Food safety is not controlled at only one point in the food chain.
It begins with raw materials, agricultural production and suppliers, continues through processing, manufacturing, packaging, storage and transportation, and ultimately reaches retail, food service and the consumer.
A weakness at any stage can potentially affect the safety of the final food product.
This is where ISO 22000:2018 becomes relevant.
ISO 22000:2018 is an international standard specifying requirements for a Food Safety Management System (FSMS). It is intended for organizations directly or indirectly involved in the food chain and can be applied regardless of their size or position within that chain. ISO currently lists ISO 22000:2018 as the published edition, together with Amendment 1:2024 — Climate action changes.
But ISO 22000 is more than a food-safety checklist.
It combines management-system thinking, prerequisite programmes, hazard analysis, operational controls, communication, traceability, verification, internal auditing, management review and continual improvement into a structured Food Safety Management System.
What is ISO 22000:2018 certification?
ISO 22000:2018 certification is third-party certification of an organization’s Food Safety Management System (FSMS) against the requirements of ISO 22000:2018. The standard is designed for organizations directly or indirectly involved in the food chain and provides a systematic framework for identifying, evaluating and controlling food-safety hazards.
It connects food-safety controls with broader management-system processes such as leadership, planning, competence, communication, documented information, monitoring, internal audit, management review and continual improvement.
ISO 22000 can apply to organizations such as food manufacturers, processors, farms, food-service organizations, retailers, storage and distribution providers, packaging-material suppliers and other organizations involved in the food chain. ISO 22000 is therefore broader than HACCP alone: it incorporates hazard-control principles within a management-system framework.
What Is ISO 22000?
ISO 22000 is an international Food Safety Management System standard that specifies requirements for organizations in the food chain to systematically manage food-safety hazards and demonstrate their ability to provide safe products and services.
It can be used by organizations of different sizes and across different stages of the food chain, from primary production and food manufacturing to storage, transportation, retail and food services.
1. What Is ISO 22000:2018?
ISO 22000:2018 — Food safety management systems — Requirements for any organization in the food chain provides a framework for establishing, implementing, maintaining and continually improving a Food Safety Management System.
The standard’s purpose is not simply to ask an organization:
“Do you have a HACCP plan?”
It asks a much broader management question:
“Does your organization have a systematic and controlled way of managing food-safety risks throughout the relevant processes of the food chain?”
That distinction is important.
An organization may have food-safety procedures, laboratory testing, sanitation programmes and HACCP documentation. However, those individual controls need to operate within a coherent system.
An FSMS brings together:
- Food-safety policy
- Organizational responsibilities
- Food-safety objectives
- Risk-based planning
- Prerequisite programmes
- Hazard analysis
- Operational controls
- HACCP principles
- Traceability
- Emergency preparedness
- Competence
- Communication
- Verification
- Internal audit
- Management review
- Corrective action
- Continual improvement
ISO describes ISO 22000 as applicable to organizations regardless of size or position in the food chain.
2. What Does FSMS Mean?
FSMS = Food Safety Management System.
It is the organized system through which an organization manages food-safety responsibilities and controls.
Think of it as the connection between:
PEOPLE
Who is responsible?
↓
PROCESSES
What activities affect food safety?
↓
HAZARDS
What could make the food unsafe?
↓
CONTROLS
How are those hazards controlled?
↓
MONITORING
How do we know the controls are working?
↓
VERIFICATION
How do we confirm the system works as intended?
↓
IMPROVEMENT
What do we change when performance is not satisfactory?
This is why ISO 22000 should not be treated as a collection of documents.
The documentation supports the system.
The system itself is the way the organization manages food safety.
3. Why Is Food Safety Management Different From Ordinary Quality Management?
Food quality and food safety are related, but they are not identical.
For example, a food product might have:
- attractive packaging,
- good taste,
- consistent appearance,
- correct weight,
- good customer acceptance,
and still present a food-safety concern if a relevant biological, chemical or physical hazard has not been adequately controlled.
Food safety therefore requires systematic identification and control of hazards.
ISO 22000 is specifically designed around this food-safety perspective.
ISO notes that food-safety management standards help organizations identify and control food-safety hazards while supporting safety throughout the global food supply chain.
4. Who Needs ISO 22000 Certification?
One of the most important things to understand about ISO 22000 is the phrase:
“Any organization in the food chain.”
That means ISO 22000 is not limited to large food factories.
Organizations at different stages of the food chain may establish an FSMS according to their activities, risks and applicable requirements.
Examples include:
1. Food Manufacturers
Examples:
- dairy products
- beverages
- bakery products
- snacks
- ready-to-eat foods
- frozen foods
- processed foods
- packaged foods
A manufacturing organization may need to control hazards associated with raw materials, processing, equipment, personnel, environment, packaging and storage.
2. Food Processing Organizations
Processing activities can introduce or modify food-safety risks.
Examples include:
- grain processing
- milling
- oil processing
- fruit and vegetable processing
- meat processing
- seafood processing
- spice processing
- ingredient processing
An FSMS helps the organization systematically identify where hazards can arise and how they are controlled.
3. Food Ingredient Manufacturers and Suppliers
Ingredients can become a critical part of the food-safety chain.
Examples include suppliers of:
- spices
- additives
- flavours
- preservatives
- food ingredients
- oils
- concentrates
- premixes
The organization needs to understand the food-safety implications of its products and processes.
4. Primary Producers and Farms
Food safety can begin before the product reaches a processing facility.
Relevant organizations can include:
- farms
- agricultural producers
- aquaculture operations
- primary food producers
- organizations involved in harvesting
The applicable controls will depend on the organization’s activities and the scope of its FSMS.
5. Food Packaging Organizations
Packaging materials can form part of the food chain, particularly where they come into contact with food.
Organizations may therefore need to consider:
- material suitability
- contamination risks
- production hygiene
- storage
- handling
- traceability
- supplier controls
6. Warehousing and Storage Organizations
Food can be exposed to risks during storage even when the original product was manufactured correctly.
Relevant considerations can include:
- temperature
- humidity
- pest control
- hygiene
- segregation
- product identification
- stock rotation
- contamination prevention
- traceability
7. Transportation and Distribution Organizations
Food safety does not stop when a product leaves the manufacturing facility.
Transportation and distribution activities may affect:
- temperature control
- product integrity
- contamination
- handling
- traceability
- delivery conditions
The FSMS should address controls relevant to the organization’s activities.
8. Food Retail Organizations
Retail operations may handle food through:
- receiving
- storage
- display
- handling
- preparation
- distribution
The appropriate FSMS scope and controls depend on the organization’s actual activities.
9. Catering and Food-Service Organizations
Examples include:
- institutional catering
- commercial catering
- restaurants
- food-service operations
- central kitchens
- contract catering
Food-safety controls may include:
- receiving
- storage
- preparation
- cooking
- holding
- serving
- cleaning
- personnel hygiene
- allergen controls
- waste management
10. Cleaning and Sanitation Service Providers
Organizations providing services that directly or indirectly affect food safety can also be relevant to the food chain.
This is particularly important where sanitation activities affect food-production environments.
11. Equipment and Service Suppliers
Organizations supplying equipment, cleaning materials, disinfectants, packaging materials and other relevant inputs may form part of the broader food chain.
The current ISO/DIS 22000 material also identifies a broad range of directly and indirectly involved organizations, including equipment suppliers, cleaning and disinfectant suppliers, packaging-material suppliers and food-contact-material suppliers.
5. Understanding the Food Chain
A useful way to understand ISO 22000 is to visualize the journey of food:
Primary Production
↓
Raw Materials
↓
Ingredient Suppliers
↓
Food Processing
↓
Manufacturing
↓
Packaging
↓
Storage
↓
Transportation
↓
Distribution
↓
Retail / Food Service
↓
Consumer
Food safety can be influenced at every stage.
That is why an effective FSMS needs to consider not just what happens inside one facility, but also relevant interactions with suppliers, customers and other organizations within the food chain.
6. What Are Food-Safety Hazards?
At the heart of ISO 22000 is the need to identify and control relevant food-safety hazards.
Broadly, organizations may need to consider hazards such as:
🦠 Biological Hazards
Examples can include:
- pathogenic bacteria
- viruses
- parasites
- biological toxins
🧪 Chemical Hazards
Examples can include:
- chemical contamination
- cleaning-chemical residues
- pesticide residues
- veterinary-drug residues
- naturally occurring toxins
🧱 Physical Hazards
Examples can include:
- glass
- metal
- stones
- hard plastic
- other foreign materials
⚠️ Allergen-Related Risks
Depending on the product and applicable requirements, allergen management can become a significant part of food-safety controls.
The exact hazards, significance and controls must be determined based on the organization’s products, processes, intended use and applicable requirements.
7. ISO 22000 and HACCP — Are They the Same?
No.
This is one of the most common questions.
HACCP
Hazard Analysis and Critical Control Points is a systematic methodology for identifying and controlling food-safety hazards.
ISO 22000
ISO 22000 is a Food Safety Management System standard.
It incorporates HACCP-based hazard-control thinking into a broader management system.
ISO explains that ISO 22000 strengthens the traditional HACCP approach by combining food-safety hazard controls with management-system requirements such as policy, planning, implementation, performance assessment, management review and improvement.
A simplified way to understand the relationship is:
HACCP = Food-safety hazard-control methodology
ISO 22000 = Food-safety management system incorporating hazard-control principles
8. What Does ISO 22000 Add to HACCP?
This is where ISO 22000 becomes particularly valuable for organizations looking for a structured management system.
ISO 22000 connects food-safety hazard control with:
- Leadership
- Food-safety policy
- Organizational context
- Planning
- Competence
- Communication
- Documented information
- Operational control
- Monitoring
- Internal audit
- Management review
- Corrective action
- Continual improvement
ISO also explains that ISO 22000 integrates PRPs, operational PRPs and HACCP plans through hazard analysis into an integrated food-control system.
So the relationship can be visualized as:
Management System
Leadership + Planning + Support + Evaluation + Improvement
↓
Food-Safety Controls
PRPs + OPRPs + HACCP Plan
↓
Food-Safety Performance
Safe Food + Evidence + Verification + Improvement
9. What Are PRPs?
PRP = Prerequisite Programme.
PRPs establish the basic conditions and activities needed to maintain an appropriate hygienic environment.
Depending on the organization, these may address areas such as:
- cleaning and sanitation
- pest control
- personnel hygiene
- facility hygiene
- equipment maintenance
- waste management
- supplier controls
- storage
- transportation
- utilities
- contamination prevention
PRPs create the foundation on which the food-safety control system operates.
A useful way to think about it is:
PRPs establish the environment in which safe food can be produced.
10. What Are OPRPs?
OPRP = Operational Prerequisite Programme.
Within ISO 22000’s food-safety control framework, hazard analysis can identify controls that are necessary for managing significant hazards but are not controlled through CCPs.
