Nobody likes the auditor.

I've noticed over the last few months, possibly years, a growing but very clear anti-audit sentiment. A quick search through my LinkedIn feed, conversations with colleagues and peers, confirms this suspicion.

I have always thought there is a particular thanklessness to the social compliance auditor's position. NGOs accuse them of providing cover for exploitative brands. Some factories treat them as an inconvenience to be managed and waited out. Brands commission their work and then hope the findings aren't too uncomfortable. And increasingly, legislators and journalists cite audit failures as evidence that the entire enterprise is a charade, with the US Congressional-Executive Commission on China famously describing corporate social audits as "another fig leaf."

The criticism is loud and sustained, and in parts it is fair. Audits have been gamed, weaponised, and sold as something they were never designed to be, and there are real, structural problems the profession has been too slow to confront.

I am comfortable acknowledging some of that, but what exactly is the alternative?

The Audit Was Never Meant to Be a Guarantee

After every supply chain disaster, whether a factory fire, a forced labour exposé, or a child labour scandal, the audit becomes one of the first exhibits for the prosecution. The facility was audited. The audit found nothing. Therefore audits are worthless.

It is a seductive argument. It is also a category error.

Audits were never designed to be a guarantee. They are a structured, evidence-based assessment of conditions at a specific facility, on a specific day, against a specific set of criteria. At their best, they function as an early warning system and a risk identification mechanism.

But the more fundamental point, and one the industry has been too reluctant to state plainly, is an audit deployed without prior risk identification and prioritisation is an audit likely to be looking in the wrong place.

The UN Guiding Principles on Business and Human Rights are clear on this. The UNGPs describe human rights due diligence as a continuous cycle: identify and assess actual and potential adverse impacts, integrate and act on the findings, track responses, and communicate externally. Audits are an evidence-gathering tool within that cycle, a powerful one, but they are not the cycle itself. When companies treat the audit as the starting point of due diligence rather than a structured response to prior risk assessment, they undermine both their programme and the audit's own value.

Critics attack audits for failing at a job they were never designed to do. A speed camera does not prevent every accident. A financial audit does not guarantee no fraud has occurred. These are tools within systems, and when systems fail, the tools carry blame that rightly belongs elsewhere.

In most of the cases that have generated the loudest criticism, audits were commissioned as a compliance destination rather than a starting point. Findings were not acted upon. How do you measure the impact of a corrective action plan gathering dust? That is a commissioning failure, a systems failure, and in many cases a failure of corporate will. It is not evidence that sending a trained, independent professional into a facility to speak to workers and examine records is a pointless exercise.

Audit-Washing Is Real, But That's Not the Audit's Fault

Audit-washing exists. I hate it as much as the next human-rights professional. Commissioning a compliance audit not to understand your supply chain but to insulate yourself from reputational damage is a genuine problem, and the industry still struggles to call it out.

But if a pharmaceutical company manipulates clinical trial data, we don't abolish medicine. When an accountancy firm signs off on fraudulent books, we don't conclude that financial auditing is pointless. We investigate, regulate, and reform. Social compliance auditing deserves the same treatment, not a bonfire.

The structural problems are well-documented. When supplier contracts include automatic termination clauses on the detection of a violation, the perverse incentive rewards concealment over transparency. Factories don't confess to violations when the penalty for honesty is losing the business. They coach workers, prepare parallel records, and wait for the auditor to leave.

The best auditor on the planet would struggle in these conditions. And even when these issues are highlighted, the methods of reporting are not ideal. Throw in the problems of audit fees, time pressure, and bloated report requirements, and you have the makings of a race to the bottom that will decimate audit quality.

None of this indicts the audit as a concept. It indicts the way audits have been commissioned, priced, and used. Above all, it indicts the way they have been disconnected from the risk intelligence that should be directing them.

The Regulatory Floor Is Rising, And It Isn't Coming Back Down

If anything were going to kill the social compliance audit, you might have expected it to be the last five years. We have had a global pandemic and a hostile geopolitical environment. NGOs have called vocally to abandon the model entirely, and political headwinds have emboldened industry lobbies to push back against mandatory sustainability legislation. And yet the regulatory context has never been more demanding.

The EU's Corporate Sustainability Due Diligence Directive, despite the delays and dilutions it has absorbed, represents a fundamental shift in what the law expects of large companies. The era of the voluntary code of conduct and the aspirational supplier questionnaire is drawing to a close. Companies are now legally required to identify, prevent, mitigate, and remediate actual and potential adverse human rights and environmental impacts across their value chains.

Notably, the CSDDD is structurally aligned with the UNGPs. Both frameworks require companies to know and show. It is not enough to demonstrate that you acted; you have to demonstrate that your actions were proportionate to identified risk. That is a critical point. Regulators are not simply asking whether you audited. They are asking whether you understood where your highest risks sat, whether you directed your scrutiny accordingly, and whether what you found translated into meaningful corrective action. An audit programme that cannot answer those questions, because it was never anchored in prior risk prioritisation, will not satisfy either framework.

The factories have not cleaned themselves up in the interval between one regulatory deadline and the next. Forced labour persists. Wage theft persists. Unsafe working conditions persist. What this moment does is reframe what audits are for: not a compliance destination, but a structured evidence-gathering mechanism within a broader due diligence programme. One that begins with honest risk identification, is directed by rigorous prioritisation, and does not end when the auditor leaves the building.

