CVS Social and Security Factory Audit Program Guide Version 4
- 格式:pdf
- 大小:571.30 KB
- 文档页数:21
CVSS评分代码CVSS(Common Vulnerability Scoring System,通用漏洞评分系统)是一种用于评估计算机系统和网络设备安全漏洞严重性的标准化方法。
CVSS评分代码是根据CVSS标准设计的一套规则和算法,用于计算漏洞的基础评分和向量。
1. 什么是CVSS?CVSS是一种公认的、开放的、行业标准的漏洞评估方法,旨在提供一个统一的评估框架,使组织能够比较和优先处理不同漏洞。
它包含三个主要部分:基本指标、环境指标和基础分数。
1.1 基本指标基本指标包括7个独立的度量,每个度量都与漏洞相关的某个方面有关:•攻击复杂性(Attack Complexity):描述攻击者利用该漏洞所需的条件和资源。
•攻击向量(Attack Vector):描述攻击者访问受影响组件所需的路径。
•认证要求(Authentication):描述攻击者访问受影响组件时是否需要身份验证。
•机密性损失(Confidentiality Impact):描述成功利用该漏洞对机密信息造成的影响。
•完整性损失(Integrity Impact):描述成功利用该漏洞对系统完整性造成的影响。
•可用性损失(Availability Impact):描述成功利用该漏洞对系统可用性造成的影响。
•攻击向量复杂性(Privileges Required):描述攻击者在成功利用该漏洞之前需要具备的特权级别。
1.2 环境指标环境指标是基于组织特定环境的评估参数,包括3个度量:•机密性要求(Confidentiality Requirement):描述对机密信息的保护需求程度。
•完整性要求(Integrity Requirement):描述对系统完整性的保护需求程度。
•可用性要求(Availability Requirement):描述对系统可用性的保护需求程度。
1.3 基础分数基础分数是通过将基本指标和环境指标结合起来计算得出的一个值,表示漏洞严重程度。
社会责任Social responsibility factory audit(Social compliance audit),官方称为社会责任审核、社会责任稽核、社会责任工厂评估等,即客户对供应商的劳工权益,工作条件以及环境保护三方面的情况进行审核。
社会责任审核,不同的客户或者项目会有不同的叫法。
按类型可以分为第二方审核和第三方审核,第二方即由客户自己进行审核,客户制定有自己的社会责任审核标准,安排内部审核员按照该标准进行审核;第三方审核即由客户委托的第三方机构如ITS, SGS, BV等公证行进行的审核,他们依据客户自己的标准或者客户指定的公认标准进行审核;按审核标准分可以分为企业社会责任标准认证和客户标准审核。
企业社会责任标准认证的标准,指的是通用性的标准,适用于某个行业或者某个地区,被多数客户而非某个特定客户所认可。
常见的主要有SA8000(全球各行业)、ICTI(玩具行业)、EICC(电子行业)、美国的WRAP(服装鞋帽等行业)、欧洲大陆地区的BSCI(所有行业)、法国的ICS(零售行业)、英国的ETI/SEDEX/SMETA(所有行业)等。
社会责任标准认证(SA8000)是指企业社会责任体系制定方授权一些中立的第三方机构对申请通过该种标准的企业是否能达到所规定的标准进行审查的活动,通过后申请企业会获得资格证书。
实际上,真正客户要求或者企业获得的SA8000认证证书并不多,通常都是指的是依据SA8000标准进行的一般性的社会责任审核。
客户审核标准是指客户自己制定的社会责任标准。
社会责任审核标准,不同的客户或者项目会有不同的叫法,比如常见的有叫COC( Code of Conduct, 行为守则),CSR(Corporate Social Responsibility, 企业社会责任),ES(Ethical Standard, 道德标准,沃尔玛的社会责任审核标准),ILS(International Labor Standard, 国际劳工标准,迪士尼采用的社会责任审核标准),Social Compliance(社会责任合规),WCA(Working Condition Assessment, 工作条件评估,不少国外客户认可的一种社会责任标准),COP (Code of Practice, 操作准则,next的社会责任标准)等。
微软验厂SEA社会责任审核劳工、商业道德、EHS部分注意细则Compliance with the Law一、总则G2.1Major If the facility has been subject to any labor regulatory actions where monetary penalties were assessed,or where formal corrective actions were mandated by the issuing govern ment agency,have the violations been corrected or are they on track for correction工厂是否对涉及劳动法的法律法规的行为,设立了处罚并进行评估,或由政府机构正式监督,违规行为是否被强制整改和追踪。
G2.2Major If the facility has been subject to any ethics regulatory actions where monetary penalties were assessed,or where formal corrective actions were mandated by the issuing government agency,have the violations been corrected or are they on track for correction?工厂是否对道德监管行为,设立了处罚并进行评估,或由政府机构正式监督,违规行为是否被强制整改和追踪。
G2.3Major If the facility has b een subject to any health & safety regulatory actions where monetary penalties assessed,or where formal corrective actions mandated by the issuing government agency,have the violations been corrected or are they on track for correction?工厂影响健康和安全的行为,设立了处罚并进行评估,或由政府机构正式监督,违规行为是否被强制整改和追踪。
cvs验厂评分标准CVS验厂评分标准。
CVS验厂评分标准是指供应链企业在进行验厂评估时所遵循的一套评分标准体系,通过对企业生产环境、劳工权益、环境保护、商业道德等方面的评估,来评定企业的社会责任表现和管理水平。
CVS验厂评分标准的建立旨在推动企业遵守相关法律法规,履行社会责任,提高生产环境和员工权益保障水平,促进可持续发展。
下面将从不同的角度对CVS验厂评分标准进行详细介绍。
首先,CVS验厂评分标准对企业生产环境的评估包括工厂设施、生产工艺、原料采购、产品质量等方面。
工厂设施的评估主要包括厂房结构、设施设备、安全防护措施等,而生产工艺和原料采购的评估则关注生产过程中的环境污染、资源消耗情况以及原料采购的合规性。
此外,产品质量也是评估的重点之一,包括产品的安全性、可追溯性、符合性等方面。
企业需要在这些方面做好管理和控制,以确保生产环境的安全和产品质量的稳定。
其次,CVS验厂评分标准对劳工权益的评估主要包括劳动合同、工资福利、工时管理、劳动安全等方面。
劳动合同的评估主要关注合同的签订情况、内容是否合法合规,工资福利的评估则包括工资水平、福利待遇、社会保险等方面,而工时管理和劳动安全则是评估劳工权益保障的重点内容。
企业需要合理制定劳动合同,保障员工的工资福利待遇,严格控制工时管理和加强劳动安全管理,以确保员工的合法权益得到保障。
此外,CVS验厂评分标准还对环境保护方面进行评估,包括环境管理、资源利用、废物处理、能源消耗等方面。
环境管理的评估主要关注企业是否建立了完善的环境管理体系和相关制度,资源利用和废物处理的评估则关注企业的资源节约利用和废物排放情况,能源消耗则是评估企业的能源利用效率和能源消耗情况。
企业需要加强环境管理,推行资源节约利用和废物减量化处理,提高能源利用效率,以减少对环境的影响。
最后,CVS验厂评分标准还对企业的商业道德进行评估,包括合规经营、诚信管理、公益慈善等方面。
合规经营的评估主要关注企业是否遵守相关法律法规,诚信管理则关注企业的商业道德和诚信经营,公益慈善则是评估企业的社会责任履行情况。
cvs验厂工时要求CVS验厂工时要求随着全球化的发展,越来越多的企业开始重视供应链管理和社会责任。
为了确保供应商符合一定的劳动标准和工时要求,许多企业会进行验厂。
CVS验厂是一种常见的验厂方式,它注重工时管理,下面将介绍CVS验厂工时要求的相关内容。
1. 工时管理制度在进行CVS验厂时,供应商应该建立完善的工时管理制度。
该制度应明确规定员工每天的工作时间和休息时间,以及加班和休假的安排。
工时管理制度应符合国家相关法律法规的要求,并且要与员工进行充分沟通,确保员工对工时管理制度有清晰的了解。
2. 每日工作时间CVS验厂要求供应商严格控制员工的每日工作时间。
一般来说,每日工作时间不得超过8小时,不得安排员工连续工作超过6天。
如果需要安排员工加班工作,应按照相关法律法规的要求支付加班工资,并确保员工的加班时间不超过规定限制。
3. 加班管理CVS验厂要求供应商建立健全的加班管理制度。
加班应该是自愿的,员工有权选择是否加班。
如果需要加班,供应商应提前通知员工,并与员工达成一致。
加班时间应按照相关法律法规的要求支付加班工资。
4. 休息时间CVS验厂要求供应商合理安排员工的休息时间。
