How to Prepare for a Food Safety Audit: A Plant Manager’s Playbook
Your auditor reads your records before walking the production floor. Most plants get this backwards — they deep-clean the building and leave the paperwork for the night before. Flip the order. Audits are won in the office, in the weeks before anyone arrives, one record set at a time.
This guide walks through what GFSI-benchmarked auditors (BRCGS, SQF, FSSC 22000) actually look for, the sequence every audit follows under ISO 19011, the records you should have ready, and the corrective-action deadlines that decide whether your certificate gets issued.
Figure out which audit you’re facing
Not all audits play by the same rules. A customer second-party audit is a conversation with your buyer’s checklist. An FDA inspection is a regulatory visit — findings land on a Form FDA 483, and you respond in writing. A third-party certification audit decides whether you keep selling to major retailers. Preparation looks similar on the surface, but the stakes and the grading change everything.
Ask three questions before you do anything else: who is the auditor, which standard are they auditing against, and what happens to a nonconformity. Your answers shape every decision below.
Third-party certification audits grade you — know the grades
BRCGS, SQF, and FSSC 22000 all rank findings, and the rank sets your deadline. Under BRCGS, auditors grade nonconformities as critical (a serious failure affecting product safety or legality — the audit fails on the spot), major (a substantial failure to meet the standard, or a situation raising significant doubt about product conformity), or minor (a clause not fully met, but isolated). Sites must submit corrective actions for majors and minors within 28 calendar days of the audit — no certificate issues until the certification body accepts them. A major raised against a fundamental requirement means no certification at all.
SQF runs tighter clocks. Minor nonconformities must be corrected, verified, and closed in the SQF assessment database within 30 calendar days of the facility audit; majors within 14 calendar days. A critical nonconformity at a certification audit is an automatic failure — the site has to reapply. FSSC 22000 doesn’t grade findings the same way, but it runs the same logic on a three-year cycle: Stage 1 readiness review, Stage 2 full implementation audit (no more than six months after Stage 1), annual surveillance audits, at least one of them unannounced, and recertification before the certificate expires.
Grades decide your deadline — act like it
Thirty days sounds generous until you subtract the weekend your QA manager is on leave, the lab turnaround for retest samples, and the two rounds of back-and-forth with the certification body over evidence that isn’t quite enough. Start corrective-action work the week of the audit, not the week the deadline reminder arrives. BRCGS gives you the right to appeal the certification decision in writing within 7 days, with the certification body responding within 30 — but appeals don’t pause your corrective-action clock, so keep working the fixes while the appeal runs.
Every audit follows the same five moves
ISO 19011, the international guideline for auditing management systems, treats each audit as a staged process: initiate, prepare, conduct on-site activities, then report and close. Whatever the standard, your auditor moves through the same sequence — document review, opening meeting, floor time, evidence gathering, closing meeting. Knowing the sequence lets you prepare each piece once, properly, instead of scrambling in order of panic.
Document review comes first — sometimes before the auditor arrives
For certification audits, the auditor reviews your documented system before or at the start of the visit: the food safety manual, HACCP plan or food safety plan, procedures, and a sample of records. FSSC 22000’s Stage 1 exists specifically for this — a readiness evaluation of the documented system before the Stage 2 implementation audit. Weak documentation here doesn’t just cost you findings; it tells the auditor where to dig on the floor.
Pull the full document set two weeks out. Read your own HACCP plan like a stranger would. Flow diagrams must match the actual line — auditors walk the diagram against the floor, and every mismatch becomes a question. Verify that the procedures your team actually follows are the ones written down; the reverse (beautiful procedures nobody follows) fails just as fast.
The seven record sets auditors always pull
You don’t need every record perfect. You need these seven complete, current, and traceable:
- Monitoring records for CCPs and operational PRPs — signed, dated, with corrective actions noted where limits were missed
- Calibration records for thermometers, scales, and any measuring device tied to a food safety decision — in-date, traceable
- Training records — who was trained, on what, when, and how competence was verified
- Internal audit records — the full cycle: plan, findings, corrective actions, verification
- Management review minutes — showing top management actually reviewed the system and assigned actions
- CAPA records from the last audit — root cause, actions, evidence, and proof the fix held
- Traceability and mock recall records — one finished exercise with the mass balance shown
Missing records are worse than imperfect ones. A temperature log with one missed check and a documented correction shows a working system. A missing log shows no system at all.
Prepare records so a stranger can follow them
Here’s the test: hand any record to someone who has never seen your plant. Can they follow what happened, who did it, and what the result was — without asking you a single question? Auditors work exactly this way. They sample records cold, and every record that needs your verbal explanation is a record that failed the test.
