When your food business completes an IFS audit, the final report contains sensitive information about your operations, non-conformities, and corrective actions. Understanding who owns this report and how it should be distributed is critical for maintaining confidentiality while meeting transparency requirements with your clients and certification bodies.

Table of Contents

Who owns the IFS audit report?

The audit report belongs to the audited company. This ownership structure ensures that businesses maintain control over sensitive operational details, proprietary information, and findings that could be commercially sensitive. Unlike public records, these reports contain details on findings and corrective actions that are specific to your facility’s performance and compliance status.

This ownership principle protects your business in several important ways. First, it prevents unauthorized access to your operational details and food safety practices. Second, it gives you control over who sees information about any non-conformities identified during the audit. Third, it allows you to manage how your audit performance is communicated to different stakeholders.

How IFS audit reports are distributed

While you own the report, distribution isn’t entirely at your discretion. The final audit report is distributed to relevant stakeholders within your organization and possibly shared with clients, depending on your agreements. The certification body that conducted your audit also maintains records as required by accreditation standards.

Internal distribution requirements

Within your organization, the audit report should be accessible to key personnel who need to understand audit findings and implement corrective actions. This typically includes quality assurance managers, food safety teams, senior management, and department heads responsible for areas where non-conformities were identified. The report must be securely stored to maintain transparency and facilitate future audits.

External sharing considerations

Sharing your IFS audit report with external parties requires careful consideration. In the food industry, it’s increasingly common for clients and potential customers to request full audit reports rather than just certificates. In the UK particularly, sharing complete reports has become routine practice, with some customers receiving direct access to reports simultaneously with the audited company.

However, you’re not obligated to share your full report with every party that requests it. Many businesses choose to share only their certification status and score with prospective clients initially, providing the complete report only when necessary for business relationships. Some companies opt for on-site review only, allowing interested parties to examine the report at their facility rather than distributing copies.

Managing confidential information in audit reports

IFS audit reports often contain information that businesses reasonably consider confidential. This might include specific production processes, formulations, supplier relationships, or detailed descriptions of security measures. The challenge lies in balancing transparency with protection of proprietary information.

When third-party auditors conduct IFS assessments, certification bodies and auditees must sign agreements covering data security and confidentiality. These agreements establish the ground rules for how sensitive information will be handled throughout the audit process and in the resulting reports.

The IFS database and controlled access

The IFS database provides a structured system for managing audit information. Certification bodies upload reports to this database, where access is controlled and limited to authorized parties. This system helps maintain confidentiality while ensuring that certification status can be verified by legitimate stakeholders such as retailers and food service companies.

Companies can designate which users have access to their information in the database, providing another layer of control over report distribution. This digital infrastructure supports both confidentiality and verification needs in modern food supply chains.

Your contracts with clients, retailers, or distributors may include specific clauses about audit report sharing. Some agreements explicitly require you to provide full audit reports upon request, while others may only require certificate sharing. Review these contractual obligations carefully to understand your legal responsibilities.

When negotiating new contracts, consider including clear language about what audit information will be shared, how often, and under what circumstances. Some businesses successfully negotiate non-disclosure agreements to protect sensitive information when full reports must be shared.

Best practices for audit report management

Develop a clear internal policy for audit report distribution that addresses who internally can access reports, how long reports should be retained, what security measures protect stored reports, and under what circumstances reports will be shared externally. This policy should align with your broader data protection and information security protocols.

Establish a decision-making framework for external sharing requests. Consider factors such as the requesting party’s legitimate business need, your contractual obligations, whether a non-disclosure agreement is in place, and what competitive or security risks might arise from sharing.

Communicate transparently with potential clients about your audit performance and certification status. Many businesses find that being open about their commitment to food safety builds trust, even if they choose not to share complete reports initially. Consider offering alternatives such as summary reports highlighting key compliance areas, facility tours for serious prospects, or on-site report review for qualified parties.

Handling requests from customers and regulators

When customers request your audit report, respond professionally and promptly. Acknowledge their request, explain your company’s policy on report sharing, and offer alternatives if you’re not comfortable sharing the complete report immediately. Many customers will accept a certificate and score initially, with full report access granted once a business relationship is established.

Regulatory authorities may have different rights to access audit reports depending on jurisdiction and circumstances. Legal requirements for disclosure to government agencies typically override confidentiality concerns. Consult with legal counsel when facing regulatory requests to ensure compliance with applicable laws while protecting your interests to the extent possible.

Maintaining audit report integrity

However you choose to distribute your audit reports, maintaining their integrity is essential. Never alter, redact, or selectively edit audit reports before sharing them. If you share a report, share it complete and unchanged. Tampering with audit documentation undermines the entire certification process and could result in certificate withdrawal.

