Next week GFSI will be hosting 200 industry and government professionals to discuss leveraging GFSI in FSMA implementation. The GFSI Expert Briefing takes place on November 15 in Washington, D.C., and will look at the role of GFSI in the marketplace and the domestic and international collaboration necessary to comply with new regulations.
“Science guides industry and policymakers to the same place as we work towards our common objective of ensuring a safe food supply for consumers,” commented Mike Robach, chair of the GFSI Board of Directors in a press release from The Consumer Goods Forum. “Public-private dialogue and collaboration is paramount to achieving this goal.”
Speakers at the event come from a range of international companies, including Cargill, Dole, McDonald’s, Target, Walmart and Wegmans. FDA and other national policymakers and legislators will also be present. Industry briefings take place in the morning and afternoon.
Note: FSMA will include the scheduled compliance inspection as part of the implementation of rules. This will occur in the next several years for many food companies.
With FSMA rules moving to the compliance stage, food companies must prepare appropriately to best respond to the requirements and, correspondingly, to additional inspections. These inspections are in addition to others, including GFSI with its emphasis on unannounced level audits for some schemes. For example, these audits may be required by the code (as with SQF) or as part of customer arrangements per certification contracts.
Learn more about FSMA Inspection Readiness at this year’s Food Safety Consortium in Schaumburg, IL | December 7-8, 2016 | REGISTERWith the growing potential for inspections and audits, a well-planned program and response must be developed, implemented and tested to achieve a most successful outcome. This is an important area to address, especially given the many changes in compliance under FSMA, greater scrutiny under GFSI, and a rapidly changing responsibility for food safety management resources.
For companies experienced with past FDA compliance audits, the new rules and Section 117 cGMPs will require more formalized programs and strong evidence of compliance through internal audits and oversight by Qualified Individuals (QI). The inspectors will look to focus heavily on new requirements and the “letter of the law”. Additionally, organizations under the Preventive Control Rule must have multiple Food Safety Plan QIs, qualified audit resources and competent sanitation management, along with competent plant operators. It is critical to have established roles, planning and testing as part of any inspection readiness program.
Self-Diagnostic Assessment Tool
The following self-diagnostic assessment tool can help organizations better determine their current state of planning when it comes to developing inspection readiness. To complete your own planning assessment, review your progress compared to the questions in Table I.
Table I. Kestrel Management’s self-diagnostic tool can help a company assess its level of inspection readiness and preparedness for FSMA compliance.
Get Compliance-Ready
Companies must have the appropriate plans and resources to comply with FSMA and certifications or face possible violations that can include fines and penalties under FDA enforcement. The questions in Table I will help companies identify areas to consider for Inspection readiness. Kestrel can also help answer questions, provide input on solutions, discuss how to better manage all of your food safety requirements—and change “No” responses into “Yes” responses that promote best practices for FSMA and food safety compliance.
Compliance to FSMA requires companies to meet existing program requirements and new ones being published or face regulatory consequences. A part of FSMA also requires that companies follow established food safety plans, which includes GFSI certification.
With these changes, GFSI-level programs must integrate into an aligned Food Safety Management System (FSMS) and strategy. Key considerations include sustainability, multi-year planning, effective organizational structures and expectations, well-defined roles and expectations, compliance, and business objectives.
The value of GFSI certification depends on how the company uses its organizational resources to maximize return on investment, while meeting the changing FDA requirements. Effective management of a GFSI-certified FSMS can have a significant impact on FDA/FSMA compliance. The risk of not meeting established programs while implementing new FSMA programs must be measured, and attention must be given to addressing FSMA compliance, while maintaining established programs.
Complying with FSMA Food Safety Programs
The implementation of FSMA-compliant programs requires having an established GFSI FSMS and demonstrating conformance with one’s own policies. Programs must be maintained and improved as the FSMA requirements are developed and implemented. Each of the GFSI schemes has been vetted to meet a significant level of FDA/FSMA requirements—a key benefit to these industry programs.
Developing a compliant FSMS with proper alignment of your existing programs to FSMA must be assessed. For example, companies with more than 500 employees must include requirements in their programs for the FSMA Preventive Controls rule, which is set for compliance September 19, 2016. In this regard, registered food facilities must evaluate and implement preventive control provisions and meet the requirements by the approaching deadline. This requires effectively updating current programs, establishing key imperatives including cGMPs (Section 117), identifying a Preventive Control Qualified Individual (PCQI), and implementing a Food Safety Plan.
The following areas are all included under the FSMA requirements:
cGMP, Controls and Preventive Controls. Must be identified, modified, and implemented to further minimize or prevent the occurrence of hazards based on Section 117 requirements.
Food Safety Plan, Hazard Analysis, and HACCP. Companies must identify and evaluate changes in their existing programs to include FSMA Preventive Controls.
