Article
Food safety: which scheme, and why the buyer decides
ISO 22000, FSSC 22000, BRC and HACCP overlap heavily and are not interchangeable. The difference that matters is who recognises which.
Prem Kumar Dvivedi · 12 September 2026
Food businesses are offered four things that sound like the same thing: HACCP, ISO 22000, FSSC 22000 and BRC. They share most of their content. They are not interchangeable, and choosing on price is how an organisation ends up certifying twice.
What each one is
HACCP is the method — hazard analysis and critical control points — not a management system. It is the core of everything else here, and in many jurisdictions it is a legal requirement rather than a commercial choice.
ISO 22000 wraps HACCP in a management system: context, leadership, competence, internal audit, management review, plus prerequisite programmes and operational prerequisites.
FSSC 22000 is ISO 22000 plus sector-specific prerequisite requirements and a set of additional requirements. It is recognised by the Global Food Safety Initiative, which is what many international retailers require.
BRCGS is a separate standard with its own grading system, widely named by UK and European retailers, and audited unannounced at higher grades.
The decision rule
Ask the buyer. GFSI recognition is the dividing line in practice: if your customer requires a GFSI-benchmarked scheme, ISO 22000 alone will not satisfy them, and the gap between it and FSSC 22000 is smaller than the cost of discovering that later.
Where food businesses actually fail audits
Rarely on the HACCP plan, which is usually the best-written document in the building. The findings come from the prerequisite programmes: cleaning records signed in advance, pest control reports with open actions from three visits ago, personal hygiene rules not followed in the one area the auditor walks through unannounced, water testing that lapsed.
And from traceability. The exercise is simple — take a finished batch, trace back to the raw material and forward to the customer, within the time the standard allows — and it exposes everything. A business that has never run one under time pressure should do so before an auditor asks.
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 22000, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- ISO 22000:2018: documentation and compliance requirements
Everything ISO 22000:2018 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
12 September 2026
- India's DPDP consent manager rules bite in November 2026
Rule 4 of the DPDP Rules comes into force on 13 November 2026, with full compliance due by May 2027. What Indian businesses have to have ready.
12 September 2026
- Australia's first mining industrial manslaughter conviction
Mastermyne was convicted in March 2026 and fined $7 million in May — a record WHS penalty. What changed, and what boards should read into it.
12 September 2026
