The 24 Risk Assessments a GFSI Food Audit Expects

RISK ASSESSMENTS · GFSI AUDITS

The 24 Risk Assessments a GFSI Food Audit Expects

By Mthokozisi Nkosi, Food Safety Specialist & Lead Auditor, ASC Food Safety · 14 min read

The 24 food safety risk assessments a GFSI audit expects, shown on a hazard identification and risk evaluation board

BRCGS Issue 9, FSSC 22000 Version 7 and IFS all require documented risk assessments, and a hazard analysis does not satisfy them. A certified site holds about 24, from allergen management under BRCGS clause 5.3 to context of the organisation under ISO 22000:2018 clause 4.1. ASC packs are R690 each. Toolkits run R699 for the Basic set to R8,720 for GLOBALG.A.P. IFA, certification level toolkits from R4,000, assessments already inside.

At a glance

Risk assessments a certified site normally holds
About 24, covering prerequisite programmes, contamination routes and the management level clauses
Price per ASC pack
R690, containing a register, a procedure, a completion guide and a read me, in editable Word and Excel
All 24 bought separately
R16,560
Toolkit range
R699 to R8,720 by standard, with the certification level toolkits from R4,000, risk assessments already built in plus one hour of premium consultation
Standards these map to
BRCGS Issue 9, FSSC 22000 Version 7, ISO 22000:2018, IFS and SQF clauses
Minimum review discipline
Annually, plus an out of cycle review on any change that affects the subject
The finding auditors write most
A risk score with no stated basis, on a document with no named owner
Consulting
From R480 an hour, or a full project scoped and quoted as one figure

Buy the one you are missing, or the whole system

Most sites reading this already know which risk assessment their last audit exposed. Start there, or start with the set.

Browse all 24 risk assessment packs, R690 each Ask ASC which of the 24 your audit will actually ask for

What is a food safety risk assessment?

A food safety risk assessment is a documented judgement about one subject, cleaning, pests, zoning, suppliers, allergens, fraud or utilities, required in writing by BRCGS Issue 9, FSSC 22000 Version 7 and ISO 22000:2018 clause 6.1. It differs from a hazard analysis in scope, because a hazard analysis works product by product through the process flow under ISO 22000:2018 clause 8.5 while a risk assessment works subject by subject. A GFSI recognised scheme wants both.

The confusion is expensive. It shows up as a non-conformity against a clause the site believed its HACCP study had already answered. A HACCP study is bounded by its scope and its flow diagram, so it can only reason about hazards that appear at a process step. It has nothing sensible to say about why your external bins sit where they sit, why the goods in bay is cleaned weekly rather than daily, or why a supplier in a new country of origin was approved on a certificate alone. Those questions live in prerequisite programmes and in management decisions, and the schemes ask you to justify them in writing.

The distinction matters at the audit table. When an auditor asks why a control is set where it is, a HACCP plan answers with a critical limit and its validation. A prerequisite programme answers with a procedure. Neither of those explains the choice. The risk assessment explains the choice, and it is the only document on site that carries the reasoning. If you want the HACCP side laid out in full, our guide on what a HACCP plan contains covers the twelve steps in order.

The one line test

If the question starts with “why is that enough”, the answer lives in a risk assessment. If it starts with “how do you control that”, the answer lives in a procedure or a HACCP plan.

Why certification schemes ask for risk assessments by name

Because the schemes stopped prescribing controls and started demanding justification. BRCGS Global Standard Food Safety Issue 9, published 1 August 2022, runs to nine sections with twelve fundamental requirements, and several of those fundamentals are written in risk based language rather than as a fixed rule. FSSC 22000 Version 7, published May 2026, carries its own additional requirements in Part 2, section 2.5.

First, a correction that matters for anyone searching this topic. There is no such thing as GFSI certification. GFSI is hosted by The Consumer Goods Forum and benchmarks schemes; it does not certify anybody. A GFSI audit means an audit against a GFSI recognised scheme: BRCGS, FSSC 22000, IFS, SQF or GLOBALG.A.P. IFA v6 in the GFS edition. ISO 22000 on its own is not GFSI recognised, which is exactly why FSSC 22000 exists as ISO 22000:2018 plus a sector prerequisite programme standard from the ISO 22002 series plus the FSSC additional requirements. If you are still choosing, the BRCGS, FSSC 22000 and IFS decision framework sets out the trade offs.