Qualified Individual. Must be trained with authority to oversee Preventive Control program aspects, developments and impacts.
Written Programs and Documentation. Up-to-date GFSI-level FSMS provides documented programs, procedures, and records for meeting requirements under FDA/FSMA.
Management & Monitoring. All controls, including under FSMA and existing GFSI-level, must be monitored, validated, and verified for effectiveness.
Management of Corrective Actions. Procedures including traceability response for addressing failures of procedures, GMPs and controls must be under management review and confirmed for prevention of adulterated food from entering commerce.
Recordkeeping. Records must be complete and accurate for all food production and safety activities and kept for two years, including the testing level verification of all programs under FSMA and GFSI-level programs.
Self-Diagnostic Assessment Tool
The following self-diagnostic assessment tool can help organizations better determine their current state of planning when it comes to GFSI-level programs meeting FSMA. To complete your own planning assessment, review your progress compared to the questions in Table I.
Table I. Kestrel Management’s self-diagnostic tool can help a company assess its level of FSMS and GFSI preparedness for FSMA compliance.
Get Compliance-Ready
Companies must have their existing food compliance and GFSI programs in good standing to comply with FSMA or face possible violations, fines and penalties under FDA enforcement. The questions in Table I will help companies identify the areas in which they need to focus attention. Kestrel can also help answer questions, provide input on solutions, discuss how to better manage GFSI certification—and change “No” responses into “Yes” responses that promote best practices for FSMA compliance.
The Global Food Safety Initiative (GFSI) is a global initiative for the continuous improvement of food safety management systems. From a functional standpoint, you might be surprised to learn that one of the most challenging elements of keeping up with GFSI compliance for many food producers is sufficient document control. In fact, data compiled by SQF shows that document control-related issues are one of the most common sources of a non-conformance during GFSI-benchmarked audits. Examples of these non-conformances are associated with documentation of training requirements, business continuity planning, and corrective and preventative actions.
The Global Food Safety Initiative (GFSI) is an industry-driven initiative providing thought leadership and guidance on food safety management systems necessary for safety along the supply chain. This work is accomplished through collaboration between the world’s leading food safety experts from retail, manufacturing and food service companies, as well as international organizations, governments, academia and service providers to the global food industry. They meet together at technical working group and stakeholder meetings, conferences and regional events to share knowledge and promote a harmonized approach to managing food safety across the industry. GFSI is facilitated by The Consumer Goods Forum (CGF), a global, parity-based industry network, driven by its members.
So what exactly are some of the most common causes for document control issues as it relates to non-conformances? Keep an eye out for the following five errors that can affect compliance.
1. Lack of document control altogether
Lack of correct usage of document control in the context of GFSI compliance is a common error. This is an issue that often occurs as a result of document sprawl—specifically as it pertains to duplicate documents and supporting documents. For example, an organization might create internal reference material designed to be cheat sheets or summaries of larger policies. These could include simple charts that list key equipment set-up parameters or charts summarizing abbreviated information from product specification sheets. Many organizations fail to realize that because of the nature of the information in these files, these reference documents must also be included in their document control program to ensure that the information in them is current and universally applied.
2. Document version control
From using outdated forms to referencing outdated employee procedures, lack of proper document version control and enforcement is the most common GFSI compliance-related non-conformance. These issues can arise from operational errors (employees don’t know where to find up-to-date documentation or how to ensure that it is being used) to technical errors (the document control system is unable to properly manage document versioning, or in the case of home-grown document control software systems, they may be unable to do so altogether). To avoid these errors, it’s necessary to establish where controlled versions of documents are located and ensure that they are kept up to date. It’s also important remove obsolete versions of these documents—this is a basic principle of document control, but it’s often an area where errors compound over time. Reinforcing training so employees are made aware of document control best practices and policies is critical to keeping your compliance activities current.
3. Document revision errors
One of the most common activities and most common sources of error within any document control program involves publishing revisions to documents. These errors include:
Updating the contents of a document but forgetting to update information such as the version number
Improper tracking of revision history
Adding new documents to the database rather than revising or updating existing documents
4. Inclusion of documents from external sources
If your food safety management system includes or makes use of external documents, these must be controlled in the same manner in which you control internal documents.
Some examples of external documents that may need to be included in your document control program include:
Sample labels provided by your chemical and pest management suppliers
Raw material specifications provided by your suppliers
Customer expectations manuals provided by your customers
5. Improper identification of approval personnel
A best practice of document control is for the person knowledgeable about the content of a document to be assigned the responsibility of approving updates to it. In many organizations, this is interpreted to mean that all approval responsibilities are assigned to a single person across the organization. This could be the food safety coordinator or the document control administrator, despite the fact that it is not reasonable for a single person to be knowledgeable about all the procedures across the organization.