员工每天应有至少1小时的连续休息时间,并且每周应有至少1天的休息日。
供应商应建立健全的休息时间记录制度,确保员工的休息权益得到保障。
5. 假期管理CVS验厂要求供应商合理安排员工的假期。
员工应享有带薪年假、病假和其他法定假期。
供应商应建立健全的假期管理制度,确保员工能够合理休假,并按照相关法律法规的要求支付相应的假期工资。
6. 工时记录和报表CVS验厂要求供应商建立健全的工时记录和报表制度。
供应商应记录员工的上班时间、休息时间、加班时间和假期等信息,并及时生成工时报表。
工时报表应包括各项工时指标的统计数据,以便于管理者进行工时管理和监控。
7. 培训和沟通CVS验厂要求供应商开展员工培训和沟通活动。
供应商应定期组织工时管理培训,向员工介绍工时管理制度和相关法律法规,提高员工的工时意识和知识水平。
美国现代企业内部审计过程(范例——审计流程经典教程)审计过程又被称作审计循环。
它是指二个审计项目从开始到结束的整个系统化过程。
在美国一些规模较大的企业中,内部审计部门通常是按照董事会审计委员会在年度审计计划中批准的审计项目和为满足企业管理当局的一些特殊要求而临时确定的审计项目来执行日常审计工作的。
不同类型的审计项目因其性质和要求的不同而具有不同的审计目的和目标。
要保证审计人员的工作能达到这些目的和目标,把完成项目审计任务的整个工作过程科学地划分为几个阶段,并赋予与之相适宜的工作内容是非常必要的。
这是对项目审计工作给予指导和控制,保证审计工作有计划、有步骤地进行,以提高审计工作质量的有效手段。
通常,外部审计人员将审计过程分为计划、实施和终结三个阶段。
内部审计的审计过程与外部审计的审计过程不完全相同。
由于内部审计侧重于企业的经营管理活动的检查和评价,目的在于督促和帮助被中计单位堵塞管理漏洞,完善控制,提高经营活动的效率、效果和经济性;而且企业管理当局非常关心审计之后的变化,关心被审计单位对审计中发现的问题所采取的纠正行动及其结果,因此,内部审计有必要重视后续审计工作,将其成为一个单独的阶段。
《内部审计专业实务标准》指出,审计工作应该包括制定审计计划、检查和评价信息、传递审计结果以及后续跟踪四个主要方面的工作。
完整的内部审计过程可划分为计划、实施、报告和后续四个阶段。
每一个阶段都有与其相适应的工作步骤,将这些步骤联系起来便构成了完成项目审计工作的审计程序。
一、审计的计划阶段计划阶段是有效执行审计工作的准备阶段,是指从确定审计项目开始,到制定出书面的审计方案为止的这一过程。
计划阶段被认为是整个审计过程的起点,其工作的周密细致程度直接影响到项目审计工作的质量和效果。
为保证这一阶段的工作质量,《内部审计专业实务标准》指出:内部审计人员应该对每一个审计项目制定审计计划,计划必须用文字记录并包括:(1)确定审计目标和范围;(2)取得有关被审计活动的背景资料;(3)确定执行工作所需要的人力资源;(4)与所有需要了解情况的人员沟通信息;(5)适当的进行现场调查,以熟悉那些需要审计的活动及其内部控制情况,确定重点审查的领域并听取被审计人员发表的意见和建议;(6)编写审计方案;(7)决定用什么方式,在什么时候,对什么人传递审计结果;(8)取得对审计方案的批准。
CVS Social and SecurityTable of Contents1. Introduction•CVS Values – Integrity and Business Practices (3)•CVS Caremark Ethics Policy (3)•Program Intent (4)•Introduction to Intertek .................................... . (4)2. Program Basics•What type of audit is required? (5)•Workplace Conditions Assessment (WCA) Criteria (6)•CVS WCA Zero Tolerance Issues (7)•Global Security Verification (GSV) Criteria (8)•Acceptance of Third Party Audit Result (9)•Additional Criteria – Subcontractor Policy (10)3. Audit Process•Step 1: On-line Factory Registration with Intertek (11)•Step 2: Audit Scheduling, Cost and Payment (13)•Step 3: Audit Preparation (14)•Step 4: Audit Day (15)4. Results and Follow-up•Audit Reports and Supplier Letter (16)•WCA Zero Tolerances and Scores 50 and below (16)•Online CAP Process and Follow-up / Annual Assessments (17)•Continuous Improvement (18)•Double Orange/Three Strikes Policy (19)5. Timeline Summary and Contacts•Audit Process Timeline Summary (20)•CVS Audit Program Contact List (21)1. IntroductionCVS Values – Integrity & Business PracticesAt CVS, our set of values defines our company and serves as a guide for how we conduct business every day. Innovation: Demonstrate openness,curiosity and creativity in the pursuit ofdelivering excellenceCollaboration: Sharing and partnering withpeople to explore and create things that wecould not do on our own.Caring: Treating people with respect andcompassion so that they feel valued andappreciatedIntegrity: Delivering on our promises: doingwhat we say and what is rightAccountability: Taking personal ownership for our actions and their resultsCVS Caremark also believes complying with the law and promoting high ethical standards is a responsibility shared by the entire organization. CVS is committed to creating a work environment that promotes integrity, ethics and compliance with applicable international, federal and state laws and regulations at all levels of interactions with suppliers, customers, and clients. We have policies in place to help prevent, detect and resolve instances of potential unethical behavior and compliance concerns within our International Supply Chain.CVS Caremark Ethics PolicyWe seek suppliers that share our values, our promise to deliver outstanding service and our commitment to uphold the highest standard and level of integrity as communicated by CVS Caremark. All CVS suppliers and their manufacturing facilities, including all subcontracting and packaging facilities, are required to adhere to our company’s standards, supplier requirements, and business processes which are published on .Program IntentTo ensure that CVS Direct Import and Storebrand Suppliers are held to the same CVS Standards as mentioned above in the CVS Caremark Ethics Policy,, CVS launched an enhanced factory audit program in January 2012. Suppliers are subject to social and security audits to ensure that:•We provide our customers with