Similarly, ensure that shared reports are current and reflect your most recent audit results. Sharing outdated reports, even inadvertently, misrepresents your current compliance status and creates confusion in your business relationships.

What do you think? How does your organization balance transparency with the need to protect confidential information in IFS audit reports? Have you found effective ways to satisfy customer requests while maintaining appropriate control over sensitive operational details?

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://goaudits.com/blog/ifs-audits/
  2. https://www.ifsqn.com/forum/index.php/topic/36455-potential-clients-asking-for-the-entire-audit/
  3. https://www.ifs-certification.com/images/ifs_documents/IFS_Broker_v3.2_remote_audit_protocol_v3_EN.pdf

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Food Safety and Quality Management Systems

1 Introduction to Management systems

  1. Introduction to ISO 9001
  2. ISO 9000
  3. Introduction to ISO 14001:2004
  4. How to Use ISO 14001
  5. Introduction to OHSAS 18001:2007
  6. How to Use OHSAS 18001:2007
  7. Introduction to ISO/IEC 27001
  8. The PDCA Model

2 Auditing

  1. Clause 1 – Scope of the Standard
  2. Clause 2 – Normative References
  3. Clause 3 – Terms and Definitions
  4. Clause 4 – Principles of Auditing
  5. Clause 5 – Managing an Audit Program
  6. Clause 6 – Audit Activities
  7. Clause 7 – Competence and Evaluation of Auditors

3 Standardization and Accreditation

  1. International Accreditation Forum (IAF)
  2. International Laboratory Accreditation Cooperation (ILAC)
  3. Quality Council of India (QCI)
  4. National Accreditation Board for Testing and Calibration Laboratories (NABL)
  5. ISO/TS 22003:2007 Food Safety Management System
  6. ISO Guide 65: General Requirements for Bodies Operating Product Certification Systems
  7. ISO/IEC 17020:1998 General Criteria for the Operation of Various Types of Bodies Performing Inspections
  8. ISO/IEC 17021:2006 – Conformity Assessment-Requirements for Bodies Providing Audit and Certification of Management Systems
  9. ISO 17025:2005 General Requirements for the Competence of Testing and Calibration Laboratories

4 ISO 9001-2000 – An Overview

  1. ISO 9000
  2. Quality Management Principles
  3. ISO 9000:2005, Quality Management Systems: Fundamentals and Vocabulary
  4. ISO 9001:2000, Quality Management Systems: Requirements
  5. Steps for Implementing Quality Management Systems
  6. Benefits of ISO 9001:2000
  7. ISO 9004:2000, Quality Management Systems: Guidelines for Performance Improvements
  8. Relationship with ISO 9001:2000
  9. Self-assessment Model

5 ISO 9001-2000 – Structure

  1. Documentation Structure of ISO 9001:2000
  2. Quality Manual
  3. Mandatory Procedures
  4. Standard Operating Procedures (SOPs)
  5. Process Definition Documents
  6. Work Instructions
  7. Miscellaneous Documents
  8. Formats and Records
  9. ISO 9001:2000 Clauses

6 Clause wise interpretation of ISO 9001-2000

  1. Clause 1: Scope
  2. Clause 2: Normative Reference
  3. Clause 3: Terms and Definitions
  4. Clause 4: Quality Management System
  5. Clause 5: Management Responsibility
  6. Clause 6: Resource Management
  7. Clause 7: Product Realization
  8. Clause 8: Measurement, Analysis and Improvement

7 ISO 9001-2000 – Case Studies

  1. Engineering Job Work Organisation
  2. Software Development Organisation
  3. Management Review in Engineering
  4. Customer-Related Processes in Software
  5. Internal Audits in Engineering
  6. Design and Development in Software
  7. Corrective and Preventive Actions in Software
  8. Customer Property Management in Engineering

8 ISO 22000-2005 – An Overview

  1. What Does ISO 22000 Bring to the HACCP Method?
  2. System Components
  3. Communication between Participants in the Food Industry
  4. ISO 22000: A Passport for Exporting?
  5. Why do Companies Commit themselves to an ISO 22000 Approach?
  6. Who Should Use ISO 22000:2005?
  7. Why Use ISO 22000:2005?
  8. ISO 22000 and HACCP
  9. Codex Alimentarius
  10. Key Elements and Benefits of ISO 22000