The twelve BRCGS Issue 9 fundamentals are clauses 1.1, 2, 3.4, 3.5.1, 3.7, 3.9, 4.3, 4.11, 5.3, 6.1, 6.2 and 7.1. A major non-conformity against its statement of intent is a fail. Certification is off the table, the auditor, the certification body and site management agree whether the audit ends there or carries on as a non-certification gap audit, and a further full audit is needed to certify. Look at that list against the risk assessment table below and the overlap is obvious: supplier approval, traceability, layout and segregation, housekeeping and hygiene, allergen management and control of operations all sit in it, and every one of them is assessed on the strength of your written reasoning.

IFS applies the same logic through its own checklist, with risk based wording running through the requirements rather than a separate risk assessment register. The practical effect is the same. An IFS auditor asks for the justification behind a frequency, a zone boundary or a supplier decision, and expects a document rather than a conversation.

An auditor tests something narrower than whether you have controls: whether you can show why those controls are the right ones for your site.

Food defence and food fraud are where new sites lose the most time

TACCP and VACCP are named requirements in both BRCGS Issue 9 and FSSC 22000 Version 7, and they are the two most commonly written from scratch the week before an audit.

Buy the Food Defence (TACCP) Risk Assessment, R690 Talk to ASC about a full risk assessment set

The full list of risk assessments a GFSI audit expects, and the clause that drives each

No standard prints a list of required risk assessments. Sites are left to work the list out for themselves. In practice a certified food manufacturing site holds about 24, and an auditor works through them by subject rather than by number. The table below gives every one, what it covers, and the clause that drives it in BRCGS Issue 9, FSSC 22000 Version 7 or ISO 22000:2018. Every pack is R690.