safe, quality products that are manufactured in a socially responsible manner•We uphold our commitment to protecting our brand, and helping people on their path to better health•CVS Suppliers comply with and improve processes that conform to social, legal, and ethical standards, while maintaining our commitment to Human Rights.In order to meet these objectives, the overall intent of the audit based program is to conduct business with continually high level performing factories. Although CVS is committed to working with suppliers toward continuous improvement, suppliers that persistently perform poorly within the program jeopardize their business relationship with CVS. In section four of this guide, specific expectations regarding audit results will be discussed in greater detail.Introduction to IntertekCVS has selected Intertek to be the sole provider of social and security auditing services for the Factory Audit Program.Intertek is the world’s largest provider of Social Compliance Audits monitoring the well-being of more than 100 million workers annually in over 40,000 factories. Intertek employs the international expertise of more than 500 Corporate Social Responsibility (CSR) Auditors servicing brands in 45 countries. CVS has chosen Intertek’s Workplace Conditions Assessment (WCA) and Global Security Assessment (GSV) programs as the auditing standards to verify compliance to our social and security expectations.2. Program BasicsWhat type of audit is required?CVS Direct Import items require two types of audits – Social (WCA) and Security (GSV). CVS Store Brands domestically purchased items require a WCA audit if the items are manufactured in a non-exempt country (refer to table below). Additionally, ALL subcontractors providing finished goods to CVS or CVS logo components must successfully complete a WCA audit. Failure to complete an audit may result in delay of shipments or cancellation of orders.Certain CVS Store Brands domestically purchased items also require a quality audit depending upon the type of item being produced. Please direct any questions you have related to Quality Audits to the contacts listed at the end of this document. This document is intended only as a guide to outline CVS’ social and security audit requirements.It is important to first understand what category of audit is necessary for your manufacturing facilities. Listed below are the various types of audits that may be required in order to conduct business with CVS/ Caremark:Audit MatrixType of Item and Country of Manufacture Type of AuditWCA GSV SQP GMP Direct Import non-Store Brand item (Non-FDA Regulated) WCA GSV*Direct Import non-Store Brand item (FDA Regulated) WCA GSV* GMP Direct Import Store Brand item (Non-FDA Regulated) WCA GSV* SQP - Direct Import Store Brand item (FDA Regulated) WCA GSV* - GMPStore Brands Domestic items manufactured in China & non-exempt countries **(non-FDA Regulated) WCA - SQP -Store Brands Domestic items manufactured in China & non-exempt countries ** (FDA Regulated) WCA - - GMP* GSV (Security Audits) are performed on 20% of factories producing direct imports in China and 100% of factoriesproducing direct imports outside of China** Non-exempt countries include: China, India, Mexico, Thailand, Columbia, Israel, , Turkey,El Salvador, Philippines, Vietnam, Malaysia, TaiwanExempt countries include: Canada, Germany, Portugal, Spain, Italy, Czech Republic, Denmark, France, Japan, Switzerland, Netherlands, South Korea, UK, USIf the product is manufactured in a country that is not listed as either non-exempt or exempt, CVS/Caremark will, at its sole discretion, determine what audit(s) are required.•Workplace Conditions Assessment (WCA) CriteriaAnchored in Intertek’s extensive social compliance expertise, the WorkplaceConditions Assessment (WCA) is a powerful tool for ensuring the welfare of individuals producing CVS products, benchmarking, improving supplier performance, mitigating supply chain risk, and improving product quality. This social auditing program is supported by a web-based platform that automates and streamlines the audit process, increasing efficiencies for all supply chain partners. The Workplace Conditions Assessment standard is aligned with the Global Social Compliance Program (GSCP),which is endorsed by some of the world’s largest retailers.W orkplace C onditions A ssessment benefits include:• Improved work conditions for a more content, healthier and productive workforce• Improved confidence in partnerships with suppliers through greater transparency and trust• Reduction in excessive auditing and duplication (“audit fatigue”)**A WCA social audit is required for 100% of all import suppliers’ facilities and all their subcontractors providing finished goods to CVS or CVS logo components prior to shipment.