What happens in your first audit — and where first-timers fail
How the certification audit actually runs — the records review, the floor walk, how findings are graded, and the handful of gaps that write up most first-timers — so the day is a confirmation, not a scramble.
Chef Diego runs a real food plant. If this page didn't get you there, tell us — a person reads every message.
After this lesson you can walk into your first certification audit knowing how the day
runs — and having already found and closed the handful of gaps that fill up most
first-timers' reports. The audit is more predictable than the dread around it. It asks
two questions, in two parts, and it grades what it finds on a scale you can plan
against.
Two questions, in two parts
Strip the audit down and the auditor is checking two things. First, does your written
system meet the code? Second, does your floor actually run the way the writing says?
The whole visit is those two questions, and the code has a plain shorthand for them:
say what you do, do what you say. A perfect binder that describes a process the floor
abandoned fails just as surely as a floor that runs well with nothing written down.
Those two questions map onto two parts of the audit. The first is a review of your
records — your food-safety plans, your procedures, your training and monitoring
records, your internal audits and corrective actions, and your traceability and
mock-recall exercise. People call this part the desk audit. The second is the floor
walk: the auditor observes the work and the cleaning, follows up on anything the
records left unclear, and confirms the system actually operates across every product
and process in your scope. People call that the facility, or site, audit.
Under , that records review may be done
remotely by agreement, but at least half of the audit's allocated time has to be
on-site, and the certification or re-certification audit runs a minimum of two days.
The exact split and the names differ by scheme — some run the records review as a
separate, earlier stage — so ask your certification body how yours is structured. What
does not change is the pairing: paper against the code, then floor against the paper.
The floor walk covers the whole site, not just your scope
The on-site part takes in the entire site — interior and exterior — and every
operational and cleaning shift, including the pre-operational inspections, regardless
of which products are in your scope of certification. An auditor who arrives for a
day shift can still ask about how the night shift cleans. Plan for the whole
building, not the part you rehearsed.
How the day actually runs
The visit is evidence-gathering, not interrogation. The auditor builds their picture
three ways: reading your documents and records, interviewing the people who do the
work, and watching the operation and the cleaning happen. They are matching what they
read to what they see, and writing down wherever the two diverge.
A few things make the day less mysterious. The auditor expects a real history to read:
SQF recommends at least 90 days of records be available before the site audit, because
a system with a week of records has not been running long enough to prove anything.
And there is no ambush at the end — the auditor is required to report every finding to
you before the audit closes, so you leave the closing meeting knowing exactly what was
written up. The report itself is drafted on site, then goes back to the certification
body for a technical review before it is finalized and made available to you, which the
code requires within ten calendar days of the last day of the audit.
Knowing the day runs this way changes how you prepare. You are not preparing to perform
for a stranger. You are making sure the records are retrievable, the people can speak to
their own work, and the floor matches the binder — because those are the three things
the auditor will actually check.
How findings are graded
Every finding is a , and the grade decides how much it costs
you. SQF Edition 9 uses three grades, and it is worth knowing exactly what separates
them:
A minor non-conformance is a random or infrequent lapse — an incomplete or
loosely implemented requirement that has not broken the system but could if it is
left alone. A vague procedure or a gap in a log usually lands here.
A major non-conformance is a failure of a whole system element: a systemic
breakdown, a serious deviation, or an absence of the evidence that would show you
comply. It signals a real food-safety risk to the products in your scope.
A critical non-conformance is a breakdown of control at a critical control point,
a prerequisite program, or another process step, judged likely to cause a real public
health risk or product contamination — or systemic falsification of food-safety
records.
Those grades feed a score. Under SQF Edition 9 each applicable clause is scored: a minor
adds 1 point, a major adds 5, a critical adds 50, and your site rating is 100 minus that
total. Land at 70 or above — a rating of "Complies" or better — and, once every finding
is closed out, you are certified; below 70 is a fail. There is one shortcut to failing:
a single critical non-conformance at an initial certification audit is an automatic
failure, and you re-apply. So "passing" is really two conditions at once — a rating that
clears the bar, and no finding left open.
Grading is scheme-specific — confirm yours
The 1 / 5 / 50 scoring and the "Complies" threshold above are SQF Edition 9's. Other
recognized schemes grade differently — BRCGS, for instance, issues a letter grade
rather than a plain pass. Before your audit, confirm how your scheme scores and what
rating you need, at the scheme owner's own site, so "passing" means the right thing
for the standard you chose. The
scheme-choice lesson
covers where each scheme's code lives.
