Skip to content

Evidence request lists

ISO 22000

Evidence request list. 39 controls, 39 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Context

ISO22000-4.1
Understanding the organization and its context

Determine internal and external issues relevant to food safety and the FSMS.

Artefacts an auditor will ask for
  • Context analysis
  • PESTLE
  • Issue register
Where this commonly fails
  • Context generic
  • Food safety issues missed
ISO22000-4.2
Needs and expectations of interested parties

Identify interested parties relevant to the FSMS and their requirements including statutory and customer.

Artefacts an auditor will ask for
  • Stakeholder register
  • Requirements log
  • Compliance obligations
Where this commonly fails
  • Customer specs not captured
  • Regulatory list stale
ISO22000-4.3
Scope of the FSMS

Define scope including products, processes, sites, and end-to-end activities covered.

Artefacts an auditor will ask for
  • Scope statement
  • Site list
  • Process map
Where this commonly fails
  • Scope ambiguous
  • Outsourced steps excluded

Evaluation

ISO22000-9.1
Monitoring, measurement, analysis, evaluation

Monitor and measure FSMS performance, evaluate effectiveness, and analyse data.

Artefacts an auditor will ask for
  • KPI dashboard
  • Trend analysis
  • Reports
Where this commonly fails
  • No trend analysis
  • KPIs not reviewed
ISO22000-9.2
Internal audit

Conduct internal audits to confirm FSMS conformance and effectiveness on a planned schedule.

Artefacts an auditor will ask for
  • Audit programme
  • Reports
  • CAPA log
Where this commonly fails
  • Audits incomplete
  • CAPA overdue
ISO22000-9.3
Management review

Top management reviews the FSMS at planned intervals using defined inputs and outputs.

Artefacts an auditor will ask for
  • Review minutes
  • Input packs
  • Action register
Where this commonly fails
  • Inputs incomplete
  • Actions not tracked

ISO 22000: OH&S Policy & Planning

ISO22000-01
OH&S policy and commitment

OH&S policy and commitment. Control from ISO 22000 framework, domain: ISO 22000: OH&S Policy & Planning.

Artefacts an auditor will ask for
  • emergency response plan
  • internal audit report
  • OHS policy
  • hazard identification register
  • PPE issue records
Where this commonly fails
  • weak contractor onboarding
  • insufficient incident root cause analysis
  • gaps in legal compliance tracking
ISO22000-02
Hazard identification and risk assessment

Hazard identification and risk assessment. Control from ISO 22000 framework, domain: ISO 22000: OH&S Policy & Planning.

Artefacts an auditor will ask for
  • internal audit report
  • OHS policy
  • hazard identification register
  • PPE issue records
  • incident investigation reports
  • emergency response plan
Where this commonly fails
  • weak contractor onboarding
  • insufficient incident root cause analysis
  • gaps in legal compliance tracking
  • incomplete hazard register
ISO22000-03
Legal and regulatory compliance

Legal and regulatory compliance. Control from ISO 22000 framework, domain: ISO 22000: OH&S Policy & Planning.

Artefacts an auditor will ask for
  • incident investigation reports
  • emergency response plan
  • internal audit report
Where this commonly fails
  • insufficient incident root cause analysis
  • gaps in legal compliance tracking
  • incomplete hazard register
  • missing worker consultation evidence
  • weak contractor onboarding
ISO22000-04
OH&S objectives and action plans

OH&S objectives and action plans. Control from ISO 22000 framework, domain: ISO 22000: OH&S Policy & Planning.

Artefacts an auditor will ask for
  • emergency response plan
  • internal audit report
  • OHS policy
  • hazard identification register
  • PPE issue records
  • incident investigation reports
Where this commonly fails
  • gaps in legal compliance tracking
  • incomplete hazard register
  • missing worker consultation evidence
  • weak contractor onboarding
ISO22000-05
Worker consultation and participation

Worker consultation and participation. Control from ISO 22000 framework, domain: ISO 22000: OH&S Policy & Planning.

Artefacts an auditor will ask for
  • internal audit report
  • OHS policy
  • hazard identification register
Where this commonly fails
  • missing worker consultation evidence
  • weak contractor onboarding
  • insufficient incident root cause analysis
  • gaps in legal compliance tracking
  • incomplete hazard register

ISO 22000: Operational Controls

ISO22000-06
Elimination and substitution of hazards

Elimination and substitution of hazards. Control from ISO 22000 framework, domain: ISO 22000: Operational Controls.

