The Scope Model You Already Know — and the One You Don't
If your certification body operates primarily in management system standards like ISO 9001, ISO 14001, or ISO 45001, you are accustomed to EA codes. The European Accreditation framework defines 39 technical areas (EA 1 through EA 39), and your auditors hold qualifications mapped to those codes. Scope management means tracking which EA codes your CB is accredited for, which codes each auditor can cover, and ensuring the audit team assigned to a client has the right coverage.
This system is well understood. It is also completely inadequate for food safety certification.
Food Chain Categories: A Different Classification System
ISO 22000 and FSSC 22000 do not use EA codes to classify the scope of certification. Instead, they use food chain categories. These categories describe the organization's position in the food chain and the nature of its activities:
- •Category A: Farming (animal)
- •Category C: Food processing (perishable animal products)
- •Category D: Food processing (perishable plant products)
- •Category E: Food processing (ambient stable products)
- •Category F: Feed production
- •Category G: Catering
- •Category I: Packaging material manufacturing
- •Category K: Biochemicals
Each category has distinct characteristics that affect audit planning. A Category C organization (a meat processing plant) presents different food safety hazards than a Category I organization (a packaging manufacturer). The auditor needs to understand not just ISO 22000 requirements but the specific food safety risks and regulatory environment of that category.
FSSC 22000 Adds Another Layer
Many CBs certify against FSSC 22000, a GFSI-benchmarked scheme built on top of ISO 22000. FSSC adds its own requirements that compound the scope management challenge:
- •Prerequisite program specifications: FSSC 22000 requires compliance with specific prerequisite program standards (ISO/TS 22002-1 for food manufacturing, ISO/TS 22002-4 for packaging, etc.) depending on the food chain category. The CB must track which prerequisite standard applies to each client.
- •Scheme-specific audit requirements: FSSC mandates additional audit elements beyond ISO 22000, including food defense, food fraud vulnerability assessments, and allergen management. These requirements vary by category.
- •Auditor competence requirements: FSSC has its own auditor qualification criteria tied to food chain categories. An auditor qualified for Category C may not be qualified for Category E. The CB must track FSSC-specific competence alongside general ISO 22000 competence.
Consider a CB like Meridian Food Safety Certification. They certify clients across five food chain categories under both ISO 22000 and FSSC 22000. For each client, they must track: the food chain category, whether the certification is ISO 22000 or FSSC 22000 (or both), which prerequisite program standard applies, which auditors are qualified for that specific category under the applicable scheme, and how the audit time is calculated for that category.
Category-Specific Audit Time Rules
Audit time calculation in food safety certification is not a simple lookup in the MD 5 tables. Food chain categories introduce their own variables:
- •Category complexity: Some categories require longer audit times due to the complexity of food safety hazards. A multi-product food processing facility in Category E may require significantly more time than a single-product operation in the same category.
- •Number of HACCP plans: Unlike management system audits where scope is the primary time driver, food safety audits must account for the number of HACCP plans the organization maintains. More product lines typically mean more HACCP plans and more audit time.
- •Seasonal production: Some food chain categories involve seasonal production. The audit must be timed to observe active production, which constrains scheduling.
- •Multi-category organizations: An organization may operate across multiple food chain categories — for example, a company that both processes and packages food products. The audit must cover all applicable categories, and the team must have competence across all of them.
Where Generic Scope Models Break Down
A CB that manages food safety certifications alongside management system certifications faces a fundamental data modeling problem. The scope system used for ISO 9001 (EA codes) is structurally different from the scope system used for ISO 22000 (food chain categories). A platform that models scope as a single list of EA codes cannot represent food chain categories without workarounds.
Common workarounds include:
- •Repurposing EA codes: The CB maps food chain categories to EA code fields, creating a confusing hybrid where "EA 3" might mean one thing for ISO 9001 clients and something else for ISO 22000 clients. This breaks reporting and auditor qualification matching.
- •Free-text fields: The CB enters food chain categories in notes or description fields. This preserves the information but makes it unsearchable, unvalidatable, and invisible to auditor assignment logic.
- •External spreadsheets: The CB maintains a separate spreadsheet for food safety scope data. This creates a dual system with all the synchronization problems that implies.
None of these approaches work at scale. When a planner at Meridian needs to find an auditor qualified for FSSC 22000 Category D in a specific region, they need the system to understand what Category D means, which auditors hold that qualification, and whether those auditors are available.
How Certiva Handles Food Chain Categories
Certiva treats food chain categories as a distinct scope classification system, separate from and parallel to EA codes. This means:
- •Each standard uses its own scope model. When a client is certified against ISO 22000 or FSSC 22000, the scope record uses food chain categories. When the same client holds an ISO 9001 certification, that scope uses EA codes. Both exist in the system without conflict.
- •Auditor qualifications are mapped to food chain categories. An auditor's competence profile includes their qualified food chain categories, tracked separately from their EA code qualifications. The planner can filter auditors by food chain category when building an audit team for a food safety engagement.
- •Audit time calculations account for category-specific rules. Certiva's deterministic audit time calculator applies the correct calculation method based on the standard and category, including adjustments for HACCP plan count and multi-category operations.
- •FSSC scheme requirements are tracked per client. The system knows whether a client is certified under ISO 22000 alone or under the FSSC 22000 scheme, and applies the appropriate prerequisite program standard and audit requirements.
The Operational Impact
For CBs like Meridian that operate across both management system and food safety standards, having a unified platform that correctly handles both scope systems eliminates an entire category of operational risk. Auditor assignments are validated against the right qualification framework. Audit times are calculated using the right methodology. Scope records are accurate and searchable.
Food safety certification is complex enough without the software making it harder. The scope model should match the reality of how food safety standards classify organizations — and that means supporting food chain categories as a first-class concept, not an afterthought.