Principle 1: find the hazards that can actually hurt someone
How to run a defensible hazard analysis — walk your verified flow diagram step by step, name every biological, chemical, and physical hazard, and judge which are significant enough that safety depends on controlling them.
Chef Diego runs a real food plant. If this page didn't get you there, tell us — a person reads every message.
After this lesson you can run Principle 1 the way an auditor reads it: walk your verified flow diagram one step at a time, name every biological, chemical, and physical hazard that could enter or survive at each step, and judge which of them are significant enough that safety depends on controlling them. This is the list the rest of the plan is built to protect.
Principle 1 is the ground the rest of the plan stands on
The seven principles begin here because every principle after it is built on this one list. If a hazard never makes it into the analysis, no critical limit is set for it, no monitoring watches it, and no corrective action ever catches it. A hazard you miss here is a hazard nobody controls. That is why an auditor opens your plan to the hazard analysis first, and reads the reasoning before anything else.
A is Principle 1. The National Advisory Committee on Microbiological Criteria for Foods, whose method FDA still publishes as the HACCP Principles and Application Guidelines, states its purpose plainly: to produce a list of hazards significant enough that they are reasonably likely to cause illness or injury if you do not control them.
Two disciplines keep the analysis honest. First, separate safety from quality. A lumpy texture, an off color, a short fill — those are quality defects, and they do not belong in a hazard analysis. A hazard is something that can make a person sick or physically hurt them; keep the two apart, or the analysis drowns in things that threaten no one. Second, write it down no matter how it comes out. Under FDA's Preventive Controls rule the hazard analysis must be written regardless of its outcome — even a conclusion of "nothing here needs a control" has to exist on paper, because the written reasoning is the artifact the auditor examines.
Two stages: list first, then judge
NACMCF splits the work into two stages, and doing them in that order is what keeps you from talking yourself out of a real hazard before you have even seen it.
Stage one is hazard identification — a brainstorm. Walk down your verified flow diagram and, at each step, review the ingredients, the activity, the equipment, how the product is stored and shipped, and who eats it. Write down every biological, chemical, and physical hazard that could reasonably show up. Do not filter yet. The job in stage one is to be exhaustive, not to be right.
Stage two is hazard evaluation — now you judge. A is one that clears the bar on two axes at once:
Severity — how serious the harm is if it happens. NACMCF points at things like how long the illness lasts and whether it leaves lasting damage.
Likely occurrence — how probable it is in your particular product and process, judged from experience, outbreak data, and the technical literature, not from a gut feeling.
A hazard that rates high on both is plainly significant. A hazard that is severe but genuinely rare, or common but trivial, is a judgment call — and that call, written down with the reasoning behind it, is the substance of the analysis. The conclusion matters less than the reasoning that got you there.
The three classes of hazard
Every food safety hazard falls into one of three classes. Naming the class at each step is a discipline: it stops you from examining a step for the hazards you happen to think of and missing a whole category you did not.
Biological — living things that make people sick, and their toxins: bacteria like Salmonella and Listeria monocytogenes, pathogenic E. coli, parasites. For most foods this is where the serious hazards live.
Chemical — anything chemical that does not belong, or is present above a safe level: cleaning-chemical residue, pesticide and drug residues, natural toxins such as mycotoxins in grains, unapproved additives or colors, and — the one operators forget — food allergens. FDA's Preventive Controls rule also files radiological hazards under chemical.
Physical — hard or sharp foreign matter that can cut, choke, or break a tooth: metal, glass, stone, hard plastic, bone.
Those same three categories are the ones FDA's rule requires you to work through in 21 CFR 117.130, and the ones NACMCF's method walks step by step.
Allergens are a chemical hazard, not a footnote
The single most common place a hazard analysis goes soft is allergens. Under the FSMA Preventive Controls rule, food allergens are named outright as a chemical hazard — 21 CFR 117.130 lists them alongside pesticide residue and natural toxins. They are not a labeling afterthought; they are a hazard, and they belong on their own line in the analysis.
