ISO 22000 Documentation Requirements

Training Outcomes Within Your Budget!

We ensure quality, budget-alignment, and timely delivery by our expert instructors.

ISO 22000 Documentation Requirements

Last updated on August 18th, 2026

ISO 22000 Documentation Requirements

Understanding ISO 22000 Food Safety makes it easier to understand how these documents fit into the food safety management system.

ISO 22000 Documentation Requirements and Best Practices

Food safety depends on clear instructions and proper records. Policies, procedures, plans, forms, and records explain what needs to be done and provide proof of completed activities. Understanding ISO 22000 Food Safety makes it easier to understand how these documents fit into the food safety management system. Good ISO 22000 documentation keeps important information organized and under control rather than spread across folders, spreadsheets, and paper files. It also makes it easier for staff to find the latest instructions, understand their duties, and retrieve records when they are needed.

Enroll Now for ISO 22000 Foundation Certification

What Does ISO 22000 Require for Documentation?

ISO 22000 requires organizations to maintain and retain documented information needed to establish, operate, control, and demonstrate an effective Food Safety Management System. Depending on the requirement, this may include the FSMS scope, food safety policy, objectives, PRP information, hazard-analysis and hazard-control information, monitoring evidence, traceability records, competence evidence, verification results, corrective actions, internal audit results, and management review records.

ISO 22000 Documentation Requirements at a Glance

The documentation structure should support normal food safety work rather than exist only for an audit. Some information tells people what should happen, while other information provides evidence that an activity was carried out.

Management System Information

This group can include the FSMS scope, food safety policy, objectives, assigned responsibilities, planning information, and other controlled information needed to manage the system.

Operational Food Safety Information

Operational information explains how food safety work should be carried out, it can include basic hygiene programs, hazard-control plans, monitoring steps, traceability details, emergency instructions, work procedures, product specifications, and other controls used in food safety activities.

Records and Evidence

Records are useful for keeping track of completed work and showing when each activity took place, these records may include temperature logs, staff training details, product tracking information, verification results, corrective actions, internal audit findings, and notes from management reviews.

Documentation Area

Example

Main Purpose

Typical Type

System scope

Facility or process scope

Defines FSMS boundaries

Maintained information

Policy

Food safety policy

Establishes direction

Maintained information

Hazard control

Hazard-control plan

Defines controls and monitoring

Maintained information

Monitoring

Temperature log

Records monitoring results

Retained evidence

Competence

Training record

Shows completed competence activity

Retained evidence

Improvement

Corrective action record

Shows how a problem was addressed

Retained evidence

What Are Mandatory Documents in ISO 22000?

ISO 22000 does not require every supporting file to exist as a separate document with a fixed title. Some documented information is explicitly required to be maintained or retained, while other procedures, instructions, registers, or forms may be created because the organization needs them to operate and control its FSMS effectively.

The documents needed can differ from one organization to another. The size of the organization, types of products, work processes, food safety risks, legal requirements, customer needs, technology, and place in the food supply chain all affect what must be documented. The main requirement is that important information is available, properly controlled, kept up to date when needed, and stored as evidence when required.

ISO 22000 Documents List and Their Purpose

A useful checklist should show what the information is used for, not just provide file names. A practical list of documents for iso 22000 may include the following food safety management system documents.

