ISO 22000 is organized across seven requirement clauses — Clauses 4 through 10 — built around four key elements: interactive communication, system management, prerequisite programs, and HACCP principles. Together, these clauses define what a Food Safety Management System must include, how it must be maintained, and how its effectiveness must be demonstrated across the entire food chain.
ISO 22000 is built on a clear, logical structure — but understanding what each clause requires in practice, and how the standard's four defining elements connect across that structure, is where most FSMS implementations run into difficulty. This article walks through all clauses of ISO 22000, explaining what each requires and why it matters, with particular attention to the elements that make ISO 22000 genuinely distinct from other management system standards — drawing on the audit experience of Maria Falbo, a Lead Auditor with decades of food safety experience.
ISO 22000 follows the Harmonized Structure common to major ISO management system standards, giving it the same clause numbering, terminology, and Plan-Do-Check-Act logic as ISO 9001, ISO 14001, and ISO 45001. Clauses 1 through 3 cover scope, normative references, and definitions — no auditable requirements. The requirements run from Clause 4 through Clause 10.
What makes ISO 22000 genuinely distinct is that it operates through two interrelated PDCA cycles rather than one. The first cycle governs the management system as a whole — Clauses 4, 5, 6, 7, 9, and 10 — the same organizational-level planning, leadership, support, evaluation, and improvement structure found in any Harmonized Structure standard. The second cycle sits entirely within Clause 8 (Operation) and is built specifically around HACCP-based hazard control — hazard analysis, classification into PRPs, OPRPs, and CCPs, monitoring, and verification. Understanding that Clause 8 runs on its own distinct operational cycle, layered inside the broader management system cycle, is essential to understanding how ISO 22000 actually works.
The standard combines four generally recognized key elements throughout this structure: interactive communication throughout the food chain, system management, prerequisite programs, and HACCP principles. These aren't confined to a single clause — they are found throughout the entire standard, which is why understanding them is very important. For a broader overview of what ISO 22000 is and who needs it, see our complete guide to ISO 22000.
Clause 4 establishes the foundation the entire FSMS is built on. It requires the organization to understand its internal and external context, identify its interested parties and their requirements, and determine the scope of the FSMS.
Clause 4.1 — Understanding the organization and its context requires identifying internal and external issues relevant to the organization's food safety purpose — its position in the food chain, applicable regulations, and factors affecting its ability to consistently provide safe products.
Clause 4.2 — Understanding the needs and expectations of interested parties requires identifying relevant interested parties — regulators, customers, consumers, suppliers — and their food safety requirements, which then feed directly into the compliance and communication requirements elsewhere in the standard.
Clause 4.3 — Determining the scope of the FSMS requires the organization to define which products, processes, and locations are covered. Given ISO 22000's applicability across the entire food chain — from primary production through packaging and distribution — scope definition matters more here than in many other management system standards, since the organization's specific position in the chain significantly shapes which hazards and requirements actually apply.
Clause 5 establishes top management's role in the FSMS — and it's where the evidence of genuine organizational commitment either exists or doesn't.
Clause 5.1 — Leadership and commitment requires top management to take accountability for FSMS effectiveness, ensure the food safety policy aligns with strategic direction, and integrate food safety requirements into core business processes — not treat food safety as a parallel, separate function.
Clause 5.2 — Policy requires a documented food safety policy communicated throughout the organization, establishing the framework for food safety objectives.
Clause 5.3 — Organizational roles, responsibilities and authorities requires top management to assign FSMS responsibilities — critically including the appointment of a food safety team leader with the authority to initiate and coordinate FSMS activities and to stop production or hold product when food safety is at risk, without requiring escalation delays that could compromise consumer safety.
Clause 6 covers risks and opportunities affecting the management system itself, and food safety objectives.
Clause 6.1 — Actions to address risks and opportunities requires the organization to determine risks and opportunities that could affect the FSMS's ability to achieve its intended outcomes. This is distinct from the hazard analysis conducted under Clause 8 — Clause 6 addresses risks to the management system itself (resourcing, organizational change, supplier relationships), while Clause 8's hazard analysis addresses specific food safety hazards in the product and process.
Clause 6.2 — Food safety objectives requires measurable objectives consistent with the food safety policy, with documented action plans specifying what will be done, resources required, responsibility, and timelines.
Clause 7 covers resources, competence, awareness, communication, and documented information — the infrastructure that makes the FSMS functional.
Clause 7.1 — Resources requires the organization to determine and provide the people, infrastructure, and work environment needed for the FSMS, including the specific competence and multidisciplinary expertise the food safety team requires.
Clause 7.2 — Competence requires determining and ensuring the competence of personnel whose work affects food safety, with documented evidence.
Competence under Clause 7.2 is one of the areas where I see the biggest gap between documented training and genuine capability. An organization can show a stack of general food handler hygiene certificates for every employee and still fail this clause where it matters most — the food safety team itself. The team responsible for hazard analysis and HACCP plan development needs specific, demonstrable competence in food science, process technology, and hazard identification methodology, not just general food safety awareness training. A food safety team that's technically weak produces a hazard analysis that looks complete but misses the hazards that actually matter for that specific product and process.
Clause 7.3 — Awareness requires personnel to understand the food safety policy, their contribution to FSMS effectiveness, and the implications of not conforming to requirements.
