ISO 22000

ISO 22000 Internal Audit Checklist: What Food Safety Auditors Look For

An ISO 22000 internal audit checklist covers the requirements of Clauses 4 through 10 — from prerequisite programs and hazard analysis through the HACCP plan, operational PRPs, traceability, and management review. A well-structured checklist maps each clause to the evidence an auditor expects to find, ensuring full FSMS coverage and consistent findings across every audit.

An ISO 22000 internal audit checklist is one of the most widely searched topics in food safety management — and one of the most misunderstood. Most organizations treat a checklist as a list of yes/no questions to work through. The auditors who produce the most credible, useful findings treat it differently: as a structured framework for evidence gathering, built around the organization's actual hazards, not a generic template. This article explains what a well-structured ISO 22000 internal audit checklist covers, how it maps to the standard's clauses, and what auditors are actually looking for in each area — drawing on the approach developed by Maria Falbo, a Lead Auditor with decades of food safety auditing experience.

Maria Falbo|Lead Trainer, Logix ISO|July 2026|9 min read

What an ISO 22000 Internal Audit Checklist Is — and What It Isn't

An ISO 22000 internal audit checklist is a structured tool that guides an auditor through the requirements of the standard — clause by clause — ensuring that every area of the FSMS is examined with consistency across audits and auditors. It is not a script, not a pass/fail form, and not a substitute for auditor judgment or food safety technical knowledge.

The most common mistake organizations make is treating a downloaded, generic checklist as adequate for their specific operation. A checklist built for a general food manufacturer will ask whether a HACCP plan is in place and being followed. A checklist built around this organization's actual hazard analysis asks whether the specific critical limits for this organization's cooking CCP are being met, whether the specific allergens present in this facility are controlled at the specific points where cross-contact risk exists. The generic version confirms a document exists. The specific version tells you whether the system is actually working.

A well-structured checklist covers all clauses of ISO 22000 from Clause 4 through Clause 10, maps each clause to the type of evidence the auditor should expect to find, and leaves room to follow evidence beyond what the checklist anticipated. It is the framework the auditor uses before and during the audit — not the output they produce at the end of it. For a complete guide to the full ISO 22000 internal audit lifecycle, see our ISO 22000 Internal Audit: The Complete Guide.

In Practice

A checklist bought off the internet asks whether operational PRPs have been identified. A checklist built by someone who actually understands the operation asks whether the operational PRP controlling allergen cross-contact on the shared production line reflects the fact that a new allergen-containing product was added to that line six months ago. The specificity is what separates a checklist that produces real findings from one that produces a completed form with every box checked and nothing genuinely verified.

Clause 4 — Context of the Organization

Clause 4 covers the foundational analysis the entire FSMS is built on — internal and external issues, interested parties, and the scope of the FSMS across the food chain.

The checklist for Clause 4 examines whether the context analysis is documented and reflects the organization's actual position in the food chain — raw material supplier, manufacturer, distributor, retailer — since the scope and relevant hazards differ significantly depending on that position. Auditors verify that the FSMS scope accurately reflects what the organization does and where, including any outsourced processes that could affect food safety.

Clause 5 — Leadership

Clause 5 covers top management commitment, the food safety policy, and — distinctively for ISO 22000 — the appointment and empowerment of the food safety team.

The checklist for Clause 5 examines whether the food safety policy is documented and communicated, and whether top management demonstrates genuine commitment through resource allocation and integration of food safety into business decisions. Critically, it verifies that the food safety team has been formally appointed with the authority to act — including the authority to stop production or hold product when a food safety issue is identified, without requiring escalation delays that could compromise consumer safety.

Clause 6 — Planning

Clause 6 is where the most critical and most frequently cited nonconformities in ISO 22000 audits are found. It covers risk and opportunity planning and, critically, the food safety objectives that drive the system's direction.

Risks and opportunities — The checklist examines whether the organization has identified risks to the FSMS itself, distinct from the food safety hazards addressed later under Clause 8, and whether objectives are being tracked with measurable progress.

In Practice

Organizations frequently conflate Clause 6 planning risks with the hazard analysis conducted under Clause 8. They're genuinely different things. Clause 6 asks what could prevent the management system itself from functioning as intended — losing a key food safety team member, a resourcing gap, a supplier relationship ending unexpectedly. Clause 8's hazard analysis asks what specific biological, chemical, physical, or allergen hazard could contaminate the product. A checklist that treats these as the same exercise will produce a thin, confused planning record that satisfies neither requirement properly.

A professionally structured checklist, ready to use

The Logix ISO documentation package includes an ISO 22000 internal audit checklist built to the current standard — fully editable for your organization.

View Documentation

Clause 7 — Support

Clause 7 covers resources, competence, awareness, communication, and documented information.

Competence — The checklist examines whether personnel whose work affects food safety have documented, role-specific competence — and specifically whether the food safety team includes the multidisciplinary expertise ISO 22000 requires, not just general food safety training.

