Skip to main content

SQF Edition 10 audits start January 2027. Is your program ready? Learn more →

Back to Insights

Guides · Sep 24, 2026 · 9 min read

Edition 10 Wants Every Corrective Action Traced. Most Programs Can't.

SQF Edition 10 makes corrective action a core clause and writes out the chain it expects: correction, root cause method, action, verification of effectiveness, communication. Element 2.5.3.1 lists nine things that have to feed it, and internal audits, complaints, and CCP deviations all route into it. The audit test is pulling one finding and asking where it went. A ten-finding trace test on last year's internal audit report shows where the thread breaks.

SM
Steven Moussawer Founder

SQF Edition 10 makes corrective action a core clause and writes out the chain it expects: a correction, a documented root cause method, an action aimed at that cause, verification that the action worked, and communication of the result. The audit test is one question. An auditor pulls a single internal audit finding and asks where it went. A program that keeps the finding in one file and the action in another can't answer that in one pass.

The clause changed its name, and the name is the argument

In Edition 9, element 2.5.3 was Corrective and Preventative Action. In the Edition 10 Food Manufacturing code it reads Corrections, and Corrective and Preventative Action, and SQFI lists it as a Core Clause.

Core Clause is a scoring designation. On the Edition 10 scale a minor costs one point and a minor against a core clause costs two. A major costs five and a core clause major costs seven. A critical costs fifty. Corrective action sits on that core clause list alongside the food safety plan (2.4.3), environmental monitoring (2.4.8), allergen management (2.8.1), product identification (2.6.1), and complaint management (2.1.3).

Edition 10 audits begin as early as January 2, 2027, and SQFI's Edition 10 FAQ states they won't commence any earlier than that date. The start depends on the GFSI benchmarking application and may move later. As of September 2026, Edition 9 is still the code being audited.

What changed is that the procedure is now written out. Element 2.5.3.1 requires the documented method to include, at a minimum:

i. Use of corrections, as applicable, to address the identified issue; ii. Method(s) of analysis used to investigate and identify the root cause; iii. Process for determining and implementing the corrective and preventative actions needed to address the root cause; iv. Verification of effectiveness of the implemented actions to prevent reoccurrence; and v. Communication of results to relevant site management and personnel.

The glossary SQFI posted for Edition 10 keeps the definitions the industry already works from. A correction is "action to eliminate a detected non-conformity." A corrective action is one "based on a root cause analysis with the intent to eliminate the cause of a non-conformity and prevent its recurrence." Edition 10 promotes the correction to step one of a five-step procedure, so the immediate fix and the root-cause fix become two entries with two dates.

SQFI's vice president of technical affairs framed the edition as built to help sites "demonstrate, not just describe" their commitment to food safety. For 2.5.3, that means the record has to run from the finding to the verified fix.

One word changed in the verification step

Edition 9 asked that corrective and preventative actions be "determined, implemented, and verified." Edition 10 asks for "verification of effectiveness of the implemented actions to prevent reoccurrence."

Verifying that an action happened and verifying that it worked are two records with two dates. Most CAPA logs carry the first one. A date in a closed column tells an auditor somebody did the task, not that anyone came back later and checked that the problem stopped.

The second record also needs time to pass. You retrain the crew in October and you find out whether the finding recurred by watching the same check through November and December. Closed corrective action loops belong in the pile of Edition 10 evidence that has to accumulate, which is the sorting exercise in the records you can't backfill.

The list of what feeds the process got longer and lost its hedge

Edition 9 said deviations from food safety requirements "may include" four categories, "as appropriate." Edition 10 says what the procedure covers "shall include, but not be limited to" nine.

Edition 9, element 2.5.3.1: "Deviations from food safety requirements may include customer complaints, nonconformances raised at internal or external audits and inspections, non-conforming product and equipment, withdrawals and recalls, as appropriate."

Edition 10, element 2.5.3.1: "These shall include, but not be limited to, deviations of critical food safety limits, complaints, findings at internal and external audits and inspections, non-conforming product and equipment, deficiencies found during annual tests and reviews, verification and validation activities, withdrawals and recalls, and regulatory infractions, and negative trends of the food safety system."

Four entries are additions to the Edition 9 list. (Critical food safety limits were already in Edition 9's own sentence, just before its list.) Deficiencies found during annual tests and reviews covers the mock recall that ran long, the trace test that lost a step, the food defense test, the crisis management test. Verification and validation activities covers the verifier who signed a monitoring record and noted the form was incomplete. Regulatory infractions covers the inspection report sitting on somebody's desk. Negative trends covers the pattern nobody wrote up because no single instance crossed a threshold.

All four get recorded somewhere at most sites. Almost none of them produces a corrective action record.