These controls can be managed through OPRPs.
Therefore, ISO 22000 provides a structured way of connecting:
Hazard Analysis
→ PRPs
→ OPRPs
→ CCPs / HACCP Plan
→ Monitoring
→ Verification
The precise controls depend on the organization’s food products, processes and hazard analysis.
11. What Is a CCP?
CCP = Critical Control Point.
A CCP is a step at which control can be applied and is essential to prevent, eliminate or reduce a significant food-safety hazard to an acceptable level.
Examples in different food processes could involve controls associated with:
- cooking
- pasteurization
- sterilization
- metal detection
- temperature control
However, organizations should not assume that a particular process is automatically a CCP.
The classification should result from the organization’s hazard analysis and established methodology.
This distinction is extremely important during ISO 22000 implementation.
12. ISO 22000 Is More Than “Food Safety Documentation”
A common implementation mistake is to start with:
“What documents do we need?”
A better starting point is:
1. What products do we make?
↓
2. What processes do we perform?
↓
3. What hazards could arise?
↓
4. Which hazards are significant?
↓
5. What controls are required?
↓
6. How are those controls monitored?
↓
7. How do we verify their effectiveness?
↓
8. What happens when something goes wrong?
↓
9. How does management evaluate performance?
↓
10. How does the organization improve?
Only after understanding those questions should documentation be designed.
13. Traceability — A Critical Element of Food Safety
Imagine a food manufacturer discovers that a particular raw material may have a safety issue.
Can the organization identify:
- Which supplier supplied it?
- Which batch was received?
- Where was it used?
- Which production batch contains it?
- Where was the finished product distributed?
- Which customers received it?
That is where traceability becomes important.
An effective traceability system should enable the organization to understand relevant links through the food chain and support appropriate action when a food-safety issue occurs.
Traceability should therefore not be treated as just a register.
It should be a working operational capability.
14. Emergency Preparedness and Response
Food-safety emergencies can arise from situations such as:
- contamination events
- equipment failures
- utility failures
- natural events
- fire
- water contamination
- refrigeration failure
- supply disruption
- product incidents
- suspected food-safety incidents
The organization should consider relevant emergency scenarios and establish appropriate response arrangements.
A mature FSMS asks:
“What happens if our normal food-safety controls fail?”
Not merely:
“Do we have an emergency procedure?”
15. Communication Is Central to ISO 22000
Food safety depends on information moving correctly.
Communication may occur between:
Suppliers ↔ Organization ↔ Customers ↔ Regulators ↔ Employees ↔ Other Food-Chain Organizations
Relevant information may include:
- product requirements
- food-safety hazards
- specifications
- changes
- incidents
- regulatory requirements
- supplier information
- customer requirements
Poor communication can create food-safety risks even when individual processes appear well controlled.
16. Food Safety Culture
A strong FSMS is not created only by the food-safety team.
It requires participation across the organization.
Consider a production employee who notices a possible contamination issue.
What happens next?
If employees are encouraged to report concerns and management responds appropriately, the organization has a stronger foundation for food-safety performance.
Food safety culture can therefore be reflected through:
- leadership commitment
- employee awareness
- communication
- accountability
- reporting of issues
- training
- appropriate response to food-safety concerns
- continual improvement
Consultant’s Insight
Food safety culture becomes visible when people make the right food-safety decision even when nobody is standing beside them.
That is why ISO 22000 implementation should not be reduced to training people on procedures.
People need to understand why the control exists.
17. ISO 22000 vs ISO 9001
Both are management-system standards, but their primary focus differs.
| Area | ISO 22000 | ISO 9001 |
|---|---|---|
| Primary focus | Food safety | Quality management |
| Main objective | Control food-safety hazards | Consistent products/services and customer satisfaction |
| Food-chain applicability | Specifically designed for food chain | General applicability |
| Hazard analysis | Central to FSMS | Risk-based quality approach |
| HACCP principles | Integrated into food-safety control framework | Not a core requirement |
| PRPs | Fundamental to food-safety controls | Not a central ISO 9001 requirement |
| Food-safety communication | Specific importance | General organizational/customer communication |
| Certification | Available | Available |
These standards can also be integrated.
For a food manufacturing organization, an integrated management system can combine:
ISO 9001 → Quality
ISO 22000 → Food Safety
potentially other systems such as:
ISO 14001 → Environment
ISO 45001 → Occupational Health & Safety
This can reduce duplication where processes genuinely overlap.
18. ISO 22000 vs FSSC 22000
Another common search question is:
“Is ISO 22000 the same as FSSC 22000?”
No.
ISO 22000 is an ISO Food Safety Management System standard.
FSSC 22000 is a separate food-safety certification scheme built around ISO 22000 together with additional requirements and relevant prerequisite-programme standards.
Therefore, organizations should not treat:
ISO 22000 = FSSC 22000
as equivalent statements.
The certification objective, scheme requirements and applicable additional requirements need to be understood before choosing the appropriate route.
19. ISO 22000:2018 and the 2026 Update
This is particularly important for anyone researching ISO 22000 certification now.
Current published standard
ISO 22000:2018
ISO currently lists this as the published edition and says it was last reviewed and confirmed in 2023.
Amendment
ISO 22000:2018/Amd 1:2024
The amendment is titled:
Climate action changes
and was published in February 2024.
Future revision
ISO/DIS 22000 is currently under development as the proposed revision of ISO 22000.
As of the latest ISO information available, the draft is in the enquiry/development lifecycle rather than being a published replacement standard. ISO’s lifecycle information shows the DIS process and indicates that the document has been referred back within the development process, so organizations should not treat the draft as the current certifiable edition.
Therefore:
Current published edition:
ISO 22000:2018 + applicable Amendment 1:2024
Future revision:
ISO/DIS 22000 — under development
This distinction is important for organizations planning certification in 2026.
20. What Does the Climate-Action Amendment Mean?
The 2024 amendment is titled Climate action changes.
This is part of a broader change affecting ISO management-system standards.
Organizations implementing or maintaining ISO 22000 should therefore consider the relevance of climate change to their management-system context and applicable interested-party requirements.
The important point is:
Do not create a separate climate document simply because the word “climate” appears in an amendment.
Instead, determine:
- Is climate change relevant to our FSMS?
- Could climate-related conditions affect food safety?
- Could climate-related changes affect suppliers or the food chain?
- Have relevant interested-party expectations changed?
- Are risks and opportunities affected?
The organization’s actual context should determine the response.
21. Benefits of ISO 22000 Certification
ISO 22000 certification can provide a structured framework for organizations to strengthen food-safety management.
Potential benefits include:
🛡️ Better Food-Safety Control
Systematic identification and control of food-safety hazards.
🔍 Improved Traceability
Better ability to trace relevant materials and products.
📋 Structured Processes
Defined responsibilities and controlled food-safety processes.
🤝 Supplier and Food-Chain Control
Better management of relevant external interactions.
📊 Performance Evaluation
Monitoring, measurement, internal audit and management review.
🚨 Better Preparedness
Defined responses to relevant food-safety emergencies.
🔄 Continual Improvement
Corrective action and continual improvement become part of the management system.
🌍 Market Confidence
Certification can provide evidence to customers and other interested parties that an organization operates a certified FSMS.
ISO itself states that ISO 22000 can be certified and provides a framework for organizations to demonstrate their ability to control food-safety hazards and ensure food is safe.
22. What ISO 22000 Certification Does NOT Mean
Certification should not be misunderstood.
An ISO 22000 certificate does not mean:
❌ Every possible food-safety risk has been eliminated.
❌ The organization will never experience a food-safety incident.
❌ The certificate replaces legal or regulatory requirements.
❌ HACCP is no longer necessary.
❌ Every product is automatically “ISO certified.”
❌ Certification eliminates the need for monitoring and verification.
Instead, certification provides independent conformity assessment of the organization’s management system against the applicable certification requirements.
Food safety remains an ongoing operational responsibility.
23. ISO 22000 Implementation: The Basic Management Cycle
A practical implementation can be visualized as:
UNDERSTAND
Understand the organization, food chain and requirements.
↓
IDENTIFY
Identify hazards, processes, interested parties and risks.
↓
CONTROL
Establish PRPs, OPRPs, CCP-related controls and operational processes.
↓
IMPLEMENT
Put the FSMS into practice.
↓
MONITOR
Measure and monitor relevant controls and processes.
↓
VERIFY
Verify that the system is functioning as intended.
↓
AUDIT
Conduct internal audits.
↓
REVIEW
Management evaluates the FSMS.
↓
IMPROVE
Correct problems and continually improve.
This is the management-system thinking behind ISO 22000.
24. What Does an ISO 22000 Auditor Actually Want to See?
One of the biggest misconceptions is that certification audits are primarily about checking documents.
Documentation matters.
But the auditor ultimately needs objective evidence that the system is implemented and functioning.
The evidence chain can be thought of as:
Requirement
↓
Process
↓
Implementation
↓
Record / Evidence
↓
Monitoring
↓
Verification
↓
Improvement
For example:
Requirement: Control a food-safety hazard.
↓
Process: Defined control method.
↓
Implementation: Employees follow the control.
↓
Evidence: Monitoring records.
↓
Verification: Verification activities confirm control effectiveness.
↓
Improvement: Corrective action is taken when performance is inadequate.
That is much stronger than simply presenting a procedure to an auditor.
25. ISO 22000 for Indian Food Businesses
For Indian organizations, an FSMS may need to operate alongside applicable statutory and regulatory food-safety requirements.
Organizations may include:
- food manufacturers
- food processors
- restaurants
- catering companies
- food packaging companies
- warehouses
- distributors
- exporters
- ingredient suppliers
- food-service organizations
The exact regulatory obligations depend on the organization’s activities, products, location and market.
Therefore:
ISO 22000 ≠ regulatory compliance
Instead:
ISO 22000 + applicable statutory/regulatory requirements
should work together within the organization’s food-safety management framework.
This distinction is particularly important when preparing for certification.
26. ISO 22000 for Hyderabad and Telangana Food Businesses
Hyderabad and Telangana have a broad ecosystem of food-related organizations, including:
- food manufacturers
- packaged-food businesses
- food-processing companies
- dairy-related businesses
- spice and ingredient suppliers
- restaurants
- catering organizations
- cloud kitchens
- warehouses
- distributors
- food-export businesses
For these organizations, ISO 22000 implementation should begin with the actual food-safety risks and processes of the organization, rather than copying a generic FSMS manual.
A food manufacturer, restaurant, warehouse and packaging supplier may all use ISO 22000, but their processes and hazard profiles will not be identical.
That is why scope and hazard analysis are foundational activities.
27. Common ISO 22000 Implementation Mistakes
Mistake 1 — Treating ISO 22000 as Only HACCP
ISO 22000 is broader than HACCP because it establishes a management-system framework around food safety.
