ISO 22000

ISO 22000 Internal Audit: The Complete Guide to Food Safety Management System Auditing

An ISO 22000 internal audit is a planned, evidence-based assessment of whether an organization's Food Safety Management System conforms to ISO 22000 requirements and is effectively implemented. It verifies that prerequisite programs, hazard analysis, HACCP plans, and operational controls are genuinely functioning — not just documented — before an external certification auditor makes that same assessment.

An ISO 22000 internal audit carries a different weight than most management system audits, because the consequences of a failure aren't abstract — a potentially harmful product could reach a consumer. Done well, an FSMS internal audit tells management whether food safety controls are actually working in practice, catches gaps before they become recalls, and gives the organization the evidence base a certification auditor will expect to see. This guide is written by Maria Falbo, a Lead Auditor with decades of food safety auditing experience, and covers the full internal audit lifecycle — from planning through corrective action follow-up.

Maria Falbo|Lead Trainer, Logix ISO|July 2026|15 min read

What Is an ISO 22000 Internal Audit?

An ISO 22000 internal audit is a planned, evidence-based assessment of an organization's Food Safety Management System. Its purpose is to determine whether the FSMS conforms to the requirements of ISO 22000 and to the organization's own procedures, and whether it is effectively implemented and maintained — as required by Clause 9.2 of the standard.

The key distinction is that an internal audit is a first-party audit — conducted by or on behalf of the organization itself, not by a certification body. Its value lies in giving management verified, objective information about how the FSMS is performing before an external auditor arrives to make that same assessment — and, more fundamentally, before a food safety failure reaches a consumer.

What makes internal auditing so consequential in food safety specifically is the nature of what's being verified. A nonconformity in a food safety management system — a critical control point not properly monitored, a prerequisite program that's stopped functioning, a hazard that was never identified — can result in illness or death. That reality shapes how seriously food safety internal auditing needs to be approached.

ISO 22000 internal audits are conducted in accordance with ISO 19011, the international guidelines for auditing management systems. With over 59,521 organizations certified to ISO 22000 globally, the internal audit requirement under Clause 9.2 covers a genuinely global food supply chain — from primary production through manufacturing, packaging, and distribution. ISO 22000 is often paired with FSSC 22000 in organizations pursuing GFSI-recognized certification — for a full explanation of what that combination involves, see our FSSC 22000: The Complete Guide.

In Practice

The single most revealing gap I find in ISO 22000 audits is the space between what a food safety team can explain in a meeting room and what's actually happening on the production floor. A food safety team leader can walk you through the HACCP plan flawlessly, cite every critical limit, and describe the monitoring frequency for each CCP without hesitation. Then you walk the floor and find the actual monitoring log for that CCP has gaps, or the person responsible for taking the reading doesn't fully understand what happens if the reading is out of limits. The documentation quality and the operational reality are not the same thing, and an internal audit exists specifically to find the gap between them before someone outside the organization does.

How ISO 22000 Auditing Differs from Other Management System Audits

ISO 22000 shares the same Harmonized Structure as ISO 9001, ISO 14001, and ISO 45001 — Clauses 4 through 10, the same overall logic, the same Plan-Do-Check-Act framework. But the subject matter an FSMS auditor is verifying is fundamentally different, and auditors coming to ISO 22000 from a quality or environmental background need to build genuinely new technical knowledge, not just apply familiar auditing skills to new terminology.

The defining difference is that ISO 22000 auditing is HACCP-based. Where a QMS audit examines whether processes consistently produce conforming output, and an EMS audit examines environmental aspects and impacts, an FSMS audit examines whether the organization has correctly identified food safety hazards, determined the appropriate control measures for each one, and can demonstrate those controls are functioning as designed. This requires the auditor to understand — not just recognize — the distinction between three categories of control that don't exist in any other management system standard.

Prerequisite programs (PRPs) establish the basic hygienic conditions and operating practices necessary throughout the food chain — pest control, personnel hygiene, cleaning and sanitation, water quality, equipment maintenance. PRPs are foundational and not targeted at any single, specific hazard; they create the operating environment within which food safety is possible.