**Manufacturing facilities and all their subcontractors providing finished goods to CVS or CVS logo components for Store Brand Domestic Suppliers located in the countries listed below also require a WCA audit prior to shipment:China Israel TaiwanColombia Malaysia ThailandEl Salvador Mexico TurkeyIndia Philippines VietnamAdditionally, suppliers manufacturing direct import or store brand domestically purchased items in the countries listed below require a comprehensive review by CVS and approval by the Director of QA Regulatory Compliance (or designee) before the factory can source finished goods produced in these countries for CVS.BangladeshCambodiaHaitiPakistanThe Workplace Conditions Assessment addresses all of the topics mentioned below. For a comprehensive explanation of the WCA program, please contact Rohan Padhye at Rohan.Padhye@.The following is a list of the code of conduct criteria audited during a Workplace Conditions Assessment:CVS Workplace Conditions Assessment (WCA) Zero TolerancesIMPORTANT : Certain compliance issues are of high importance to CVS and are considered “Zero Tolerance” or “ZT” issues. They display as a red flag on the audit reports and will be communicated to CVS within 24 hours. The ramifications for Zero Tolerance findings will be discussed in more detail within section four of this Guide.The following are Zero Tolerance issues for CVS:Workplace Conditions Assessment (WCA) CriteriaLabor Child Labor; Forced Labor; Discrimination; Discipline, Harassment or Abuse; Freedom of Association; Labor Contracts Wages & Hours Wages & Benefits; Working HoursHealth & Safety General Work Facility; Emergency Preparedness; Occupational Injury; Machine Safety; Safety Hazards; Chemical and Hazardous Materials; Dormitory and Canteen Management SystemsPolicies and Processes; Documentation and Records; Worker Participation; Corrective Action ProcessEnvironmentLegal Compliance; Environmental Management Systems; Waste and Air EmissionsCVS Zero Tolerance IssuesIssue ExpectationChild LaborThere are no workers employed by the facility currently below the age requirement of local law (if no law, below 15)Forced / Prison LaborThe facility does not utilize employees who are imprisoned (i.e., utilized in a manner not in accordance with International Labor Convention 29), bonded, or indentured either to the facility itself, or a brokerAbuse and HarassmentThere is no evidence of either sexual, psychological, physical, verbal harassment, abuse, intimidation and/or bullying occurring at the facilityLife Threatening Conditions There are no blocked or locked emergency exits /doors/stairwaysBriberyThere is no evidence of the factory bribing or attempting to bribe the auditing team in any mannerFalsified Audit ReportsThere is no evidence of the factory submitting falsified audit reports to circumvent the requirements of the social and/or security auditGlobal Security Verification (GSV) CriteriaThe Global Security Verification (GSV) program is based on US Customs-Trade Partnership for Terrorism (C-TPAT) Foreign Manufacturer’sSecurity Criteria Minimum Requirements. The Global SecurityVerification program has been reviewed and is recognized by USCustoms Border Protection (CBP) as an approved 3rd party serviceprovider. The program is calibrated annually with CBP senior officials.Participation in a Global Security Verification audit can also be used todemonstrate performance for other importers under Canadian and European requirements.As an Importer and C-TPAT certified member, CVS agrees to abide by the security standards outlined by CBP. As part of our program membership, CVS has chosen to verify that its suppliers are also following these security requirements through the Global Security Verification audit process. The GSV addresses all of the topics mentioned below.For a comprehensive explanation of Global Security Verification program, please contact Rohan Padhye at Rohan.Padhye@ . For further information concerning the C-TPAT program, please refer to the U.S. Customs website /.