Overview
An on-site assessment is, understandably, the part of certification companies are most anxious about before their first one — and usually find far more straightforward than expected afterward. This guide walks through exactly what happens: who visits, what they look at, how long it takes, what a finding actually means, and what you receive when it's over.
What Level 3 Adds to Level 2
Level 2 verifies that your documents are genuine and current. Level 3 verifies that what the documents describe is actually true on the ground — through physical inspection, confidential interviews, and tracing declared figures back to their source. It is the protocol's practical extension of ISO 20400, drawing in elements of SA8000, ISO 14001/45001, and GRI, and it produces both the strongest certificate wording available — "Data verified through documentation review and independent on-site assessment" — and a detailed, independently useful improvement report.
Who Conducts the Visit
Visits are conducted by Standard ESG trained auditors or an approved partner auditor operating under a signed agreement binding them to the protocol. Auditors are required to complete documented training on the protocol itself, plus demonstrate familiarity with ISO 20400, SA8000 auditing practice, and health-and-safety inspection basics. Auditors must also declare any conflict of interest and may not assess a company where one exists — a structural safeguard, not just a stated policy.
The Eight Checklist Domains
A Level 3 visit works through eight default domains, each with items tagged by method (observation, interview, or record-review), severity, and the specific questionnaire indicators they cross-examine:
- Site & operations walkthrough — do your production or office areas match what you declared, and are environmental controls — emissions points, effluent handling, waste segregation — physically present and functioning?
- Health & safety inspection — emergency exits, fire equipment, PPE availability and actual use, machine guarding, chemical storage and labelling, first-aid provision.
- Labour records cross-check — a sample of personnel files checked against payroll and working-hours records, age-verification procedures, and contract terms.
- Worker interviews — confidential, off-management interviews with a sample of staff, covering freedom of association, discrimination, disciplinary practices, and whether workers actually know how to access the grievance mechanism you described at Level 1/2.
- Management interviews — governance oversight of ESG, how risk is actually managed day to day, and your history of corrective action on past issues.
- Document authenticity spot-checks — originals of key Level 2 documents sighted in person, with permits and certificates checked against issuing registers where possible.
- Supply-chain due diligence — how you actually select suppliers, whether your supplier code of conduct is in real use, and evidence of supplier assessments you've conducted.
- Data trail verification — declared figures for energy, water, waste, and accident rates traced back to the underlying meters, invoices, or logs.
How Long a Visit Takes
Minimum duration is guided by workforce size, ranging from half a day up to three auditor-days. A small operation with a handful of employees might complete the full checklist in an afternoon; a larger facility with hundreds of workers and multiple operational areas will need the full multi-day allocation to complete a representative sample across all eight domains.
The Visit Itself: Opening, Execution, Closing
Every visit follows the same three-part structure:
- Opening meeting. The auditor explains the scope, the domains they'll cover, and the logistics of the day(s) — who they'll need access to, which areas they'll walk, and roughly how the interviews will be scheduled.
- Execution. The auditor works through the checklist domains, mixing observation, document review, and interviews. Worker interviews happen away from management, specifically so staff can speak candidly.
- Closing meeting. The auditor shares preliminary findings with management before leaving. Nothing in the final report should come as a surprise at this stage — the closing meeting exists precisely so you hear the substance of what was found while the auditor is still on site and can answer immediate questions.
Finding Severities and What They Mean
Every discrepancy the auditor identifies is recorded as a finding with one of three severities:
- Minor — a gap worth noting and fixing but not blocking. Recorded in the report with a recommendation.
- Major — requires a corrective-action plan submitted within 30 days before a certificate can be issued. This doesn't mean the issue must be fully resolved in 30 days — it means you must have a credible, documented plan to resolve it.
- Critical — blocks certification outright. Critical findings are typically tied directly to the protocol's gates (for example, credible evidence of forced labour would be both a critical on-site finding and a certification gate under §4.3 of the protocol).
A visit that surfaces only minor findings is a genuinely good outcome and is common — Level 3 is designed to find the normal gap between paper and practice that exists in almost every organization, not to fail companies for imperfection.
When On-Site Findings Override Your Declared Data
If what the auditor observes contradicts what you declared at Level 1 or documented at Level 2, the on-site finding overrides the declared answer, and the corrected value feeds back into your score. The discrepancy itself is also logged as part of the assessment record, referencing the affected indicator. This is the mechanism that gives Level 3 its authority: it's not that on-site auditors are assumed more trustworthy in the abstract, it's that direct observation is structurally harder to game than a document, which is itself harder to game than a self-declared answer — each level closes a specific gap the level below it can't.
The Findings & Recommendations Report
Following the closing meeting, you receive a Findings & Recommendations Report alongside your certificate (once issued). It includes:
- Every finding recorded during the visit, with its severity and the indicators it relates to.
- Corrective-action recommendations for every major or critical finding, including the 30-day deadline where applicable.
- The auditor(s) of record and the visit date(s).
- The template version and checksum the assessment was scored against — the same version and hash printed on your certificate, so the two documents are always traceable to identical assessment content.
This report stays in your dashboard for the lifetime of your tenant relationship. Many organizations treat it as a genuine internal improvement roadmap, independent of its role in certification — it's often the most detailed, specific, externally-generated assessment of operational gaps a small or mid-size company will ever receive.
How to Prepare
- Have your Level 2 evidence originals accessible, not just the scans you uploaded — auditors sight originals during document authenticity spot-checks.
- Brief your team, honestly, that interviews will happen and that they're confidential and away from management — don't coach specific answers; the interview process is designed to detect coaching, and an honest, ordinary conversation serves you better than a rehearsed one.
- Make sure your operational records match your Level 2 evidence. If your declared working hours don't match your actual time-tracking system, that gap will surface during the labour-records cross-check regardless of what was uploaded at Level 2.
- Walk your own site with the checklist domains in mind beforehand — fire equipment servicing, PPE availability, and machine guarding are exactly the kind of items that are cheap to fix in advance and costly to explain after the fact.
- Make time genuinely available. Rushing an auditor through a compressed schedule tends to produce a worse outcome than allocating the full guided duration.
Frequently Asked Questions
Standard ESG (standardesg.org) trains every Level 3 auditor to the same protocol standard, whether internal staff or an approved partner. See The Three Certification Levels Explained for how Level 3 compares to Levels 1 and 2, and Verify a Certificate for how your finished certificate can be checked by anyone.
Cette page vous a-t-elle été utile ?