Written and maintained by CASRAI Editorial Board
Last updated
TL;DR: A food safety audit is a structured, criteria-based assessment of whether a food production, processing, storage, or testing facility actually operates the food safety management system it claims to have — not just whether it holds a certificate. Audits fall into three types (first-party/internal, second-party/customer, and third-party/certification-body), and most B2B supply-chain relationships in the food and food-testing space run on third-party audits benchmarked against a Global Food Safety Initiative (GFSI) scheme such as SQF, BRCGS, FSSC 22000, or IFS. This guide covers what a food safety audit actually checks, how NSF and other certification bodies run one, what belongs on a procurement-side checklist, and how to evaluate audit companies, training, and course options before you commit budget to any of them.
What a food safety audit is
A food safety audit is a systematic, documented examination of a facility’s food safety management system against a defined set of criteria — a regulation, a private standard, or a customer’s own specification — carried out by someone independent of the process being reviewed. The output is a written finding: conformances, nonconformances (often scored by severity, e.g. minor/major/critical), and a corrective-action requirement with a deadline. An audit is a point-in-time verification exercise; it is distinct from ongoing monitoring (routine testing, environmental sampling, temperature logging) and from a regulatory inspection, which is government-conducted and enforces statutory requirements rather than a private standard.
Three audit types cover essentially the whole landscape a procurement or quality team will encounter:
- First-party (internal) audit — a facility audits its own operation, usually as a required element of its food safety plan, to catch and correct gaps before an external party finds them.
- Second-party audit — a customer (a retailer, a foodservice buyer, a brand owner) audits its own supplier directly, using its own or a shared standard.
- Third-party audit — an independent, typically accredited certification body audits the facility against a recognized standard and issues (or withholds) certification. This is the type most relevant to procurement decisions, because certification is portable: one audit result can satisfy many customers at once, rather than each buyer running its own second-party audit.
The regulatory backdrop: FSMA and preventive controls
In the United States, the FDA Food Safety Modernization Act (FSMA), signed into law in January 2011, shifted federal food regulation from a reactive (respond-to-contamination) model to a preventive one. Its core operative rule for most human-food facilities is the Preventive Controls for Human Food rule (21 CFR Part 117), which requires a written food safety plan built around hazard analysis and risk-based preventive controls (HARPC) — a superset of the older HACCP (Hazard Analysis and Critical Control Points) framework still used as the base methodology in most GFSI-benchmarked schemes. Meat, poultry, and egg-product facilities fall instead under USDA FSIS jurisdiction and its own HACCP regulations, not FDA/FSMA.
A private-standard third-party audit (SQF, BRCGS, FSSC 22000, IFS, etc.) does not replace regulatory compliance — a facility must meet FSMA/FSIS requirements regardless of whether it ever pursues certification. What a GFSI-benchmarked audit adds is a standardized, buyer-recognized attestation that goes beyond the regulatory floor, which is why most large retailers and foodservice buyers require it as a condition of doing business, independent of what the law itself mandates.
GFSI-recognized certification schemes
The Global Food Safety Initiative (GFSI) is not itself a certification body or a standard — it is a benchmarking organization that evaluates private food safety certification schemes against a common set of requirements. A scheme that is “GFSI-recognized” has been independently benchmarked to meet that baseline, which is why buyers can generally accept certification under any GFSI-recognized scheme interchangeably. The major GFSI-recognized schemes a procurement team will encounter are:
- SQF (Safe Quality Food) — administered by SQFI (a division of the Food Marketing Institute), widely used across North American manufacturing, storage, and distribution.
- BRCGS (Brand Reputation through Compliance, formerly British Retail Consortium) — a UK-originated standard with heavy adoption among retailers and their global supply chains.
- FSSC 22000 — built on the ISO 22000 food safety management system standard plus sector-specific technical specifications (e.g. ISO/TS 22002 series).
- IFS (International Featured Standards) — widely used across continental European retail supply chains.
Each scheme has its own scope documents (food manufacturing, storage and distribution, packaging, primary production, and so on), so the first procurement question is always “which scope does this facility need,” not “which scheme is best” — a facility’s buyers, not an abstract ranking, usually determine which scheme is actually required.