**A GSV Security Audit is required for 100% of all import suppliers outside of China and on 20% of randomly selected suppliers within China because China is considered a “low risk” country regarding security. **Security RequirementsBusiness Partner Requirements Personnel, Procedural, and Physical Security Container and Trailer Security Requirements Information Technology Security Requirements Physical Access Controls Security Training and Threat Awareness RequirementsAcceptance of Third Party Audit ResultsIn an effort to reduce related assessment costs and limit audit fatigue for our suppliers, CVS is pleased to accept certain audit reports in lieu of a new factory audit.The following types of reports are currently accepted by CVS Caremark :WCA, GSV, ICTI, WRAP, SA8000, and BSCIProvided audit reports must meet the following criteria to be considered valid and must not expire before the FDD (Factory Delivery Date) or the In DC Date of the CVS item that is being manufactured. The process of submitting reports to CVS is performed during registration and is explained in the following section.Audit TypeReport TypeGrade NeededDocuments RequiredExpiry DateSocialWCA –Workplace Conditions Assessment85+Report1 year from Audit Date Social WCA – Workplace Conditions Assessment 71-84 Report 9 months from Audit Date Social ICTI – International Council of Toy IndustriesCertified Class A,B,or C Report & Certificate As per Certificate Social WRAP – Worldwide Responsible Accredited ProductionCertified Silver Report & Certificate As per Certificate SocialBSCI – Business Social Compliance InitiativeGoodReport 18 Months Social SA8000 – Social Accountability International (SAI)CertifiedReport & Certificate As per Certificate Security GSV – Global Security Verification 76+ Report 1 year from Audit Date SecuritySCS – Wal-Mart Supply Chain Security81+Report1 year from Audit DateAdditional Criteria - Subcontractor PolicyAll CVS Caremark Suppliers and their manufacturing facilities, including subcontracting facilities, are required to conduct business in accordance with our ethical standards and the law as mentioned in our CVS Caremark Ethics Policy. It is the expectation of CVS that its factories disclose the use of all suppliers & subcontractors on the day of the audit; when submitting a third party audit; and when a supplier/subcontractor changes between PO initiation and product shipment.CVS Caremark Suppliers must disclose to CVS the use of any subcontractor that:•Provides finished goods to a CVS Caremark supplier that CVS Caremark has paid the supplier to provide •Provides consumer ready components to be used in finished goods that CVS Caremark has paid the supplier to provide•Provides components or embellishments that contain a CVS Caremark private label or proprietary brand logo•Provides retail packaging or point of purchase packaging and/or labeling that contain a CVS Caremark private label or proprietary brand logo•Performs other subcontracting functions, i.e. printing, spraying, dyeing, injection, welding, washing, embroidery.Failure to disclose the use of a subcontractor may result in cancellation of existing purchase orders and/or termination of the business relationship with that supplier.ALL subcontractors providing finished goods to CVS, or CVS logo components, must successfully complete a WCA audit. Failure to complete an audit may result in delay of shipments or cancellation of orders. Further, it is the responsibility of CVS Caremark Suppliers to communicate to all entities within their supply chain, including any subcontractor performing any of the functions described above, all applicable laws and all CVS Caremark policies applicable to suppliers, and to ensure that such entities comply with all such applicable laws and policies.CVS Caremark or its designated third party auditing firm, reserves the right to audit any subcontractor. If the subcontractor fails the audit or is found to have a zero tolerance, existing orders with the subcontractor will be cancelled and the subcontractor will be suspended for twelve months.3. Audit ProcessStep 1: