Social Audit

A social audit reviews an organization's effects on workers, communities, customers, and other stakeholders using defined criteria, evidence, and follow-up.

A social audit is a structured review of how an organization identifies, measures, manages, and reports its effects on workers, communities, customers, and other stakeholders. For investors, it is a source of evidence about social risks and operating practices, not proof that a company is ethical, compliant, financially attractive, or free from future harm.

Key Takeaways

  • “Social audit” is a broad label. The report should identify its scope, criteria, auditor, evidence, sampling method, period, findings, and remediation status.
  • A policy review alone is weak evidence. Stronger work tests records, interviews affected people, inspects operations, reconciles data, and follows up on corrective actions.
  • First-party, customer-led, and independent third-party reviews provide different levels of objectivity. Independence should be evaluated rather than assumed.
  • An audit can cover only selected sites or suppliers. Coverage by company count may differ materially from coverage by spending, revenue, workers, or risk.
  • Passing a minimum score does not establish that no adverse impact exists. Threshold design, undisclosed subcontracting, worker access, and short audit windows can hide problems.
  • ISO 26000 provides social-responsibility guidance, but it is not a certifiable management-system standard.
  • Investors should connect findings to cash flow, operating continuity, legal exposure, customer relationships, access to capital, and management credibility without assuming a mechanical effect on returns.

What a Social Audit Can Cover

The scope should follow the decision being made and the organization’s most significant impacts. Common areas include:

AreaExample evidence
Workforce practicesPayroll records, hours worked, injury logs, turnover, grievance records, worker interviews
Supply-chain laborSupplier contracts, site inspections, recruitment fees, subcontractor lists, corrective-action records
Human rightsImpact assessments, complaints, remedy, security practices, consultation with affected groups
Community effectsLand access, resettlement, local procurement, complaints, community investment, operating disruptions
Customer welfareProduct safety, accessibility, data handling, complaints, recalls, vulnerable-customer procedures
Inclusion and opportunityHiring, pay, promotion, retention, accessibility, and program-outcome data
Ethics and conductWhistleblowing, retaliation controls, investigations, disciplinary outcomes, third-party conduct

An environmental audit may overlap with community health or environmental-justice issues, but it has a different technical scope. A social audit should not claim comprehensive environmental assurance unless that work was actually performed.

ReviewMain questionImportant limitation
Social auditHow well are selected social impacts and controls identified, evidenced, and addressed?No single universal methodology or assurance level applies to every report.
Financial-statement auditAre the financial statements free from material misstatement under the applicable framework?It does not automatically assure every sustainability claim or social outcome.
Sustainability assuranceDoes specified sustainability information meet stated criteria at the reported assurance level?Assurance covers the identified subject matter, criteria, period, and scope only.
ESG ratingHow does a provider score selected ESG risks or characteristics using its methodology?Ratings can differ because scope, data, weights, and objectives differ.
Social-impact assessmentWhat effects may a project or activity have before or during implementation?Forecast effects and mitigation plans are not evidence that outcomes occurred.
Certification auditDoes an organization or site meet a particular certification scheme’s requirements?Certification quality depends on scheme governance, scope, surveillance, and enforcement.

Readers should avoid treating these labels as interchangeable. The engagement letter, criteria, and report language reveal what was actually tested.

How a Credible Social Audit Works

1. Define the User and Decision

The audit may support board oversight, supplier approval, lending, investment analysis, regulatory compliance, or public reporting. The intended decision determines which impacts, entities, and evidence are material.

2. Set the Boundary

Identify the legal entities, facilities, countries, suppliers, worker groups, products, and period covered. Explain exclusions and whether sites were selected randomly, by risk, by spending, or by management.

3. Choose Suitable Criteria

Criteria may come from law, contracts, collective agreements, company policies, sector standards, or recognized responsible-business frameworks. Vague criteria such as “good community relations” are difficult to test consistently.

4. Gather and Corroborate Evidence

Evidence can include documents, transaction records, observation, confidential interviews, grievance data, external databases, and third-party confirmations. A credible conclusion should not rely solely on management questionnaires.

5. Test Controls and Outcomes

The reviewer assesses whether controls exist, operate as described, and produce the intended result. Testing should examine exceptions and root causes, not only the percentage of checklist items marked complete.

6. Report Findings With Severity and Scope

Useful reports distinguish isolated exceptions from systemic failures and explain the population tested. They identify responsible owners, deadlines, escalation triggers, and any limitation on the work.

7. Verify Remediation

Closing a finding should require evidence that the cause was addressed. A management assertion that an action is complete is weaker than a retest showing the control now works and affected people received appropriate remedy.

Evidence Strength

EvidenceTypical strengthWhat to verify
Public policy or codeLow on its ownCoverage, accountability, implementation, and exceptions
Management questionnaireLow to moderateSupporting records and independent corroboration
Operational recordsModerateCompleteness, system controls, manipulation risk, and reconciliation
Site observationModerateVisit timing, site selection, hidden operations, and temporary staging
Confidential stakeholder interviewsModerate to highAccess, sample diversity, translation, retaliation risk, and consistency
Independent external confirmationHigh when relevantSource competence, independence, population covered, and date
Remediation retestHigh for the tested issueRoot cause, sustained operation, affected population, and recurrence

No single evidence type is decisive. Triangulating records, observations, and stakeholder testimony is usually more informative than increasing the volume of one weak source.

Worked Example: Supplier-Audit Coverage

An apparel company has 50 direct suppliers. During the year, it audits 10 suppliers representing 55% of procurement spending. Nine meet the program’s minimum score, so management reports a 90% pass rate among audited suppliers.