Mistake 2 — Copying a Generic HACCP Plan
Hazard analysis should reflect the organization’s actual products, processes and intended use.
Mistake 3 — Creating Documents Before Understanding Processes
Documentation should represent the actual FSMS.
Mistake 4 — Ignoring PRPs
Food-safety controls cannot be considered in isolation from the prerequisite conditions supporting hygienic operations.
Mistake 5 — Weak Traceability
A traceability procedure that cannot be demonstrated through an actual exercise is a weakness.
Mistake 6 — Collecting Monitoring Records Without Verification
A completed form does not automatically demonstrate that the FSMS is effective.
Mistake 7 — Treating Internal Audit as a Formality
Internal audit should evaluate the effectiveness and conformity of the system.
Mistake 8 — Management Review Without Management Decisions
Management review should result in meaningful evaluation and decisions where appropriate.
Mistake 9 — Ignoring Supplier Controls
Food safety can be influenced before raw materials enter the organization.
Mistake 10 — Confusing the Current Standard With the Draft Revision
In 2026, this is especially important.
ISO 22000:2018 remains the published edition, with Amendment 1:2024, while the revision represented by ISO/DIS 22000 remains under development.
What exactly does ISO 22000:2018 require?
ISO 22000:2018 is structured around the familiar ISO management-system framework, with the core requirements for the FSMS contained in Clauses 4 through 10.
These clauses move logically from:
Context → Leadership → Planning → Support → Operation → Performance Evaluation → Improvement
The important distinction is that ISO 22000 adds a highly specialized food-safety operational layer, particularly in Clause 8, covering prerequisite programmes, traceability, emergency preparedness, hazard analysis, hazard control plans, verification and control of nonconforming products and processes.
ISO currently lists ISO 22000:2018 as the published edition, with Amendment 1:2024 on climate-action changes. ISO also identifies a future ISO/DIS 22000 revision under development.
So let’s examine the clauses from an implementation and auditor perspective.
What are the ISO 22000:2018 Clauses?
The main ISO 22000:2018 Food Safety Management System requirements are contained in Clauses 4–10:
| Clause | Main Area |
|---|---|
| 4 | Context of the Organization |
| 5 | Leadership |
| 6 | Planning |
| 7 | Support |
| 8 | Operation |
| 9 | Performance Evaluation |
| 10 | Improvement |
For food businesses, Clause 8 is particularly significant because it contains the operational food-safety controls, including prerequisite programmes (PRPs), traceability, emergency preparedness, hazard analysis, validation of control measures, HACCP/OPRP plans, monitoring, verification and control of nonconforming products and processes.
The clauses work together rather than operating as separate checklists.
Clause 4 defines the context → Clause 5 establishes leadership → Clause 6 plans the system → Clause 7 provides support → Clause 8 controls operations → Clause 9 evaluates performance → Clause 10 drives improvement.
ISO 22000:2018 Clause Structure at a Glance
Before going into the details, this is the management-system architecture we should keep in mind:
CLAUSE 4
Context
↓
CLAUSE 5
Leadership
↓
CLAUSE 6
Planning
↓
CLAUSE 7
Support
↓
CLAUSE 8
Food-Safety Operations
↓
CLAUSE 9
Performance Evaluation
↓
CLAUSE 10
Improvement
And throughout the system:
Communication + System Management + PRPs + HACCP Principles
ISO itself identifies these as key components of ISO 22000.
Clause 4 — Context of the Organization
Clause 4 establishes the environment in which the FSMS operates.
It asks:
What is the organization, what affects its food-safety objectives, who matters to it, and what is included in the FSMS?
4.1 Understanding the Organization and Its Context
The organization needs to determine the internal and external issues relevant to its purpose and that can affect its ability to achieve the intended outcomes of the FSMS.
External issues could include:
- Food-safety regulations
- Market requirements
- Customer requirements
- Supply-chain conditions
- Technology
- Climate-related conditions
- Economic factors
- Industry developments
- Emerging food-safety hazards
Internal issues could include:
- Organization structure
- Employee competence
- Production capacity
- Equipment
- Food-safety culture
- Existing processes
- Organizational knowledge
- Infrastructure
- Internal communication
Example
Consider a packaged-food manufacturer in Hyderabad.
External issues could include:
Regulatory requirements → customer specifications → supplier risks → climate conditions → market expectations
Internal issues could include:
Production capacity → employee competency → equipment condition → sanitation controls → laboratory capability
These issues can influence how the FSMS is designed and maintained.
🌡️ 2026 Climate-Action Consideration
The 2024 amendment to ISO 22000:2018 is titled Climate action changes.
Therefore, organizations maintaining an ISO 22000 FSMS should consider whether climate change is a relevant issue in their context and whether relevant interested parties have climate-related requirements.
This should be treated as a contextual assessment, not as an instruction to create a generic “climate document.”
The question is:
Could climate change affect our food-safety management system or our ability to achieve intended FSMS outcomes?
The answer should be based on the organization’s actual circumstances.
ISO lists Amendment 1:2024 as part of the current ISO 22000:2018 edition.
4.2 Understanding the Needs and Expectations of Interested Parties
Food safety rarely depends on one organization alone.
Relevant interested parties may include:
- Consumers
- Customers
- Regulatory authorities
- Suppliers
- Employees
- Contractors
- Certification bodies
- Owners
- Distribution partners
- Retailers
- Industry organizations
Each may have requirements relevant to the FSMS.
Example
A food manufacturer may need to consider:
Regulator → statutory requirements
Customer → product specification
Consumer → allergen information
Supplier → raw-material information
Employee → food-safety responsibilities
Certification body → conformity requirements
The organization should determine which of these requirements are relevant to its FSMS.
4.3 Determining the Scope of the FSMS
The scope defines the boundaries of the Food Safety Management System.
It should clearly identify the relevant:
- Products
- Processes
- Sites
- Activities
- Food-chain categories
- Organizational boundaries
Example
Instead of writing:
“Food manufacturing.”
A more useful scope could identify the actual activities covered, such as:
“Manufacture and packaging of ready-to-eat cereal-based food products at the Hyderabad manufacturing facility.”
The exact wording must reflect the organization’s actual activities.
4.4 Food Safety Management System
The organization needs to establish, implement, maintain, update and continually improve the FSMS.
This means the FSMS is not a one-time certification project.
It is a living management system.
Clause 4 — What an Auditor May Look For
| Requirement | Possible Evidence |
|---|---|
| Organizational context | Context analysis |
| Interested parties | Interested-party register |
| Relevant requirements | Regulatory/customer requirements |
| FSMS scope | Approved scope statement |
| FSMS processes | Process interaction map |
| System maintenance | Review/update records |
Auditor mindset
An auditor may ask:
“Why did you identify this issue as relevant to your FSMS?”
The organization should be able to explain the reasoning.
Clause 5 — Leadership
Food safety cannot be delegated entirely to the quality or food-safety department.
Top management has an important role in establishing and maintaining the FSMS.
5.1 Leadership and Commitment
Leadership should demonstrate commitment to the FSMS.
This can include:
- Ensuring the FSMS is integrated into business processes
- Providing necessary resources
- Supporting food-safety objectives
- Communicating the importance of food safety
- Ensuring the FSMS achieves intended outcomes
- Supporting relevant personnel
- Promoting continual improvement
The practical question
If production targets conflict with a food-safety control, what does management do?
That is where leadership commitment becomes visible.
5.2 Food Safety Policy
The organization should establish a food-safety policy appropriate to its purpose and context.
A useful policy should communicate the organization’s commitment to:
- Food safety
- Applicable requirements
- Relevant objectives
- Continual improvement
- Appropriate communication
But a policy should not simply be displayed on a wall.
Employees should understand what it means for their work.
5.3 Organizational Roles, Responsibilities and Authorities
Who is responsible for:
- Food-safety decisions?
- Hazard analysis?
- PRPs?
- Monitoring?
- Verification?
- Product release?
- Nonconforming product?
- Traceability?
- Recall?
- Internal audit?
- Corrective action?
Responsibilities need to be clear.
A common implementation weakness is:
“The Quality Manager is responsible for everything.”
An effective FSMS distributes responsibility according to actual organizational roles.
Food Safety Team
ISO 22000 uses a food-safety-team approach for important FSMS activities.
The team should have appropriate knowledge and competence relevant to the organization’s food products, processes and food-safety hazards.
This could involve expertise in:
- Food technology
- Microbiology
- Production
- Quality
- Engineering
- Maintenance
- Sanitation
- Regulatory requirements
The exact team composition depends on the organization’s size and complexity.
Clause 5 — Auditor Evidence
| Area | Example Evidence |
|---|---|
| Leadership | Management commitment |
| Policy | Approved food-safety policy |
| Responsibilities | Organization chart / responsibility matrix |
| Food-safety team | Team appointment |
| Competence | Qualification/training records |
| Communication | Meeting records |
| Resources | Budget/equipment/personnel evidence |
Clause 6 — Planning
Clause 6 converts context and leadership direction into structured planning.
It answers:
What could affect the FSMS, what are we trying to achieve, and how will we manage change?
6.1 Actions to Address Risks and Opportunities
The organization should determine risks and opportunities that need to be addressed to ensure the FSMS can achieve its intended outcomes.
This is different from the detailed food-hazard analysis in Clause 8.
Important distinction
Clause 6 risk planning
looks at risks and opportunities affecting the FSMS.
Clause 8 hazard analysis
looks specifically at food-safety hazards associated with products, processes and the process environment.
They should not simply be treated as the same exercise.
6.2 FSMS Objectives and Planning to Achieve Them
Organizations should establish appropriate food-safety objectives.
A good objective should be:
- Relevant
- Measurable where appropriate
- Monitored
- Communicated
- Updated when necessary
Example objectives
Instead of:
“Improve food safety.”
Consider objectives such as:
- Reduce repeat sanitation-related nonconformities.
- Improve traceability exercise performance.
- Increase completion of food-safety training.
- Reduce supplier-related food-safety deviations.
- Improve corrective-action closure performance.
The actual objective should reflect the organization’s context and risks.
6.3 Planning of Changes
Food-safety changes should be planned.
Changes might involve:
- New products
- New ingredients
- New suppliers
- New equipment
- New production lines
- New packaging
- New facility layouts
- Process changes
- New regulatory requirements
- Changes in personnel
- Changes in production volumes
The organization should consider the potential impact of the change on the FSMS.
Clause 6 — Auditor Evidence
Possible evidence includes:
- Risk and opportunity assessment
- FSMS objectives
- KPI records
- Action plans
- Change-management records
- Management decisions
- Objective monitoring
Clause 7 — Support
Clause 7 asks:
Does the organization have the people, infrastructure, knowledge, communication and documented information necessary to operate the FSMS?
7.1 Resources
Resources can include:
People
Adequately competent personnel.