Operational prerequisite programs (OPRPs) are prerequisite programs that have been identified, through hazard analysis, as essential to control the likelihood of a specific significant hazard, but which don't require the same critical-limit-based monitoring as a critical control point.

Critical control points (CCPs) are the points in a process where control is essential to prevent, eliminate, or reduce a significant food safety hazard to an acceptable level — cooking temperature, chill storage, metal detection. CCPs require critical limits, continuous or high-frequency monitoring, and immediate corrective action when a limit is exceeded.

An auditor who doesn't understand why a specific control was classified as a PRP versus an OPRP versus a CCP cannot meaningfully assess whether that classification — and therefore the level of monitoring rigor applied to it — is actually correct. For a full breakdown of how the ISO 22000 clause structure covers these requirements, see our ISO 22000 requirements explained. For a deeper explanation of how HACCP principles are formalized within ISO 22000's broader management system framework, see our guide to ISO 22000 and HACCP.

The other structural distinction is interactive communication. ISO 22000 requires food safety information to flow both up and down the food chain — to suppliers, customers, regulatory authorities, and other interested parties. An FSMS audit needs to verify this communication is genuinely happening, not just documented as a policy statement.

Many organizations implementing ISO 22000 also consider FSSC 22000, which builds on ISO 22000 with additional sector-specific and scheme requirements — for a full comparison of the two, see our article on ISO 22000 vs FSSC 22000.

The Five Most Common ISO 22000 Nonconformities

Understanding where FSMS audits most frequently find nonconformities is essential background for any internal auditor, and the patterns are well documented across certification bodies.

1. CCP monitoring records with gaps or late entries. A critical control point requires continuous or high-frequency monitoring with immediate action on deviation. Missing readings and backfilled records are among the most consistently cited findings in food safety audits.

2. Hazard analysis that hasn't been updated after a process or product change. New ingredients, new suppliers, new equipment, or a new product line can all introduce hazards that weren't present when the original hazard analysis was conducted. An organization that changes its process without revisiting the hazard analysis is operating against an outdated risk picture.

3. Verification activities that are really just repeated monitoring. Verification is supposed to be an independent check that the FSMS is functioning as intended — different from, and in addition to, routine monitoring. Organizations frequently conflate the two, effectively monitoring the same thing twice rather than genuinely verifying the system's overall effectiveness.

4. PRPs that have quietly stopped functioning. Pest control that's not followed as scheduled, cleaning schedules that slip during busy periods, water testing that falls behind — PRPs are foundational precisely because they're easy to take for granted, and they're also easy to let erode without anyone formally deciding to let that happen.

5. Traceability systems that can't demonstrate a genuine mock recall. Organizations often have a traceability procedure on paper that fails when actually tested — they can't successfully trace a specific batch forward and backward through the supply chain within a reasonable timeframe.

Planning an ISO 22000 Internal Audit

Effective ISO 22000 internal auditing starts with a risk-based audit program — required under Clause 9.2.2 — that coordinates all internal audit activity across a defined period, typically 12 months, and ensures full coverage of the FSMS.

Building the Audit Program — The audit program must reflect where food safety risk is actually concentrated. Processes involving CCPs and OPRPs — cooking, chilling, allergen control, metal detection — warrant more frequent and more rigorous audit attention than administrative or lower-risk support functions. Areas with a history of nonconformities, recent process changes, or new suppliers should also be prioritized for more frequent coverage.

Auditor Competence — Clause 7.2 requires auditors to be competent, and for ISO 22000 specifically, that competence needs to include genuine understanding of HACCP principles, hazard analysis methodology, and the organization's specific product and process risks — not just general auditing technique. An auditor who understands audit methodology but not food microbiology, allergen cross-contact risk, or the specific hazards relevant to the organization's products will miss findings that a technically competent auditor would catch immediately.

