Every food manufacturer knows the week before a BRCGS audit. Someone is in the office until eight at night pulling temperature logs out of ring binders, someone else is chasing a supplier approval certificate that expired in March, and there is always one traceability record that nobody can put a hand on. The standard itself is rarely the problem. Finding the evidence is.
With Issue 10 of the BRCGS Food Safety Standard now working its way through publication, this is a sensible moment to fix that properly. Here is where the revision stands, what auditors actually look for, and the records work that pays off whatever the final standard says.
Public consultation on Issue 10 closed in February 2026. BRCGS will publish the final standard, and a transition period will follow before audits switch across to it. Until that transition ends, Issue 9 remains the standard you are audited against - it was released in August 2022 and has been mandatory for all audits since 1 February 2023.
A word of caution here, because it matters. Until BRCGS publishes the final text, nobody outside the process knows exactly what Issue 10 requires. The commentary in circulation points towards greater emphasis on digitalisation, the use of AI, improved audit transparency and food safety culture, but that is direction of travel, not clause detail. Do not rebuild your systems around speculation. Build them around evidence you can retrieve, because that requirement is not going anywhere.
It is worth being clear about the job in front of the auditor, because it explains why so many non-conformances are really filing problems.
The auditor verifies two separate things. First, that the documentation exists and is current - the policies, the HACCP plan, the procedures, the records. Second, and this is the part that catches sites out, that what is documented is actually being done. A beautiful procedure with no completed records behind it is worse than useless; it is evidence of a system that is not being followed.
So when you cannot produce a record on request, the auditor is not just noting a missing piece of paper. They are being invited to conclude that the control might not have happened at all.
The specific list depends on your site and your scope, but the documents an auditor will routinely ask for look like this:
| Record | What it has to show |
|---|---|
| HACCP plan | Current, reviewed, with the hazard analysis and critical control points documented and justified. |
| Food safety policy | Signed, current, and communicated to staff. |
| Procedures and specifications | Version-controlled, with the current version in use on the floor - not an old print-out in a folder. |
| Supplier approval | Approval decisions, certificates and their expiry dates, plus ongoing performance monitoring. |
| Corrective actions | What went wrong, what was done, who signed it off and whether it worked. |
| Internal audits | A planned programme, actually completed to schedule, with findings closed out. |
| Traceability | A documented procedure and the ability to demonstrate it under test, both directions, within the time limit. |
| Training | Who was trained, on what, when, and evidence of competence. |
| Monitoring records | The daily reality - temperature logs, checks, calibration records - complete, legible and signed. |
BRCGS does not hand you a single retention figure, which is precisely why sites get it wrong. Records must be kept for a period appropriate to the shelf life of the product, plus whatever your customers contractually require on top. A long-life ambient product carries a materially longer retention period than a short shelf-life chilled line, and a major retailer customer will often impose its own minimum that exceeds both.
The requirement that trips people up is the next one: records must be stored securely and protected against loss, damage or unauthorised modification. Think about what that means for a pencil-completed temperature log in a folder in a damp corner of the despatch bay. Or for a spreadsheet on a shared drive that anyone can overwrite with no history. Neither can demonstrate it has not been altered.
If you want the wider picture on retention across the business, our guide to how long to keep business records in the UK covers the statutory periods that sit alongside your BRCGS obligations.
Most food manufacturers we speak to are not running a bad system. They are running a good system on bad infrastructure. The controls happen, the checks get done, the records get completed - and then they go into a binder where they are effectively invisible until someone spends three hours looking.
That gap produces a specific, avoidable category of non-conformance: the record existed, the control happened, and the site still lost marks because the evidence could not be produced in the room. It is a filing failure being scored as a food safety failure.
DocFlow does not replace your quality management system or your HACCP plan. What it does is hold the evidence behind them in a form an auditor can be walked through in seconds rather than hours.
Records are captured as they are produced - Aida can classify and index incoming documents such as supplier certificates automatically, so they are filed correctly without anyone deciding where they go. Retention rules are applied automatically against each record type. Workflow automation routes corrective actions and approvals so they are signed off and evidenced rather than chased. Every record carries a tamper-evident audit trail showing who touched it and when, which is exactly the protection against unauthorised modification the standard asks for. And when the auditor asks for the calibration certificate for a specific probe on a specific date, you search for it in front of them.
We work with food manufacturers on precisely this problem - see our food manufacturing document management page for how it fits a production environment, or our guide to document digitisation if you are still getting historical records out of paper.
Issue 10 will land when it lands. The sites that will find it straightforward are the ones that stopped storing their evidence in binders well before it did.
Issue 10 is the next revision of the BRCGS Food Safety Standard, the certification scheme most UK food manufacturers are audited against. Public consultation on the revision closed in February 2026. Once BRCGS publishes the final standard there will be a transition period before audits switch over to it, which is the window sites use to update their systems and documentation. Until then, Issue 9 remains the standard you are audited against.
Issue 9. It was released in August 2022 and has been mandatory for all audits since 1 February 2023. Issue 10 does not replace it until BRCGS publishes it and the transition period ends, so do not change your systems to match speculation about Issue 10 - get your Issue 9 evidence in order instead, because that is what carries forward.
An auditor verifies two things: that the documentation exists and is current, and that what is documented is actually being done. In practice that means your HACCP plan, food safety policy, procedures and specifications, supplier approval records, corrective action records, internal audit programme, traceability procedure, training records and the day-to-day monitoring records such as temperature logs - plus evidence that all of it is being followed.
BRCGS does not set one universal figure. Records must be kept for a defined period appropriate to the shelf life of the product plus any additional customer requirements, so a long-life ambient product will carry a longer retention period than a short shelf-life chilled one. The important thing is that your retention period is defined, documented and consistently applied rather than left to chance.
Yes, and increasingly they should be. The requirement is not that records are on paper, it is that they are secure, legible, retrievable and protected against loss, damage or unauthorised modification. A well-controlled electronic system meets that far more convincingly than a lever-arch file, because it can prove who changed what and when.
Do not wait for the published standard. The work that pays off regardless of what Issue 10 says is the same: make sure every required record is being captured, that you can retrieve any of them in seconds during an audit, that retention periods are defined and applied automatically, and that you have a tamper-evident audit trail. Sites that lose marks rarely lose them because the record did not exist - they lose them because nobody could find it.
See how DocFlow captures, retains and audit-trails every quality record, so your next BRCGS audit is a walkthrough rather than a scramble.