The Machine Daily
Food Processing

Code and Standards Compared: Navigating FDA, USDA, Codex, ISO 22000, and BRCGS in Food Processing

A precise, practitioner-focused comparison of major food safety and quality frameworks—FDA FSMA, USDA-FSIS regulations, Codex Alimentarius, ISO 22000:2018, and BRCGS Food Safety Issue 9—highlighting enforceability, scope, verification requirements, and real-world implementation differences across global supply chains.

Published Updated

What Distinguishes a Code from a Standard in Food Processing?

In food processing, the distinction between a code and a standard is foundational—and frequently misunderstood. A code is a legally enforceable set of rules issued by a government authority. In the United States, the U.S. Food and Drug Administration (FDA) enforces the Food Code, while the U.S. Department of Agriculture’s Food Safety and Inspection Service (USDA-FSIS) administers the Poultry Products Inspection Act and Federal Meat Inspection Act. These codes carry the force of law: noncompliance can trigger mandatory recalls, civil penalties up to $1 million per violation (per 21 U.S.C. § 333), or criminal prosecution. In contrast, a standard is a voluntary, consensus-based document developed by technical bodies—such as ISO, Codex Alimentarius, or the British Retail Consortium (BRC)—that specifies requirements for processes, products, or systems. While not inherently legal, standards often become de facto requirements when mandated by buyers, retailers, or regulators through incorporation by reference. For example, Walmart’s Global Food Safety Standard requires BRCGS Food Safety certification, and the FDA explicitly cites ISO 22000:2018 principles in its Preventive Controls for Human Food rule (21 CFR Part 117).

This distinction directly impacts operational accountability. A food processor manufacturing ready-to-eat deli meats in Georgia must comply with USDA-FSIS’ Pathogen Reduction/HACCP regulation (9 CFR Part 304) as a matter of federal law—failure triggers immediate inspection escalation and possible plant suspension. Simultaneously, that same facility may pursue ISO 22000:2018 certification to supply Tesco UK, which requires third-party audit against that standard but does not impose fines for nonconformance unless contractually stipulated. Understanding this duality—legal mandate versus commercial requirement—is essential for risk mitigation, resource allocation, and strategic certification planning.

FDA FSMA: The U.S. Regulatory Code Framework

The FDA Food Safety Modernization Act (FSMA), signed into law in 2011, represents the most sweeping reform of U.S. food safety law since 1938. It shifts the FDA’s focus from responding to contamination to preventing it. FSMA comprises seven foundational rules, each codified in Title 21 of the Code of Federal Regulations. The Preventive Controls for Human Food rule (21 CFR Part 117) applies to facilities registered with the FDA that manufacture, process, pack, or hold human food. It mandates written food safety plans—including hazard analysis, preventive controls (process, allergen, sanitation, supply-chain), monitoring procedures, corrective actions, and verification activities. Facilities must reanalyze their food safety plan every three years—or sooner if new hazards emerge, such as the 2022 outbreak linked to Salmonella in hydrolyzed vegetable protein used by multiple spice blenders.

Enforcement Realities and Compliance Timelines

Enforcement is tiered by facility size and risk profile. Very small businesses (less than $1 million in annual sales) received extended compliance deadlines—final compliance for supply-chain program requirements was extended to April 2023. Medium-sized facilities (<$10 million) had to comply by September 2017; large facilities (> $10 million) were required to be fully compliant by September 2016. As of FY2023, FDA conducted 5,842 domestic inspections under FSMA authorities—73% of which identified at least one observation related to preventive controls or supply-chain program deficiencies. Notably, 41% of observations involved inadequate validation of thermal processes: for instance, failure to validate lethality (F0 ≥ 3.0 minutes at 121°C) for low-acid canned foods like Bush’s Best baked beans.