Documented Information

Main Purpose

Main Clause Area

Status in the System

FSMS scope

Defines the boundaries and applicability of the FSMS

Clause 4

Required documented information

Food safety policy

States the organization's food safety direction

Clause 5

Required documented information

Food safety objectives

Defines intended food safety results

Clause 6

Required documented information

PRP information

Supports basic conditions needed for food safety

Clause 8

Required as applicable to the system

Product and raw-material information

Supports hazard analysis

Clause 8

Maintained as needed for hazard analysis

Flow diagrams and process descriptions

Shows process steps used during hazard analysis

Clause 8

Maintained and verified as required

Hazard-analysis information

Records hazard identification, assessment, and control decisions

Clause 8

Controlled documented information

Hazard-control plan

Defines OPRPs, CCPs, monitoring, corrections, and responsibilities

Clause 8

Required documented information

Monitoring results

Shows whether operational controls were checked

Clause 8

Retained evidence

Validation evidence

Supports the suitability of selected control measures

Clause 8

Retained evidence

Traceability information

Supports identification and tracking through the food chain

Clause 8

Maintained and retained as applicable

Competence evidence

Shows that relevant people are competent

Clause 7

Retained evidence

Internal audit results

Shows whether the FSMS is being evaluated

Clause 9

Retained evidence

Management review results

Records management review decisions and outputs

Clause 9

Retained evidence

Nonconformity and corrective action records

Shows how problems were corrected and addressed

Clause 10

Retained evidence

Work instructions and local forms

Supports consistent work where needed

Depends on process

Organization-defined

The last column is important because not every useful procedure or form should be presented as a separately mandated ISO document. Organizations can decide the level of supporting detail needed for effective control.

Documents Should Match Actual Work

A document is useful when it matches the actual work being carried out. For example, a cold-storage instruction can explain what needs to be checked, who performs the check, the required limit, and what action to take if the limit is not met, the completed monitoring record provides proof that the check was carried out.

This approach makes the food safety documentation system easier to use and reduces the risk of keeping procedures that look correct on paper but do not match operations.

Maintained vs Retained Documented Information

One of the simplest ways to organize food safety management system documents is to separate information that must remain current from information that must be kept as evidence.

What Is Maintained Documented Information?

Maintained information supports day-to-day food safety activities and should be reviewed when important changes occur.

Examples include:

  • Food safety policies
  • Procedures
  • Work instructions
  • Process specifications
  • Hazard-control plans
  • Responsibility statements

Changes to ingredients, equipment, facility layout, process steps, staff responsibilities, legal requirements, or food safety controls may require the related documents to be reviewed and updated.

What Is Retained Documented Information?

Retained information keeps a clear record of what was completed and the results obtained. This may include monitoring results, training records, product tracking details, inspection results, verification records, internal audit findings, corrective action records, and management review records.

Maintained Information

Retained Information

Kept current

Kept as evidence

Guides present work

Shows completed or past activity

Changes when relevant conditions change

Preserves the result that occurred

Cleaning procedure

Completed cleaning record

Hazard-control plan

Monitoring result

Work instruction

Inspection record

iso-22000-maintained-versus-retained-documents-comparison

Documentation Requirements by ISO 22000 Clause

Documented information appears across the Food Safety Management System. The table below summarizes the main areas where documentation commonly supports the requirements.

ISO 22000 Clause

Main Documentation Focus

Clause 4

Organizational context, interested parties, climate-change relevance under Amendment 1:2024, and FSMS scope

Clause 5

Food safety policy, responsibilities, authorities, and leadership-related information

Clause 6

Risks and opportunities, food safety objectives, and planning

Clause 7

Resources, competence, awareness, communication, and documented information

Clause 8

PRPs, traceability, emergency preparedness, hazard analysis, OPRPs, CCPs, monitoring, validation, verification, and operational control

Clause 9

Monitoring and measurement results, internal audits, and management review

Clause 10

Nonconformities, corrective actions, updating, and continual improvement

Not every topic in the table requires its own separate procedure or file. The purpose of the table is to show where documented information supports the FSMS and where particular evidence may need to be maintained or retained.

Amendment 1:2024 applies to ISO 22000:2018 and introduces climate action changes into the management-system context requirements. Organizations should therefore consider the amendment when reviewing Clause 4 information.

Clause 7.5 Documented Information

Clause 7.5 sets out how documented information should be managed, documents need to be created correctly, updated when changes occur, clearly identified, available to the right people, and protected from loss or unauthorized changes. Records also need to be stored properly, kept for the required period, and disposed of in a controlled manner when they are no longer needed.

