Six weeks is roughly what a buyer gives you. The email arrives from a sourcing manager, names an audit you have heard of but never sat through, and asks for confirmation of a date. Somewhere in the thread is a link to the Sedex platform and a request to complete something called a Self-Assessment Questionnaire.
What follows below is what the auditor will actually do. Not the principles behind the audit, and not a list of things you ought to have. The sequence of the day, the number of workers who will be pulled off the floor and interviewed, the specific months of payroll that will be sampled, and the four ways a finding can be written against you.
Most of what is described here comes from the SMETA Auditor Manual, which Sedex publishes and which anyone can read [1]. The auditor arriving at your gate has been trained on that document. It is worth knowing what it tells them to do.
What is SMETA
SMETA stands for Sedex Members Ethical Trade Audit. Sedex owns and maintains the methodology and describes it as the most widely used social audit in the world. Sedex does not conduct audits itself. The work is done by approved audit companies, and Sedex oversees consistency through an audit quality programme [2].
SMETA measures a site against three things at once: the ETI Base Code, the conventions of the International Labour Organisation, and local law [1]. That third element matters more than people expect, and this post returns to it.
The ETI Base Code has nine clauses [3]:
- Employment is freely chosen
- Freedom of association and the right to collective bargaining are respected
- Working conditions are safe and hygienic
- Child labour shall not be used
- Living wages are paid
- Working hours are not excessive
- No discrimination is practised
- Regular employment is provided
- No harsh or inhumane treatment is allowed
The current version of the methodology is SMETA 7.0, which replaced version 6.1 in September 2024. Version 7.0 kept the Base Code structure and the audit types, and added two things that changed the character of the exercise: a Management Systems Assessment, and a finding type for problems a single supplier cannot fix alone [1].
What SMETA Is Not
SMETA is not a certification. There is no certificate at the end of it and no pass or fail. The Auditor Manual instructs auditors to say this out loud to site management, because factories that believe they are being graded tend to hide things, and hidden things produce worse audits [1].
What the audit produces is two documents: an Audit Report and a Corrective Action Plan Report, usually shortened to CAPR. Both are uploaded to the Sedex platform, where the buyers you are linked to can read them [1].
The pressure does not come from a certificate you never receive. It comes from a report your customer can read.
Two Pillars or Four Pillars
The buyer chooses the scope, not you.
A two-pillar audit covers labour standards and health and safety, together with a shorter environment assessment. A four-pillar audit adds a fuller environment module and a business ethics module. The extra two modules add half an auditor day to the time on site, and because that half day is split across both, the document review for those modules tends to be closer to an assisted self-assessment than a full investigation [1].
If the buyer has not told you which one they are requesting, ask before you book anything. The preparation differs.
The Process, From Request to Report
The audit is requested. Any party with a legitimate interest can commission and pay for the audit. That is usually the buyer, sometimes the supplier itself [1].
Your site must be an active Sedex member. Sedex permits an approved audit company to conduct a SMETA audit only for registered members with an active platform account. Without a live account, the audit cannot be uploaded, and an audit that cannot be uploaded is of no use to the buyer who asked for it [2].
You complete the Self-Assessment Questionnaire. The SAQ is where you describe your workforce, your hours, your operations, and your existing practices. Auditors are instructed to use it as preparatory material, and many of the data points in the final audit report are drawn from the same fields [1]. The SAQ is not a formality. It is the document that tells the auditor where to look first.
The audit type is set. There are three. An announced audit means the date is agreed with you. A semi-announced audit means the audit falls somewhere inside a window of at least three weeks, and you are not told which day. An unannounced audit means no notice at all [1].
The direction of travel here is worth understanding. Following a member consultation, Sedex updated its platform so that semi-announced scheduling is the default option, and anyone who books an announced audit has to record a reason for doing so [4]. The industry is moving away from giving factories a date to prepare for. A site that can only pass on a day it knows about in advance is not, in the assessing buyer’s view, a site that passes.
The audit is scheduled during real production. The Manual instructs that audits take place when at least 60 percent of the peak workforce is present, and when the site is in full operation. If the audit runs at between 60 and 80 percent of peak workforce, the auditor must explain why in the report. Below 60 percent, the audit is not to happen at all [1].
You receive the pre-audit pack. At least two weeks before the audit, the audit company must send you the agreed scope, a list of documents that need to be available, a list of the people who must be present, the agenda, the requirements for worker interviews, the rules on photography, and the arrangements for uploading the report [1].