An allergen turns into a hazard two ways. One is an allergen that is in the product but not declared on the label. The other is . Both belong in the analysis, marked at the steps where they can actually happen: receiving (an undeclared allergen inside a purchased blend), any shared equipment, rework, and packaging and labeling. Because a trace a lab would barely detect can seriously harm someone with a peanut allergy, severity is high wherever an allergen is present in the plant — which is why allergens almost always come out significant.
"Reasonably likely to occur" — say it in your framework's words
Here naming the framework matters. Three regulators express the same idea in three different phrasings, and using the wrong one in front of an auditor reads as not knowing which rule you are under.
Classic HACCP (NACMCF) and USDA FSIS, which governs meat and poultry, ask which hazards are reasonably likely to occur. FSIS even defines the phrase in 9 CFR 417.2(a): a hazard a prudent establishment would control because it has historically occurred, or because there is a reasonable possibility it will occur in that particular product.
FDA's FSMA Preventive Controls rule words it differently. 21 CFR 117.130 has you identify known or reasonably foreseeable hazards, then evaluate them to decide which are hazards requiring a preventive control. Different phrase, identical discipline — severity and probability decide either way.
The wording matters because it names your obligation. Under FSIS you are finding hazards "reasonably likely to occur"; under FSMA you are finding "hazards requiring a preventive control." What you then call the control you put on one — a critical control point, or a preventive control — is the next lesson's question, and the two are not interchangeable. For now, use the hazard-analysis words that belong to the rule you operate under.
FDA also publishes a reference to check your list against: Appendix 1 to its draft Preventive Controls for Human Food guidance, a set of tables of known or reasonably foreseeable hazards for common foods and processes. It is draft guidance, not a binding rule, and it cannot stand in for your own judgment about your own product — but reading it is a cheap way to catch a hazard you overlooked.
A worked example (hypothetical)
Take a hypothetical hot-filled tomato-and-herb sauce, shelf-stable in a jar. Walk two steps of its flow diagram to see the method run.
At the receiving dried herbs and spices step, the identification and evaluation might land like this:
Hazard
Class
Severity
Reasonably likely?
Significant?
Salmonella on untreated dried spices
Biological
High
Yes
Yes
Undeclared allergen in a purchased blend
Chemical (allergen)
High
Yes
Yes
Stones or metal in bulk dry goods
Physical
Medium
Possible
Yes
At the cook and hot-fill step, the cook is what kills vegetative pathogens like Salmonella, so their survival is a severe, reasonably likely hazard right there — significant, and the place control has to land. What temperature and time actually make it safe is a critical limit, and setting one from validated science is the next course's work, not a number to carry in your head. If the same kettle ran an allergen-containing recipe earlier in the day, cross-contact is a chemical hazard at this step too.
Notice the pattern. The same hazard can appear at more than one step, and a single step can carry hazards from all three classes. That is normal, and it is the point: what you are building is a defensible line of reasoning where every step was examined, every class was considered, and every significant hazard was marked with the reason it is significant.
Whatever scale you use to decide significance — high and low, a numbered matrix, a call your team argues out loud — write the method down and apply the same one to every hazard. GFSI-recognized schemes make this explicit: SQF Edition 9, for one, requires that the method for determining hazard significance be documented and used consistently across every hazard (clause 2.4.3.8). An analysis whose rules quietly change halfway down the flow diagram is exactly the kind of thing an auditor pulls on.
What a significant hazard sets up
At the end you have a written analysis: every step, every class considered, and a marked set of significant hazards, each carrying the reasoning behind it. That written reasoning is the first thing an auditor scrutinizes and the thing the rest of the plan exists to control.
It does not yet tell you where to control each one. A significant hazard might be held in check by a prerequisite program you already run — sanitation, supplier approval, a label-check procedure — or it might need a control point built just for it. Sorting the two apart is Principle 2: deciding which significant hazards need a critical control point and which are already handled elsewhere. That is the next lesson, and the analysis you just built is what makes it answerable.