The 24 Risk Assessments a GFSI Food Audit Expects
By Mthokozisi Nkosi, Food Safety Specialist & Lead Auditor, ASC Food Safety · 14 min read

BRCGS Issue 9, FSSC 22000 Version 7 and IFS all require documented risk assessments, and a hazard analysis does not satisfy them. A certified site holds about 24, from allergen management under BRCGS clause 5.3 to context of the organisation under ISO 22000:2018 clause 4.1. ASC packs are R690 each. Toolkits run R699 for the Basic set to R8,720 for GLOBALG.A.P. IFA, certification level toolkits from R4,000, assessments already inside.
At a glance
- Risk assessments a certified site normally holds
- About 24, covering prerequisite programmes, contamination routes and the management level clauses
- Price per ASC pack
- R690, containing a register, a procedure, a completion guide and a read me, in editable Word and Excel
- All 24 bought separately
- R16,560
- Toolkit range
- R699 to R8,720 by standard, with the certification level toolkits from R4,000, risk assessments already built in plus one hour of premium consultation
- Standards these map to
- BRCGS Issue 9, FSSC 22000 Version 7, ISO 22000:2018, IFS and SQF clauses
- Minimum review discipline
- Annually, plus an out of cycle review on any change that affects the subject
- The finding auditors write most
- A risk score with no stated basis, on a document with no named owner
- Consulting
- From R480 an hour, or a full project scoped and quoted as one figure
Buy the one you are missing, or the whole system
Most sites reading this already know which risk assessment their last audit exposed. Start there, or start with the set.
Browse all 24 risk assessment packs, R690 each Ask ASC which of the 24 your audit will actually ask forIn this guide
- What is a food safety risk assessment?
- Why certification schemes ask for risk assessments by name
- The full list of risk assessments a GFSI audit expects, and the clause that drives each
- What a defensible risk assessment actually contains
- Which risk scoring methods survive an auditor’s challenge
- How often must each risk assessment be reviewed?
- The findings auditors write against risk assessments
- Should you write your own or start from a template?
- Is a R690 risk assessment pack or a R5,500 toolkit better value?
- How the packs, the toolkits and consulting fit together
- Frequently asked questions
What is a food safety risk assessment?
A food safety risk assessment is a documented judgement about one subject, cleaning, pests, zoning, suppliers, allergens, fraud or utilities, required in writing by BRCGS Issue 9, FSSC 22000 Version 7 and ISO 22000:2018 clause 6.1. It differs from a hazard analysis in scope, because a hazard analysis works product by product through the process flow under ISO 22000:2018 clause 8.5 while a risk assessment works subject by subject. A GFSI recognised scheme wants both.
The confusion is expensive. It shows up as a non-conformity against a clause the site believed its HACCP study had already answered. A HACCP study is bounded by its scope and its flow diagram, so it can only reason about hazards that appear at a process step. It has nothing sensible to say about why your external bins sit where they sit, why the goods in bay is cleaned weekly rather than daily, or why a supplier in a new country of origin was approved on a certificate alone. Those questions live in prerequisite programmes and in management decisions, and the schemes ask you to justify them in writing.
The distinction matters at the audit table. When an auditor asks why a control is set where it is, a HACCP plan answers with a critical limit and its validation. A prerequisite programme answers with a procedure. Neither of those explains the choice. The risk assessment explains the choice, and it is the only document on site that carries the reasoning. If you want the HACCP side laid out in full, our guide on what a HACCP plan contains covers the twelve steps in order.
If the question starts with “why is that enough”, the answer lives in a risk assessment. If it starts with “how do you control that”, the answer lives in a procedure or a HACCP plan.
Why certification schemes ask for risk assessments by name
Because the schemes stopped prescribing controls and started demanding justification. BRCGS Global Standard Food Safety Issue 9, published 1 August 2022, runs to nine sections with twelve fundamental requirements, and several of those fundamentals are written in risk based language rather than as a fixed rule. FSSC 22000 Version 7, published May 2026, carries its own additional requirements in Part 2, section 2.5.