Infrastructure
Such as:
- Buildings
- Production equipment
- Utilities
- Storage facilities
- IT systems
- Transportation arrangements
Work environment
Conditions necessary to support food-safety operations.
Monitoring and measuring resources
Where monitoring and measurement are required, suitable resources need to be available and appropriately controlled.
7.2 Competence
People performing work that affects food safety should have appropriate competence.
Competence may come from:
- Education
- Training
- Experience
- Skills
- Supervision
- Demonstrated capability
Example
A person responsible for monitoring a food-safety control should understand:
- What needs to be monitored
- How it is monitored
- The required limits/criteria
- What to do when monitoring indicates loss of control
- How to record results
Training should therefore be connected to actual responsibilities.
7.3 Awareness
Employees should understand relevant aspects of food safety, including the implications of not following applicable FSMS requirements.
This is where food-safety culture and employee behavior become important.
7.4 Communication
ISO 22000 places significant importance on communication.
External communication can include:
- Suppliers
- Customers
- Regulatory authorities
- Contractors
- Certification bodies
- Other food-chain organizations
Internal communication can include:
- Changes in processes
- Food-safety incidents
- New hazards
- Product changes
- Customer requirements
- Regulatory changes
- Monitoring results
Food safety depends heavily on timely and accurate information flow.
7.5 Documented Information
The FSMS needs appropriate documented information.
This may include:
- Policies
- Procedures
- Hazard-analysis information
- PRPs
- HACCP/OPRP plans
- Monitoring records
- Verification records
- Traceability records
- Internal audit records
- Management review records
- Corrective-action records
But documentation should be proportional to the organization’s needs.
The objective is not:
More documents.
The objective is:
Controlled information that supports safe and consistent operation.
Clause 7 — Auditor Evidence
| Area | Example Evidence |
|---|---|
| Competence | Training/qualification records |
| Awareness | Interviews |
| Infrastructure | Facility/equipment records |
| Monitoring resources | Calibration/verification evidence |
| Communication | Emails, meetings, notifications |
| Documented information | Controlled procedures and records |
Clause 8 — Operation
🔥 The Technical Heart of ISO 22000
Clause 8 is where the management system meets the actual food-safety operation.
It includes:
- Operational planning and control
- PRPs
- Traceability
- Emergency preparedness
- Hazard control
- Hazard analysis
- Validation
- HACCP/OPRP plan
- Monitoring
- Verification
- Product/process nonconformities
- Withdrawal and recall
ISO 22000’s operational structure specifically includes these elements.
8.1 Operational Planning and Control
The organization needs to plan, implement, control, maintain and update processes necessary to meet food-safety requirements.
This includes implementing actions identified during planning and controlling relevant operational changes.
Think of it as:
Plan → Implement → Control → Monitor → Update
8.2 Prerequisite Programmes — PRPs
PRPs provide the basic conditions and activities needed to support a hygienic environment suitable for safe food production and handling.
Examples may include:
- Cleaning and sanitation
- Pest control
- Personnel hygiene
- Waste management
- Utilities
- Equipment maintenance
- Storage
- Transportation
- Supplier controls
- Prevention of cross-contamination
- Facility hygiene
Important 2026 update
The ISO 22002 series was significantly restructured and updated in 2025.
ISO 22002-100:2025 provides common PRP requirements for the food, feed and packaging supply chain, while sector-specific documents address areas such as food manufacturing, catering, packaging, transport and storage. ISO
For food manufacturing specifically, ISO 22002-1:2025 specifies PRP requirements to be used with ISO 22002-100. ISO lists the previous ISO/TS 22002-1:2009 as withdrawn and ISO 22002-1:2025 as the published replacement. ISO
This is an important point for organizations implementing or updating their FSMS in 2026.
8.3 Traceability System
The organization needs a traceability system appropriate to its products and processes.
The objective is to establish relevant links between:
Input → Process → Output
For example:
Supplier
↓
Raw-material batch
↓
Production batch
↓
Finished product
↓
Customer/distribution
A traceability exercise should demonstrate that the system actually works.
8.4 Emergency Preparedness and Response
The organization should establish processes for responding to relevant emergencies and incidents that can affect food safety.
Possible scenarios include:
- Power failure
- Water contamination
- Fire
- Flood
- Refrigeration failure
- Equipment failure
- Product contamination
- Natural events
- Supply disruption
- Food-safety incident
The organization should not merely maintain a list of emergencies.
It should understand:
Who responds?
What is communicated?
What product is affected?
How is food safety protected?
How is the incident recorded?
What happens after the emergency?
8.5 Hazard Control
This is one of the most important sections in ISO 22000.
The organization needs to conduct systematic hazard analysis and establish appropriate control measures.
8.5.1 Preliminary Steps to Enable Hazard Analysis
Before performing hazard analysis, the organization needs appropriate information about:
- Products
- Raw materials
- Ingredients
- Product characteristics
- Intended use
- Process steps
- Process environment
- Existing PRPs
- Regulatory/customer requirements
8.5.1.4 Intended Use
The intended use of the product is important because the same hazard can have different implications depending on how the product is expected to be used.
Consider:
Ready-to-eat product
versus
Product intended to be cooked before consumption
The hazard-control analysis needs to reflect the intended use.
8.5.1.5 Process Description
The food-safety team should understand the actual process.
This can involve:
- Process flow
- Equipment
- Materials
- Contact surfaces
- Processing conditions
- Existing controls
- Process environment
- Seasonal variations
- Shift-related variations
The flow diagram should represent reality.
Auditor question:
“Can I walk through the production floor and see the same process described in your flow diagram?”
If the answer is no, the organization has a problem.
8.5.2 Hazard Analysis
Now comes the core food-safety analysis.
The organization should identify hazards that are reasonably expected to occur.
These may include:
Biological
- Pathogens
- Viruses
- Parasites
- Toxins
Chemical
- Cleaning chemicals
- Pesticide residues
- Chemical contaminants
- Naturally occurring toxins
Physical
- Glass
- Metal
- Stone
- Hard plastic
Other relevant hazards
Including allergen-related risks where applicable.
The hazard identification should be based on relevant information, experience, scientific and historical information, food-chain information and applicable statutory, regulatory and customer requirements. studylib.net
Hazard Assessment
Identifying a hazard does not automatically mean that it is a significant food-safety hazard requiring the same type of control.
The organization needs a defined methodology for evaluating hazards.
Factors can include:
Likelihood of occurrence
Severity of adverse health effects
→
Significance of the hazard
The organization should document the methodology and results.
Acceptable Levels
Where applicable, the organization needs to establish acceptable levels for identified food-safety hazards.
These levels need to consider relevant:
- Legal requirements
- Regulatory requirements
- Customer requirements
- Intended use
- Scientific information
- Other relevant information
The rationale should be documented.
8.5.2.4 Selection and Categorization of Control Measures
Once significant hazards are identified, appropriate control measures need to be selected.
This is where the food-safety team determines:
What control is required?
Where should it be applied?
How effective does it need to be?
How will it be monitored?
Control measures can then be categorized within the ISO 22000 framework, including through:
- PRPs
- OPRPs
- CCPs
PRP vs OPRP vs CCP
This is one of the most important concepts in ISO 22000.
| Element | Main Purpose | Typical Question |
|---|---|---|
| PRP | Establish basic hygienic/operational conditions | Is the environment suitable for safe food? |
| OPRP | Control a significant hazard through an operational prerequisite control | What operational control is necessary to prevent/reduce a significant hazard? |
| CCP | Control a significant hazard at a critical point | At what step is control essential and measurable against critical limits? |
Simplified model
PRPs
↓
Create the hygienic foundation
↓
Hazard Analysis
↓
Determine significant hazards
↓
OPRPs / CCPs
↓
Control significant hazards
↓
Monitoring + Verification
↓
Demonstrate control
The organization should use a defined methodology rather than simply labeling every important control as a CCP.
8.5.3 Validation of Control Measures
Before relying on a control measure or combination of control measures, the organization needs to establish that the measure is capable of achieving the intended level of control.
Example
Suppose a heat treatment is being used to control a microbiological hazard.
The organization needs evidence supporting the effectiveness of the specified control conditions.
This is different from routine monitoring.
Validation asks:
Will this control work?
Monitoring asks:
Are we applying the control as planned?
Verification asks:
Is the FSMS and its controls working as intended?
These three concepts should not be confused.
8.5.4 Hazard Control Plan — HACCP / OPRP Plan
The organization should establish an appropriate hazard-control plan.
The plan should identify relevant information such as:
- Hazard
- Control measure
- CCP or OPRP categorization
- Critical limits or action criteria, as applicable
- Monitoring
- Responsibilities
- Frequency
- Corrections/corrective actions
- Records
Example
| Process | Hazard | Control | Classification | Monitoring |
|---|---|---|---|---|
| Cooking | Biological | Controlled cooking condition | CCP | Temperature/time |
| Metal detection | Physical | Metal detector | CCP/appropriate control based on analysis | Challenge/monitoring |
| Cleaning | Cross-contamination | Sanitation programme | PRP/OPRP as determined | Inspection/testing |
These examples are illustrative only. The actual classification must come from the organization’s hazard analysis.
8.6 Updating Information Specifying PRPs and Hazard-Control Plan
Food-safety systems need to change when the organization changes.
Triggers can include:
- New raw materials
- New suppliers
- New equipment
- New products
- Process changes
- New hazards
- Incidents
- Regulatory changes
- Customer requirements
- Verification findings
When relevant information changes, the organization should review whether its PRPs and hazard-control plan also need updating.
8.7 Control of Monitoring and Measuring
Monitoring and measuring equipment used for food-safety controls needs appropriate management.
Depending on the equipment, this can involve:
- Calibration
- Verification
- Maintenance
- Identification
- Protection from damage
- Suitable measurement capability
Example
If temperature is a food-safety control, the organization needs confidence that the thermometer or temperature-monitoring system provides reliable information.
A completed temperature log is only useful if the measurement system itself is trustworthy.
8.8 Verification Related to PRPs and Hazard-Control Plan
Verification asks whether the FSMS controls are operating as intended.
Verification can involve:
- Review of monitoring records
- Inspection
- Testing
- Sampling
- Internal audits
- Analysis of results
- Review of PRP effectiveness
- Review of hazard-control performance
The difference:
Monitoring: What is happening now?
Verification: Is the control system working as intended?
Validation: Will the selected control work?
These distinctions are extremely important during an ISO 22000 audit.
8.9 Control of Product and Process Nonconformities
What happens when a food-safety control fails?
The organization needs processes for dealing with:
- Nonconforming products
- Process deviations
- Loss of control
- Potentially unsafe products
- Corrective action
The organization should determine appropriate action based on the food-safety implications.
Withdrawal and Recall
If a product that may be unsafe has entered the food chain, the organization may need an appropriate withdrawal or recall process.
This should answer:
Who decides?
Who communicates?
How are affected batches identified?
How are customers informed?