That document list is not a suggestion. Read the next section carefully.
How Long the Auditor Stays and How Many Workers They Interview
This is prescribed, and it scales with headcount. For an initial or periodic two-pillar audit [1]:
| Workers on site | Auditor days | Individual interviews | Group interviews | Total workers interviewed | Worker files reviewed |
|---|---|---|---|---|---|
| 5 to 100 | 1 | 5 | 1 group of 5 | 10 | 10 |
| 101 to 500 | 2 | 6 | 4 groups of 5 | 26 | 26 |
| 501 to 1,000 | 3 | 12 | 6 groups of 5 | 42 | 42 |
| 1,001 to 2,000 | 4 | 20 | 8 groups of 4 | 52 | 52 |
| 2,001 and above | 4 | 22 | 8 groups of 5 | 62 minimum | 62 |
A few things follow from that table that are easy to miss.
The interview numbers are a floor, not a target. The auditor days exclude preparation, travel, and report writing, but include producing the CAPR on site. Group interviews are capped at five people, on the reasoning that larger groups suppress discussion of sensitive matters. Individual interviews run 15 to 30 minutes and may not run shorter than 15. Group interviews run 30 to 40 minutes and may not run shorter than 30. A four-pillar audit adds half an auditor day and at least one additional worker interview and one additional management interview [1].
Sedex does not recommend SMETA for sites with fewer than five workers [1].
The workers who sit in the individual interviews are always included in the sample of files that gets pulled. The rest of the file sample is drawn randomly across the workforce, and the auditor is instructed to make sure all types of worker appear in it: agency workers, temporary workers, permanent workers, migrant workers, young workers, pregnant workers. The sample must include workers who are not on site on the day, including those employed at a different time of year and those not on shift [1].
If you run a night shift, the audit company is required to have a policy that brings night shift workers into the audit, either by starting early, finishing late, or making a separate visit [1].
What Happens on the Day
Six stages. Sedex does not mandate the order, but all six must happen for the audit to count [1].
The opening meeting
Senior management attends. So do the managers responsible for key functions, typically human resources and production. If a trade union or worker representatives exist at the site, the auditor is instructed to strongly request their presence, and if they are not there, the auditor must obtain a reason from the site and record it in the report [1].
The meeting happens in a language the participants understand. If the auditor does not speak it, a translator is used.
The site tour
The auditor leads the tour and sets the pace. You do not. The Manual is explicit that the auditor is not to be guided by management on which areas to visit, and is expected to plan the route in advance from a site map [1].
Production must continue during the tour. The auditor needs to see the floor working, and a site that halts production for the visit has removed the thing being assessed.
The auditor is also selecting interviewees during the tour, looking specifically for workers who may be more exposed to risk: those in hazardous jobs, migrant workers, and women workers [1].
Management interviews
The auditor talks to relevant managers about each Base Code area, and combines this with the document review. Questions are open, not leading. The Manual gives the example of asking how the site checks ages at recruitment rather than asking whether the site ensures all workers are above minimum age [1]. The first question produces an answer. The second produces a yes.
The auditor is instructed to talk to administrative staff and less senior managers as well, on the view that they see the implementation differently from the people who wrote the policy.
Worker interviews
Workers are selected by the auditor alone. Management may not select them or influence the selection. Selection happens as late as possible, specifically to reduce the chance that workers have been coached [1].
Interviews are held away from management offices. No manager is present. Workers must not be watched, seen, or overheard. Where a translator is needed, the translator must be independent of site management and briefed on confidentiality [1].
The auditor leaves a contact number with every worker interviewed so that the worker can report reprisals afterwards. Names of workers who raise issues are never disclosed to the site, the supplier, or the audit requestor, and never appear in the report [1].
This is the part of the audit that cannot be prepared for by preparing an answer. Worker interviews exist precisely to surface what documents cannot: discrimination, harassment, forced labour, intimidation [1]. Coaching workers is an attempt to pervert the audit, and an attempt to pervert the audit through fraud, coercion, deception, or interference is defined in the methodology as a Critical non-conformance in its own right [1].
Document review
Here is the rule that catches most factories.
All documentation must be available at the site on the day of the audit, including payroll and working hours records. If records for the previous 12 months are not available, the site must explain why. Where the absence has no legitimate explanation, the auditor records it as a non-compliance [1].
