FSSC 22000 management review

FSSC 22000 Management Review: What Needs to Be Covered and How to Document It

The FSSC 22000 management review is a regularly scheduled top management meeting in which the food safety management system performance, risks, and improvements are assessed according to the requirements of the FSSC 22000 Scheme and ISO 22000 standard. The auditors consider such meetings as the proof of the organization’s leadership commitment, and deficiencies in either the scope of the discussion or the records are the most frequent types of nonconformities during certification and surveillance audits. This guide describes what should be discussed at the FSSC 22000 management review and how ISO 22000 management review process contributes to that.

What Is an FSSC 22000 Management Review

The management review of the FSSC 22000 is a scheduled and documented review performed by top management at periodic intervals of time, normally annually, to ensure that the food safety management system is adequate and effective. It is not an operational meeting but a structured review based on specific inputs and outputs as stipulated under Clause 9.3 of ISO 22000 and additional requirements of FSSC 22000.

From the Indian perspective, a proper management review has an added benefit other than ensuring compliance with the requirements of certification. In today’s world, global customers are more inclined towards asking for management review results during supplier evaluation process, which helps in saving time on customer audits and repetition of the information provided earlier.

Top management participation is mandatory. Auditors frequently check the list of attendees of meetings to make sure whether the person who has the authority on resources, policies, and direction is attending the meeting or is he/she being represented by some other member. If the top management delegates the task of chairing the meeting, then there is an expectation from the management review scheme to have proof that the outputs have been formally reviewed and approved by the responsible person.

FSSC 22000 Management Review Requirements

 

FSSC 22000 Management Review Requirements

 

The review requirement for the FSSC 22000 management review requirement is a combination of the general clause for food safety management review under the ISO 22000 standard as well as scheme-specific additions made to the FSSC 22000 Version 6.

Read  more :- fssc 22000 gap analysis

  • Frequency: Review of management shall be carried out periodically, usually at intervals of not less than 12 months, while there should be more reviews when there are significant events, for example, product recalls, product withdrawals, or other regulatory observations.
  • Scope: Management review shall include all parts of the food safety management system like pre-requisite programs, HACCP program outcome, and food safety culture program.
  • Additions to FSSC: There should be reviews of food safety culture performance, food fraud vulnerability assessment outcome, food defense/TACCP outcome, and allergen management performance.
  • Resourcing: There shall be an assurance that there are enough resources and competencies to run the food safety management system.

This is why such FSSC 22000 management review procedures are necessary to ensure that the decisions made are based on facts and not on assumptions; this is precisely what a management review FSSC 22000 auditor will try to prove during the process. In essence, it means that such management review will not be able to prove only that the certification is still valid; it should also include evaluation of trends and risks, as well as performance of the system.

What Should Be Included in an FSSC 22000 Management Review Meeting

A successful food safety management audit meeting goes through a series of pre-defined inputs before generating any relevant output. The following table highlights some of the agenda items to be discussed during an FSSC 22000 and ISO 22000 review meeting.

Review Input What It Should Cover
Status of previous actions Follow-up on action items from the last management review
Internal and external audit results Findings from internal audits, certification audits, and second-party audits
Customer feedback and complaints Trends in complaints, satisfaction data, and customer audit outcomes
Process performance and KPIs Food safety objectives, monitoring data, and trend analysis
Nonconformities and corrective actions Root cause findings and effectiveness of corrective actions
Food safety culture results Survey outcomes, training uptake, and behavioral indicators
Food fraud and food defense Vulnerability assessment and threat assessment updates
Allergen management performance Cross-contact incidents and control verification results
Emergency preparedness Testing of emergency and crisis procedures, including recall simulations
Resource adequacy Staffing, equipment, infrastructure, and competency gaps
Changes in context New regulatory, market, or organizational changes affecting the FSMS
Legal and regulatory compliance Status of applicable food safety legislation and updates

 

How to Conduct an FSSC 22000 Management Review Meeting

Knowing how to carry out the process of an FSSC 22000 management review is mostly about following the consistent process rather than making it something unique.

  • Develop an official agenda: Send out the agenda beforehand and link it directly to the ISO 22000 management review process input documents mentioned above.
  • Collect information prior to the meeting: Collect KPI dashboards, audit summaries, and complaint trends so that decisions are based on facts rather than reactions.
  • Have top management present: Ensure the person responsible for the FSMS is there and not just the quality/food safety manager.
  • Process each input sequentially: Do not leave out anything; auditors verify whether all the necessary inputs have been covered, even if briefly.
  • Record decisions as outputs: Each input must result in a decision, an action, or a decision that “no action needed.”
  • Assign ownership and deadlines: Each output/action item must have an owner and a deadline.
  • Close the loop: Verify past action items are evaluated before adding new action items.

FSSC 22000 Management Review Documentation Requirements and Records

Documentation for FSSC 22000 management review should show that the meeting took place, who attended the meeting, what was discussed during the meeting, and what decisions were taken after the discussion. The auditors usually ask for such documentation in order to have evidence, so lack of such documentation is a common reason for minor nonconformities.

  • Minutes: Dated minutes that detail all topics in the agenda, participants, and the individual leading the review.
  • Input sources: Inputs and evidence of their source, in terms of supporting documents, reports, or dashboards that were used to develop each input.
  • Decisions and outputs: Documented decisions including resource and systems allocations.
  • Action item register: Document that keeps track of action items, with assigned ownership, due dates, and status; ideally, this is an ongoing document between reviews.
  • Evidence of top management approval of the outputs: Proof of senior leadership approval of the output decisions.
  • Retention: The records are to be retained according to the organizational document control policy, typically for one certification cycle.