9 ISO 22000-2005 – Structure

  1. Economic Loss due to Food Borne Illness
  2. ISO 22000: 2005 Clauses
  3. FSMS Documentation Structure
  4. Food Safety Team Structure
  5. Food Safety Manual
  6. Mandatory Procedures
  7. Standard Operating Procedures (SOP)/Work Instructions
  8. HACCP Pre-steps Related Documents
  9. HACCP Principles Related Documents
  10. Miscellaneous Documents
  11. Formats and Records

10 Clause-wise interpretation of ISO 22000- 2005

  1. Clause 1: Scope
  2. Clause 2: Normative References
  3. Clause 3: Terms and Definitions
  4. Clause 4: Food Safety Management System
  5. Clause 5: Management Responsibility
  6. Clause 6: Resource Management
  7. Clause 7: Planning and Realization of Safe Products
  8. Clause 8: Validation, Verification and Improvement of the FSMS

11 ISO 22000-2005-Case Studies

  1. Kick-off meeting
  2. Introduction to the standard
  3. Formation of food safety team
  4. Description of product and its intended use
  5. PRP (Pre-requisite programme)
  6. Flow diagrams, process steps and control measures
  7. Control measure assessment
  8. Verification of food safety management system
  9. Traceability system
  10. External communication
  11. Internal communication
  12. Management Reviews

12 An Overview and Requirements of ISO 17025

  1. Introduction to the ISO/IEC 17025 Standard
  2. Scope of ISO/IEC 17025
  3. Normative References
  4. Terms and Definitions
  5. General Requirements
  6. Structural Requirements
  7. Resource Requirements
  8. Process Requirements
  9. Management System Requirements

13 Requirements specific to Food testing laboratories – Physical and chemical Parameters

  1. Introduction
  2. Quality and Safety Requirements of Food Products
  3. Chemical and Physical Testing Requirements of Food Products
  4. Laboratory Quality Management System
  5. Management Requirements (Clause 4 of ISO 17025)
  6. Technical Requirements (Clause 5 of ISO 17025)
  7. Traceability of Measurement
  8. Sampling
  9. Handling Test and Calibration Items
  10. Assuring the Quality of Test and Calibration Results

14 Requirements specific to Food testing laboratories – Biological parameters

  1. Introduction
  2. Quality and Safety Requirements of Food Products
  3. Biological Testing Requirements of Food Products

15 General topics- related to Food testing laboratories

  1. Method Validation
  2. Ruggedness
  3. Uncertainty of Measurement
  4. International Accreditation Aspects

16 BRC Food and BRC/IOP Standards – An Overview

  1. BRC Global Standard – Food (Issue 5, January 2005)
  2. Introduction to BRC Food Standard
  3. Legislative Requirements
  4. Benefits of the BRC Global Standard – Food
  5. Principles of the BRC Global Standard – Food
  6. The Standard Technical Advisory Committee
  7. Scope of the BRC Global Standard – Food
  8. The Format of the BRC Global Standard – Food
  9. Application
  10. Structure and Interpretation of the Standard
  11. BRC / IOP Global Standard Issue 3 2001 (Food Packaging and Other Packaging Materials)
  12. IOP: The Institute of Packaging
  13. BRC/IOP Relationship
  14. Benefits of BRC/IOP Packaging Standard
  15. Principles of BRC/IOP Packaging Standard
  16. Application
  17. Structure of BRC / IOP Global Standard – Food Packaging and Other Packaging Materials

17 International Food Standard

  1. Background of the IFS
  2. Service Protocol of the IFS ISSUE 5
  3. Contractual Arrangements – Selection of Certifying Body
  4. Audit Notification
  5. Scope of the Audit
  6. Audit Flow – Preparing the Audit Plan
  7. Level Determination – KO, Major NC’s, NA
  8. Scores, Issuing the Audit Report and Certification
  9. Audit Frequency
  10. Audit Report
  11. Awarding of Certificate
  12. Distribution of the Audit Report
  13. Supplementary Action
  14. Appeal Procedure
  15. Complaints
  16. IFS – Catalogue of Requirements
  17. Management of Quality System
  18. Management Responsibility
  19. Resource Management
  20. Product Realization
  21. Measurements, Analysis and Improvements
  22. Requirements for Certification Bodies and Auditors
  23. Report

18 SQF 1000 And SQF 2000

  1. SQF 1000
  2. Interpretation of SQF 1000 Standard
  3. SQF 2000
  4. Interpretation of SQF 2000 Standard
  5. Let Us Sum Up

19 Global GAP and India GAP

  1. Potential Benefits and Challenges Related to Good Agricultural Practices (GAP)
  2. Description of the FAO/GAPs
  3. USDA GAP/GHP Programme
  4. Global GAP
  5. India GAP