Keystone
by CloudVoro
Guide · Compliance

The HACCP records auditors actually check
, and the gaps that write findings.

HACCP paperwork divides into two piles: the plan (hazard analysis, CCPs, limits, written once, reviewed rarely) and the records (monitoring, deviations, verification, generated every shift). Audits are lost in the second pile. This guide lists exactly which records get pulled, what auditors cross-check them against, and the recurring gaps.

9 min read Updated 2026-07-08By the CloudVoro team

Plan documents vs. operational records

The plan pile, hazard analysis, CCP determination, critical limits, process flow diagrams, proves you designed a safe process. Codex HACCP principle 7 and Regulation 852/2004 Article 5 require documentation proportionate to the business, and inspectors will read it. But a plan is static; auditors know it was polished for them.

The records pile proves the plan runs: CCP checks at the frequency the plan states, signed and timed; deviations with dispositions; verification activity; calibration. These are generated under production pressure, which is exactly why auditors trust them, and why they contain the gaps.

The records that get pulled, and the cross-checks

RecordThe cross-check an auditor runs
CCP monitoring logsFrequency in the log vs frequency the plan promises; times realistic (not four entries at 16:58); signatures match trained people on the training matrix
Deviation / corrective action logEvery monitoring excursion has a disposition; affected product identified by batch; root cause beyond "operator error"
Verification recordsScheduled reviews of monitoring records actually happened, by someone other than the monitor, at the promised cadence
Calibration recordsThe probe used at the CCP is on the calibration schedule; readings traceable to a calibrated reference
Validation evidenceCritical limits justified, regulation, guidance, challenge study, not folklore
Training recordsThe person signing the 06:00 CCP check is trained for that CCP, with a date

The five gaps that recur in findings

1 · Pencil-whipped logs
Identical values every check, entries written in one sitting, checks recorded for a line that was down. Auditors compare ink, times and production schedules, this is the credibility killer, because one falsified log poisons every other record.
2 · Deviations without product disposition
The excursion is logged, the fridge fixed, but nothing records what happened to the product that sat above limit, or which batches it was. Corrective action must always answer both: process and product.
3 · Monitoring disconnected from batches
Temperature logs by room and day, batches by product and vat, and no key linking them. When a deviation strikes, identifying affected product means reconstructing the day from memory.
4 · Verification that never happens
The plan promises weekly record review by the QA manager; the audit finds three months unsigned. Promise a cadence you can keep, then keep it visibly.
5 · Uncalibrated instruments at CCPs
A CCP decided by a probe last calibrated two years ago makes every reading arguable. Calibration cadence and evidence are part of the CCP, not housekeeping.

The connection that changes everything: records tied to batches

Most HACCP record findings share one root cause: monitoring records are organised by time and place, while product moves by batch, and nothing joins the two. The strongest single improvement a producer can make is recording batch identity on CCP checks and deviations, so 'what did this deviation touch?' is a lookup, not an investigation.

This is how Keystone structures QC execution: checks and deviations attach to the make-day and batch they belong to, so a deviation automatically knows its affected batches, and a batch's traceability report carries its QC history with it. During a vertical audit, the auditor's nominated lot arrives with its monitoring evidence already attached, which converts the tensest hour of a BRCGS audit into a screen-share.

Retention and format

Regulation 852/2004 requires documents and records to be retained for an appropriate period, proportionate guidance, not a single number. Practical practice: keep HACCP records at least as long as product shelf life plus a margin, and align with your traceability retention (commonly 5 years) so an incident investigation never outlives its evidence. Paper, spreadsheet or system are all acceptable formats; what matters is legibility, attributability (who, when), protection from casual amendment, and retrievability, an auditor asking for last February's CCP logs expects minutes, not a loft expedition.

Key takeaways
  • Audits are decided by operational records (monitoring, deviations, verification), not the HACCP manual.
  • Every monitoring excursion needs a disposition for both the process and the product, by batch.
  • Match reality to promises: monitor at the frequency the plan states, verify at the cadence it commits to.
  • Tie CCP checks and deviations to batch identity, it converts investigations into lookups.
  • Calibration is part of the CCP: an uncalibrated probe makes every reading arguable.
Free 5-part email course
Get audit-ready in five short emails.
The 18-point checklist PDF, the 30-second traceability test, what BRCGS auditors actually flag, and how Cashel Blue got audit-ready, one email every few days. No spam, one-click unsubscribe.
GDPR-friendly: we store your email for this course only. Unsubscribe link in every email.

Frequently asked questions

What HACCP records am I legally required to keep?
Regulation 852/2004 Article 5 requires documents and records proportionate to the nature and size of the business, demonstrating your HACCP-based procedures work: in practice CCP monitoring, deviations and corrective actions, verification and supporting records like calibration and training.
How long should HACCP records be kept?
The law says an appropriate period rather than one number. Common practice is shelf life plus margin at minimum, aligned with traceability retention (typically 5 years) so incident investigations never outlive their evidence.
Can HACCP records be digital?
Yes, paper, spreadsheets and software are all acceptable. Requirements are the same in any format: legible, attributable (who and when), protected from casual amendment, and retrievable on demand.
What is the difference between verification and validation in HACCP?
Validation proves the plan is right (critical limits justified by regulation, guidance or study, done before/when the plan changes). Verification proves the plan is being followed (scheduled review of monitoring records, internal audits, testing, done continuously).
What do auditors check most in HACCP records?
Consistency: log frequency vs plan promises, signatures vs training records, deviation entries vs monitoring excursions, probe IDs vs calibration schedules, and, increasingly, whether monitoring records connect to the batches they cover.

See this done in software, on real production data.

Keystone runs the full chain, supplier delivery → batch → dispatch → customer, in under 30 seconds. 20-minute discovery call, no sales pitch.

Compliance & trust

How we keep your
data and your audits safe.

Enterprise-grade controls as standard, encryption, MFA for every user, tenant isolation and tamper-evident audit trails, on EU cloud or your own servers. Privacy queries go to privacy@cloudvoro.com. Sub-processor list at /legal/sub-processors. Full security posture at /site/security.

Live
Hosted in EU / Ireland, or on-premise
Customer data resides on AWS Ireland (eu-west-1) and never leaves the EU. Local on-premise deployment available where policy requires it.
Live
GDPR · Privacy Contact named
Internal Data Protection Lead handles subject access requests. Owner is ADPO Ireland member.
Live
MFA for every user
TOTP multi-factor authentication across all roles, with rate limiting, brute-force lockout and reCAPTCHA bot protection on public forms.
Live
ISO 27001 · aligned controls
Security controls mapped to the ISO/IEC 27001:2022 Annex A framework, access management, encryption, logging, incident response.
Live
NIS2 · supporting evidence
Tenant isolation, MFA and tamper-evident audit trails give customers in NIS2 scope direct supporting evidence for their obligations.
Live
Encryption · at rest & in transit
TLS 1.3 in transit, industry-standard symmetric ciphers at rest, KMS-managed keys.