CBAM and more continuously, so non-EU businesses touching EU markets are working from current requirements as the legislative landscape evolves. Start for free.
The EU's list of high-risk third countries for AML purposes is not static. It is updated by delegated regulation, changes without a fixed schedule, and triggers enhanced due diligence obligations across both policies and systems. Managing geographic risk classifications dynamically is a continuous operational function, not a one-time setup task.