A US restaurant kitchen operating under FDA Food Code and USDA jurisdiction faces the same underlying question every ISO 22000 auditor asks a food processor in Europe or an ingredient supplier in Asia: can you demonstrate, with documented evidence, that every food safety hazard reasonably expected in your operation is identified, controlled, and continuously monitored? The clause structure that answers that question is ISO 22000:2018 — Clauses 4 through 10 — layered with prerequisite programmes (PRPs), operational PRPs, and HACCP critical control points, and, for FSSC 22000 certified sites, the additional scheme requirements now moving from V6 to V7 in May 2026. The gap most US teams hit is not the clauses themselves. It is the paper trail — the temperature log with a missing timestamp, the allergen changeover checklist signed at end of shift instead of at the changeover, the corrective action closed verbally on Friday. Below is the full ISO 22000 FSMS internal audit checklist, mapped clause by clause to what an auditor actually asks to see, with pass/fail criteria and the digital execution model that turns each requirement from a filing-cabinet gamble into an evidence-backed defence. Start free and load this audit checklist as a scheduled kitchen route this week, or book a demo to see the FSMS workflow mapped to your kitchen operation.
Food Safety · ISO 22000:2018 · FSSC V6 to V7 · US Teams · 2026
Comprehensive ISO 22000 FSMS Audit Checklist for US Teams
The full clause-by-clause internal audit framework aligned to ISO 22000:2018, FSSC 22000 additional requirements, and US regulatory overlays — FDA Food Code, USDA, FSMA. Structured as an evidence-gathering framework, not a yes/no template, so the audit outcome reflects operational reality rather than filing-cabinet paperwork.
-
Cl. 4–10
ISO 22000:2018 clause structure covering the complete FSMS scope
-
3 tiers
hazard control — PRP, OPRP, and CCP — each with distinct audit evidence
-
May 2026
FSSC 22000 V7 publishes — sites currently on V6 transition through the year
-
Annual
minimum internal audit frequency covering every clause, every applicable PRP
The US Regulatory Overlay
How ISO 22000 Layers Onto FDA, USDA, and FSMA
ISO 22000 is a management-system standard, not a regulation. For a US operation, it sits on top of mandatory federal and state requirements — and a well-run FSMS uses the ISO structure to consolidate evidence for all of them at once. This is the working map of how the frameworks interlock, so an audit for one produces defensible evidence for the others.
The Hazard Control Hierarchy
PRP, OPRP, and CCP — Three Tiers, Three Evidence Standards
The single biggest source of ISO 22000 audit findings is misclassifying hazard controls between the three tiers. A PRP is a foundational hygiene practice. An OPRP is a control identified as necessary but not measurable against a critical limit. A CCP has a validated critical limit that, if breached, requires the product to be held. Each tier carries a different evidence burden — and each requires a different workflow to satisfy.
CCP · Critical Control Point
Highest evidence burden. Validated critical limit, continuous or high-frequency monitoring, defined corrective action, and product hold procedure. Example: cooking temperature ≥ 165°F for 15 seconds at the fryer.
Audit expects: monitoring records with time-stamped readings, deviation log, verified corrective action per event, product disposition record.
OPRP · Operational PRP
Middle tier. Control identified as essential by hazard analysis but not tied to a measurable critical limit. Example: allergen changeover cleaning between production runs.
Audit expects: documented procedure, evidence of execution, verification of effectiveness, corrective action record when procedure not followed.
PRP · Prerequisite Programme
Foundational. Baseline hygiene and operating conditions — cleaning schedules, pest control, personal hygiene, water quality. Not linked to specific product hazards but essential across the operation.
Audit expects: written programme, execution records, verification of effectiveness, competent personnel, periodic review.
Clause-by-Clause Checklist
ISO 22000:2018 Internal Audit — Every Clause, Every Evidence Point
The working audit checklist. Every clause carries specific evidence an auditor expects to find. Below is the full framework — Clauses 4 through 10 — with pass/fail criteria written the way an auditor writes findings, not the way a template writes questions.