A better approach to approval responsibilities is to identify individuals who can be responsible for authorizing changes based on function or discipline. By spreading the responsibilities across more people, your document control program is more likely to be current and accurate.
When it comes to food safety compliance and best practices, particularly as they relate to GFSI, it’s often the basic principles that get overlooked once your organizations processes and systems are up and running. Setting up a process for document control and maintaining this process over time is a key to achieving and maintaining compliance. As such, it’s important to revisit your controlled document process and library regularly to ensure things are operating as designed and avoid costly compliance surprises at the same time.
Confusion reigns in many organizations and especially with our food safety and quality professionals, as we debate and attempt to decide how best to address the requirements of FSMA. With the first compliance date of September 2016 drawing near, companies are feeling increased pressure to take action. As many are already accredited to a GFSI-approved food safety scheme such as SQF Level 3, BRC, Primas, IFS or FSSC 22000, often the question is, how does my current system fit into FSMA, and where do I need to make changes? The undercurrent to this question is the implication that changing the system to fit FSMA will cause it to no longer be tailored for the desired GFSI food safety scheme, and that a change could cause issues with those audits (which are crucial for purchasing, marketing and sales).
The Food Safety Consortium will discuss critical industry issues, including FSMA compliance. The event takes place in Schaumburg, IL | December 5–9, 2016 | LEARN MOREAs with so many of our industry challenges, there is no easy and prescriptive answer to these questions. Each organization has to make the decision for their own system based on their individual hazard analysis, risk tolerance and resources. Some over-arching themes begin to emerge, which may be analyzed to assist the decision makers in the creation of a road map to FSMA compliance.
During our FSMA Preventive Control Qualified Individual (PCQI) training courses we are repeatedly asked, “What qualifies as a preventive control? Are our critical control points (CCPs) automatically a preventive control? How about our operational prerequisite programs (OPRPs)—are these PCs also?” While there is no easy answer (yes or no), there are some important things to keep in mind that can help in the decision.
The official answer is that a preventive control should be any point in the process where, with a loss of control, it is reasonably foreseeable that a significant food safety hazard either will occur or has an increased likelihood of occurrence. Remember this is intended to be a single point in the process, not the entire process. For example, the sanitation program may be managed as a prerequisite program; however, there may be a point in the process that requires special sanitation attention and without it, there is a reasonably foreseeable likelihood of a hazard.
Thinking about the concept, a logical conclusion is that a loss of control leads to a significant food safety hazard or, at the very least, increases the likelihood of said hazard. It follows that a loss of control would beget the need for a withdrawal if the product had already left the organization’s control. Therefore, one should only designate a point as a preventive control if the implications of conducting a recall in the event of failure have been analyzed as part of the risk assessment. The organization must be fully prepared to conduct such a recall in the event of failure.
The FSMA Preventive Control regulation (§21CFR117.135 – Preventive Controls) requires a recall program only if there is a preventive control identified in the process. Of course, any food processing organization would be remiss if they did not have an effective recall program defined and tested by regular mock recalls. Waiting for a true recall is no time to find out that your program has issues. Even without a preventive control, what happens if a supplier contacts the processor with an issue that requires a recall?
Through the evolution of compliant and mature food safety management systems, it is common for an organization to initially identify multiple CCPs and then, through data collection and process improvements, slowly reduce the CCPs to control points managed through OPRPs or PRPs over time. So, should an OPRP (Operational Prerequisite Program – ISO 22000:2005 Section 7.5) also be designated preventive control? This is perhaps one of the grayest of gray areas in this arena. A deviation in a preventive control, if the product has left the organization’s control, requires a recall. A recall for a deviation in an OPRP is not absolute, and it is actually handled by the food safety team and management on a case-by-case basis, depending on the risk. In addition, although identified when possible, a critical limit is not required for an OPRP (ISO 22000:2015 Section 7.5). Parameters are required for a preventive control.
There really isn’t one answer that fits every situation, but it is important to remember that the requirements for FSMA Preventive Controls regulation (§21CFR117.135) are designed for those operations that in the past have not had the opportunity to define, implement and maintain a food safety program—one that includes a hazard analysis based on HACCP guidelines (Codex Alimentarius Commission [Annex to CAC/RCP 1-1969, Rev. 3 (2003)]) and/or a GFSI-approved food safety scheme. Personally, we feel that if an organization has evaluated their process in compliance with a GFSI-approved food safety scheme, then any reasonably foreseeable hazards have been identified and addressed through a control point such as a CCP, OPRP or PRP. However, that said, upwards of 90% of recalls are linked to either ineffective or nonexistent PRPs such as allergen mislabeling, which accounted for 53% of all recalls last year. Thus, it is imperative that we evaluate all aspects of our processes with the same scrutiny that we do our microbial pathogen and metal control programs, which are common CCPs in today’s world of food safety.