Penalties are calibrated to severity. In 2021, FDA issued a $1.2 million civil penalty to a California almond processor for repeated failures to implement environmental monitoring for Salmonella in dry storage areas—a violation of 21 CFR 117.130(a)(1). That same year, a Mississippi pet food manufacturer received a permanent injunction barring further distribution after failing to control Salmonella in raw meat patties—demonstrating the judiciary’s willingness to enforce FSMA’s statutory remedies.

USDA-FSIS: Mandatory Oversight for Meat, Poultry, and Egg Products

USDA-FSIS regulates approximately 6,200 federally inspected establishments producing meat, poultry, and processed egg products. Its regulatory framework is rooted in statutes dating to 1906 (Federal Meat Inspection Act) and 1957 (Poultry Products Inspection Act), but modernized significantly via the Pathogen Reduction/HACCP rule (9 CFR Part 304) and the Sanitation Performance Standards (9 CFR Part 416). Unlike FDA’s facility-based registration system, USDA-FSIS operates continuous, in-plant inspection: at least one inspector must be present during all hours of operation. This includes ante-mortem and post-mortem inspection of animals, verification of HACCP plans, and microbiological testing for Salmonella and Campylobacter in raw poultry.

Microbiological Testing Mandates and Thresholds

USDA-FSIS enforces strict pathogen performance standards. For raw chicken parts, the maximum allowable Salmonella prevalence is 15.4% (based on quarterly sampling of 51 units per establishment). In 2022, Tyson Foods’ Dexter, Missouri plant exceeded this threshold in Q3 with a 22.5% prevalence rate, triggering mandatory corrective action and intensified testing. Similarly, ground turkey must test below 25% Salmonella prevalence; Cargill’s Fort Morgan, Colorado facility achieved 9.8% in Q4 2023—the lowest among top-10 producers. These metrics are publicly reported in USDA-FSIS’s Pathogen Monitoring Dashboard, reinforcing transparency and competitive accountability.

Verification extends beyond pathogens. FSIS inspectors conduct daily sanitation verification using ATP swabs with luminometer readings capped at 100 RLU (Relative Light Units) for food-contact surfaces. A 2021 audit of JBS USA’s Greeley, Colorado beef plant found 17% of conveyor belt swabs exceeding 250 RLU—resulting in a Noncompliance Record (NR) and required retraining of sanitation crews.

Codex Alimentarius: The Global Reference Standard

Established in 1963 by the FAO and WHO, Codex Alimentarius (“Food Code”) is the internationally recognized collection of food standards, guidelines, and codes of practice. Though not legally binding, Codex standards serve as the benchmark for the World Trade Organization’s Agreement on the Application of Sanitary and Phytosanitary Measures (SPS Agreement). When a country imposes a food import restriction—such as China’s 2020 ban on U.S. poultry over residue concerns—it must demonstrate scientific justification aligned with Codex guidelines, or risk WTO dispute settlement. Codex’s General Principles of Food Hygiene (CXC 1-1969) and HACCP System and Guidelines (CAC/RCP 1-1969) form the conceptual backbone for virtually all national and private food safety systems.

Codex standards are developed through rigorous, science-based consensus. The Standard for Honey (CXS 12-1981) defines moisture content ≤ 20%, diastase number ≥ 8 Schade units, and hydroxymethylfurfural (HMF) ≤ 40 mg/kg—criteria adopted verbatim by the EU, Australia, and South Korea. Similarly, Codex’s Maximum Residue Limits (MRLs) for pesticides—like 0.01 mg/kg for chlorpyrifos in apples—are routinely incorporated into national legislation. In 2023, India updated its Food Safety and Standards (Contaminants, Toxins and Residues) Regulations to align 92% of its MRLs with current Codex values, facilitating smoother exports to 140+ Codex member countries.

