A social audit reviews an organization's effects on workers, communities, customers, and other stakeholders using defined criteria, evidence, and follow-up.
A social audit is a structured review of how an organization identifies, measures, manages, and reports its effects on workers, communities, customers, and other stakeholders. For investors, it is a source of evidence about social risks and operating practices, not proof that a company is ethical, compliant, financially attractive, or free from future harm.
The scope should follow the decision being made and the organization’s most significant impacts. Common areas include:
| Area | Example evidence |
|---|---|
| Workforce practices | Payroll records, hours worked, injury logs, turnover, grievance records, worker interviews |
| Supply-chain labor | Supplier contracts, site inspections, recruitment fees, subcontractor lists, corrective-action records |
| Human rights | Impact assessments, complaints, remedy, security practices, consultation with affected groups |
| Community effects | Land access, resettlement, local procurement, complaints, community investment, operating disruptions |
| Customer welfare | Product safety, accessibility, data handling, complaints, recalls, vulnerable-customer procedures |
| Inclusion and opportunity | Hiring, pay, promotion, retention, accessibility, and program-outcome data |
| Ethics and conduct | Whistleblowing, retaliation controls, investigations, disciplinary outcomes, third-party conduct |
An environmental audit may overlap with community health or environmental-justice issues, but it has a different technical scope. A social audit should not claim comprehensive environmental assurance unless that work was actually performed.
| Review | Main question | Important limitation |
|---|---|---|
| Social audit | How well are selected social impacts and controls identified, evidenced, and addressed? | No single universal methodology or assurance level applies to every report. |
| Financial-statement audit | Are the financial statements free from material misstatement under the applicable framework? | It does not automatically assure every sustainability claim or social outcome. |
| Sustainability assurance | Does specified sustainability information meet stated criteria at the reported assurance level? | Assurance covers the identified subject matter, criteria, period, and scope only. |
| ESG rating | How does a provider score selected ESG risks or characteristics using its methodology? | Ratings can differ because scope, data, weights, and objectives differ. |
| Social-impact assessment | What effects may a project or activity have before or during implementation? | Forecast effects and mitigation plans are not evidence that outcomes occurred. |
| Certification audit | Does an organization or site meet a particular certification scheme’s requirements? | Certification quality depends on scheme governance, scope, surveillance, and enforcement. |
Readers should avoid treating these labels as interchangeable. The engagement letter, criteria, and report language reveal what was actually tested.
The audit may support board oversight, supplier approval, lending, investment analysis, regulatory compliance, or public reporting. The intended decision determines which impacts, entities, and evidence are material.
Identify the legal entities, facilities, countries, suppliers, worker groups, products, and period covered. Explain exclusions and whether sites were selected randomly, by risk, by spending, or by management.
Criteria may come from law, contracts, collective agreements, company policies, sector standards, or recognized responsible-business frameworks. Vague criteria such as “good community relations” are difficult to test consistently.
Evidence can include documents, transaction records, observation, confidential interviews, grievance data, external databases, and third-party confirmations. A credible conclusion should not rely solely on management questionnaires.
The reviewer assesses whether controls exist, operate as described, and produce the intended result. Testing should examine exceptions and root causes, not only the percentage of checklist items marked complete.
Useful reports distinguish isolated exceptions from systemic failures and explain the population tested. They identify responsible owners, deadlines, escalation triggers, and any limitation on the work.
Closing a finding should require evidence that the cause was addressed. A management assertion that an action is complete is weaker than a retest showing the control now works and affected people received appropriate remedy.
| Evidence | Typical strength | What to verify |
|---|---|---|
| Public policy or code | Low on its own | Coverage, accountability, implementation, and exceptions |
| Management questionnaire | Low to moderate | Supporting records and independent corroboration |
| Operational records | Moderate | Completeness, system controls, manipulation risk, and reconciliation |
| Site observation | Moderate | Visit timing, site selection, hidden operations, and temporary staging |
| Confidential stakeholder interviews | Moderate to high | Access, sample diversity, translation, retaliation risk, and consistency |
| Independent external confirmation | High when relevant | Source competence, independence, population covered, and date |
| Remediation retest | High for the tested issue | Root cause, sustained operation, affected population, and recurrence |
No single evidence type is decisive. Triangulating records, observations, and stakeholder testimony is usually more informative than increasing the volume of one weak source.
An apparel company has 50 direct suppliers. During the year, it audits 10 suppliers representing 55% of procurement spending. Nine meet the program’s minimum score, so management reports a 90% pass rate among audited suppliers.
That headline needs context:
| Measure | Calculation | Result |
|---|---|---|
| Supplier-count coverage | 10 audited / 50 total | 20% |
| Spending coverage | Reported by the company | 55% |
| Pass rate in audited sample | 9 passing / 10 audited | 90% |
| Network-wide pass rate | Cannot be calculated from the sample alone | Unknown |
Assume the failed supplier represents 18% of total procurement spending. Within the audited spending, its weight is approximately:
118% / 55% = 32.7% of audited spending
A 10% failure rate by supplier count therefore represents almost one-third of audited spending. The failed site has 12 corrective actions; eight are closed and independently retested by year-end:
1Verified remediation rate = 8 / 12 = 66.7%
2Open or unverified actions = 4 / 12 = 33.3%
An investor should ask why the 40 unaudited suppliers were omitted, whether high-risk indirect subcontractors were in scope, how the minimum score was set, and whether the four open actions affect production continuity or customer contracts. The audit provides useful evidence, but it does not support a claim that 90% of the full supplier network complies.
The OECD Due Diligence Guidance for Responsible Business Conduct describes risk-based due diligence as an ongoing process that prioritizes significant impacts and engages business partners and stakeholders. A social audit can contribute evidence to that process, but a periodic site visit is not a substitute for continuous due diligence and remediation.
The GRI Standards help organizations report material impacts on the economy, environment, and people. A GRI-based disclosure can provide criteria or data points for review, but publication under a reporting framework does not by itself establish independent assurance.
ISO 26000 provides guidance on social responsibility, stakeholder engagement, and communicating performance. ISO explicitly states that the standard contains guidance rather than certifiable requirements. A claim of being “ISO 26000 certified” should therefore be treated as a warning sign.
This article is educational and does not provide investment, legal, labor, compliance, assurance, or sustainability-reporting advice. Evaluate the actual audit scope and obtain qualified advice for a specific organization or obligation.