The sampling method is specific. The auditor reviews at least three months of records drawn from the 12-month set, and those three months must include the most recent month, a peak season month, and a low season or random month. For a site of up to 100 workers, that means a minimum of 10 records for each pay period selected. Wages and working hours records are generally sampled from the same time periods, so they can be read against each other. If issues turn up in the first sample, a larger sample is pulled [1].
That last point is worth restating in plain terms. The auditor deliberately compares your busiest month against your quietest month, because that is where overtime irregularities live.
The auditor also cross-checks documents against each other and against what workers said. Where production records, payroll records, shipping records, and working hours records do not agree, the auditor completes the wages and hours analysis anyway, states in the report whether the inconsistency was isolated or repeated, and raises findings where the absence or inconsistency of records means compliance cannot be verified [1].
Compliance that cannot be verified is treated as compliance that does not exist.
Falsified or withheld records fall under Base Code Area 0, and a systemic or wilful intent to mislead is treated as a serious matter and recorded as such [1].
The closing meeting
Before it, the auditor drafts the CAPR. The closing meeting is attended by the same people who attended the opening meeting, including worker representatives. Findings are discussed, corrective actions are agreed, timescales are set, and the CAPR is signed by both a site representative and the auditor [1].
If you disagree with a finding, there is a dispute box on the CAPR. You may state your reasons there, sign to acknowledge the dispute, and dispute the finding again after the report is published [1].
If you refuse to sign entirely, that refusal is itself recorded [1].
One detail that surprises people: the auditor is prohibited from telling you the criticality of your non-compliances during the audit, and is not shown criticalities in the platform. Auditors also may not sell you consultancy, and may not act in a consultative role in defining or closing your corrective actions [1]. The person who found the problem is not permitted to be the person who fixes it.
The Management Systems Assessment
This is the substantive change in SMETA 7.0, and it is the part that mid-sized Indian manufacturers tend to fail without understanding why.
The Management Systems Assessment, or MSA, is applied to every Base Code area separately. It asks a different question from the rest of the audit. The rest of the audit asks whether you are compliant today. The MSA asks whether your systems are likely to keep you compliant over time [1].
Four elements are graded for each Base Code area [1]:
- Policies and procedures. Do documented policies and procedures exist to keep the site compliant with the requirements in that Base Code area?
- Resources. Is there a manager of sufficient seniority with operational responsibility and the authority to implement them?
- Communication and training. Have workers, supervisors, and managers been trained on them, and can they demonstrate understanding?
- Monitoring. Does the site monitor whether the procedures work, and act on what the monitoring shows?
Each element receives one of four grades: Not Addressed, Fundamental Improvements Required, Some Improvements Recommended, or Robust Management System [1].
Two rules inside the grading deserve attention.
First, an undocumented procedure that the auditor can corroborate through other evidence can achieve at most a grade of Fundamental Improvements Required. The reasoning is that a procedure which exists only in someone’s head is not a system. An undocumented procedure that cannot be corroborated is graded Not Addressed [1].
Second, the top grade is never awarded by default. The Manual states plainly that the absence of a non-conformance does not entitle a site to the top grade, and that every grade requires an explanation [1]. Passing on the day is not the same as being assessed as sustainable.
The MSA does not itself produce non-compliances. It produces grades, and those grades appear in the CAPR alongside your findings, where your buyer reads them [1]. A site with few findings and four elements graded Not Addressed has told its customer something specific: that this year’s clean audit was luck.
How The Findings Are Written
There are four kinds of audit finding [1]:
Non-compliance. The site does not meet local, national, or international law.
Non-conformance. The site meets the law but does not meet the Base Code.
The distinction matters, and it explains why an Indian factory can be entirely legal and still receive findings. The auditor is instructed to raise a finding wherever either the law or the Base Code is unmet, so that the higher protection applies [1]. Where the Base Code sets a stricter standard than Indian law, the Base Code is what you are held to.
Good Example. A practice that goes beyond what the law or the Base Code requires. Merely meeting the requirement does not earn one [1].
Collaborative Action Required. This is new in SMETA 7.0. It is a type of non-conformance raised where the site does not meet the Base Code but closing the gap sits partly outside the supplier’s control. Living wages are the obvious case. A CAR finding carries no mandated closure time. The supplier may share an action plan on the platform, which moves the status from open to in progress, and the expectation is that the buyer and supplier work on it together [1].
