ISO 22000
Evidence request list. 39 controls, 39 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Context
Determine internal and external issues relevant to food safety and the FSMS.
- Context analysis
- PESTLE
- Issue register
- Context generic
- Food safety issues missed
Identify interested parties relevant to the FSMS and their requirements including statutory and customer.
- Stakeholder register
- Requirements log
- Compliance obligations
- Customer specs not captured
- Regulatory list stale
Define scope including products, processes, sites, and end-to-end activities covered.
- Scope statement
- Site list
- Process map
- Scope ambiguous
- Outsourced steps excluded
Evaluation
Monitor and measure FSMS performance, evaluate effectiveness, and analyse data.
- KPI dashboard
- Trend analysis
- Reports
- No trend analysis
- KPIs not reviewed
Conduct internal audits to confirm FSMS conformance and effectiveness on a planned schedule.
- Audit programme
- Reports
- CAPA log
- Audits incomplete
- CAPA overdue
Top management reviews the FSMS at planned intervals using defined inputs and outputs.
- Review minutes
- Input packs
- Action register
- Inputs incomplete
- Actions not tracked
ISO 22000: OH&S Policy & Planning
OH&S policy and commitment. Control from ISO 22000 framework, domain: ISO 22000: OH&S Policy & Planning.
- emergency response plan
- internal audit report
- OHS policy
- hazard identification register
- PPE issue records
- weak contractor onboarding
- insufficient incident root cause analysis
- gaps in legal compliance tracking
Hazard identification and risk assessment. Control from ISO 22000 framework, domain: ISO 22000: OH&S Policy & Planning.
- internal audit report
- OHS policy
- hazard identification register
- PPE issue records
- incident investigation reports
- emergency response plan
- weak contractor onboarding
- insufficient incident root cause analysis
- gaps in legal compliance tracking
- incomplete hazard register
Legal and regulatory compliance. Control from ISO 22000 framework, domain: ISO 22000: OH&S Policy & Planning.
- incident investigation reports
- emergency response plan
- internal audit report
- insufficient incident root cause analysis
- gaps in legal compliance tracking
- incomplete hazard register
- missing worker consultation evidence
- weak contractor onboarding
OH&S objectives and action plans. Control from ISO 22000 framework, domain: ISO 22000: OH&S Policy & Planning.
- emergency response plan
- internal audit report
- OHS policy
- hazard identification register
- PPE issue records
- incident investigation reports
- gaps in legal compliance tracking
- incomplete hazard register
- missing worker consultation evidence
- weak contractor onboarding
Worker consultation and participation. Control from ISO 22000 framework, domain: ISO 22000: OH&S Policy & Planning.
- internal audit report
- OHS policy
- hazard identification register
- missing worker consultation evidence
- weak contractor onboarding
- insufficient incident root cause analysis
- gaps in legal compliance tracking
- incomplete hazard register
ISO 22000: Operational Controls
Elimination and substitution of hazards. Control from ISO 22000 framework, domain: ISO 22000: Operational Controls.
- incident investigation reports
- emergency response plan
- internal audit report
- incomplete hazard register
- missing worker consultation evidence
- weak contractor onboarding
Engineering and administrative controls. Control from ISO 22000 framework, domain: ISO 22000: Operational Controls.
- hazard identification register
- PPE issue records
- incident investigation reports
- insufficient incident root cause analysis
- gaps in legal compliance tracking
- incomplete hazard register
- missing worker consultation evidence
Personal protective equipment management. Control from ISO 22000 framework, domain: ISO 22000: Operational Controls.
- incident investigation reports
- emergency response plan
- internal audit report
- OHS policy
- hazard identification register
- incomplete hazard register
- missing worker consultation evidence
- weak contractor onboarding
Emergency preparedness and response. Control from ISO 22000 framework, domain: ISO 22000: Operational Controls.
- OHS policy
- hazard identification register
- PPE issue records
- incident investigation reports
- emergency response plan
- internal audit report
- gaps in legal compliance tracking
- incomplete hazard register
- missing worker consultation evidence
Contractor and visitor safety management. Control from ISO 22000 framework, domain: ISO 22000: Operational Controls.
- hazard identification register
- PPE issue records
- incident investigation reports
- insufficient incident root cause analysis
- gaps in legal compliance tracking
- incomplete hazard register
- missing worker consultation evidence
ISO 22000: Performance & Improvement
Incident investigation and reporting. Control from ISO 22000 framework, domain: ISO 22000: Performance & Improvement.
