Pass the inspection: 10 AI skills for the paperwork that keeps you open
haccp-plan
your own process, written down
How the two work together
Claude thinks it through. Paste the Claude prompt into Claude Code, or drop the folder into your skills folder. Claude does the judgement: what to look for, what is worth doing, what is right.
Codex gets it done. At the hand-off point Claude runs Codex on your machine with one command and passes it the Codex prompt. Codex does the mechanical part and hands the result back. Claude checks it before you see it.
No API key to set up: Claude calls the Codex you already have installed. If Codex is not installed, Claude does that half itself and tells you.
Prompt for Claude
--- name: haccp-plan description: Turns the way your kitchen already works into a written food safety management plan built on the seven HACCP principles, with the hazards named at each step, critical limits you can read off a probe, and a monitoring and corrective action line for every one. Use when you have no written plan, or you have a downloaded template that describes a kitchen you do not run. --- # Your own process, written down, in the shape the law asks for You give me how food actually moves through your place: what you buy in, who delivers it, where it goes, what you cook fresh, what you cook ahead and chill, what you reheat, what you serve cold, and who does each of those jobs. Phone photos of the walk-in, a scrawled prep list, last year's downloaded template, a supplier PDF, all fine. You get back a written plan with your process drawn out step by step, the hazards named at each step, a short list of the points where control is genuinely critical, a number for each of those, the monitoring that proves it, the corrective action for when it fails, and a review page. It is your kitchen on paper, not a generic one. ## What it does 1. **Write the scope before anything else, so the plan cannot quietly cover a kitchen you do not run.** One page at the front: the trading name and address, what the business is, the hours you produce food, the number of covers or meals on your busiest day, every process you carry out (cook and serve, cook chill reheat, hot hold, cold prep, sous vide, vac pac, raw fish, rice, home cured, delivery and takeaway), and every process you explicitly do not. Then the customers you serve, because a plan feeding a care home, a nursery or a hospital is judged against a more vulnerable group than one feeding a pub crowd. Most downloaded templates fail here: they describe a kitchen doing eleven processes when yours does four, so every officer reading it sees controls for things you have never done and no control for the thing you do every Saturday. Name the person who owns this plan and the date it was written. GOV.UK is direct that this ownership carries a training duty: "If you are responsible for developing and maintaining a business's food safety management procedures, you must have had suitable training on food safety and hygiene to do this." 2. **Put the basics in writing first, because HACCP sits on top of them and collapses without them.** Before you go hunting for critical control points, list what is already running every day regardless of what you are cooking: the cleaning schedule and who signs it, pest control and who visits and when, waste, water, structure and equipment maintenance, personal hygiene and fitness to work rules, supplier approval and delivery acceptance, stock rotation and date labelling, allergen information and how it reaches the customer, and staff training. GOV.UK sets the training rule for everyone else in the kitchen: "You must make sure that any member of staff who handles food is trained in food hygiene and safety, including allergens, before they start work." These basics are not your HACCP plan, and the plan should not try to control them as critical points. They are the floor it stands on, and naming them in one list is what stops the plan claiming a probe reading solves a problem that is really a filthy chopping board. 3. **Draw the flow of food through your kitchen, then walk it with a pen at service time.** Start at delivery and end at the customer, one box per step, using the words your staff use: delivery, store, defrost, prep, cook, cool, chill, portion, reheat, hot hold, serve, leftovers. Split the line where the food splits, so the salmon that goes to the plancha and the salmon that goes out raw are two paths, not one. Then, and this is the part people skip, walk it during an actual service and change the diagram to match what you see. You will find a step nobody wrote down: the tray that sits on the pass, the tub that goes in the walk-in still warm, the delivery that comes in through the bar at eleven on a Friday. Drawing a flow diagram is not written into Article 5 itself, so treat it as good practice rather than a legal requirement, but an officer can read a one page flow diagram in thirty seconds and it is the fastest way to show you know your own process. 4. **Principle 1, name the hazards step by step, in four kinds.** For each box on your diagram, ask what could make someone ill here, in four categories: biological (bacteria growing, surviving cooking, or getting on afterwards), chemical (cleaning product, machine oil), physical (glass, metal, bone, packaging), and allergen (the wrong ingredient reaching the wrong person). Retained Regulation (EC) No 852/2004, Article 5(2)(a), states this principle as "identifying any hazards that must be prevented, eliminated or reduced to acceptable levels". Be specific rather than encyclopaedic: "cooked rice held warm, bacillus" beats a page of microbiology. Two sentences per step is enough. The value is not the list, it is that you looked at every step including the boring ones, and the boring ones are where it goes wrong: the defrost, the cool down, the tub of stock that lives on the shelf. 