Pre-Audit Preparation — Before the audit begins, the auditor should review the HACCP plan and hazard analysis, the PRP and OPRP documentation, CCP monitoring and verification records, previous audit findings and corrective actions, customer complaints, and any incidents or near-misses involving food safety. This review tells the auditor where to focus and what evidence to expect to find. For a full breakdown of what a well-structured ISO 22000 internal audit checklist covers, see our ISO 22000 internal audit checklist guide. For a step-by-step walkthrough of how to plan and conduct each stage of the audit, see our guide on how to conduct an ISO 22000 internal audit.

In Practice

Preparation for an FSMS audit is different from preparation for most other management system audits, because you're not just reviewing procedures — you're building a technical picture of where the real hazards could be present in this specific product and process. Reviewing the hazard analysis for a ready-to-eat product tells you allergen cross-contact and post-process contamination are the priority risks. Reviewing it for a canned product tells you thermal processing adequacy and container integrity are what matter most. Walking in without that specific technical picture means auditing generically, and generic food safety auditing misses exactly the hazards that matter most for that particular operation.

Build the skills to conduct credible, evidence-based ISO 22000 internal audits

The ISO 22000 Internal Auditor course covers the full audit process, HACCP-based auditing methodology, and every stage from program planning through corrective action follow-up.

View Course

Conducting the Audit: What to Look For

An ISO 22000 internal audit is conducted through document and records review, physical observation of operations, and interviews with the food safety team, management, and operational staff — all three are necessary, and together they reveal whether the FSMS is functioning as designed.

Document and records review establishes what the system says: the food safety policy, the hazard analysis, the HACCP plan, PRP and OPRP procedures, CCP monitoring records, verification records, supplier approval documentation, and traceability records.

Physical observation establishes what is actually happening — whether PRPs like cleaning and sanitation, pest control, and personnel hygiene practices are being followed as documented, whether CCP monitoring equipment is correctly calibrated and positioned, and whether staff at the point of control genuinely understand what they're monitoring and why.

Staff interviews reveal whether the people responsible for critical controls understand their role. A worker responsible for monitoring a CCP should be able to explain, in their own words, what the critical limit is, what they do if a reading is out of limits, and why that control matters.

What to Audit: The Key Areas

Hazard analysis and the HACCP plan. The auditor examines whether hazard identification covers biological, chemical, physical, and allergen hazards across the full process, whether the significance determination is credible, and whether the resulting control measures — PRPs, OPRPs, CCPs — are correctly classified and justified.

PRPs and OPRPs. The auditor verifies that prerequisite programs are being followed in practice, not just documented, and that OPRPs specifically identified through hazard analysis have defined monitoring and correction procedures appropriate to their role in controlling a significant hazard.

CCP monitoring and verification. This is where audit scrutiny should be highest. The auditor checks that monitoring is occurring at the required frequency, that critical limits are being correctly applied, that deviations trigger the defined corrective action, and that verification activities are genuinely independent and thorough checks.

Traceability. The auditor should test the traceability system directly wherever possible — selecting a batch and asking to trace it both forward and backward through the process — rather than simply confirming a traceability procedure exists on paper.

Interactive communication. The auditor examines whether food safety information genuinely flows to and from suppliers, customers, and relevant authorities — not just whether a communication policy has been written.

In Practice

The distinction between monitoring and verification is one of the most consistently misunderstood requirements I encounter, and it's worth being precise about. Monitoring is the routine, ongoing check that a control measure is operating within its limits — someone reading a thermometer every hour. Verification is a separate activity that confirms the overall system is working as intended — reviewing a sample of those monitoring records, or independently verifying the thermometer's calibration. An organization that treats verification as simply "someone else also checking the temperature" hasn't actually verified anything beyond what monitoring already covered. Genuine verification asks a different question: is the whole system, not just this one reading, actually functioning as designed?

Reporting Audit Findings and Nonconformities

Audit findings must be reported accurately, objectively, and in sufficient detail for management to understand what was found, where, and what evidence supports it. A finding that says "CCP monitoring is inadequate" gives management nothing to act on. A finding that specifies which CCP, which shift, which dates had missing or out-of-limit readings with no documented corrective action tells management exactly what failed and what needs to be fixed.