24risk assessments a certified site holds
R690per pack, Word and Excel
12BRCGS Issue 9 fundamentals
9sections in BRCGS Issue 9
CodeRisk assessment packWhat it covers, and what an auditor opens it to seeThe clause that drives it
RA01PRP Verification Plan Risk Assessment Template with Instructional Video · R690How each prerequisite programme is verified, by whom, how often, and on what evidence. The document that stops verification being a swab schedule nobody can justify.ISO 22000:2018 clause 8.2, prerequisite programmes, read with the ISO 22002 series and BRCGS Issue 9 Section 3
RA02Food Defence (TACCP) Risk Assessment Template with Instructional Video · R690Deliberate contamination and malicious tampering: access points, vulnerable process steps, visitors, contractors, disgruntled insiders, and the countermeasures for each.BRCGS Issue 9 clause 4.2, food defence, and the FSSC 22000 Version 7 additional requirement on food defence
RA03Cleaning and Disinfection Risk Assessment Template · R690Why each area, surface and piece of equipment is cleaned at the frequency and to the standard you have chosen, and how that standard is proved.BRCGS Issue 9 clause 4.11, housekeeping and hygiene, a fundamental requirement
RA04Personal Hygiene Risk Assessment Template · R690Hand washing points, jewellery, protective clothing, changing routes, medical screening and visitor rules, justified by zone rather than copied from a poster.BRCGS Issue 9 clauses 7.2 personal hygiene and 7.4 protective clothing
RA05Pest Control Risk Assessment Template · R690Species of concern, device type and placement, bait policy, inspection frequency, proofing weaknesses and the trend that would trigger action.BRCGS Issue 9 clause 4.14, pest management
RA06Waste and Food Loss Management Risk Assessment Template · R690Waste streams and their routes out of the building, external bin siting, contamination and pest attraction, and how surplus food is handled or donated.BRCGS Issue 9 clauses 4.12 waste and waste disposal and 4.13 management of surplus food
RA07Site and Building Fabric Risk Assessment Template · R690Walls, floors, ceilings, drains, doors, windows, roof and external areas, scored by the contamination each defect could cause and the repair priority that follows.BRCGS Issue 9 clauses 4.4 building fabric and 4.1 external standards and site security
RA08Layout and Hygienic Zoning Risk Assessment Template · R690Product, people, waste and air flow across the site, zone boundaries, and the cross contamination each crossing point creates. Auditors walk this one with you.BRCGS Issue 9 clause 4.3, layout, product flow and segregation, a fundamental, with Section 8 production risk zones
RA09Utilities, Water, Air, Steam and Lighting Risk Assessment Template · R690Water source and treatment, ice, compressed air, steam contact, gases and lighting, with the sampling regime each one earns.BRCGS Issue 9 clause 4.5, utilities, water, ice, air and other gases
RA10Equipment Suitability and Maintenance Risk Assessment Template · R690Hygienic design, material suitability, maintenance access, temporary repairs, lubricants and the hand back to production after engineering work.BRCGS Issue 9 clauses 4.6 equipment and 4.7 maintenance, and the FSSC 22000 Version 7 additional requirement on equipment management
RA11Supplier and Purchased Material Approval Risk Assessment Template · R690The risk category of every raw material and supplier, and the approval evidence each category demands, from a certificate to an on site audit.BRCGS Issue 9 clause 3.5, supplier and raw material approval, with 3.5.1 a fundamental
RA12Storage, Warehousing and Transport Risk Assessment Template · R690Segregation in store, stock rotation, temperature control, vehicle condition and checks, loading and third party logistics.BRCGS Issue 9 clauses 4.15 storage facilities and 4.16 dispatch and transport, with ISO 22002-5:2025 for transport and storage
RA13Rework Risk Assessment Template · R690Which product may be reworked, into what, at what inclusion rate, with what allergen and traceability consequence, and who authorises it.BRCGS Issue 9 clause 6.1, control of operations, a fundamental, read with clause 5.3 management of allergens
RA14Microbiological Contamination Risk Assessment Template · R690Pathogens and spoilage organisms relevant to your products and processes, survival and growth points, and the controls and sampling that follow.BRCGS Issue 9 Section 2, the food safety plan based on HACCP, a fundamental, with Section 8 production risk zones
RA15Physical Contamination and Foreign Bodies Risk Assessment Template · R690Glass, brittle plastic, metal, wood, stones, pests and personal items, mapped to the process step, with detection and removal equipment justified rather than assumed.BRCGS Issue 9 clauses 4.9 chemical and physical product contamination control and 4.10 foreign body detection and removal equipment
RA16Chemical Contamination Risk Assessment Template · R690Cleaning chemicals, lubricants, pesticides, processing aids, packaging migration and taint, with storage, decanting and labelling controls.BRCGS Issue 9 clause 4.9, chemical and physical product contamination control
RA17Allergen Management Risk Assessment Template · R690Allergens on site, cross contact routes through storage, line, rework, air and people, cleaning validation, and the basis for any precautionary statement.BRCGS Issue 9 clause 5.3, management of allergens, a fundamental, and the FSSC 22000 Version 7 additional requirement on management of allergens
RA18Food Fraud Vulnerability (VACCP) Risk Assessment Template · R690Adulteration, substitution, dilution, mislabelling and counterfeit risk by raw material, with horizon scanning evidence and the mitigation you have actually put in place.BRCGS Issue 9 clause 5.4, product authenticity, claims and chain of custody, and the FSSC 22000 Version 7 additional requirement on food fraud mitigation
RA19Environmental Monitoring Risk Assessment Template · R690Zone one to zone four sampling sites, organism, frequency, action limits and the escalation when a result goes the wrong way.FSSC 22000 Version 7 additional requirement on environmental monitoring, with BRCGS Issue 9 Section 8 production risk zones
RA20Traceability, Withdrawal and Recall Risk Assessment Template · R690Where traceability could break, how long a mass balance takes, and what the recall decision, contact list and test would look like under pressure.BRCGS Issue 9 clause 3.9 traceability, a fundamental, with 3.11 management of incidents, product withdrawal and product recall, and ISO 22000:2018 clause 8.3
RA21Emergency Preparedness and Response Risk Assessment Template · R690Power and water failure, flood, fire, load shedding, strike action, IT loss and supply interruption, with the food safety consequence of each and the response plan.ISO 22000:2018 clause 8.4, emergency preparedness and response, with BRCGS Issue 9 clause 3.11
RA22Context of the Organisation Risk Assessment Template · R690External and internal issues that affect your ability to deliver safe food: market, regulatory, climate, infrastructure, skills and ownership.ISO 22000:2018 clause 4.1, understanding the organisation and its context
RA23Interested Parties Risk Assessment Template · R690Customers, regulators, certification bodies, staff, community and suppliers, their requirements, and which of those requirements you have accepted as binding.ISO 22000:2018 clause 4.2, understanding the needs and expectations of interested parties
RA24Strategic Risks and Opportunities Risk Assessment Template · R690The management level register: what could stop the food safety management system achieving its intended result, and what you will do about it.ISO 22000:2018 clause 6.1, actions to address risks and opportunities