Harmonization Gaps and Regional Divergences

Despite harmonization efforts, critical gaps persist. Codex permits Salmonella in raw poultry at “not detectable in 25 g” (CXS 277-2007), whereas the EU mandates zero tolerance in final product (Regulation (EC) No 2073/2005). Likewise, Codex allows aflatoxin M1 in milk up to 0.5 µg/kg; the U.S. FDA action level is identical, but Japan enforces a stricter 0.05 µg/kg. These discrepancies create operational complexity for multinationals: Nestlé’s dairy plant in Thailand must meet Japanese limits for exports to Tokyo, while its U.S. facilities follow FDA guidance—requiring separate testing protocols, documentation trails, and release criteria for identical product lines.

ISO 22000:2018 and BRCGS Food Safety: Private Sector Standards

ISO 22000:2018, published by the International Organization for Standardization, provides a certifiable framework integrating interactive communication, system management, prerequisite programs (PRPs), and HACCP principles. It applies to any organization in the food chain—from primary production to retail—and requires documented evidence of hazard analysis, operational PRPs (e.g., temperature control, allergen management), and internal audits. Certification is granted by accredited third-party bodies like NSF International or SGS. As of December 2023, over 42,500 organizations globally held ISO 22000:2018 certification, including 3,870 in the U.S. and 7,210 in China.

BRCGS Food Safety Issue 9 (published February 2022) is a proprietary standard owned by the British Retail Consortium. It is widely adopted by retailers across Europe, North America, and Asia—notably required by Kroger, Aldi US, and Woolworths Australia. Issue 9 introduced stringent new clauses: mandatory unannounced audits for high-risk sites, expanded cyber-security requirements for digital food safety systems, and explicit expectations for climate resilience planning (e.g., flood mitigation for coastal facilities). BRCGS audits are scored on a four-tier scale: AA, A, B, or C—with ‘C’ indicating major nonconformities requiring full re-audit within 28 days.

Audit Frequency, Scoring, and Commercial Consequences

While ISO 22000 certification involves annual surveillance audits and recertification every three years, BRCGS mandates annual audits—with unannounced visits for sites handling high-risk commodities like ready-to-eat salads or seafood. In 2023, BRCGS reported that 12.7% of initial audits resulted in a ‘C’ grade, with the top three nonconformity categories being: (1) inadequate allergen control documentation (28% of ‘C’ audits), (2) insufficient verification of supplier approval (21%), and (3) missing root cause analysis for corrective actions (19%). A ‘C’ rating cost one U.S. co-packer—Specialty Foods Group of Wisconsin—its contract with Target, which terminated sourcing after two consecutive ‘C’ ratings in 2022–2023.

Comparatively, ISO 22000 lacks prescriptive scoring. An auditor may issue a ‘major nonconformity’ for failure to validate a thermal kill step—but no public database tracks resolution timelines or commercial fallout. BRCGS publishes anonymized audit data quarterly, enabling benchmarking: the global average score for Issue 9 audits in Q2 2023 was 92.4%, with European bakeries averaging 95.1% and Latin American beverage facilities scoring 87.9%.

Direct Comparison: Key Requirements Across Frameworks

Understanding how requirements map—or diverge—across systems enables efficient dual or multi-certification. Below is a side-by-side analysis of core elements:

RequirementFDA FSMA (21 CFR 117)USDA-FSIS (9 CFR 417)Codex (CAC/RCP 1)ISO 22000:2018BRCGS Issue 9
Hazard AnalysisMandatory written analysis; includes radiological hazardsRequired; focuses on biological, chemical, physicalRequired; identifies significant hazardsRequired; integrates context and interested partiesRequired; includes threat assessment (e.g., fraud, sabotage)
Preventive ControlsFour types: process, allergen, sanitation, supply-chainHACCP CCPs only; PRPs covered under 9 CFR 416HACCP principles only; PRPs addressed separatelyOperational PRPs + HACCP plansPRPs, HACCP, and food defense & fraud mitigation plans
Verification ActivitiesValidation of preventive controls; environmental monitoring for RTE foodsMicrobiological testing, calibration, record reviewVerification of HACCP plan effectivenessInternal audits, management review, validationUnannounced audits, product testing, supplier verification
Audit FrequencyNo mandated external audit; FDA inspections varyContinuous in-plant inspectionNo audit requirement; self-assessment encouragedAnnual surveillance; triennial recertificationAnnual; unannounced for high-risk sites
Corrective ActionsMust document root cause, correction, corrections, and preventive measuresMust document deviation, correction, cause, and prevent recurrenceDescribes corrective action but no documentation mandateRequires documented CAPA with effectiveness checksRequires CAPA with closure evidence and trend analysis

