RBA Code of Conduct Certification: What It Actually Requires

The RBA Code of Conduct is the standard published by the Responsible Business Alliance (RBA), currently Version 8.0.1, and it's what most electronics, component and hardware suppliers are being audited against when a customer asks for "RBA certification" or a "VAP assessment." If you supply into electronics manufacturing or the data center hardware supply chain and a buyer has just asked you to prepare for one, this article breaks down what the Code actually requires, how the audit itself works, and where to focus your preparation first.
The RBA was founded in 2004 by a group of leading electronics companies to set a shared set of social, environmental and ethical standards across their supply chains. It has since extended well beyond electronics into automotive, toy manufacturing and other industries with complex, multi-tier supply chains, including the hardware and component suppliers behind data center infrastructure.
What is the RBA Code of Conduct, and is it really a "certification"?
The current version, 8.0.1, was released in November 2025 as a minor update to Version 8.0, which was published in January 2024. The Code references international norms including the Universal Declaration of Human Rights, ILO international labour standards, the OECD Guidelines for Multinational Enterprises, and relevant ISO and SA standards, and it's reviewed roughly every five years through an extensive multi-stakeholder consultation process.
Unlike some standards, RBA doesn't issue a formal certificate once a company passes. Compliance is verified through an on-site assessment, and what a buyer actually reviews afterward is the assessment report and its findings, not a certificate. "RBA certification" is still the term most buyers and suppliers use in practice, so this article uses it too, but it's worth knowing there's no certificate changing hands the way there is with a scheme like ISO or RJC.
The Code itself is organised into five sections: Labor, Health and Safety, Environment, Ethics, and Management Systems. Together they cover most of what a buyer's due diligence team is checking for when they ask a supplier to demonstrate responsible business practices.
What each section of the Code actually requires
A. Labor
This section prohibits forced labour in any form and restricts child labour, and it sets specific limits on working hours: a workweek should not exceed 60 hours including overtime except in emergency or unusual situations, and workers must be allowed at least one day off every seven days. It also covers fair wage payment and freedom of association.
B. Health and Safety
Suppliers need documented occupational health and safety systems, including identification and assessment of potential emergency situations, injury and illness prevention, industrial hygiene controls, machine safeguarding, and clear communication of health and safety information to workers.
C. Environment
This covers environmental permits and reporting, pollution prevention, hazardous substance management, waste and wastewater handling, air emissions, and resource use. It also requires participants to establish and report against an absolute corporate-wide greenhouse gas reduction goal, which is a heavier requirement than many suppliers expect going in.
D. Ethics
Ethics covers business integrity, a stated zero-tolerance policy on bribery, corruption and extortion, transparent disclosure, protection of intellectual property, fair competition, and protection for whistleblowers. It also requires participants to adopt a policy and exercise due diligence on the source and chain of custody of tantalum, tin, tungsten, gold and cobalt, consistent with OECD guidance on responsible mineral sourcing from conflict-affected and high-risk areas. This is the same due diligence expectation behind RBA's Responsible Minerals Assurance Process (RMAP), and it's worth planning for separately if any of these materials are present in what you supply.
→ See: RMAP Certification: A Guide for Tin, Tantalum, Tungsten and Gold Suppliers
E. Management Systems
This is the section that ties everything else together, and it's usually where preparation should start rather than end. It sets out 12 elements: company commitment, management accountability and responsibility, legal and customer requirements, risk assessment and risk management, improvement objectives, training, communication, worker and stakeholder engagement and access to remedy, audits and assessments, a corrective action process, documentation and records, and supplier responsibility, meaning a process to communicate the Code's requirements to your own suppliers and monitor their compliance in turn.
How the audit itself works
Most RBA audits are conducted through the Validated Assessment Program (VAP), the RBA's standard for Code of Conduct compliance verification. Assessments are carried out by independent, third-party auditors, not by RBA staff directly, drawn from a pool of approved firms operating in more than 40 countries. A typical on-site assessment runs one to five days depending on the size and risk profile of the facility, and combines document review, interviews with management and workers, and a walk-through of the site itself.
Findings are rated across three severity tiers rather than the simple major/minor split used by some other certification schemes: minor, major, and priority. Each tier carries its own expected timeframe for closing the finding through a corrective action plan, which needs to address both the immediate issue and the underlying system that allowed it to happen. Facilities that close out their findings can be recognised through the VAP Recognition Program, and RBA members can share completed assessment reports with each other through the Assessment Cooperation Program, which can reduce how often a supplier gets audited by different customers for the same thing.
Where to focus preparation first
Because Section E ties the other four sections together, most of the preparation work worth doing before an audit sits there. A few areas are worth checking specifically:
Working hours and overtime records. The 60-hour weekly cap and the one-day-off-in-seven requirement are checked against actual time records, not policy documents, so this is one of the first things worth reconciling if your payroll or timekeeping system doesn't already track it cleanly.
Responsible minerals due diligence. If tantalum, tin, tungsten, gold or cobalt appear anywhere in your bill of materials, having a documented due diligence process and chain-of-custody information ready in advance avoids this becoming a late-stage scramble.
Supplier flow-down. Element 12 expects you to communicate Code requirements to your own suppliers and monitor them, which is easy to overlook if your attention is entirely on your own facility.
Self-assessment and corrective action history. Element 9 expects periodic self-evaluation against the Code, and having a documented internal audit and corrective action trail in place shows an auditor the system is actually being used, not built for the visit.
See also: Why Data Center Suppliers Across Asia Are Being Asked for RBA Compliance
Getting a second set of eyes before the audit
If you're not sure where your current systems actually stand against the Code, it's often faster to have someone walk through your documentation and practices with you before the audit date is set, rather than finding out from the auditor. If that would be useful, get in touch and we can talk through where the gaps are likely to be for your specific operation.
Frequently asked questions
What is the RBA Code of Conduct?
It's the social, environmental and ethical standard published by the Responsible Business Alliance, currently Version 8.0.1. It covers five areas: Labor, Health and Safety, Environment, Ethics, and Management Systems, and is used across electronics, automotive and other complex supply chains, including data center hardware suppliers.
Does RBA issue an actual certificate?
No. Compliance is verified through an on-site VAP assessment, and buyers work from the assessment report and its findings rather than a certificate. "RBA certification" is the common shorthand, but there's no certificate issued the way there is with ISO or RJC.
How long does an RBA audit take?
A typical on-site VAP assessment runs one to five days, depending on the size and risk profile of the facility being audited.
What happens if an RBA audit finds nonconformities?
Findings are categorised as minor, major, or priority, and each category has its own expected timeframe for closing it through a corrective action plan that addresses both the immediate issue and the underlying cause.