Knowledge & Perspectives

Supplier Social Risk in India: The Blind Spot Most Procurement Teams Are Only Now Starting to See

Most procurement teams in India manage financial, quality, and delivery risk on their suppliers. Supplier social risk, covering labour practices, wage compliance, safety conditions, subcontracting exposure, and grievance access, is the gap. With BRSR Core value chain expectations, CSRD buyer questionnaires, and the EU Forced Labour Regulation converging, that gap is becoming commercially expensive. Here is what a real supplier social compliance system looks like, and how to know whether yours is one.
Table of Contents

Supplier Accountability

Procurement teams in mid-sized Indian companies have become genuinely sophisticated about certain kinds of supplier risk. Financial risk: is this vendor solvent, do they have the working capital to deliver? Quality risk: what is their rejection rate, do they hold the right certifications? Delivery risk: what is their on-time performance, do they have backup capacity?

These are the risks that procurement was built to manage. They are measurable, they have established assessment tools, and they have direct operational consequences when they go wrong.

Supplier social risk does not fit that model. It is harder to quantify, sits outside traditional procurement workflows, and has historically produced consequences that felt distant and theoretical. Labour violations at a tier-two subcontractor. A safety incident at a supplier site that never made it into any internal report. A wage compliance failure that a buyer’s due diligence team uncovered three years later during an acquisition.

That distance is closing. Fast.

The combination of BRSR Core value chain disclosure requirements, buyer-side ESG questionnaires cascading from CSRD-compliant European companies, and the EU Forced Labour Regulation has shifted supplier social risk from a theoretical concern to an operational one. The procurement teams that have not yet built a social risk management system are not just behind on compliance. They are accumulating commercial exposure that will eventually land on someone’s desk at a bad moment.

This post explains what supplier social risk actually covers, why it is structurally different from the risks procurement teams already manage, and what a real supplier social compliance system looks like versus a signed code of conduct sitting in a shared drive.

What supplier social risk actually covers

“Social risk” in a supply chain context is broader than most procurement teams assume. It is not just child labour or forced labour, though those are the categories that make headlines. It covers the full range of how a supplier manages its obligations to the people who work within it and around it.

In practice, supplier social risk breaks into five categories:

Labour practices and wage compliance.

Are workers being paid on time, in full, and at or above minimum wage? Are wage deductions being made legally? Is the contractor workforce (often the highest-risk group) receiving the same baseline protections as permanent employees? In India’s manufacturing sector, contractor-heavy operations are the norm, not the exception, and contractor wage compliance is almost never monitored by the principal employer’s procurement team.

Health, safety, and working conditions.

Does the supplier have functional safety systems, not just policies? Are incident records maintained and accurate? Are safety incidents at subcontracted sites reported upward? A supplier can have a clean safety record on paper while operating facilities where workers have never been trained on emergency procedures.

Subcontracting and multi-tier exposure.

Tier-one suppliers often subcontract work, particularly during peak demand. Most procurement teams have visibility into their tier-one suppliers and essentially none into tier-two or tier-three. Social risk does not stop at the first tier. It accumulates downstream, and when a buyer or regulatory body finds a problem three tiers down, the liability traces back to the principal company.

Freedom of association and grievance access.

Do workers at supplier facilities have access to a functioning grievance mechanism? Can they raise concerns without fear of retaliation? This is one of the least-monitored social risk categories and one of the first things a social compliance auditor checks.

Community and environmental interface.

How does the supplier manage its relationship with surrounding communities? Are there land use disputes, water access conflicts, or waste disposal practices that create community harm? These are social risks that can surface in buyer due diligence even when they do not show up in any formal supplier report.

Why this gap is becoming expensive right now

Three converging pressures have moved supplier social risk from a voluntary ethics position to an operational risk management requirement. They are worth understanding separately because they come from different directions and affect different parts of the business.

Pressure 1: BRSR Core value chain expectations

SEBI’s BRSR Core framework requires social KPI disclosure from the top 1,000 listed Indian companies, with third-party assessment or assurance phased in to reach all 1,000 by FY 2026-27. The March 2025 SEBI circular made value chain ESG disclosure voluntary (not mandatory) for the top 250 listed entities, with a revised threshold of value chain partners individually contributing 2% or more of purchases or sales.

Voluntary at the regulatory level does not mean optional at the commercial level. Investors, ESG rating agencies, and large buyers all expect to see value chain social data from companies they deal with. As one analysis put it, supplier ESG data cannot be collected without contractual rights, onboarding processes, training systems, internal ownership, digital tools, and senior management backing. Procurement teams are not traditionally designed to manage ESG performance. (Source: esg360.in, January 2026)

The companies building supplier social risk systems now are doing so because their own BRSR Core obligations, and the questions they get from investors and buyers, are making the absence of that data visible.

