Level 3 HACCP

Module 4: Preliminary steps and process flow

Define the HACCP scope, describe the food and intended use, map every actual process stage and confirm the diagram in the workplace.

Video runtime: 11:12

What you will learn in this module
  • A clear scope identifies the actual food, site and process covered rather than an undefined whole-business label.
  • Map all actual stages, including cooling, permitted leftovers and delivery, so hazards are not omitted.
  • Accurate preliminary work is the foundation for later controls; challenge omissions and outdated assumptions.

Load this video from YouTube. Your browser will connect to YouTube; embedding follows your cookie preferences.

External playback does not record on-page study progress.

Module 4: Preliminary steps and process flow

Module 4: Preliminary steps and process flow

Define the HACCP scope, describe the food and intended use, map every actual process stage and confirm the diagram in the workplace.

Records your study progress, not an assessment result or certificate.

Key points

  • A clear scope identifies the actual food, site and process covered rather than an undefined whole-business label.
  • Describe the real ingredients, allergens, storage, packing and use that determine the product’s hazards.
  • Intended use and customer vulnerability affect control needs; do not assume later handling fixes earlier hazards.
  • Map all actual stages, including cooling, permitted leftovers and delivery, so hazards are not omitted.
  • On-site confirmation must reveal real work and lead to safe correction, not legitimise an unsafe process.
  • Consider inputs and outputs as well as food steps, including bought-in ingredients, packaging and traceability.
  • Accurate preliminary work is the foundation for later controls; challenge omissions and outdated assumptions.

Lesson guide

4.1 Define the scope

The scope states which foods, processes, site and operations a plan covers, and what is outside it. A chilled ready-to-eat sandwich process differs from a raw chicken cooking and delivery process. If the scope is vague, relevant stages or hazards may be missed; if it is unrealistically broad, responsibilities and controls can become unclear.

Define the actual menu or product groups, where work occurs and which handling stages are included. Consider delivery, storage, preparation, cooking, packing, holding, service and transport as applicable. Staff and the team should understand the boundary so they know when a change requires review. Do not assume another operation’s plan covers activities that have not been assessed.

4.2 Describe the product or menu item

Describe ingredients, allergens, whether the food is raw, cooked or ready-to-eat, relevant packaging, shelf life, storage conditions and how it is served or handled. These facts affect the hazards and controls. A chilled chicken-and-mayonnaise sandwich is not the same process as curry cooked, cooled and reheated for later service.

Use the actual recipe and product information rather than memory or a generic description. Changes to ingredients, prepared components or packing can change allergen, date and temperature needs. Keep the description current and specific enough to support analysis, including how the product reaches the customer. A product description is a practical planning input, not a marketing summary that omits relevant handling conditions.

4.3 Intended use and customer groups

Intended use asks how the food will be eaten or handled: immediately, after chilled storage, after customer cooking or reheating, or after transport. Ready-to-eat food has no further cooking before consumption. Raw products still need suitable storage, separation and information even when cooking is expected later.

Consider customers who may be more vulnerable, such as people in care, nursery, school or hospital settings, and those relying on allergen information. These contexts can require especially careful suitable procedures. Do not assume every customer will correct earlier unsafe handling. Product and service information must agree with the actual intended use so the hazard analysis does not leave gaps between preparation, delivery and consumption.

4.4 Create the process flow

A process flow diagram maps the steps food actually follows, from receipt to its final destination. Include relevant storage, preparation, cooking, cooling, reheating, packing, display, delivery and service, plus returns, rework or leftovers where these are permitted and controlled in the operation.

A chicken process that cooks and holds food may also cool leftovers for later reheating; leaving cooling out of the diagram can leave a serious hazard unassessed. A sandwich process may involve assembly, packing, labelling and chilled display rather than a final cook. Map the real sequence instead of an idealised one. The diagram gives the team a basis for considering hazards and controls at each step.

4.5 Confirm the flow on site

Walk through the workplace, observe staff, ask questions and compare the diagram with real operations. Confirmation should include normal and busy service, not only a quiet demonstration. Check actual equipment, containers, timings and shared work areas.