Two notes on how to read that table. Where a row cites a BRCGS clause, the same subject appears in FSSC 22000 through ISO 22000:2018 and the relevant part of the ISO 22002 series, which was restructured in July 2025 so that most parts became full International Standards, including ISO 22002-100:2025 as a new common baseline published on 29 July 2025. Where a row cites an ISO 22000 clause, BRCGS reaches the same subject through Section 1 and Section 3. The subject is what the auditor cares about, not the label on the document.

Second, RA22, RA23 and RA24 are the three that manufacturing sites most often skip, because they feel like paperwork for the boardroom. They are not optional in an ISO 22000 or FSSC 22000 audit. Clauses 4.1, 4.2 and 6.1 are auditable requirements, and an auditor who finds no evidence of them writes the finding against the management system, not against the factory floor.

Buying more than four packs? Do the sum first

Four packs cost R2,760. A GFSI Intermediate Level toolkit is R4,000 and carries a complete management system with the risk assessments already in it.

Buy the GFSI Intermediate toolkit, 105+ documents, R4,000 Ask us which set fits your scope

What a defensible risk assessment actually contains

A defensible risk assessment carries ten things, and they are what an auditor tests against ISO 22000:2018 clause 6.1 and BRCGS Issue 9: scope, the hazards your site actually has, a stated basis for likelihood, a stated basis for severity, a scoring rule, the existing controls, a residual risk, actions with dates, a named owner, and a review date with an approval. Miss one and it shows in a minute.

  1. Scope and boundaryWhich site, which lines, which products, which shifts, and what is deliberately excluded. An assessment with no boundary cannot be shown to be complete.
  2. The hazards or issues, listed by youWritten from your own walk of the site, your complaint file and your micro data. This is the field that separates a real document from a downloaded one.
  3. Basis for likelihoodWhat makes something likely here. Historical incidents, complaint rate, equipment age, staff turnover, supplier performance. Say which one you used.
  4. Basis for severityConsequence to the consumer first, then to legality and to the brand. Severity for a pathogen in a ready to eat product is not the same as severity for a taint complaint.
  5. The scoring ruleThe matrix, the bands and what each band means in words, printed on the document rather than held in the head of the person who wrote it.
  6. Existing controlsOnly controls you can evidence on the day. A control listed here is a control the auditor will ask to see running.
  7. Residual riskThe score after the existing controls, and the threshold above which action is compulsory.
  8. Actions, with datesEach action with an owner and a target date, and a closure record when it is done. Open actions past their date are a finding on their own.
  9. Named ownerA person, not a department. “QA” is not an owner.
  10. Review date and approvalThe next review date and the signature of the person who approved the current version, with version control that matches your document control procedure.

Every ASC risk assessment pack is built on those ten fields, and each pack contains a register, a procedure, a completion guide and a read me, in editable Word and Excel, mapped to BRCGS, IFS and SQF clauses. The procedure is the part sites forget to buy elsewhere: without it you have a spreadsheet, and an auditor asks who is allowed to change it.

Pest control is one of the twenty four, and the easiest one to outsource and forget

ASC Pest Control is part of the ASC Food Safety Consultants group, owned and designed by food safety specialists, a SAPCA member with pest control operators registered under Act 36 of 1947, and built around what a BRCGS, FSSC 22000 or R638 audit or inspection actually asks for. Service reports, barcoded device monitoring and trend analysis live in the My ASC Pest Control Hub, so the pest file is audit ready before anyone asks for it. ASC Pest Control serves Gauteng and the Eastern Cape.

Food and beverage pest control by ASC Request a pest control site assessment

Which risk scoring methods survive an auditor’s challenge

Any method survives if its bands are defined in words and tied to your own data, because neither BRCGS Issue 9 nor FSSC 22000 Version 7 prescribes a scoring method. A three by three or five by five likelihood and severity matrix is accepted by every GFSI recognised scheme, and so is a plain high, medium and low classification. What fails is a score with no stated basis, and one that changes when the auditor asks why.

