Why Data Center Suppliers Across Asia Are Being Asked for RBA Compliance

If your company, based in Vietnam, India, Singapore or elsewhere in Asia, has recently been asked by a buyer to complete an RBA questionnaire or prepare for an RBA audit, the request almost certainly isn't coming from RBA itself. It's coming from your customer, because the customer is a member of the Responsible Business Alliance (RBA) and has adopted the RBA Code of Conduct as its own supplier code, which means the requirement flows down to you and, in turn, to your own suppliers. This article explains where that request actually comes from, why it's showing up now across electronics, component and data center hardware supply chains in the region, and what your buyer is really checking for.
Who is the RBA, and why does it show up in your supply chain?
The Responsible Business Alliance was founded in 2004 by a group of leading electronics companies to create a shared standard for social, environmental and ethical practices across their supply chains, rather than each company running its own separate audit programme. The RBA Code of Conduct that resulted is now used well beyond its original electronics base, including by companies supplying servers, networking equipment and other hardware into data centers.
Cisco is a public example of how this works in practice. Cisco is a founding member of the RBA, and states that it "adopted the Code as our own Supplier Code of Conduct" and that it "hold[s] our suppliers, and their suppliers, accountable to the Code." That second part is the key mechanism: a company doesn't need to be an RBA member itself to be asked for RBA compliance. It only needs to be a supplier, or a supplier's supplier, to one. RBA members themselves are typically global electronics, technology and hardware companies; the request then travels down through however many supplier tiers sit between that member and your factory or trading company.
Why the request is landing on your desk specifically
Vietnam, India and Singapore, alongside other manufacturing hubs in the region such as Cambodia, all host significant electronics manufacturing, component supply and, increasingly, data center hardware supply chains, which puts factories and trading companies in these markets squarely inside RBA member companies' supplier networks. As buyers extend responsible sourcing requirements further down their supply chains, and as more of them build out data center-related procurement, the RBA questionnaire or audit request is one of the more common ways that shows up for a supplier that has never dealt with RBA directly before.
This is different from certification schemes you seek out and apply for yourself. Nobody chooses to become RBA-compliant in the abstract. The requirement exists because a specific customer relationship requires it, which also means the request is unlikely to be a one-off. If one customer is asking, and that customer's own commitments to the RBA aren't changing, the expectation tends to continue for as long as the relationship does, and it can spread to other customer relationships in the same industry over time.
What your buyer is actually checking for
The RBA Code of Conduct covers five areas, and a buyer's due diligence team, or the third-party auditor they've engaged, is typically checking all five rather than picking one:
Labor. Prohibition of forced labour, restrictions on child labour, working hour limits (a 60-hour weekly cap including overtime, with at least one day off in seven), fair wages and freedom of association.
Health and Safety. Documented occupational health and safety systems, emergency preparedness, injury prevention and industrial hygiene.
Environment. Permits, pollution prevention, hazardous substance and waste management, and increasingly, a documented corporate-wide greenhouse gas reduction goal.
Ethics. Anti-bribery and anti-corruption controls, fair competition, whistleblower protection, and due diligence on the source and chain of custody of tantalum, tin, tungsten, gold and cobalt, where those materials are present in what you supply.
Management Systems. Whether there's an actual internal system, policy, ownership, training, self-audits, corrective action process, documentation, and requirements passed down to your own suppliers, holding the other four areas together.
→ See: RBA Code of Conduct Certification: What It Actually Requires
How this is usually verified
Most RBA compliance is verified through the RBA's own Validated Assessment Program (VAP), an on-site assessment carried out by an independent third-party auditor rather than by the buyer or the RBA directly. A typical on-site assessment takes one to five days and combines document review, staff interviews and a walk-through of the facility. Because RBA members can share completed VAP reports with each other through the RBA's Assessment Cooperation Program, a single well-prepared assessment can sometimes satisfy more than one customer's requirement, rather than each buyer running a separate audit.
What to do when the request first arrives
The most useful first step is establishing which of the five areas above your systems already cover reasonably well, and which ones exist mainly as informal practice rather than documented process. Working hour records, a responsible minerals due diligence process if relevant materials are in your supply chain, and whether requirements are being communicated to your own suppliers tend to be the areas that catch companies off guard, simply because they sit slightly outside where most compliance attention normally goes.
Not sure where to start?
If an RBA request has just landed and you're trying to work out how much preparation is actually needed before your next audit, it's usually faster to talk it through than to guess. Reach out and we can help you work out where your current systems stand and what's worth prioritising first.
Frequently asked questions
Why is my buyer asking me to comply with the RBA Code of Conduct?
Because your buyer is a member of the Responsible Business Alliance, or supplies a company that is, and has adopted the RBA Code of Conduct as its own supplier code. RBA members are expected to hold their suppliers, and their suppliers' own suppliers, accountable to the Code, which is how the requirement reaches companies that have never worked with RBA directly.
Do I need to become an RBA member myself?
No. Suppliers are not required to join the RBA to comply with the Code. The requirement comes through your customer relationship, not through RBA membership.
Is this a one-time request or an ongoing expectation?
It's generally ongoing for as long as the customer relationship continues and that customer's own RBA commitments remain in place, and the same expectation can extend to other customer relationships in the same industry over time.
Which industries in Asia are most likely to see RBA requests?
Electronics manufacturing, component supply, and increasingly data center hardware supply chains, particularly in manufacturing hubs like Vietnam, India, Singapore and Cambodia, all of which sit inside the supplier networks of RBA member companies.