Risks must be evaluated through an effective risk assessment based on science and facts. We start almost all of our workshops with the great American Society for Quality (ASQ) video: Cost of Poor Quality. This highlights the lack of an effective risk assessment performed on January 28, 1986, related to the launch of the Challenger. Unfortunately, emphasis was not on the fact that the engineers presented about the lack of cold temperature stability of critical O-rings, but rather on the fact that the launch had already been postponed for two days, and there was intense media and political hype surrounding the event. An effective risk assessment must be based on facts and objectivity, not on our feelings about what we want or need the decision to be.
FSMA PCQI training stresses the use of reliable and credible resources such as academia, trade organizations and process authorities. The internet itself can also be a valuable resource. Jon Porter stated in 2004, “HACCP, as we know it, would not exist without the internet.” (If Jon could only see us now.) However, again, we must be sure we are choosing credible information from the internet. We all know that we can usually find any answer we desire on the internet, but is it credible and accurate?
Competent industry sector-experienced consultants may also be good options if the organization ensures their credibility. Sometimes, a set of independent eyes can be just what the doctor ordered. Even in cases where the organization has a fully qualified team that is perfectly capable of managing the food safety program on their own, the right external resource (i.e., consultant) may provide an additional, independent viewpoint to your process. A friendly debate with an external resource can oftentimes open a whole new vista of previously unconsidered possibilities for the team.
The FSMA Preventive Controls regulation (§21CFR117.135) states that “each organization is required to have a PCQI that has successfully completed training in the development and application of risk-based preventive controls at least equivalent to that received under a standardized curriculum recognized as adequate by FDA or be otherwise qualified through job experience to develop and apply a food safety system”. What qualifies an individual to be qualified through job experience is not specifically defined but is judged by the effectiveness of their food safety program. However, if FDA visits the facility and asks for the PCQI and no one has taken an FDA-recognized course—but there is someone that the organization has identified as qualified—this has the potential to start the visit off with a negative focus. We urge each organization to send two food safety associates to an FDA-recognized FSMA PCQI training course regardless of their background (this provides a back-up person in case the primary representative is ill, traveling for business or pleasure, wins the lottery, or otherwise leaves the company, etc.). This provides a strong foundation for the future, as ownership of the system is always crucial to not just surviving an inspection, but excelling—and as food safety professionals that is an idea we can all support.
Food Safety Tech recently sat down with experts from Eurofins to discuss FSSC 22000. According to Kristopher Middleton, technical manager at Eurofins, and Kim Knoll, food safety systems national sales manager at the company, there are still quite a few companies (especially in North America) that are unfamiliar with the ins and outs of the certification scheme. In a Q&A with FST, Middletown and Knoll break down the basics of FSSC 2000, along with explaining some of its benefits.
Kristopher Middleton, technical manager, Eurofins
Food Safety Tech: How is the trend with FSSC 22000 evolving?
Kristopher Middleton: The scheme started in 2009 based on a demand for people wanting to have an ISO-based certification within the GFSI benchmarking process. When the program came out, it trended toward larger companies that already had ISO-based certifications, mainly ISO 22000 and ISO 9001. The FSSC 22000 scheme is the fastest growing GFSI benchmarking scheme currently. It’s not just for large multinational companies; a lot of smaller suppliers are seeking certification to this scheme. The foundation continues to expand its scopes to become a true farm-to-fork certification program.
FST: Is FSSC 22000 also appropriate for a single site or for a company with fewer than 50 employees?
Middleton: The certification doesn’t discriminate based on facility size—nor footprint or number of employees. It’s ideal for any company that has a robust food safety management system and manufacture products that fall within the FSSC 22000 scope of certification. This currently includes manufacturers of perishable animal products (feed and food), perishable vegetable products, products with a long shelf life, biochemical products (i.e., food ingredients, vitamins, biocultures, etc.), manufacturers of food packaging, and primary production of animal products.
The key thing about FSSC 22000 certification is that it is not a terribly prescriptive food safety scheme, when compared to others that are available. You will be successful with FSSC 22000 certification if you are confident and knowledgeable about your own food safety management system, and you have appropriate justification or validation for the method in which your programs have been implemented, as well as validation for the controls of your food safety hazards.
FST: Are there quite a few companies that have not heard of FSSC 22000 or are not aware that it is a GFSI-recognized scheme?
Middleton: Since ISO 22000 was not terribly popular here in North America, it didn’t catch on right away. It was more so overseas that it caught on. However, within the past two years the scheme has become increasingly popular here, especially among companies that have other ISO standards already implemented (i.e. ISO 9001, 14001, 18001,etc), where it relates to occupational health and safety, environmental, and quality. The reason for that is the FSSC can easily intertwine with that entire management system program so that it all works together versus having separate programs in place.
