Context, Interested Parties and Strategic Risk: The Three ISO 22000 Assessments Most Sites Fail
By Mthokozisi Nkosi, Food Safety Specialist & Lead Auditor, ASC Food Safety · 14 min read

ISO 22000:2018 clause 4 asks a site to determine the external and internal issues relevant to its food safety management system and the requirements of relevant interested parties. Clause 6.1 then asks for actions to address the risks and opportunities that follow. None of this is hazard analysis, and it is where FSSC 22000 auditors write findings. The three ASC packs that cover it are R690 each.
At a glance
- Where the requirement sits
- ISO 22000:2018 clause 4 for context and interested parties, clause 6.1 for risks and opportunities to the management system
- Current edition
- ISO 22000:2018, confirmed in 2023, with Amendment 1:2024 on climate action. It has not been replaced
- FSSC 22000 position
- Version 7 was published in May 2026 and is ISO 22000:2018 plus a sector prerequisite programme standard from the ISO 22002 series plus the FSSC additional requirements
- The distinction that decides the finding
- Clause 6.1 risk is risk to the management system. Clause 8 hazard is risk to the product
- Most common failure
- The document exists, is dated at implementation, and nothing downstream depends on it
- South African context inputs
- R638 of 2018 and the Certificate of Acceptability, R146 of 2010 labelling, NRCS compulsory specifications, Port Health, utility supply, customer scheme demands
- Where the trail ends
- Food safety objectives, management review inputs and continual improvement
- Templates
- RA22 context, RA23 interested parties and RA24 strategic risks and opportunities, R690 each. ISO 22000:2018 toolkit, 271 documents, R5,900
Three assessments, one afternoon each, R690 a pack
If your last report carried a finding against clause 4 or clause 6.1, these are the three documents that answer it. Each pack holds a register, a procedure, a completion guide and a read me, in editable Word and Excel, so you score your own site rather than adopting somebody else’s answers.
Browse the risk assessment range, R690 each Ask ASC to build the context assessment with you
In this guide
- Which three risk assessments does clause 4 actually ask for?
- Why does an auditor write a non-conformance against context of the organisation?
- How is a risk to the management system different from a product hazard?
- How do you do a context analysis for a South African food business?
- What did Amendment 1:2024 add about climate change?
- How do you build an interested party register that is useful rather than decorative?
- Which interested party requirements become obligations you have to meet?
- How do you assess risks and opportunities to the food safety management system?
- Worked example: how does one context issue travel through a KwaZulu-Natal dairy?
- How do context and risk turn into food safety objectives?
- What does management review have to do with clause 4?
- What does the auditor ask for on the day?
- Frequently asked questions
Which three risk assessments does clause 4 actually ask for?
ISO 22000:2018 asks for two determinations at clause 4: the external and internal issues relevant to the food safety management system, and the requirements of the interested parties relevant to it. Clause 6.1 then asks the organisation to consider both and to plan actions addressing the risks and opportunities that arise. Three pieces of work, usually delivered as three documents.
Sites that certify to FSSC 22000 meet the same demand, because FSSC 22000 Version 7, published in May 2026, is ISO 22000:2018 plus a sector prerequisite programme standard from the ISO 22002 series plus the FSSC additional requirements. The ISO 22000 half carries clause 4 unchanged. There is no route to an FSSC certificate that avoids this work, and there is no version of it that a hazard analysis can perform on your behalf.
The last of those four is the part that gets missed. The three documents form the front end of a chain that ends at management review and continual improvement, and every link in the chain is separately auditable.
Neighbours, waste and pests are context issues for the clause 4.1 context review
ASC Pest Control is part of the ASC Food Safety Consultants group, owned and designed by food safety specialists, a SAPCA member with pest control operators registered under Act 36 of 1947, and built around what a BRCGS, FSSC 22000 or R638 audit or inspection actually asks for. Service reports, barcoded device monitoring and trend analysis live in the My ASC Pest Control Hub, so the pest file is audit ready before anyone asks for it. ASC Pest Control serves Gauteng and the Eastern Cape.
Food and beverage pest control by ASC Request a pest control site assessmentWhy does an auditor write a non-conformance against context of the organisation?
Because the document exists and nothing depends on it. ISO 22000:2018 requires clause 4 issues to be monitored and reviewed, and a context analysis dated at implementation, never reviewed, listing issues with no stated effect on the food safety management system, cannot be shown to have been monitored or to have fed the scope, the objectives or the management review. The auditor tests the connections rather than the file.