Every non-compliance is also described by an Issue Title, which carries a criticality that the auditor does not select and cannot see. Criticalities run from Business Critical, which means an imminent risk to life or a severe human rights impact, down through Critical and Major to Minor [1].
Then there is the isolated and systemic distinction, which drives more of your outcome than the finding itself.
An issue is treated as isolated when the management system is largely working and the failure came from a rare cause. Where three or fewer instances turn up in a sample, or where a non-sampled issue occurs at a rate below 10 percent, the auditor may consider it isolated. More than three instances, or a failure rate above 10 percent, and the auditor is instructed to investigate further and record the issue as systemic [1].
A systemic finding says the system is absent or unfit. That is a different conversation with your buyer from an isolated one.
The Outputs, and How Long They Last
Where the contract does not specify a deadline, the audit company must submit the report on the Sedex platform within 15 calendar days of the audit [1].
Corrective action timescales are set by the Issue Title, and can be adjusted by agreement between auditor, site, and customer. Most run to a minimum of 30 days, because the auditor needs at least a month of records to verify that something has changed. Wages and hours corrections commonly require 60 to 90 days of evidence. Business critical issues carry an immediate timeframe [1].
Verification is either a desktop review, using photographs, certificates, and invoices uploaded to the platform, or an on-site follow-up. Anything that can only be verified by walking the floor, interviewing people, or sampling records requires the auditor to come back [1].
On validity, Sedex’s position after its member consultation is that it no longer accepts a SMETA audit as a sound assessment of current workplace conditions after 24 months. The recommended cadence remains yearly for high risk sites, every two years for medium risk, and at the buyer’s discretion for low risk [4].
Where Indian Factories Lose Ground
Nothing above is India-specific. This section is.
Because SMETA audits against local law as well as the Base Code, the four labour codes are now inside the audit. They came into force on 21 November 2025, and the final central rules under all four were notified on 8 May 2026 [5][6]. An auditor who has done their pre-audit background review, which the Manual requires, arrives knowing what the law changed [1].
Working hours have two ceilings, and they are not the same ceiling.
Indian law sets eight hours a day and 48 hours a week, with overtime paid at twice the ordinary rate of wages and requiring the worker’s consent [5][7]. The final central rules cap overtime at 144 hours in any quarter [6]. That figure replaced the 125 hours that appeared in the draft rules, and both are far above the 50 hours a quarter that the Factories Act allowed. Any commentary still quoting 125 is quoting the draft.
The ETI Base Code caps total hours worked in any seven-day period at 60, including all overtime, and requires at least one day off in seven [3][8]. It permits exceeding 60 hours only in narrowly defined exceptional circumstances involving a collective agreement, and the Ethical Trading Initiative has stated that seasonal work does not qualify as exceptional, because a seasonal peak is predictable [8].
So a factory can distribute 144 quarterly overtime hours in a way that is lawful in India and breaches clause 6.4 of the Base Code in a specific week. The auditor raises a finding either way [1]. If your peak season concentrates overtime, this is the arithmetic that will produce your findings. Do it before the auditor does.
One point runs the other way. The Base Code recommends an overtime premium of not less than 125 percent of the regular rate [3]. India requires 200 percent [7]. Where the law affords the greater protection, the law applies. A factory paying double for overtime is above the Base Code on that specific clause, and it is worth having the payroll evidence ready to show it.
Contract labour is the first place the auditor will look, and the last place the paperwork exists.
Contract workers were 40.7 percent of India’s formal manufacturing workforce in FY23, 5.95 million of 14.61 million, the highest share on record [9]. Base Code clause 8 requires that obligations arising from a regular employment relationship not be avoided through labour-only contracting or sub-contracting [3]. Base Code area 8A in the SMETA methodology deals specifically with sub-contracting and homeworkers [1].
The auditor’s file sample is required to include agency workers and workers supplied through third parties [1]. Under the OSH Code, the contract labour licensing threshold moved from 20 to 50 workers, and the principal employer carries primary liability: where the contractor fails to pay wages, the principal employer pays them [5][7]. Two consequences follow. Your contractor’s registers are your exposure. And the fact that a contractor employing fewer than 50 workers needs no licence does not relieve you of the requirement to hold their wage and attendance records.
The documents the labour codes now require are the documents the auditor now expects.