First, a correction that matters for anyone searching this topic. There is no such thing as GFSI certification. GFSI is hosted by The Consumer Goods Forum and benchmarks schemes; it does not certify anybody. A GFSI audit means an audit against a GFSI recognised scheme: BRCGS, FSSC 22000, IFS, SQF or GLOBALG.A.P. IFA v6 in the GFS edition. ISO 22000 on its own is not GFSI recognised, which is exactly why FSSC 22000 exists as ISO 22000:2018 plus a sector prerequisite programme standard from the ISO 22002 series plus the FSSC additional requirements. If you are still choosing, the BRCGS, FSSC 22000 and IFS decision framework sets out the trade offs.
The twelve BRCGS Issue 9 fundamentals are clauses 1.1, 2, 3.4, 3.5.1, 3.7, 3.9, 4.3, 4.11, 5.3, 6.1, 6.2 and 7.1. A major non-conformity against its statement of intent is a fail. Certification is off the table, the auditor, the certification body and site management agree whether the audit ends there or carries on as a non-certification gap audit, and a further full audit is needed to certify. Look at that list against the risk assessment table below and the overlap is obvious: supplier approval, traceability, layout and segregation, housekeeping and hygiene, allergen management and control of operations all sit in it, and every one of them is assessed on the strength of your written reasoning.
IFS applies the same logic through its own checklist, with risk based wording running through the requirements rather than a separate risk assessment register. The practical effect is the same. An IFS auditor asks for the justification behind a frequency, a zone boundary or a supplier decision, and expects a document rather than a conversation.
An auditor tests something narrower than whether you have controls: whether you can show why those controls are the right ones for your site.
Food defence and food fraud are where new sites lose the most time
TACCP and VACCP are named requirements in both BRCGS Issue 9 and FSSC 22000 Version 7, and they are the two most commonly written from scratch the week before an audit.
Buy the Food Defence (TACCP) Risk Assessment, R690 Talk to ASC about a full risk assessment setThe full list of risk assessments a GFSI audit expects, and the clause that drives each
No standard prints a list of required risk assessments. Sites are left to work the list out for themselves. In practice a certified food manufacturing site holds about 24, and an auditor works through them by subject rather than by number. The table below gives every one, what it covers, and the clause that drives it in BRCGS Issue 9, FSSC 22000 Version 7 or ISO 22000:2018. Every pack is R690.
| Code | Risk assessment pack | What it covers, and what an auditor opens it to see | The clause that drives it |
|---|---|---|---|
| RA01 | PRP Verification Plan Risk Assessment Template with Instructional Video · R690 | How each prerequisite programme is verified, by whom, how often, and on what evidence. The document that stops verification being a swab schedule nobody can justify. | ISO 22000:2018 clause 8.2, prerequisite programmes, read with the ISO 22002 series and BRCGS Issue 9 Section 3 |
| RA02 | Food Defence (TACCP) Risk Assessment Template with Instructional Video · R690 | Deliberate contamination and malicious tampering: access points, vulnerable process steps, visitors, contractors, disgruntled insiders, and the countermeasures for each. | BRCGS Issue 9 clause 4.2, food defence, and the FSSC 22000 Version 7 additional requirement on food defence |
| RA03 | Cleaning and Disinfection Risk Assessment Template · R690 | Why each area, surface and piece of equipment is cleaned at the frequency and to the standard you have chosen, and how that standard is proved. | BRCGS Issue 9 clause 4.11, housekeeping and hygiene, a fundamental requirement |
| RA04 | Personal Hygiene Risk Assessment Template · R690 | Hand washing points, jewellery, protective clothing, changing routes, medical screening and visitor rules, justified by zone rather than copied from a poster. | BRCGS Issue 9 clauses 7.2 personal hygiene and 7.4 protective clothing |
| RA05 | Pest Control Risk Assessment Template · R690 | Species of concern, device type and placement, bait policy, inspection frequency, proofing weaknesses and the trend that would trigger action. | BRCGS Issue 9 clause 4.14, pest management |
| RA06 | Waste and Food Loss Management Risk Assessment Template · R690 | Waste streams and their routes out of the building, external bin siting, contamination and pest attraction, and how surplus food is handled or donated. | BRCGS Issue 9 clauses 4.12 waste and waste disposal and 4.13 management of surplus food |
| RA07 | Site and Building Fabric Risk Assessment Template · R690 | Walls, floors, ceilings, drains, doors, windows, roof and external areas, scored by the contamination each defect could cause and the repair priority that follows. | BRCGS Issue 9 clauses 4.4 building fabric and 4.1 external standards and site security |