Survives the challengeDoes not survive the challenge
A five by five matrix where each likelihood band is defined, for example “has occurred at this site in the last 24 months”A five by five matrix printed from a template with no band definitions anywhere in the document
Severity defined by consumer consequence, with a separate note where legality is the driverSeverity scored on cost or on customer complaint volume alone
An inherent score, the controls, then a residual score, with the arithmetic visibleOne score entered after the controls, so every line lands comfortably in green
High, medium and low with written criteria for each, used consistently across all 24 assessmentsHigh, medium and low applied by feel, with the same subject scored differently in two documents
An action threshold stated on the document, for example “any residual score of 12 or above requires an action”Scores calculated but never used, with no threshold and no action ever raised
Scores that move over time as data changes, with the reason recorded in the review rowIdentical scores in every annual version for four years running

The single most common failure is subtler than any of those. It is the assessment where the matrix is correct, the bands are defined, and the hazards listed are still the template author’s hazards. The site has a glass policy, a metal detector and a wooden pallet problem, and none of the three appear. That document is not wrong, it is simply about somebody else’s factory, and a competent auditor spots it because the hazards do not match the walk they have just done with you.

The three questions that break a weak assessment

Why is this a three and not a four. Show me the control you have listed here, running, now. Who owns this document and when did they last change their mind about anything in it.

If your scoring is the problem, fix the two that get challenged hardest

Contamination assessments are where scoring gets tested, because the auditor can walk the line and check every claim against what they see.

Buy the Physical Contamination and Foreign Bodies pack, R690 Ask a consultant to review your matrix

How often must each risk assessment be reviewed?

The working rule is at least annually, and immediately on any change that affects the subject, because neither BRCGS Issue 9 nor FSSC 22000 Version 7 prints a universal review frequency. The frequency you choose becomes a commitment the auditor will hold you to. A review date of twelve months that has passed by three weeks is a finding, and it is one of the easiest findings in the book to write.

  • A new product, recipe or claim, including any new allergen brought on site
  • A new process step, new equipment, or a change of supplier or country of origin
  • A layout change, building work, or a change to a zone boundary
  • A complaint trend, an adverse micro result, a foreign body incident, a withdrawal or a recall
  • Pest activity above your own action level, or a change of pest control contractor
  • A scheme version change: FSSC 22000 Version 6 audits are permitted until 30 April 2027, the Version 7 upgrade audit window runs 1 May 2027 to 30 April 2028, and the certification body must complete the upgrade documentation in the FSSC platform by 30 June 2028
  • A regulatory change affecting the subject
  • A non conformance raised against the subject by an internal audit, a customer or your certification body
  • A change of the named owner, or the loss of a key person who held the reasoning in their head

Record the out of cycle review on the same document, with the trigger written into the review row. An auditor who sees “reviewed 14 March 2026 following foreign body complaint C-2026-041, detection frequency increased” reads a system that is alive. An auditor who sees a review row with a date and nothing else reads a diary entry. Our BRCGS Issue 9 ninety day audit countdown sets out when to schedule the reviews before an audit rather than in the last fortnight.

Review dates quietly expire, and that is the easiest finding to write

The PRP verification plan pulls the review cycle for every other prerequisite programme into one place.

Buy the PRP Verification Plan pack with video, R690 Ask a consultant to check your review dates

Twenty four risk assessments need twenty four sets of live records

ASCloud is the ASC paperless compliance platform: digital checklists, HACCP records and traceability supporting FSSC 22000, BRCGS, HACCP and R638 sites. The printing stops, the evidence sits where an auditor can see it, and where ASC manages your food safety system on the weekly option, your consultant approves the checklists and keeps an eye on the site between visits rather than waiting for the next one. Ask us for a walkthrough on your own checklists.

See ASCloud, the ASC paperless system Ask ASC for an ASCloud walkthrough

The findings auditors write against risk assessments

Findings against risk assessments are rarely about the absence of a document. They are about a document that cannot be defended. In BRCGS Issue 9 that lands as a minor or major non conformity depending on the clause, and where the subject is a fundamental such as clause 5.3 on allergens or clause 4.11 on housekeeping and hygiene, the consequence escalates quickly.