Appointment letters are mandatory for every worker, in a prescribed format, and workers who never received one are to be issued one [6]. Wage slips must be issued electronically, on or before the date of wage payment [6]. Wage registers, muster rolls, attendance records, and overtime records are to move to electronic formats with retention capability [6]. The final OSH rules add a declaration on provident fund and employee state insurance contributions to the annual return, which links your labour compliance to your social security compliance in a single filing [6].
Read that against the SMETA document rule of 12 consistent months, and the exposure is obvious. A factory that started issuing appointment letters in June 2026 has six months of a twelve-month window covered.
Two committees, two thresholds, and most factories have neither.
Section 4 of the Industrial Relations Code requires every industrial establishment employing 20 or more workers to constitute one or more Grievance Redressal Committees, with equal employer and worker representation, a maximum of ten members, women represented at least in proportion to their share of the workforce, and proceedings completed within 30 days of an application [10].
The POSH Act separately requires an Internal Committee at any workplace with 10 or more workers [11]. It is a different committee with a different purpose, and one does not substitute for the other.
The auditor will ask workers whether they know how to raise a complaint and whether anyone ever has. The Manual instructs auditors to establish the level at which policies and procedures are known, understood, and perceived as effective by the workforce [1]. A grievance committee that exists on a notice board and produces no records fails the monitoring element of the MSA before it fails anything else.
A caution on state rules. Labour is a concurrent subject. The central rules notified on 8 May 2026 apply directly where the central government is the appropriate government. For most factories, the operative position depends on the rules notified by their state, and states remain at different stages [12]. Verify your state’s position before you rely on a central figure.
What to Do in the Six Weeks Before the Audit
If the request has landed and the date is somewhere in the next month and a half, the work divides cleanly.
Confirm the scope. Two pillars or four. Ask the buyer directly.
Register on Sedex and complete the SAQ honestly. An SAQ that overstates the position tells the auditor exactly where to sample.
Pull twelve months of records and read them yourself. Payroll, attendance, overtime, worker files, contractor registers. Compare your peak month against your slowest month, because the auditor will. Where a month is missing, decide now what the legitimate explanation is, because you will be asked.
Find the undocumented procedures. Every practice that works because a particular person has always done it that way is capped at Fundamental Improvements Required under the MSA [1]. Write them down. This is the cheapest grade improvement available to you.
Check the two committees. Grievance Redressal Committee at 20 workers. POSH Internal Committee at 10. Constituted, minuted, and known to the workforce.
Do not coach anyone. Train workers on their rights, which is a legitimate and expected thing to do, and let them answer truthfully. Coaching is an integrity issue and it is treated as one [1].
Walk the site as the auditor will. They will lead the route, they will not be steered, and they will see the areas you would rather they did not.
A pre-audit gap check six weeks out is a fraction of the cost of a failed audit, a systemic finding on the platform, an on-site follow-up, and a buyer who pauses orders while it is resolved. The report your customer reads lasts 24 months [4].
Frequently Asked Questions About SMETA Audits
Is SMETA a certification?
No. SMETA produces an Audit Report and a Corrective Action Plan Report. There is no certificate, and there is no pass or fail. Auditors are instructed to explain this to site management, because sites that believe they are being graded tend to withhold information [1]. SA8000, run by Social Accountability International, is an actual certification and is a different exercise. If your buyer has asked for a certificate, clarify which scheme they mean before you book anything.
Who pays for a SMETA audit?
Any party with a legitimate interest in the site’s performance may commission and pay for the audit, including the buying company, the supplier, or the site itself [1]. In practice the buyer requests it and the supplier pays, but this is a commercial matter and not a rule of the methodology. Costs vary by site size, worker numbers, and scope, and are quoted at the booking stage.
Do we need a Sedex membership before the audit?
Yes. Sedex permits an approved audit company to conduct a SMETA audit, whether a full audit or a follow-up, only where the business is a registered Sedex member with an active account. The report cannot be uploaded to the platform otherwise [2].
How long does a SMETA audit take on site?
It depends on your headcount. A two-pillar audit at a site with 5 to 100 workers is one auditor day. From 101 to 500 workers it is two days. From 501 to 1,000 it is three days. A four-pillar audit adds half an auditor day. These figures exclude preparation, travel, and report writing [1].
How many workers will be interviewed?
