First party audits

Internal audits that find what will fail

An internal food safety audit is a first party audit of your own food safety management system against the standard, the law and your customer specifications. ASC plans and conducts it to ISO 19011, writes findings that name the requirement and the evidence, and verifies corrective action. ASC is not a certification body and does not certify management systems.

Auditing is charged hourly and a full programme is quoted on scope once ASC has seen the site. ASC will tell you before the quote if the work is smaller than you think.

Three daysOn site for a BRCGS Food Safety internal audit
Last dayFindings presented to management before the team leaves site
Two weeksFull written report after the closing meeting
SAATCA, Exemplar Global, IRCA registered lead auditorsFoodBev SETA Accredited Provider No. 587/00337/1900Gqeberha, Johannesburg, Cape Town and Durban
Talk to ASC, or start with the documentsWhatsApp ASCRequest a quoteRisk assessment packs
Audited to ISO 19011Findings rest on evidence rather than opinion, written so a certification body auditor could read the report cold and follow it.
Led by a working lead auditorThe person auditing your site is a lead auditor registered with SAATCA, Exemplar Global and IRCA who audits to these standards for a living, so a finding is graded at the severity its consequence justifies.
You are told the truth about the dateWhere a customer deadline is not achievable, ASC says so before the quote rather than after the audit.

An internal food safety audit is a first party audit: your organisation auditing its own food safety management system against the standard you are certified to, the law that applies to your product, and your customer specifications. Your certification body sees you for a few days a year, and your internal audit programme covers everything else.

Most sites have an internal audit file. Far fewer have a programme that would survive being read cold by a third party auditor. The file holds checklists ticked yes down one column, findings written as opinions, and corrective actions closed the day they were raised with no evidence that the fix held.

Auditing to tick a clause is a different activity from auditing to find what will fail. ASC does the second. Every audit is planned in line with ISO 19011, the international guidelines for auditing management systems, and every finding names the requirement, the evidence and the gap between them. Where a broader review of the whole system is needed, ASC runs that through its wider FSMS audit service.

Commercially this is the cheapest audit you will buy. A major nonconformance at a certification audit costs an unplanned corrective action, an evidence submission under time pressure, and in some schemes a return visit. Finding it yourself costs only the time to fix it.

What most internal audit providers actually deliver

Look at what is published for this service, in South Africa and internationally, and the pattern holds. Providers list the standards they cover and promise to find issues before your certification body does, without describing the method, the durations, how a finding is written, or what happens after the report. The common product is a checklist walk, worked through as a question list with the quality manager, ticking the clauses the documents appear to satisfy.

That tests the documentation rather than the operation. A system can pass it in full while running an allergen changeover validated once at commissioning and never rechecked. ASC audits the operation and uses the documents as evidence, not the other way round. Where the record and the line disagree, the auditor stays with it until the reason is established.

The second difference is closure. A finding ASC raises names the clause or legal requirement, the objective evidence, and the statement of nonconformity, in language someone who was not there could act on. It is not closed because a person says it has been fixed, but when the evidence named at the time it was raised is on file and verified, and where the finding was systemic, when the area has been audited again.

Key facts at a glance

An internal food safety audit is a first party audit, meaning it is conducted by or on behalf of the organisation that owns the management system being audited.
ASC Food Safety Consultants plans and conducts internal audits in line with ISO 19011, the international guidelines for auditing management systems.
Internal audit durations on site are two days for ISO 22000:2018, two and a half to three days for FSSC 22000 depending on site size, three days for BRCGS Food Safety, and one day for GLOBALG.A.P. IFA.
A customer or second party audit conducted by ASC runs one day on site.
ASC presents internal audit findings to site management on the last day of the audit and issues the full written report within two weeks of the closing meeting.
ASC Food Safety Consultants is not a certification body, and the decision to certify a food safety management system belongs to an accredited certification body after its own third party audit.
South African food premises are required to hold a certificate of acceptability from the local authority under the general hygiene requirements R638 of 22 June 2018, published in Government Gazette 41730 under the Foodstuffs, Cosmetics and Disinfectants Act 54 of 1972.
ASC is SAATCA registered, a FoodBev SETA Accredited Provider No. 587/00337/1900, with teams in Gqeberha, Johannesburg, Cape Town, Durban and across South Africa.

When a business calls ASC in

  • Your certification or recertification audit is approaching and no part of the system has been tested since the last one.
  • Internal audits are being done, but the same findings keep reappearing, which means corrective actions are treating symptoms rather than causes.
  • You are certified to a standard that expects audits across several separate dates, and your programme has compressed into one week.
  • The only person competent to audit the system is the person who wrote it, so every audit of that area is an audit of the auditor’s own work.
  • A customer has scheduled a second party audit, or a complaint, withdrawal or incident has exposed a control that did not hold.

How ASC does the work

1

The audit programme, not one audit week

An internal audit programme covers the whole management system across the certification cycle, with the frequency of each area set by risk. Allergen control, the critical control points, cleaning validation, traceability and recall are audited more often than areas where a failure is only an inconvenience. Poor performance raises the frequency, and the reasoning behind every interval is recorded.

