731 901 601
Product safety culture and fraud vulnerability assessment – new requirements in BRCGS Consumer Products Issue 5

Product safety culture and fraud vulnerability assessment – new requirements in BRCGS Consumer Products Issue 5

In our previous article, we described the structural changes in the forthcoming fifth edition of BRCGS Consumer Products – the consolidation of the standard into a single version, the removal of the tiered structure, and the introduction of two new sections of requirements. This time, we focus on what will, for many sites, represent a tangible change in the day-to-day operation of their product safety and quality management system.

Safety and product quality culture as a formal plan

Issue 5 significantly expands the requirements relating to safety and product quality culture. Whilst this topic has previously featured in the BRCGS family of standards, in the new edition of the Code of Practice (CP) it takes on a clearly formalised structure. Site management is required to define and maintain a documented plan for developing a safety and product quality culture, covering, amongst other things, communication, training, gathering feedback from staff, and measuring the effectiveness of the measures taken.

Importantly, the BRCGS has planned to implement this requirement in stages – the element concerning the action plan with specified implementation deadlines is to become auditable from 5 April 2028, whilst the requirement to review the effectiveness of completed and ongoing actions will only apply from 5 April 2029. This signals that BRCGS regards the development of a safety culture as a process spread over time, rather than a one-off documentation requirement to be met at the start of certification under the new edition.

New: product vulnerability assessment

One of the most notable substantive changes is the introduction of the product vulnerability assessment into the standard – a requirement already well known from the BRCGS Food Safety family of standards, where it is referred to as the vulnerability assessment / food fraud assessment. In Issue 5, a similar approach is being applied to the world of non-food products.

The vulnerability assessment focuses not on the risk of fraud within the facility itself, but on the weak points throughout the supply chain – points where materials, components or packaging may be substituted, falsified or misrepresented before they even reach the facility. This approach is well known from the context of protection against deliberate food contamination and adulteration, and is now finding its counterpart in the world of non-food products. According to the draft standard, this assessment should take into account, amongst other things, historical data, economic factors increasing the attractiveness of fraud, ease of access within the supply chain, the sophistication of routine control tests, and the level of trust in the supplier. The outcome of this work is to be a documented plan, updated in response to changing market conditions and subject to a formal review at least once a year.

As with the safety culture, the BRCGS has provided for a transition period – the requirements relating to vulnerability assessment are to become auditable from 5 April 2028, giving sites additional time to establish appropriate processes, even though the standard itself will come into use in audits from April 2027.

Combined risk assessment and hazard analysis

Under the new structure of the standard, product risk assessment (covering design, development and labelling) and hazard analysis and risk assessment of the production process (HARA) have been included in a single Section 2, designated as a fundamental requirement. The BRCGS emphasises that both elements can be carried out jointly as early as the product design stage, which in practice may simplify documentation for facilities that have hitherto treated these processes separately.

Traceability with a specific time target

Traceability requirements now have a more precise benchmark – a traceability system test should demonstrate the ability to trace a product’s path within 4 hours, unless local regulations or customer requirements stipulate otherwise. This is a specific numerical value that was not previously included in this form within the standard, and it is worth checking now whether the system currently in use allows this to be achieved.

Incident management with regard to cybersecurity

It is also worth noting the expansion of the definition of an incident that a site should manage as part of its procedure – in addition to traditional events such as product contamination or a site breakdown, the standard now explicitly lists disruptions resulting from cyber-attacks on the site’s systems. This reflects a broader trend in BRCGS standards, which are increasingly linking product safety with the operational resilience of the facility as a whole.

What does this mean in practice?

Although the deadlines for compliance with some of the new requirements have been deferred (to 2028 and 2029), the processes themselves – particularly the development of a safety culture and the preparation of a supply chain vulnerability assessment – take time to implement and cannot reasonably be ‘wrapped up’ at the last minute. In our next article, we’ll show you how to map out this process over time, taking into account all the key review deadlines. If you’d like to assess right now how far your current system is from meeting the requirements of Issue 5, let’s discuss implementation.

 

Read other posts

What is ISO 45001 and how do you obtain ISO 45001:2018 certification?

What is ISO 45001 and how do you obtain ISO 45001:2018 certification?

ISO 45001:2018 is an international standard setting out the requirements for an Occupational Health and Safety Management System (OHSMS). read more
Cosmetics and household chemicals manufacturers supplying retail chains – what does the IFS HPC standard offer them?

Cosmetics and household chemicals manufacturers supplying retail chains – what does the IFS HPC standard offer them?

Cosmetics and household chemicals manufacturers supplying their products to European retail chains operate in a sector where product quality and safety requirements are constantly increasing. read more
ISO 45001 in the construction industry – specific requirements and the most common hazards

ISO 45001 in the construction industry – specific requirements and the most common hazards

For years, the construction industry has topped the statistics for fatal accidents at work in Poland. read more
More posts