Social Compliance Is a Risk Management Problem
Brands have gotten good at finding problems in their supply chains. An audit turns up a violation, or a questionnaire flags a gap, and someone has to act on it.
The corrective action goes out as an email and lands in a spreadsheet which is updated whenever someone remembers to. Weeks later, nobody can say for sure whether the factory changed anything.
Retraced reads an audit in seconds, no matter the standard or layout, and turns each finding into a corrective action your supplier can act on right away. Once it's resolved, your risk score updates on its own. You always know where you stand, and you can prove it when someone asks.
What Changes With Retraced
| Without Retraced | With Retraced | |
|---|---|---|
| Per audit | Hours of reading a PDF and typing findings into a spreadsheet by hand. | Findings pulled out in seconds with AI, whatever standard your auditors work to, including SMETA, BSCI, WRAP and ERSA. |
| Per finding | An email thread and a tracker somebody has to remember to update. | An owner, a due date, a closure record, and an update to the risk score. |
| Per document request | You request an audit report the supplier already sent to other brands. | It's shared to the supplier's profile, so you can reuse the data without sending a request. |
| Per tier | A serious compliance program at tier one and very little below it. | Audits and assessments that tier-two factories already hold, brought into your view. |
How You Go From a Risk Flag to a Closed Finding
This is the path a single finding travels, from the moment something looks wrong to the day you can show what changed.

1. Detect
Every supplier you've mapped gets scored against country and sector risk data, and the score moves when that data changes. No survey to commission and nothing to wait for.

2.Prioritize
The priority score weighs how likely a risk is and how severe it would be. You choose the formula, so the ranking can follow your policy and not our defaults.

3.Engage
You collect what you need from the supplier, from questionnaires to Code of Conduct sign-off and audit documents. You can reach indirect suppliers, not only the ones you buy from.

4. Remediate and Prove
Corrective and preventive actions (CAPA) with an owner and a date, worked with the supplier inside the system, with audit-ready documentation of what changed.
It runs as a loop. When a finding closes, it feeds back into the supplier's risk score under the rules you've set, so remediation updates your risk picture instead of dead-ending.
From Audit Report to Corrective Action
Audit management and CAPA in one system
Upload an audit report and the AI pulls out the findings, whatever standard your auditors work to, including SMETA, BSCI, WRAP and ERSA. Each finding comes back with a suggested corrective action attached.
From there it's a CAPA. You set the owner, the deadline and what counts as closed. The AI drafts, but you decide.
Your supplier sees the same list. They can start on a finding without waiting for an email that explains what you want, and they log what they changed as they go. Auditors upload their reports themselves, so nobody is forwarding PDFs between three inboxes.
Tap Into the Retraced Ecosystem
Two exlusive partnerships bring verified findings directly into the Retraced platform without your team having to download or manually process a single PDF.
SLCP
Retraced is an official Passive Accredited Host for SLCP. A supplier picks Retraced in the SLCP Gateway, enters their Facility ID, and their verified assessment flows in.
You see the assessment as data rather than a PDF. Findings arrive sorted into inaccuracies and legal flags, mapped against OECD guidance and national law, and the AI suggests a corrective action for each flag straight into your CAPA module. Over 300 fields in the supplier profile fill themselves from verified data.
For the supplier it's one assessment, shared once, reused for every brand that asks. That's SLCP's own point, and 17,000 registered facilities plus more than 100 brands accepting the data means it's already in your supply chain whether you use it or not.
amfori BSCI
If you're an amfori member, your BSCI audit data can flow straight into Retraced through amfori's API. No downloading, re-typing or waiting for someone to circulate the report.
The full BSCI dataset comes through: ratings, findings per performance area, the individual questions and answers, zero-tolerance cases, site and business partner data. A finding can trigger a corrective action the day the audit is finalized, and your risk scores run on current data.
It costs nothing extra. It's included in your amfori membership and in your Retraced subscription, and activating it takes one data-sharing agreement between you, amfori and us. Your suppliers do nothing differently.
Eight Capabilities in One System of Record
Supplier Management
Central supplier master data, perpetually maintained in one place.
Questionnaires
Supplier data collection and validation, with answers reusable across requests.
Document Management
Audits, certificates, policies and supporting proofs in one place.
Supply Chain Mapping
Supplier and facility visibility beyond the first tier.
Entity Screening (add-on)
Screening of suppliers and connected entities against risk sources.
Risk Management
Ongoing scoring and monitoring, with every closure feeding back in.
Audit Management
Collection of audit documents and AI-based interpretation of findings.
CAPA Management
Corrective and preventive actions, remediation tracking and closure of findings.
Laws and Regulations at Play
What the EU Forced Labour Regulation Asks of You
The Forced Labour Regulation entered force in December 2024 and applies from 14 December 2027. It covers every product sold in the EU and every company that sells one. No size threshold, no sectoral exemption, no lighter version for smaller businesses.
There's no annual report and no filing deadline. Enforcement runs through investigation instead, and an investigation can begin with information that anyone submits.
The authority has to establish the violation, so you're not being asked to prove your innocence. You're being asked for your evidence. Once a case opens you have 30 to 60 working days to submit what's requested. Six weeks is not enough time to reconstruct three years of corrective actions. You hand over what you already have.