A site that audits everything once a year in one week has a programme in name only: it produces nothing between audits and cannot respond to a change in the process. BRCGS Food Safety requires the programme to run across a minimum number of separate audit dates through the year, with full scope covered at least annually. ISO 22000:2018 requires audits at planned intervals justified by the importance of the processes and previous results. GLOBALG.A.P. IFA requires a documented self assessment before the certification body inspects. Confirm the applicable version with your certification body.

2

Auditor competence and independence under ISO 19011

ISO 19011 treats competence and impartiality as the conditions that make an audit worth anything. Competence is knowledge of the standard, the process and the product, plus the skill to sample, question and reach a conclusion the evidence supports. Impartiality is freedom from bias and from pressure, in planning, conducting and reporting.

Small technical teams hit a structural problem. The one person who understands the hazard analysis well enough to audit it is usually the person who built it, and good intent does not remove that conflict. Rotating auditors between departments helps, but not where the competence sits in one head. Bringing ASC in puts a lead auditor registered with SAATCA, Exemplar Global and IRCA in the seat, with no ownership of the documents and no reason to soften a finding.

3

How the audit runs on site

The audit opens with a meeting that fixes scope, criteria, areas and sampling approach, and sets the closing meeting time. It then moves between documents and records, direct observation of the operation while it runs, and interviews with the people doing the work. Operators are asked what they do and why, not to recite a procedure, because the gap between those two answers is where the finding usually sits.

Duration follows the standard and the site size. ISO 22000:2018 runs two days on site, FSSC 22000 two and a half to three days by site size, BRCGS Food Safety three days, GLOBALG.A.P. IFA one day, and a customer or second party audit one day. Findings are presented to your management team at a closing meeting on the last day, and the full written report follows within two weeks.

4

The vertical audit trail through a batch

A vertical audit takes one batch and follows it end to end, the fastest way to test whether a system that reads well is operating. The auditor picks a batch with something interesting about it: a rework, a changeover or a complaint.

The trail runs through supplier approval and the certificate of analysis for the incoming material, goods receipt and stock rotation, the batch and recipe record, the monitoring records for every critical control point on that run, the allergen changeover and cleaning verification that preceded it, the foreign body controls and their challenge tests, the calibration status of every instrument that produced a number in the file, the label and its declarations against R146 of 1 March 2010, and the despatch record. It then runs backwards from the finished product code to the raw materials, which is the traceability exercise.

5

What the audit actually finds

Findings repeat across sites, so an auditor can look for them deliberately. Monitoring records are completed in one pen, in one hand, at the end of a shift that had a breakdown in the middle of it. Calibration has lapsed on an instrument still producing release decisions. Corrective actions are signed closed with no verification that the action was effective.

Process flow diagrams no longer match the line, because equipment was added or a rework loop introduced without returning to the hazard analysis. Allergen cleaning was validated once at commissioning and never revalidated after the product range or the changeover sequence changed. Supplier approval files hold expired certificates for suppliers still delivering weekly.

6

Writing a nonconformance that can be closed

A finding has three parts and needs all three. The requirement is the clause, the legal instrument or the site procedure that sets the rule. The evidence is what was seen, in which record and on which line, specific enough that someone who was not there could go and look at it. The statement says how the evidence fails the requirement.

A finding written as an opinion cannot be closed. Metal detector records need improvement names no requirement and no evidence, so there is nothing to fix and no test of whether it was fixed. Written properly it reads: the site procedure requires a challenge test at start up, every two hours and at end of run; on the days sampled, the records for that line show start up and end of run tests only. Each finding is graded, owned and dated, and the closure evidence is named when the finding is raised, not negotiated afterwards.

7

Root cause, verified effectiveness and re audit

Correction and corrective action are different things. Repeating the missed check is a correction. Corrective action is the change that stops it being missed again, and it can only be designed once the cause is established. A missed two hourly test is rarely a careless operator. It is a shift pattern that puts the check in the break, a form with no prompt at that interval, or a procedure never trained to the relief operator.

ASC works the cause with the people who run the process, because they usually know the answer and are rarely asked. Verification that the action was implemented is one step. Verification that it was effective is a separate step, tested after the process has run long enough for the change to prove itself. Where a finding was systemic, the area is audited again rather than signed off from a desk, and the register carries exact status: open, conditionally closed pending named evidence, or closed.

How ASC helps, in practice

These are illustrative composites of the kind of work ASC does. They name no client and report no measured outcome.

The programme that existed only in the last week

A ready meals manufacturer certified to BRCGS Food Safety had a complete internal audit file. Every section had been audited in one week, five weeks before the certification audit, by the technical manager who maintains the system.

ASC rebuilt the programme as a risk based schedule across the certification cycle, spread over separate audit dates, with frequency set by the consequence of a failure in each area, then audited the highest risk areas first.

The site entered its certification audit with a programme that could be shown to be running, and with the areas previously audited only by their own owner audited independently.

