Does a SMETA audit satisfy CSDDD due diligence requirements?

Does a SMETA audit satisfy CSDDD due diligence requirements?

EU buyers increasingly point to supplier SMETA audits as evidence of CSDDD due diligence. This article maps what a SMETA audit actually produces against each obligation the directive requires, and identifies exactly where the gap sits.

10 min read

This article is for informational purposes only and does not constitute legal advice. Consult a qualified legal professional for advice specific to your situation.

  • A SMETA audit contributes real evidence to a CSDDD due diligence programme, but it does not constitute one. This is not a criticism of SMETA as a methodology. It is a consequence of what SMETA was designed to do compared to what CSDDD requires. The gap between them is specific and identifiable.
  • A SMETA audit is a point-in-time snapshot. CSDDD requires an ongoing process. Conditions can deteriorate significantly between audits. The identification obligation is not satisfied by a periodic check, even a rigorous one, and the prioritisation obligation is a portfolio-level exercise that has to happen on the buyer's side across the full supplier base.
  • A buyer that receives a SMETA report showing findings and takes no documented corrective action has created evidence against itself. The audit demonstrates the buyer knew about a problem and did not act on it, which is a materially worse position under CSDDD than not having commissioned the audit at all. Preventive and corrective action is the buyer's obligation, not the auditor's.
  • The complaints mechanism obligation, the monitoring obligation, and supply chain visibility beyond the audited facility are all outside what SMETA provides. CSDDD requires an accessible, ongoing channel for workers and affected parties to raise concerns. A SMETA audit may assess whether such a mechanism exists at a facility. It is not that mechanism, and the buyer's obligation to operate one is entirely separate.

The question buyers and suppliers are both asking

A large EU company subject to CSDDD needs to conduct due diligence on its supply chain. Many of its suppliers already hold a SMETA audit, commissioned for a different buyer or a different purpose. The question that follows naturally is whether that existing audit can be used as evidence of CSDDD compliance, or whether it needs to be supplemented, repeated, or replaced with something else.

The honest answer is that a SMETA audit contributes real evidence to a CSDDD due diligence programme, but it does not constitute one on its own. This is not a criticism of SMETA as a methodology. It is a consequence of what SMETA was built to do compared to what CSDDD requires. The two were never designed around each other, and the gap between them is specific and identifiable rather than vague.

This article works through the CSDDD due diligence cycle element by element and sets out what a SMETA audit does and does not provide at each stage. For background on what SMETA itself involves, see Sedex vs SMETA: what is the difference and which do you need?.

The starting point: what CSDDD actually requires

CSDDD sets out a structured due diligence cycle: adopting a due diligence policy, mapping the supply chain and identifying adverse impacts, prioritising those impacts, taking preventive and corrective action, engaging with affected stakeholders, maintaining a complaints mechanism, monitoring effectiveness, and communicating on the process. A detailed walkthrough of each obligation is available in CSDDD explained: what the corporate sustainability due diligence directive means for supply chains.

The obligation is substantive, not procedural. A company cannot satisfy CSDDD by producing documentation that describes a due diligence process. It has to actually run one, and the evidence has to reflect that. This is the frame that matters when assessing whether any single input, including a SMETA audit, is sufficient.

Where a SMETA audit contributes real evidence

Identifying adverse impacts

CSDDD requires companies to identify actual and potential adverse impacts using qualitative and quantitative information from internal sources, stakeholder engagement, and publicly available information. A SMETA audit, particularly the four-pillar variant, generates a structured, third-party assessment of labour conditions, health and safety, environmental practices, and business ethics at a specific facility. Findings are categorised by severity, which maps reasonably well onto the kind of structured impact identification CSDDD expects.

For the labour and health and safety pillars specifically, SMETA is a genuinely useful input. Auditors interview workers, review payroll and timekeeping records, and inspect facilities against a defined methodology. This is closer to the kind of evidence CSDDD contemplates than a supplier questionnaire or a policy statement.

Some stakeholder engagement

SMETA audits include worker interviews as a standard part of the methodology. This satisfies part of what CSDDD requires under its stakeholder engagement obligation, at least at the identification stage, provided the interviews are conducted in a way that generates reliable testimony rather than management-supervised confirmation exercises.

Where the gap sits

Impact identification is a snapshot, not a process

A SMETA audit assesses conditions at a facility on the day or days the audit takes place. CSDDD requires an ongoing process of identification that accounts for changing operations, new business relationships, and evolving risk. An audit conducted once a year, or once every eighteen months under a typical buyer's acceptance window, does not by itself demonstrate the continuous identification process CSDDD describes.