5. **Principle 2, pick the few points where control is genuinely critical, and be ruthless.** Article 5(2)(b) calls for "identifying the critical control points at the step or steps at which control is essential". A critical control point is a step where, if you get it wrong, there is nothing later that will save you. Cooking is usually one, because it is the kill step. Cooling and chilled storage usually are, because that is where survivors multiply. Reheating and hot holding usually are. Cleaning the bar taps almost certainly is not: it matters, but it belongs in step 2's basics. A small kitchen with four processes should end up with somewhere between three and six critical points, not twenty. A plan with twenty is a plan nobody monitors, and an unmonitored critical point is worse than an honest prerequisite, because you have written down that it is essential and then produced no evidence you controlled it. 6. **Principle 3, put a number and a unit on every critical point.** Article 5(2)(c) requires "establishing critical limits at critical control points which separate acceptability from unacceptability". A critical limit has to be something a person on shift can read off a probe, a clock or a display: a temperature, a time, or a temperature held for a time. "Cooked thoroughly" is not a limit, because two people will disagree about it at nine on a Saturday. Take the figures from published UK guidance rather than from memory or from a template of unknown origin, write the source next to each number, and where the number depends on your process, say so and get it confirmed. Whichever figures you adopt, they and the method behind them are the part of the plan your environmental health officer or food safety adviser should check before you rely on them, because the right limit depends on what you actually make and how you make it. 7. **Principles 4 and 5, say who watches it, how often, and what happens when it fails.** Monitoring, in Article 5(2)(d), is "establishing and implementing effective monitoring procedures at critical control points", and corrective action, in 5(2)(e), is "establishing corrective actions when monitoring indicates that a critical control point is not under control". Write both as one line per critical point, in the format: who, with what, how often, recorded where, and then, if it is outside the limit, do this. For example: chef on section, clean probe in the thickest part, every batch, written in the cook log; if below the limit, put it back and re-probe, and record both readings. The corrective action must say what happens to the food as well as to the equipment, because "called the engineer" does not answer the question of whether the chicken got served. Two lines each, six critical points, and your whole control regime fits on one page a new starter can follow. 8. **Principle 6, book the verification, and make it produce a change.** Article 5(2)(f) asks for "establishing procedures, which shall be carried out regularly, to verify that the measures outlined in subparagraphs (a) to (e) are working effectively". Verification is not the daily check, it is somebody standing back and asking whether the daily checks are true and sufficient. Give it a date, a name and three jobs: read the last four weeks of records and count the gaps, watch one person actually do one monitoring check and see whether they do it the way the plan says, and calibrate the probes against ice water and boiling water with the result written down. Then write what you are changing. GOV.UK states the duty to "regularly review your procedures to ensure they reflect what you produce or how you work", and a review that changes nothing on a plan that is a year old is usually a review that did not happen. 9. **Principle 7, keep the plan and the records in proportion, and name what triggers a rewrite.** Article 5(2)(g) is "establishing documents and records commensurate with the nature and size of the food business to demonstrate the effective application of the measures". Commensurate cuts both ways: a forty cover pub does not need a manufacturer's manual, and a ring binder of blank pages is not a plan. Article 5(4) adds three duties in its own words: "provide the competent authority with evidence of their compliance with paragraph 1 in the manner that the competent authority requires, taking account of the nature and size of the food business", "ensure that any documents describing the procedures developed in accordance with this Article are up-to-date at all times", and "retain any other documents and records for an appropriate period". So finish with a page listing what triggers a rewrite before the next scheduled review: a new dish or process, a new piece of equipment, a new supplier for a high risk item, a change of chef, a complaint of illness, or anything an officer tells you. Ask your adviser or officer what retention period they expect and write their answer down instead of guessing it. ## Then it checks 1. Every process listed in the scope page appears as a path on the flow diagram, and every box on the flow diagram belongs to a process listed in the scope. Nothing in either one is orphaned. 2. Every step on the flow diagram has been considered against all four hazard kinds, biological, chemical, physical and allergen, and each is either named or explicitly marked "none identified at this step". 3. Every critical control point has a critical limit expressed as a number with a unit, and a named published source or an explicit "to be confirmed with our adviser" beside it. No limit reads "thoroughly", "properly", "hot enough" or "until done". 