The Auditor in the Room

All of us at Aseri are optimistic about technology and what it does for risk mitigation and audit. Satellite imagery and real-time, AI-powered risk scoring. GPS worker-voice platforms and blockchain traceability - we can talk about it all day. But we also know that none of it replaces what happens when an experienced, well-trained auditor walks into a facility and gets to work.

You still need boots on the ground to feel the work environment, continually assessing worker movement, supervisor positions, unconsciously counting steps from the workfloor to the canteen, confidently knowing if that facemask filters vapours or particulates, and being able to take the unquantifiable behaviours and feelings of workers and distill that into measurable datapoints. These are not peripheral details. They are frequently the difference between a facility that passes and one that shouldn't.

A skilled auditor carries pattern recognition built across dozens of facilities, multiple sectors, and years of fieldwork. They know what a well-prepared facility looks like and how to distinguish genuine compliance from a well-rehearsed performance. They know which questions to ask twice, when to work in groups, and when to triangulate one-to-one.

That cannot be automated or aggregated. The human being in the room remains the most important instrument in the audit. Risk intelligence tells you where to send that person and what to look for when they arrive. It does not stand in for them.

A Better Path Forward

The social compliance audit has a future. But it will not look like the audit of the last two decades, and we don't think that's a bad thing.

The most important shift is less about how audits are conducted than about where they sit within a wider due diligence programme. The UNGPs offer the right architecture here. Before an audit is commissioned, a company should be able to answer a prior set of questions. Where in our value chain are human rights risks most severe? Which geographies, commodities, or supplier tiers carry the highest exposure? Which affected stakeholder groups are most vulnerable? The answers should be determining where audits are deployed, what they look for, and how their findings are weighted.

These are precisely the questions our risk intelligence exists to answer. Commodity risk scoring shows which materials in your chain carry the heaviest exposure. Conflict-affected and high-risk area (CAHRA) flags show which geographies demand closer scrutiny. Supply chain mapping shows which tiers and suppliers you can actually see, and which ones you can't. None of that replaces the auditor, but it helps the auditor know where to stand.

Due diligence cycle (UNGP)Risk intelligence's roleThe audit's role
Identify & prioritiseCommodity risk scoring, CAHRA flags and supply chain mapping surface the highest-risk materials, geographies and tiersHolstered until the intelligence names a target
InvestigateSets the target: where to send the auditor, and what to look for on arrivalBoots on the ground: worker interviews, records, and the conditions a score can't capture
Act & remediateWeighs each finding in context, so remediation effort lands where exposure is greatestSurfaces the findings that drive the corrective action plan
Track & communicateContinuously re-screens suppliers and keeps a regulator-ready chain from risk to finding to remediationReturns to verify remediation and re-audit as conditions change

Audits directed by genuine risk intelligence are more likely to find what matters. They go into facilities with better prior information, more targeted protocols, and clearer criteria for what a finding means in context. Audits deployed indiscriminately, sprayed across a supplier base as a defensive exercise, are more likely to generate paperwork than protection.

That means working with suppliers rather than simply scrutinising them, and building relationships grounded in transparency rather than the threat of termination. It takes a genuinely brave company to build supplier partnerships grounded in candour, but those that do build supply chains that are more resilient and more stable.

Translating audit findings into actionable strategy also requires genuine expertise, not just a report. Human rights due diligence, properly understood under the UNGP framework, is not a box-ticking exercise. It is a continuous cycle of identification, assessment, action, and review. The audit feeds that cycle. It does not complete it.

Technology, used intelligently, should amplify that process rather than replace it. The most valuable application of data and analytics in this space is not to substitute for field assessment but to direct it. This is exactly how we think about our own platform. It ensures audit resource lands where commodity risk is highest, where geographic indicators are most concerning, and where supplier-level signals warrant a closer look. The intelligence sets the target, but the auditor still has to take the shot.

On evidence management, the gap between what audits produce and what organisations can actually use remains one of the industry's most persistent failures. Findings buried in static PDF reports. Corrective action plans tracked in spreadsheets. Evidence scattered across email threads. None of this is fit for purpose in an environment where regulators are asking not just whether you audited, but whether you can demonstrate a clear chain from risk identification to finding to remediation. Structured workflows, centralised evidence management, and documentation configured to regulatory frameworks from the outset are increasingly the baseline, not the exception.

Showing Up

The workers at the end of a global supply chain are not well served by a debate that concludes audits are too flawed to bother with. They are served by honest, trained, independent professionals showing up and asking difficult questions, imperfectly and incompletely, but consistently.

But they are also not well served by audits that show up in the wrong place, looking for the wrong things, because no one did the prior work of understanding where the real risks lie.

The UNGPs give us the framework. The CSDDD is giving it legal teeth. The audit is not the framework. But within the right framework, directed by honest risk intelligence and followed by genuine action, it remains one of the most powerful tools the industry has.

Democracy is a flawed system. So is medicine. So is financial regulation. We do not abandon these things because they fail sometimes. We work to make them better, recognising that the alternative to an imperfect system is not a perfect one - It is usually no system at all. The workers of the world don't need a perfect audit. They need someone to show up in the right place, at the right time, with the right questions, and an industry that takes seriously what happens next.

Make every audit count

Direct your audit resource where commodity risk is highest and supplier-level signals warrant a closer look. See how Aseri turns risk intelligence into targeted, defensible assurance.