How is product controlled?
How is the effectiveness of the withdrawal/recall evaluated?
A mock recall/traceability exercise can be an excellent way to test whether the system actually works.
Clause 8 — The Auditor’s Evidence Chain
This is the part I recommend organizations memorize:
Hazard → Control → Monitoring → Deviation → Action → Verification
For example:
Hazard: Microbiological contamination
↓
Control: Validated process condition
↓
Monitoring: Defined monitoring frequency
↓
Deviation: Control parameter outside required condition
↓
Action: Correction/corrective action and product disposition
↓
Verification: Evidence that the control system remains effective
That is what turns a food-safety plan into an operating FSMS.
Clause 9 — Performance Evaluation
Once the FSMS is implemented, the organization needs to determine:
Is it actually working?
Clause 9 provides the performance-evaluation framework.
9.1 Monitoring, Measurement, Analysis and Evaluation
The organization should determine what needs to be:
- Monitored
- Measured
- Analyzed
- Evaluated
Examples can include:
- Food-safety objectives
- Monitoring results
- Verification results
- Nonconformities
- Customer complaints
- Supplier performance
- Audit findings
- Product testing
- Environmental monitoring, where applicable
The objective is not to collect data simply because it is available.
The organization should use relevant data to understand FSMS performance.
9.2 Internal Audit
Internal audit is one of the most important readiness activities.
The audit programme should consider:
- Importance of processes
- Changes affecting the organization
- Previous audit results
- Relevant requirements
The audit should determine whether the FSMS:
Conforms
and
Is effectively implemented and maintained.
A Strong ISO 22000 Internal Audit
A weak internal audit asks:
“Do you have a procedure?”
A stronger audit asks:
“Show me how this control operates.”
And then:
“Show me the evidence.”
And then:
“What happens when the control fails?”
And finally:
“How do you verify that the corrective action was effective?”
That is process-based auditing.
9.3 Management Review
Top management needs to review the FSMS at planned intervals to determine its continuing suitability, adequacy and effectiveness. SCS Global Services
Management review can consider:
- Previous review actions
- Changes in context
- Monitoring and measurement
- Verification results
- Nonconformities
- Corrective actions
- Internal/external audit results
- Regulatory/customer inspections
- External-provider performance
- Risks and opportunities
- Achievement of FSMS objectives
- Resource adequacy
- Emergency situations
- Incidents
- Withdrawal/recall
- Communication
- Complaints
- Improvement opportunities
The output should include decisions and actions concerning improvement and necessary updates or changes to the FSMS. SCS Global Services
Management Review Is Not:
“Management signed the minutes.”
Management Review Is:
Management evaluates FSMS performance and makes decisions.
Clause 10 — Improvement
Clause 10 closes the management-system loop.
It addresses:
- Nonconformity
- Corrective action
- Continual improvement
- FSMS updating
10.1 Nonconformity and Corrective Action
When a nonconformity occurs, the organization should:
1. React
Control and correct the issue.
2. Determine the cause
Understand why it happened.
3. Determine whether similar issues exist
Look beyond the individual incident.
4. Implement appropriate corrective action
Address the cause.
5. Review effectiveness
Determine whether the action worked.
6. Update the FSMS where necessary
Make appropriate changes.
Example: Repeated Temperature Deviation
Imagine a refrigerated food-storage area repeatedly exceeds the defined temperature requirement.
A weak response would be:
“Temperature corrected.”
A stronger FSMS response would ask:
What happened?
Temperature exceeded the required condition.
↓
What product was affected?
Identify affected batches.
↓
Why did it happen?
Equipment failure / monitoring failure / process issue.
↓
What immediate correction was taken?
Restore appropriate conditions and assess affected product.
↓
What corrective action is required?
Address the underlying cause.
↓
Was effectiveness verified?
Review subsequent monitoring data.
↓
Does the FSMS need updating?
Update controls if required.
That is continual-improvement thinking.
10.2 Continual Improvement
Continual improvement should be based on actual information.
Potential inputs include:
- Audit results
- Complaints
- Verification results
- Nonconformities
- Corrective actions
- Food-safety incidents
- Performance trends
- Management review
- New knowledge
- Changes in technology
- Supplier performance
The goal is not simply:
“Improve.”
It is:
Use evidence to identify where the FSMS can perform better and take appropriate action.
ISO 22000:2018 Clauses 4–10 — Complete Matrix
| Clause | Requirement Area | Main Question | Typical Evidence |
|---|---|---|---|
| 4 | Context | What affects our FSMS? | Context, interested parties, scope |
| 5 | Leadership | Who leads food safety? | Policy, roles, leadership evidence |
| 6 | Planning | What risks/objectives/change need management? | Risk assessment, objectives, change planning |
| 7 | Support | Do we have resources and competence? | Training, infrastructure, communication, documents |
| 8 | Operation | How do we control food-safety hazards? | PRPs, hazard analysis, HACCP/OPRP plan, monitoring |
| 9 | Performance Evaluation | Is the FSMS working? | KPI analysis, verification, internal audit, management review |
| 10 | Improvement | How do we correct and improve? | NC, CAPA, improvement records |
ISO 22000 Auditor Evidence Chain
A certification audit should ultimately connect the requirements to actual evidence.
Requirement
What does the FSMS require?
↓
Process
How does the organization implement it?
↓
Personnel
Who performs the activity?
↓
Control
What prevents or controls the food-safety hazard?
↓
Monitoring
How is the control monitored?
↓
Record
What evidence is retained?
↓
Verification
How does the organization confirm effectiveness?
↓
Corrective Action
What happens when the control fails?
↓
Improvement
What did the organization learn and change?
This is the difference between a documented FSMS and an implemented FSMS.
PRP → OPRP → CCP: The Relationship Explained
One of the most searched and misunderstood areas of ISO 22000 is the relationship between PRP, OPRP and CCP.
A practical conceptual model is:
PRPs
Create the basic hygienic environment.
Examples: cleaning, pest control, personnel hygiene, maintenance.
↓
Hazard Analysis
Identify and evaluate food-safety hazards.
↓
Significant Hazards
Determine which hazards require specific control.
↓
Control Measures
Select appropriate measures.
↓
Categorization
Determine the appropriate control framework, including OPRPs and CCPs as applicable.
↓
Monitoring
Establish monitoring methods and criteria.
↓
Verification
Confirm that controls operate effectively.
This is why hazard analysis should come before simply labeling controls as CCPs.
ISO 22000:2018 vs ISO 22002-1:2025
This distinction is increasingly important in 2026.
ISO 22000:2018
Provides the overall Food Safety Management System requirements.
ISO 22002-100:2025
Provides common PRP requirements for the food, feed and packaging supply chain.
ISO 22002-1:2025
Provides PRP requirements specifically for food manufacturing, used in conjunction with ISO 22002
Other 2025 ISO 22002 documents include sector-specific PRPs
The ISO catalogue lists published 2025 documents covering areas such as:
- Catering
- Food packaging manufacturing
- Transport and storage
- Feed and animal food production
The ISO food-safety committee also lists these as part of the updated ISO 22002 series.
Therefore:
ISO 22000 = FSMS
ISO 22002 series = PRP framework supporting food-safety controls
They should not be treated as interchangeable standards.
Common Clause-Level Implementation Mistakes
1. Weak Scope
The FSMS scope does not clearly reflect the actual food processes.
2. Generic Context Analysis
Organizations copy a generic SWOT/PESTLE document without connecting it to food safety.
3. Food Safety Policy With No Awareness
Employees cannot explain what the policy means for their work.
4. Food Safety Team Without Real Competence
People are appointed but lack relevant knowledge.
5. PRPs Copied From Another Company
PRPs do not reflect the actual facility or process.
6. Hazard Analysis Based on Templates
Hazards are copied instead of being evaluated from the organization’s real products and processes.
7. Too Many CCPs
Every important control is labeled a CCP.
8. Weak Monitoring
Monitoring forms are completed but deviations are not properly handled.
9. No Traceability Test
The organization has a traceability procedure but has never tested it.
10. Internal Audit Becomes a Checklist
The auditor checks documents instead of examining process effectiveness.
11. Management Review Becomes a Formal Meeting
Management signs minutes without analyzing performance.
12. Corrective Action Stops at Correction
The organization fixes the immediate problem but never addresses the underlying cause.
Consultant’s Insight
The strongest ISO 22000 systems connect the management system to the production floor.
If your FSMS exists in a computer folder but employees cannot explain the controls, the system is not mature.
If your HACCP plan identifies a hazard but the production team does not understand the control, the system is weak.
If monitoring records are completed but deviations are ignored, the system is weak.
If internal audits identify problems but management does not act, the system is weak.
A mature ISO 22000 system creates a continuous chain:
Leadership → Food-Safety Team → Hazard Analysis → Controls → Monitoring → Verification → Audit → Management Review → Corrective Action → Improvement
That is the real architecture of an effective FSMS.
ISO 22000 Certification Readiness — Clause-by-Clause Quick Check
Before moving toward certification, ask:
Clause 4
☑ Is the FSMS scope clear?
☑ Have relevant internal/external issues been identified?
☑ Have interested parties been identified?
☑ Has climate-change relevance been considered where applicable?
Clause 5
☑ Is top management involved?
☑ Is the food-safety policy established?
☑ Are responsibilities defined?
☑ Is the food-safety team competent?
Clause 6
☑ Are FSMS risks/opportunities addressed?
☑ Are objectives established?
☑ Are changes planned?
Clause 7
☑ Are people competent?
☑ Is awareness demonstrated?
☑ Is communication effective?
☑ Is documented information controlled?
Clause 8
☑ Are PRPs implemented?
☑ Is traceability functional?
☑ Is emergency preparedness established?
☑ Is hazard analysis completed?
☑ Are control measures validated?
☑ Are HACCP/OPRP plans implemented?
☑ Is monitoring effective?
☑ Is verification performed?
☑ Are nonconforming products controlled?
☑ Is withdrawal/recall capability tested?
Clause 9
☑ Are performance results evaluated?
☑ Has internal audit been completed?
☑ Has management review been conducted?
Clause 10
☑ Are nonconformities addressed?
☑ Is root-cause analysis appropriate?
☑ Is corrective-action effectiveness verified?
☑ Is continual improvement demonstrated?
The ISO 22000 Management System in One Diagram
CONTEXT
What affects food safety?
↓
LEADERSHIP
Who is responsible?
↓
PLANNING
What risks and objectives matter?
↓
SUPPORT
Do we have people, resources and knowledge?
↓
OPERATION
How are hazards controlled?
↓
PRPs + HAZARD ANALYSIS + OPRPs + CCPs + TRACEABILITY
↓
PERFORMANCE EVALUATION
Is the system working?
↓
MONITORING + VERIFICATION + INTERNAL AUDIT + MANAGEMENT REVIEW
↓
IMPROVEMENT
What needs to change?