4. Every critical control point has a monitoring line naming a person or role, a method, a frequency and where it is recorded, and a corrective action line saying what happens to the food as well as to the equipment. 5. The count of critical control points is between three and eight for a small catering kitchen, or, if it is outside that range, the plan says in one sentence why this business is different. 6. The plan carries the author's name, the date written, the date of the next verification, and a trigger list for rewriting it, and the prerequisite list in step 2 names a document or a person for every item rather than leaving any blank. Any check fails: name it, redo that step once. Failed twice: say what is wrong and stop. ## Rules - Public information only. - Never invent a fact, a number or a quote. - Anything sent in someone's name says whose name it is. - Never write a temperature, a time or a combination of the two that did not come from a published source you can name on the page. An invented critical limit is the single most dangerous thing this skill could produce, because it will be written into a plan, followed by staff, and shown to an officer as evidence of control. - Never describe a plan as compliant, approved or sufficient. Whether a HACCP based procedure is adequate is judged by the enforcing authority against what this business actually does, and no document produced here can make that judgement. - Never copy a process into the plan that the kitchen does not carry out, and never leave out one it does. A plan describing somebody else's kitchen is the failure this skill exists to fix, and it is worse than no plan, because it is evidence you were not paying attention. - Note that food hygiene enforcement law is not identical across the UK. The offence provision quoted here is from the England regulations; Wales, Scotland and Northern Ireland have their own, and the packs published for small businesses differ too. - This output is a working document prepared for the owner's environmental health officer, food safety adviser or local authority to check before it is relied on. It is not legal advice, and it does not determine whether a business complies with food hygiene law. ## Built from - Legislation.gov.uk, "Regulation (EC) No 852/2004 of the European Parliament and of the Council of 29 April 2004 on the hygiene of foodstuffs, Article 5", https://www.legislation.gov.uk/eur/2004/852/article/5, retained EU legislation as it applies in the UK, read 14 September 2026: the duty in 5(1) and all seven principles in 5(2)(a) to (g) quoted verbatim, which are the backbone of steps 4 to 9, plus the three limbs of 5(4) that shaped the retention and up-to-date wording in step 9. - GOV.UK / Food Standards Agency, "Managing food safety", https://www.gov.uk/government/publications/managing-food-safety/managing-food-safety, updated 21 August 2026, read 14 September 2026: the training duties quoted in steps 1 and 2, the duty to keep documents and records up to date and to "regularly review your procedures to ensure they reflect what you produce or how you work" in step 8, and the flexibility line that keeps the plan proportionate. - GOV.UK, "Food safety management systems", https://www.gov.uk/food-safety-management-systems, no publication date shown on the page, read 14 September 2026: the definition of a food safety management system as "A written set of processes, checks, rules and records", which is why the plan is written rather than held in someone's head, and the list of what a system covers that shaped the prerequisite list in step 2. - Legislation.gov.uk, "The Food Safety and Hygiene (England) Regulations 2013, regulation 19", UK Statutory Instruments 2013 No. 2996, https://www.legislation.gov.uk/uksi/2013/2996/regulation/19/made, read 14 September 2026: the offence provision that makes Article 5 enforceable in England, which is why rule six refuses to let a template describe a kitchen the owner does not run, and why the rules note that the other UK nations have their own regulations. - GOV.UK / Food Standards Agency, "Safer food, better business (SFBB)", https://www.gov.uk/government/publications/safer-food-better-business-sfbb/safer-food-better-business-sfbb, published 5 June 2025, read 14 September 2026: the published small-business route that this plan is an alternative to rather than a replacement for, and the reminder that its records live in a daily diary, which is why step 7 ends every monitoring line with where it is recorded.
Prompt for Codex
# haccp-plan ## You are given A folder of inputs from a UK hospitality business: a scrawled prep list, phone photographs of the walk-in and the hot hold unit, last year's downloaded HACCP template, supplier specification PDFs, a menu, a cook log or temperature diary, a rota, and a written description of how food moves through the place. Claude has already walked the process, decided which steps are critical control points, and written the critical limits it could source. That decided material arrives as a text, CSV or Markdown file in the same folder, naming each step, each hazard, each critical control point, and, for each limit, either a figure with a named published source beside it or the words `to be confirmed with our adviser`. Treat that file as the input to transcribe, not as something to improve. ## Produce Write into an `output/` folder next to the inputs: 1. `scope.csv` - one row per process. Columns exactly, in this order: `process_name,carried_out,description_as_supplied,covers_or_meals_on_busiest_day,customer_group,source_file` - `carried_out` is `yes` or `no`. A process the inputs say the business does not do is written as a `no` row, never omitted. - Anything the inputs do not state is `NOT SUPPLIED`. 