I audit and I implement, and the pattern is the same from both chairs. Clause 4 documents are usually written once, by the consultant or the technical manager, at three in the morning before a stage one audit. They are then filed. Three years later the plant has a new line, a new retail customer, a new owner and a new technical manager, and the context document still describes the business that existed at implementation. Nothing in it is untrue. Nothing in it is current either.
- Issues are listed with no stated consequence for the food safety management system, so the auditor cannot see why they were included
- There is no record of monitoring or review, only a creation date, so the ongoing requirement is unevidenced
- The scope statement was written independently of the context, and the two do not agree about what the site does
- The interested party register lists parties but not what each one requires
- The risks and opportunities register is the hazard analysis with different column headings
- Actions were assigned but their effectiveness was never evaluated, so the loop is open
- Food safety objectives bear no visible relationship to any issue or requirement the site determined
- Management review minutes have no agenda item for changes in external and internal issues
Paraphrased in my own words, not quoted from any standard, the wordings I see most are these. The organisation could not demonstrate that external and internal issues relevant to the food safety management system had been monitored and reviewed. The interested party register did not identify the relevant requirements of the parties listed. Actions to address risks and opportunities were documented, but the organisation could not demonstrate that their effectiveness had been evaluated. Food safety objectives were not consistent with the issues and requirements the organisation had determined. Management review records did not address changes in external and internal issues.
These are minor findings on a good day. On a bad day the certification body treats them together as a systemic breakdown and raises a major, because a system whose planning inputs are stale and whose improvement loop is open is not a functioning management system, whatever the production records look like. Our summary of the 25 most common FSSC 22000 non-conformances places clause 4 findings alongside the operational ones for exactly that reason.
If the finding was written against risks and opportunities
This is the pack for the site whose risk register turned out to be the hazard analysis in different clothing. It gives you a scored register at the level of the management system, with owners, actions, effectiveness evaluation and review triggers built in, plus the procedure that explains the method to your internal auditor.
Buy the Strategic Risks and Opportunities Risk Assessment, R690 Request a quote for a clause 4 gap review
How is a risk to the management system different from a product hazard?
The hazard analysis asks what can make the product unsafe at a process step. The clause 4 and clause 6.1 work asks what can stop the management system itself from working. A technical manager resigning never appears in a hazard analysis, yet it is a serious risk to a system that depends on one person to run verification, and ISO 22000 puts it in a different place, assessed by a different method.
ISO 22000:2018 uses the word risk at two levels, and that is the root of the confusion. At the organisational level, clause 6.1 deals with risks and opportunities arising from the context and the interested party requirements. At the operational level, clause 8 deals with hazards through the hazard analysis, which classifies control measures as prerequisite programmes, operational prerequisite programmes or critical control points. Same word, two jobs. Our article on risk assessment against hazard analysis works the operational half of that split in detail.
| Feature | Risk to the management system (clause 6.1) | Product hazard (clause 8 hazard analysis) |
|---|---|---|
| Question it answers | What could stop the system delivering safe food, legal compliance and our objectives | What could make this product unsafe at this step, and what controls it |
| Unit of analysis | The organisation, the system, the process of managing food safety | The process step on a verified flow diagram |
| Inputs | Context issues, interested party requirements, scope, audit and verification results, incidents, planned changes | Product descriptions, intended use, flow diagrams, hazard data, prerequisite programme conditions |
| Typical entries | Loss of a single competent verifier, a customer moving to a scheme you do not hold, supply interruption, an unretrievable records system, a regulation coming into force | Salmonella surviving a thermal step, metal from a fatigued sieve wire, undeclared milk from shared equipment |
| How it is judged | Effect on the intended results of the system, likelihood, current controls, residual exposure | Likelihood of occurrence and severity of the adverse health effect |
| Output | Actions integrated into the system, resources, owners, deadlines, often an objective | Significant hazards and control measures classified as PRP, operational PRP or CCP |
| Recorded in | The risks and opportunities register, referenced from the context and interested party documents | The HACCP study and the hazard control plan |
| Reviewed when | Context changes, an interested party requirement changes, an action closes, at management review | New product, new process, new equipment, new hazard information |
| Escapes if wrong | The system decays quietly and the audit finds it | Unsafe product reaches a consumer |
A hazard analysis protects the consumer from your product. A clause 6.1 risk assessment protects your system from your organisation.