↓
CORRECTIVE ACTION + CONTINUAL IMPROVEMENT
↓
A STRONGER FSMS

How do you actually implement ISO 22000:2018 in an organization?
An effective Food Safety Management System cannot be created by simply purchasing a set of procedures, preparing a HACCP plan and scheduling a certification audit.
The implementation needs to connect:
Organization → Food Chain → Processes → Hazards → Controls → Monitoring → Verification → Audit → Management Review → Improvement
ISO 22000:2018 is the current published edition, and ISO says it remains current following its 2023 review. It has Amendment 1:2024 on climate-action changes. ISO/DIS 22000 is currently under development as the future revision, so organizations planning certification in 2026 should distinguish the current certifiable standard from the draft revision.
This guide provides a practical implementation roadmap for food manufacturers, processors, packaging organizations, catering businesses, warehouses, distributors and other organizations within the food chain.
How do you implement ISO 22000:2018?
ISO 22000:2018 implementation normally begins by defining the FSMS scope and conducting a gap analysis against the organization’s existing food-safety practices. The organization then establishes its food-safety team, context, interested-party requirements, policy, objectives and prerequisite programmes (PRPs). The food-safety team maps processes, identifies hazards, conducts hazard analysis and establishes appropriate control measures through the organization’s hazard-control plan. The FSMS is then implemented through training, operational controls, monitoring, traceability, verification and documented evidence.
After implementation, the organization conducts internal audits, addresses nonconformities, performs management review and evaluates certification readiness. A competent independent certification body can then audit the FSMS for certification. ISO itself does not perform certification; certification is carried out by independent certification bodies.
The ISO 22000 Implementation Journey
A practical implementation model is:
1. Define
FSMS Scope
↓
2. Understand
Context & Interested Parties
↓
3. Assess
Gap Analysis
↓
4. Organize
Food Safety Team
↓
5. Establish
PRPs
↓
6. Analyze
Food-Safety Hazards
↓
7. Control
OPRPs / CCPs / Hazard-Control Plan
↓
8. Implement
Processes & Training
↓
9. Monitor
Food-Safety Performance
↓
10. Verify
Controls & FSMS
↓
11. Audit
Internal Audit
↓
12. Review
Management Review
↓
13. Improve
Corrective Action
↓
14. Prepare
Certification Readiness
↓
15. Certify
Third-Party Certification Audit
↓
16. Maintain
Continual Improvement
Step 1 — Define the FSMS Scope
Before creating procedures, determine:
What exactly is the Food Safety Management System going to cover?
The scope should reflect the organization’s actual activities, products, processes, locations and relevant food-chain boundaries.
For example:
Food Manufacturer
Manufacture and packaging of ready-to-eat food products at the organization’s defined production facility.
The actual scope should be developed based on the organization’s operations rather than copied from another company.
Questions to Ask
- Which products are covered?
- Which production lines are covered?
- Which locations are covered?
- Which processes are included?
- Are storage activities included?
- Are transportation activities included?
- Which outsourced processes affect food safety?
- Which food-chain categories apply?
- Are there justified exclusions?
A clearly defined scope becomes the foundation for the rest of the FSMS.
Step 2 — Understand the Organization and Its Food Chain
The organization should understand its internal and external context.
Consider:
Internal
- People
- Processes
- Infrastructure
- Equipment
- Competence
- Food-safety culture
- Existing controls
- Organizational structure
External
- Customers
- Regulators
- Suppliers
- Market requirements
- Technology
- Supply-chain conditions
- Environmental conditions
- Applicable legislation
- Industry developments
The 2024 climate-action amendment also means organizations should consider whether climate change is relevant to their FSMS context and relevant interested-party requirements.
Step 3 — Identify Interested Parties
Food safety is not controlled by one department.
Relevant interested parties may include:
- Consumers
- Customers
- Suppliers
- Regulatory authorities
- Employees
- Contractors
- Distributors
- Retailers
- Certification bodies
- Owners
- Industry organizations
For each relevant interested party, ask:
What do they require?
Is the requirement relevant to food safety?
How is it controlled?
What evidence demonstrates conformity?
Step 4 — Conduct an ISO 22000 Gap Analysis
This is one of the most important stages of implementation.
A gap analysis compares:
Current State
against
ISO 22000 Requirements
Example
| Area | Current Situation | Requirement | Gap | Action |
|---|---|---|---|---|
| FSMS scope | Informal | Defined scope | Yes | Establish scope |
| PRPs | Existing | Controlled PRPs | Partial | Review/update |
| Hazard analysis | HACCP available | ISO 22000 methodology | Partial | Reassess |
| Traceability | Basic | Effective system | Partial | Test system |
| Internal audit | Informal | Planned audit programme | Yes | Establish |
| Management review | Not formal | Management review | Yes | Implement |
The gap analysis should not be used simply to produce a long checklist.
It should answer:
What is already working, what is missing, what needs improvement and what should be prioritized?
Step 5 — Establish the Food Safety Team
ISO 22000 implementation requires appropriate food-safety knowledge and competence.
The food-safety team may include people from:
- Quality
- Production
- Food technology
- Microbiology
- Engineering
- Maintenance
- Procurement
- Warehouse
- Sanitation
- Regulatory/compliance
The exact structure depends on the organization.
Important point
The food-safety team should not exist only on paper.
Its members should actually participate in:
- Hazard analysis
- PRP evaluation
- Control-measure selection
- Verification
- FSMS review
- Food-safety decisions
Step 6 — Establish the Food Safety Policy
Top management should establish an appropriate food-safety policy.
The policy should connect to the organization’s:
- Purpose
- Food-safety responsibilities
- Applicable requirements
- Objectives
- Continual improvement
But there is a critical implementation test:
Ask an employee:
“What does our food-safety policy mean for your job?”
If the answer is:
“I don’t know.”
the organization has a communication and awareness gap.
Step 7 — Establish Food-Safety Objectives
Objectives should be connected to measurable food-safety performance.
Examples could include:
- Reduce repeat food-safety nonconformities.
- Improve traceability exercise performance.
- Improve completion of food-safety training.
- Reduce supplier-related food-safety deviations.
- Improve sanitation verification performance.
- Improve corrective-action closure.
- Improve complaint-response performance.
The actual objectives should reflect the organization’s risks and priorities.
Step 8 — Establish and Review PRPs
PRPs form the foundation for hygienic food operations.
Depending on the organization’s activities, PRPs may address:
- Building and facility hygiene
- Equipment
- Cleaning and sanitation
- Pest control
- Personnel hygiene
- Utilities
- Waste management
- Storage
- Transportation
- Supplier controls
- Cross-contamination prevention
- Maintenance
- Food-contact surfaces
- Temperature control
Important 2026 Update
The PRP landscape has changed significantly.
ISO 22002-100:2025 establishes common PRP requirements for the food, feed and packaging supply chain. Sector-specific standards then provide additional requirements for specific activities
For food manufacturing, ISO 22002-1:2025 is the current published PRP standard for food manufacturing and is intended to be used with ISO 22002-100. ISO lists the previous ISO/TS 22002-1:2009 as withdrawn
This means a food manufacturer updating its FSMS in 2026 should review its PRP framework against the current ISO 22002 series, rather than automatically continuing to rely on an old 2009 PRP document.
Step 9 — Map the Food-Safety Processes
Now move from documents to actual operations.
Map the organization’s process from beginning to end.
For a food manufacturer, this could look like:
Supplier Approval
↓
Raw Material Receipt
↓
Inspection
↓
Storage
↓
Preparation
↓
Processing
↓
Cooking / Treatment
↓
Cooling
↓
Packaging
↓
Metal Detection / Inspection
↓
Finished Product Storage
↓
Dispatch
↓
Customer
The exact flow depends on the organization.
Step 10 — Develop and Verify the Process Flow Diagram
The flow diagram should reflect the actual process.
The food-safety team should verify it on-site.
Walk the floor.
Compare:
Documented Flow
with
Actual Flow
Look for:
- Additional process steps
- Rework
- Temporary storage
- Cross-connections
- Waste flows
- Personnel movement
- Material movement
- Cleaning activities
- Outsourced activities
- Process deviations
A flow diagram that looks correct on paper but does not represent the actual production process creates problems during hazard analysis.
Step 11 — Define Product Characteristics and Intended Use
The food-safety team should understand the product.
Relevant information can include:
- Ingredients
- Physical characteristics
- Chemical characteristics
- Biological characteristics
- Processing method
- Packaging
- Storage conditions
- Shelf life
- Distribution conditions
- Intended use
- Intended consumer
Why does intended use matter?
Consider:
Ready-to-eat product
versus
Product that must be cooked before consumption.
The hazard assessment and controls need to reflect how the product will actually be used.
Step 12 — Conduct Hazard Analysis
Now the core technical food-safety work begins.
For each relevant process step, ask:
What hazards could occur?
Biological
→ pathogens, viruses, parasites, toxins
Chemical
→ chemical contamination, residues, toxins
Physical
→ metal, glass, stone, hard plastic
Allergen-related
→ cross-contact or incorrect allergen control, where relevant
Then ask:
How likely is the hazard?
How severe could the consequence be?
Is the hazard significant?
What controls are required?
Step 13 — Establish Control Measures
Once significant hazards are identified, appropriate control measures need to be established.
The food-safety team determines whether controls are managed through:
- PRPs
- OPRPs
- CCPs
The classification must result from the organization’s hazard analysis and defined methodology.
Simplified example
Hazard
Biological contamination
↓
Control
Validated heat treatment
↓
Classification
Could be a CCP where the hazard analysis establishes that the step meets the relevant criteria.
↓
Monitoring
Temperature + time
↓
Deviation
Required condition not achieved
↓
Action
Correction + product evaluation + corrective action as appropriate
↓
Verification
Evidence that the control remains effective
Step 14 — Establish the HACCP / OPRP Plan
The hazard-control plan should define how significant hazards are controlled.
Depending on the applicable control, the plan may establish:
- Hazard
- Control measure
- Control classification
- Critical limits or action criteria
- Monitoring method
- Monitoring frequency
- Responsibility
- Correction
- Corrective action
- Records
- Verification
Important
Do not simply create a HACCP table because a certification auditor expects one.
The hazard-control plan should represent the organization’s actual food-safety control strategy.
Step 15 — Validate Control Measures
Validation asks:
Can this control actually achieve the intended food-safety outcome?
For example, where a process condition is being relied upon to control a microbiological hazard, the organization needs appropriate evidence that the control is capable of achieving the intended result.
Validation may involve relevant:
- Scientific information
- Technical studies
- Process data
- Historical evidence
- Testing
- Specialist knowledge
Remember:
Validation ≠ Monitoring
Validation:
Will the control work?
Monitoring:
Are we applying the control?
Verification:
Is the system operating effectively?
Step 16 — Establish Monitoring
Once controls are established, define:
- What is monitored?
