FOOD TRACEABILITYLEDGER

Follow the food. Preserve the record.

Standards & Interoperability · Primary-source analysis

ISO 22000 governs a food-safety system—not a lot-traceability protocol

ISO 22000 specifies requirements for a food-safety management system across the food chain and incorporates HACCP principles. It does not replace the separate lot, event, data-exchange, or jurisdiction-specific records used to trace food.

Editorial figure by Food Traceability Ledger. Source context: ISO — ISO 22000:2018 Food safety management systems.

A management system and a traceability record answer different questions

The direct answer in ISO's public record is that ISO 22000 specifies requirements for a food-safety management system. It addresses an organization's systematic ability to manage food-safety hazards and provide safe products and services. A traceability record instead connects identified food, lots or batches, locations, parties, processes, events, times, and source evidence so an organization can follow movement and transformation within a defined scope.

Those records interact, but neither can stand in for the other. A food-safety management system may define traceability responsibilities and use trace records during response. A technically interoperable lot history does not prove that hazards are controlled, and an ISO 22000 certificate does not reveal every lot event or satisfy every traceability rule. The data model should preserve the link without merging the conclusions.

HACCP and prerequisite programs need their own evidence

ISO says ISO 22000 integrates Codex HACCP principles and application steps and combines interactive communication, system management, prerequisite programs, and HACCP principles. Those components concern hazard analysis and control within an operating system. They are not merely additional attributes on a shipment, and a trace event is not evidence that a preventive or critical control was designed, monitored, verified, or effective.

A representative evaluation should connect a product and process to hazard analysis, prerequisite programs, control measures, monitoring, verification, nonconformity or incident handling, affected lots, distribution events, withdrawal or recall actions, and retained evidence. The platform should show which facts come from production, laboratory, warehouse, supplier, customer, logistics, regulatory, or manually governed sources and how conflicts are resolved.

Applicability across the chain does not create one data protocol

ISO says the standard can apply to primary producers, food manufacturers, transport and storage operators, caterers, retailers, subcontractors, and other organizations in the food chain. Broad organizational applicability does not mean those parties share one event vocabulary, identifier scheme, retention period, response format, or regulatory scope. Interoperability still requires an agreed data model, identifiers, mappings, access controls, and tested exchange.

Buyers should ask a provider to trace a transformed lot across at least one supplier, internal operation, warehouse, and recipient; reconcile quantities and identifier changes; show corrections; and export the evidence required for the applicable authority or customer. They should separately test the food-safety-management workflows. A polished network map is not proof of hazard control, and a certification badge is not proof of trace completeness.

Certification and revision status remain bounded

ISO's page identifies ISO 22000:2018 as the current published second edition, notes an amendment, and shows a draft successor under development. ISO also says certification is not required and that ISO does not perform certification. Current edition, draft development, organizational implementation, certification, and certificate transition are separate states that should retain their own sources and dates.

This article does not verify a food-safety management system, certify an organization, perform hazard analysis, determine traceability scope, assess a lot history, or establish compliance with FDA, USDA, EU, Canadian, UK, customer, or other requirements. Organizations need current law, standards, product and facility facts, and qualified food-safety, quality, operations, supply-chain, data, certification, regulatory, and legal judgment.

Enterprise buyer test

Translate this change into the exact population, record type, workflow stage, decision owner, effective date, and evidence that could be affected. Ask current or prospective providers to demonstrate the named workflow with representative data and an exception—not a polished feature tour. Record what official documentation establishes, what a provider states, what the team observes, and what remains unresolved.

A defensible review also identifies the dependency outside the product. Authority interpretation, policy configuration, data quality, integrations, human judgment, approval rights, release governance, training, and retained evidence may remain customer or service responsibilities. The evaluation should preserve those boundaries instead of treating a technology claim as the complete operating model.

What we will watch next

Food Traceability Ledger will watch the named source and affected market records for later evidence that changes status, scope, availability, implementation timing, workflow consequence, or the limits of the initial report. A later announcement does not silently overwrite this dated account; the change ledger preserves the sequence.

Primary source: ISO — ISO 22000:2018 Food safety management systems · Official standards-body record.

Evidence boundary: This article independently analyzes ISO's public ISO 22000:2018 record reviewed August 11, 2026. It is not food-safety, HACCP, traceability, recall, certification, regulatory, compliance, or legal advice and does not determine the safety, traceability, or conformity of any organization, product, process, or lot.

Editorial record: Published August 11, 2026; updated August 11, 2026. Corrections policy.