On-line Factory Registration with Intertek – Direct Import Items OnlyAll Import suppliers are required to register their factory (s) with Intertek via the GSCC online website at /audit/ (pictured below) immediately upon receipt of purchase orders. Registration is required for all CVS Item Numbers that have not been previously registered. Additionally, the factory must be re-registered if new CVS item numbers will be manufactured at a previously registered factory. Furthermore, if there is a change in factory for a specific CVS Item number, the new factory must be registered as well.Previous Audit Reports: If you have previous audit reports to provide for review in lieu of performing a new audit, it must be uploaded to the site during registration.PRE-PO Audits: If you would like to conduct an audit before a PO has officially been released and before an item number has been assigned, please enter “Pre-PO” in the item number field. IMPORTANT: If the correct factory producing the relevant items is not registered, the audit process will not commence and purchase orders will not be approved to book or ship. Should you have any questions regarding the registration process, please contact NeiNei Dong from Intertek at neinei.dong@.Factory Registration with Intertek – Store Brand Domestic PurchasesAll Domestic Store Brand Suppliers that supply products manufactured in factories located overseas are required to fill out the CVS Potential New Item Form (PNI) (pictured below) with the correct factory name, address, contact information, once the factory has been identified. Registration is required for all factories that have not been previously registered. Once the factory has been identified, you must work with Frances Tang at Intertek at frances.tang@ to register the factory with Intertek.Previous Audit Reports: Previous audit reports may be provided for review in lieu of performing a new audit, it must be e-mailed to Frances Tang at frances.tang@.IMPORTANT: If the correct factory producing the relevant items is not registered, the audit process will not commence and purchase orders will not be approved to book or ship. Should you have any questions regarding the registration process, please contact Frances Tang at frances.tang@.CVS Potential New Item Form** Manufacturing facilities must be listed on the form **Step 2: Audit Scheduling, Cost and PaymentFollowing the factory registration process, an Intertek representative will reach out to the factory to either:1.) Schedule a new audit(s)2.) If valid audit report(s) were submitted, prepayment of the 3rd party report sharing fee as well as aCVS subcontractor declaration form will be collected from supplier prior to providing approval to ship to CVSAudit SchedulingWhen scheduling a new audit, a local Intertek Customer Service Representative (CS) will contact the factory directly and request that an Audit Application Form be filled out and signed. This document clarifies the factory details and signifies the factory’s agreement to Intertek’s audit terms and conditions. The local CS will then arrange a 1 week unannounced audit window that is agreeable to both the factory and Intertek. Please note that the assessment may take place on any day within the agreed upon assessment week.Audit CostThe cost of the audit is determined based on the ITS quoted rate (i.e., location, turnaround time, and type of audit) multiplied by the number of Man days + expenses. A Man day is calculated based on the number of employees at the factory:Audit PaymentsA local Customer Service Representative will also send out a Payment Advice slip communicating the payment details including the audit costs. Please note that due to shipping considerations with this auditing program, payment must be received quickly by Intertek.• Payment should be received by Intertek BEFORE the assessment occurs. • Payment for accepted third party audit reports will be invoiced.• Payment should be received from the billed party within 5 DAYS of receiving the Payment Advice slip. (Pro-forma Invoice).• If payment is not received by the START of the audit day, the audit will proceed as planned.