HACCP process flowchart (7-principle food safety plan)

HACCP process flowchart template: assemble the team, map the process, run hazard analysis and CCP decision-tree logic, set limits, monitoring and verification.

Use this template

What the haccp process flowchart (7-principle food safety plan) process is

A HACCP plan is built, not written in one sitting: a team is assembled, the product and its intended use are described, the process is mapped and then walked on the floor to confirm the map is honest, and only after that does the hazard analysis start. The chart below follows that build end to end, in the order Codex Alimentarius lays it out — the preliminary steps first, then hazard analysis, then the CCP decision at each step, then the four principles that turn a CCP into something monitorable (critical limits, monitoring, corrective actions, verification), then documentation and sign-off. The trigger is either a new product or process with no plan yet, or a scheduled revalidation of one that already exists, and both enter the same chart at the same place.

This chart builds the plan; it does not run it. Everything after the plan is approved — taking a reading, recording it against the critical limit, judging in the moment whether a result is in control — belongs to a separate, day-to-day process, CCP monitoring, at /templates/ccp-monitoring-process, and this page stops short of it on purpose rather than duplicating it. It is not the plant floor itself either: the receiving-to-dispatch chain a HACCP plan attaches CCPs onto is mapped separately at /templates/food-manufacturing-process, and an allergen program or a cleaning and sanitation procedure — prerequisite programmes that have to already be working for a hazard analysis to be honest about what's left to control at the step level — are their own documents, not steps on this chart. Nor is it a certification or a compliance filing: no flowchart makes a plan compliant with a scheme or a regulation by itself, and a real HACCP plan is validated against a specific product, specific hazards and whichever rules actually apply, by the people who own that decision, not by a template. Treat what follows as a structure to build a real plan inside, not a delivered one.

Five decisions carry the process. "Diagram matches what's happening on the line?" sits with Production rather than Food Safety, because the team that drew the flow diagram at a desk is the wrong judge of whether the floor still works the way the diagram says. The three-way "Significant hazard — CCP decision-tree outcome?" is the one that keeps CCP status a property of this product and this process rather than a label copied from the last plan — the same hazard can be the CCP on one line and a prerequisite-programme control on another, and which branch a step takes has to be argued from the analysis, not assumed from habit. "More process steps to assess?" loops the team through the whole process before a single limit gets set, because critical limits, monitoring and corrective actions only make sense once the full CCP list exists. "Verification confirms the CCPs and limits control the hazards?" can send the team back into the hazard analysis on its own finding, because a verification failure is a plan problem and shouldn't be fixed the way a single bad batch is fixed. And "Revalidation trigger since the last review?" closes the loop on a real event — a new ingredient, a line change, a regulatory update, a verification failure — rather than a date that happens to have arrived on the calendar.

What this flowchart covers

In this template

  • Four swimlanes (Food Safety, Production, Quality / QA and Management) across six phases — scope the plan, map the process, analyze hazards, set controls, verify and document, and approve and maintain — so the plan has a named owner at every stage, not only at sign-off
  • A "Diagram matches what's happening on the line?" check owned by Production, so a paper process flow diagram is corrected against the floor — an unlabelled rework loop, a hold cooler used as overflow storage — before the hazard analysis ever runs against it
  • A three-way "Significant hazard — CCP decision-tree outcome?" decision (not significant, controlled upstream, or the CCP itself) that keeps every CCP determination specific to this product and process, paired with a "More process steps to assess?" loop that carries the team through the whole process before any limit is set
  • Critical limits, monitoring procedures and corrective actions established only for the CCPs that decision produced, each one deliberately left as something the reader pulls from their own validated science, regulation or study rather than a figure this template asserts
  • A "Verification confirms the CCPs and limits control the hazards?" decision that can send the team back into the hazard analysis on its own finding, and a "Revalidation trigger since the last review?" decision at sign-off so the plan is reviewed on a real trigger rather than a routine renewal

When to use this template

  • You're writing a HACCP plan from scratch for a new product or process and need one picture of who does what, from assembling the team through to sign-off
  • A CCP list was set once, years ago, and nobody on the current team can point to the decision-tree reasoning behind why a given step is, or isn't, a CCP
  • Critical limits, monitoring records and corrective actions live in three places that don't obviously trace back to the same hazard analysis, and an auditor has started asking to see the connection
  • You need to show how the plan itself gets built and revalidated, as distinct from the monitoring records the plan generates once it's running against real production
  • A new ingredient, a line change, or a near-miss has made the current plan look stale, and you want a structured way to decide whether it actually needs revalidating rather than a hunch

How it works

  1. Rename the lanes to your own roles

    Replace Food Safety, Production, Quality / QA and Management with whoever genuinely does this work at your site. On a small operation the same person may sit in two lanes; merge them rather than drawing a handoff that never happens, but keep the steps in the order they're actually done.

  2. Write your own product description and intended use

    Name the actual product, its formulation, its shelf life and how it's expected to be stored, prepared and eaten — and by whom. A product aimed at infants, hospital patients or another vulnerable population carries a different bar for what counts as a significant hazard than one sold to the general public, so this step isn't a formality.

  3. Decide how your team applies the CCP decision-tree logic

    Agree the questions your team actually asks at the "Significant hazard — CCP decision-tree outcome?" step — whether a control measure exists at this step, whether it's necessary for safety, and whether a later step would catch what this one misses. Write the questions down once, so two team members reviewing the same hazard six months apart reach the same kind of reasoning, not necessarily the same answer for every product.