How do you do a context analysis for a South African food business?
ISO 22000:2018 clause 4 asks for external and internal issues, so work through them in categories and apply one test to each: state the effect on the ability of the food safety management system to achieve its intended results. An issue with no stated effect is a note about the business, not a context issue. In South Africa the external half is heavily regulatory and heavily infrastructural, and both change often enough to need scheduled monitoring.
Start with the external categories. Regulatory sits first because it is the one with dates attached. Regulation 3(1) of R638 of 2018 prohibits handling food on premises without a valid Certificate of Acceptability issued by the local authority, which makes the municipal environmental health department an external issue and an interested party at the same time. R146 of 2010 governs labelling. The NRCS administers compulsory specifications for products such as canned fish under VC 8014 and processed meat products under VC 9100. Port Health inspects imported foodstuffs at points of entry and can detain a consignment. The Department of Agriculture, which separated from DALRRD on 1 April 2025 by Proclamation 199 of 2024, administers the Agricultural Product Standards Act 119 of 1990. Draft R3337, published for comment on 21 April 2023, is still a draft with no gazetted commencement date, which makes it a watch item rather than an obligation.
- Regulatory and enforcement: local authority and the Certificate of Acceptability, R146 labelling, NRCS compulsory specifications, Legal Metrology Act 9 of 2014 and SANS 289:2022 net quantity, Port Health, the Department of Agriculture, section 61 of the Consumer Protection Act 68 of 2008
- Customer and scheme: which retail groups you supply, which scheme each requires, whether any customer is moving between BRCGS, FSSC 22000 and IFS, and any customer specific technical standard layered on top
- Infrastructure and utilities: electricity supply interruptions and their effect on cold chain and cleaning, municipal water reliability and quality, borehole or stored water use, effluent capacity, road and port lead times
- Supply chain: single sourced ingredients, imported material lead times, exchange rate exposure on inputs, the certification status of your own suppliers
- People and competence: availability of qualified food technologists in your province, turnover in the technical team, shift patterns, dependence on one person for verification or internal audit
- Internal: plant age and hygienic design limits, capacity against demand, product portfolio changes, the state of your records and traceability system, ownership and capital availability, food safety culture maturity
Then score. For each issue record the direction, whether it threatens the system or offers it an opportunity, the current state, the effect on the intended results, who monitors it, how they monitor it and when it is next reviewed. That final column is the one auditors read first, because the requirement to monitor and review information about these issues is separate from the requirement to determine them.
Stop rewriting the context analysis from a blank page
The Context of the Organisation pack gives you the category structure, the scoring method and the monitoring and review columns already built, with a completion guide that walks a technical manager through populating it for a single site or a group. Register, procedure, completion guide and read me, in editable Word and Excel.
Buy the Context of the Organisation Risk Assessment, R690 Have ASC facilitate the context workshop
What did Amendment 1:2024 add about climate change?
ISO 22000:2018 remains the current edition, confirmed in 2023, and Amendment 1:2024 added climate action into the context and interested party clauses. Paraphrased: you must consider whether climate change is a relevant issue when determining your context, and recognise that relevant interested parties can have climate related requirements. It does not require a carbon programme and it does not replace the standard.
For a South African manufacturer this is a short piece of work with a real answer. Water availability and quality, temperature extremes affecting cold chain and storage conditions, agricultural raw material availability and seasonality, and the resilience of your utilities are all climate linked and all already sit in the context categories above. The amendment asks you to make the consideration visible rather than to invent a new programme. A site that records the consideration, states which climate linked issues are relevant and which are not, and dates it, has met the requirement.
Add a climate column or a climate section to the context register. For each relevant issue, state the climate link and the effect on the food safety management system. Where climate change is not a relevant issue for a particular category, record that conclusion and the date it was reached. A determination that something is not relevant is still a determination, and it is auditable. What is not auditable is silence.
How do you build an interested party register that is useful rather than decorative?
ISO 22000:2018 clause 4 needs each party named specifically rather than by category, with what that party actually requires of you, whether you have adopted the requirement as an obligation, the evidence that you meet it, the person who owns the relationship, how you learn when the requirement changes, and a review date. A register that stops at the party names is a contact list with a clause number on it.