Findings are typically classified as major nonconformities, minor nonconformities, and opportunities for improvement. A major nonconformity in a food safety context often involves a CCP that failed with no evidence of corrective action, or a complete absence of hazard analysis for a new process — findings serious enough to put both certification and, more importantly, consumer safety at risk. A minor nonconformity is an isolated departure without evidence of a systemic pattern. An improvement opportunity is an area where the standard requirements are being met but the process can be improved based on best practices.

The audit report is a required documented output under Clause 9.2 and a mandatory input to management review under Clause 9.3. It should be issued promptly, since corrective action timelines depend on it.

Corrective Action and Follow-Up

Clause 10.2 requires that nonconformities be addressed through corrective action, and the audit program is responsible for verifying that those actions are genuinely implemented and effective — not merely submitted and marked closed.

For each nonconformity, the responsible party must identify the root cause, define a corrective action that addresses that root cause, and provide evidence it's working. In food safety specifically, root cause analysis often needs to go further than in other management systems, because the immediate cause of a CCP deviation — an operator error, an equipment fault — is frequently a symptom of a deeper gap in training, equipment maintenance scheduling, or staffing during peak periods.

The auditor's role includes verifying, not just accepting, that corrective actions have been closed effectively. Audit program follow-up should include a defined interval check confirming actions were implemented and remain effective, with status reported to management review under Clause 9.3. For a full explanation of what ISO 22000 is and what certification involves, see our complete guide to ISO 22000. If your organization needs professionally structured FSMS documentation to support certification, our ISO 22000 documentation package covers the manual and internal audit checklist your organization needs. For organizations preparing for certification or needing expert support strengthening their FSMS, our ISO 22000 consulting services cover gap analysis, internal audit support, and full certification preparation.

FAQ

Frequently asked questions

How often does an ISO 22000 internal audit need to be conducted?

ISO 22000 requires internal audits at planned intervals but doesn't prescribe a specific frequency. The audit program must be risk-based, meaning CCPs, OPRPs, and areas with a history of nonconformities should be audited more frequently than lower-risk administrative functions. Most certified organizations audit their full FSMS at least once per 12-month cycle, with higher-risk processes covered more often.

What is the difference between a PRP, an OPRP, and a CCP?

PRPs are foundational hygienic conditions not targeted at any single hazard — cleaning, pest control, personnel hygiene. OPRPs are prerequisite programs that hazard analysis has identified as essential to control a specific significant hazard, but that don't require the critical-limit monitoring of a CCP. CCPs are the points where control is essential to prevent or reduce a significant hazard to an acceptable level, requiring critical limits and continuous or high-frequency monitoring with immediate corrective action on deviation.

Can the same person conduct the ISO 22000 internal audit every year?

Yes, provided they remain competent and impartial — meaning they do not audit their own work. ISO 22000 does not require auditor rotation, but auditors must maintain current technical knowledge of food safety hazards relevant to the organization's products and processes, as well as knowledge of the standard requirements.

Do ISO 22000 internal auditors need HACCP training specifically?

ISO 22000 requires auditors to be competent, and for a food safety management system, that competence must include genuine understanding of HACCP principles and hazard analysis — not just general auditing methodology. Most organizations ensure their internal auditors have HACCP training in addition to internal audit training, since auditing the classification and monitoring of PRPs, OPRPs, and CCPs requires that specific technical foundation.

What happens if a critical control point deviation is found during an internal audit?

A CCP deviation with no evidence of the required immediate corrective action is typically classified as a major nonconformity given the direct food safety risk involved. The audit must document what happened, whether product disposition was correctly handled, and whether the root cause has been addressed to prevent recurrence — not just the immediate symptom.

About the Author
Maria Falbo — Lead Trainer, Logix ISO
Maria Falbo
Founder & Lead Trainer, Logix ISO · 25+ Years Global Experience

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.

Learn more about Maria →
ISO 22000 Internal Auditor Training
Ready to become a qualified ISO 22000 internal auditor?

Self-paced · 365-day access · Training certificate included

View Course