SanjinManufacturing

Certification Guide: BSCI vs. SEDEX/SMETA vs. ISO 9001

Certification Guide: BSCI vs. SEDEX/SMETA vs. ISO 9001

Last updated: August 2026

Almost every supplier profile on a sourcing platform lists a stack of certification acronyms — BSCI, SEDEX/SMETA, ISO 9001 — often with a badge or a PDF attached, and often without any explanation of what was actually checked to earn it. Buyers frequently assume these all mean roughly the same thing ("this factory is audited and trustworthy"), or worse, assume an ISO 9001 certificate covers labor conditions. It doesn't. Each of these certifications verifies a different, narrow thing, using a different process, and none of them are interchangeable. This guide breaks down what each one actually checks, how they differ from each other, and exactly how to confirm a certificate you're shown is genuine rather than decorative.

What a BSCI Audit Actually Checks

BSCI (Business Social Compliance Initiative, now operating under the amfori BSCI Code of Conduct) is a social-compliance audit — it exists to verify how a factory treats its workers, not the quality of what it produces. An amfori BSCI audit is conducted against a defined Code of Conduct covering areas such as: legally compliant employment relationships, freely chosen employment (no forced or bonded labor), no child labor, fair remuneration and legally compliant wages, decent working hours, workplace health and safety, freedom of association, no discrimination, and environmental protection basics. Auditors walk the factory floor, review payroll and time records, check worker dormitories where applicable, and interview workers — sometimes off-site or without management present — to cross-check what documents say against what workers actually report. The output isn't a pass/fail certificate in the traditional sense; it's a rated audit report (using a letter grading system, A through E) that a buyer should ask to see in full, not just a summary page.

What SEDEX/SMETA Covers, and How It Differs from BSCI

SEDEX (Supplier Ethical Data Exchange) is a membership platform where factories upload their own self-assessment and audit reports for buyers to access; SMETA (Sedex Members Ethical Trade Audit) is the actual audit methodology used to generate those reports. In scope, SMETA covers very similar ground to BSCI — labor standards, health and safety, environment, and business ethics, organized into "pillars" (a 2-pillar SMETA audit covers labor and health & safety; a 4-pillar audit adds environment and business ethics). The real differences between BSCI and SEDEX/SMETA are structural rather than about what's being checked: BSCI reports live inside amfori's own system and are typically visible only to the amfori member that commissioned the audit and buyers they choose to share it with, while SEDEX is built as a shared data platform — once a factory uploads a SMETA audit to its SEDEX profile, any buyer connected to that factory on the platform can pull the report directly, which is why many factories that export widely maintain both. Audit methodology, question sets, and the auditing bodies used can also differ slightly between the two, so a factory holding both isn't being redundant — it's often satisfying two different buyer bases that each standardize on one platform.

ISO 9001: A Quality Management System, Not a Labor Audit

This is the single most common misunderstanding buyers have about factory certifications, so it's worth stating plainly: ISO 9001 has nothing to do with labor conditions, wages, working hours, or worker welfare. ISO 9001 is a quality management system (QMS) standard — it certifies that a factory has documented, consistent processes for controlling quality: how incoming materials are inspected, how in-process quality checks are recorded, how non-conforming products are handled and traced, how corrective actions are documented when something goes wrong, and how those processes are reviewed and improved over time. An ISO 9001 auditor is checking whether the factory's quality system is consistently documented and followed — not whether workers are paid fairly, whether overtime is within legal limits, or whether the workplace is safe. A factory can hold a spotless ISO 9001 certificate and still have serious labor compliance problems, because the two certifications are answering completely different questions. If a supplier's sourcing profile lists only ISO 9001 and nothing else, that tells you something useful about their process discipline — it tells you nothing about social compliance, and it should not be read as reassurance on that front.

Side-by-Side Comparison: BSCI vs. SEDEX/SMETA vs. ISO 9001

 BSCI (amfori)SEDEX / SMETAISO 9001
What it verifiesSocial compliance / labor rightsSocial compliance / labor rights (similar scope to BSCI)Quality management process consistency
Typical scope checkedWages, working hours, forced/child labor, health & safety, freedom of associationLabor standards, health & safety; 4-pillar audits add environment & business ethicsDocument control, incoming/in-process inspection, non-conformance handling, corrective action, continuous improvement
Who conducts itIndependent third-party auditor accredited under the amfori BSCI systemIndependent third-party auditor accredited to conduct SMETA, uploaded to the Sedex platformAccredited ISO certification body (must itself be accredited by a recognized national/international accreditation board)
OutputRated audit report (A–E grading), not a simple pass/fail certificateDetailed audit report hosted on the factory's Sedex profile, shareable with connected buyersA certificate with a certificate/registration number, valid for a fixed period
Typical validity period12 months, then re-auditUsually 12–24 months depending on rating/risk level, then re-audit3 years, with required annual or biannual surveillance audits to remain valid
What a buyer should ask forThe full audit report (not just a summary), audit date, and the auditing firm's nameSedex platform access/connection so you can view the actual SMETA report, not a screenshotThe certificate number and the name of the accredited certification body, so both can be verified independently