NSF food safety audits
NSF (originally the National Sanitation Foundation, now operating as NSF International) is one of the certification bodies accredited to conduct audits under multiple GFSI-recognized schemes, alongside other accredited certification bodies (e.g. SGS, Bureau Veritas, DNV, Intertek, and others operating in the same space). “NSF food safety audit” in practice refers to an audit conducted by an NSF-employed or NSF-contracted auditor against whichever scheme the facility is certifying to (SQF, BRCGS, FSSC 22000, etc.) or against NSF’s own proprietary programs. NSF’s accreditation to audit a given scheme is issued by an accreditation body (see below), the same way any certification body’s authority is — NSF is not itself the standard, it is one of several organizations licensed to audit against one.
For procurement purposes, the practical question is not “NSF vs. a competitor” in the abstract, but: is the certification body accredited for the specific scheme and scope you need, does it have auditors with relevant category experience (dairy, produce, ready-to-eat, cold storage, lab/testing facility, etc.), and can it deliver within your required audit window. Those are verifiable, comparable criteria across any certification body, NSF included.
Food safety audit checklist
Checklist content varies by scheme, but nearly every food safety audit — first-, second-, or third-party — walks through the same core domains:
- Food safety management system — documented food safety plan, HACCP/HARPC hazard analysis, management review, internal audit program, document control.
- Prerequisite programs (GMPs) — facility and equipment design, personnel hygiene, pest control, cleaning and sanitation procedures and verification (e.g. ATP swabbing, environmental monitoring), water/ice/air quality.
- Allergen control — allergen mapping, segregation, changeover/cleaning validation, label verification.
- Supplier and raw-material control — approved supplier lists, incoming material specifications and verification, foreign-material controls.
- Traceability and recall — lot coding, one-up/one-back traceability records, a tested mock recall procedure with a documented time-to-completion.
- Process and product control — critical control point monitoring records, calibration records for monitoring instruments, corrective-action documentation.
- Storage, transportation, and cold chain — temperature control and monitoring records, especially relevant for facilities also handling cold-chain-sensitive product (see our guide on pharma cold chain logistics for the equivalent framework in a regulated-drug context).
- Corrective and preventive action (CAPA) — how prior nonconformances, whether from audits, customer complaints, or internal deviations, were closed out and verified.
Before commissioning any audit, ask the certification body or auditor for the actual scored checklist/audit guidance document for the specific scheme edition you’re certifying to (schemes revise their editions periodically) rather than relying on a generic template — scoring weight and critical-failure criteria differ by scheme and by edition.
Third-party food safety audit: how to evaluate audit companies
When comparing third-party food safety audit companies for a procurement or vendor-qualification decision, the criteria that actually differentiate providers on verifiable grounds are:
- Accreditation status. A certification body should be accredited by a recognized accreditation body (in the US, commonly ANAB — the ANSI National Accreditation Board) to issue certificates under the specific GFSI-recognized scheme and scope you need. Ask for the accreditation certificate and scope statement directly, not a marketing claim.
- Scope match. Confirm the body is accredited for your facility category (e.g. manufacturing vs. storage/distribution vs. primary production vs. laboratory) — accreditation is scope-specific, not blanket.
- Auditor competence and category experience. Ask how auditors are qualified and whether they have direct experience auditing your product category; this affects both audit quality and how efficiently findings get resolved.
- Scheduling and lead time. Certification bodies book audit slots well in advance, especially around common recertification windows; confirm lead time against your own certification deadline.
- Cost structure. Audit fees are typically a function of facility size, audit duration (auditor-days), and travel; get an itemized quote rather than a flat number, and clarify what’s included (report writing, follow-up verification of corrective actions, certificate issuance fees).
- Conflict-of-interest controls. A certification body should not simultaneously provide consulting/gap-assessment services and certification audits for the same facility — GFSI-recognized schemes prohibit this to preserve audit independence; ask directly if this separation is in place.