| RA08 | Layout and Hygienic Zoning Risk Assessment Template · R690 | Product, people, waste and air flow across the site, zone boundaries, and the cross contamination each crossing point creates. Auditors walk this one with you. | BRCGS Issue 9 clause 4.3, layout, product flow and segregation, a fundamental, with Section 8 production risk zones |
| RA09 | Utilities, Water, Air, Steam and Lighting Risk Assessment Template · R690 | Water source and treatment, ice, compressed air, steam contact, gases and lighting, with the sampling regime each one earns. | BRCGS Issue 9 clause 4.5, utilities, water, ice, air and other gases |
| RA10 | Equipment Suitability and Maintenance Risk Assessment Template · R690 | Hygienic design, material suitability, maintenance access, temporary repairs, lubricants and the hand back to production after engineering work. | BRCGS Issue 9 clauses 4.6 equipment and 4.7 maintenance, and the FSSC 22000 Version 7 additional requirement on equipment management |
| RA11 | Supplier and Purchased Material Approval Risk Assessment Template · R690 | The risk category of every raw material and supplier, and the approval evidence each category demands, from a certificate to an on site audit. | BRCGS Issue 9 clause 3.5, supplier and raw material approval, with 3.5.1 a fundamental |
| RA12 | Storage, Warehousing and Transport Risk Assessment Template · R690 | Segregation in store, stock rotation, temperature control, vehicle condition and checks, loading and third party logistics. | BRCGS Issue 9 clauses 4.15 storage facilities and 4.16 dispatch and transport, with ISO 22002-5:2025 for transport and storage |
| RA13 | Rework Risk Assessment Template · R690 | Which product may be reworked, into what, at what inclusion rate, with what allergen and traceability consequence, and who authorises it. | BRCGS Issue 9 clause 6.1, control of operations, a fundamental, read with clause 5.3 management of allergens |
| RA14 | Microbiological Contamination Risk Assessment Template · R690 | Pathogens and spoilage organisms relevant to your products and processes, survival and growth points, and the controls and sampling that follow. | BRCGS Issue 9 Section 2, the food safety plan based on HACCP, a fundamental, with Section 8 production risk zones |
| RA15 | Physical Contamination and Foreign Bodies Risk Assessment Template · R690 | Glass, brittle plastic, metal, wood, stones, pests and personal items, mapped to the process step, with detection and removal equipment justified rather than assumed. | BRCGS Issue 9 clauses 4.9 chemical and physical product contamination control and 4.10 foreign body detection and removal equipment |
| RA16 | Chemical Contamination Risk Assessment Template · R690 | Cleaning chemicals, lubricants, pesticides, processing aids, packaging migration and taint, with storage, decanting and labelling controls. | BRCGS Issue 9 clause 4.9, chemical and physical product contamination control |
| RA17 | Allergen Management Risk Assessment Template · R690 | Allergens on site, cross contact routes through storage, line, rework, air and people, cleaning validation, and the basis for any precautionary statement. | BRCGS Issue 9 clause 5.3, management of allergens, a fundamental, and the FSSC 22000 Version 7 additional requirement on management of allergens |
| RA18 | Food Fraud Vulnerability (VACCP) Risk Assessment Template · R690 | Adulteration, substitution, dilution, mislabelling and counterfeit risk by raw material, with horizon scanning evidence and the mitigation you have actually put in place. | BRCGS Issue 9 clause 5.4, product authenticity, claims and chain of custody, and the FSSC 22000 Version 7 additional requirement on food fraud mitigation |
| RA19 | Environmental Monitoring Risk Assessment Template · R690 | Zone one to zone four sampling sites, organism, frequency, action limits and the escalation when a result goes the wrong way. | FSSC 22000 Version 7 additional requirement on environmental monitoring, with BRCGS Issue 9 Section 8 production risk zones |
| RA20 | Traceability, Withdrawal and Recall Risk Assessment Template · R690 | Where traceability could break, how long a mass balance takes, and what the recall decision, contact list and test would look like under pressure. | BRCGS Issue 9 clause 3.9 traceability, a fundamental, with 3.11 management of incidents, product withdrawal and product recall, and ISO 22000:2018 clause 8.3 |
| RA21 | Emergency Preparedness and Response Risk Assessment Template · R690 | Power and water failure, flood, fire, load shedding, strike action, IT loss and supply interruption, with the food safety consequence of each and the response plan. | ISO 22000:2018 clause 8.4, emergency preparedness and response, with BRCGS Issue 9 clause 3.11 |