Artefacts an auditor will ask for
  • incident investigation reports
  • emergency response plan
  • internal audit report
Where this commonly fails
  • incomplete hazard register
  • missing worker consultation evidence
  • weak contractor onboarding
ISO22000-07
Engineering and administrative controls

Engineering and administrative controls. Control from ISO 22000 framework, domain: ISO 22000: Operational Controls.

Artefacts an auditor will ask for
  • hazard identification register
  • PPE issue records
  • incident investigation reports
Where this commonly fails
  • insufficient incident root cause analysis
  • gaps in legal compliance tracking
  • incomplete hazard register
  • missing worker consultation evidence
ISO22000-08
Personal protective equipment management

Personal protective equipment management. Control from ISO 22000 framework, domain: ISO 22000: Operational Controls.

Artefacts an auditor will ask for
  • incident investigation reports
  • emergency response plan
  • internal audit report
  • OHS policy
  • hazard identification register
Where this commonly fails
  • incomplete hazard register
  • missing worker consultation evidence
  • weak contractor onboarding
ISO22000-09
Emergency preparedness and response

Emergency preparedness and response. Control from ISO 22000 framework, domain: ISO 22000: Operational Controls.

Artefacts an auditor will ask for
  • OHS policy
  • hazard identification register
  • PPE issue records
  • incident investigation reports
  • emergency response plan
  • internal audit report
Where this commonly fails
  • gaps in legal compliance tracking
  • incomplete hazard register
  • missing worker consultation evidence
ISO22000-10
Contractor and visitor safety management

Contractor and visitor safety management. Control from ISO 22000 framework, domain: ISO 22000: Operational Controls.

Artefacts an auditor will ask for
  • hazard identification register
  • PPE issue records
  • incident investigation reports
Where this commonly fails
  • insufficient incident root cause analysis
  • gaps in legal compliance tracking
  • incomplete hazard register
  • missing worker consultation evidence

ISO 22000: Performance & Improvement

ISO22000-11
Incident investigation and reporting

Incident investigation and reporting. Control from ISO 22000 framework, domain: ISO 22000: Performance & Improvement.

Artefacts an auditor will ask for
  • incident investigation reports
  • emergency response plan
  • internal audit report
  • OHS policy
Where this commonly fails
  • insufficient incident root cause analysis
  • gaps in legal compliance tracking
  • incomplete hazard register
  • missing worker consultation evidence
ISO22000-12
OH&S monitoring and measurement

OH&S monitoring and measurement. Control from ISO 22000 framework, domain: ISO 22000: Performance & Improvement.

Artefacts an auditor will ask for
  • PPE issue records
  • incident investigation reports
  • emergency response plan
  • internal audit report
Where this commonly fails
  • missing worker consultation evidence
  • weak contractor onboarding
  • insufficient incident root cause analysis
  • gaps in legal compliance tracking
ISO22000-13
Internal OH&S audit program

Internal OH&S audit program. Control from ISO 22000 framework, domain: ISO 22000: Performance & Improvement.

Artefacts an auditor will ask for
  • incident investigation reports
  • emergency response plan
  • internal audit report
Where this commonly fails
  • missing worker consultation evidence
  • weak contractor onboarding
  • insufficient incident root cause analysis
  • gaps in legal compliance tracking
  • incomplete hazard register
ISO22000-14
Management review and continual improvement

Management review and continual improvement. Control from ISO 22000 framework, domain: ISO 22000: Performance & Improvement.

Artefacts an auditor will ask for
  • incident investigation reports
  • emergency response plan
  • internal audit report
  • OHS policy
Where this commonly fails
  • gaps in legal compliance tracking
  • incomplete hazard register
  • missing worker consultation evidence
  • weak contractor onboarding
  • insufficient incident root cause analysis
ISO22000-15
Corrective actions and lessons learned

Corrective actions and lessons learned. Control from ISO 22000 framework, domain: ISO 22000: Performance & Improvement.

Artefacts an auditor will ask for
  • internal audit report
  • OHS policy
  • hazard identification register
  • PPE issue records
  • incident investigation reports
Where this commonly fails
  • missing worker consultation evidence
  • weak contractor onboarding
  • insufficient incident root cause analysis

Improvement

ISO22000-10.1
Nonconformity and corrective action

Identify nonconformities, take action to control and correct, and address root causes.

Artefacts an auditor will ask for
  • NC log
  • RCA
  • CAPA records
Where this commonly fails
  • RCA shallow
  • CAPA recurring
ISO22000-10.3
Continual improvement

Continually improve the suitability, adequacy, and effectiveness of the FSMS.

Artefacts an auditor will ask for
  • Improvement log
  • Metrics trend
  • Project records
Where this commonly fails
  • No improvement programme
  • Metrics flat

Leadership

ISO22000-5.1
Leadership and commitment

Top management demonstrates commitment to food safety with policy, resources, and accountability.