The decorative version is easy to spot. It has fifteen rows reading customers, suppliers, employees, regulators, shareholders, the community, the certification body, and a second column reading safe food, on all fifteen rows. Nothing in the system changes if that document is deleted. The useful version is longer, more specific and immediately obviously connected to work the site already does.
| Interested party (named) | What they require of us | Adopted as an obligation? | Evidence we meet it | How we learn of changes |
|---|---|---|---|---|
| Local authority environmental health department | Valid Certificate of Acceptability for the premises under regulation 3(1) of R638 of 2018, and compliance on inspection | Yes, statutory | Current certificate on file, inspection reports, closure of any listed items | Inspection visits, direct contact with the assigned practitioner, quarterly check |
| Named national retail customer | Certification to a GFSI recognised scheme, their own technical standard, agreed specifications, defined complaint response times | Yes, contractual | Certificate, customer audit reports, signed specifications, complaint log with response times | Customer technical bulletins, annual standard revision, account manager |
| Certification body | Compliance with the scheme, timely closure of findings, notification of significant changes and incidents | Yes, contractual | Audit reports, corrective action evidence, notification records | Scheme owner communications, certification body circulars |
| NRCS, where a compulsory specification applies | Compliance with the applicable compulsory specification, for example VC 8014 for canned fish | Yes, statutory | Product conformity records, test results, sales permit position | Government Gazette monitoring, industry association |
| Employees and their representatives | Safe working conditions, competence training, clear instructions, a route to raise a food safety concern | Yes | Training records, induction records, the reporting route and its use | Committee meetings, culture survey, exit interviews |
| Ingredient supplier, single sourced | Forecast accuracy, agreed specifications, payment terms, notification of our process changes | Partly, commercially | Supplier agreement, specification acknowledgements, change notifications sent | Supplier review meetings, approval renewal cycle |
| Surrounding community and neighbours | Control of odour, effluent, noise, vermin harbourage and waste from the site | Yes, where it affects food safety and licence to operate | Waste contractor records, pest trend data, complaint register | Complaint register, municipal contact |
Two design rules make the difference. First, only include parties relevant to the food safety management system. A pension fund administrator is an interested party of the business and not of the system. Second, every requirement in column two should be traceable to something in your system: a specification, a procedure, a monitoring activity, a customer agreement, an objective. If a requirement leads nowhere, either it is not really a requirement or you have found a gap, and both are useful answers.
The register that converts stakeholders into obligations
The Interested Parties pack is built around the columns above, with the adoption decision recorded explicitly so an auditor can see which requirements you took on and which you considered and declined. It comes with the procedure that explains how parties are identified and how the register is maintained between reviews.
Buy the Interested Parties Risk Assessment, R690 Talk to ASC about interested parties and clause 4
Which interested party requirements become obligations you have to meet?
Statutory and regulatory requirements, R638 of 2018 among them, are obligations whether you like them or not. Contractual requirements become obligations when you sign. Everything else is a decision: you consider the requirement, you decide whether to adopt it, and you record the decision. That recorded decision is what separates a register that governs the system from a register that describes the world.
The distinction matters at audit because an auditor will select a row and follow it. If a named retail customer requires a five year record retention period and your procedure says three years, one of two things is true: you did not adopt the requirement and did not say so, or you adopted it and did not implement it. The first is a documentation gap. The second is a breach of a customer agreement, which is a larger conversation.
Sites with export customers carry the heaviest version of this. An importing country requirement, a customer specific standard, a private label technical manual and the certification scheme can all apply to one production line, and they do not always agree. Recording the most onerous requirement as the one adopted, and saying so, is a defensible position. Leaving the conflict undocumented is not. Our guide to South African food legislation is the reference we point clients to when they are building the statutory half of this register.
Clause 4 is where an ISO 22000 audit starts, and where most files are thinnest
If clause 4 is thin, the rest of the system is usually thin in the same places. The ISO 22000:2018 toolkit is 271 documents, policies, procedures, work instructions, forms and the risk assessments that support them, indexed and cross referenced in editable Word and Excel, and it includes one hour of premium consultation with one of our consultants.
Buy the ISO 22000:2018 Document Templates Toolkit, R5,900 Request a scoped implementation quote
How do you assess risks and opportunities to the food safety management system?