🔢A score with no stated basisThe number exists, the reasoning does not. The most common finding of all, and the easiest to prevent.
📄A template with nobody’s hazards in itThe matrix is fine, the hazards belong to the vendor’s example site, and the auditor’s site walk does not match the document.
📅A review date that has passedYou set the frequency and then missed it. The finding is against your own commitment, which makes it hard to argue.
👤No named ownerA document owned by a department is a document nobody updates. Auditors ask for a person and a date.
🔍Controls you cannot evidenceThe assessment lists a control that is not running, or is running differently. This is the finding most likely to be graded as a major, because it makes the document untrue.
Contradicting the HACCP planThe risk assessment says the step is low risk, the HACCP plan calls it a CCP. One of them is wrong and the auditor will decide which.
📋Actions raised and never closedActions with target dates in the past and no closure evidence turn a good document into a corrective action finding.
📦One document covering everythingA single “site risk assessment” that tries to cover pests, allergens, fraud and zoning satisfies none of the clauses that drive them.

When a finding does land, the response is what the certification body actually grades. Root cause analysis on a documentation finding is usually done badly, because the site fixes the document and calls that the cause. The guide on corrective action and root cause analysis for audit findings shows what a certification body accepts as a closed action, and the 25 most common FSSC 22000 non conformances shows how often these repeat across sites.

Train the people who write the assessments and the people who challenge them

Internal auditors who know what a defensible risk assessment looks like find these findings before your certification body does. That is the cheapest audit you will ever pay for.

Enrol in Internal and Supplier Auditing Practices, R3,500 Ask about internal auditor support

Should you write your own or start from a template?

Start from a template, then make it yours. An ASC pack at R690 arrives with its clause mapping to BRCGS, IFS and SQF already done, which leaves you the part only you can write. A certification body does not audit where the format came from; it audits whether the content is yours. Writing 24 risk assessments from a blank page takes a competent QA manager several weeks. A template gives you the structure, the hazard prompts and the clause mapping in an afternoon.

The honest limit of any template is this: it cannot know your site. Nobody can sell you your own hazards, your own complaint history, your own zone boundaries or your own supplier list. What you are buying is the scaffolding and the prompts, so that the thinking you have to do anyway lands in a defensible format. A site that buys a pack and enters nothing has bought a finding at R690, and I have seen it happen.

How to use a pack properly

Print the register. Walk the site with it. Cross out every prompt that does not apply to you and write in the three that do. Then score, then name the owner, then set the review date. Two hours of that beats two weeks of drafting.

Where the packs earn their price is in the parts most sites do not think to write: the procedure that governs who may change the assessment, the completion guide that explains what each field is for, and the clause mapping that lets you answer “which clause does this satisfy” without hunting. That mapping is also why the FSSC 22000 toolkit index is clause mapped, so you can trace a clause to a document and back.

Is a R690 risk assessment pack or a R5,500 toolkit better value?

All 24 packs at R690 each come to R16,560. The HACCP and PRPs toolkit is R5,500 and the BRCGS Food Safety toolkit is R6,550, and both already contain the risk assessments plus the full management system and one hour of premium consultation. For a site heading for certification the toolkit is the better buy, and I would rather say so.

Your situationWhat to buyPrice
You have a working system and one gap the auditor namedThe single pack for that subjectR690
Two or three subjects are weak, everything else holdsTwo or three packsR1,380 to R2,070
You are building a system for a first certification, or a GFSI intermediate stepGFSI Intermediate Level toolkit, 105+ documentsR4,000
You run HACCP to SANS 10330 and SANS 10049 and need the prerequisite programmes documentedHACCP and PRPs toolkit, 120+ documentsR5,500
You are certifying to ISO 22000:2018ISO 22000:2018 toolkit, 271 documentsR5,900
You are certifying to FSSC 22000 Version 7 in food manufacturingFSSC 22000 Category C toolkit, 260+ documents, clause mapped indexR6,350
You are certifying to BRCGS Issue 9BRCGS Food Safety toolkit, 220+ documentsR6,550
You want all 24 risk assessments and nothing else24 separate packsR16,560

The break even against the R4,000 GFSI Intermediate toolkit sits at about six packs, and against the BRCGS Food Safety toolkit at about ten. Buy six and you have spent R4,140 for six documents; buy the BRCGS Food Safety toolkit for R6,550 and you have 220 or more documents including those six, an indexed structure, and an hour with one of our consultants to point at the parts that do not fit your scope. The packs are for a site that has a system and one gap. The toolkits are for a site that is building one.