The Role of CSDDD After Omnibus
After the Omnibus revision, the Due Diligence Directive applies to EU companies above 5,000 employees and €1.5bn net turnover, and to non-EU companies above €1.5bn of EU turnover.
Member States transpose it by 26 July 2028 and it first applies on 26 July 2029. Most fashion brands sit outside those thresholds. Plenty of their retail customers don't, and the requirements arrive through contracts either way.
What You Did Next. A Brand’s Guide to Closing Audit Findings
A practical guide for the team that holds the audit reports and has to answer for them.
- What an investigation actually asks for, and how long you get to answer.
- Why corrective actions stop below tier one, and what to do about the tiers you can’t see.
- What changes when finding extraction stops being manual work.
- How to work a corrective action with a supplier rather than at them.

See an Audit Report Become a Closed Finding
Use this text to share information about your brand with your customers. Describe a product, share announcements, or welcome customers to your store.
Need help?
Frequently Asked Questions
CAPA stands for corrective and preventive action. The corrective action fixes what an audit found at a specific factory. The preventive action changes the process so it doesn't come back, which usually means the way something is scheduled, paid or trained rather than the single instance. In supply chain compliance, a CAPA is the record that connects a finding to an owner, a deadline and proof that something changed. Without one, an audit is a description of a factory on one day.
Tier 1 is the factory that ships to you, usually cut and sew. Tier 2 is where fabric is made, dyed and finished, which is also where most of the environmental impact sits. Tier 3 is spinning and yarn. Managing social audits at those tiers means the same work as at tier one, from finding the sites to collecting audits and closing findings, except you normally have no contract with the factory and no order volume to give you leverage. That's why most programs stop at tier one.
Retraced works those tiers three ways. You map what you know and invite those suppliers directly. A factory with an SLCP assessment can share it through the Gateway and it arrives in Retraced as data. And where a supplier has already shared audits or certificates to its profile for another brand, you can see them without sending a request.
Most compliance teams start with country and sector data, which says where a factory sits before anyone has visited it. Then they add what they know about the supplier itself, from audit findings to questionnaire answers and certificates. Those combine into a likelihood and a severity. In Retraced you pick the formula, so the ranking follows your own policy. The score then moves on its own when the underlying data refreshes or when a rule has been triggered closes.
You need a record per finding showing what was wrong, what was done, when it was done and who did it. The evidence has to be dated after the work, so a photo, a payroll record, a training log or a follow-up inspection. In Retraced the evidence sits on the corrective action itself, and the supplier who did the work updates it, with a timestamped history running from the original audit finding through to closure. That matters because an investigation gives you 30 to 60 working days. Assembling this after the request arrives isn't realistic.
Retraced reads audit reports from the standards most brands already run, including SMETA, amfori BSCI, WRAP and ERSA, and others can be added. Findings come out as structured data, each with a suggested corrective action. Verified SLCP assessments arrive through our Passive Host integration rather than as a PDF, and amfori members can pull their BSCI data directly from amfori's platform. Certificates and policies sit in the same supplier record.
No, it sits on top. You keep commissioning your own audits, to your own standard, with the auditors and thresholds you already use. What changes is what happens once the report exists. Retraced reads it, turns findings into corrective actions, tracks them to closure and feeds the result back into the supplier's risk score. Nothing about your audit calendar has to change to start.
You upload the report to Retraced and Audit AI reads it, then drafts corrective or preventive actions for each finding. A person reviews that draft and sets the owner, the date and what counts as closed. The reading and retyping drops from a couple of hours per audit to seconds. Judgment stays with your team, and Retraced sends nothing to a supplier until someone at your company approves it.
Your suppliers don't pay Retraced anything. They answer a questionnaire once and reuse those answers in Retraced for the next brand that asks. They see the same findings you see, so they can start on a corrective action without waiting for an email explaining what you want, and they update it as the work gets done. If your BSCI data comes through the amfori integration, they carry on with amfori exactly as they do today.
It applies from 14 December 2027 to every company and every product sold in the EU, with no size threshold and no sectoral exemption. There's no report to file. Retraced keeps the evidence an investigation asks for, because the Forced Labour Regulation runs through investigation rather than filing. An authority opens an investigation, and anyone can submit the information that starts one. Once a case is open you have 30 to 60 working days to hand over what's requested, and the authority carries the burden of proving a violation.

