
Establishing an ISO 22000 system requires the involvement of the entire organisation – from management to operational staff. In practice, however, many companies make similar mistakes, which result in non-conformities during the audit or the refusal to issue a certificate. Being aware of these pitfalls in advance allows you to navigate the entire process smoothly.
This is the area where non-conformities occur most frequently – both in companies implementing the standard for the first time and those transitioning from the 2005 version.
1. Incorrect distinction between CCPs, OPRPs and PRPs. ISO 22000:2018 precisely defines the differences between a critical control point (CCP), an operational prerequisite programme (OPRP) and a general prerequisite programme (PRP). Companies often misclassify these points – leading to an overly complex HACCP plan or insufficient control over actual hazards. Auditors require documented justification for each classification.
2. Hazard analysis based on a template rather than the actual process. Copying a hazard analysis from ready-made templates without adapting it to the specific nature of the facility is one of the most common mistakes. The auditor verifies whether the analysis reflects actual processes – a discrepancy between documentation and production practice is one of the most serious non-conformities.
3. Lack of validation of control measures. The standard requires proof of the effectiveness of control measures before they are implemented. Companies often confuse validation with verification: validation answers the question “Is this measure capable of controlling the hazard?”, whilst verification asks “Does it work correctly in practice?”. Lack of validation is a non-conformity that regularly arises during audits.

1. Documentation that is out of touch with reality. Procedures describe processes as they should be in theory, rather than how they actually operate within the organisation. Auditors verify whether the documentation matches actual practice by observing processes and speaking to staff – any discrepancies are immediately apparent.
2. Inadequate analysis of the organisation’s context. Chapter 4 of the standard requires the identification of internal and external factors affecting the system, as well as the needs of interested parties. Many companies treat this element as a formality and fill it in with vague wording. Auditors expect the results of the analysis to have a real impact on the design of the system and to be regularly updated.
3. Food safety objectives that are unmeasurable or unmonitored. The standard requires specific, measurable objectives linked to a timetable. “Improving food safety” is an intention, not an objective. Failure to monitor progress towards objectives is one of the most common formal non-conformities.
4. Internal audits only prior to the external audit. Companies conduct internal audits solely as preparation for certification, without analysing the results or implementing corrective actions. External auditors check not only that audits have been carried out, but also whether they have led to tangible changes in the system.
1. Lack of management commitment. The standard requires top management to be actively involved in the system – it is not enough to sign the policy and delegate all responsibility to a representative. Auditors speak directly with management and verify whether they understand the standard’s requirements and make decisions based on data from management reviews.
2. Treating certification as a one-off project. ISO 22000 is a system of continuous improvement. Companies that prepare intensively before an audit but then neglect to maintain the system quickly lose their certificate at the next surveillance audit. Management reviews, hazard analysis updates and internal audits must take place regularly throughout the year.
3. Inadequate staff training. Operational staff are a key element of the system. Companies often limit training to the quality department, overlooking line operators and support staff. Auditors speak directly with staff at various levels and verify their actual awareness of the system’s requirements.
Avoiding the most common mistakes right from the system design stage enables an organisation to prepare more effectively for an audit and successfully implement the ISO 22000 system.