The pattern to notice: BSCI and SEDEX/SMETA answer the same underlying question (is this factory treating its workers fairly and safely) through different platforms and methodologies, while ISO 9001 answers a completely unrelated question (does this factory run a consistent, documented quality process). A supplier can reasonably hold one, two, or all three — but holding one is never a substitute for another, and a buyer who only checks for "some certification" without knowing which one is looking at the wrong thing for their actual concern.

Self-Declared Certificates vs. Third-Party-Audited Reports

Not every "certificate" a supplier shows you was issued the same way. There's a meaningful difference between a self-declaration — a factory filling out its own compliance questionnaire, or printing a certificate template with its own name on it — and a genuine third-party audit, where an independent, accredited auditor physically visits the factory, reviews original records (not summaries prepared for the audit), interviews workers, and issues a report under their own name and accreditation. A self-assessment isn't worthless as a starting point, but it should never be treated as equivalent to an audited report, because the factory being assessed is also the one grading itself. The giveaway is usually in the document itself: a genuine third-party audit report names the auditing body, includes a specific audit date and site visited, and carries a reference or report number that the auditing body can confirm on request. A certificate with no auditor name, no reference number, and no way to verify it independently is not evidence of anything beyond the factory's own claim.

How to Verify a Supplier's Certificate Is Genuine

  1. Ask for the full audit report, not just the certificate PDF. A certificate or badge image is a summary at best; the underlying audit report contains the audit date, scope, findings, and any corrective actions raised — this is the document that actually tells you something.
  2. Check the certificate or audit reference number. Legitimate certifications carry a unique reference number tied to a specific audit event and, for ISO certificates, a registration number tied to the certification body's own records — ask the supplier for this number specifically if it isn't already visible on the document.
  3. Confirm which accredited body issued it. For ISO 9001, the certifying body should itself be accredited by a recognized national or international accreditation board — a certificate from an unaccredited or unfamiliar issuer is far less meaningful even if it looks official. For BSCI and SMETA, confirm the audit was conducted by a firm accredited to perform that specific audit type.
  4. Check the audit date and validity window. A BSCI or SMETA report from three years ago tells you little about current conditions; these audits are meant to be refreshed on a defined cycle, and a supplier who can't produce a recent one may be relying on an outdated result.
  5. Ask what corrective actions, if any, were raised — and whether they were closed. An audit with minor findings that were promptly corrected is normal and often a good sign of a transparent factory; a supplier who claims a "perfect" audit with zero findings at all, or who won't discuss findings, is worth a second look.
  6. None of this requires specialized expertise — it just requires asking for the underlying document instead of accepting a badge at face value, and being specific about which certification actually answers the question you're trying to answer (labor conditions, or quality process control).

    Frequently Asked Questions

    If a factory has ISO 9001, does that mean its labor practices are also fine?

    No. ISO 9001 certifies a quality management system — process consistency, documentation, and quality control — and says nothing about wages, working hours, or worker safety. If labor conditions matter to your sourcing decision, look for a BSCI or SEDEX/SMETA audit report specifically; ISO 9001 alone does not cover that ground.

    Should I ask for BSCI or SEDEX/SMETA — do I need both?

    Either one, done as a genuine third-party audit, covers similar ground on labor and social compliance. Which one a factory holds often depends on which platform their other buyers standardize on. You generally don't need both — what matters more is getting the full audit report for whichever one the factory holds, rather than requiring a specific acronym.

    How often should these certifications be renewed?

    BSCI and SMETA audits are typically valid for 12–24 months depending on the rating and risk level, after which a re-audit is expected. ISO 9001 certificates run on a 3-year cycle but require annual or biannual surveillance audits in between to stay valid — ask when the last surveillance audit took place, not just the original certification date.

    What if a supplier can only show a self-assessment, not a third-party audit?

    Treat it as a starting point, not a verification. A self-assessment is the factory grading itself and can be a reasonable first step for a new relationship, but it shouldn't carry the same weight as an independently audited report when you're making a sourcing decision that depends on verified labor conditions.

    Trying to make sense of a supplier's certification stack, or want to see our own audit documentation before placing an order? Get in touch and we'll walk you through exactly what's been verified and how.

More guides