The purpose of these FSSC 22000 management review documentation and record keeping procedures is to establish an audit trail: any auditor must be able to trace a management decision from its root cause through to the action taken as a result. The facilities that use one ongoing management review document that gets updated after each review meeting will usually have a better record compared to those that take each review separately.

A digital solution to keep the records is worth consideration when there are several facilities or certifications because this approach will simplify gathering the trend information before conducting another management review and prevent any versioning problems between minutes, action tracking form, and the report.

ISO 22000 Management Review Process vs FSSC 22000 Additions

ISO 22000 management review procedure, as described in Clause 9.3, is the basis for all management reviews carried out through FSSC 22000, but there are additional requirements for FSSC 22000 version 6.

 

Aspect ISO 22000 Base Requirement FSSC 22000 Addition
Food safety culture Not explicitly required Mandatory review of culture plan progress and metrics
Food fraud Addressed under vulnerability assessment generally Explicit food fraud vulnerability review at each cycle
Food defense Not specifically mandated TACCP-based threat assessment review required
Allergen management Covered under hazard control Dedicated allergen performance review expected
Environmental monitoring General hazard control reference Specific EMP data review for applicable categories

For those organizations who consider ISO 22000’s management review checklist as the whole checklist, they fail to include these elements, and the omission of these elements is one of the most common gaps identified during scheme audits. The easiest way to prevent these gaps each year would be creating a review checklist where the base clauses from ISO and those extra requirements from FSSC are listed next to each other.

Common Mistakes in FSSC 22000 Management Review Documentation

 

Common Mistakes in FSSC 22000 Management Review Documentation

  • Minutes that outline what topics were covered without mentioning the decision made
  • Evidences showing the presence of top management in the review and its approval of the outputs
  • Lack of connection between the input and the original data for the review
  • Inputs on food safety culture, food frauds, or food defense that are verbalized but unrecorded
  • Tasks without any assigned owner, deadline, or follow-up in the next review cycle

Practical Tips for Passing an FSSC 22000 Management Review Audit

Auditors for certification usually select one or two previous management reviews for their assessment during stage 2 or surveillance audits; hence, one should prepare for this rather than concentrating only on the current meeting.

  • Ensure cross-referencing of documents: Ensure the minutes refer to the actual reports used, including their names and dates, so that the auditor can use the same data set for consistency verification.
  • Update the action tracker continuously: Rather than updating the tracker only during the review session, update it between review sessions because if the tracker is updated once a year, it becomes an obvious nonconformity.
  • Ensure food safety objectives match review outcomes: In case there was no achievement of an objective, ensure the review reflects the discussion on the root cause and the directions given by the management.
  • Perform a dry run of review: Performing a dry run of the review inside the organization helps uncover any missing data sources or lack of ownership prior to the real review.
  • Also document non-decisions: In case the decision from an input is that nothing needs to be done, document that explicitly rather than leaving it out since a blank agenda item looks like an unreviewed input.

Read more :-  what is iso 22000 certification

Key Takeaways

  • A management review of the FSSC 22000 should be conducted by the top management of the organization at least once per year.
  • Management review of FSSC 22000 includes the requirements of ISO 22000 Clause 9.3 along with additional inputs for culture, fraud, defense, and allergens.
  • All inputs mentioned above should lead to an output, a decision, or some kind of action item.
  • The FSSC 22000 documentation should create an auditable path from the data through the decision to closure.
  • One of the most frequent reasons for nonconformity during the audit is omitting specific inputs of FSSC 22000.

ETHICAL COMPLIANCE SERVICES

BRCGS Certificate Expiry Support for Indian Businesses

Avoid certificate expiry, maintain buyer confidence, and restore compliance quickly. Our experts help with audit planning, corrective actions, documentation, and BRCGS recertification support.

📋
Audit Planning
🌍
Buyer Confidence
Expert Compliance

Need Help with BRCGS Certificate Expiry?

Our BRCGS consultants help you manage certificate expiry, recertification audits, corrective actions, compliance documentation, and fast reinstatement to minimize business disruption.

 

FAQs 

How do you conduct an FSSC 22000 management review meeting?

Develop the agenda on all inputs that are to be addressed, collect necessary data, and ensure the presence and approval by top management of the outputs from such a meeting.

What should be included in an FSSC 22000 management review?

Audit outcomes, KPIs, complaints, food safety culture, food fraud and defense, allergen performance, and adequacy of resources.

How do you document a management review for FSSC 22000 certification?

Document minutes which include the date of the meeting, attendees, data inputs referenced, decisions taken, and action items.

What are the FSSC 22000 management review documentation requirements and records?

The minutes, referenced data inputs, outputs, action tracker, and top management approval as per document control procedures.

How often must an FSSC 22000 management review be conducted?

It should occur at least once per year with extra meetings following any major events like recalls or significant regulatory findings.

Who must attend an FSSC 22000 management review meeting?

The meeting must include top management with control over the food safety management system and not just the quality or food safety manager.

How does the ISO 22000 management review process differ from FSSC 22000 requirements?

While ISO 22000 outlines the basic review process in Clause 9.3, FSSC 22000 has added cultural review, food fraud, food defense, and allergen management to the list.

Request Consultation

    Need Help?