Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 22000 mandatory documents explained

ISO 22000 Mandatory Documents: All 30 Explained by Clause (2026)

ISO 22000 mandatory documents are the documented information the standard explicitly requires an organisation to maintain or retain — and ISO 22000:2018 requires more of it than most ISO management system standards, because clause 8 turns each Codex HACCP step into a documented requirement and adds prerequisite programmes, traceability, emergency preparedness and verification on top. Thirty items is the honest count: nine from the management-system clauses 4 to 7, eighteen from clause 8, and three from clauses 9 and 10.

The list below gives each one with its clause, whether it is a document to maintain or a record to retain, and what an auditor expects it to contain — followed by the documents that are not required by the text but that every certification audit asks for anyway, and a sequence for producing the set without duplicating it.

ISO 22000 mandatory documents: 30 items by clause
Clauses 4–7: scope, policy, objectives, externally developed elements, competence, communication, documented information control · Clause 8: PRPs, traceability, emergency, preliminary steps, hazard analysis, validation, hazard control plan, monitoring, verification, nonconformity, recall · Clauses 9–10: monitoring results, internal audit, management review.

How ISO 22000 uses “documented information”

ISO 22000:2018 follows the harmonised structure, so it never says “procedure” or “record” as a requirement; it says documented information that must be maintained (a living document) or retained (evidence of what happened). The distinction decides how each item is controlled under clause 7.5: maintained information is version-controlled and approved; retained information is protected from alteration and kept for a defined period. The list below marks each item accordingly. Our guide to ISO 22000 covers the structure the list follows.

ISO 22000 mandatory documents: clauses 4 to 7

# Clause Documented information Maintain / retain What it must show
1 4.3 Scope of the FSMS Maintain Products and services, processes and production sites covered; the activities that can affect end-product safety
2 5.2 Food safety policy Maintain Appropriate to the organisation, providing a framework for objectives, committing to applicable requirements and continual improvement; communicated and available to interested parties
3 6.2 FSMS objectives Maintain Measurable, consistent with the policy, monitored, communicated, updated; with what, who, when and how evaluated
4 7.1.6 Control of externally developed elements Retain Evaluation, selection and monitoring of external providers of processes, products or services that affect the FSMS
5 7.2 Competence Retain Evidence of competence of the food safety team and persons doing work under the organisation’s control that affects food safety
6 7.4.2 External communication Retain Evidence of communication with external providers, customers, authorities and others on food safety
7 7.4.3 Internal communication Retain (as required) Communication of changes that affect food safety to the food safety team in time to update the hazard analysis
8 7.5.1 Documented information required by the standard and by the organisation Maintain The set itself, identified and controlled
9 7.5.3 Control of documented information Maintain Distribution, access, storage, change control, retention and disposition; external documents identified and controlled

ISO 22000 mandatory documents in clause 8: the operational set

# Clause Documented information Maintain / retain What it must show
10 8.1 Operational planning and control Retain Evidence that the processes were carried out as planned
11 8.2.4 Prerequisite programmes Maintain The PRPs established, with selection and establishment against ISO/TS 22002 or equivalent, for the organisation’s context
12 8.3 Traceability system Retain Records identifying lots of received material to suppliers and end product to the first stage of distribution; verification and test of the system’s effectiveness
13 8.4.1 Emergency preparedness and response Maintain Procedures for potential emergencies and incidents that can affect food safety
14 8.4.2 Emergency response Retain Records of tests and of actual emergencies, with review and update
15 8.5.1.1 Preliminary steps Retain Applicable statutory, regulatory and customer requirements; products, processes and equipment; hazards relevant to the FSMS
16 8.5.1.2 Characteristics of raw materials, ingredients and product contact materials Maintain Composition, origin, packaging, storage and shelf life, preparation before use, acceptance criteria
17 8.5.1.3 Characteristics of end products Maintain Product name, composition, characteristics relevant to food safety, intended shelf life and storage, packaging, labelling, distribution method
18 8.5.1.4 Intended use Maintain Intended use, reasonably expected handling, unintended but reasonably expected mishandling; consumer groups and vulnerable groups
19 8.5.1.5 Flow diagrams and description of processes Maintain Flow diagrams per product or category, confirmed on site by the food safety team, and descriptions of processes and process environment
20 8.5.2 Hazard analysis Maintain Hazard identification with acceptable levels; hazard assessment (severity and likelihood) identifying significant hazards; selection and categorisation of control measures as CCP or OPRP
21 8.5.3 Validation of control measures Retain Evidence that the control measures, and combinations of them, are capable of achieving the intended control before implementation
22 8.5.4 Hazard control plan (HACCP/OPRP plan) Maintain Per CCP and OPRP: hazards controlled, critical limits or action criteria, monitoring procedures, corrections and corrective actions, responsibilities, records
23 8.5.4.4 Monitoring records Retain Monitoring results at CCPs and OPRPs, signed by the person monitoring and reviewed
24 8.7 Control of monitoring and measuring Retain Calibration or verification of monitoring and measuring equipment and software; action when equipment is found out of calibration
25 8.8.1 Verification Retain Verification activities against the plan: PRPs implemented, hazard analysis updated, hazard control plan implemented and effective, hazard levels within acceptable levels
26 8.9.2–8.9.3 Corrections and corrective actions Retain Nature of nonconformities, causes, consequences, actions taken, results, and the review of effectiveness
27 8.9.4 Handling of potentially unsafe products Retain Evaluation for release and the disposition of nonconforming product
28 8.9.5 Withdrawal/recall Maintain and retain The procedure with named authority, and records of withdrawals and recalls and their verification, including tests of the procedure

