How do you document contamination control measures for a BRC audit?

Quality technician in white coat reviewing compliance documents on clipboard inside a pharmaceutical cleanroom with stainless steel surfaces.

To document contamination control measures for a BRC audit, you need a structured set of written procedures, completed records, and a risk-based rationale that demonstrates your facility actively manages contamination risks at every critical point. BRC Global Standards, now operating under BRCGS, require documented evidence, not just verbal assurances, that contamination controls are in place, monitored, and regularly reviewed. The sections below address the most common documentation questions facilities face when preparing for a BRC food safety audit.

What records are required for contamination control under BRC standards?

BRC audit contamination control requirements centre on three categories of documentation: written procedures that describe what controls exist, completed records that prove those controls were carried out, and corrective action logs that show how deviations were handled. Together, these form the evidential backbone auditors will examine during a BRC food safety audit.

At a minimum, your contamination control records should include:

  • Cleaning and disinfection schedules for controlled zones and entry points
  • Personnel hygiene and gowning logs
  • Inspection or monitoring records for physical barriers such as mats, airlocks, and footbaths
  • Pest control records where applicable
  • Foreign body and allergen control documentation
  • Supplier assurance records for any materials entering controlled areas
  • Corrective action and non-conformance reports linked to contamination events

Each record must be traceable, dated, and signed by the responsible person. Auditors look for consistency between what your procedures say should happen and what your records show actually happened. Gaps between these two are one of the most frequently cited non-conformances in BRC contamination control audits.

How should contamination risk assessments be structured for a BRC audit?

A contamination risk assessment for a BRC audit should be structured as a formal, written document that identifies potential contamination hazards by type (microbiological, physical, chemical, and allergen), evaluates the likelihood and severity of each hazard, and assigns control measures with clear ownership and review dates.

The assessment should follow a logical sequence that auditors can trace from hazard identification through to control verification. A well-structured BRC contamination risk assessment typically includes:

  • Scope definition: which areas, processes, and product categories are covered
  • Hazard identification: categorised by contamination type and source
  • Risk evaluation: using a likelihood-versus-severity matrix or equivalent scoring method
  • Control measures: specific actions assigned to named roles or departments
  • Residual risk rating: confirmation that controls reduce risk to an acceptable level
  • Review schedule: documented dates for periodic reassessment

The risk assessment must be reviewed whenever there is a significant change to the facility, process, or product range. Auditors will check that the document is live and current, not a static file that was written once and never revisited.

What is the difference between a contamination control procedure and a contamination control record?

A contamination control procedure is a written instruction that describes how a control measure should be carried out, by whom, and how often. A contamination control record is the completed evidence that the procedure was followed on a specific date. The procedure tells people what to do; the record proves it was done.

This distinction matters significantly during a BRC audit. Auditors will cross-reference your procedures against your records to confirm that actual practice matches documented intent. A facility with thorough procedures but incomplete records will still receive non-conformances, because the records are the proof of implementation.

For example, a procedure might specify that entry-point mats are inspected and cleaned every shift. The corresponding record would be a signed log showing that inspection occurred at the start of each shift, with any observations noted. If the log has blank entries or inconsistent completion, the control cannot be verified, regardless of how well the procedure is written.

How do you document entry-point contamination controls at BRC-audited facilities?

Entry-point contamination controls at BRC-audited facilities should be documented through a combination of a site map identifying all controlled access points, a written procedure for each type of control measure in use, and a monitoring log that records inspection outcomes, cleaning activity, and any corrective actions taken at each entry point.

Entry points are a primary focus during BRC contamination control audits because they represent the most direct route for external contamination to enter a controlled environment. Industry experience consistently shows that up to 80% of contamination enters controlled spaces at floor level through foot traffic and wheeled equipment, making entry-point documentation particularly important.

Your documentation for each entry point should capture:

  • The type of control measure in place (mat, footbath, airlock, gowning station, or a combination)
  • The cleaning or maintenance frequency and method
  • The person responsible for each check
  • A record of each inspection, including condition observations
  • Any corrective actions taken and their outcomes

Where contamination control mats are used at entry points, documentation should also include product specifications, cleaning validation records, and replacement or review schedules. This gives auditors confidence that the physical control is being maintained to a consistent standard over time.

How often should contamination control documentation be reviewed to stay BRC-compliant?

Under BRC GFSI compliance requirements, contamination control documentation must be reviewed at least annually, and additionally whenever there is a significant change to the site, process, product, or regulatory context. The annual review should be formally recorded, with any updates tracked and approved by a named responsible person.

In practice, the most audit-ready facilities treat documentation review as a continuous activity rather than a once-a-year task. Monitoring records are checked in real time by supervisors. Procedures are flagged for revision when operational changes occur. Risk assessments are revisited following any contamination incident, near miss, or internal audit finding.

Key triggers that should prompt an unscheduled documentation review include:

  • Introduction of a new product, ingredient, or allergen
  • Changes to facility layout, entry points, or controlled zone boundaries
  • New or amended regulatory requirements from BRCGS or a customer
  • A contamination incident or failed internal audit
  • Changes to cleaning chemicals, equipment, or supplier materials

Auditors will look at the version history of your documents. Procedures and risk assessments that show no revision history over several years are a common audit concern, even if the underlying controls are sound.

What are the most common documentation failures found during BRC contamination control audits?

The most common documentation failures in BRC contamination control audits are incomplete monitoring records, procedures that do not reflect actual practice, risk assessments that have not been reviewed following changes, and missing corrective action evidence when deviations have occurred. Each of these represents a gap between documented intent and demonstrated reality.

Auditors are trained to look for these specific weaknesses. The failures that most frequently result in non-conformances include:

  • Blank or inconsistently completed logs: monitoring records with missing dates, unsigned entries, or unexplained gaps undermine the credibility of the entire control system
  • Outdated procedures: written instructions that describe equipment, chemicals, or processes that are no longer in use signal that documentation is not being maintained
  • Risk assessments with no review dates: a risk assessment that cannot demonstrate it has been reviewed since it was first written will not satisfy an auditor looking for evidence of ongoing management
  • No corrective action trail: when a deviation is recorded but there is no corresponding corrective action or follow-up verification, it suggests the control system is not functioning as intended
  • Procedures that exist but staff cannot locate or describe them: documentation that is not accessible to the people responsible for carrying out the controls is treated as non-functional

Addressing these failures before an audit requires an internal review that compares every procedure against current practice, checks that all monitoring logs are complete and up to date, and confirms that corrective action records are linked to the relevant deviations.

How Dycem helps with BRC audit contamination control documentation

Dycem’s reusable contamination control mats are designed to support facilities in building a verifiable, audit-ready entry-point control system. For Quality and EHS Managers preparing for a BRC food safety audit, Dycem provides:

  • Product specifications and performance data to support risk assessment documentation
  • Clearly defined cleaning and maintenance guidance to underpin written procedures and monitoring logs
  • Antimicrobial protection via Biomaster silver-ion technology, inhibiting microbial growth by up to 99.9%, adding a measurable layer of control to your contamination management records
  • A 3 to 5 year product lifespan that reduces the operational burden of frequent replacement and supports consistent, long-term documentation
  • ISO-certified manufacturing to EN ISO 9001 and 14001 standards, providing supplier assurance documentation that auditors expect to see

Where disposable sticky mats create documentation challenges through frequent replacement cycles and inconsistent performance records, Dycem’s reusable systems offer a more stable, documentable control measure that holds up under audit scrutiny. To find out how Dycem can support your facility’s contamination control documentation, speak to a specialist today.

Related Articles