Communication — The checklist verifies that interactive communication is genuinely happening with suppliers, customers, regulators, and other interested parties — supplier-provided hazard information being incorporated into the organization's own hazard analysis is a concrete example auditors look for, not just a documented communication procedure.

Documented information — The checklist confirms that FSMS documentation is controlled, current, and that the versions in use on the floor match the approved versions, not outdated copies.

Clause 8 — Operation

Clause 8 is where hazard analysis, the HACCP plan, and operational controls live — the technical heart of an ISO 22000 audit.

Prerequisite programs (PRPs) — The checklist verifies that PRPs covering hygiene, sanitation, pest control, and personnel practices are being followed in practice, with records demonstrating consistent execution rather than periodic compliance.

Hazard analysis — The checklist examines whether hazard identification covers biological, chemical, physical, and allergen hazards, whether it has been updated after recent process or ingredient changes, and whether the significance determination for each hazard is credible and documented.

Operational PRPs and the HACCP plan — The checklist verifies that control measures are correctly classified as OPRPs or CCPs, that CCPs have defined critical limits and monitoring frequency, and that corrective action procedures exist for deviations. This is the area requiring the deepest technical scrutiny, since misclassifying a control measure means applying the wrong level of monitoring rigor to it.

Traceability — The checklist should prompt an actual test of the traceability system — tracing a specific batch forward and backward — rather than only confirming a traceability procedure exists on paper. For a deeper explanation of how HACCP principles are formalized within ISO 22000, see our guide to ISO 22000 and HACCP.

Clause 9 — Performance Evaluation

Clause 9 covers monitoring and measurement, verification, internal audit, and management review.

Monitoring and verification — The checklist distinguishes between routine monitoring and verification, which should be independent and confirm the system as a whole is functioning — not simply repeat the same check monitoring already performs.

Internal audits — The checklist verifies that internal audits are performed in line with the organization's procedures.

Management review — The checklist examines whether management review is genuinely evaluating FSMS performance — incident trends, audit findings, verification results, customer feedback — and producing documented decisions and resource allocation, not just meeting minutes.

Clause 10 — Improvement

Clause 10 covers nonconformity and corrective action, and continual improvement.

Corrective action — The checklist examines whether nonconformities are addressed through root cause analysis rather than symptom-level fixes, and whether product disposition decisions — including any withdrawal or recall considerations — are documented and evidence-based.

Continual improvement — The checklist looks for evidence the organization is actively seeking to strengthen food safety performance, not just maintain the status quo — objectives becoming more ambitious, proactive identification of improvement opportunities through the internal audit program, among other sources. For a step-by-step walkthrough of how to use a checklist during an actual audit, see our guide on how to conduct an ISO 22000 internal audit.

FAQ

Frequently asked questions

Does an ISO 22000 internal audit checklist need to cover every clause?

The audit program must cover all clauses of ISO 22000 across the audit cycle — but not every clause needs to be audited in every individual audit. Higher-risk areas like CCPs should be audited more frequently, with full clause coverage achieved across the annual program.

Should the checklist be the same for every audit?

No — a well-designed checklist is tailored to the specific scope, hazards, and risk profile of each individual audit. A generic checklist applied to every audit regardless of context will miss the organization-specific hazards that matter most. The clause structure provides the framework, but the questions should reflect the organization's actual hazard analysis.

What is the difference between an audit checklist and the HACCP plan?

The HACCP plan documents the organization's specific hazard analysis, critical control points, critical limits, and monitoring procedures. An audit checklist is the tool the auditor uses to verify whether the FSMS — including the HACCP plan itself — genuinely conforms to ISO 22000 requirements and is being followed in practice. The HACCP plan is one of the things the checklist examines, not a substitute for it.

Does the checklist need to include questions about communication?

Yes — and this is one of the areas generic checklists handle poorly. Interactive communication throughout the food chain is a distinctive ISO 22000 requirement. A checklist that treats it as a single yes/no item misses the substance of the requirement — the checklist should prompt the auditor to verify genuine information flow, not just the existence of a communication policy.

Is a downloadable checklist sufficient for ISO 22000 certification?

A checklist is a tool, not a management system. Organizations that approach ISO 22000 by downloading a checklist and working through it are likely to pass the checklist but fail the audit — because conformity requires a functioning FSMS built around the organization's specific hazards, not a completed generic form. A professionally developed checklist is a useful starting point, but it needs to be applied by a competent auditor who understands both the standard and the organization's specific food safety risks.

About the Author
Maria Falbo — Lead Trainer, Logix ISO
Maria Falbo
Founder & Lead Trainer, Logix ISO · 25+ Years Global Experience

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.

Learn more about Maria →
ISO 22000 Documentation
Need a ready-to-use foundation for your FSMS?

Our ISO 22000 documentation package includes the manual and internal audit checklist your organization needs — fully editable and built to the current standard.

View ISO 22000 Documentation