This site does not rank or recommend specific commercial audit providers; the criteria above are the verifiable dimensions to compare providers on, not a substitute for checking a given body’s current accreditation scope yourself before signing an audit agreement.
Food safety audit training and courses
Training needs generally split into three tracks, and procurement/quality teams often need to budget for more than one:
- Foundational HACCP/HARPC training — establishes the hazard-analysis methodology underlying every scheme; often a prerequisite for other courses.
- PCQI (Preventive Controls Qualified Individual) training — specific to FSMA’s Preventive Controls for Human Food rule; a facility is generally required to have at least one PCQI-trained individual overseeing its food safety plan under 21 CFR Part 117.
- Scheme-specific auditor/practitioner training — internal auditor courses (for running your own first-party audits) and lead auditor courses (for individuals conducting second- or third-party audits) offered directly by the scheme owner (SQFI, BRCGS, FSSC 22000, IFS) or by accredited training providers.
When evaluating a course or training provider, check whether the course is officially recognized/registered by the scheme owner (most GFSI schemes publish a directory of approved training providers) — a certificate from an unrecognized provider may not satisfy a customer’s or certification body’s competence requirement, even if the course content is substantively similar.
Building a food safety audit budget and cycle
For procurement and quality planning purposes, a few practical figures to build into an annual budget:
- Certification cycle — most GFSI-recognized certifications run on an annual recertification audit cycle, with some schemes offering extended cycles for facilities with a strong compliance history.
- Unannounced audits — several GFSI-recognized schemes now require or offer an unannounced-audit option for some or all certification cycles; confirm which model applies before budgeting audit-day coverage/staffing.
- Corrective-action verification — nonconformances found during a certification audit typically require a follow-up verification (documentary or on-site) before certification is granted or maintained; budget both the time and, if on-site, the additional cost.
- Multi-site programs — organizations with multiple facilities should ask about multi-site or corporate-umbrella audit programs, which some schemes and certification bodies support to reduce per-site audit cost and scheduling burden.
Frequently asked questions
What is a food safety audit?
A food safety audit is an independent, criteria-based review of whether a facility’s food safety management system is documented, implemented, and effective — conducted as a first-party (internal), second-party (customer), or third-party (certification body) exercise.
What’s on a food safety audit checklist?
Core domains common across schemes: food safety management system and HACCP/HARPC documentation, GMP prerequisite programs (sanitation, pest control, personnel hygiene), allergen control, supplier/raw-material verification, traceability and recall capability, process/CCP monitoring records, and corrective-action history. See the checklist section above for the full breakdown.
What is an NSF food safety audit?
It’s an audit conducted by NSF International, one of several accredited certification bodies authorized to audit facilities against GFSI-recognized schemes (SQF, BRCGS, FSSC 22000, etc.) or NSF’s own programs. Evaluate NSF the same way you’d evaluate any certification body: confirm accreditation scope, auditor category experience, and scheduling fit for your specific facility.
Where can I find food safety audit training or a course?
Start with the scheme owner’s own published directory of approved/recognized training providers (SQFI, BRCGS, FSSC 22000, IFS each maintain one) rather than a generic search — this confirms the training will actually be recognized toward a competence requirement.
How do I evaluate food safety audit companies?
Compare accreditation status and scope (verified against the accreditation body, e.g. ANAB, not the provider’s own marketing), category-specific auditor experience, lead time against your certification deadline, itemized cost structure, and conflict-of-interest separation between consulting and certification services.
What’s the difference between a third-party food safety audit and a regulatory inspection?
A third-party audit is conducted against a private standard (a GFSI-recognized scheme) by an accredited certification body and results in certification; a regulatory inspection is conducted by a government agency (FDA or USDA FSIS in the US) enforcing statutory requirements. Passing a third-party audit does not substitute for regulatory compliance, and vice versa.
For related procurement and compliance frameworks, see our guides on the GMP audit checklist (the equivalent facility-audit framework for pharmaceutical and drug-product manufacturing) and pharma cold chain logistics, and our dictionary entry on the for-cause audit concept as it applies more broadly to compliance audits.