One thing the arithmetic does not capture. The toolkits are cross referenced, so the allergen risk assessment agrees with the allergen procedure, which agrees with the labelling control and the cleaning validation. Twenty four packs bought one at a time over eight months will not agree with each other unless somebody spends a fortnight making them agree, and that fortnight is the real cost. If you want the full explanation of what sits inside one, read what a food safety toolkit contains.

Heading for certification? Buy the system, not the patches

Six packs cost R4,140 and give you six documents. The BRCGS Food Safety toolkit costs R6,550 and gives you the whole management system with the risk assessments already inside it.

Buy the BRCGS Food Safety toolkit, 220+ documents, R6,550 Request a quote for your scope

How the packs, the toolkits and consulting fit together

Three routes, priced to be honest about each other. A pack at R690 fixes one named gap. A certification level toolkit from R4,000 to R8,720 builds the system and includes an hour of premium consultation with one of our consultants. Consulting from R480 an hour, or a project quoted as one figure, is for a site that wants the thinking done with them.

Sites usually arrive at the middle option after trying the first. They buy the allergen pack because that is where the finding landed, then find that the cleaning validation behind the allergen assessment is also thin, then that zoning is undocumented, and by the fourth purchase the toolkit would have been cheaper. There is no shame in that order, but if you already know you are three or four documents short of a system, skip to the toolkit.

On the consulting side, we implement, we audit, and we are willing to audit sites we have supplied documents to. If you want the capability in house instead, the training academy is the cheaper long term answer: HACCP for Supervisors and HACCP Teams at R2,730 puts the hazard analysis and the risk assessment logic into the same heads, and Food Fraud (VACCP) and Food Defence (TACCP) at R1,450 covers the two subjects that generate the most rewritten documents. No VAT is charged on training, so the price shown is the price paid.

Two further reads if you are early in the process. Implementing BRCGS Issue 9 works through the nine sections in build order, and the FSSC 22000 Version 7 guide for South Africa covers the Version 6 to Version 7 transition dates in full. If food defence is new to you, what food defence and TACCP actually require is the shortest way in.

We will tell you which of the 24 you are missing

Send us your document register and your last audit report. One of our consultants will tell you which risk assessments are absent, which are stale, and whether a toolkit or three packs is the cheaper fix. ISO 22000:2018 sites at R5,900 and FSSC 22000 Version 7 sites at R6,350 are the two we quote on most.

Browse the shop, packs from R690 and toolkits from R699 Send us your register for review