A practical control approach may check whether information is:

  • Clearly identified
  • Reviewed before being issued
  • Approved by the responsible person
  • Available where it is needed
  • Protected from loss or unauthorized changes
  • Updated when relevant changes occur
  • Stored so it remains readable and easy to find
  • Changes and revisions properly recorded
  • Kept for the required period
  • Archived or disposed of according to established rules

A controlled document may include its title, identification number, responsible person, revision number, effective date, approval details, and record of changes. The main purpose is to make sure staff use the latest information and that important records are kept as reliable proof of completed activities.

ISO 22000 Document Management Process and Internal Controls

The ISO 22000 document management process covers the full life of controlled information. A file should not simply be created, saved, and forgotten.

Creating and Approving Documents

Before creating a procedure or form, first define its purpose and the activity it supports, the responsible person, approval authority, location, and process for making future changes should also be clearly defined.

A controlled document can include the following details:

  • Document title
  • Identification number
  • Department or process
  • Responsible person
  • Approver
  • Revision number
  • Effective date

The review should check that the instructions match the actual work being carried out. Approval confirms that the document is suitable for use.

ISO 22000 Internal Document Control Process

The ISO 22000 document control process helps ensure that staff use the correct and approved information, it can cover document versions, access permissions, distribution, protection, external documents, outdated copies, backups, storage, retrieval, retention, and disposal.

A useful control method should also reduce the chance that an old instruction remains in active use after a replacement has been approved. If a sanitation method changes, for example, obsolete instructions at the work area should be removed, replaced, or clearly prevented from further use.

A second purpose of the internal control process is traceability of change. An organization should be able to identify which version is active, who approved it, when it became effective, and how outdated copies are handled.

iso-22000-document-control-process

Creating Compliance Records

A practical procedure for creating compliance records can follow these steps:

  1. 1. Identify the activity that requires evidence.
  2. 2. Decide what information must be recorded.
  3. 3. Use an approved form or controlled electronic record.
  4. 4. Assign responsibility for completing the record.
  5. 5. Record information when the activity occurs.
  6. 6. Review or verify the entry where required.
  7. 7. Store it in an identified and retrievable location.
  8. 8. Protect it from loss or unauthorized alteration.
  9. 9. Apply the defined retention period.
  10. 10. Dispose of it according to established controls.

Sample ISO 22000 Document Register

A document register gives one place to track controlled information. The fields can be adapted to the organization's system.

Document ID

Document Name

Owner

Revision

Approval

Storage Location

Retention/Status

FS-001

Food Safety Policy

FSMS Lead

Rev 03

Top Management

Controlled Drive

Current

OP-006

Cleaning Instruction

Sanitation Lead

Rev 05

QA Manager

Production Area + Drive

Current

FR-012

CCP Monitoring Form

Production

Rev 02

QA Manager

FSMS Records

Defined retention period

AU-004

Internal Audit Record

Internal Audit Lead

Rev 01

FSMS Lead

Audit Folder

Defined retention period

CA-009

Corrective Action Form

Process Owner

Rev 04

QA Manager

CAPA Folder

Closed record retained

This type of register is an example rather than a required ISO template. Its value is that document owners, revisions, approvals, storage locations, and retention rules can be checked without opening every file.

Organizations responsible for building or maintaining an FSMS may also need practical knowledge of document control, implementation planning, operational requirements, and continual improvement. ISO 22000 Lead Implementer Training can support a deeper understanding of how these requirements are applied when developing and maintaining a food safety management system. 

Document Roles and ISO 22000 Audit Readiness

A controlled system works best when everyone knows who is responsible, an organization can assign these duties within its current structure, so a separate document controller may not be needed.

