Principles 5 and 6: corrective actions and proving the plan works
How to decide in advance what happens when a critical control point fails — fix the process, control the affected product, document it — and build the verification routine that proves your whole plan is being followed and actually holds.
Chef Diego runs a real food plant. If this page didn't get you there, tell us — a person reads every message.
After this lesson you can write the corrective-action procedure for each of your critical control points before you ever need it — what fixes the process, what happens to the product that was running when the limit broke, and who signs off — and build the verification routine that proves, on a schedule, that the plan is being followed and actually holds. Principles 5 and 6 are the two that turn a plan on paper into a plan you can defend when an auditor pulls a record.
When a limit breaks, the plan has to answer
Principle 4 gave every critical control point a monitoring routine, and the whole point of that routine is to catch the moment a reading falls outside its critical limit — a . A routine that catches the breach but has no answer for it is only half a control. Principle 5 is the answer.
That answer is the . FDA's HACCP Principles and Application Guidelines — the method US regulators publish, developed by the National Advisory Committee on Microbiological Criteria for Foods — are blunt about why it exists: an important purpose of corrective actions is to keep food that may be hazardous from reaching consumers. Where a reading crosses a critical limit, a corrective action is required. Not encouraged. Required.
The three jobs of a corrective action
The guidelines break a corrective action into three elements, and every framework you will meet later says the same thing in its own words. A corrective action must (a) find and correct the cause, (b) decide what happens to the non-compliant product, and (c) record what was done.
Fix the process. The first job is to get the CCP back under control, and that means finding the and correcting it, not just restarting the line. For meat and poultry, USDA's Food Safety and Inspection Service is explicit: under 9 CFR 417.3, a corrective action must ensure the cause of the deviation is identified and eliminated, that the CCP will be under control after the action is taken, and that measures to prevent the deviation from recurring are established. A fix that gets the line moving again but leaves the cause in place is not a corrective action; it is a pause.
Control the affected product. The second job is to decide the of everything that was made while the CCP was out of control. The guidelines say to determine the disposition of the non-compliant product and note that experts may be brought in to help. FSIS is harder-edged for meat and poultry: 9 CFR 417.3 requires you to segregate and hold the affected product at least until it has been reviewed, and to ensure that no product that is injurious to health or otherwise adulterated as a result of the deviation enters commerce. FDA's Preventive Controls rule sets the same expectation for the foods it covers: under 21 CFR 117.150, all affected food must be evaluated for safety and kept out of commerce if you cannot ensure it is safe.
A CCP is not a 'preventive control'
HACCP, the method in FDA's guidelines, calls the step a critical control point. FDA's Preventive Controls rule (21 CFR 117) attaches its own corrective-action requirement to a , which is a wider family than CCPs alone. The corrective-action idea is the same across both; the vocabulary is not. Use each framework's word for the framework you are working in, and do not assume a CCP and a preventive control are interchangeable.
Holding the affected product is a discipline your records have to show, and paper makes it easy to let a run advance before anyone has made the call. In Bettr Manager, a production run that carries cooking and cooling CCP logs cannot be marked finished until every batch's log is complete, and a reading outside the limit shows as a red alert on the run — so a run with a missing or breached record cannot quietly move on while its disposition is still open. It does not make the disposition decision for you or place a hold that blocks a sale; that call and its record stay yours, and a disciplined paper quarantine does the same job. The mechanics of pulling a lot out of the sellable pool and releasing it only after review are their own discipline — the lesson on QA holds and release works through how a hold behaves.
Record what was done. The third job is the one that gets skipped under pressure and costs you at the audit: write down the deviation, the cause you found, the disposition you decided, and who did each part. The guidelines require the corrective actions taken to be recorded; 21 CFR 117.150 and 9 CFR 417.3 both require the same. A corrective action that happened but was never written down is, to an auditor, a corrective action that did not happen.
Decide it in advance, not in the heat of the moment
Here is the part first-timers miss. The guidelines say specific corrective actions should be developed in advance for each CCP and written into the plan — at a minimum, what is done when a deviation occurs, who is responsible for doing it, and that a record will be kept. The reason is human: at the moment a limit breaks, on a running line, under a shipping deadline, is the worst possible time to decide what "adulterated" means for your product and whether a batch can be released. People improvise, and improvisation under pressure trends toward minimizing the problem.
A corrective-action procedure written when no batch is on the line names the decision-maker and the steps ahead of time, so the response is the same whether the deviation happens on a calm Tuesday or during a rush. The guidelines are specific that the people assigned to oversee corrective actions should understand the process, the product, and the plan well enough to judge a disposition — this is not a job to hand to whoever happens to be nearest when the alarm sounds.