The findings first-timers walk into
SQF does not publish a league table of the most common non-conformances, and you should
distrust anyone who quotes you one as a hard statistic. But four failure modes show up
again and again for first-timers, and each one maps to a place the code is strict —
which is exactly why they are worth pre-empting.
1
A weak food-safety plan
The Food Safety Plan is a mandatory element of the code, and it is the document an
auditor probes hardest. A plan that misses a hazard, names a control it cannot
justify, or sets a critical limit with no basis is not a paperwork slip — it is a
failure of a system element, which grades as a major. Build the plan so every hazard
and every control can be defended out loud, because that is the conversation the
audit becomes.
2
Vague procedures the floor cannot follow
A procedure too loose to carry out the same way twice is, by the code's own
definition, an incomplete implementation — a minor waiting to be written up, and one
the auditor confirms simply by walking your SOP against the task. The
lesson on writing SOPs
is the fix: name the what, the how, the how-often, the who, and how each run is
verified.
3
Traceability that cannot be completed on demand
Product Trace is mandatory, and the bar is one step forward to your customer and one
step back to your supplier, with the receipt dates recorded. When an auditor asks you
to trace a lot and the answer is a scramble through paper — or a chain that dead-ends
— that is a system element failing in front of them.
4
Corrective action that arrives late
Findings are expected; a good audit still produces some. What fails a site is not the
finding but the response that never comes, or comes past the clock. That clock is
specific enough to deserve its own section.
Corrective action runs on a clock
Getting findings is normal — even a strong audit records a few. What separates a pass
from a re-application is what you do with them, and how fast.
A is required for every non-conformance the auditor
records. Under SQF Edition 9 the evidence of your corrective actions has to be sent to
the auditor, verified, and closed out within 30 calendar days of the last day of your
site audit — and for every minor and major finding, that evidence has to include a
documented root-cause analysis, not just a photo of the thing fixed. Miss that window,
or fail to satisfy the auditor within it, and the certification body cannot certify you;
you re-apply. The certification decision itself lands no more than 45 calendar days after
the audit.
There is a little give built in. If a finding needs a structural change or a part on a
lead time, the certification body can grant more time — but only when the immediate risk
is controlled in the meantime and the extension is documented. The lesson is to treat
close-out as part of the audit, not a chore that follows it: line up your root-cause
process and your evidence trail before the auditor arrives, so a finding on the last day
does not become a missed deadline four weeks later.
Run the audit before the auditor does
Everything above is easier if the audit is your second look at these gaps, not your
first. The single most useful thing you can do before a certification audit is run one
on yourself.
1
Run a real internal audit against the checklist
The code already requires internal audits, in full and at least annually, against
the SQF checklist or a similar tool — so this is not extra work, it is the work the
standard expects. Run it as if it counted: record objective evidence, grade what you
find, and open a corrective action with a due date for every gap. The
SQF Practitioner lesson
covers who should run it and why the person auditing a function should not be the
person who runs it.
2
Run a full mock recall
A recall test — reviewed, tested, and verified as effective — is expected at least
annually, tracing incoming materials one step back and finished product one step
forward, across different shifts. Do it before your audit, on a real lot, and time
it. If you cannot complete the trace, you have found a major finding on your own
terms instead of the auditor's. The lessons on
why you run a mock recall
and
running one step by step
walk the exercise.
3
Consider a pre-assessment
SQF offers an optional pre-assessment audit — a health check that surfaces gaps
before you engage your certification body for the real thing. It is not required, and
it costs you either time or a fee depending on who runs it, but for a first-timer it
turns unknown risk into a punch list you can work.
A mock recall is only painful when you have to reconstruct the trace — pull paper
receiving logs, match lot numbers by hand, and hope the movement history is complete.
There is one honest place a tool helps here, worth naming plainly: because Bettr Manager
records each lot as it is received, with its supplier lot and expiry, and every movement
after, the forward-and-back trace an auditor asks for is already captured, retrieved
rather than rebuilt. That is the whole of the mention — the discipline of contemporaneous
records is what carries the audit, whatever you keep them in.
The audit is a confirmation, not an event
Put it together and the first audit stops being a cliff. It is two parts — your records,
then your floor — grading findings on a known scale, with a 30-day clock on your
response and a self-run version you can do first. A site that has written its plans to be
defended, matched its SOPs to the floor, and traced a real lot before the auditor asked
walks in to confirm a system that already works, not to find out whether it does.
That is also the bridge to what comes next. Certification is not a one-day performance;
it is proof that your operation runs cleanly enough, day after day, to survive a stranger
reading your records against your floor. Building that daily operating model — lots,
expiry, holds, batch records, and the traceability underneath all of it — is what the
running-production track is about.