For a two-pillar audit, 10 workers at a site of up to 100, 26 workers at a site of 101 to 500, and 42 workers at a site of 501 to 1,000. Individual interviews run a minimum of 15 minutes and group interviews a minimum of 30 minutes, with no more than five workers in a group [1]. The auditor selects the workers, not management, and selection happens as late as possible [1].
How many months of records must we produce?
Twelve. All documentation must be available on the day, including payroll and working hours records. Where records for the previous 12 months are not available, the site must explain why, and an absence without legitimate explanation is recorded as a non-compliance. The auditor samples at least three months from that twelve-month set, always including the most recent month, a peak month, and a low season or random month [1].
What is the difference between a non-compliance and a non-conformance?
A non-compliance means the site does not meet local, national, or international law. A non-conformance means the site meets the law but does not meet the ETI Base Code. The auditor raises a finding wherever either is unmet, so that the standard affording the higher protection to workers applies [1].
Can we be fully compliant with Indian law and still receive findings?
Yes, and this is the most common source of confusion. The clearest example is working hours. Indian law permits up to 144 hours of overtime in a quarter under the central rules notified on 8 May 2026 [6]. The ETI Base Code caps total hours worked in any seven-day period at 60, including overtime [3]. A distribution of overtime that is lawful in India can breach the Base Code in a particular week, and the auditor will record a non-conformance [1].
Does the ETI Base Code overtime premium of 125 percent apply to us?
The Base Code recommends a premium of not less than 125 percent of the regular rate [3]. The OSH Code requires overtime at twice the ordinary rate of wages [7]. Where the law and the Base Code address the same subject, the provision affording the greater protection applies [3]. Indian law is stricter here, so Indian law governs. Keep the payroll evidence available to demonstrate it.
What is the Management Systems Assessment, and why does it matter to a small factory?
The MSA grades four elements for each Base Code area: policies and procedures, resources, communication and training, and monitoring. The grades are Not Addressed, Fundamental Improvements Required, Some Improvements Recommended, and Robust Management System [1]. It matters to smaller factories because SMETA does not impose a specific management system model and does not expect a formal system in the short term. It expects processes that are fit for purpose given the size and type of the site [1]. What it does not accept is a procedure that exists only in practice. An undocumented procedure that can be corroborated by other evidence caps at Fundamental Improvements Required. One that cannot be corroborated is graded Not Addressed [1].
What is a Collaborative Action Required finding?
It is a type of non-conformance introduced in SMETA 7.0, raised where the site does not meet the Base Code but the ability to close the gap sits partly outside the supplier’s control. Living wages are the standard example. CAR findings have no mandated closure time. The supplier can publish an action plan on the platform, which changes the status from open to in progress, and the expectation is that the buyer and supplier address it jointly [1].
Can the auditor help us fix what they find?
No. The Auditor Manual prohibits the auditor from selling consultancy services during the audit and from acting in a consultative role in either defining or closing corrective actions. They may share general best practice from their experience but may not prescribe your specific corrective actions [1].
What happens if we do not let the auditor into an area?
Denied access is categorised as full or partial. Full access denied means the audit is published as incomplete and a non-conformance is raised against Workplace Requirement 0.A, which requires the site to allow the auditor to conduct and complete the audit without obstruction. Partial access denied means the auditor continues, raises a non-conformance against 0.A, and raises additional findings in any Base Code area where the lack of access means compliance cannot be assured [1]. A narrow exception exists for genuinely confidential production, agreed with Sedex in advance and documented.
Are announced audits still available?
Yes, but the platform now defaults to semi-announced, and anyone booking an announced audit must record a reason for the decision. Sedex made this change following a member consultation in which it decided against mandating semi-announced audits outright, while moving customers in that direction [4]. A semi-announced audit falls within a window of at least three weeks, and the site is not told which day [1].
How long is a SMETA audit valid?
Sedex no longer accepts a SMETA audit as a sound assessment of current workplace conditions after 24 months. The recommended cadence is annual for high risk sites, every two years for medium risk, and at the buyer’s discretion for low risk sites [4]. Individual buyers may set stricter requirements.
What are the contract labour thresholds we need to worry about?
Under the OSH Code, the contract labour provisions apply where 50 or more contract workers are engaged, and a contractor supplying fewer than 50 workers does not require a licence. This raised the earlier threshold of 20 [5][7]. The principal employer bears primary liability for the wages and welfare of contract workers, and must pay the wages directly where the contractor fails to do so [7]. A licensing exemption does not remove your obligation to hold wage and attendance records for contract workers, and the auditor’s file sample is required to include agency and third-party workers [1].
