
The problem with letting suppliers choose their own auditors
Most widely used social compliance audits, including SMETA, rely on a model where the supplier selects and pays the auditor. This article explains the structural incentive that creates, why it matters more under CSDDD than it did before, and what companies can do about it.
This article is for informational purposes only and does not constitute legal advice. Consult a qualified legal professional for advice specific to your situation.
- Most widely used social compliance audits, including SMETA, rely on a model where the supplier selects and pays the auditor. The party whose conduct the audit is meant to assess is also the auditor's commercial client. This creates a systematic pressure toward leniency that operates at the population level, regardless of the professionalism of individual auditors.
- CSDDD changes what is at stake. Before CSDDD, an audit process with a bias toward not finding problems was a reputational and operational risk. Under CSDDD, failing to identify impacts that existed carries regulatory enforcement and civil liability consequences. A due diligence programme built primarily on supplier-selected, supplier-paid audits is relying on an evidentiary source with a documented structural bias in exactly the context where that bias has legal consequences.
- Switching from one supplier-selected scheme to another does not solve the underlying problem. Moving to a different certification or audit provider with the same selection model changes the criteria being assessed. It does not change who is choosing and paying the assessor. The independence issue is architectural, not scheme-specific.
- The more defensible approach is tiered. Supplier-selected audits like SMETA are legitimate as a baseline screening layer across lower-risk parts of the supplier base. Buyer-commissioned or buyer-governed independent verification, with unannounced visits and independently sourced worker interviews, is proportionate and necessary for suppliers in higher-risk sectors or geographies, or where baseline screening has already surfaced findings that warrant closer examination.
A commercial relationship at the centre of an independence claim
Most social compliance audits used in global supply chains today, SMETA among the most widely adopted, operate on the same basic model. The supplier being assessed selects the auditor, from an approved list, and pays them directly for the engagement. The buyer who ultimately relies on the audit report has no role in that selection and typically no direct commercial relationship with the auditor at all.
This model exists for understandable reasons. It lets a single audit be shared across multiple buyers through platforms like Sedex, which reduces the number of separate audits a supplier has to host. It keeps the cost of assessment with the party the audit is meant to improve accountability for, rather than requiring every buyer to fund separate audits of the same facility. Both of these are real efficiency gains.
The structural cost of that efficiency is an independence problem that sits at the centre of the whole arrangement: the auditor's client, in the ordinary commercial sense of who selects and pays them, is the party whose conduct the audit is meant to assess.
Why this creates a leniency incentive, not just a theoretical conflict
The concern here is not hypothetical or unique to any single audit firm or scheme. It is a documented dynamic across social compliance auditing generally: when an auditor's revenue depends on being repeatedly selected by the facilities they assess, and facilities are free to choose a different auditor for their next audit, auditors compete on more than technical rigour. A reputation for stringent findings can cost an audit firm future business from the same facility and from facilities in the same buyer network who hear about it. A reputation for smoother, more accommodating audits can generate repeat commissions.
This does not mean individual auditors act in bad faith, and it does not mean every SMETA report understates conditions at the audited facility. It means the financial architecture of the arrangement creates a systematic pressure in one direction, and that pressure exists regardless of the professionalism of any individual auditor operating within it. Structural incentives shape outcomes at the level of a population of audits, even when most individual auditors are conscientious.
A second, related pattern compounds this. Facilities that know an audit is coming, because they scheduled and paid for it themselves, have both the opportunity and often the incentive to prepare for it: cleaning up records, briefing workers on how to answer questions, and presenting temporary conditions as though they were standard practice. This preparation effect is distinct from the auditor selection issue but interacts with it. An auditor selected and paid by a well-prepared facility has less opportunity to observe conditions that deviate from what the facility wants shown, even setting aside any question of auditor leniency.
Why this matters more under CSDDD than it did before
Before CSDDD, the independence limitations of the supplier-selected auditor model were a quality concern for buyers trying to manage supply chain risk sensibly. A buyer relying on a leniency-prone audit process risked missing real problems, which was a reputational and operational risk worth managing, but the consequences of getting it wrong were largely commercial.