Kim Knoll, food safety systems national manager, Eurofins
Kim Knoll: I’m having a lot of conversations with smaller manufacturers who are brand new to GFSI. Many of them are being asked by their customers to achieve a GFSI benchmarked certification and are in the early stages of researching scheme options. Some of these companies are surprised to learn that FSSC 22000 is a viable option. Like other certification schemes, Eurofins lends support to companies planning to pursue FSSC 22000 through training courses, consulting services, pre-assessments and ultimately certification services. Even though FSSC 22000 is a newer scheme, auditor availability is not an issue.
FST: What are the key differences between FSSC 22000 and the other GFSI schemes?
Middleton: Probably the most apparent difference with FSSC compared to other GFSI benchmark schemes is the fact that your certification lasts for three years, not one year. The reason for that is that it’s not a product-based certification like the others, it is a process-based certification and it uses the accreditation standard of ISO 17021 not ISO 17065. It also uses ISO 22003 for direction to the certification body for the conducting of the audit. That doesn’t mean that sites won’t be audited annually; it just means that once the certificate is granted, it’s good for three years.
Another key difference is that there is no true pass or fail within the audit. It’s a conform or not-conform audit. The decision to certify is based off the findings from the auditor and their recommendations, as well as the decision from a technical review meeting at the certification body. It requires the effective closure of a particular non-conformance or satisfactory plan being submitted for the closure of those non-conformances before the actual certificate can be granted. So that’s a bit different, because you can just submit plans for your non-conformances [instead of] actually showing that everything has been completely resolved. That being said, if a facility isn’t able to hold or get a certificate, if there’s an imminent food safety threat noted during an audit—if there’s an issue, such as a potential recall or contaminated goods, the ability to be granted that certificate is not feasible.
FST: Can you walk us through the auditing and certification process under FSSC 22000?
Middleton: Like any of the standards out there, you can get a pre-assessment, which is not necessarily part of the certification activity. The certification activity starts at a Stage 1 audit within this scheme (also known as a document audit within other schemes). It’s an evaluation of a facility’s food safety management system document to determine if they’re valid. The process does not include an entire evaluation of the implementation of the program, just simply that the programs are adequately designed and meet the requirements that are in place.
Next there’s a Stage 2 audit (sometimes referred to a facility audit) that is conducted no more than six months after the Stage 1 audit. The Stage 1 audit will identify the areas of concern—programs that might not meet exactly what the specifications required within the standard, which would become non-conformances in a Stage 2 audit (also called a facility audit or certification audit).
The Stage 2 audit is the full evaluation of the implementation of the program that was reviewed in the Stage 1 audit. Following completion of the audit, effective closure of non-conformances is required. This closure can either be [related to] major non-conformances, CAPA or root cause analysis. You have to supply evidence that the non-conformance is properly eliminated and will not recur, and this evidence must be supplied to the certification body and the auditor for review.
Any other non-conformances (also known as minor non-conformances) must have corrective action plans. Companies need to state how they plan on resolving the issue. They will be “closed” but left open for the next audit, which has to occur within one calendar year (known as a surveillance audit). The term “surveillance audit” within this standard is different from some of the other standards. Within some of the other standards, a surveillance audit is not a yearly activity—it is done within the year of certification. The surveillance audit within this standard is a yearly audit that is required to meet the requirements of GFSI. It’s also a requirement within [ISO] 17021 and [ISO] 22003 that surveillance audits are conducted. The GFSI requirement changed the surveillance audit within the ISO world because they used to do a sampling audit, which progressed to a full-blown audit. Your whole food safety management system will be evaluated, which is slightly different from ISO 22000 surveillance audits.
After that audit is conducted, you have another surveillance audit in the following calendar year. Within those surveillance audits, if any minor non-conformances or non-conformances from the previous audit are still present, they are upgraded to major non-conformances and [companies] would have to implement a full corrective action plan, root cause analysis, etc. and then determine the solution.
Once the second surveillance audit is conducted, the following year will be your recertification audit, which is simply another facility audit. It’s not a document audit—you don’t have to do Stage 1 audits after that initial one. This recertification audit occurs prior to your certificate expiring.
In the final article in Food Safety Tech’s Q&A series on food safety culture, Lone Jespersen, director of food safety at Maple Leaf Foods, and Brian Bedard, executive director of the GMA Science and Education Foundation sound off on the development of food safety culture this year.
Food Safety Tech: Where are we headed in the food safety culture landscape in 2016?
The GMA Science Forum takes place April 18–21, 2016 in Washington, DC | LEARN MORELone Jespersen: I think we’re going down a path of standardizing or at least agreeing on a set of definitions for food safety culture. Some of this will come out of the GFSI technical working group on food safety culture. That will lead us to better guidelines for what the different components of food safety culture are. That’s going to be strongly science based and collectively agreed upon. I think we’ll see a lot of that work done in 2016.