| RA22 | Context of the Organisation Risk Assessment Template · R690 | External and internal issues that affect your ability to deliver safe food: market, regulatory, climate, infrastructure, skills and ownership. | ISO 22000:2018 clause 4.1, understanding the organisation and its context |
| RA23 | Interested Parties Risk Assessment Template · R690 | Customers, regulators, certification bodies, staff, community and suppliers, their requirements, and which of those requirements you have accepted as binding. | ISO 22000:2018 clause 4.2, understanding the needs and expectations of interested parties |
| RA24 | Strategic Risks and Opportunities Risk Assessment Template · R690 | The management level register: what could stop the food safety management system achieving its intended result, and what you will do about it. | ISO 22000:2018 clause 6.1, actions to address risks and opportunities |
Two notes on how to read that table. Where a row cites a BRCGS clause, the same subject appears in FSSC 22000 through ISO 22000:2018 and the relevant part of the ISO 22002 series, which was restructured in July 2025 so that most parts became full International Standards, including ISO 22002-100:2025 as a new common baseline published on 29 July 2025. Where a row cites an ISO 22000 clause, BRCGS reaches the same subject through Section 1 and Section 3. The subject is what the auditor cares about, not the label on the document.
Second, RA22, RA23 and RA24 are the three that manufacturing sites most often skip, because they feel like paperwork for the boardroom. They are not optional in an ISO 22000 or FSSC 22000 audit. Clauses 4.1, 4.2 and 6.1 are auditable requirements, and an auditor who finds no evidence of them writes the finding against the management system, not against the factory floor.
Buying more than four packs? Do the sum first
Four packs cost R2,760. A GFSI Intermediate Level toolkit is R4,000 and carries a complete management system with the risk assessments already in it.
Buy the GFSI Intermediate toolkit, 105+ documents, R4,000 Ask us which set fits your scopeWhat a defensible risk assessment actually contains
A defensible risk assessment carries ten things, and they are what an auditor tests against ISO 22000:2018 clause 6.1 and BRCGS Issue 9: scope, the hazards your site actually has, a stated basis for likelihood, a stated basis for severity, a scoring rule, the existing controls, a residual risk, actions with dates, a named owner, and a review date with an approval. Miss one and it shows in a minute.
- Scope and boundaryWhich site, which lines, which products, which shifts, and what is deliberately excluded. An assessment with no boundary cannot be shown to be complete.
- The hazards or issues, listed by youWritten from your own walk of the site, your complaint file and your micro data. This is the field that separates a real document from a downloaded one.
- Basis for likelihoodWhat makes something likely here. Historical incidents, complaint rate, equipment age, staff turnover, supplier performance. Say which one you used.
- Basis for severityConsequence to the consumer first, then to legality and to the brand. Severity for a pathogen in a ready to eat product is not the same as severity for a taint complaint.
- The scoring ruleThe matrix, the bands and what each band means in words, printed on the document rather than held in the head of the person who wrote it.
- Existing controlsOnly controls you can evidence on the day. A control listed here is a control the auditor will ask to see running.
- Residual riskThe score after the existing controls, and the threshold above which action is compulsory.
- Actions, with datesEach action with an owner and a target date, and a closure record when it is done. Open actions past their date are a finding on their own.
- Named ownerA person, not a department. “QA” is not an owner.
- Review date and approvalThe next review date and the signature of the person who approved the current version, with version control that matches your document control procedure.
Every ASC risk assessment pack is built on those ten fields, and each pack contains a register, a procedure, a completion guide and a read me, in editable Word and Excel, mapped to BRCGS, IFS and SQF clauses. The procedure is the part sites forget to buy elsewhere: without it you have a spreadsheet, and an auditor asks who is allowed to change it.
Pest control is one of the twenty four, and the easiest one to outsource and forget
ASC Pest Control is part of the ASC Food Safety Consultants group, owned and designed by food safety specialists, a SAPCA member with pest control operators registered under Act 36 of 1947, and built around what a BRCGS, FSSC 22000 or R638 audit or inspection actually asks for. Service reports, barcoded device monitoring and trend analysis live in the My ASC Pest Control Hub, so the pest file is audit ready before anyone asks for it. ASC Pest Control serves Gauteng and the Eastern Cape.
