Food safety audits come in several distinct forms that are frequently conflated. A certification audit produces a decision and is conducted by an accredited certification body. An internal audit is a required element of most management systems and is conducted by your own trained auditors. A second-party audit is conducted by or for a customer. A consulting audit produces a work plan.
SURU Compliance conducts the last of those, plus supplier and co-manufacturer audits on your behalf, internal audits alongside your team, and pre-assessment audits under audit conditions. We are not a certification body and cannot certify anything.
The audit types we run
Which audit you need depends on what decision it has to support — a corrective action plan, a supplier approval, a certification date, or a customer response.
- GMP / CGMP audit against 21 CFR Part 117 Subpart B, a certification standard, or a customer requirement
- Pre-assessment audit against the current issue of the certification standard, run under audit conditions with an opening and closing meeting
- Internal audit support, including training your auditors and running the first cycle with them
- Supplier and co-manufacturer audits performed on your behalf, with a report you can put in your approval file
- Mock FDA inspection, including document requests and interview-style questioning
- Mock health department inspection against the food code edition your jurisdiction has adopted
- Environmental monitoring and sanitation program assessment, including zone mapping and site selection review
What a useful audit report looks like
Each finding should state the requirement, the objective evidence observed, and the gap between them — in that order. A finding written as an opinion invites an argument about methodology; a finding written with evidence invites a correction.
Findings should then be ranked by food safety significance and regulatory or certification exposure, not by how easy they are to fix. Reports padded with cosmetic observations are easy to produce and very hard to act on, and they train people to skim.
Finally, a report should distinguish between a system gap and an execution gap. A missing procedure and a procedure that exists but is not followed require different corrective actions, and confusing the two produces the endless retraining cycle that never resolves anything.
Why independence changes the result
Internal audits conducted by someone who manages the same operators tend to soften over time. It is not dishonesty; it is the ordinary consequence of an ongoing working relationship. Findings get discussed rather than written, and severity drifts downward.
Independence also enables calibration. Where we run multi-site programs, we use one instrument with defined severity definitions and calibrated auditors, so a score in one location means the same as the same score in another. Without that, multi-site audit data cannot support a decision about where to spend money or attention.
One caution worth stating: an audit is a sample taken at a point in time. A clean audit is evidence, not a guarantee, and a firm that presents it as proof of ongoing compliance is overselling. We do not promise audit outcomes or certification results — those decisions belong to auditors and certification bodies.
SURU Compliance is an independent regulatory consulting practice. We are not the FDA or any other government agency, not a certification body or accredited certifying entity, and not a law firm. We do not provide FDA approval, guaranteed inspection or audit outcomes, or legal advice, and we refer legal matters to qualified counsel. Regulatory applicability depends on your specific products, processes, size and jurisdiction.