Environmental monitoring is a core clause of its own at 2.4.8, and a positive result is exactly the kind of issue 2.5.3 exists to catch. Cleaning the area and re-swabbing is a correction. Edition 10 wants the root cause behind the positive and the change that came out of it, which is the same argument running through environmental monitoring under Edition 10.

Contracted services reach the list through internal audit findings. A sanitation vendor's service log is the vendor's record of work performed. A finding against your sanitation program still needs your root cause in your own 2.5.3 record, which is the gap between what vendors hand you and what an audit counts as evidence.

The cross-references already existed. Edition 10 changed what travels along them

Edition 9 already pointed internal audits and complaints at 2.5.3 by number. What has to travel along those references changed, and the CCP deviation clause picked up the same language.

Internal audits (2.5.4). Edition 9 required corrective and preventative actions "of deficiencies identified during the internal audits." Edition 10 requires "root cause analysis, corrections, and corrective and preventative actions for deficiencies or trends indicating potential deficiencies, identified during the internal audits," undertaken according to 2.5.3. The trend half is the addition. Three small repeat findings across three internal audits may form a trend indicating a potential deficiency, and that trend has to enter the 2.5.3 process on its own. The communication item names a recipient with a job: audit results go to personnel "responsible for implementing and verifying the effectiveness of actions taken according to 2.5.3."

Complaints (2.1.3). Complaint management is a core clause in Edition 10. Element 2.1.3.2 requires that "root cause analysis and the corrective action process shall be completed for all adverse trends and serious incidents as outlined in 2.5.3." Edition 9 required root cause on adverse trends and corrective action "based on the seriousness of the incident." Serious incidents are now named alongside adverse trends.

CCP deviations (2.4.3). Edition 9 said deviation procedures "shall also prescribe actions to correct the process step to prevent recurrence of the safety failure." Edition 10 says they "shall include root cause analysis, corrections, and corrective and preventative actions to correct the process step to prevent recurrence of the safety failure." Same sentence, three items inserted: root cause analysis, corrections, and corrective and preventative actions.

Two more clauses read your corrective action records rather than feed them. Element 2.1.2.2 requires the monthly update to site management to include corrections and corrective and preventative actions, results from internal and external audits, and food safety complaints. Change management at 2.3.5.1 covers changes "made as a result of the corrective action process," so an action that alters a process routes back through change control and has to be confirmed or validated there.

Spreadsheets hold both ends and drop the join

The finding gets recorded. The action gets recorded. The key that joins them lives in somebody's head. Six places the thread breaks:

  • The internal audit report numbers its findings one way and the CAPA log numbers its actions another. Nothing carries the first number into the second, so the only join is a person who remembers.

  • One action absorbs three findings, or three actions come out of one finding. Neither direction survives a pull test.

  • The root cause column holds a category instead of a method. "Operator error" is a category. Element 2.5.3.1 ii asks which method of analysis produced it, which means the procedure names the method you use (five whys, fishbone, fault tree) and the record shows it applied to this finding, with the answers written down.

  • The closed column holds a date. It doesn't hold a verifier, a verification date, or the evidence that person checked.

  • Communication of results lives in a sent-items folder that belongs to neither record.

  • Complaints live in a third system, usually customer service, so the 2.1.3.2 pointer into 2.5.3 has no route at all.

Run the ten-finding trace test

Pull last year's internal audit report, pick ten findings, and give yourself two minutes per finding to produce six things.

  1. The finding as written, with its date.

  2. The correction taken, and when.

  3. The root cause, and the method used to reach it.

  4. The corrective or preventative action, its owner, and its due date.

  5. The verification of effectiveness: who performed it, on what date, against what evidence.

  6. Where the result was communicated, and to whom.

Then run it backward. Pick three corrective actions out of the log and name what triggered each one. An action with no source is as much a gap as a finding with no action.

Then run it for coverage. Read the nine sources listed in 2.5.3.1 and mark the ones with no route into your process at all. Annual tests, verification activities, and negative trends are the three that usually sit outside it.

Score which of the six steps drops out, and use the missing step to choose the repair. It's almost always step three and step five, and those are the two Edition 10 wrote out longhand.

The changeover timing for a site depends on its audit schedule, so confirm your Edition 10 timing with your certification body. Then work out how many complete finding-to-verification cycles will exist by that date. For the clause-by-clause view of everything else that moved, what changed in Edition 10 covers the rest, and our Edition 10 services cover the gap assessment itself.

This is the practical case for keeping findings, actions, and verifications in one record instead of three files. In Beacon an audit finding creates a CAPA that carries the finding's own number, an owner, and an investigation due date. People record the root cause and the effectiveness verification, and a closure approval gate controls the final close.

Run the trace test on last year's report first. It takes twenty minutes and it tells you which step your program is missing. If you want to see the whole chain come out as one record, book a call.

Run a food safety program? See how Beacon keeps it audit-ready.

See Beacon in 20 minutes