Food and beverage pest control by ASC Request a pest control site assessmentWhich risk scoring methods survive an auditor’s challenge
Any method survives if its bands are defined in words and tied to your own data, because neither BRCGS Issue 9 nor FSSC 22000 Version 7 prescribes a scoring method. A three by three or five by five likelihood and severity matrix is accepted by every GFSI recognised scheme, and so is a plain high, medium and low classification. What fails is a score with no stated basis, and one that changes when the auditor asks why.
| Survives the challenge | Does not survive the challenge |
|---|---|
| A five by five matrix where each likelihood band is defined, for example “has occurred at this site in the last 24 months” | A five by five matrix printed from a template with no band definitions anywhere in the document |
| Severity defined by consumer consequence, with a separate note where legality is the driver | Severity scored on cost or on customer complaint volume alone |
| An inherent score, the controls, then a residual score, with the arithmetic visible | One score entered after the controls, so every line lands comfortably in green |
| High, medium and low with written criteria for each, used consistently across all 24 assessments | High, medium and low applied by feel, with the same subject scored differently in two documents |
| An action threshold stated on the document, for example “any residual score of 12 or above requires an action” | Scores calculated but never used, with no threshold and no action ever raised |
| Scores that move over time as data changes, with the reason recorded in the review row | Identical scores in every annual version for four years running |
The single most common failure is subtler than any of those. It is the assessment where the matrix is correct, the bands are defined, and the hazards listed are still the template author’s hazards. The site has a glass policy, a metal detector and a wooden pallet problem, and none of the three appear. That document is not wrong, it is simply about somebody else’s factory, and a competent auditor spots it because the hazards do not match the walk they have just done with you.
Why is this a three and not a four. Show me the control you have listed here, running, now. Who owns this document and when did they last change their mind about anything in it.
If your scoring is the problem, fix the two that get challenged hardest
Contamination assessments are where scoring gets tested, because the auditor can walk the line and check every claim against what they see.
Buy the Physical Contamination and Foreign Bodies pack, R690 Ask a consultant to review your matrixHow often must each risk assessment be reviewed?
The working rule is at least annually, and immediately on any change that affects the subject, because neither BRCGS Issue 9 nor FSSC 22000 Version 7 prints a universal review frequency. The frequency you choose becomes a commitment the auditor will hold you to. A review date of twelve months that has passed by three weeks is a finding, and it is one of the easiest findings in the book to write.
- A new product, recipe or claim, including any new allergen brought on site
- A new process step, new equipment, or a change of supplier or country of origin
- A layout change, building work, or a change to a zone boundary
- A complaint trend, an adverse micro result, a foreign body incident, a withdrawal or a recall
- Pest activity above your own action level, or a change of pest control contractor
- A scheme version change: FSSC 22000 Version 6 audits are permitted until 30 April 2027, the Version 7 upgrade audit window runs 1 May 2027 to 30 April 2028, and the certification body must complete the upgrade documentation in the FSSC platform by 30 June 2028
- A regulatory change affecting the subject
- A non conformance raised against the subject by an internal audit, a customer or your certification body
- A change of the named owner, or the loss of a key person who held the reasoning in their head
Record the out of cycle review on the same document, with the trigger written into the review row. An auditor who sees “reviewed 14 March 2026 following foreign body complaint C-2026-041, detection frequency increased” reads a system that is alive. An auditor who sees a review row with a date and nothing else reads a diary entry. Our BRCGS Issue 9 ninety day audit countdown sets out when to schedule the reviews before an audit rather than in the last fortnight.
Review dates quietly expire, and that is the easiest finding to write
The PRP verification plan pulls the review cycle for every other prerequisite programme into one place.
Buy the PRP Verification Plan pack with video, R690 Ask a consultant to check your review datesTwenty four risk assessments need twenty four sets of live records
ASCloud is the ASC paperless compliance platform: digital checklists, HACCP records and traceability supporting FSSC 22000, BRCGS, HACCP and R638 sites. The printing stops, the evidence sits where an auditor can see it, and where ASC manages your food safety system on the weekly option, your consultant approves the checklists and keeps an eye on the site between visits rather than waiting for the next one. Ask us for a walkthrough on your own checklists.