The changeover that had been validated once

A bakery ran three allergen changeovers a shift on a line extended with an additional depositor. The cleaning procedure had been validated at commissioning and the report was on file and signed.

ASC ran a vertical audit through one batch following a peanut containing product. The changeover record, the cleaning verification and the flow diagram together showed the diagram omitted the added depositor, and the validation had never covered it.

The hazard analysis was reopened for the changed line, the changeover revalidated in its current configuration, and the flow diagram corrected and reissued under document control.

The auditor who owned the system

A citrus packhouse certified to GLOBALG.A.P. IFA had one person competent to audit the quality management system, and that person had written it. The self assessment was complete, thorough and clean.

ASC conducted the internal audit as an independent auditor with no ownership of the documents, covering the sites within the certification scope against the checklist used at the external inspection, and completed it before that inspection.

The findings raised were ones the site could not see from inside, including a supplier approval file holding certificates that had expired.

What you receive

Deliverable What it contains
Audit programme and schedule A risk based plan covering the whole system across the certification cycle, with each frequency justified in writing and audits spread across separate dates.
Audit plan Scope, criteria, areas, sampling approach, timings and auditees, issued before the audit so the right people and records are available.
Nonconformance register Every finding with its requirement, objective evidence, statement of nonconformity, grade, owner, due date and named closure evidence.
Written audit report Issued within two weeks of the closing meeting, covering scope, method, sampling, findings and the auditor’s conclusion on system performance.
Root cause and corrective action guidance Working sessions with the process owners to establish cause, and actions written with an owner, a date and the evidence of effectiveness.
Follow up verification A return visit or documented review of closure evidence, with systemic findings audited again rather than signed off from a desk.

The rest of the ASC audit programme

Internal auditing is one part of it. These are the services sites most often combine with it.

Who this work suits

ASC audits across the South African food chain: citrus and deciduous fruit packhouses in the Eastern and Western Cape, poultry and red meat abattoirs, dairy, bakery, ready meals, fish and seafood processing along the coast, beverage production, spice and dry goods blending, and the packaging and ingredient suppliers who audit into all of them.

Teams work from Gqeberha, formerly Port Elizabeth, in Nelson Mandela Bay in the Eastern Cape, with consultants in Johannesburg and Cape Town and on site teams in Durban and across South Africa, so an audit is scheduled around your production plan, not around travel. ASC audits are led by lead auditors registered with SAATCA, Exemplar Global and IRCA. ASC Food Safety Consultants is SAATCA registered, a FoodBev SETA Accredited Provider No. 587/00337/1900, and ASC Consultants SA is also a member of the Sustainability Initiative of South Africa, membership number 20240910 112270.

Where ASC stops

ASC is not a certification body and never certifies a management system. An internal audit conducted by ASC is a first party audit performed on your behalf and carries no certification status. The certification decision belongs to an accredited certification body after its own third party audit, and nothing ASC does can influence, shorten or substitute for that audit.

ASC also does not close its own findings. Closure belongs to your management system, on your evidence, and ASC verifies it. Where ASC has implemented part of your system, the internal audit of that part is scoped so that no ASC auditor audits ASC’s own work, agreed with you in writing before the audit is planned.

Frequently asked questions

Can ASC conduct our internal audits for us, or must our own staff do them?

An internal audit is conducted by or on behalf of your organisation, so an auditor working for you keeps it first party, provided the audit is planned and reported through your management system and the findings are owned and closed by you.

How often should we audit, and does everything need auditing every year?

Frequency is set by risk rather than habit. Every part of the system should be covered within the certification cycle, most schemes expect full scope coverage at least annually, and weak areas more often. Some standards also require audits across several separate dates rather than one block.

How long does an internal audit take, and when do we get the report?

Two days on site for ISO 22000:2018, two and a half to three days for FSSC 22000 by site size, three days for BRCGS Food Safety, one day for GLOBALG.A.P. IFA, and one day for a customer or second party audit. Findings go to management on the last day and the report follows within two weeks.

Our quality manager wrote the system and is the only person who can audit it. What do we do?

That is the most common independence problem in a small team, and rotating auditors between departments only partly solves it. Where the competence sits in one head, the answer is an independent auditor for the areas that person owns.

Why would a finding be rejected as unclear when the issue seemed obvious?

A finding that states an opinion cannot be closed: it names no requirement and no evidence, so there is no test of whether it was fixed. A usable finding names the requirement, the evidence in enough detail that someone else could check it, and how the one fails the other.

Does an internal audit from ASC help us pass certification?

It tests your system before the certification body does and gives you time to fix what it finds properly. It confers no certification status, and ASC has no role in the certification decision, which belongs to your accredited certification body.

Book an internal audit that tests the system, not the file

Tell ASC which standard you are certified to, the size of the site and where you are in the certification cycle, and you will get a scoped audit plan and a programme proposal. Auditing is charged hourly and a full programme is quoted on scope once ASC has seen the site.

Not ready for a quote? Use Where Do I Start, or book a virtual consultation.

News & updates 5 new
4.9/5 what do you need today?