Document Management Roles in ISO 22000 System

Typical responsibilities may look like this:

Role

Typical Documentation Responsibility

Top management

Approves policy and provides overall direction

Food safety team leader

Coordinates important FSMS information

Document controller

Manages versions, access, issue, and archive controls where this role exists

Process owner

Keeps procedures technically accurate

Department manager

Reviews operational information within the department

Employees

Follow approved instructions and complete required records

Clear ownership helps prevent documents from becoming outdated because everyone assumed someone else was responsible.

ISO 22000 Risk Assessment Procedure and Records

When an organization documents its ISO 22000 risk assessment procedure, it should clearly separate management-system risks and opportunities from operational food safety hazard analysis.

For operational food safety hazards, records may show how hazards were identified, assessed, controlled, monitored, and verified. A simplified sequence can be:

Hazard identification → hazard assessment → control-measure selection → CCP/OPRP categorization → validation → monitoring → correction or corrective action when needed → verification

The wider management-system risk process should not be confused with food safety hazard analysis. Clause 6 deals with organizational risks and opportunities, while detailed operational food safety hazards are addressed within Clause 8.

ISO 22000 Document Control System Examples

ISO 22000 document control system examples can be understood more clearly by looking at how common records move through the control process.

Example

Document Control Flow

Result

Cleaning procedure

Owner → Revision → Approval → Controlled issue

Completed cleaning record

Temperature form

Controlled template → Employee entry → Review

Retained monitoring record

Corrective action form

Problem → Correction → Cause → Assigned action → Verification

Closed corrective action record

These examples show how controlled documents guide current activities, while completed records provide evidence that the required work was carried out.

How to Conduct ISO 22000 Gap Analysis

A documentation gap analysis compares applicable requirements with the information already in use.

  1. 1. Identify the applicable ISO 22000 requirements.
  2. 2. List existing policies, procedures, plans, forms, and records.
  3. 3. Match current information against relevant requirements.
  4. 4. Identify missing, outdated, duplicated, or uncontrolled information.
  5. 5. Assign an owner and corrective action.
  6. 6. Update or create the needed information.
  7. 7. Confirm that the change has been completed and implemented.

Requirement

Current Information

Gap

Action

Revision control

Sanitation procedure

Revision history missing

Add revision history

Competence evidence

Training completed

Some records incomplete

Complete and control records

Monitoring

Existing form

Old limits shown

Update controlled template

Traceability

Records available

Retrieval is slow

Define storage and naming rules

The review may also identify unnecessary compliance documents for food safety that can be merged, simplified, or removed if they do not support an actual requirement or operational need.

How to Prepare ISO 22000 Documentation for Audit

Before an external audit, check that the documents match the work being carried out and that required records can be found easily. Common checks include document versions, approvals, outdated copies, traceability records, corrective action records, monitoring records, storage, and retention periods.

The goal is not to create new paperwork just before an audit. The documentation should show how the FSMS normally operates.

Documentation Audit Checklist for ISO 22000

Use this short check before an internal or external assessment:

  • Check that current procedures have the correct revision number.
  • Make sure required approvals are in place.
  • Remove outdated copies or clearly mark them as obsolete.
  • Check that monitoring and verification records are complete.
  • Make sure traceability records can be found when needed.
  • Confirm that corrective actions have supporting records.
  • Check that records are kept for the required period.
  • Compare written procedures with the work actually being carried out.

An ISO 22000 internal audit checklist can then be used to test whether the documented arrangements are followed in practice. The checklist should evaluate the management system rather than simply confirm that files exist.

Quick Note on ISO 22000 and FSSC 22000

Area

ISO 22000

FSSC 22000

Main purpose

Provides requirements for a Food Safety Management System

Builds on ISO 22000 with additional scheme and sector requirements

Core standard

ISO 22000:2018

ISO 22000:2018 plus applicable PRP requirements and FSSC additional requirements

PRP requirements

Addressed within the ISO 22000 framework

Uses applicable sector-specific PRP requirements

Additional requirements

No separate FSSC scheme requirements

Includes FSSC-specific additional requirements

Documentation impact

Focuses on documented information needed for the FSMS

May require additional documented controls to meet FSSC requirements

Current status

ISO 22000:2018 remains the published edition

FSSC 22000 Version 7 was released in May 2026

The ISO 22000 vs FSSC 22000 difference becomes important when organizations plan their documentation. A document set created only around ISO 22000 may not cover every FSSC requirement, so organizations using the FSSC scheme should also review the applicable PRP and additional scheme requirements. 