Clause 7.4 — Communication requires internal and external communication processes — and this is where ISO 22000's interactive communication element becomes explicit, requiring structured communication with suppliers, customers, regulators, and other parties throughout the food chain about food safety matters relevant to product safety.
Clause 7.5 — Documented information requires FSMS records to be controlled, current, and available — this is also where HACCP's seventh principle, record-keeping and documentation, is formally incorporated into ISO 22000's structure.
Our ISO 22000 Internal Auditor course covers every requirement from Clause 4 through Clause 10, built on HACCP-based auditing methodology and Maria Falbo's food safety audit expertise.
Clause 8 is the operational core of ISO 22000 — where the standard's second, HACCP-based PDCA cycle lives, and where the deepest technical scrutiny in any audit belongs.
Clause 8.1 — Operational planning and control requires the organization to plan, implement, and control the processes needed to produce safe products, including control of externally provided processes, products, and services.
Clause 8.2 — Prerequisite programs (PRPs) requires establishing, implementing, and maintaining PRPs — the basic hygienic conditions and operating practices necessary throughout the food chain.
Clause 8.3 — Traceability system requires the organization to maintain a traceability system capable of identifying product lots and their relationship to raw materials and processing records — genuinely tested, not just documented as a procedure.
Clause 8.4 — Emergency preparedness and response requires the organization to identify potential emergency situations affecting food safety and prepare accordingly.
Clause 8.5 — Hazard control is the heart of ISO 22000's HACCP integration, covering hazard analysis, control measure classification into PRPs, OPRPs, and CCPs, and the hazard control plan itself with critical limits, monitoring, corrective action, and verification requirements.
Clause 8.6 — Updating information requires the hazard analysis and hazard control plan to be kept current as products, processes, or the operating context change.
Clause 8.7 — Control of monitoring and measuring requires monitoring equipment to be calibrated and maintained to ensure valid results.
Clause 8.8 — Verification related to PRPs and the hazard control plan requires independent verification activities — distinct from routine monitoring — confirming the system as a whole is functioning as intended.
Clause 8.9 — Control of product and process nonconformities covers how potentially unsafe products are handled, including corrections, evaluation for release, and — where necessary — withdrawal and recall procedures.
The most consistent structural mistake I see, even among experienced auditors coming from other management system backgrounds, is treating Clause 8 like every other clause in the standard — auditing it with the same generic checklist mentality applied to Clauses 4 through 7 and 9 through 10. Clause 8 runs on a fundamentally different logic: it's the HACCP-based operational cycle, and auditing it credibly requires food safety technical knowledge, not just management system auditing methodology. An auditor who treats the hazard control plan the same way they'd audit a document control procedure will miss the substance of what actually needs to be verified.
Clause 9 covers monitoring, evaluation of compliance, internal audit, and management review — the mechanisms confirming the FSMS is genuinely working.
Clause 9.1 — Monitoring, measurement, analysis and evaluation requires ongoing evaluation of FSMS performance.
Clause 9.2 — Internal audit requires internal audits at planned intervals to determine FSMS conformity and effectiveness. For a complete guide to how ISO 22000 internal audits are planned and conducted, see our ISO 22000 Internal Audit: The Complete Guide, and for a step-by-step walkthrough, see our guide on how to conduct an ISO 22000 internal audit.
Clause 9.3 — Management review requires top management to review the FSMS at planned intervals, addressing defined inputs — audit results, compliance status, customer feedback, incident trends, verification results — and producing documented decisions.
Clause 10 covers nonconformity, corrective action, and continual improvement.
Clause 10.1 — Nonconformity and corrective action requires organizations to react to nonconformities, investigate root cause, implement corrective actions, and verify their effectiveness — with particular weight in food safety given the potential product disposition implications of any deviation.
Clause 10.2 — Continual improvement requires ongoing enhancement of FSMS suitability, adequacy, and effectiveness.
Clause 10.3 — Update of the food safety management system requires top management to ensure the FSMS is continually updated based on the outputs of management review, keeping the system current with organizational and food chain changes.
ISO 22000 combines interactive communication throughout the food chain, system management, prerequisite programs, and HACCP principles. These aren't confined to individual clauses — they run through the entire standard and are what distinguish ISO 22000 from a standalone HACCP program.
ISO 22000 uses one PDCA cycle at the organizational management system level, covering Clauses 4, 5, 6, 7, 9, and 10, and a second, distinct PDCA cycle specifically for Clause 8 (Operation), built around HACCP-based hazard control. This dual structure exists because hazard control requires its own specific operational logic — hazard analysis, classification, monitoring, and verification — that doesn't map onto the general management system cycle in the same way.
Clause 8.5 (hazard control) is consistently among the most frequently cited, particularly around hazard analysis currency and correct classification of control measures as PRPs, OPRPs, or CCPs.
The internal audit program must cover all clauses across the audit cycle, but not every clause needs auditing in every individual audit. Clause 9.2 requires the program to be risk-based, meaning CCPs and higher-risk areas should be audited more frequently, with full clause coverage achieved within each program cycle.
Yes — ISO 22000 shares the same Harmonized Structure as ISO 9001, ISO 14001, and ISO 45001, which means their clause numbering, terminology, and overall logic align closely, making integration into a single management system structurally straightforward, even though ISO 22000's Clause 8 retains its distinct HACCP-based operational logic.

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.
Learn more about Maria →Self-paced · 365-day access · Training certificate included