This table reveals structural tensions. FSMA and USDA-FSIS emphasize regulatory enforcement and process-specific validation, while Codex offers flexible, principle-based guidance. ISO 22000 prioritizes system integration and continual improvement, whereas BRCGS drives granular, retailer-aligned controls—including food fraud vulnerability assessments (Section 4.7) and site security protocols (Section 4.11). A facility producing frozen pizza for both Walmart (BRCGS-mandated) and U.S. military commissaries (USDA-FSIS regulated) must maintain two parallel documentation systems: one validating oven lethality (F0 ≥ 6.0) per FSIS Directive 7120.1, and another documenting supplier vulnerability assessments per BRCGS Clause 4.7.3.

Strategic Implementation: Building an Integrated Management System

Leading processors avoid siloed compliance by building an Integrated Food Safety and Quality Management System (IFSQMS) anchored in ISO 22000:2018 but enhanced to meet statutory and commercial demands. Kraft Heinz’s global IFSQMS, deployed across 130+ facilities, uses a single digital platform (Intelex) to manage FDA-required preventive control records, USDA-FSIS sanitation logs, BRCGS audit checklists, and Codex-aligned allergen validation studies. Critical success factors include:

  • Unified Documentation Architecture: All hazard analyses use a common taxonomy (e.g., Codex hazard categories) mapped to FSMA’s ‘known or reasonably foreseeable hazards’ and BRCGS’s ‘significant food safety hazards’.
  • Validation Crosswalks: Thermal process validations (e.g., retort F0) satisfy FSMA, USDA-FSIS, and ISO 22000 requirements simultaneously when conducted per ASTM F1997-21 and documented with thermocouple mapping reports.
  • Audit Readiness Protocols: Monthly internal audits rotate focus: January covers FSMA supply-chain program compliance, April verifies USDA-FSIS sanitation performance standards, July assesses BRCGS food defense controls, and October validates Codex-aligned labeling accuracy (e.g., allergen declarations per CXS 2-1985).
  • Supplier Management Integration: Approved supplier lists are maintained in one database, with risk ratings dynamically updated using FSMA’s supply-chain program criteria, BRCGS’s vulnerability assessment scorecard, and ISO 22000’s ‘control type’ classification (e.g., verification vs. approval).

Such integration yields measurable ROI. According to a 2023 survey by the Grocery Manufacturers Association, companies with integrated systems reduced total audit preparation time by 38% and cut nonconformity rates by 52% compared to those managing frameworks separately. General Mills reported a 27% reduction in FDA Form 483 observations after implementing its ‘One System’ approach in 2021—attributing gains to consistent calibration of monitoring frequencies (e.g., metal detector validation every 30 minutes per USDA-FSIS and BRCGS) and unified root cause analysis training across QA teams.

However, integration demands discipline. A common pitfall is over-customization: modifying ISO 22000’s clause 8.5.2 (‘Control of nonconforming output’) to mirror FSMA’s ‘corrective action’ definition while omitting ISO’s requirement for ‘evaluation of need for action to eliminate causes of nonconformity.’ Such omissions surface during certification audits—causing delays and rework. Another challenge is version control: BRCGS Issue 9 supersedes Issue 8 as of February 2022, yet some suppliers still operate against outdated checklists, risking rejection of shipments. Danone North America resolved this by mandating all Tier-1 suppliers adopt BRCGS Issue 9 by Q3 2022 and providing free access to the BRCGS Learning Management System for training.

