DOCUMENTS TO PREPARE FOR AN ISO 22000:2018 AUDIT – A COMPREHENSIVE GUIDE FOR BUSINESSES
ISO 22000:2018 certification audits are an important step in confirming that an organization has established and operates a Food Safety Management System (FSMS) in accordance with the requirements of the standard.
During the audit, auditors do not review documentation alone. They also verify the consistency between documented information, actual operations, and the organization’s level of compliance.
Many businesses invest significantly in developing a comprehensive management system but may still receive Nonconformities (NCs) due to incomplete records, inconsistencies, or documentation that does not accurately reflect actual operations. Therefore, preparing all required documentation and records before the audit not only helps ensure a smooth audit process but also demonstrates the effectiveness of the Food Safety Management System.
Why Is Documentation Important in an ISO 22000 Audit?
Under ISO 22000:2018, organizations are required to maintain documented information as evidence that the Food Safety Management System (FSMS) has been established, implemented, and continually improved.
For auditors, ISO 22000 audit records provide objective evidence to verify whether:
- The organization is implementing its established procedures as intended.
- Food safety hazards have been adequately identified and controlled.
- Monitoring, verification, and improvement activities are carried out consistently rather than merely as a formality.
- The management system is operating effectively and meeting the requirements of ISO 22000:2018.
In other words, “no records means no evidence,” even if the organization claims that the activities have been carried out in practice.
ISO 22000:2018 Audit Documentation – What Should Businesses Prepare?
Group 1. Food Safety Management System Documentation
This group of documents helps auditors understand how the organization has established and managed its Food Safety Management System (FSMS).
Businesses should typically prepare:
- The scope of the Food Safety Management System.
- Food safety policy.
- Food safety objectives.
- Organizational chart and assignment of responsibilities.
- Documented information register.
- Procedures and work instructions.
Auditors will assess whether the certification scope, organizational structure, and actual business activities are consistent with one another.
Group 2. Hazard Analysis and Risk Control Documentation
This is a core area of ISO 22000:2018, as it demonstrates how the organization manages food safety based on risk.
The required documentation typically includes:
- Product descriptions and intended use.
- Production process flow diagrams.
- On-site verification of process flow diagrams.
- Hazard analysis records.
- Risk assessment records.
- Identification of CCPs and OPRPs.
- Control plans and monitoring methods.
- Critical limits, where applicable.
Auditors will assess whether the identified hazards are appropriate to the actual production processes, raw materials, and operating conditions.
Group 3. Operational and Monitoring Records
Once control measures have been established, businesses need to demonstrate that these measures are consistently implemented through appropriate records.
This group typically includes:
- CCP and OPRP monitoring records.
- Incoming raw material inspection records.
- Semi-finished and finished product inspection records.
- Cleaning and sanitation records for facilities, equipment, and utensils.
- Pest control records.
- Machinery maintenance records.
- Calibration records for monitoring and measuring equipment.
- Employee training records.
- Supplier control and evaluation records.
During the audit, auditors may select records at random to assess traceability and cross-check them against actual activities observed on site.
Group 4. Verification and Continual Improvement Records
ISO 22000 not only requires businesses to control food safety hazards but also to demonstrate that the FSMS is evaluated and continually improved.
The documentation should include:
- Internal audit reports.
- Management review records.
- Corrective action records.
- Nonconforming product handling records.
- Verification and validation records.
- Customer complaint records.
- Product recall or mock recall records, where applicable.
These records provide important evidence that the organization proactively identifies issues and improves its system in accordance with the PDCA cycle.
Group 5. Compliance and Traceability Records
In addition to the requirements of the standard, many businesses must also comply with applicable legal requirements and customer-specific requirements.
Therefore, businesses should prepare:
- Traceability records for raw materials and finished products.
- Product testing and laboratory analysis records.
- Relevant licenses and certificates.
- Supplier evaluation records.
- Records demonstrating compliance with food safety regulations.
This group of records helps demonstrate that the business meets both the requirements of ISO 22000:2018 and applicable legal and regulatory requirements
Common Documentation Errors Businesses Encounter During ISO 22000 Audits
In practice, many nonconformities identified during audits do not result from a lack of procedures, but rather from how documented information is managed and maintained.
Common issues include:
- Incomplete records or missing information.
- Inconsistencies between different forms and records.
- Records not properly signed, verified, or approved as required.
- Outdated forms being used after documents have been revised.
- Records not being retained for the required period.
- Records that do not accurately reflect actual operations.
Reviewing and standardizing documentation before the audit can significantly reduce the risk of nonconformities being identified.
What Should Businesses Prepare Before the Audit?
To ensure an effective audit process, businesses should:
- Review all records according to each relevant process.
- Check the consistency between documented information and actual operations.
- Organize records by department to facilitate easy retrieval and verification.
- Complete the internal audit and management review before the certification audit.
- Communicate the audit plan and assign responsible personnel for each area.
Thorough preparation not only helps save time during the audit but also demonstrates the professionalism and maturity of the Food Safety Management System (FSMS).
Preparing complete ISO 22000 audit documentation is not only about meeting the requirements of ISO 22000:2018, but also provides evidence that the organization’s Food Safety Management System (FSMS) is operating effectively and consistently.
When documented information is properly established, regularly updated, and accurately reflects actual operations, the organization can improve its chances of achieving certification, strengthen customer confidence, and establish a solid foundation for continual improvement.

main.comment_read_more