I think we’re also going to see a greater focus on connecting food safety culture to organizational culture. Many organizations are looking at integrating food safety and quality assessments into their organizational culture assessments and I think for larger organizations this makes sense.
Lone Jespersen of Maple Leaf Foods debates food safety culture at the 2015 Food Safety Consortium.
I hope we’ll get closer to having compared measurement systems and be able to publish work around that so we don’t fall into a trap of a fragmented and independent approach, but rather building on each other as we work [together] and have a common definition.
Brian Bedard: The measurement tools and the gap analysis for which these tools are being developed needs to be done. In terms of operationalizing and actually getting food safety embedded in companies, I would envision a roadmap that looks at a four-tiered framework of who the targets are for changing behaviors. That would be focused around senior leaders in an organization, mid-level managers, supervisors in operations, and at the fourth level, the operators on the plant floor. At GMA’s Science & Education Foundation, we have a group of companies investing in this to roll out a portfolio of training programs. We’re trying to consolidate them under the umbrella of food safety culture and dealing with the full spectrum, from entry level and plant operators through to senior leadership.
Many companies certified to a GFSI scheme appear to have a leg up on preparing for FSMA, especially in the area of documentation and record keeping. During a quick chat with Food Safety Tech, Bob Butcher, group operations manager at Ipswich Shellfish Company, explained how GFSI has helped the seafood processor get ready for FSMA. Do you agree? Sound off in the comments section.
Food Safety Tech: What common challenges do companies experience when managing compliance with a GFSI scheme?
Bob Butcher: Every time there’s a new regulation it’s a matter of understanding how that regulation applies to us. The seafood industry has been regulated by FDA mandatory HACCP requirements for years now. Some of the items that are covered under FSMA have already been covered by the seafood regulations. Our facilities have also undergone third-party audits for a number of years and three are already SQF certified—so in order to meet those certifications, we comply with all the FSMA requirements at this point. That being said, there’s always a challenge or opportunity to make sure we comply with all the regulations and above that, make sure that the quality [of the product] we send to our customers meets both their standards and our standards.
FST: Has being certified to a GFSI scheme helped your company better prepare for FSMA compliance?
Butcher: Because we’re SQF certified and are meeting most of the requirements of the seafood industry, we’re well ahead of meeting FSMA requirements. Maintaining the GFSI requirements put us in great shape for FSMA.
GFSI covers so many areas. [Regarding] vendor compliance, we critically examine the seafood that comes in every day and it’s a very perishable commodity, but every plant is a little different in the talent they have and the number of people. We’ve been able to focus on making sure that the product meets the same criteria at each of the facilities no matter who is receiving it and documenting it accordingly. And whether [complying with] GFSI or FSMA, documentation is important.
We’ve gone the extra step in automating so we can better track how each of the plants and suppliers are performing. We started rolling it out at one plant two years ago and then extended it to all plants. All of our facilities have been under it for a year.
I think more and more companies are acknowledging the need to automate. With paper forms it’s difficult to make sure the employee has the correct and latest version, and the filing and recovery of that document [is difficult]. If it’s digital, you can get your hands on the latest version any time you want. Plus, you can analyze digital information and easily look for trends.
However, the seafood industry isn’t like a number of other industries—the margins are low, and so cost is absolutely a factor. If it’s a single facility, having paper forms, depending on the extent of the operation, may be acceptable. But if you get into multiple locations, it’s a whole different challenge all together.
FST: What are the broader issues that the seafood industry is currently facing?
Butcher: Supply and sustainability—making sure that you have a handle on the sustainability of the species and are able to explain that to your customers. That ties into record keeping—getting the right product, when it’s an MSC [Marine Stewardship Council] or ASC [Aquaculture Stewardship Council] chain of custody, or whether it’s having the right relationship with the vendors so you know your source. Cost is a concern, along with quality and inventory levels.
There are a lot of very small companies and a lot of them aren’t GFSI certified. A lot of them don’t even have any type of third-party audits, so I’m not sure how ready they are. It’s always a challenge for a small company to get up to speed.
FST: Does compliance with a GFSI scheme help address these issues to some extent?
Butcher: As we started working on GFSI or FSMA, and even HACCP many years ago, we started looking at products differently. You’re documenting more and gaining information—and once you have that information, you can focus on cost factors and inventory. So from that standpoint, it has been very helpful. At this point, we’re SQF Level, and we plan to go Level 3, which involves more quality parameters and certification. That will greatly impact the product and the profitability as well.
FST: What are your tips for companies in terms of being audit ready?
Butcher: The software program we use helps us maintain our facilities to be as audit ready as we can from a documentation standpoint. With SQF there will be unannounced audits, and it’s always been FDA’s practice or the state inspector’s practice to pop in anyway, so you have to be ready for that inspection at any time. The whole principle of HACCP is to make sure you’re documenting what you’re doing. And whether it’s an auditor or an inspector, they’re coming in at any time and can look at records for the past two years, so you should be in compliance and be able to prove that.