•If payment is not received by the END of the audit day, CVS will be invoiced for the audit; the supplier should NOT pay for the audit at that point. In the event that Intertek receives payment from the supplier after the invoice is issued to CVS, Intertek will refund the payment directly to the supplier. •Travel expenses not included unless otherwise specified.Audit Type Number of Man days# of Employees0-199 200-10001001-6,9997000+ WCA (Initial or Annual) 1 2 3 4 WCA (Follow-up) 1 1 1 1 GSV (Initial, Annual, Follow-up)1122WCA Cost = Rate per Man day xNumber of Man days + ExpensesGSV Cost = Rate per Man day x Number of Man days + ExpensesIMPORTANT NOTE: Audit payments not received by Intertek prior to the end of the audit day, will be charged directly to CVS. Any fees incurred by CVS will be charged back to the supplier with an additional $1,000 USD penalty fee above the cost of the audit.Step 3: Audit PreparationIn preparation for the audit, it is requested that the documentation mentioned below be collected and made available to the auditors. Furthermore, for greater preparation, please refer to the comprehensive WCA and GSV Standards documents available at /.WCA documentation:Step 4: Audit DayA WCA social audit consists of five components: an opening meeting, health and safety tour, payroll and documentation inspection, employee interviews, and a closing meeting.Opening MeetingAfter the auditors have passed all security requirements and are given access to the factory, an opening meeting is held with the contact person, preferably management. During this meeting, the format of the audit is described. The production manager and the human resources personnel are needed in order to answer a series of questions regarding production capacity, machines, lead times, and hiring practices.** Facility Integrity Acknowledgement: During the Opening Meeting, CVS requires the factory owners/managers to sign two letters of integrity (CVS Facility Integrity Acknowledgement Form and Intertek Factory Integrity Declaration Form) acknowledging policies around bribery. If the factory owners/managers/staff offer or imply to offer any form of benefit (including but not limited to meals, transportation, accommodation, money, gifts and/or favors) to an Intertek employee, CVS will cancel all orders and place the factory on probation for one year.Health and Safety TourA walkthrough of the factory is conducted to ensure adequate measures are in place to protect the health of workers and guarantee their safety and the safety of the surrounding environment. Production capacity is also evaluated during the walkthrough. Housing units, if applicable, need to be inspected by the auditors. The eating area used by the workers is also viewed, as is the kitchen if cooking takes place onsite. Photographs of the factory are also taken with permission from management.Payroll and Documentation InspectionPayroll documentation is reviewed. Payroll journals, timecards, production records, attendance books, proof of insurance payment or tax payment (if applicable) must all be provided to the auditors for a complete audit to take place. The auditors are checking to ensure that the regional minimum wage is provided to all employees for all hours worked, including overtime compensation. Also evaluated is whether maximum hours authorized to work, including weekend and evening hours, are in compliance with regional labor laws. Copies of operating licenses and other government issued permits are also reviewed. Company policies handbooks and management systems are reviewed. Employee records are reviewed. Proof of age documentation must be available.Employee InterviewsThe auditors will randomly select employees from various production areas for interviews, away from the presence of management or other employees. Auditors will require the use of a private room in which to conduct these interviews. Employees are asked questions regarding hours of work, length of employment, their understanding of human rights (freedom of association, collective bargaining, equal opportunity, non-discrimination, unrestricted liberties, etc.), disciplinary policies of the factory, hiring policies, and working conditions.Closing MeetingAt the conclusion of the audit a Continuous Improvement Report (CIR) is created if necessary and all concerns are discussed with the facility management. Management is requested to sign the CIR, to verify that they understand the findings. A