Context of the Organization
- Documented analysis of internal and external food safety issues affecting the operation
- Identified interested parties — regulators, customers, suppliers — with their requirements captured
- FSMS scope defined against products, processes, and physical sites; outsourced processes addressed
PASS: scope documented, reflects actual operation, updated within 12 months · FAIL: scope missing, outdated, or excludes material processes
Leadership & Food Safety Policy
- Documented food safety policy signed by top management, communicated to all staff
- Food safety team appointed with defined roles, responsibilities, and authority
- Management review evidence — allocation of resources, integration of FSMS into business processes
PASS: policy current, team roster maintained, review meeting minutes on file · FAIL: policy stale, team undefined, no review evidence in last 12 months
Planning — Risks, Opportunities, Objectives
- Risks and opportunities identified at the FSMS level, with treatment actions recorded
- Food safety objectives set, measurable, with target dates and accountable owners
- Changes to the FSMS planned in a controlled manner — new products, new equipment, new processes
PASS: risk register maintained, objectives tracked against targets · FAIL: risks unaddressed, objectives absent or aspirational
Support — Resources, Competence, Documented Information
- Personnel competence — training records with expiry dates for food handlers, HACCP team, allergen leads
- Infrastructure and work environment appropriate to control identified hazards
- Documented information controlled — approval, review, versioning, retention, and controlled distribution
- Internal and external communication procedures defined — including customer complaint routing
PASS: training current, documents versioned and accessible · FAIL: expired training on active staff, superseded procedures in use
Operational Planning — PRPs, HACCP, Traceability, Emergency
- Prerequisite programmes established and implemented — cleaning, pest control, personal hygiene, water
- Hazard analysis documented — biological, chemical, physical, allergens — with control determination for each
- OPRPs and CCPs identified with monitoring plans, critical limits, and documented corrective actions
- Traceability system tested at least annually — one-up, one-down through the supply chain
- Emergency preparedness — recall procedure documented and mock-recall tested within 12 months
- Control of nonconforming product with defined disposition — release, rework, hold, discard
PASS: monitoring records complete, traceability test evidenced, mock recall on file · FAIL: monitoring gaps, no mock recall, undocumented nonconformity disposition
Performance Evaluation & Internal Audit
- Monitoring, measurement, analysis, and evaluation activities defined and executed
- Internal audit programme covering every clause and every applicable PRP at least annually
- Management review conducted at planned intervals with documented outputs and follow-up actions
PASS: internal audit records show full coverage, management review outputs tracked · FAIL: audit programme incomplete, review outputs unactioned
Nonconformity, Corrective Action, Continual Improvement
- Nonconformity records — CCP deviations, customer complaints, audit findings — with root-cause analysis
- Corrective actions defined, executed, and verified for effectiveness before closure
- Evidence of continual improvement — trend analysis showing reduced recurrence over time
PASS: CAPA records closed with verification, trends demonstrably improving · FAIL: open findings past due, no verification of effectiveness
The Documentation Gap
Every Clause Above Ends With the Same Question — Where Is the Record?
A well-designed FSMS produces the record automatically at the point of work — the temperature reading, the allergen changeover, the corrective action — not reconstructed at the end of shift or the week before the audit. Oxmaint operationalises every ISO 22000 requirement as a mobile-first workflow: mandatory monitoring fields, timestamped photo evidence, digital sign-off per user, and auto-generated corrective actions linked to the underlying asset or CCP. The record exists because the work exists.
From Paper to FSMS-Ready
How the Same Clauses Behave Under Digital Execution
Same audit checklist. Radically different audit posture. The rows below map each recurring evidence-gap finding to the digital control that closes it — the operational reason US food-service teams move from paper to a mobile FSMS.
| Audit Finding | Paper Version | Digital FSMS (Oxmaint) |
|---|---|---|
| CCP monitoring — cooking temp record | Handwritten log, gaps common | Timestamped reading, server-set clock, deviation auto-alert |
| Allergen changeover verification | Signed at end of shift, from memory | Mobile photo of cleaned surface at the changeover event |
| Corrective action closure | Verbal, undated | Auto WO with owner, due date, verification photo required |
| Training expiry — food handler certs | Filing cabinet, expiries missed | Per-person matrix with 60/30/7-day alerts and route-block on lapse |
| Cleaning & sanitation records | Chart on wall, retro-signed | Mobile route per shift with photo evidence per zone |
| Traceability test — one-up, one-down | Days of paperwork reassembly | Filter by lot / date / supplier — full trace under 10 minutes |
| Internal audit evidence retrieval | Manual assembly from binders | Filter by clause, date, or PRP — export in minutes |
Built for US Food-Service Teams
How Oxmaint Runs the FSMS End to End
-
CCP Monitoring
Timestamped Readings Against Every Critical Control Point
Cooking temperatures, cooling curves, refrigeration hold times captured on the mobile app with server-set timestamps. Deviations trigger immediate alerts and product-hold procedures automatically.