If my company is GFSI-certified, is it also FSMA compliant? The answer is: With shared goals of producing safe food, coordinating preventive measures and ensuring continuous improvement, if your company is FSSC 22000 certified, you’re well on the road to FSMA compliance, according to Jacqueline Southee, Ph.D., U.S. Liaison, FSSC 22000. Southee discussed several areas in which FSSC 22000 aligns with FSMA as part of a recent Leadership Series, “GFSI in the Age of FSMA”.
Supply Chain Visibility
FSSC 22000 is applicable to all aspects of the supply chain and requires interactive communication (all of which must be documented), from the downstream level in ensuring raw materials and suppliers meet requirements of ISO 22000 framework to communication with customers and suppliers to verify and control hazards.
FSMA controls the hazard of food within the United States, says Southee, whereas GFSI certification is a global initiative, thereby extending supply chain visibility to foreign suppliers.
The Food Safety Plan
There has been much discussion surrounding building a FSMA-ready food safety plan and the migration from HACCP to HARPC. “HARPC can be referred to as HACCP with preventive controls,” says Southee. FSSC 22000 provides a flexible yet robust approach in a framework that is applicable to all situations (i.e., different manufacturers have different issues, such as producing ice cream versus baked goods). Rather than being prescriptive, the prerequisite program has the flexibility to apply to a particular situation. In addition, validation, verification, monitoring and documentation are an inherent part of the ISO 22000 approach and the FSSC 22000 certification.
FSSC 22000 serves as an effective tool in preparing companies for FSMA compliance. “We’re not a regulatory system; FDA has that domain,” says Southee. “They’re the ones that carry the responsibility of meeting those regulations. We work with everyone…to do the best job we can.”
Audit Readiness
Being audit ready all the time is a key part of preparing for FSMA. FSSC 22000 certifies a food safety management system (a three-year certification cycle) and requires internal audits of company performance, along with helping companies ensure that their records are organized at all times. The goal is to install a management system that enables constant monitoring, reevaluation and assessment as part of an ongoing process of keeping food safe, according to Southee. “If you’re certified and have an effective ongoing management system, unannounced audits won’t be an issue,” she says.
Food Safety Culture
FSSC 22000 and ISO 22000 provide a strong foundation for building food safety culture. ISO 22000 requires proof of management commitment to the food safety process, along with accountability, and for management to make resources available to see the food safety process through. “We agree that culture has to come from the top,” says Southee. “The personnel have to see that management is committed, and the culture will come from that commitment.” It also requires constant communication, up and down the supply chain as well as internally. This includes involving all employees and making sure that they know what they’re doing (i.e., training). “Everyone needs to know they’re valued and important, and how their function contributes to the function of safe food,” says Southee.
FSMA Alignment and Gap Analysis
There are sure to be some gaps when it comes to FSSC 22000 and FSMA. FSSC 22000 has commissioned a gap analysis to compare the preventive controls for human and animal food rules with the GFSI scheme and will add addendums as needed. Areas of review include a requirement to include food fraud into the hazard analysis and a review of unannounced audit protocol.
It’s safe to say that 2015 has been one of the worst years in recent history when it comes to food contamination. Everyone from global food manufacturers to major restaurant chains and grocery stores perpetuated or experienced outbreaks of foodborne illnesses like E. coli, Listeria, Salmonella and Norovirus. From farm to fork, the food industry needs to evalutate and improve its processes to deliver the utmost health and safety to consumers.
With FSMA and tougher industry standards in place, there will be much more emphasis on preventative measures—especially for food manufacturers. FSMA establishes a legislative mandate to require comprehensive, prevention-based controls across the food supply to prevent or significantly minimize the likelihood of problems occurring.
Not surprisingly, most food manufacturers say they are being impacted by FSMA
Even though most of the regulations affiliated with the FSMA have just gone into effect, or will go into effect in 2016, food manufacturers are already feeling the heat. A recent survey found that the majority (81%) of food manufacturers are experiencing some level of impact from current and impending regulations. Processes pertaining to traceability, supplier and facility audits, HACCP and product recalls are causing the most concern. While most food manufacturers support FSMA’s mission to put prevention at the forefront, the reality is that many aren’t equipped to handle growing compliance demands.
There are still a sizeable number of food manufacturers that manually record their processes for identifying, evaluating and controlling food safety hazards. In fact, more than 30% of food manufacturers document their HACCP plan in this manner.
58% of manufacturers surveyed are using an in-house system for recording issues as part of their HACCP plan
With FSMA, there isn’t any room for human error. Although technology with track and trace capabilities has been available long before FSMA came into play, obstacles such as complicated interfaces, lack of interoperability and resources deterred wide-spread adoption among food manufacturers. The tide is changing here. Advanced enterprise resource planning (ERP) solutions have built in track and trace functionality that is more intuitive and integrates seamlessly with vital manufacturing execution systems (MES).