This matters more than it sounds. A facility can hold a clean SMETA report and still have conditions deteriorate in the eleven months before the next audit is due. CSDDD's identification obligation is not satisfied by a periodic point-in-time check, even a rigorous one.

Prioritisation is not addressed at all

CSDDD requires companies to prioritise identified impacts by severity and likelihood when they cannot address everything simultaneously, and to demonstrate that lower-priority impacts are eventually addressed rather than permanently deprioritised. A SMETA report gives a buyer findings from one facility. It does not tell the buyer how that facility's findings compare against the rest of its supply chain, and it provides no mechanism for prioritising across a supplier base. Prioritisation is a portfolio-level exercise that has to happen on the buyer's side, using SMETA findings as one input among many.

Preventive and corrective action is the buyer's obligation, not the auditor's

A SMETA report documents non-conformances. It does not implement corrective action. CSDDD requires the company conducting due diligence to develop prevention action plans, seek contractual commitments, provide capacity building support where appropriate, and where the company has caused or contributed to a harm, to remediate it directly. None of this is generated by the audit itself. It has to be built and documented separately, using the audit findings as a trigger.

A buyer that receives a SMETA report showing findings and takes no further documented action has, if anything, created evidence against itself. It demonstrates the buyer knew about a problem and did not act on it, which is a materially worse position under CSDDD than not having commissioned the audit at all.

The complaints mechanism obligation is not met by SMETA

CSDDD requires the company to maintain an accessible, transparent complaints mechanism through which workers and other affected parties can raise concerns, and to demonstrate that complaints are acknowledged, investigated, and responded to. A SMETA audit may ask whether a facility has a grievance mechanism in place as part of its assessment criteria, but the audit itself is not that mechanism. It does not provide an ongoing channel for workers to raise issues between audits, and the buyer's CSDDD obligation to operate such a channel is entirely separate from anything SMETA produces.

Monitoring over time is structurally outside SMETA's scope

CSDDD requires companies to monitor the effectiveness of their due diligence measures on an ongoing basis and review the entire process at least annually. A single SMETA audit, or even an unbroken series of annual audits, tells a buyer what was found at each audit point. It does not, by itself, constitute a monitoring system that tracks whether preventive and corrective measures have actually worked between audits. Building that monitoring layer, connecting audit findings over time to specific corrective actions and their outcomes, is a task that sits with the buyer.

Established business partners beyond the audited facility

CSDDD's due diligence obligation extends across the supply chain to established business partners, which in practice can include a supplier's own upstream suppliers. A SMETA audit assesses the facility where it takes place. It does not extend the buyer's visibility into that supplier's own supply chain unless the audit scope has specifically been extended to cover it, which is unusual.

What a CSDDD-adequate use of SMETA looks like

None of this means SMETA audits are not worth commissioning or reviewing. It means they need to sit inside a larger structure rather than standing in for it. A buyer using SMETA effectively within a CSDDD programme typically does the following.

It treats SMETA findings as an input to a broader risk assessment that also draws on country and sector risk data, rather than as the risk assessment itself. It maintains a documented process for what happens after a SMETA report is received: who reviews it, what threshold of finding triggers a corrective action plan, and how that plan is tracked to completion. It operates its own complaints mechanism independent of anything the audited facility has in place, and it monitors supplier performance between audit cycles rather than only at the point each new audit report arrives.

It also treats audit age and pillar variant as compliance-relevant details rather than administrative footnotes. An eighteen-month-old two-pillar audit from a supplier in a sector where environmental risk is material is a weaker evidentiary basis than the same buyer might assume, both for satisfying the supplier's contractual requirements and for satisfying the buyer's own CSDDD identification obligation.

What this means for suppliers

For a non-EU supplier, the practical implication is that holding a current SMETA audit, even a strong one, does not mean the CSDDD conversation with an EU buyer is finished. Buyers running a serious CSDDD programme will ask supplementary questions the audit does not answer: what corrective actions have been taken on past findings, whether the facility has an independent complaints channel accessible to workers, and how conditions have been monitored since the last audit.

Suppliers who can answer these questions before being asked are in a stronger position than those who treat the SMETA report as the end of the compliance conversation. The audit is necessary evidence in many buyer relationships. It is not sufficient evidence on its own, for the buyer or for the supplier trying to demonstrate readiness.

For a detailed look at what evidence standards regulators, auditors, and courts actually apply when assessing CSDDD compliance, see What evidence EU sustainability auditors actually look for.

Verdandi monitors CSDDD, CSRD, EUDR, and CBAM continuously, so due diligence programmes built around supplier audits are working from current requirements as enforcement guidance and member state transposition develop. Start for free.

📋 Track EU sustainability regulation continuously

Verdandi monitors EU sustainability regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.