If staff cool food in deep containers because shallow trays are unavailable, the written diagram alone does not control the risk. If raw and ready-to-eat work share a surface unsafely, recording that fact is not permission to continue. Correct unsafe practice and resources, and ensure the flow accurately describes the controlled process. Reconcile documents and reality so the team assesses the actual hazards rather than a process that exists only on paper.

4.6 Inputs, outputs and steps

Inputs can include raw and prepared ingredients, packaging, water, ice, cleaning materials, staff and equipment. Supplier information helps establish ingredient and process conditions. Outputs can include finished food, waste, by-products, returned products and controlled leftovers. Each can affect contamination, handling or traceability.

Identify where materials enter, how food moves and where it leaves. An allergen can enter in a bought-in sauce; unsuitable packaging or cleaning material can create other hazards. Traceability needs to connect ingredients and relevant outputs. Include the process steps that change the food’s conditions, so hazard analysis can consider entry, growth, survival, cross-contact or exit risks rather than analysing only cooking.

4.7 Avoid preliminary-work mistakes

Common mistakes include vague scope, incorrect product information, memory-based flow diagrams and omission of temporary menus, substitutions, packaging, delivery, vulnerable customer groups, leftovers or rework. The system then risks assessing an incomplete or outdated operation.

Challenge the documents against what staff actually do and what resources they have. Confirm current recipes, suppliers, equipment, layout and timing; review when they change. Preliminary work is not an administrative exercise to finish once and forget. Accurate scope, description, intended use and flow support every later HACCP decision. If these foundations are wrong, even detailed limits and records can be attached to the wrong process.

In practice

Delivery added to a takeaway

Source teaching example rewritten as a formative scenario; not a real reported incident

The existing diagram ends at counter service, but meals now travel to customers.

Can it remain unchanged?

Review and include the actual packing, holding, transport and customer handover arrangements and associated hazards.

The scope and flow must cover the real service, not only the old one.

Deep cooling containers found on site

Source teaching example rewritten as a formative scenario; not a real reported incident

The flow says shallow-tray cooling, but observation reveals deep tubs during rush periods.

Does updating a diagram alone make this safe?

Correct the unsafe arrangements and resources and ensure the documented controlled process matches practice.

Confirmation exposes a hazard; documentation cannot legitimise it.

Reflect on your learning

What should a scope identify?

Select one answer.

Why describe intended use?

Select one answer.

What should a flow diagram represent?

Select one answer.

What should on-site confirmation do?

Select one answer.

For your own learning — not the certification assessment.

FAQs

Should leftovers or rework appear in the flow?

Include them when they are part of a permitted, controlled operation. Omitting actual stages can leave relevant hazards and food decisions unassessed.

Why observe busy service?

Methods, containers, space and timing can differ from a quiet demonstration. The system must control the actual operation reliably.

Does a new ingredient require preliminary review?

It can change the product description, allergens, storage or process. Keep the relevant information and analysis current rather than assuming old details remain correct.

Further reading

  • Make an HACCP plan (opens a new tab)

    Planning resources and access to MyHACCP; requires business-specific information and may require specialist advice.

    UK Government / Food Standards Agency. Applicable jurisdiction: UK overview; apply the relevant business and national requirements. Supplementary reading; checked 2026-10-07.

  • Food safety management systems for businesses (opens a new tab)

    Supplementary overview of HACCP-based procedures, checks and records.

    UK Government / Food Standards Agency. Applicable jurisdiction: UK overview; check the relevant national regulator and business-specific rules. Supplementary reading; checked 2026-10-07.

  • CookSafe: House Rules (opens a new tab)

    Role-specific training and practical hygiene, maintenance, temperature, stock and allergen controls.

    Food Standards Scotland. Applicable jurisdiction: Scotland; catering businesses. Supplementary reading; checked 2026-10-07.