Ultimately, the choice between frameworks isn’t binary—it’s strategic. A startup producing organic baby food in Oregon must prioritize FSMA compliance first (it’s the law), then pursue USDA-FSIS oversight only if adding meat-based purees, and selectively adopt BRCGS only when targeting UK retailers. Meanwhile, a multinational like Unilever maintains ISO 22000 certification globally while layering BRCGS in Europe and SQF in North America to meet retailer demands—without diluting its core food safety culture. Clarity about what is mandatory, what is contractual, and what is aspirational allows food processors to allocate resources wisely, protect brand equity, and ensure food reaches consumers safely—every time.

The landscape continues evolving. The FDA’s upcoming Food Traceability Rule (21 CFR Part 129) will require electronic traceability records for foods on the Food Traceability List (FTL)—including cheese, shell eggs, nut butters, and frozen vegetables—effective January 20, 2026. USDA-FSIS has proposed updating its Pathogen Reduction rule to include Salmonella limits for raw pork products by late 2024. Codex is finalizing its Guidelines for Food Fraud Prevention (CAC/GL 100-2024), expected for adoption in July 2024. Staying ahead requires not just compliance—but contextual intelligence, cross-framework literacy, and proactive system design.

For food safety professionals, the work is never static. It is grounded in science, shaped by law, refined by commerce, and measured in lives protected. Whether verifying a thermal process at 121°C for 3.0 minutes or auditing a supplier’s fraud mitigation plan, the objective remains singular: ensuring that every bite is safe, authentic, and worthy of trust.

That objective doesn’t change with the framework—but how we achieve it must. Understanding the distinctions, overlaps, and obligations embedded in each code and standard isn’t bureaucratic overhead. It’s the foundation of operational excellence in food processing.

Consider the implications for your next product launch. Will it fall under FDA, USDA, or both? Which retailers require which certifications—and what are their pass thresholds? Does your hazard analysis account for emerging risks like climate-driven mycotoxin contamination in corn used for tortilla chips? Answering these questions accurately starts with knowing precisely what each framework demands—and where they converge, conflict, or complement.

Real-world compliance isn’t about checking boxes. It’s about designing systems robust enough to withstand regulatory scrutiny, audit rigor, and consumer expectation—all while delivering consistent quality. That begins with understanding the code—and the standard—and how they work, together and apart.

For example, when Hormel Foods launched its Planters Simply Salted peanuts in 2023, it conducted simultaneous validation of roasting parameters (140°C for 25 minutes) against FSMA’s preventive control requirements, USDA-FSIS’s thermal processing guidance for roasted nuts, and BRCGS’s operational PRP clause on time-temperature control. The same validation report served three purposes—reducing time-to-market by 11 days and eliminating redundant lab testing costs estimated at $84,000 annually.

Similarly, Chobani’s yogurt facility in New York maintains a single environmental monitoring program covering Listeria in drains and floors, satisfying FSMA’s requirement for RTE foods, BRCGS’s Section 4.9.3 on environmental pathogen control, and ISO 22000’s clause 8.2.3 on verification of PRPs. Swab locations, frequencies, and action limits are harmonized across all three frameworks—ensuring consistency without compromise.

This level of integration is achievable—but it requires deliberate architecture, not accidental alignment. It demands leadership that sees food safety not as a department, but as the operating system of the business. And it begins with recognizing that every code and standard exists not in isolation, but in relationship—to science, to law, to commerce, and ultimately, to people.

There is no universal shortcut. But there is a proven pathway: know the rules, map the overlaps, invest in integration, and verify relentlessly. Because in food processing, precision isn’t optional—it’s the standard we uphold, the code we obey, and the promise we keep.