Start with monitoring records, because auditors start there. Each entry needs the date, time, the actual reading, the limit it was judged against, the operator’s name or initials, and — where a deviation occurred — what was done with the affected product. “Checked OK” with no numbers tells the auditor nothing. A log full of identical readings at identical times tells them something worse.
Run your own internal audit first
Your internal audit is a dress rehearsal with the answers included. Schedule it four to six weeks before the certification audit, audit against the full standard (not a shortened checklist), and treat findings like the real thing: root cause, corrective action, evidence, verification. Auditors always review the previous internal audit cycle — an internal audit that found nothing is a red flag, because no plant is perfect and the auditor knows it.
Assign someone who doesn’t own the area being audited. Independence isn’t bureaucracy; it’s the only way findings surface instead of getting smoothed over. Your QA manager auditing their own CCP logs will find typos. A production supervisor auditing QA’s logs will find the Monday-morning gap nobody wanted to mention.
Do one mock traceability run — timed
Pick a finished product lot, run it backward to the raw materials and forward to the customers, and time the whole exercise. GFSI schemes expect traceability to work, not just exist on paper. If your team can’t complete a mock recall inside your own target time, the auditor’s traceability challenge will expose it live. Keep the finished exercise on file with the mass balance — quantities in, quantities out, and the reconciliation explained. That’s the record the auditor wants to see, and it’s the one most plants can’t produce on demand.
What the auditor watches on the floor
Floor time is where the auditor tests whether the documented system is real. They watch people work, ask operators what they do when something goes wrong, and compare answers to the procedure. Operators who can explain their CCP monitoring in plain language do more for your audit than any binder. Brief your team, not to memorize scripts — auditors spot rehearsed answers instantly — but to understand the why behind their tasks.
Nonconformities cluster in the same places
No ranking here, just the themes auditors return to, audit after audit: monitoring recorded differently from the written procedure; calibration stickers past their due date on devices tied to food safety decisions; training records that show attendance but no evidence anyone understood the material; corrective actions from the last audit with no proof the fix actually worked; allergen changeovers with no verification record; pest control reports filed but never reviewed by anyone on site. None of these are exotic. They’re ordinary controls, left to drift.
Walk your plant with fresh eyes a week before. Check the calibration stickers yourself. Ask a line operator to show you where the allergen cleaning verification record lives. If they can’t find it in thirty seconds, the auditor won’t find it either.
Yeah, but actually — perfect paperwork can still fail
Here’s the uncomfortable part: a plant with flawless records and a team that doesn’t follow them fails harder than a plant with messy records and a team that does. Auditors are trained to notice the gap between the binder and behavior — the sanitizer concentration log that says 200 ppm while the test strips in the bucket read zero, the metal detector check recorded every hour while the reject bin hasn’t been emptied all shift. Records describe the system. Behavior is the system. Fix behavior first; the records will follow.
After the closing meeting, the clock starts
The closing meeting is where the auditor presents findings and agrees on what was found — not a negotiation, but your last chance to make sure each finding is factually accurate. If a finding misstates what the auditor saw, say so now, with evidence. Once the report is issued, correcting the record gets much harder.
Correction is not corrective action — auditors know the difference
Every finding needs three layers, and mixing them up is the most common CAPA failure in food plants:
- Correction — the immediate fix. Segregate the affected product, recalibrate the thermometer, retrain the operator today.
- Corrective action — kill the root cause so it doesn’t recur. Run the 5 Whys or a fishbone past the symptom until you hit the systemic reason, then change the system.
- Preventive action — look sideways. Where else could the same root cause be hiding? Apply the fix there too.
Submit evidence, not promises. Updated procedures with the changes highlighted, completed forms showing the new process in use, training records for the retrained staff, before-and-after photos where they help. Label everything by nonconformity number. And remember the BRCGS rule that catches plants every year: recurring minors get upgraded to majors at the next audit. A minor you “fixed” without addressing the root cause comes back bigger.
What the certification decision actually looks like
The auditor recommends; the certification body decides. Under SQF, the audit report stays in draft until technical review by the certification body — the auditor’s findings are recommendations until that review lands. Once your corrective actions are accepted and closed, the certification decision follows, and the certificate issues. Then the cycle continues: surveillance audits every year, one of them unannounced under FSSC 22000, recertification before expiry. Certification isn’t a finish line. It’s the start of a three-year maintenance contract with your own system.
Start with the records, not the deep clean
Auditors don’t fail plants for dusty corners. They fail them for monitoring logs nobody can explain, calibration stickers past their date, and last year’s corrective actions with no evidence the fix held. Two weeks of honest record review beats two days of panic cleaning every time. Open your CCP logs tonight. Read them like a stranger. Fix what you find. That’s the whole playbook.