See ASCloud, the ASC paperless system Ask ASC for an ASCloud walkthroughThe findings auditors write against risk assessments
Findings against risk assessments are rarely about the absence of a document. They are about a document that cannot be defended. In BRCGS Issue 9 that lands as a minor or major non conformity depending on the clause, and where the subject is a fundamental such as clause 5.3 on allergens or clause 4.11 on housekeeping and hygiene, the consequence escalates quickly.
When a finding does land, the response is what the certification body actually grades. Root cause analysis on a documentation finding is usually done badly, because the site fixes the document and calls that the cause. The guide on corrective action and root cause analysis for audit findings shows what a certification body accepts as a closed action, and the 25 most common FSSC 22000 non conformances shows how often these repeat across sites.
Train the people who write the assessments and the people who challenge them
Internal auditors who know what a defensible risk assessment looks like find these findings before your certification body does. That is the cheapest audit you will ever pay for.
Enrol in Internal and Supplier Auditing Practices, R3,500 Ask about internal auditor supportShould you write your own or start from a template?
Start from a template, then make it yours. An ASC pack at R690 arrives with its clause mapping to BRCGS, IFS and SQF already done, which leaves you the part only you can write. A certification body does not audit where the format came from; it audits whether the content is yours. Writing 24 risk assessments from a blank page takes a competent QA manager several weeks. A template gives you the structure, the hazard prompts and the clause mapping in an afternoon.
The honest limit of any template is this: it cannot know your site. Nobody can sell you your own hazards, your own complaint history, your own zone boundaries or your own supplier list. What you are buying is the scaffolding and the prompts, so that the thinking you have to do anyway lands in a defensible format. A site that buys a pack and enters nothing has bought a finding at R690, and I have seen it happen.
Print the register. Walk the site with it. Cross out every prompt that does not apply to you and write in the three that do. Then score, then name the owner, then set the review date. Two hours of that beats two weeks of drafting.
Where the packs earn their price is in the parts most sites do not think to write: the procedure that governs who may change the assessment, the completion guide that explains what each field is for, and the clause mapping that lets you answer “which clause does this satisfy” without hunting. That mapping is also why the FSSC 22000 toolkit index is clause mapped, so you can trace a clause to a document and back.
Is a R690 risk assessment pack or a R5,500 toolkit better value?
All 24 packs at R690 each come to R16,560. The HACCP and PRPs toolkit is R5,500 and the BRCGS Food Safety toolkit is R6,550, and both already contain the risk assessments plus the full management system and one hour of premium consultation. For a site heading for certification the toolkit is the better buy, and I would rather say so.
| Your situation | What to buy | Price |
|---|---|---|
| You have a working system and one gap the auditor named | The single pack for that subject | R690 |
| Two or three subjects are weak, everything else holds | Two or three packs | R1,380 to R2,070 |
| You are building a system for a first certification, or a GFSI intermediate step | GFSI Intermediate Level toolkit, 105+ documents | R4,000 |
| You run HACCP to SANS 10330 and SANS 10049 and need the prerequisite programmes documented | HACCP and PRPs toolkit, 120+ documents | R5,500 |
| You are certifying to ISO 22000:2018 | ISO 22000:2018 toolkit, 271 documents | R5,900 |
| You are certifying to FSSC 22000 Version 7 in food manufacturing | FSSC 22000 Category C toolkit, 260+ documents, clause mapped index | R6,350 |
| You are certifying to BRCGS Issue 9 | BRCGS Food Safety toolkit, 220+ documents | R6,550 |
| You want all 24 risk assessments and nothing else | 24 separate packs | R16,560 |
The break even against the R4,000 GFSI Intermediate toolkit sits at about six packs, and against the BRCGS Food Safety toolkit at about ten. Buy six and you have spent R4,140 for six documents; buy the BRCGS Food Safety toolkit for R6,550 and you have 220 or more documents including those six, an indexed structure, and an hour with one of our consultants to point at the parts that do not fit your scope. The packs are for a site that has a system and one gap. The toolkits are for a site that is building one.