- incident investigation reports
- emergency response plan
- internal audit report
- OHS policy
- insufficient incident root cause analysis
- gaps in legal compliance tracking
- incomplete hazard register
- missing worker consultation evidence
OH&S monitoring and measurement. Control from ISO 22000 framework, domain: ISO 22000: Performance & Improvement.
- PPE issue records
- incident investigation reports
- emergency response plan
- internal audit report
- missing worker consultation evidence
- weak contractor onboarding
- insufficient incident root cause analysis
- gaps in legal compliance tracking
Internal OH&S audit program. Control from ISO 22000 framework, domain: ISO 22000: Performance & Improvement.
- incident investigation reports
- emergency response plan
- internal audit report
- missing worker consultation evidence
- weak contractor onboarding
- insufficient incident root cause analysis
- gaps in legal compliance tracking
- incomplete hazard register
Management review and continual improvement. Control from ISO 22000 framework, domain: ISO 22000: Performance & Improvement.
- incident investigation reports
- emergency response plan
- internal audit report
- OHS policy
- gaps in legal compliance tracking
- incomplete hazard register
- missing worker consultation evidence
- weak contractor onboarding
- insufficient incident root cause analysis
Corrective actions and lessons learned. Control from ISO 22000 framework, domain: ISO 22000: Performance & Improvement.
- internal audit report
- OHS policy
- hazard identification register
- PPE issue records
- incident investigation reports
- missing worker consultation evidence
- weak contractor onboarding
- insufficient incident root cause analysis
Improvement
Identify nonconformities, take action to control and correct, and address root causes.
- NC log
- RCA
- CAPA records
- RCA shallow
- CAPA recurring
Continually improve the suitability, adequacy, and effectiveness of the FSMS.
- Improvement log
- Metrics trend
- Project records
- No improvement programme
- Metrics flat
Leadership
Top management demonstrates commitment to food safety with policy, resources, and accountability.
- Management commitment statement
- Budget
- Org chart
- Token leadership
- Under-resourced FSMS
Establish a food safety policy appropriate to purpose, communicated and reviewed.
- Food safety policy
- Communication records
- Review minutes
- Policy not communicated to all
- No review cycle
Define and communicate FSMS roles including food safety team leader and team responsibilities.
- RACI
- FS team charter
- Job descriptions
- No nominated team leader
- Authority unclear
Operation
Establish, implement, and maintain PRPs to support control of food safety hazards.
- PRP register
- Cleaning schedules
- Pest control records
- PRPs not verified
- Pest records missing
Establish a traceability system to uniquely identify incoming materials and outgoing products.
- Traceability procedure
- Lot records
- Mock recall results
- Mock recall not annual
- Lot codes inconsistent
Plan for and respond to emergencies affecting food safety including communication and recovery.
- Emergency plan
- Drill records
- After-action reports
- No drills
- Plan not tested
Conduct hazard analysis, determine CCPs and OPRPs, set critical limits, monitor, and verify.
- Hazard analysis
- HACCP plan
- CCP logs
- CCP limits unjustified
- Monitoring gaps
Update PRPs and the hazard control plan based on new information, changes, or verification results.
- Change log
- Updated plans
- Verification records
- Plans static
- Changes not triggered
Ensure monitoring and measurement equipment is fit for purpose and calibrated.
- Calibration schedule
- Certificates
- Verification logs
- Out-of-cal equipment in use
- No traceable standards
Identify, evaluate, and control potentially unsafe products to prevent unintended release.
- NC procedure
- Hold log
- Recall procedure
- No formal hold/release
- Recall untested
Planning
Plan actions to address food safety risks and opportunities and integrate into FSMS processes.
- Risk register
- Opportunity log
- Action plan
- Risk treated as HACCP only
- No opportunities captured
Set measurable food safety objectives and plan how to achieve them with resources and timelines.
- Objectives register
- Plans
- Resource allocation
- Objectives not SMART
- No accountability
Support
Provide resources for the FSMS including people, infrastructure, work environment, and external development.
- Resource plan
- Facility specs
- Environment monitoring
- Old equipment
- Environmental controls weak
Ensure persons doing work affecting food safety are competent with training, education, and experience.
- Training matrix
- Records
- Assessments
- Refresher overdue
- Contractors untrained
Establish internal and external communication relevant to food safety including supplier and customer channels.
- Comms plan
- Supplier portal
- Recall channel
- No recall comms plan
- Supplier issues unreported
Control documented information required by the FSMS for creation, update, distribution, and retention.
- Document control procedure
- DMS
- Retention schedule
- Uncontrolled docs in use
- No retention
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 22000 framework page.