Clause 6.1 takes the context issues and the adopted interested party requirements as inputs, adds audit results, verification results, incident history and planned changes, then asks one question of each: what could stop the food safety management system achieving its intended results. Score it, decide an action, name an owner and a date, integrate the action into a system process, and evaluate whether it worked.
- Set the inputs explicitlyList the sources feeding the register: the context analysis by document number, the interested party register, the last internal and external audit reports, verification and validation results, complaints and incidents, and any change planned in the next twelve months. An auditor should be able to see where each risk came from.
- Write the risk at system levelNot microbiological contamination of product. Instead: verification of the environmental monitoring programme depends on one qualified person, whose absence would leave results unreviewed for weeks. That is a risk to the system, and it has an action.
- Score consistently with your other registersUse the same likelihood and consequence scale you use elsewhere so the numbers mean the same thing. Define what each consequence level means for the system: a delayed decision, a lapsed certificate, an unretrievable record, a customer delisting.
- Choose a response and say which oneAvoid, reduce, share, accept, or pursue as an opportunity. Acceptance is a legitimate answer when it is a recorded decision with a named accepter, and an illegitimate one when it is silence.
- Integrate the action into a process, not a spreadsheetIf the action is to train and authorise a second verifier, it belongs in the training matrix and the authorisation list, not only in the risk register. The register tracks it. The system carries it.
- Evaluate effectiveness and close the loopSix months later, did the risk reduce. Evidence, not opinion: the second verifier reviewed results during the first verifier’s leave, and the review turnaround stayed inside the target. This step is the one most often missing at audit.
Opportunities deserve real entries rather than a column of blanks. Adopting the restructured prerequisite programme standards is one: the ISO 22002 series was restructured in July 2025, with ISO 22002-100:2025 published on 29 July 2025 as a common baseline and ISO 22002-1:2025 covering food manufacturing, while ISO/TS 22002-3:2011 for farming remained a Technical Specification after review in 2025. Others are ordinary and valuable: digitising a paper check that is chronically late, consolidating two suppliers into one with better controls, moving a cleaning task off the end of a shift where it is always rushed.
Your internal auditors are the ones who have to test this
Clause 4 findings are found internally or they are found by the certification body, and the second route is more expensive. Internal and Supplier Auditing Practices at R3,500 teaches an auditor to follow the thread from a context issue to an objective and back. Self paced online, lifetime access, QR verifiable certificate, and ASC does not charge VAT on training, so the price shown is the price paid.
Enrol in Internal and Supplier Auditing Practices, R3,500 Ask about team enrolments
Worked example: how does one context issue travel through a KwaZulu-Natal dairy?
Take a 180 person dairy processor in KwaZulu-Natal producing UHT milk and set yoghurt, supplying two national retail groups and exporting into Botswana and Namibia, and work it through ISO 22000:2018 clause 4 and clause 6.1. This is an illustrative example built to show the structure, not a client, and the figures are illustrative. One external context issue is followed from determination through to continual improvement.
| Stage | What is recorded | Which document holds it |
|---|---|---|
| Context issue | External, infrastructure. Municipal water supply is interrupted without notice, sometimes for a full shift. The site holds stored water and a borehole to bridge the gap. Effect on the system: cleaning and CIP verification assumes potable mains water, and that assumption is not always true | Context of the organisation register, external issues, infrastructure category |
| Interested parties touched | Local authority environmental health, which issues the Certificate of Acceptability under regulation 3(1) of R638 of 2018. The two retail customers, whose standards require water used in cleaning to be potable. The certification body | Interested party register, with the potable water requirement recorded as adopted and statutory |
| Risk to the system | CIP cycles may run on stored or borehole water tested less frequently than mains, so the cleaning verification result may not be valid for those cycles, and the site cannot currently tell from its records which cycles those were | Risks and opportunities register, scored high on consequence, medium on likelihood |
| Response chosen | Reduce. Three actions: log every switch to alternative water with time and duration; test stored and borehole water on a defined schedule and before return to production; hold product from any CIP cycle run on untested alternative water pending a cleaning verification result | Risks and opportunities register, with owners and dates, and the actions written into the CIP procedure and the water monitoring schedule |
| Opportunity recorded | Install continuous residual chlorine monitoring on the stored water line, removing the hold rule and reducing testing cost. Capital request raised for the next financial year | Risks and opportunities register, opportunity entry, with the capital request referenced |
| Objective set | Every CIP cycle in the year runs on water with a valid potability result covering that cycle, monitored monthly by the QA manager, reported to management review quarterly | Food safety objectives register, traced to the context issue by document number |
| Monitoring result | Quarter one: nine alternative water events, two CIP cycles held, both released after satisfactory verification. Quarter two: six events, no holds, one late water test found in internal audit | Objective monitoring record, internal audit report |
| Management review | Changes in external and internal issues: the interruption pattern worsened in quarter one and eased in quarter two. Effectiveness of the action: the hold rule worked, the testing schedule slipped once. Decision: approve the chlorine monitoring capital request | Management review minutes, agenda item on external and internal issues |
| Continual improvement | Continuous monitoring installed. The hold rule is replaced by an in line alarm. The objective is retired and replaced with an alarm response time target. The context issue stays on the register with its state updated | Updated context register, updated risks and opportunities register, updated objectives |
Read down the right hand column. Six documents, one thread, and any auditor who picks up any one of them can walk to the other five. That is what a clause 4 system looks like when it is working, and it is also why the three assessments are worth doing properly rather than quickly. The same site could have written a context analysis saying that water supply in South Africa is unreliable, and it would have been true, and it would have produced nothing.