Jump to a key moment
Transcript

[0:00] Welcome to lesson 4.1. Defining the
[0:02] scope of the hacked plan. Before a
[0:05] hacked plan can be developed, the
[0:06] business must define the scope of the
[0:08] plan. The scope explains what the hacked
[0:11] plan covers. It sets the boundary so
[0:14] everyone understands which food,
[0:16] process, site, product, menu, item, or
[0:19] activity is being assessed. At level
[0:22] three, this is important because a hack
[0:24] plan that is too vague may miss
[0:25] important hazards. A plan that is too
[0:28] broad may become confusing and difficult
[0:30] to manage. For example, a cafe may
[0:33] decide to create a hacked plan for
[0:35] preparing and selling ready to eat
[0:37] sandwiches. The scope may include
[0:39] receiving ingredients, chilled storage,
[0:42] preparation, allergen control, packing,
[0:45] labelling, display, and sale. A takeaway
[0:48] may define the scope for cooked chicken
[0:50] products.
[0:51] This could include delivery, storage,
[0:53] raw preparation, cooking, hot holding,
[0:56] packing, delivery, and cleaning
[0:58] controls.
[1:00] The scope should also make clear what is
[1:02] not included.
[1:03] For example, a plan for hot food
[1:05] delivery may not cover bakery production
[1:07] unless that is part of the same process.
[1:10] Defining the scope helps the hack team
[1:12] focus on the correct hazards, controls,
[1:14] records, and responsibilities.
[1:17] The key message is the scope sets the
[1:19] starting point and boundaries of the
[1:21] hack plan. If the scope is unclear, the
[1:24] hazard analysis may be incomplete or
[1:26] confusing.
[1:28] Welcome to lesson 4.2, describing the
[1:30] product or menu item. Once the scope is
[1:33] clear, the next step is to describe the
[1:36] product or menu item. A product
[1:38] description helps the hack team
[1:40] understand what the food is, how it is
[1:42] made, how it is stored, how it is
[1:44] served, and what hazards may be linked
[1:45] to it.
[1:47] At level three, this description should
[1:49] include practical food safety details.
[1:52] These may include ingredients,
[1:54] allergens, whether the food is raw or
[1:56] cooked, whether it is ready to eat, how
[1:58] it is packaged, its shelf life, storage
[2:01] temperature, serving method, and any
[2:02] special handling requirements.
[2:05] For example, a chicken mayonnaise
[2:07] sandwich may include cooked chicken,
[2:09] bread, mayonnaise, and salad. It is a
[2:12] ready to eat product stored chilled,
[2:14] displayed for sale, and eaten without
[2:16] further cooking. This tells the hack
[2:19] team that chilled storage, hand hygiene,
[2:21] crosscontamination, date control, and
[2:23] allergens are important. A cooked curry
[2:26] may have different details.
[2:29] It may include raw ingredients, cooking,
[2:31] cooling, reheating, hot holding or
[2:34] delivery. This creates different hazards
[2:37] and controls. The product description
[2:39] should be accurate and based on how the
[2:41] food is actually prepared, not how the
[2:43] business assumes it is prepared. If a
[2:46] recipe changes, the product description
[2:48] may also need updating.
[2:50] The key message is a good product
[2:52] description helps identify real food
[2:54] safety risks. The more accurately the
[2:57] food is described, the stronger the hack
[3:00] plan will be. Welcome to lesson 4.3,
[3:03] intended use and vulnerable customers.
[3:06] Intended use means how the food is
[3:08] expected to be used or eaten by the
[3:10] customer. This matters in hacked because
[3:13] food safety risks can change depending
[3:15] on whether the food will be cooked
[3:16] again, eaten immediately, stored for
[3:18] later, reheated, transported or eaten by
[3:22] vulnerable customers.
[3:24] For example, a ready to eat sandwich
[3:26] will not be cooked again before the
[3:27] customer eats it. This means any
[3:30] contamination from hands, equipment,
[3:32] allergens or poor storage may go
[3:34] directly to the customer. A raw meat
[3:37] product is different because it is
[3:38] expected to be cooked before eating.
[3:41] However, the business still needs