-
OPRP Workflows
Allergen Changeovers Verified at the Event
Mobile changeover checklist with mandatory photo evidence of the cleaned surface — captured at the changeover, not retro-signed. Directly addresses the top OPRP audit finding.
-
PRP Routes
Cleaning, Pest, Personal Hygiene Executed as Scheduled Routes
Every PRP — sanitation, pest, water testing, personal hygiene — runs as a scheduled mobile route with per-shift execution records and photo evidence per zone.
-
CAPA Loop
Every Nonconformity Becomes a Tracked Corrective Action
Auto work order fires with owner, due date, and clause citation. Closure requires verification photo and second-person sign-off. Root-cause tagging supports Clause 10 continual improvement.
-
Training Matrix
Per-Person Certification Tracked, Blocked on Expiry
Food handler cards, HACCP training, allergen certification tracked with 60/30/7-day expiry alerts and automatic route-assignment blocking when a required certification lapses.
-
Audit Export
Full FSMS Evidence Pack Assembled in Minutes
Filter by clause, PRP, CCP, date range, or product line — export a complete evidence pack with monitoring records, photos, signatures, and corrective actions. No week-before-audit scramble.
Measured Outcomes
What US Food-Service Teams Gain Running FSMS Digital
-
0
Retro-Signed Records
Server-set timestamps make retro-signing impossible. The top ISO 22000 documentation-integrity finding closes structurally, not by policy.
-
Under 10 min
Traceability One-Up, One-Down
Full lot trace across the supply chain filtered and exported in minutes — the Clause 8.3 test auditors run without warning.
-
100%
CCP Monitoring Coverage
No shift ends with an unmonitored critical control point. Mandatory field configuration blocks record closure without required readings.
-
$0
Free Forever Plan to Start
Food-service teams start on the free plan, digitise a first CCP and its PRPs, and scale into the full FSMS when audit season demands it.
Frequently Asked
ISO 22000 FSMS Audit Questions
Does ISO 22000 replace FDA Food Code compliance?
No. ISO 22000 is a voluntary management-system standard; FDA Food Code and USDA / FSMA requirements remain mandatory for US operations. A well-designed FSMS uses the ISO clause structure to consolidate evidence for all regulatory regimes at once — one framework, multiple audit purposes. Start free and consolidate your Food Code and FSMS evidence today.
What is the difference between a PRP, an OPRP, and a CCP?
Three tiers of hazard control with distinct evidence burdens. A PRP is a foundational hygiene practice — cleaning, pest control. An OPRP is a control determined necessary by hazard analysis but not tied to a measurable critical limit — allergen changeover. A CCP has a validated critical limit that, if breached, requires product hold — cooking temperature at the fryer. Each tier requires different monitoring rigour.
How often must the internal FSMS audit be conducted?
At least annually, covering every ISO 22000 clause and every applicable PRP. Auditors expect evidence of interviews with food handlers, record reviews, and observation of practices — with findings mapped to specific clause numbers and corrective actions tracked to verified closure. Book a demo to see the internal audit workflow configured for your operation.
Does FSSC 22000 V7 change what US teams need to prepare?
FSSC 22000 V7 publishes in May 2026, with a transition period for currently certified sites. V6 additional requirements — food defence, food fraud, food safety culture, environmental monitoring, allergen management — remain the core structure. Sites building the FSMS on V6 today will transition rather than start over.
Is there a free plan to digitise a first CCP or PRP?
Yes. Oxmaint offers a free forever plan — enough to run a mobile monitoring route against a first CCP (cooking, cooling, or refrigeration hold) or a first PRP (cleaning or sanitation), prove the evidence quality, and scale to the full FSMS when audit prep demands it. Sign up for the free plan and stand up your first digital CCP today.
Clause · Evidence · CAPA · Continual Improvement
An ISO 22000 Audit Is Won or Lost Long Before the Auditor Arrives
Every clause on the checklist above ends with the same question — where is the record? Oxmaint is the mobile-first FSMS that produces the record at the point of work, not the week before the audit. Deploy it against your CCPs, OPRPs, and PRPs and walk into the next ISO 22000 internal audit with the evidence already assembled, timestamped, signed, and searchable.