How do context and risk turn into food safety objectives?
Food safety objectives under ISO 22000:2018 must be consistent with the policy, measurable, take account of applicable food safety requirements including customer and statutory requirements, be monitored, verified and communicated, and be maintained and updated. The practical test an auditor applies is simpler: can you show which context issue or interested party requirement produced each objective.
Objectives fail for two reasons. The first is that they measure an outcome the site does not control day to day. Zero recalls is a hope. Zero customer complaints is a hope with a phone number attached. Neither tells anyone what to do on a Tuesday. The second is that they are recycled year on year with the target moved by a percentage point, which produces the honest but damaging answer at audit that nobody remembers why the objective exists.
- Each objective names the context issue or interested party requirement it comes from, by document reference
- Each has a plan attached: what will be done, what resources are required, who is responsible, when it is due, how the result will be evaluated
- Leading indicators sit alongside lagging ones, so the objective can be managed rather than only reported
- Objectives are communicated to the people whose work moves them, in language they use
- An objective that is achieved is retired and replaced rather than carried forward with a new number
- An objective that is missed produces an analysis of why, not a restated target
Objectives move when the culture moves
Most clause 4 objectives depend on people reporting, escalating and recording honestly, which is a culture question before it is a system question. Food Safety and Quality Culture is R1,195, self paced online with lifetime access, and no VAT is charged on training. Our article on implementing food safety culture covers the plan side.
Enrol in Food Safety and Quality Culture, R1,195 Ask about a culture programme for your site
What does management review have to do with clause 4?
Management review is where the clause 4 loop closes. ISO 22000:2018 lists changes in external and internal issues relevant to the food safety management system among the review inputs, alongside system performance, verification results, resource adequacy, emergency situations and the status of actions from previous reviews. If the context register was never reviewed, the review cannot evidence that input.
The fix is a change to the agenda, not a new document. Put an item on the standing agenda called changes in external and internal issues and interested party requirements. Take the context register and the interested party register into the meeting. For each, state what changed since the last review, what it means for the system, and what will be done. Where nothing changed, minute that the registers were reviewed, that no change was identified, and the date. A negative finding recorded is evidence. A gap in the minutes is a finding.
One: the context register and interested party register were reviewed on this date, and these issues changed. Two: the actions from the risks and opportunities register due in this period were assessed for effectiveness, with these conclusions. Three: these objectives were reviewed against their monitoring results, and these were retired, revised or added. Three paragraphs in the minutes close the loop that most clause 4 findings are written against.
Outputs matter as much as inputs. Decisions on improvement, resource needs, revision of the policy and objectives, and changes to the system all come out of the review, and each one should be traceable back to something that went in. A review that produces no decisions has not reviewed anything, and an auditor reading twelve months of minutes with no decisions in them will start looking for the reason.
Interested parties change. Keep the context review where it can be updated
ASCloud is the ASC paperless compliance platform: digital checklists, HACCP records and traceability supporting FSSC 22000, BRCGS, HACCP and R638 sites. The printing stops, the evidence sits where an auditor can see it, and where ASC manages your food safety system on the weekly option, your consultant approves the checklists and keeps an eye on the site between visits rather than waiting for the next one. Ask us for a walkthrough on your own checklists.