Read next from the ASC risk assessment library

Frequently asked questions

How many risk assessments does a GFSI audit expect to see?
There is no fixed number in any standard, but a food manufacturing site certified to BRCGS Issue 9 or FSSC 22000 Version 7 will normally hold about 24 documented risk assessments. They cover the prerequisite programmes, the contamination routes, allergens, food defence, food fraud, traceability and the management level requirements of ISO 22000:2018 clauses 4.1, 4.2 and 6.1. ASC sells all 24 as separate packs at R690 each.
Is a risk assessment the same as a HACCP hazard analysis?
No. A hazard analysis works product by product through the process flow and ends in critical control points and operational prerequisite programmes, under ISO 22000:2018 clause 8.5 and Codex CXC 1-1969. A risk assessment works subject by subject: cleaning, pests, zoning, suppliers, fraud, utilities. Auditors expect both, and expect them to agree with each other.
What risk scoring method do auditors accept?
Any method with written definitions. A three by three or five by five likelihood and severity matrix is accepted everywhere, provided each band is defined in words and tied to your own data. Qualitative high, medium and low is accepted on the same condition. What fails is a number with no stated basis, or a score that changes when the auditor asks why.
How often must a food safety risk assessment be reviewed?
At least once a year as a minimum discipline, and immediately whenever something changes. Triggers include a new product, process, supplier, allergen or piece of equipment, a layout change, a customer complaint trend, an adverse micro result, a recall or withdrawal, a scheme version change such as FSSC 22000 Version 7, and any finding raised against the subject.
Can I use a template risk assessment for a BRCGS audit?
Yes, and most certified sites do. A certification body does not audit where the format came from, it audits whether the content is yours. The finding comes when the template is submitted with the vendor’s example hazards still in it and none of your own. Buy the structure, then spend an afternoon entering your hazards, your data and your controls.
Which risk assessments do auditors challenge most often?
Allergen management, cleaning and disinfection, food fraud and environmental monitoring. Allergens because BRCGS Issue 9 clause 5.3 is a fundamental requirement and a major non-conformity against its statement of intent is a fail, and certification is off the table. What happens to the audit itself is then agreed between the auditor, the certification body and site management: it can end there, or it can carry on as a non-certification gap audit. Either way a further full audit is needed before the site can be certified. Cleaning because frequencies are usually inherited rather than justified. Food fraud because horizon scanning evidence is often missing. Environmental monitoring because sample sites are rarely tied to a written rationale.
Is it cheaper to buy the 24 packs or a toolkit?
All 24 packs bought separately come to R16,560. A full document toolkit runs from R699 for the R638 aligned Basic Food Safety set to R8,720 for GLOBALG.A.P. IFA with all add-ons, with the certification level toolkits from R4,000 for the GFSI Intermediate set to R6,550 for BRCGS Food Safety, and each one already contains the risk assessments plus the policies, procedures, forms and one hour of premium consultation. If you are building a system for certification, the toolkit is the better buy. If you have a system and one gap, buy the pack.
Will ASC audit a site it has supplied documents to?
Yes. ASC Food Safety Consultants is willing to audit sites it has supplied documents to, and carries out second party and internal audits as a separate service. If you would rather build the capability in house, the Internal and Supplier Auditing Practices course is R3,500 with no VAT charged, self paced online, with lifetime access and a QR verifiable certificate.

Key takeaways

  • A risk assessment answers “why is this control enough”. A hazard analysis under ISO 22000:2018 clause 8.5 answers “how is this step controlled”. A GFSI recognised scheme audits both.
  • About 24 risk assessments cover what BRCGS Issue 9, FSSC 22000 Version 7 and ISO 22000:2018 ask for, and seven of the twelve BRCGS fundamentals sit inside that list.
  • Auditors challenge the reasoning, not the format. A score with no stated basis, a passed review date, an unnamed owner and a control you cannot evidence are the four findings written most often.
  • Review annually as a minimum and out of cycle on any change, and write the trigger into the review row so the document reads as a live one.
  • All 24 packs cost R16,560. If you have a system and one named gap, buy the single ASC risk assessment pack at R690. If you are building the system, the BRCGS Food Safety toolkit at R6,550 carries 220+ documents with the risk assessments already inside, and the toolkit range runs R699 to R8,720 with certification level sets from R4,000.
MN
Mthokozisi Nkosi
Food Safety Specialist & Lead Auditor, ASC Food Safety

Managing Director and Principal Consultant at ASC Food Safety Consultants. Registered Lead Auditor with Exemplar Global and IRCA, SAATCA registered R638:2018 Lead Implementer, PCQI, FoodBev SETA assessor and an HPCSA registered Environmental Health Practitioner, a registration personal to him rather than a company accreditation. He holds an MPH, an MSc in Data Science, an MBA and a BSc (Agric) Hons in Food Science and Technology, and is completing a PhD in Public Health. He speaks at the 2026 SAAFoST and Nelson Mandela University Food Safety Symposium and works with teams from Gqeberha, Johannesburg and Cape Town, supported by food scientists, biochemists and FSSC 22000 Lead Auditors.

Your audit date is fixed. Your document register is not.

Tell us the standard and the audit date and one of our consultants will tell you whether three packs close it or the toolkit is the cheaper answer. ASC is SAATCA registered, a FoodBev SETA Accredited Provider No. 587/00337/1900, B-BBEE Level 1 with 135% procurement recognition, and rated 4.9 out of 5 from 1,260 Google reviews.

Buy risk assessment packs, R690 each Send us your last audit report and we will map the gaps

Published by ASC Food Safety, South African food safety and quality consultants. This article is general guidance and not a substitute for certification-specific advice.

Leave a Comment

I accept the Terms and Conditions and the Privacy Policy

News & updates 5 new
4.9/5 what do you need today?