A BRCGS Global Standard for Food Safety Issue 9 audit follows a pattern that any site audited more than once will recognise. After the opening meeting and the first walk of the factory, the auditor sits down and asks for five records in roughly the same order every time: the HACCP plan and its last review, the internal audit schedule and reports, supplier approval records for a handful of raw materials picked from the warehouse, CCP monitoring records for the day of the audit and a day chosen at random, and the corrective action log. How those five records arrive at the table sets the tone of the next two days.
1. The HACCP plan and the evidence it was reviewed
Issue 9 section 2 asks for a HACCP plan based on Codex principles, with a documented review at least annually and whenever there is a change. The auditor is not reading the plan for the first time, they are looking at the review. Who attended, what changed, which CCPs were challenged and what the validation evidence was. On paper this is a meeting minute filed somewhere near the plan. On ASCloud the HACCP plan is a live document with its review history attached, the hazard analysis is a table that shows the date each line was last confirmed, and the validation records for each CCP limit are linked from the limit itself.
2. Internal audits, and whether they found anything
Section 3.4 requires a programme of internal audits covering the whole standard across the year, by trained auditors independent of the area audited, with non-conformances recorded and closed. The auditor checks that the programme exists, that it was followed and, tellingly, that it found things. A year of internal audits with zero findings is a red flag. A paperless system schedules the audits, assigns the auditor, holds the checklist against the relevant clauses and feeds any finding straight into the corrective action log with an owner and a due date. Overdue findings are visible on the dashboard long before the external auditor sees them.
3. Supplier approval for three raw materials
Section 3.5 is where many sites bleed non-conformances. The auditor walks the raw material store, picks three items including at least one high-risk one, and asks for the approval record of each supplier: the risk assessment, the certificate or questionnaire, the specification and the ongoing performance monitoring. The failure is nearly always a lapsed certificate or a specification that does not match the pack. With a supplier portal on ASCloud, suppliers upload their own certificates and the system flags expiry well before the date. The approval record for any supplier is one search away, with the specification attached.
4. CCP monitoring for today and for a random day
Section 2.10 and 2.11 cover monitoring and corrective action at critical control points. The auditor will take today’s record from the line and compare it with the record for a date they choose, often a weekend or a night shift. They check the frequency matches the plan, the limits are the validated ones, every reading is signed and verified, and any deviation led to a documented action on the affected product. Paper monitoring sheets are where pre-filled and missing entries are found. Digital monitoring on ASCloud timestamps each reading, alerts on a missed check, forces a corrective action record when a limit is breached and keeps the verifier separate from the operator.
5. The corrective action log
Section 3.7 asks for root cause analysis and corrective action for every non-conformance, whether it came from an internal audit, a customer complaint, a CCP deviation or an external audit. The auditor reads the log looking for repeats, for actions closed without evidence, and for root causes that are really restatements of the problem. One log, in one place, with the evidence of closure attached, is the difference between a clean section 3.7 and a minor non-conformance. On ASCloud every source of non-conformance feeds the same log, and a repeat within a set period is flagged automatically.
What this looks like at the audit table
At a site running a paperless system the five records arrive on a tablet in under five minutes, with the audit trail on each visible on request. The auditor’s time then goes into the factory floor and the risk assessments, which is where a good site shows its strength. At a paper site the first hour is spent locating files, and the auditor forms a view about the control of the system before they have seen a single process. Issue 9 does not give a grade for tidiness, but an auditor who has waited twenty minutes for a supplier file looks harder at everything else.
Audit-ready BRCGS records
HACCP review, internal audits, supplier approval, CCP monitoring and CAPA in one system, maintained for Issue 9 and updated for Issue 10 when it is published. From R3,800 per site per month.
Frequently asked questions
When is BRCGS Issue 10 coming?
BRCGS has Issue 10 of the Food Safety standard in development. Issue 9 remains the audited version until the published transition date, and ASC will update ASCloud content when Issue 10 is released.
Does BRCGS accept electronic records?
Yes. Issue 9 requires records to be legible, genuine, retained and protected from loss. An electronic system with an audit trail meets that more easily than paper.
Can the auditor access the system directly?
You control access. Most sites give the auditor a read-only view on a tablet for the duration of the audit.
What about unannounced audits?
A paperless system is the best preparation for an unannounced audit, because the records are in the same state every day. There is no audit week.