  4. Set limits, monitoring and corrective actions from your own validation, never from this chart

    For every CCP the decision-tree logic produces, pull the critical limit from validated science, a regulatory requirement or your own validation study for that specific product, ingredient and equipment. Do the same for the monitoring method, the frequency and the corrective action — none of it is transferable from another product without being re-validated for this one.

  5. Define what counts as a revalidation trigger for you

    List the events that should send the plan back through hazard analysis rather than straight to renewal: a new ingredient or supplier, a recipe or process change, new equipment, a hazard reported in the scientific literature, a regulatory update, or a verification finding. A plan revalidated only on a fixed calendar misses the trigger that actually matters.

  6. Name your documentation and record-keeping system

    State which forms exist, where the hazard analysis worksheet, the CCP list, the monitoring records and the verification records are filed, and how long each is kept. A plan that names no record system is a description of intent, not a working plan.

  7. Walk it against one real product's hazard analysis

    Take an existing hazard analysis worksheet or CCP list, including one CCP determination someone on the team disagrees with, and trace it through the chart. Anywhere the actual reasoning doesn't match a step here — a limit nobody can source, a verification nobody schedules — is the finding worth fixing before the next plan gets built the same way.

Frequently asked questions

What are the steps in building a HACCP plan?

The team is assembled, the product and its formulation are described, and the intended use and consumer are identified. The process is mapped as a flow diagram and then walked on the floor to confirm the diagram matches reality, correcting it if it doesn't. Hazard analysis runs step by step: each hazard is judged significant or not, and a significant one is run through the team's CCP decision-tree logic to determine whether the step is a CCP or is controlled elsewhere — a loop repeats this until every step is covered. For the resulting CCPs, the team establishes critical limits, monitoring procedures and corrective actions, then verification procedures and documentation requirements. A verification finding can send the team back into the hazard analysis before the plan goes to management for review and approval, which also checks whether anything since the last review — a new ingredient, a line change, a regulatory update — triggers revalidation rather than routine sign-off.

Is a HACCP plan legally required for my facility?

It depends heavily on what you make, where you manufacture and where you sell, so check the rule that actually applies rather than treat any one of these as universal. In the United States, most food facilities fall under FDA's Preventive Controls for Human Food rule (21 CFR Part 117), which requires a hazard analysis and risk-based preventive controls rather than naming HACCP specifically; meat and poultry products regulated by USDA are instead covered by mandatory HACCP systems under 9 CFR Part 417 (egg products fall under USDA's separate Egg Products Inspection regulations), and juice (21 CFR Part 120) and seafood (21 CFR Part 123) have their own HACCP-specific rules. In the EU, Regulation (EC) No 852/2004 Article 5 requires food business operators to put in place, implement and maintain procedures based on HACCP principles. Codex Alimentarius's General Principles of Food Hygiene (CXC 1-1969) and its HACCP annex are the internationally recognised reference most national rules and certification schemes (ISO 22000, FSSC 22000, BRCGS, SQF) build on, without themselves being a national law. Confirm the current text of whichever of these actually governs your product against your own regulatory affairs function.

What's the difference between a CCP and a prerequisite programme?

A prerequisite programme — sanitation, pest control, an allergen management program, supplier approval, calibration, staff hygiene — creates the baseline conditions a hazard analysis assumes are already working; it isn't monitored step by step against a critical limit the way a CCP is. A critical control point is a specific step where a hazard analysis and the team's CCP decision-tree logic conclude that control has to happen right there, with a measurable critical limit and continuous or scheduled monitoring, because nothing later in the process will catch a failure. The same real-world control can sit on either side of that line depending on the product and process: a cooking step is often a CCP because it's the last chance to eliminate a pathogen, while the supplier program that keeps raw material within spec is usually a prerequisite programme because it operates upstream of, and independently from, any single step on this chart. Getting the split wrong in either direction is a real risk — too few CCPs misses a hazard, too many makes a plan nobody can actually monitor.

How does this relate to CCP monitoring and a deviation?

This chart is where the critical limit, the monitoring method and the corrective action are decided; it stops before any of them are executed. Once the plan is approved, taking the scheduled reading, comparing it to the critical limit and recording the result is CCP monitoring, covered separately at /templates/ccp-monitoring-process — a shift-by-shift process, not a planning one. What happens when a reading actually falls outside the critical limit — containing the affected product, running the predetermined corrective action, and deciding its disposition — is a deviation, and it runs on its own record and its own escalation rather than looping back through this chart. This page only has to get the plan right; those two processes are what put it into practice.

Does building this chart mean our facility is HACCP-compliant or certified?

No, and no template can make that claim honestly. This chart is a process for building a documented plan; it names no critical control point, critical limit or monitoring frequency of its own, because all of those are specific to your product, your process and a hazard analysis this chart cannot perform for you. Certification against a GFSI-recognised scheme (FSSC 22000, BRCGS, SQF and others) or a regulator's acceptance of your plan depends on an audit or a review of the actual plan you build, including its validation evidence — not on having followed a template's structure. Use this chart as an adaptable starting point for authoring or documenting your plan, and have the finished plan reviewed by whoever owns your facility's food safety system before relying on it.

Use this template

More in Food & beverage manufacturing process templates

Browse all Food & beverage manufacturing process templates