[3:43] controls for storage, labelling,
[3:45] preparation, and preventing raw food
[3:47] from contaminating ready to eat food.
[3:50] Vulnerable customers are also important.
[3:53] These may include young children, older
[3:55] people, pregnant women, and people with
[3:57] weakened immune systems or underlying
[3:59] health conditions. If a business serves
[4:02] care homes, nurseries, schools,
[4:04] hospitals, or similar settings, the hack
[4:07] team may need to apply stricter controls
[4:09] because the consequences of food
[4:10] poisoning can be more serious. Allergen
[4:13] sensitive customers must also be
[4:15] considered. If customers rely on
[4:18] allergen information to make safe
[4:19] choices, the business must control
[4:21] ingredients, labels, cross contact, and
[4:24] communication.
[4:25] At level three, managers and supervisors
[4:28] should ask who will eat this food, how
[4:30] will they eat it, and what could happen
[4:32] if the controls fail. The key message is
[4:35] intended use and customer type affect
[4:37] the level of food safety control needed.
[4:40] Hacked must consider the real customer,
[4:42] not just the food product.
[4:44] Welcome to lesson 4.4. for creating a
[4:47] process flow diagram. A process flow
[4:50] diagram shows the steps food goes
[4:52] through from start to finish. It helps
[4:54] the hack team understand the full
[4:56] process and identify where hazards may
[4:58] enter, grow, survive, or spread. At
[5:02] level three, a flow diagram does not
[5:04] need to be complicated, but it must be
[5:06] accurate. It should show the real steps
[5:08] in the business, not an ideal version
[5:10] that only happens on paper.
[5:13] For example, a simple cooked chicken
[5:15] process may include delivery, chilled
[5:17] storage, raw preparation, cooking, hot
[5:20] holding, serving, cooling leftovers if
[5:22] allowed, reheating if used, and
[5:24] cleaning. A sandwich process may include
[5:27] delivery, chilled storage, preparation,
[5:30] assembly, packing, labelling, chilled
[5:32] display, and sale. The flow diagram
[5:35] should include important steps such as
[5:37] storage, preparation, cooking, cooling,
[5:40] reheating, packing, display, transport,
[5:43] allergen handling, and waste where
[5:45] relevant. It should also include
[5:47] returns, rework, or leftovers. If these
[5:50] happen in the business leaving these out
[5:52] can cause hazards to be missed. For
[5:55] example, if cooked food is sometimes
[5:57] cooled and reused the next day, that
[5:59] step must appear in the flow. Otherwise,
[6:02] cooling and reheating hazards may not be
[6:04] properly assessed. The key message is a
[6:07] process flow diagram maps the food
[6:09] journey. Hack depends on this map being
[6:12] accurate because hazards can only be
[6:14] controlled if the team knows where they
[6:16] happen. Welcome to lesson 4.5.
[6:19] Confirming the process flow on site.
[6:22] After creating a process flow diagram,
[6:25] the hack team must confirm it on site.
[6:28] This means checking the diagram against
[6:30] what actually happens in the workplace.
[6:32] At level three, this step is important
[6:34] because many food safety problems happen
[6:37] when documents do not match real
[6:38] practice. A process may look safe on
[6:41] paper, but staff may work differently
[6:43] during busy service. For example, the
[6:46] flow diagram may say cooked food is
[6:49] cooled in shallow trays, but on site,
[6:51] the supervisor may find that staff leave
[6:53] food in large, deep containers because
[6:54] shallow trays are not available. The
[6:57] diagram may say raw and ready to eat
[6:59] food are prepared separately, but on
[7:01] site the same worktop may be used during
[7:03] busy periods without proper cleaning
[7:05] between tasks. To confirm the flow,
[7:08] managers should walk through the
[7:10] process, observe staff, check equipment,
[7:12] ask questions, and compare each step
[7:15] against the diagram. This should be done
[7:17] during real working conditions, not only
[7:20] when the kitchen is quiet and tidy. If
[7:23] differences are found, the hack team