Pressure 2: CSRD-driven buyer questionnaires

EU CSRD (Corporate Sustainability Reporting Directive) requires large European companies to report sustainability data including supply chain social metrics. That reporting obligation cascades into the questionnaires they send to Indian suppliers. A European buyer preparing its own CSRD disclosure needs supplier data to fill its scope 3 and value chain disclosures. That need does not wait for Indian regulation to catch up.

SEBI’s updated framework means auditors now ask for evidence of implementation, not just policy documents. This includes vendor codes of conduct, documented ESG commitments signed by suppliers, and evidence of monitoring. (Source: pqsmitra.com, September 2025)

Indian companies receiving longer, more detailed buyer questionnaires at contract renewal are experiencing this pressure directly. The questionnaires are getting more specific, the documentation requirements are getting more detailed, and the consequence of a weak response is increasingly a lost contract rather than a follow-up email.

Pressure 3: The EU Forced Labour Regulation

The EU Forced Labour Regulation (Regulation (EU) 2024/3015), adopted in November 2024 and applying from December 2027, prohibits products made with forced labour from being placed on or exported from the EU market. Enforcement involves product investigations, port detentions, and market withdrawal orders. The regulation covers all products, all supply chain tiers, and all geographies. Indian exporters in textiles, garments, leather, electronics assembly, and agricultural processing are in scope.

The practical consequence for procurement teams: the documentation required to demonstrate a clean supply chain under the Forced Labour Regulation is the same documentation that comes from a functional supplier social compliance system. Companies building that system now for BRSR and buyer reasons get FLR readiness as a by-product. Companies that wait will need to build it reactively under regulatory pressure, which is significantly more expensive.

The difference between a supplier code of conduct and a supplier compliance system

This is the central distinction that most procurement teams have not yet made. And it is the distinction that becomes visible during a buyer audit or assessment review.

A supplier code of conduct is a document. It states what the company expects of its suppliers on labour practices, safety, environmental management, and ethical conduct. Most mid-sized Indian companies have one. It was drafted, reviewed by legal, shared with suppliers at onboarding, and filed. Many suppliers signed it.

A supplier social compliance system is the operating model behind that document. It includes:

  • A risk segmentation process that tells you which suppliers carry the most social risk and why
  • Documented assessment criteria and a consistent methodology for evaluating social compliance
  • A monitoring schedule with defined frequency by supplier tier
  • A corrective action and preventive action (CAPA) process for when non-compliance is found
  • An evidence management system that maintains documentation in a format that can be produced under audit
  • Defined ownership within procurement or sustainability for each element of the system

The gap between these two things is where most mid-sized Indian companies currently sit. The code of conduct exists. The system does not. And the gap only becomes visible when someone actually checks.

How to segment supplier social risk: a working framework

Not all suppliers carry the same social risk. A supplier segmentation model allows procurement teams to direct monitoring resources toward the highest-risk relationships and apply proportionate controls across the base. The following framework is a starting point, not a definitive standard, but it covers the variables that matter most in the Indian manufacturing context.

Risk dimensionHigh risk indicatorsMedium risk indicatorsLower risk indicators
SectorTextiles, garments, leather, construction, mining, agricultural processingChemicals, electronics assembly, food processingIT services, professional services, logistics
Workforce profileHigh contractor ratio, migrant workers, piece-rate paymentMixed permanent and contract, regular payrollPredominantly permanent, salaried workforce
GeographyRemote or semi-urban locations, states with weak labour enforcementTier 2 cities, mixed enforcementMajor industrial hubs, strong enforcement environment
SubcontractingMulti-tier subcontracting, home-based work, job work arrangementsSome subcontracting, defined scopeNo subcontracting, fully in-house production
Past compliance recordPrior audit findings, legal notices, worker complaintsSome minor findings, remediatedClean record, proactive disclosure
Size and capacitySmall, family-run, limited HR functionMid-sized, basic HR systemsStructured HR, compliance function in place

Use this table to assign each tier-one supplier a risk band: high, medium, or lower. The output determines assessment frequency (high risk: annual site assessment; medium: biennial with desk review in alternating years; lower: triennial or self-declaration with spot checks), the depth of documentation required, and the escalation threshold for CAPA.

This segmentation exercise is not complex to run for the first time. A procurement team with access to basic supplier information can complete an initial segmentation across their top 20-30 suppliers in one working day. The value is not in the segmentation itself but in the decisions it produces: which suppliers get assessed this year, what the assessment covers, and what happens when findings are identified.

What a buyer audit actually looks for

Understanding what a buyer social compliance audit examines is useful context for building an internal system, because the buyer audit is essentially a preview of what a BRSR Core assessment reviewer or an investor due diligence team will also look for.