Manufacturing execution solutions play a key in helping companies achieve traceability. All figures courtesy of Aptean. View full infographic
Although the FDA does not have the legal authority to require companies to use computerized traceability solutions, implementing track and trace technology is one of the most effective measures a food manufacturer can take when it comes to FSMA compliance. It can help create a more systematic and reliable account throughout the lifecycle of a food product, and also establish preventative measures, including automated product checkpoints and quality tests throughout the supply chain. Ultimately, this gives food manufacturers the opportunity to identify and prevent issues before they become epidemics.
In addition to taking strong measures to prevent contamination, under FSMA the FDA now has authority to initiate mandatory recalls. Although mandatory recalls are anticipated to be rare, food manufacturers should use track and trace technology to make recall preparation routine. When used properly, these tools can pinpoint specifics about a product in real time, streamline quality reporting, and launch mock recalls.
Of course, technology is not only the vessel for improvement—to actually see change, food manufacturers need to take a critical look at their processes and make adjustments. Automating poor processes will only accelerate poor results, therefore approaching FSMA compliance and implementing track and trace technology requires time and strategy.
Ultimately, your company’s reputation is on the line as well as the safety of consumers. Dedicating necessary resources toward compliance planning and technology implementation is always well worth the investment. Many of the companies and suppliers that were in this year’s spotlight for contamination will look back on 2015 with regret because safety wasn’t at the forefront. Let’s learn from the hard lessons they provided and make 2016 the year that food manufacturers win back consumer trust and focus on quality.
This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.
Strictly Necessary Cookies
Strictly Necessary Cookies should be enabled at all times so that we can save your preferences for these cookie settings.
We use tracking pixels that set your arrival time at our website, this is used as part of our anti-spam and security measures. Disabling this tracking pixel would disable some of our security measures, and is therefore considered necessary for the safe operation of the website. This tracking pixel is cleared from your system when you delete files in your history.
We also use cookies to store your preferences regarding the setting of 3rd Party Cookies.
If you visit and/or use the FST Training Calendar, cookies are used to store your search terms, and keep track of which records you have seen already. Without these cookies, the Training Calendar would not work.
If you disable this cookie, we will not be able to save your preferences. This means that every time you visit this website you will need to enable or disable cookies again.
Cookie Policy
A browser cookie is a small piece of data that is stored on your device to help websites and mobile apps remember things about you. Other technologies, including Web storage and identifiers associated with your device, may be used for similar purposes. In this policy, we say “cookies” to discuss all of these technologies.
Our Privacy Policy explains how we collect and use information from and about you when you use This website and certain other Innovative Publishing Co LLC services. This policy explains more about how we use cookies and your related choices.
How We Use Cookies
Data generated from cookies and other behavioral tracking technology is not made available to any outside parties, and is only used in the aggregate to make editorial decisions for the websites. Most browsers are initially set up to accept cookies, but you can reset your browser to refuse all cookies or to indicate when a cookie is being sent by visiting this Cookies Policy page. If your cookies are disabled in the browser, neither the tracking cookie nor the preference cookie is set, and you are in effect opted-out.
In other cases, our advertisers request to use third-party tracking to verify our ad delivery, or to remarket their products and/or services to you on other websites. You may opt-out of these tracking pixels by adjusting the Do Not Track settings in your browser, or by visiting the Network Advertising Initiative Opt Out page.
You have control over whether, how, and when cookies and other tracking technologies are installed on your devices. Although each browser is different, most browsers enable their users to access and edit their cookie preferences in their browser settings. The rejection or disabling of some cookies may impact certain features of the site or to cause some of the website’s services not to function properly.
Individuals may opt-out of 3rd Party Cookies used on IPC websites by adjusting your cookie preferences through this Cookie Preferences tool, or by setting web browser settings to refuse cookies and similar tracking mechanisms. Please note that web browsers operate using different identifiers. As such, you must adjust your settings in each web browser and for each computer or device on which you would like to opt-out on. Further, if you simply delete your cookies, you will need to remove cookies from your device after every visit to the websites. You may download a browser plugin that will help you maintain your opt-out choices by visiting www.aboutads.info/pmc. You may block cookies entirely by disabling cookie use in your browser or by setting your browser to ask for your permission before setting a cookie. Blocking cookies entirely may cause some websites to work incorrectly or less effectively.
The use of online tracking mechanisms by third parties is subject to those third parties’ own privacy policies, and not this Policy. If you prefer to prevent third parties from setting and accessing cookies on your computer, you may set your browser to block all cookies. Additionally, you may remove yourself from the targeted advertising of companies within the Network Advertising Initiative by opting out here, or of companies participating in the Digital Advertising Alliance program by opting out here.