Principles 4–5: Monitoring and Corrective Action
Watch the lesson video: Principles 4–5: Monitoring and Corrective Action (0:50)
Principle 4: Establish a system to monitor control of CCPs. Monitoring is the scheduled measurement or observation that tells you whether the CCP is under control. If monitoring stops, the CCP is uncontrolled. Every monitoring procedure answers four questions: what is measured, how it is measured, when it is done, and who does it.
What: the parameter from the critical limit — product centre temperature, pH, metal detector sensitivity check, conveyor speed. How: the exact method and equipment — calibrated probe thermometer, model and ID number, pH meter with buffer calibration. Records must show which instrument was used; “thermometer” is not an instrument ID. When: the frequency, set by risk — every batch for batch processes, every 30 minutes for continuous cooking, continuous recording with alarms where the risk justifies it. Who: the role responsible, named by position, trained and signed off. “The operator” is acceptable if every operator on that line is trained; the supervisor is acceptable if the supervisor is actually at the line.
Design the frequency around one question: how much product could be affected before the next check catches a deviation? In a continuous cooker checked every 30 minutes, a failure discovered at 10:30 puts everything produced since 10:00 under suspicion. Shorten the interval and you shrink the hold pile — that is the real cost argument for more frequent checks. Continuous monitoring with chart recorders or digital loggers plus alarms is the strongest option: it catches the deviation the moment it happens and timestamps the evidence. Where checks are manual, the record must be made at the time of the check, signed by the person who did it. Monitoring records filled in at the end of the shift from memory are a classic audit failure, and auditors know how to spot them.
Calibration sits underneath all of this. A monitoring instrument that reads wrong makes every record worthless. Thermometers, pH meters, and metal detector test pieces need scheduled calibration against traceable references, with the results recorded. Codex counts calibration of monitoring equipment as a verification activity — in practice, it is what keeps monitoring honest day to day.

Principle 5: Establish corrective actions
Principle 5 covers the bad day: the corrective actions to take when monitoring shows a deviation from a critical limit. These decisions are made now, in calm conditions, because people under pressure improvise — and improvisation during a deviation is how unsafe product gets shipped. For every CCP, the corrective action is written in advance, trained, and available at the line.
Every corrective action has two components. First, bring the process back under control: stop the line, adjust the cooker, recalibrate the detector, divert product flow. The procedure names who has authority to stop the line — if that authority is unclear, the line keeps running while people look for a supervisor. Second, control the affected product: identify everything produced since the last good monitoring check, place it on hold with physical segregation and clear HOLD labelling, and evaluate it before any release decision. Affected product must never drift back into normal flow on someone’s judgement call.
Product evaluation follows a fixed order. A trained, designated person assesses the deviation: what happened, how far outside the limit, for how long, and what the evidence says about safety. The options are release (only with evidence the product is safe), rework through a validated process, divert to a safe use, or destroy. “It was only two degrees under” is not an evaluation — either the evidence shows the product is safe, or it does not ship. Every recall investigation finds a deviation that someone decided was probably fine.
Corrective action records carry: the deviation (what, when, how discovered), the quantity and identity of product affected, the disposition decision and who made it, the root cause, and what was done to prevent recurrence. A deviation that repeats is a system failure, not bad luck — recurring deviations mean the plan, the equipment, or the training is wrong, and the verification review must catch the pattern.