- Who monitors it?
- How is it monitored?
- How often?
- What criteria apply?
- What happens when results are outside requirements?
- What records are maintained?
Example
Control: Refrigerated storage
Monitoring: Temperature
Frequency: Defined by the organization
Responsible person: Assigned employee
Deviation: Temperature outside established criteria
Action: Defined response and product evaluation
The actual criteria must be established according to the organization’s hazard analysis and applicable requirements.
Step 17 — Establish Traceability
Traceability should connect relevant inputs and outputs.
Example
Supplier
→ Raw-material batch
→ Production batch
→ Finished-product batch
→ Dispatch
→ Customer
A good implementation should be capable of answering:
“Where did this material come from?”
and:
“Where did this finished product go?”
Step 18 — Conduct a Traceability / Mock Recall Exercise
Do not wait for a real incident to discover whether the traceability system works.
Conduct a controlled exercise.
For example:
Scenario
A raw-material batch is suspected of being unsafe.
Can the organization identify:
- Supplier?
- Receipt date?
- Batch number?
- Production batches affected?
- Quantity produced?
- Quantity in stock?
- Quantity dispatched?
- Customers affected?
- Actions required?
Then measure:
How quickly can the organization reconstruct the chain?
The exercise should generate learning and improvement opportunities.
Step 19 — Establish Emergency Preparedness
Identify relevant food-safety emergency scenarios.
Depending on the organization, these could include:
- Power failure
- Refrigeration failure
- Flooding
- Fire
- Water contamination
- Equipment breakdown
- Product contamination
- Supply-chain disruption
- Utility failure
- Food-safety incident
For each relevant scenario, determine:
Who responds?
What product could be affected?
What immediate controls are required?
Who must be informed?
How is the incident documented?
How is recovery managed?
Step 20 — Implement the FSMS
Now move from system design to actual implementation.
This means people should start using:
- Procedures
- Work instructions
- Monitoring records
- Cleaning records
- Inspection records
- Traceability records
- Supplier controls
- Hazard-control records
- Verification records
- Corrective-action processes
The golden rule:
If the process is not actually being followed, the document does not demonstrate implementation.
Step 21 — Training and Awareness
Training should be role-specific.
Production employees
Need to understand relevant operational controls.
Food-safety team
Needs deeper competence in hazard analysis and FSMS requirements.
Warehouse employees
Need to understand storage, identification, segregation and traceability controls.
Procurement
Needs to understand relevant supplier and material requirements.
Maintenance
Needs to understand how maintenance activities can affect food safety.
Management
Needs to understand FSMS performance and responsibilities.
Step 22 — Start Collecting Objective Evidence
An implemented FSMS generates evidence.
Examples:
- Monitoring records
- Verification records
- Training records
- Supplier evaluations
- Inspection reports
- Cleaning records
- Calibration/verification records
- Traceability tests
- Complaint records
- Nonconformity records
- Corrective actions
- Internal audit reports
- Management review records
The objective is not to generate paperwork.
The objective is to generate evidence of controlled processes.
Step 23 — Monitor FSMS Performance
Establish appropriate performance indicators.
Potential indicators include:
- Food-safety incidents
- Customer complaints
- Supplier nonconformities
- Internal audit findings
- Corrective-action closure
- Traceability exercise performance
- Training completion
- Verification results
- Product-testing trends
- PRP verification results
Do not measure everything.
Measure what helps management understand whether the FSMS is performing.
Step 24 — Conduct Internal Audit
The internal audit should evaluate:
Conformity
Does the FSMS meet the applicable requirements?
Implementation
Are the processes actually being followed?
Effectiveness
Are the controls achieving their intended outcomes?
Evidence
Can the organization demonstrate this objectively?
How to Conduct a Strong ISO 22000 Internal Audit
Instead of:
“Show me the procedure.”
Use:
“Show me how this process operates.”
Then:
“Show me the monitoring evidence.”
Then:
“What happens when there is a deviation?”
Then:
“Show me the corrective action.”
Then:
“How did you verify effectiveness?”
This creates a process-based audit.
Step 25 — Correct Nonconformities
Internal audits will identify issues.
Do not simply close them by writing:
“Training given.”
Ask:
What happened?
Why did it happen?
Is it an isolated issue?
Could it happen elsewhere?
What correction is required?
What corrective action is required?
How will effectiveness be verified?
This creates a stronger corrective-action system.
Step 26 — Conduct Management Review
Top management should review FSMS performance.
Inputs can include:
- Audit results
- Food-safety incidents
- Customer complaints
- Verification results
- Supplier performance
- Objectives
- Corrective actions
- Changes in context
- Risks and opportunities
- Resource requirements
- Regulatory developments
- Emergency events
- Improvement opportunities
Management review should result in meaningful decisions and actions.
Examples
Management may decide to:
- Invest in new equipment
- Increase training
- Change a supplier
- Modify a process
- Increase verification
- Improve infrastructure
- Change objectives
- Update the FSMS
That is much more meaningful than simply signing meeting minutes.
Step 27 — Certification Readiness Review
Before contacting the certification body for the formal audit, conduct a final readiness review.
Ask:
Scope
☑ Is the FSMS scope finalized?
Context
☑ Have relevant issues and interested parties been addressed?
Leadership
☑ Is management actively involved?
PRPs
☑ Are PRPs implemented?
Hazard Analysis
☑ Is hazard analysis complete?
Control Measures
☑ Are OPRPs/CCPs appropriately established?
Monitoring
☑ Are monitoring records available?
Verification
☑ Is verification effective?
Traceability
☑ Has traceability been tested?
Emergency Preparedness
☑ Has the organization tested relevant response arrangements?
Internal Audit
☑ Has an effective internal audit been completed?
Corrective Action
☑ Have significant findings been addressed?
Management Review
☑ Has management review been completed?
Objective Evidence
☑ Can the organization demonstrate implementation?
If several answers are “No,” the organization should address the gaps before the certification audit.
Step 28 — Select an Independent Certification Body
This is an important distinction:
ISO does not issue ISO 22000 certificates.
ISO develops and publishes the standard.
Certification is performed by independent certification bodies.
ISO specifically states that organizations choosing certification should find a reputable third-party certification body
When selecting a certification body, consider:
- Accreditation status
- Relevant food-sector competence
- Scope of accreditation
- Auditor competence
- Geographic coverage
- Certification process
- Audit duration
- Fees
- Sector experience
- Client references where appropriate
For organizations seeking accredited certification, verify the certification body’s accreditation and scope rather than selecting solely on price.
Step 29 — Certification Audit
The certification audit is generally conducted in stages.
The certification body establishes the applicable audit programme and requirements.
A typical certification process involves:
Stage 1
Assessment of readiness and documented/system information.
The auditor may evaluate:
- FSMS scope
- Context
- Documentation
- Process understanding
- Site readiness
- Hazard-control approach
- Audit planning
Stage 2
A more detailed assessment of the implemented FSMS.
The auditor may examine:
- Actual production/process activities
- PRPs
- Hazard analysis
- HACCP/OPRP controls
- Monitoring
- Traceability
- Employee competence
- Records
- Internal audit
- Management review
- Corrective actions
The exact audit arrangements and duration depend on the certification body’s applicable rules, organization size, complexity, sites, processes and other factors.
Step 30 — Certification Decision
Following the audit, the certification body evaluates the audit results and any nonconformities according to its certification process.
The organization may need to:
- Correct nonconformities
- Provide root-cause analysis
- Submit corrective-action evidence
- Demonstrate effectiveness where required
Certification is issued only through the certification body’s conformity-assessment process.
Step 31 — Maintain the FSMS After Certification
Certification is not the end.
It is the beginning of maintaining the management system.
The organization should continue:
Monitor
↓
Audit
↓
Review
↓
Correct
↓
Improve
↓
Maintain
The certification body will also conduct ongoing surveillance/reassessment activities according to the applicable certification programme.
Therefore:
An ISO 22000 certificate should never become a reason to stop improving the FSMS.
ISO 22000 Implementation Timeline
There is no single universal implementation duration.
The timeline depends on:
- Organization size
- Number of sites
- Product complexity
- Existing HACCP system
- Existing PRPs
- Existing ISO management systems
- Number of employees
- Process complexity
- Food-safety hazards
- Regulatory requirements
- Documentation maturity
- Availability of internal resources
- Scope of certification
Indicative implementation model
| Phase | Typical Activity |
|---|---|
| Phase 1 | Scope + Gap Analysis |
| Phase 2 | Context + Food Safety Team |
| Phase 3 | PRPs + Process Mapping |
| Phase 4 | Hazard Analysis + Control Measures |
| Phase 5 | Documentation + Implementation |
| Phase 6 | Training + Monitoring |
| Phase 7 | Verification + Traceability |
| Phase 8 | Internal Audit |
| Phase 9 | Corrective Action |
| Phase 10 | Management Review |
| Phase 11 | Certification Readiness |
| Phase 12 | Certification Audit |
For a relatively straightforward organization with an established HACCP/food-safety system, implementation can be significantly faster than for an organization starting from the beginning.
Therefore, it is better to determine the timeline after the gap analysis rather than promise a fixed number of days to every organization.
ISO 22000 Certification Cost — What Determines the Price?
There is no single ISO 22000 certification price applicable to every organization.
Cost can involve two different components:
1. Implementation / Consultancy Cost
Potential factors:
- Scope
- Number of sites
- Employee count
- Existing FSMS maturity
- HACCP maturity
- PRP status
- Process complexity
- Documentation requirements
- Training requirements
- Internal audit support
- Management-review support
- Certification-readiness support
2. Certification Body Cost
The certification body’s fee can depend on factors such as:
- Number of employees
- Number of sites
- Complexity
- Food-chain category
- Audit duration
- Certification programme
- Travel
- Surveillance requirements
Important:
Consultancy fee ≠ certification fee.
They are separate commercial components.
ISO 22000 + ISO 9001 Integration
Many food organizations already operate or plan to operate an ISO 9001 Quality Management System.
Because ISO 22000 uses the common ISO management-system structure, integration can be practical.
Shared processes may include:
- Context
- Interested parties
- Leadership
- Policy
- Objectives
- Document control
- Competence
- Internal audit
- Management review
- Corrective action
- Continual improvement
Food-safety-specific processes include:
- PRPs
- Hazard analysis
- HACCP/OPRP controls
- Food-safety verification
- Traceability
- Food-safety emergency response
Therefore:
ISO 9001
Quality
ISO 22000
Food Safety
can form an integrated management-system structure.
ISO 22000 + ISO 9001 + ISO 14001 + ISO 45001
For larger food-processing organizations, multiple management systems may be integrated.
For example:
| Standard | Primary Focus |
|---|---|
| ISO 9001 | Quality |
| ISO 22000 | Food Safety |
| ISO 14001 | Environment |
| ISO 45001 | Occupational Health & Safety |
The opportunity is to share common management-system processes while retaining the technical controls specific to each standard.
