ISO 22000

How to Conduct an ISO 22000 Internal Audit Step by Step

To conduct an ISO 22000 internal audit, establish a risk-based audit program, plan each audit against the hazard analysis, HACCP plan, and PRP outputs, prepare by reviewing monitoring and verification records, gather evidence through document review, site observation, and interviews with the food safety team, document and classify findings, and follow up to verify corrective actions address root causes — not just symptoms.

An ISO 22000 internal audit is required under Clause 9.2 — but its real value lies in what it uncovers before your certification auditor does, and before a food safety failure reaches a consumer. A well-run FSMS audit tells management whether hazard controls are actually working in practice, not just whether they exist on paper. This guide walks through each stage of the ISO 22000 internal audit process, drawing on the approach taught by Maria Falbo, a Lead Auditor with decades of food safety auditing experience.

Maria Falbo|Lead Trainer, Logix ISO|July 2026|11 min read

What ISO 22000 Requires for Internal Audits

ISO 22000 Clause 9.2 requires organizations to conduct internal audits at planned intervals to determine whether the FSMS conforms to requirements and is effectively implemented. The clause has two parts: Clause 9.2.1 sets the objective — conformity and effectiveness — and Clause 9.2.2 governs the audit program itself, requiring it to be planned, implemented, maintained, and risk-based.

What makes FSMS auditing distinct from most other management system audits is that it's HACCP-based. An internal audit isn't just checking that procedures are documented and followed — it's checking whether the organization's hazard analysis is credible, whether the resulting control measures (PRPs, OPRPs, CCPs) are correctly classified, and whether they're genuinely functioning. This requires the auditor to bring food safety technical knowledge into the audit, not just general auditing methodology.

ISO 22000 internal audits are conducted in accordance with ISO 19011, the international guidelines for auditing management systems. For a comprehensive overview of the full FSMS internal audit lifecycle and how ISO 22000 auditing differs from other management system standards, see our ISO 22000 Internal Audit: The Complete Guide.

Step 1 — Establish Your Audit Program

The audit program is the overarching framework that governs all internal audit activity across a defined period — typically 12 months. It coordinates multiple audits across all processes, sites, and functions of the FSMS to ensure full coverage over the cycle.

The program must be risk-based. Clause 9.2.2 requires it to account for the importance of the processes being audited and the results of previous audits. Processes involving CCPs and OPRPs — cooking, chilling, allergen control, metal detection — warrant more frequent and more rigorous audit attention than administrative or lower-risk support functions.

In Practice

The most common audit program weakness I see in food safety systems is treating every process as equally deserving of audit time. A cooking CCP with a direct pathogen-kill step needs far more frequent, far more rigorous attention than an administrative support process — but I regularly see programs that give both the same slot in the annual schedule. The program needs to reflect where the real food safety risk sits, and that requires someone who genuinely understands the hazard analysis, not just someone following a template.

Step 2 — Plan the Individual Audit

Each audit within the program needs its own audit plan — defining the scope, objectives, criteria, schedule, and methods for that specific audit. The criteria are the requirements against which conformity will be assessed — the relevant ISO 22000 clauses, the organization's hazard analysis and HACCP plan, and applicable regulatory requirements for that area.

The plan also assigns auditors. Clause 9.2.2 requires impartiality — auditors must not assess areas they are personally responsible for. This does not require external auditors; a quality manager can audit production, and a production supervisor can audit the quality function, provided neither audits their own work.

Where the audit covers CCP monitoring specifically, the plan should allow adequate time to review a genuinely representative sample of records — rushing this review is one of the most consistent causes of missed findings.

Step 3 — Prepare for the Audit

Preparation is where audit quality is determined, before the audit begins. For an ISO 22000 audit, this means building a genuine technical picture of where hazards actually sit in the specific product and process being audited — not just reviewing a generic procedure list.

The auditor should review the hazard analysis and HACCP plan for the area — focusing on whether it reflects current operations, and whether recent process or ingredient changes could have introduced hazards that haven't been captured. PRP and OPRP documentation should be reviewed to understand what controls are supposed to be in place. Previous audit reports, customer complaints, and any incidents or near-misses reveal where problems have already surfaced. For a deeper look at what a well-structured ISO 22000 internal audit checklist covers by area, see our ISO 22000 internal audit checklist guide.

In Practice

Good preparation for a food safety audit means knowing the specific risk profile of what you're auditing before you walk in. Reviewing the hazard analysis and noting that a new supplier was onboarded for a key ingredient three months ago — and that the supplier documentation hasn't been updated since — means you walk onto the floor already knowing exactly what to check. An auditor who works from a generic checklist without that specific technical context will miss precisely the gaps that matter most for that operation.

Build the skills to conduct credible, evidence-based ISO 22000 internal audits

The ISO 22000 Internal Auditor course covers every stage of the audit process, HACCP-based auditing methodology, and food safety team competencies, built on ISO 22000 and ISO 19011.

View Course

Step 4 — Hold the Opening Meeting

An ISO 22000 internal audit typically begins with an opening meeting. Its purpose is to confirm the audit is authorized and understood, establish ground rules, and align expectations before fieldwork begins.

A well-run opening meeting covers the audit scope, objectives, and criteria; the schedule and which areas will be visited; the methods the auditor will use; how findings will be classified and communicated; and who the auditor needs access to, including specific members of the food safety team. Keep it concise — fifteen to thirty minutes is typically sufficient.

Step 5 — Conduct the Audit

The audit itself is conducted through three methods: document and records review, physical observation, and interviews with the food safety team and operational staff.