Documentation Best Practices

A practical system should make important information easy to find, use, and manage. The following practices can help:

  • Assign a clear owner to each controlled document.
  • Use consistent file names and document numbers.
  • Keep approval and revision details easy to see.
  • Avoid having multiple forms for the same activity.
  • Remove outdated versions from active use.
  • Set record-retention periods based on legal, customer, and business requirements.
  • Review related documents when processes or controls change.
  • Keep forms simple enough to complete during normal work.
  • Protect electronic records with suitable access and backup controls.
  • Check regularly that written instructions match the work being carried out.

The document management system should match the size and needs of the organization, small business may manage documents using a controlled folder and a simple register. A larger organization may need document-management software to handle approvals, access permissions, version history, and review reminders.

Professionals working with food safety systems may also need broader knowledge of standards, implementation practices, auditing, and compliance. SterlingNext Food Safety Training Programs provide learning options across these areas for those developing their understanding of food safety management. 

Conclusion

Effective ISO 22000 documentation should make food safety work clear and easier to manage, maintained information explains how tasks should be carried out, while retained information shows what was done and what results were recorded. Clear ownership, approval, revision control, storage, retrieval, retention, and regular review help keep information accurate and prevent outdated documents from being used. A good documentation system does not need a large number of files. It needs the right information, based on actual work, applicable requirements, and food safety controls, with important records easy to find when needed.

Get Certified With Industry Level Projects & Fast Track Your Career

Checkout Top 10 Highest Paying Jobs

Frequently Asked Questions

No. ISO 22000 does not require a separate file called a “Food Safety Manual.” The standard requires certain documented information to support the Food Safety Management System (FSMS), manual can still be useful for explaining how the system is organized, who is responsible for each activity, and how different documents and records fit together.

Clause 7.5 deals with documented information, it explains how important information should be prepared, updated, identified, stored, protected, accessed, and kept when needed. The aim is to make sure current information is available and completed records are not lost or changed without control.

A document explains what should be done, while a record shows what was actually done, for example, a temperature-checking instruction explains how to take and record a temperature. The completed temperature log shows the actual temperature found during the check.

Yes. Food safety records can be kept electronically, digital records should remain easy to read, find, and access when required. Proper access controls, backups, protection from unwanted changes, storage arrangements, and retention periods should also be in place.

Documents should be approved by people who have the right authority and enough knowledge of the activity covered by the document, person responsible for approving a policy may therefore be different from the person approving a work instruction or form.

There is no single retention period for every food safety record, retention period should be decided based on legal requirements, customer needs, contracts, traceability needs, product characteristics, and the organization's own requirements.

Documents should be reviewed whenever a change could make the information incorrect or outdated, this may happen after changes to products, ingredients, equipment, processes, hazards, responsibilities, legal requirements, customer requirements, or food safety controls. A regular review schedule can also be used.

Before an external audit, check that documents have the correct approval and revision status. Obsolete copies should be removed or clearly controlled, completed records, traceability information, corrective actions, storage arrangements, and retention periods should also be checked. Most importantly, the written information should match what is actually being done.

An internal audit checklist is used to check whether the FSMS is being followed and working as intended, document control has a different role. It makes sure documents are approved, current, protected, easy to find, and properly managed from creation through disposal.

A basic structure can group information into policies and scope, procedures, work instructions, forms, and completed records, each document can have a responsible person, storage location, revision number, access rules, and retention period. A master list of documents can also make it easier to see what is current and what needs updating.