Most food manufacturers I work with didn't choose to run two management systems. They ended up with one for quality because a customer asked for it, and one for food safety because a regulator or a retailer required it, and now they're maintaining two document trees, two internal audit calendars, and two management reviews that cover roughly the same ground twice a year. That's the problem this guide is written to solve.
ISO 9001 and ISO 22000 were built to fit together. Both use the High Level Structure that ISO introduced across its management system standards starting in 2012, which means they share the same ten-clause skeleton, the same core vocabulary around context, leadership, planning, support, operation, performance evaluation, and improvement. That shared architecture is not a coincidence. It's the reason integration is a realistic project rather than a compliance fantasy, and in my experience it's the single biggest lever a food company has for getting real value out of two certifications instead of just carrying the cost of two.
What ISO 9001 and ISO 22000 Actually Share
Because both standards sit on the High Level Structure, clauses 4 through 10 line up almost one for one. Clause 4 (context of the organization) asks the same question in both standards: who are your interested parties, and what do they need from you. Clause 5 (leadership) requires the same top-management commitment and policy structure. Clause 9 (performance evaluation) calls for the same internal audit and management review cycle. If you've built a context analysis, an interested-parties register, or a management review agenda for ISO 9001:2015, you already have 70 to 80 percent of what ISO 22000:2018 asks for in those same clauses.
Where the standards genuinely diverge is inside clause 8, operational planning and control. ISO 9001 clause 8.5 covers production and service provision generally: work instructions, traceability where required, and control of changes. ISO 22000 clause 8 goes much deeper, because it has to. It requires a documented hazard analysis built on Codex Alimentarius HACCP principles, prerequisite programs (PRPs) covering things like pest control, cleaning and sanitation, and allergen management, and a formal system for identifying critical control points (CCPs) and operational PRPs (oPRPs) with defined critical limits and monitoring procedures. That's the part of ISO 22000 that has no real equivalent in ISO 9001, and it's the part that determines whether your integration project is straightforward or genuinely difficult.
The Clause-by-Clause Overlap
| Clause | ISO 9001:2015 | ISO 22000:2018 | Integration effort |
|---|---|---|---|
| 4. Context of the organization | Interested parties, QMS scope | Same, plus food safety team scope | Low — combine into one document |
| 5. Leadership | Quality policy, roles | Food safety policy, food safety team leader | Low — one policy, two objective sets |
| 6. Planning | Risks/opportunities, quality objectives | Same, plus food safety objectives | Low — shared risk register |
| 7. Support | Competence, infrastructure, documented info | Same, plus PRP infrastructure | Medium — PRPs need their own controls |
| 8. Operation | Design, production control, nonconformity | Hazard analysis, HACCP plan, CCPs, oPRPs, traceability, recall | High — this is where the systems diverge |
| 9. Performance evaluation | Internal audit, management review | Same, plus verification of the HACCP plan | Low — combine the audit program |
| 10. Improvement | Corrective action, continual improvement | Same, plus system update triggers | Low — one CAPA process |
If you're deciding whether an integrated audit is realistic for your site, this table is the honest answer: clauses 4, 5, 6, 9, and 10 integrate cleanly. Clause 7 needs some care around prerequisite program infrastructure. Clause 8 is where you build a genuinely food-safety-specific process and stop trying to force it into a generic quality template.
Why Bother Integrating At All
The case for integration isn't just tidiness. A combined audit program that covers both standards in a single visit typically cuts total audit days by 20 to 30 percent compared to running them separately, because the auditor isn't re-interviewing the same people about the same context analysis and the same management review twice in one year. Certification bodies price integrated audits on combined man-day tables that account for this overlap, and most of the accredited bodies I've worked with (SGS, BSI, NSF) will quote a joint ISO 9001/ISO 22000 audit at less than the sum of two standalone audits.
There's also a real risk-reduction argument. The CDC estimates that foodborne illness sickens roughly 48 million people in the United States every year, hospitalizes about 128,000, and causes an estimated 3,000 deaths, and a documented, verifiable hazard analysis is the single control that stands between a manufacturer and being the source of one of those outbreaks. ISO 22000 forces that documentation. ISO 9001 forces the discipline to actually follow the documented process instead of letting it drift, because clause 9.1 performance evaluation and clause 10.2 corrective action apply to food safety nonconformities exactly the way they apply to quality ones. Integration isn't about making food safety softer. It's about making sure the quality system's discipline gets applied to the highest-consequence risks in the plant.
FSSC 22000, the scheme built on top of ISO 22000 plus the ISO/TS 22002 series of sector-specific prerequisite programs, has become the dominant certification path for food manufacturers selling into retail supply chains, and it was built with this integration in mind from the start. If your customers are asking for GFSI recognition, you're very likely heading toward FSSC 22000 rather than bare ISO 22000, and the integration principles in this guide apply the same way to that combination.
Building One Integrated Manual Instead of Two
The most common mistake I see is treating integration as running two systems under one binder. That's not integration, it's storage. A real integrated management system (IMS) has one policy statement that addresses both quality and food safety objectives, one context and interested-parties analysis, one risk register that captures both quality risks and food safety hazards (with the food safety hazards flagged for the deeper HACCP treatment they need), one internal audit schedule, and one management review meeting with a single agenda that has a food safety section built in rather than a separate meeting scheduled six weeks later.