See ASCloud, the ASC paperless system Ask ASC for an ASCloud walkthroughWhat does the auditor ask for on the day?
On the day, clause 4 evidence means the context analysis and the interested party register, the date each was last reviewed and the evidence of that review, the scope statement, the risks and opportunities register, the actions taken and the evidence that their effectiveness was evaluated, the food safety objectives with their monitoring results, and the management review minutes. Then the auditor picks one row and follows it end to end.
- Both registers, with version control, an author, an approval and a review history rather than only a creation date
- A scope statement that matches what the context says the business does, including any outsourced process or co-packed line
- The risks and opportunities register showing the input source for each entry
- Closed actions with effectiveness evidence attached, not just a tick and a date
- Objectives cross referenced to the issues and requirements that produced them
- Management review minutes with the clause 4 inputs visible as their own agenda item
- An internal audit report that actually audited clause 4 rather than skipping to the production floor
- Someone in the room who can explain the reasoning without reading it off the page
Sites take one of two routes to that position. Some build it themselves from templates, which is the cheaper route and works where there is a competent technical person with the time to think. Others have ASC facilitate the context and risk workshop with the leadership team and write it up, which is scoped and quoted as one figure rather than billed by the hour, with consultation available from R480 an hour where only advice is needed. ASC is willing to audit sites it has supplied documents to. If you are still deciding which scheme you are building towards, the training site guide to ISO 22000 clauses, prerequisite programmes and certification and our complete 2026 guide to FSSC 22000 Version 7 in South Africa set out both routes and the transition dates.
Going to FSSC 22000 Version 7 rather than ISO 22000 alone
ISO 22000 alone is not GFSI recognised, so sites supplying the major retail groups usually need FSSC 22000. The Food Manufacturing toolkit is 260+ documents, clause mapped so you can trace a clause to a document and back, in editable Word and Excel, including one hour of premium consultation with one of our consultants.
Buy the FSSC 22000 Food Manufacturing Toolkit, R6,350 Ask which scheme your customers require
Read next from the ASC risk assessment library
Frequently asked questions
What is the difference between clause 4 context and the hazard analysis in ISO 22000?
Does ISO 22000 require a documented context analysis?
What should a food company put in an interested party register?
Are risks and opportunities the same as food safety hazards?
Does Amendment 1:2024 change what I have to do about climate change?
How often should the context analysis and interested party register be reviewed?
What does an auditor ask for when auditing ISO 22000 clause 4?
Can one document cover context, interested parties and risks and opportunities?
What is included in the ASC context, interested parties and strategic risk packs?
Key takeaways
- ISO 22000:2018 clause 4 covers context and interested parties, and clause 6.1 covers risks and opportunities to the management system. FSSC 22000 Version 7, published in May 2026, carries all three because it is built on ISO 22000:2018.
- Clause 6.1 risk is risk to the system. Clause 8 hazard is risk to the product. A risk register full of product hazards has answered the wrong question.
- An interested party register earns its place only when it names each party specifically, states what that party requires, and records whether the requirement was adopted as an obligation.
- Amendment 1:2024 asks you to consider whether climate change is a relevant context issue and to recognise climate related interested party requirements. Recording a considered no is still evidence.
- The findings are written where the thread breaks: no review evidence, no link to the scope or objectives, no effectiveness evaluation, and no clause 4 input in the management review minutes.
- Three packs cover the three assessments at R690 each: Context of the Organisation (RA22), Interested Parties (RA23) and Strategic Risks and Opportunities (RA24), each with a register, a procedure, a completion guide and a read me, and the ISO 22000:2018 Document Templates Toolkit at R5,900 carries the 271 document system they feed.
Take the three packs together, or have us run the workshop
Context of the Organisation, Interested Parties, and Strategic Risks and Opportunities are R690 each, and each carries a register, a procedure, a completion guide and a read me in editable Word and Excel. If you would rather have the thinking facilitated with your leadership team and written up in your own document format, ASC scopes and quotes the project as one figure, with consultation from R480 an hour where only advice is needed. B-BBEE Level 1 with 135% procurement recognition, which matters if your customer scores your supply chain.
Buy the clause 4 risk assessment packs, R690 each Book a clause 4 workshop with ASC
Published by ASC Food Safety, South African food safety and quality consultants. This article is general guidance and not a substitute for certification-specific advice.