This can reduce unnecessary duplication where the processes genuinely overlap.
ISO 22000 vs FSSC 22000 — Implementation Decision
An organization considering food-safety certification may encounter both:
ISO 22000
and
FSSC 22000
They should not be treated as identical certification routes.
ISO 22000 is the international FSMS standard.
FSSC 22000 is a separate certification scheme that builds on ISO 22000 with additional requirements and applicable PRP standards.
The right route depends on factors such as:
- Customer requirements
- Market expectations
- Sector
- Supply-chain requirements
- Certification objective
- Applicable scheme requirements
Therefore, the organization should determine its intended certification route before designing the entire implementation programme.
ISO 22000 Implementation for Different Food Businesses
Food Manufacturer
Focus areas:
PRPs + HACCP + OPRPs/CCPs + Traceability + Process Controls
Restaurant / Catering
Focus areas:
Food handling + Hygiene + Storage + Preparation + Temperature Control + Allergen Management + Cleaning
The applicable PRP framework should reflect the sector. ISO’s updated 22002 series includes a 2025 catering PRP standard
Food Warehouse
Focus areas:
Storage + Temperature + Pest Control + Segregation + Traceability + Dispatch
Food Packaging Manufacturer
Focus areas:
Food-contact materials + Contamination Control + Hygiene + Traceability + Supplier Control
ISO’s updated 22002 series includes ISO 22002-4:2025 for food packaging manufacturing
Food Transport & Storage
Focus areas:
Temperature + Hygiene + Vehicle/Facility Conditions + Product Integrity + Traceability
The updated ISO 22002 series includes sector-specific PRP requirements for transport and storage
A Practical ISO 22000 Documentation Structure
Documentation should be designed around the organization’s actual system.
A practical structure can include:
Level 1 — FSMS Framework
- FSMS scope
- Food-safety policy
- Context
- Interested parties
- Process interaction
Level 2 — System Procedures
- Document control
- Internal audit
- Corrective action
- Management review
- Communication
- Competence
Level 3 — Food-Safety Controls
- PRPs
- Hazard analysis
- Hazard-control plan
- Traceability
- Emergency preparedness
- Product withdrawal/recall
- Verification
Level 4 — Operational Records
- Monitoring records
- Inspection records
- Cleaning records
- Training records
- Verification records
- Traceability records
- Audit records
- Corrective-action records
The actual documentation structure should be tailored to the organization.
The Biggest ISO 22000 Implementation Mistake
Starting With Documents Instead of Food Safety
A weak implementation model looks like:
Buy Templates
↓
Modify Documents
↓
Print Procedures
↓
Fill Forms
↓
Call Auditor
A stronger model is:
Understand Organization
↓
Define Scope
↓
Map Processes
↓
Identify Hazards
↓
Establish PRPs
↓
Determine Controls
↓
Implement
↓
Monitor
↓
Verify
↓
Audit
↓
Review
↓
Improve
↓
Certification
The 5-Layer ISO 22000 Implementation Model
At CK Associates, a practical way to explain implementation is through five connected layers:
Layer 1 — MANAGEMENT
Leadership + Policy + Objectives + Resources
↓
Layer 2 — FOUNDATION
PRPs + Infrastructure + Hygiene + Competence
↓
Layer 3 — HAZARD CONTROL
Hazard Analysis + OPRPs + CCPs + HACCP
↓
Layer 4 — ASSURANCE
Monitoring + Verification + Traceability + Internal Audit
↓
Layer 5 — IMPROVEMENT
Corrective Action + Management Review + Continual Improvement
When these five layers work together, the FSMS becomes much more than a certification file.
ISO 22000 Certification Readiness Checklist
Before the certification audit, verify:
Organization
☑ FSMS scope defined
☑ Context established
☑ Interested parties identified
☑ Applicable requirements identified
Leadership
☑ Food-safety policy established
☑ Responsibilities defined
☑ Food-safety team established
☑ Management commitment demonstrated
Planning
☑ Risks and opportunities addressed
☑ Objectives established
☑ Change planning established
PRPs
☑ Applicable PRPs implemented
☑ PRP verification performed
☑ Current applicable PRP standards reviewed
Hazard Analysis
☑ Product characteristics documented
☑ Intended use identified
☑ Process flow verified
☑ Hazards identified
☑ Hazard significance evaluated
☑ Control measures established
☑ OPRPs/CCPs appropriately determined
☑ Control measures validated where required
Operation
☑ Monitoring implemented
☑ Traceability implemented
☑ Emergency preparedness established
☑ Nonconforming-product controls established
☑ Withdrawal/recall process established
Performance Evaluation
☑ Monitoring results evaluated
☑ Verification completed
☑ Internal audit completed
☑ Management review completed
Improvement
☑ Nonconformities addressed
☑ Corrective actions implemented
☑ Effectiveness verified
☑ Continual improvement demonstrated
Consultant’s Insight
The certification audit should not be the first time the organization discovers whether its FSMS works.
A mature organization should test itself before the certification body arrives.
Ask:
If an auditor walked into our production area tomorrow, could our employees explain the controls that affect food safety?
Then ask:
Could we demonstrate the evidence?
Then:
Could we show what happens when a control fails?
And finally:
Could management demonstrate what has been improved as a result of monitoring, audits, incidents and feedback?
If the answer is yes, the organization is moving toward a functioning FSMS rather than simply preparing for a certificate.
ISO 22000:2018 — The Complete Implementation Cycle
DEFINE
Scope
↓
UNDERSTAND
Context + Interested Parties
↓
ASSESS
Gap Analysis
↓
BUILD
Food Safety Team + PRPs
↓
ANALYZE
Hazards
↓
CONTROL
PRPs + OPRPs + CCPs
↓
IMPLEMENT
Processes + Training
↓
MONITOR
Operational Controls
↓
VERIFY
Evidence + Testing + Review
↓
AUDIT
Internal Audit
↓
CORRECT
Nonconformities
↓
REVIEW
Management Review
↓
IMPROVE
FSMS
↓
CERTIFICATION
Independent Certification Body
↓
MAINTAIN
Surveillance + Continual Improvement
2026 ISO 22000 Update — What Organizations Should Watch
There are two important developments organizations should keep on their radar.
Current ISO 22000
ISO 22000:2018 + Amendment 1:2024
This remains the published standard. ISO says ISO 22000:2018 was reviewed and confirmed in 2023
Future ISO 22000 Revision
ISO/DIS 22000
The revision is currently under development. ISO’s current project page identifies it as a Draft International Standard intended to replace ISO 22000:2018. Its development has progressed through the enquiry stage, but it is not yet the published replacement standard
Updated PRP Framework
The ISO 22002 series was updated in 2025, including ISO 22002-100:2025 and sector-specific documents such as ISO 22002-1:2025 for food manufacturing
Therefore, organizations implementing ISO 22000 in 2026 should make sure their PRP framework reflects the applicable current requirements rather than relying automatically on legacy documents.
Frequently Asked Questions
How long does ISO 22000 implementation take?
There is no universal timeline. Duration depends on the organization’s size, number of sites, existing HACCP/FSMS maturity, product complexity, PRPs, hazard profile, resources and certification scope. A gap analysis is the appropriate starting point for developing a realistic implementation schedule.
How much does ISO 22000 certification cost?
The cost varies according to implementation scope, organization size, complexity, number of sites, existing systems, consultancy requirements and certification-body audit requirements. Consultancy and certification-body fees are separate costs.
Can an organization implement ISO 22000 without a consultant?
Yes. ISO 22000 does not require the use of a consultant. An organization can develop and implement its FSMS using internal and/or external resources, provided it can meet the applicable requirements.
Does ISO provide ISO 22000 certification?
No. ISO develops and publishes the standard but does not conduct certification. Organizations seeking certification use an independent certification body
Can ISO 22000 be integrated with ISO 9001?
Yes. ISO 22000 follows the common ISO management-system structure and ISO explicitly notes that it can be integrated into existing management processes, including systems such as ISO 9001
Is HACCP required for ISO 22000?
ISO 22000 integrates the principles of HACCP into the FSMS. The hazard-control framework must therefore be established in accordance with the standard and the organization’s actual food-safety hazards.
What is the role of PRPs in ISO 22000?
PRPs establish the foundational hygienic and operational conditions needed to support food safety. For food manufacturing, ISO 22002-1:2025 is the current sector-specific PRP standard used with ISO 22002-100:2025
Is ISO 22000:2018 still valid in 2026?
Yes. ISO currently lists ISO 22000:2018 as the published/current edition, with Amendment 1:2024. A replacement, ISO/DIS 22000, is under development
What happens after ISO 22000 certification?
The organization needs to maintain and continually improve its FSMS. The certification body also conducts ongoing surveillance/reassessment according to its certification programme.
Key Takeaways
ISO 22000 implementation is not a document-creation exercise.
A successful implementation connects:
Management
→ Food Safety Team
→ PRPs
→ Hazard Analysis
→ Control Measures
→ Monitoring
→ Verification
→ Internal Audit
→ Management Review
→ Corrective Action
→ Continual Improvement
The certification journey can be summarized as:
DEFINE → ANALYZE → CONTROL → IMPLEMENT → MONITOR → VERIFY → AUDIT → REVIEW → IMPROVE → CERTIFY
The certificate is the result of the system.
The system is the real objective.
About CK Associates
CK Associates provides ISO certification consultancy and implementation support across Hyderabad, Telangana and India.
Our practical implementation approach covers:
Gap Analysis → Documentation → System Design → Implementation → Training → Internal Audit → Management Review → Certification Readiness
Why Trust This Guidance?
20+ Years Experience
450+ Certification Projects
400+ ISO 9001 Projects
25+ ISO 27001 Projects
4+ ISO 42001 Projects
45+ ISO 14001 Projects
45+ ISO 45001 Projects
Sirish K
Founder & Lead ISO Consultant
CK Associates
Summary
ISO 22000:2018 implementation involves establishing and operating a Food Safety Management System that connects organizational context and leadership with prerequisite programmes, hazard analysis, food-safety controls, monitoring, verification, internal audit, management review and continual improvement. A practical implementation starts with defining the FSMS scope and conducting a gap analysis, followed by establishing the food-safety team, PRPs, process flow, product characteristics, hazard analysis and appropriate OPRP/CCP controls. The organization then implements monitoring, traceability, emergency preparedness, verification, internal audits and corrective actions before conducting management review and a final certification-readiness assessment. Certification is performed by an independent certification body, not ISO itself. ISO currently lists ISO 22000:2018 as the published edition with Amendment 1:2024, while ISO/DIS 22000 is under development as its intended replacement. The updated ISO 22002 series, including ISO 22002-100:2025 and ISO 22002-1:2025 for food manufacturing, should also be considered when establishing the applicable PRP framework