Buyer social audits typically follow one of several recognised standards, SA8000, SMETA (Sedex Members Ethical Trade Audit), BSCI, or a buyer-proprietary protocol. The content varies but the core areas are consistent:

  • Worker interviews: auditors speak directly with workers, often without management present, to verify whether stated conditions match actual conditions
  • Wage records: payroll records, contractor invoices, and attendance records are cross-checked against statutory minimums
  • Safety documentation: incident registers, first aid records, fire safety inspection records, emergency procedure training logs
  • Grievance records: evidence that a grievance mechanism exists, that it is accessible to workers, and that complaints have been received, addressed, and closed
  • Subcontractor visibility: who the tier-one supplier uses for subcontracted work, and whether those subcontractors have been assessed

The most common failure points in Indian manufacturing supply chains, based on published audit finding patterns, are wage and contractor compliance, grievance mechanism functionality, and subcontractor visibility. These are also the areas where a company that has a code of conduct but no compliance system will be most exposed.

Five signs your supplier social risk management is a policy, not a system

These questions are for internal use. They do not require external input to answer, and the answers are diagnostic.

1. Can you name which suppliers carry the highest social risk in your base, and why?
If the answer is based on gut feel rather than a documented segmentation, you do not have a risk management system. You have an opinion.

2. When did you last conduct a meaningful assessment of a tier-one supplier’s social compliance?
Not receive a signed declaration. Conduct a review involving site visits, worker interviews, or at minimum a structured document review with follow-up questions.

3. Do you have a defined corrective action process for when a supplier fails a social assessment?
What happens when a supplier does not meet the standard? If there is no documented CAPA process, non-compliance findings disappear rather than get resolved.

4. Can you produce the last three years of supplier social compliance documentation in 48 hours?
A buyer audit or assessment review will typically request historical documentation with limited notice. If producing it would require a cross-departmental scramble, the evidence management system does not exist in any meaningful sense.

5. Does anyone at leadership level receive a regular view of supplier social compliance status?
Not a one-line mention in an annual sustainability report. A structured update, on a defined cadence, showing which suppliers have been assessed, what was found, and what is being done about it.

If any of these questions produces a pause, that pause is the gap a buyer auditor or assessment reviewer will find before you do.

The cost of finding out the hard way

The business case for building a supplier social compliance system is not primarily ethical, though the ethical case is real. It is financial and commercial.

Only 46% of organisations globally have formal sustainability risk management in place, and even fewer apply it to tier-2 suppliers. (Source: Galkaduwa Rallage, Kosalee Thameera (2021))

That gap produces real costs when it surfaces:

Contract loss.
A European buyer’s social compliance questionnaire at contract renewal reveals gaps in your supplier documentation trail. The contract goes to a competitor who can answer the questions. The revenue impact is immediate and the relationship damage is lasting.

Assessment failure remediation.
A BRSR Core assessment review identifies that your supplier social disclosures are not supported by a governance system. Remediation engagements, building the systems that should have been in place before the assessment, typically cost significantly more than building them proactively. The urgency premium is real.

Reputational exposure.
A social compliance failure at a supplier site, once public, is difficult to contain regardless of whether the principal company was directly responsible. Buyers, investors, and ESG rating agencies do not make fine distinctions between the company and its supply chain when reputational damage occurs.

PE and M&A discount.
Private equity due diligence is increasingly examining supply chain social compliance as part of ESG risk assessment. Weak supplier governance does not kill transactions, but it creates negotiating leverage for the buyer and can affect valuation multiples.

Building a supplier social compliance system now costs a fraction of managing any one of these outcomes after the fact.

Frequently Asked Questions about Supplier Social Risk

What is supplier social risk?

Supplier social risk refers to the potential for harm, financial, reputational, or regulatory, arising from how a company’s suppliers manage their obligations to workers, subcontractors, and surrounding communities. It covers labour practices, wage compliance, health and safety conditions, subcontracting transparency, grievance access, and community impact. It is distinct from supplier financial risk or quality risk, and requires a different assessment methodology.

Is supplier social compliance mandatory under BRSR in India?

BRSR Core value chain ESG disclosures are currently voluntary for the top 250 listed entities, applicable from FY 2025-26, with assessment or assurance of those disclosures also voluntary from FY 2026-27 (per SEBI Circular dated 28 March 2025). However, voluntary at the regulatory level does not mean optional commercially. Investor due diligence, ESG rating agencies, and buyer ESG audits all expect to see supplier social data regardless of whether SEBI mandates it. The commercial pressure has moved faster than the regulatory requirement.

What is a supplier code of conduct and is it enough?

A supplier code of conduct is a document stating what a company expects of its suppliers on labour, safety, ethics, and environmental conduct. It is a necessary starting point but is not sufficient on its own. Without a compliance system behind it (risk segmentation, assessment methodology, monitoring schedule, CAPA process, evidence management, and ownership structure), the code of conduct is a statement of intent that cannot be demonstrated under scrutiny.