That headline needs context:

MeasureCalculationResult
Supplier-count coverage10 audited / 50 total20%
Spending coverageReported by the company55%
Pass rate in audited sample9 passing / 10 audited90%
Network-wide pass rateCannot be calculated from the sample aloneUnknown

Assume the failed supplier represents 18% of total procurement spending. Within the audited spending, its weight is approximately:

118% / 55% = 32.7% of audited spending

A 10% failure rate by supplier count therefore represents almost one-third of audited spending. The failed site has 12 corrective actions; eight are closed and independently retested by year-end:

1Verified remediation rate = 8 / 12 = 66.7%
2Open or unverified actions = 4 / 12 = 33.3%

An investor should ask why the 40 unaudited suppliers were omitted, whether high-risk indirect subcontractors were in scope, how the minimum score was set, and whether the four open actions affect production continuity or customer contracts. The audit provides useful evidence, but it does not support a claim that 90% of the full supplier network complies.

Frameworks That Can Inform the Work

The OECD Due Diligence Guidance for Responsible Business Conduct describes risk-based due diligence as an ongoing process that prioritizes significant impacts and engages business partners and stakeholders. A social audit can contribute evidence to that process, but a periodic site visit is not a substitute for continuous due diligence and remediation.

The GRI Standards help organizations report material impacts on the economy, environment, and people. A GRI-based disclosure can provide criteria or data points for review, but publication under a reporting framework does not by itself establish independent assurance.

ISO 26000 provides guidance on social responsibility, stakeholder engagement, and communicating performance. ISO explicitly states that the standard contains guidance rather than certifiable requirements. A claim of being “ISO 26000 certified” should therefore be treated as a warning sign.

How Investors Can Evaluate a Social Audit

  1. Purpose: What decision or claim is the audit intended to support?
  2. Boundary: Which entities, sites, suppliers, workers, and periods are included or excluded?
  3. Criteria: Are the requirements specific, relevant, current, and publicly identifiable?
  4. Auditor: Who performed the work, who paid them, and what conflicts or commercial dependencies exist?
  5. Assurance: Is this an internal review, agreed-upon procedure, limited assurance, reasonable assurance, or an unqualified use of the word “audit”?
  6. Sampling: How were locations and records selected, and what percentage of the risk population was covered?
  7. Stakeholder access: Were workers and communities interviewed safely and independently?
  8. Findings: Are severity, recurrence, root cause, and affected population disclosed?
  9. Remediation: Which actions were merely promised, completed, independently verified, or still overdue?
  10. Decision impact: Could the findings affect costs, production, licenses, contracts, financing, reputation, or management credibility?

Risks and Limitations

  • Snapshot risk: Conditions can change immediately after a visit.
  • Selection bias: Management may steer reviewers toward stronger sites or records.
  • Audit staging: Announced visits can produce temporary behavior that is not representative.
  • Hidden tiers: Direct suppliers may use unauthorized subcontractors or labor brokers outside the audit boundary.
  • Interview constraints: Workers may fear retaliation, misunderstand confidentiality, or face translation barriers.
  • Checklist bias: A high score can conceal one severe issue if all questions receive similar weight.
  • Conflict risk: Auditors paid by the audited organization may face commercial pressure.
  • Outcome gap: A control can exist on paper without improving conditions for affected people.
  • Comparability limits: Different providers, criteria, samples, and periods can make company-to-company comparisons unreliable.

Common Mistakes

  • Treating a social audit as a full financial audit or universal ESG assurance.
  • Reporting a sample pass rate as if it covered the entire organization or supply chain.
  • Equating ISO 26000 guidance with certifiable compliance.
  • Counting corrective actions as closed without independent evidence or retesting.
  • Focusing on policies and training hours while ignoring grievances and outcomes.
  • Assuming no reported finding means no adverse impact occurred.
  • Comparing scores from different methodologies without normalizing scope and severity.
  • Treating strong social practices as a guarantee of investment performance or low volatility.

Authoritative Sources

  • ESG: Environmental, social, and governance factors used in investment and risk analysis.
  • ESG Criteria: The rules and measures used to assess selected sustainability characteristics.
  • ESG Investing: Investment approaches that integrate or target specified ESG considerations.
  • Stewardship Code: Principles for how investors oversee assets and report stewardship activities and outcomes.
  • Corporate Governance: Structures and processes through which an organization is directed and controlled.

FAQs

Is a social audit legally required?

It depends on the jurisdiction, industry, contract, and subject matter. Some due-diligence, labor, procurement, or disclosure rules may require specific reviews or evidence, while other social audits are voluntary. Verify the rule applicable to the organization and reporting period.

Is a social audit the same as sustainability assurance?

No. Sustainability assurance evaluates specified information against stated criteria at a defined assurance level. “Social audit” is a broader label and may describe work ranging from an internal checklist to an independent, evidence-based review.

Does a passing social audit prove a supplier is compliant?

No. The conclusion is limited by the criteria, sample, site access, audit date, and evidence tested. Hidden subcontractors, changing conditions, or a weak scoring threshold can remain material risks.

Can a company be certified to ISO 26000?

No. ISO describes ISO 26000 as guidance, not a management-system standard with certifiable requirements. Claims of ISO 26000 certification misstate the standard’s intended use.

This article is educational and does not provide investment, legal, labor, compliance, assurance, or sustainability-reporting advice. Evaluate the actual audit scope and obtain qualified advice for a specific organization or obligation.

Browse Investing