CSDDD changes what is at stake. The directive requires companies to conduct due diligence that identifies actual and potential adverse impacts, and both regulatory enforcement and civil liability now attach to whether that due diligence was adequate. A company that relied primarily on supplier-selected, supplier-paid audits as its evidence base for identifying supply chain impacts is relying on an evidentiary source with a documented structural bias toward not finding problems, in exactly the context where failing to find problems that existed carries legal consequences.
This is not an argument that supplier-selected audits are worthless as evidence. It is an argument that a regulator or a court assessing the adequacy of a due diligence programme is likely to weigh this kind of evidence more cautiously than evidence generated through a channel the assessed party does not control, for the reasons set out in What evidence EU sustainability auditors actually look for: independence is one of the core characteristics that makes evidence credible, and this model does not score well on it.
The pattern is not limited to SMETA
SMETA is the clearest and most widely encountered example because of its scale, but the same structural issue appears across most audit-based compliance schemes that rely on the assessed party to commission and fund the assessment. Facility-level management system certifications, many commodity-specific sustainability certification schemes, and a range of industry-specific social audit protocols share the same basic architecture: the facility being assessed selects and pays the assessor.
This is worth naming explicitly because it is easy to treat the leniency concern as a criticism specific to one scheme, address it by switching to a different certification or audit provider with the same underlying selection model, and believe the underlying problem has been solved. It has not. Moving from one supplier-selected audit scheme to another supplier-selected audit scheme changes the specific criteria being assessed. It does not change who is choosing and paying the assessor.
What independent verification actually looks like
The alternative to the supplier-selected model is not complicated in concept, even though it is more expensive and harder to scale. It means the party relying on the assessment, typically the buyer, selects and pays the assessor directly, or funds a pooled, buyer-governed assessment programme where individual suppliers do not control which assessor is assigned to them or when.
A small number of buyer-commissioned or buyer-governed assessment models exist in different sectors, often reserved for the highest-risk suppliers in a portfolio because of the cost involved. These typically also include unannounced or lightly announced visits, rather than audits scheduled well in advance by the facility being assessed, which removes much of the preparation effect described above. Worker interviews conducted by parties with no ongoing commercial relationship with the facility, sourced independently rather than through facility-provided interpreters or facilitators, are a further step in the same direction.
None of this needs to replace supplier-selected audits across an entire supply chain. For most companies, that would not be proportionate to the risk involved in lower-risk parts of the portfolio, and proportionality is itself a standard that regulators and courts apply when assessing whether due diligence effort matched the risk. The more defensible approach is tiered: supplier-selected audits like SMETA as a baseline screening layer across the full supplier base, with buyer-commissioned or buyer-governed independent verification reserved for suppliers in higher-risk sectors, higher-risk geographies, or suppliers where the baseline screening has already surfaced findings that warrant closer, independently verified follow-up.
What this means for the credibility of a due diligence programme
A CSDDD due diligence programme built entirely on supplier-selected, supplier-paid audits is not without value, but it has an identifiable evidentiary weakness that a regulator, a court, or an EU buyer's own assurance auditor is likely to recognise. The programme needs at least one layer of verification, applied where risk is highest, that the assessed party does not control.
This does not require abandoning the efficiency that platforms like Sedex genuinely provide for lower-risk parts of a supply chain. It requires recognising which parts of a due diligence programme that efficiency is well suited to, and which parts, because of the level of risk involved or the consequences of getting it wrong, need an evidentiary source with a different, less commercially entangled structure behind it.
For suppliers, understanding this distinction is useful context for what an EU buyer running a well-designed CSDDD programme may eventually ask for. A supplier who has only ever been asked for a SMETA report may, if their sector or geography carries elevated risk, eventually be asked to accommodate an assessment they did not select or schedule. That is not an unusual or unreasonable request under a CSDDD-driven due diligence programme. It reflects the buyer taking the independence problem described in this article seriously.
For background on what a SMETA audit does and does not establish within a CSDDD due diligence programme specifically, see Does a SMETA audit satisfy CSDDD due diligence requirements?.
Verdandi monitors CSDDD, CSRD, and EUDR continuously, including enforcement and evidentiary guidance as it develops, so due diligence programmes are built to withstand scrutiny rather than assumed to. Start for free.
📋 Track EU sustainability regulation continuously
Verdandi monitors EU sustainability regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.