Document and records review establishes what the system says — the hazard analysis, HACCP plan, PRP and OPRP procedures, CCP monitoring records, verification records, and traceability documentation. Physical observation establishes what is actually happening — whether CCP monitoring is occurring at the required frequency, whether PRPs like cleaning and pest control are visibly being followed, and whether the monitoring equipment is calibrated and identified.

Staff interviews reveal whether people understand the FSMS and their role within it. Open-ended questions probe genuine understanding: "Walk me through what you do if this reading is outside the critical limit." The answers reveal the real state of FSMS awareness far more reliably than documents alone.

The most important discipline throughout is following the evidence rather than the checklist. When an interview surfaces something unexpected — a hazard not reflected in the analysis, a verification activity that turns out to be duplicate monitoring rather than an independent check — the auditor pursues that thread. For a deeper explanation of how HACCP principles are formalized within ISO 22000, see our guide to ISO 22000 and HACCP.

In Practice

One of the most useful questions I ask food safety team members during an audit is simple: "What's the last change you made to the hazard analysis, and what triggered it?" A team that's genuinely engaged with the FSMS can usually name something specific — a newly introduced allergen, a process change that shifted a hazard's likelihood. A team that can't answer this question at all is often working from a hazard analysis that was built once, years ago, and has effectively become a static document rather than a living risk assessment.

Step 6 — Document and Classify Findings

As evidence is gathered, the auditor records findings in real time. Every finding must be supported by objective evidence — something observed, a record reviewed, or a statement verified during interview.

Findings fall into three categories. A major nonconformity is a systemic failure — a CCP deviation with no evidence of corrective action, or a complete absence of hazard analysis for a significant process. A minor nonconformity is an isolated departure with no evidence of a broader pattern — some missing monitoring records with no other indication of a systemic gap. An observation identifies a potential risk or improvement opportunity that doesn't yet constitute a failure.

Specificity is what makes a nonconformity report useful. "CCP monitoring is inadequate" gives management nothing to act on. "CCP2 monitoring records for the evening shift on [date] show no entries between 6:00 PM and 10:00 PM, with no documented corrective action or product hold, as confirmed by the shift supervisor during interview" tells management exactly what failed, where, when, and what evidence supports it.

Step 7 — Hold the Closing Meeting and Issue the Report

The closing meeting formally concludes the on-site audit, bringing together the same personnel who attended the opening meeting to present findings before the formal written report is issued. The meeting covers what was audited, the evidence reviewed, all findings with supporting evidence, and the timeline for corrective action responses.

The audit report should be issued promptly. The audit report is a required documented output under Clause 9.2 and a mandatory input to management review under Clause 9.3.

Step 8 — Follow Up on Corrective Actions

The audit does not end when the report is issued. Clause 10.2 requires nonconformities be addressed through corrective action, and part of the audit program is verifying those actions are implemented and effective — not merely submitted.

For each nonconformity, the responsible party must identify the root cause, define a corrective action that addresses that root cause, and provide evidence it's working. The critical point is root cause, not symptom.

In Practice

The corrective actions I see fail most often in food safety audits are the ones that stop at "retrained the operator." A CCP deviation gets closed with a training record — but nobody asks why an experienced operator missed a reading in the first place. Often the answer is that the monitoring equipment display is hard to read under the shift lighting, or that the operator was covering two stations during a staffing gap. A corrective action that doesn't address that underlying condition will not prevent the deviation from happening again — it will just produce a training record that looks resolved until the next audit finds the same gap.

The auditor's role is to verify, not just accept, that corrective actions have been closed effectively. For a broader understanding of how the internal audit fits into the full FSMS lifecycle, see our ISO 22000 Internal Audit: The Complete Guide.

FAQ

Frequently asked questions

How long does an ISO 22000 internal audit take?

The duration depends on the size and complexity of the organization and the scope of the audit. A single-process audit might take a few hours; a full-site audit covering multiple product lines and CCPs may require several days. What matters is that the audit covers all required areas with sufficient depth — particularly related to CCPs — not that it is completed quickly.

Who can conduct an ISO 22000 internal audit?

Internal auditors can be employees of the organization, provided they do not audit their own work. Auditors must also be competent, meaning they understand ISO 22000 requirements, HACCP principles, and food safety hazards relevant to the organization's products — not just general auditing technique. This is why ISO 22000 internal auditor training that covers both audit methodology and food safety technical content is considered essential rather than optional in most food safety organizations.

What documents does an auditor review during an ISO 22000 internal audit?

Key documents include the hazard analysis, the HACCP plan, PRP and OPRP procedures, CCP monitoring and verification records, previous audit reports and open corrective actions, and traceability records. These documents tell the auditor where risk is concentrated and what evidence to look for.

Do ISO 22000 internal auditors need HACCP-specific training?

Yes, in practice. ISO 22000 requires auditors to be competent, and for a food safety management system, competence must include genuine understanding of HACCP principles and hazard analysis. A structured internal auditor training course that combines audit methodology with HACCP-based technical content ensures auditors can meaningfully assess whether PRPs, OPRPs, and CCPs are correctly classified and functioning.

What happens if a CCP deviation is found during an ISO 22000 internal audit?

A CCP deviation with no evidence of the required immediate corrective action is typically classified as a major nonconformity given the direct food safety risk. The audit must document what happened, whether product disposition was correctly handled, and whether the root cause — not just the immediate symptom — has been addressed to prevent recurrence.

About the Author
Maria Falbo — Lead Trainer, Logix ISO
Maria Falbo
Founder & Lead Trainer, Logix ISO · 25+ Years Global Experience

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.

Learn more about Maria →
ISO 22000 Internal Auditor Training
Ready to become a qualified ISO 22000 internal auditor?

Self-paced · 365-day access · Training certificate included

View Course