An ISO 22000 internal audit checklist is the difference between finding your own gaps and having an external auditor find them for you. Internal audits under Clause 9.2 are not a paperwork formality — they are your last chance to catch a broken control point, a missing record, or a drifted procedure before it becomes a certification-threatening non-conformity.
Most food safety teams treat internal audits as a once-a-year scramble. The FSMS that passes cleanly every time treats them as a structured, scheduled discipline. Here are the 9 steps that make up a genuinely pass-ready ISO 22000 internal audit.
STEP 1 — BUILD THE ANNUAL AUDIT PROGRAMME FIRST
Every ISO 22000 internal audit checklist starts before the audit itself, with the programme. Clause 9.2.2 requires you to plan, establish, implement, and maintain an audit programme that covers every process in your FSMS at a defined frequency — not just the ones you feel confident about.
High-risk areas (CCPs, allergen control, supplier verification) should be audited more frequently than low-risk administrative processes. Build this into a 12-month calendar and assign an owner to each audit slot.
STEP 2 — SELECT AUDITORS WHO ARE INDEPENDENT OF WHAT THEY AUDIT
A production supervisor cannot audit their own production line. Clause 9.2.2 requires auditors to be objective and impartial — meaning independent of the area under review. In smaller teams, this often means cross-training two or three people to audit each other’s departments, or bringing in an external contractor auditor for a rotation.
STEP 3 — PREPARE A WRITTEN AUDIT PLAN AND CHECKLIST
Turning up with a notepad is not an ISO 22000 internal audit checklist — it is a conversation. Before the audit, prepare:
The specific clauses and procedures being audited
The records you expect to see (calibration logs, CCP monitoring sheets, training records)
The people you need to interview
The physical areas you need to walk
STEP 4 — VERIFY OPRPs AND CCPs AGAINST ACTUAL RECORDS
This is where most non-conformities hide. Pull a sample of CCP monitoring records from the last audit period and trace them against the HACCP plan’s critical limits. Check that corrective actions were actually taken — and recorded — whenever a limit was exceeded, not just that the deviation was noted.
STEP 5 — CHECK DOCUMENT CONTROL, NOT JUST CONTENT
An excellent procedure that is three revisions out of date is a finding. Confirm that the version on the shop floor matches the version in your document control system, and that obsolete copies have been removed or clearly marked.
STEP 6 — INTERVIEW STAFF, DO NOT JUST READ PAPERWORK
Ask a line operator to explain what happens if a CCP goes out of limit. If their answer does not match the procedure, you have found a training gap before the certification auditor does. Interviews consistently surface the gap between what is written and what is actually practiced.
STEP 7 — RECORD EVERY FINDING, EVEN MINOR ONES
A finding that never gets written down never gets fixed. Categorise each finding as a non-conformity, an observation, or an opportunity for improvement, and record it immediately — not from memory at the end of the day.
STEP 8 — DRIVE FINDINGS INTO YOUR CAPA PROCESS
Every non-conformity from the internal audit needs a root cause analysis and a corrective action, tracked through to verified closure. See our full CAPA guide for the format auditors expect to see. An internal audit finding that sits open for six months without action is often a bigger red flag to certification bodies than the original finding itself.
STEP 9 — REPORT TO TOP MANAGEMENT AND FEED THE MANAGEMENT REVIEW
Internal audit results are a mandatory input to management review under Clause 9.3. Summarise the audit programme’s completion rate, the number and severity of findings, and open CAPA status. This closes the loop and demonstrates the FSMS is actively managed — not just documented.
WHY THIS MATTERS FOR ISO 22000:2026
The move from ISO 22000:2018 to the 2026 revision does not remove Clause 9.2 — it sharpens the expectation around risk-based auditing and objective evidence. Teams still running internal audits as a checkbox exercise will find this gap surfaces quickly under the revised standard. Our ISO 22000:2018 vs 2026 comparison guide breaks down exactly what else has changed.
GET THE FREE CHECKLIST
We have turned these 9 steps into a printable ISO 22000 internal audit checklist you can hand to your audit team today.
👉 [Download the free ISO 22000 Internal Audit Checklist]
Need something more comprehensive? Our ISO 22000 document pack includes the full internal audit procedure, audit report templates, and a CAPA tracker built specifically for FSMS teams preparing for certification or surveillance audits.