[7:25] should update the flow diagram or change
[7:27] the working practice so the system
[7:28] becomes accurate and safe. The key
[7:31] message is the process flow must match
[7:33] reality. Confirming the flow on site
[7:36] helps prevent hazards being missed
[7:38] because of incorrect assumptions.
[7:40] Welcome to lesson 4.6. Identifying
[7:43] inputs, outputs, and process steps. When
[7:46] developing a hacked plan, the team
[7:48] should identify the inputs, outputs, and
[7:51] process steps.
[7:52] Inputs are everything that enters the
[7:54] process.
[7:56] This may include raw ingredients,
[7:58] readymade ingredients, packaging, water,
[8:00] ice, cleaning materials, staff handling,
[8:03] equipment, and supplier information.
[8:06] Outputs are what leaves the process.
[8:09] This may include finished food, packaged
[8:11] products, waste, byproducts, returned
[8:14] food, leftover food, or food sent for
[8:17] delivery. Process steps are the actions
[8:19] that happen between inputs and outputs.
[8:22] These may include receiving, storing,
[8:25] preparing, cooking, cooling, reheating,
[8:28] packing, labelling, displaying, serving,
[8:31] transporting, and cleaning. At level
[8:34] three, this matters because hazards can
[8:35] be linked to any input, output, or
[8:38] process step. For example, raw chicken
[8:41] as an input may bring microbiological
[8:43] hazards. Packaging may bring physical
[8:46] contamination if damaged. Cleaning
[8:48] chemicals may create chemical hazards if
[8:50] stored or used incorrectly.
[8:53] Staff handling may introduce bacteria or
[8:55] allergens.
[8:57] A finished sandwich as an output may
[8:58] need correct labelling, date control,
[9:01] chilled storage, and allergen
[9:02] information. Waste as an output may
[9:05] attract pests if not managed properly.
[9:08] Identifying inputs and outputs also
[9:10] helps with traceability.
[9:12] If something goes wrong, the business
[9:14] needs to understand where ingredients
[9:15] came from and where finished food went.
[9:18] The key message is hack should look at
[9:20] everything entering, moving through and
[9:22] leaving the process. Hazards may be
[9:25] linked to ingredients, people,
[9:27] packaging, equipment, waste, or finished
[9:29] food. Welcome to lesson 4.7, common
[9:33] mistakes in preliminary hacked work.
[9:36] Preliminary hacked work means the steps
[9:38] completed before the detailed hazard
[9:39] analysis begins. Mistakes at this stage
[9:42] can weaken the whole hack plan. One
[9:45] common mistake is defining the scope too
[9:47] vaguely. If the team does not know
[9:50] exactly what process or product is being
[9:52] covered, important hazards may be
[9:53] missed. Another mistake is using an
[9:56] inaccurate product description. If
[9:59] ingredients, allergens, storage
[10:01] conditions, or intended use are wrong,
[10:03] the hazard analysis will also be wrong.
[10:06] A third mistake is creating a flow
[10:08] diagram from memory instead of checking
[10:10] what really happens on site. Staff may
[10:13] follow different steps during busy
[10:15] periods or use equipment and shortcuts
[10:17] that are not shown on the diagram.
[10:19] For example, the hack document may say
[10:22] food is cooled quickly in shallow trays,
[10:24] but staff may actually leave large pots
[10:26] on the side because there is not enough
[10:28] space. If this is not identified,
[10:31] cooling hazards may be missed. Other
[10:33] mistakes include forgetting temporary
[10:35] menu items, ignoring supplier
[10:37] substitutions, leaving out packing or
[10:40] delivery steps, not considering
[10:41] vulnerable customers, and failing to
[10:43] include leftovers, rework or returned
[10:46] food. At level three, managers and
[10:49] supervisors should challenge
[10:50] assumptions.
[10:52] Ask whether the plan reflects real
[10:54] practice, real ingredients, real staff
[10:56] behaviour, and real customer use. The key
[11:00] message is strong hacked starts before
[11:02] hazard analysis.
[11:04] If the scope, product description, and
[11:06] process flow are wrong, the rest of the
[11:08] plan may not control the real risks.