One thing the arithmetic does not capture. The toolkits are cross referenced, so the allergen risk assessment agrees with the allergen procedure, which agrees with the labelling control and the cleaning validation. Twenty four packs bought one at a time over eight months will not agree with each other unless somebody spends a fortnight making them agree, and that fortnight is the real cost. If you want the full explanation of what sits inside one, read what a food safety toolkit contains.
Heading for certification? Buy the system, not the patches
Six packs cost R4,140 and give you six documents. The BRCGS Food Safety toolkit costs R6,550 and gives you the whole management system with the risk assessments already inside it.
Buy the BRCGS Food Safety toolkit, 220+ documents, R6,550 Request a quote for your scopeHow the packs, the toolkits and consulting fit together
Three routes, priced to be honest about each other. A pack at R690 fixes one named gap. A certification level toolkit from R4,000 to R8,720 builds the system and includes an hour of premium consultation with one of our consultants. Consulting from R480 an hour, or a project quoted as one figure, is for a site that wants the thinking done with them.
Sites usually arrive at the middle option after trying the first. They buy the allergen pack because that is where the finding landed, then find that the cleaning validation behind the allergen assessment is also thin, then that zoning is undocumented, and by the fourth purchase the toolkit would have been cheaper. There is no shame in that order, but if you already know you are three or four documents short of a system, skip to the toolkit.
On the consulting side, we implement, we audit, and we are willing to audit sites we have supplied documents to. If you want the capability in house instead, the training academy is the cheaper long term answer: HACCP for Supervisors and HACCP Teams at R2,730 puts the hazard analysis and the risk assessment logic into the same heads, and Food Fraud (VACCP) and Food Defence (TACCP) at R1,450 covers the two subjects that generate the most rewritten documents. No VAT is charged on training, so the price shown is the price paid.
Two further reads if you are early in the process. Implementing BRCGS Issue 9 works through the nine sections in build order, and the FSSC 22000 Version 7 guide for South Africa covers the Version 6 to Version 7 transition dates in full. If food defence is new to you, what food defence and TACCP actually require is the shortest way in.
We will tell you which of the 24 you are missing
Send us your document register and your last audit report. One of our consultants will tell you which risk assessments are absent, which are stale, and whether a toolkit or three packs is the cheaper fix. ISO 22000:2018 sites at R5,900 and FSSC 22000 Version 7 sites at R6,350 are the two we quote on most.
Browse the shop, packs from R690 and toolkits from R699 Send us your register for reviewRead next from the ASC risk assessment library
Frequently asked questions
How many risk assessments does a GFSI audit expect to see?
Is a risk assessment the same as a HACCP hazard analysis?
What risk scoring method do auditors accept?
How often must a food safety risk assessment be reviewed?
Can I use a template risk assessment for a BRCGS audit?
Which risk assessments do auditors challenge most often?
Is it cheaper to buy the 24 packs or a toolkit?
Will ASC audit a site it has supplied documents to?
Key takeaways
- A risk assessment answers “why is this control enough”. A hazard analysis under ISO 22000:2018 clause 8.5 answers “how is this step controlled”. A GFSI recognised scheme audits both.
- About 24 risk assessments cover what BRCGS Issue 9, FSSC 22000 Version 7 and ISO 22000:2018 ask for, and seven of the twelve BRCGS fundamentals sit inside that list.
- Auditors challenge the reasoning, not the format. A score with no stated basis, a passed review date, an unnamed owner and a control you cannot evidence are the four findings written most often.
- Review annually as a minimum and out of cycle on any change, and write the trigger into the review row so the document reads as a live one.
- All 24 packs cost R16,560. If you have a system and one named gap, buy the single ASC risk assessment pack at R690. If you are building the system, the BRCGS Food Safety toolkit at R6,550 carries 220+ documents with the risk assessments already inside, and the toolkit range runs R699 to R8,720 with certification level sets from R4,000.
Your audit date is fixed. Your document register is not.
Tell us the standard and the audit date and one of our consultants will tell you whether three packs close it or the toolkit is the cheaper answer. ASC is SAATCA registered, a FoodBev SETA Accredited Provider No. 587/00337/1900, B-BBEE Level 1 with 135% procurement recognition, and rated 4.9 out of 5 from 1,260 Google reviews.
Buy risk assessment packs, R690 each Send us your last audit report and we will map the gapsPublished by ASC Food Safety, South African food safety and quality consultants. This article is general guidance and not a substitute for certification-specific advice.