Which committees does an Indian factory need in place before a SMETA audit?
At least two. Section 4 of the Industrial Relations Code requires a Grievance Redressal Committee at any industrial establishment employing 20 or more workers, with equal employer and worker representation, a maximum of ten members, adequate representation of women workers, and proceedings completed within 30 days of an application [10]. The POSH Act separately requires an Internal Committee at any workplace with 10 or more workers [11]. These are distinct committees and one does not satisfy the other.
Do the central rules notified in May 2026 apply to our factory?
The central rules apply directly to establishments for which the central government is the appropriate government. Labour is a concurrent subject, and for most state-level factories the operative rules are those notified by the state. States are at different stages of notification [12]. Confirm the position in your state before applying a central figure to your own compliance calendar.
We were audited under SMETA 6.1. Do we need a new audit immediately?
An audit conducted under an earlier version remains as it stands. Any new audit will be conducted under SMETA 7.0, which replaced 6.1 from September 2024 [1]. The practical difference is the Management Systems Assessment. A site that performed well under 6.1 on operational compliance may grade poorly on the MSA if its procedures were never documented.
Talk to SVEGA Before the Auditor Arrives
SVEGA runs pre-audit gap checks for manufacturers and exporters preparing for buyer social audits. The work covers the twelve-month record trail, the contract labour documentation, the committee constitutions, and the management system documentation that the MSA now grades.
Six weeks is enough time to fix a gap. It is not enough time to fix a systemic finding after it has been published to your buyer.
Book a call at svegaconsulting.com.
References
[1] Sedex, Sedex Members Ethical Trade Audit (SMETA) Auditor Manual, Version 1.0, June 2024 (SMETA 7.0 methodology). Available at: https://www.vwa.co.uk/ethical-audits/ethical-policies/smeta-resources/Sedex-Auditor-Manual-SMETA-7.0-June-2024.pdf
[2] Sedex, “SMETA Audit: The Global Standard for Social Audits.” Available at: https://www.sedex.com/solutions/smeta-audit/
[3] Ethical Trading Initiative, The ETI Base Code. Available at: https://www.ethicaltrade.org/eti-base-code
[4] Sedex, “Updates to SMETA Guidance Following External Consultation: Summary Report.” Available at: https://www.sedex.com/knowledge-hub/news/updates-to-smeta-guidance-external-consultation-summary-report/
[5] The Occupational Safety, Health and Working Conditions Code, 2020 (Act No. 37 of 2020), brought into force 21 November 2025 vide Notification S.O. 5321(E). Available at: https://www.indiacode.nic.in/bitstream/123456789/22041/1/a2020-37.pdf
[6] JSA, “Key Considerations of the Notified Central Rules under the Labour Codes,” May 2026, on the Occupational Safety, Health and Working Conditions (Central) Rules, 2026 notified 8 May 2026. Available at: https://www.jsalaw.com/corporate/key-considerations-of-the-notified-central-rules-under-the-labour-codes/
[7] Press Information Bureau, Government of India, “Occupational Safety, Health and Working Conditions (OSH) Code, 2020,” factsheet, November 2025. Available at: https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251122702801.pdf
[8] Ethical Trading Initiative, “Base Code Clause 6: Working Hours Are Not Excessive,” guidance. Available at: https://www.ethicaltrade.org/eti-base-code/6-working-hours-are-not-excessive
[9] Centre for Economic Data and Analysis (CEDA), Ashoka University, “The Contractualisation of Workforce in India’s Factories Continues,” November 2024, drawing on Annual Survey of Industries data released by the Ministry of Statistics and Programme Implementation.
[10] The Industrial Relations Code, 2020 (Act No. 35 of 2020), Section 4. Available at: https://prsindia.org/files/bills_acts/acts_parliament/2020/Industrial%20Relations%20Code,%202020.pdf
[11] Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013, Section 4. Government of India.
[12] Legal500, “The Four Labour Codes and Their Rules: A Complete Guide for Karnataka’s Manufacturing Sector,” May 2026. Available at: https://www.legal500.com/developments/thought-leadership/the-four-labour-codes-and-their-rules-a-complete-guide-for-karnatakas-manufacturing-sector-2/