ISO 22000 mandatory documents in clauses 9 and 10

# Clause Documented information Maintain / retain What it must show
29 9.1.1 Monitoring, measurement, analysis and evaluation results Retain What was monitored, methods, when, results and evaluation of FSMS performance
30 9.2.2 Internal audit programme and results Retain The audit programme and the evidence of implementation and results; management review input
9.3.3 Management review outputs Retain Decisions on continual improvement and updates to the FSMS, resource needs, policy and objectives revision
10.1 Nonconformity and corrective action Retain Nature of nonconformities, actions and results (system-level; product-level is 8.9)

Counting 9.3.3 and 10.1 separately gives 32 ISO 22000 mandatory documents; they are grouped here because most organisations hold them in the same records as 8.9 and 9.2. Our guide to product recall under clause 8.9.5 covers item 28 in depth.

Documents not required by the text but expected at audit

Document Why the auditor asks Clause it evidences
Food safety manual or FSMS description Not required since the 2018 edition; still the fastest way to show the system’s structure 4.4
Organisation chart and food safety team appointment 8.5.1.1 requires a food safety team with a leader; 5.3 requires roles assigned 5.3, 8.5.1.1
Allergen management procedure A PRP under ISO/TS 22002-1 and a hazard in almost every hazard analysis 8.2, 8.5.2
Supplier approval procedure 7.1.6 evidence needs a process behind it 7.1.6
Training matrix The practical form of 7.2 competence evidence 7.2
Verification schedule 8.8.1 requires verification to be planned 8.8.1
Mock recall records 8.9.5 requires the procedure to be tested 8.9.5
Risks and opportunities register 6.1 requires actions to be planned; a register is the evidence 6.1

Producing the ISO 22000 mandatory documents without duplication

  1. Start with clause 8.5.1. Product and material characteristics, intended use and flow diagrams are the inputs to everything; write them first and keep them current.
  2. Do the hazard analysis in one worksheet. Identification, acceptable levels, assessment, control measure selection and CCP/OPRP categorisation are one document with columns, not five documents. Our guide to OPRP vs CCP covers the categorisation.
  3. Let the hazard control plan generate the monitoring records. Each row in the plan defines a record; design the forms from the rows.
  4. Put the PRPs on ISO/TS 22002-1’s list. One procedure per PRP topic, each with its verification method, gives 8.2 and half of 8.8 at once.
  5. Combine the small procedures. Traceability, emergency preparedness and recall are three procedures that one incident may invoke together; cross-reference them and test them in one exercise.
  6. Build the clause 9 records from the clause 8 ones. Verification analysis (8.8.2) is the input management review (9.3) needs; internal audit (9.2) samples the same records the auditor will.

Frequently asked questions

How many mandatory documents does ISO 22000 require?
Around thirty explicitly required items of documented information: nine in clauses 4–7, eighteen in clause 8 and three or more in clauses 9–10, depending on how the records are grouped. Clause 8 is the largest because each Codex HACCP step and each of PRPs, traceability, emergency preparedness and verification is a documented requirement.

Does ISO 22000 require a food safety manual?
No. The 2018 edition requires documented information, not a manual; many organisations keep a short FSMS description because it helps the auditor, but it is not mandatory.

What is the difference between maintain and retain?
Maintained documented information is a living document — policy, procedures, the hazard control plan — under version control. Retained documented information is a record — monitoring results, verification, audits — kept as evidence and protected from alteration.

Is the HACCP plan a mandatory document?
Yes — as the hazard control plan under clause 8.5.4, covering CCPs and OPRPs, together with the preliminary-step documents (8.5.1), the hazard analysis (8.5.2) and validation records (8.5.3).

Do the PRPs have to be documented?
Yes. Clause 8.2 requires the PRPs to be established, implemented, maintained and updated, and documented information on their selection, establishment, monitoring and verification to be kept — normally against ISO/TS 22002 for the relevant sector.

Where this leaves you

Build the ISO 22000 mandatory documents from clause 8 outward: the preliminary-step descriptions first, a single hazard analysis worksheet, a hazard control plan whose rows define the monitoring records, PRP procedures with their verification, and the traceability, emergency and recall procedures tested together — then the policy, objectives, communication and control documents of clauses 4–7 and the audit and review records of clauses 9–10 that sit around them.

References

More on ISO 22000

The FSMS manual set, the food safety policy and objectives, the prerequisite programme manual, the hazard analysis of raw, packing and product contact materials, the CCP and OPRP monitoring and verification plans, the identification and traceability, emergency preparedness, non-conforming product, internal audit and management review procedures are in the ISO 22000 Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.