Why a stalled corrective action fails an audit
A corrective action can be present and still fail an audit — not because it is missing, but because it is half-done. The process gets fixed on the floor and the line restarts, but the rest never lands: no root cause established, no check that the fix actually held, no closed-out record. That gap is exactly what an audit is built to surface.
The SQF Food Safety Code, Edition 9, makes the full loop mandatory. Clause 2.5.3 requires that corrective and preventive actions be determined, implemented, and verified, including identifying the root cause and recording the resolution of the deviation. Under that clause a corrective action is not done when the line restarts; it is done when the cause is found, the fix is shown to hold, and the record is closed. And the standard is strict about timing at its own boundary: when an SQF audit raises a non-conformance, the site has 30 calendar days to submit corrective-action evidence and a root-cause analysis, and a certificate cannot be issued until the auditor verifies and closes them out. Failing to act within the timeframe is a suspension trigger. A corrective action that stalls is one of the few things a standard treats as a failure of the whole system, not just of one batch.
Verification versus validation
Principle 6 asks a different question from monitoring. Monitoring watches one CCP in real time; steps back and asks whether the whole plan is actually being run the way it says and whether it is holding. The guidelines define it as those activities, other than monitoring, that determine the validity of the plan and that the system is operating according to the plan.
It is easy to confuse verification with its close cousin, . The clean split is two questions. Validation asks is the plan capable? — is there scientific evidence that these controls, run as written, actually render the food safe. Verification asks is the plan being followed, and is it working? You did the validation work when you set critical limits in the previous lesson; the guidelines even describe validation as an element of verification, and FDA's Preventive Controls rule lists it as one of the verification activities under 21 CFR 117.155. The rule's own definitions in 21 CFR 117.3 draw the line the same way: validation is evidence that a control is capable of controlling the hazard; verification is the methods, beyond monitoring, that determine whether it is operating as intended.
The practical difference is when you do each. You validate before you rely on the plan, and again when something changes — a new hazard, a process or equipment or ingredient change, or an unexplained system failure. SQF clause 2.5.1 pins this down: critical food safety limits are reviewed at least annually and re-validated when changes occur. Verification, by contrast, runs continuously and on a schedule for as long as the plan is in use.
The verification activities you actually run
Verification is not one thing; it is a short list of activities you schedule. Four of them do most of the work.
1
Review the records
The core of verification is a qualified person reading the monitoring logs and corrective-action records to confirm the plan was followed and every deviation was closed out. FDA's Preventive Controls rule sets a clock on it: under 21 CFR 117.165, a qualified individual reviews monitoring and corrective-action records within 7 working days of their creation, or within a reasonable time with a written justification. SQF clause 2.5.2 adds that a named person must authorize each verified record — verification has a signature, not just a glance.
2
Calibrate the instruments
A monitoring reading is only as honest as the instrument that made it, and a thermometer reading confidently wrong is worse than none. Checking your monitoring and verification instruments for accuracy is itself a verification activity: 21 CFR 117.165 lists calibration of process monitoring and verification instruments, and the HACCP guidelines are equally plain that monitoring equipment must be carefully calibrated. Set an interval for every device, decide who checks it, and keep the calibration record.
3
Test to confirm the CCP is doing its job
Targeted sampling and testing verify that a CCP is actually controlling its hazard — the guidelines' Appendix G lists sampling and testing to verify CCPs, and 21 CFR 117.165 covers product and environmental testing where the hazard warrants it. Note the boundary from the last lesson: testing is verification, not real-time monitoring. Lab results come back long after the product has moved, which is why monitoring uses fast physical and chemical checks and testing sits in the verification schedule instead.
4
Put it on a schedule
None of this is verification if it happens only when someone remembers. Write a verification schedule that names each activity, how often it runs, and who is responsible — the HACCP guidelines carry an example schedule, and SQF clause 2.5.2 requires exactly this: the activities, their frequency, and the person accountable for each.
What passing records set up
Do Principles 5 and 6 well and notice what you now generate: a monitoring log at each CCP, a corrective-action record for every deviation, a calibration record for every instrument, and a verification review that signs off on all of it. That is a plan that controls its hazards and can prove it.
It also leaves you holding a stack of records — and a record only earns its keep if it survives the audit that comes looking for it. Principle 7 is keeping those records so they hold up: contemporaneous, signed, dated, and retrievable. That is the next lesson, and the last principle.