Artefacts an auditor will ask for
  • Management commitment statement
  • Budget
  • Org chart
Where this commonly fails
  • Token leadership
  • Under-resourced FSMS
ISO22000-5.2
Food safety policy

Establish a food safety policy appropriate to purpose, communicated and reviewed.

Artefacts an auditor will ask for
  • Food safety policy
  • Communication records
  • Review minutes
Where this commonly fails
  • Policy not communicated to all
  • No review cycle
ISO22000-5.3
Roles, responsibilities, and authorities

Define and communicate FSMS roles including food safety team leader and team responsibilities.

Artefacts an auditor will ask for
  • RACI
  • FS team charter
  • Job descriptions
Where this commonly fails
  • No nominated team leader
  • Authority unclear

Operation

ISO22000-8.2
Prerequisite programmes (PRPs)

Establish, implement, and maintain PRPs to support control of food safety hazards.

Artefacts an auditor will ask for
  • PRP register
  • Cleaning schedules
  • Pest control records
Where this commonly fails
  • PRPs not verified
  • Pest records missing
ISO22000-8.3
Traceability system

Establish a traceability system to uniquely identify incoming materials and outgoing products.

Artefacts an auditor will ask for
  • Traceability procedure
  • Lot records
  • Mock recall results
Where this commonly fails
  • Mock recall not annual
  • Lot codes inconsistent
ISO22000-8.4
Emergency preparedness and response

Plan for and respond to emergencies affecting food safety including communication and recovery.

Artefacts an auditor will ask for
  • Emergency plan
  • Drill records
  • After-action reports
Where this commonly fails
  • No drills
  • Plan not tested
ISO22000-8.5
Hazard control (HACCP)

Conduct hazard analysis, determine CCPs and OPRPs, set critical limits, monitor, and verify.

Artefacts an auditor will ask for
  • Hazard analysis
  • HACCP plan
  • CCP logs
Where this commonly fails
  • CCP limits unjustified
  • Monitoring gaps
ISO22000-8.6
Updating PRPs and hazard control plan

Update PRPs and the hazard control plan based on new information, changes, or verification results.

Artefacts an auditor will ask for
  • Change log
  • Updated plans
  • Verification records
Where this commonly fails
  • Plans static
  • Changes not triggered
ISO22000-8.7
Control of monitoring and measuring

Ensure monitoring and measurement equipment is fit for purpose and calibrated.

Artefacts an auditor will ask for
  • Calibration schedule
  • Certificates
  • Verification logs
Where this commonly fails
  • Out-of-cal equipment in use
  • No traceable standards
ISO22000-8.9
Control of nonconforming product

Identify, evaluate, and control potentially unsafe products to prevent unintended release.

Artefacts an auditor will ask for
  • NC procedure
  • Hold log
  • Recall procedure
Where this commonly fails
  • No formal hold/release
  • Recall untested

Planning

ISO22000-6.1
Actions to address risks and opportunities

Plan actions to address food safety risks and opportunities and integrate into FSMS processes.

Artefacts an auditor will ask for
  • Risk register
  • Opportunity log
  • Action plan
Where this commonly fails
  • Risk treated as HACCP only
  • No opportunities captured
ISO22000-6.2
FSMS objectives and planning

Set measurable food safety objectives and plan how to achieve them with resources and timelines.

Artefacts an auditor will ask for
  • Objectives register
  • Plans
  • Resource allocation
Where this commonly fails
  • Objectives not SMART
  • No accountability

Support

ISO22000-7.1
Resources

Provide resources for the FSMS including people, infrastructure, work environment, and external development.

Artefacts an auditor will ask for
  • Resource plan
  • Facility specs
  • Environment monitoring
Where this commonly fails
  • Old equipment
  • Environmental controls weak
ISO22000-7.2
Competence

Ensure persons doing work affecting food safety are competent with training, education, and experience.

Artefacts an auditor will ask for
  • Training matrix
  • Records
  • Assessments
Where this commonly fails
  • Refresher overdue
  • Contractors untrained
ISO22000-7.4
Communication

Establish internal and external communication relevant to food safety including supplier and customer channels.

Artefacts an auditor will ask for
  • Comms plan
  • Supplier portal
  • Recall channel
Where this commonly fails
  • No recall comms plan
  • Supplier issues unreported
ISO22000-7.5
Documented information

Control documented information required by the FSMS for creation, update, distribution, and retention.

Artefacts an auditor will ask for
  • Document control procedure
  • DMS
  • Retention schedule
Where this commonly fails
  • Uncontrolled docs in use
  • No retention
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 22000 framework page.