copy of the CIR is left with management to assist them in resolving the concerns detected during the audit.4. Results and Follow-upAudit Report and Supplier LetterFollowing the assessment, a copy of the full Audit Report will be sent to the factory and supplier via email. (For this reason, it is very important for suppliers to provide their contact e-mail addresses during the registration process.) Facilities that successfully pass their Workplace Conditions Assessment with a grade above 50 without any Zero Tolerance issues are eligible to ship goods to CVS. They will receive a Supplier Letter with information for booking a shipping appointment with Yusen Logistics.The Supplier Letter contains two key pieces of information that are to be entered into the Yusen system during the booking process: Facility ID and Assessment Number .WCA Zero Tolerances (ZT) and Scores 50 and BelowThere are two non-passing WCA scenarios that prevent booking and cause delays in shipment:1.) Zero Tolerance non-compliance issues2.) Scores 50 and below What happens if the factory is found to have Zero Tolerance compliance issues or scores below a 51?Depending on the type of Zero Tolerance issue(s) found at the factory and/or types of issues discovered within a 50 or below audit report, CVS will make a determination on how to proceed with the business relationship.In the instance of a factory found to have a Zero Tolerance issue such as Child Labor, Forced/Prison Labor, Abuse & Harassment, or Bribery, CVS will cancel all orders and place the factory on probation for one year. In other instances, an immediate follow-up audit may be requested that could move out the ship date, which would potentially add late shipment penalties .Facility ID Assessment #Supplier LetterWCA Audit ReportThe CVS Factory Compliance Team will take the steps as mentioned below following a Zero Tolerance incidence or score of 50 or below:•Notify the Category Manager or Product Development Manager via a Non-Compliance Form and the completed audit report•Communicate and forward the audit results to the Supplier•Work with Intertek to reschedule a follow-up audit at the factory or cancel the purchase orders•If purchase orders are cancelled, place the factory on probation for one (1) year•Factories placed on probation for one year must successfully pass an audit prior to receiving new CVS Purchase Orders.Capacity Site Evaluation Review (SER)In the event that another factory is selected to produce merchandise in light of poor audit results, CVS will request that Intertek conduct a Site Evaluation Review (SER capacity audit ), at the factory’s expense, to verify that the merchandise is actually being produced in the new factory.** CVS/Caremark will, at its sole discretion, determine whether to do business with a factory/supplier based on further review of the factory.Online CAP Process and Follow-up / Annual AssessmentsWCA AssessmentsFollowing the audit, depending upon the results obtained, the factory may be required to submit an online Corrective Action Plan (CAP) and/or participate in a Follow-up/Annual assessment.The supplier letter will indicate next steps required of the factory. The matrix below summarizes which action is typically needed based upon the audit results received:WCA Follow-up Audit MatrixAuditResults Next Action Follow-upResults Next ActionVery Low 0-50 Follow-up audit within3 Months(prior to ship)Very Low Shipment TBD by CVSLow Follow-up audit 3-6 Months (No Major findings: Supply Online CAP)Medium Follow-up audit 6-9 Months (No Major findings: Supply Online CAP)High Annual AuditLow 51-70Follow-up audit3-6 Months(No Major findings:Supply CAP)Very Low Shipment TBD by CVSLow Follow-up audit 3-6 Months (No Major findings: Supply Online CAP)Medium Follow-up audit 6-9 Months (No Major findings: Supply Online CAP)High Annual AuditMedium 71-84 Follow-up audit 6-9Months(No Major findings:Supply CAP)Very Low Shipment TBD by CVSLow Follow-up audit 3-6 Months (No Major findings: Supply Online CAP)Medium Follow-up audit 6-9 Months (No Major findings: Supply Online CAP)High Annual AuditHigh85-100 Annual Audit Very Low Shipment TBD by CVSLow Follow-up audit 3-6 Months (No Major findings: Supply Online CAP) Medium Follow-up audit 6-9 Months (No Major findings: Supply Online CAP) High Annual Audit。