The Food Safety Modernization Act shifted the regulatory question from whether contamination occurred to whether you can demonstrate you prevented it. In practice it produced a set of distinct rules, each with its own scope, exemptions and recordkeeping obligations — and most businesses are subject to some of them rather than all.
Consulting on FSMA therefore starts with allocation, not construction. A distributor holding unexposed packaged food, a manufacturer of ready-to-eat product, and an importer of a single ingredient have almost nothing in common under these rules.
The rules and who they reach
Each of the major FSMA rules answers a different question, and each carries its own exemption structure. Applicability depends on your activities, your products, your size, and in some cases your customers.
- Preventive Controls for Human Food (21 CFR Part 117) — CGMP and the risk-based food safety plan for registered facilities, with qualified facility modified requirements available in some cases
- Foreign Supplier Verification Programs (21 CFR Part 1 Subpart L) — the importer's obligation to verify foreign suppliers
- Produce Safety (21 CFR Part 112) — standards for growing, harvesting, packing and holding produce for human consumption
- Sanitary Transportation of Human and Animal Food (21 CFR Part 1 Subpart O) — obligations for shippers, loaders, carriers and receivers
- Mitigation Strategies to Protect Food Against Intentional Adulteration (21 CFR Part 121) — food defense vulnerability assessment for covered facilities
- Accredited Third-Party Certification (21 CFR Part 1 Subpart M) — the accreditation framework supporting certain import programs
- Additional Traceability Records for Certain Foods (21 CFR Part 1 Subpart S, commonly called FSMA 204) — recordkeeping for foods on the Food Traceability List
Where FSMA programs commonly fall short
The recurring pattern is a plan that has drifted from the operation. New equipment, a new supplier, a rework loop, a line-speed change or a new product all alter the hazard picture, and plans reassessed only annually are frequently describing last year's plant. Reassessment triggers should be written into the plan and owned by someone.
The second pattern is a supply-chain program in name only. Where a hazard requiring a preventive control is controlled before receipt, Subpart G requires supplier approval and verification activity — not a certificate of analysis filed without a program around it.
The third is validation confused with verification. Immaculate monitoring records against a critical limit that was never justified is a specific and recognisable failure. A critical limit needs a citable basis: a regulatory requirement, agency guidance, a process authority letter, applicable literature, or a study on your product.
How we scope FSMA work
We start with a written applicability determination covering each rule against your operation, then a gap assessment against the ones that apply. Findings are ranked by food safety significance and regulatory exposure, each with an owner, an artefact and a date.
From there the work is ordinary but exacting: verify the process flow on the floor, build or rebuild the hazard analysis, establish preventive controls with defensible limits, construct the records so a reviewer can follow a lot end to end, and train the people who will maintain it. Where a requirement does not apply to you, we document why rather than building it anyway.
SURU Compliance is an independent regulatory consulting practice. We are not the FDA or any other government agency, not a certification body or accredited certifying entity, and not a law firm. We do not provide FDA approval, guaranteed inspection or audit outcomes, or legal advice, and we refer legal matters to qualified counsel. Regulatory applicability depends on your specific products, processes, size and jurisdiction.