How often should suppliers be assessed for social compliance?

Assessment frequency should be risk-based. High-risk suppliers (high contractor ratio, labour-intensive sectors, complex subcontracting, prior findings) warrant annual assessment. Medium-risk suppliers may be assessed biennially with desk reviews in alternate years. Lower-risk suppliers can operate on triennial cycles or self-declaration with spot checks. The frequency should be documented in a supplier compliance policy so it is defensible if questioned.

What does a buyer social compliance audit look for?

Buyer audits typically examine wage records and contractor invoices cross-checked against statutory minimums, worker interview responses verified against management claims, safety documentation including incident registers and emergency procedure training records, grievance mechanism evidence showing that the mechanism is accessible and functional, and subcontractor visibility demonstrating that the tier-one supplier knows who is doing subcontracted work and has some assurance of their compliance status.

What is the EU Forced Labour Regulation and does it affect Indian suppliers?

The EU Forced Labour Regulation (Regulation (EU) 2024/3015) prohibits products made with forced labour from being placed on or exported from the EU market. It applies from December 2027, covers all products, all supply chain tiers, and all geographies including India. Indian exporters in textiles, garments, leather, electronics assembly, and agricultural processing are directly in scope. Compliance requires documented evidence of supply chain social compliance, which overlaps substantially with what a BRSR Core and buyer audit programme would already require.

Where does supplier social compliance fit in the SVEGA Framework?

It sits within Pillar 3: Ethical Supply Chain Controls. This pillar covers supplier code alignment, the due diligence model, risk segmentation, assessment methodology, CAPA structure, and evidence management. In a SVEGA System Build engagement, Pillar 3 typically involves a current-state assessment of existing supplier compliance practices, a risk segmentation exercise across the active supplier base, and the design and implementation of a compliance operating model that can be demonstrated under buyer audit or BRSR Core assessment review.

What to do next

Supplier social risk management is not a project that needs to be perfect before it starts. The most important first step is to know which suppliers carry the most risk, and to have a documented basis for that judgment.

A basic segmentation of your top 20-30 suppliers against the risk dimensions above can be completed in a day. The output tells you where to focus, what to assess first, and what documentation gaps need to close before the next buyer questionnaire or assessment review arrives.

If you want to understand your current exposure across all six SVEGA Framework pillars, including supplier social compliance, a SVEGA Diagnostic gives you a full gap map and a 90-day roadmap in three weeks.

Picture of Priyanka Bajiraj

Priyanka Bajiraj

Priyanka Bajiraj is a sustainability and social ESG professional with 10 years of experience across sustainability research, social governance advisory, UN exposure, and operational systems thinking.

Through SVEGA, Priyanka focuses on helping organisations move beyond ESG narratives and build practical governance systems that make social responsibility measurable, accountable, and operational.

WHAT'S INCLUDED

Build supplier systems that protect growth and market access.

Regulatory Intelligence

The four labour codes came into force on 21 November 2025, repealing twenty-nine central labour laws, and the final central rules followed on 8 May 2026. For a factory of about a hundred people, several obligations are now settled and headcount-triggered: a new wage definition that lifts provident fund and gratuity costs, appointment letters for every worker, a grievance committee at twenty workers, a works committee at a hundred, and a creche at fifty.

Supplier Accountability

For a growing number of Indian manufacturers and exporters, a SMETA audit has become the compliance test that actually gates the order, ahead of anything SEBI requires. A buyer in Europe or the United States asks for one, and a factory that never had a BRSR obligation suddenly has an auditor at the gate. It matters here for one specific reason: SMETA measures a site against the ETI Base Code as well as Indian law, whichever protects the worker more, so a factory that is fully compliant with the labour codes can still receive findings. This post walks through what the auditor does on the day, and where mid-sized Indian factories most often lose ground.

Social Governance Fundamentals

Most social compliance advice in India is written for the top 1,000 listed companies. The unlisted manufacturers and exporters that carry the bulk of the country’s production sit below the BRSR line but still face buyer audits, the labour codes, and customer questionnaires. This post explains who the missing middle is and what social governance actually means for a company this size.

Governance Architecture

BRSR requires every listed company to disclose grievance mechanisms and resolution data across all nine NGRBC Principles. The Industrial Relations Code, 2020 mandates a Grievance Redressal Committee for any establishment with 20 or more workers. Most companies have the policy document. Very few have a functioning system with documented intake, defined workflows, escalation triggers, and closure records. This post maps the full regulatory requirement, identifies the five failure modes that show up in assessment and audit, provides an eight-step build guide for mid-sized companies, and includes FAQs on contract worker access, zero-grievance red flags, and the distinction between POSH and general grievance mechanisms.

REACH US

If this resonates with the governance challenges you are navigating,

we welcome a focused conversation about where your organisation stands and what building the right systems would look like.