The food safety team required by ISO 22000 clause 7.3.3 does not need to be a separate organizational structure sitting outside your quality function. In most mid-sized food operations, the food safety team leader and the quality manager are either the same person or sit in the same reporting line, and the food safety team itself is best built as a standing subcommittee of your existing management review structure, meeting on the same cadence, feeding the same corrective action log.
Where You Still Need Separate Documentation
Some things should not be merged, because merging them makes the food-safety-specific requirements harder to verify, not easier.
- The hazard analysis and HACCP plan stay as their own documented process, with hazard identification, likelihood and severity scoring, CCP determination, and critical limits kept distinct from your general quality risk register.
- Prerequisite programs (sanitation, pest control, allergen control, water and air quality, supplier approval for food-contact materials) need their own procedures even where they reference shared infrastructure controls.
- Traceability and recall/withdrawal procedures under ISO 22000 clause 8.5.4 and 8.9 have specific mock-recall testing requirements that don't map to anything in ISO 9001 and should be tested and documented on their own schedule, typically at least annually.
Keep those three areas distinct, integrate everything else, and you get a system that a single competent auditor can review in one visit without either standard's rigor getting diluted.
A Practical Rollout Sequence
For a food manufacturer that already holds ISO 9001 and is adding ISO 22000 (the more common direction, since quality certification tends to come first), the sequence I recommend runs roughly like this:
- Gap assessment against ISO 22000 clause 8, treating everything else as largely covered by your existing QMS. This is where the real work is, so don't spend the first month re-auditing clauses you've already satisfied.
- Stand up or formalize the food safety team and assign the food safety team leader role, even if that's your existing quality manager wearing a second hat.
- Build the prerequisite program set using ISO/TS 22002-1 as your checklist if you're heading toward FSSC 22000, or the generic PRP guidance in ISO 22000 Annex A if you're pursuing bare ISO 22000.
- Conduct the hazard analysis, product by product or process by process, and determine your CCPs and oPRPs with documented critical limits and monitoring frequency.
- Merge the management review and internal audit calendars so food safety verification activities sit inside the existing governance rhythm rather than beside it.
- Run a combined internal audit cycle covering both standards before you invite your certification body to quote a joint audit.
Most sites I've guided through this can complete steps 1 through 4 in a single quarter if the plant already has decent sanitation and pest control documentation to build on. The bottleneck is almost always the hazard analysis itself, because it requires real cross-functional input from production, maintenance, and sometimes an outside food safety specialist for products with unusual allergen or pathogen profiles.
Common Integration Mistakes
The failure pattern I see most often is a company that builds a beautiful integrated policy and context section, then leaves the HACCP plan sitting in a separate binder that nobody references during the quality team's corrective action meetings. When a food safety deviation happens, it gets logged in a food-safety-specific form that the quality system's CAPA process never sees, and root cause analysis on repeat food safety issues never gets the same rigor as a quality nonconformity would. If your corrective action process is truly integrated, a CCP deviation and a dimensional nonconformity should flow through the identical escalation, root cause, and verification steps. The finding might look different. The discipline should not.
The second common mistake is auditing the two standards separately even after documentation is merged, usually because the internal audit team doesn't have anyone trained on HACCP verification. That's worth fixing directly rather than working around: train at least one internal auditor to competency on ISO 22000 clause 9.1 and Codex HACCP principles, because a merged manual audited by two disconnected audit teams gives you the paperwork of integration without the substance of it.
Frequently Asked Questions
Can one person be both the ISO 9001 management representative and the ISO 22000 food safety team leader?
Yes. Neither standard requires the roles to be held by different people, and in practice combining them under one quality/food safety manager is the most common structure in mid-sized manufacturing operations. What matters is that the person has the authority and the technical competence both standards call for, particularly HACCP training for the food safety team leader role.
Do we need two separate certificates, or can we get one certificate covering both standards?
Certification bodies typically issue two certificates, one per standard, because they're separate accreditation scopes even when audited together in a single visit. The efficiency gain comes from the combined audit schedule and shared man-day allocation, not from a single unified certificate.
How long does it take to add ISO 22000 to an existing ISO 9001 system?
For a facility with a mature ISO 9001 system and reasonable existing sanitation and pest control programs, three to six months is a realistic range to reach a stage 1 readiness audit, with the hazard analysis and CCP determination work as the main variable in that timeline.
Is FSSC 22000 the same thing as ISO 22000?
No. FSSC 22000 is a GFSI-recognized certification scheme built on ISO 22000 plus sector-specific prerequisite programs from the ISO/TS 22002 series and additional FSSC requirements. Most food manufacturers selling into major retail supply chains pursue FSSC 22000 rather than standalone ISO 22000 because retailers increasingly require GFSI recognition specifically.
What's the biggest risk of integrating too aggressively?
Diluting the hazard analysis, prerequisite programs, or traceability/recall testing by treating them as just another quality procedure. Those three areas need their food-safety-specific rigor preserved even inside a fully merged manual — that's the one place where integration for efficiency's sake can quietly undercut the thing ISO 22000 exists to protect.
Integration done well gives you one governance rhythm, one audit calendar, and one improvement process, with the food safety hazard analysis kept rigorous inside that shared structure rather than diluted by it. That's the balance worth aiming for, and it's usually closer than most quality managers assume once the clause-by-clause overlap is actually mapped out.
If you're scoping this project for your own facility, our ISO 9001 internal audit checklist is a useful starting point for assessing how much of your existing QMS documentation is already reusable, and our guide to ISO clause 8 operational planning goes deeper into the production-control differences that drive most of the integration effort.
Last updated: 2026-08-07
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.