2. `prerequisites.csv` - columns exactly: `prerequisite,document_name,where_kept,responsible_person_or_role,last_updated,source_file`. One row each for: cleaning schedule, pest control, waste, water, structure and equipment maintenance, personal hygiene and fitness to work, supplier approval and delivery acceptance, stock rotation and date labelling, allergen information, staff training. Missing values are `NOT SUPPLIED`, never guessed. 3. `flow-steps.csv` - one row per step on the flow, in process order. Columns exactly: `step_no,step_name_as_staff_call_it,process_name,path_label,previous_step_no,next_step_no,who_does_it,source_file`. Where the flow splits, each path carries its own `path_label` and the split appears as two rows, not one. 4. `hazard-analysis.csv` - one row per step per hazard kind, so four rows minimum per step. Columns exactly: `step_no,step_name,hazard_kind,hazard_as_supplied,is_ccp,ccp_ref,source_file`. `hazard_kind` is one of exactly `biological`, `chemical`, `physical`, `allergen`. Where the supplied material identified nothing at that step for that kind, write `none identified at this step`. `is_ccp` is `yes` or `no`, copied from the supplied material and never decided here. 5. `ccp-control-chart.csv` - one row per critical control point. Columns exactly, in this order: `ccp_ref,step_no,step_name,hazard_controlled,critical_limit_as_supplied,limit_unit,limit_source_named_in_input,monitoring_who,monitoring_method,monitoring_frequency,recorded_where,corrective_action_to_the_food,corrective_action_to_the_equipment,source_file` - `critical_limit_as_supplied` is transcribed character for character from the supplied material. Where the supplied material says `to be confirmed with our adviser`, that exact phrase goes in the cell, `limit_unit` and `limit_source_named_in_input` stay empty, and the row is added to file 8. - `limit_source_named_in_input` is the publication named beside the figure in the inputs. A limit with no named source is not written as a figure. 6. `monitoring-record-sheet.csv` - a blank sheet for the kitchen to fill in. Columns exactly: `date,ccp_ref,step_name,critical_limit,reading_taken,within_limit_yes_no,corrective_action_taken,initials,time`. One row per critical control point per day for a seven day week. `critical_limit` is pre-filled from file 5 only where a sourced figure exists; otherwise the cell is left blank for the adviser. Nothing else is pre-filled and no reading, initial or tick is ever entered. 7. `verification-schedule.csv` - columns exactly: `verification_task,who,due_date,frequency,what_is_checked,where_result_is_written,last_done,source_file`. Rows for: read the last four weeks of records and count the gaps, observe one monitoring check being performed, calibrate probes in ice water and boiling water. Add a `rewrite_triggers` row set listing each trigger named in the inputs. 8. `limits-to-be-confirmed.md` - a numbered list of every critical control point whose limit arrived as `to be confirmed with our adviser`, whose source was not named, or which the inputs did not mention at all. For each, give the `ccp_ref`, the step, the hazard, and the one sentence saying what the owner must obtain from their adviser or officer. This file is the whole safety valve of the job; it is never empty by choice. 9. `haccp-plan.html` - the plan as one printable document, A4 portrait, black on white, 11pt minimum, margins at least 10mm, in this section order: scope, prerequisites, flow steps, hazard analysis, critical control point control chart, verification schedule, rewrite triggers, limits to be confirmed. It carries the author name, the date written and the next verification date read from the inputs, or `NOT SUPPLIED`. 10. `README.md` - what was read, the count of processes, steps, hazards and critical control points, and what could not be transcribed. ## Rules - Never set, choose, adjust, round, convert, complete or invent a critical limit. Not a temperature, not a time, not a combination of the two, not for any step, not as an example, not as a placeholder, not in a comment, not in the printable HTML. A limit is transcribed only where the inputs state it or quote it with a named published source beside it. Everything else is written as `to be confirmed with our adviser` and listed in `limits-to-be-confirmed.md`. An invented critical limit is the single most dangerous thing this work could produce, because it will be written into a plan, followed by staff, and shown to an officer as evidence of control. - Never copy a figure across from a supplied template of unknown origin, from a supplier PDF that does not name a published source, or from one step to another because the steps look similar. - Never decide whether a step is a critical control point, and never move a step between the prerequisite list and the control chart. That judgement arrives in the inputs. - Never write `compliant`, `approved`, `sufficient`, `passes`, `meets the regulations`, `safe` or `signed off` in any output. - Never write a limit as `thoroughly`, `properly`, `hot enough`, `until done`, `piping hot` or `chilled`. If that is what the inputs say, it is not a limit; write `to be confirmed with our adviser` and list it in file 8. - Never add a process, step, dish or piece of equipment the inputs do not evidence, and never drop one they do. A plan describing somebody else's kitchen is the failure this exists to fix. - Every figure, date and name in every output must trace to a supplied input file named in the row's `source_file` cell. Gaps go in `limits-to-be-confirmed.md` or as `NOT SUPPLIED`, never filled with an assumption. - Food hygiene enforcement law is not identical across England, Wales, Scotland and Northern Ireland. Do not write any output that assumes one nation's regime or names one nation's regulations as though they applied throughout. - British English, £ where any cost appears, dates written as DD Month YYYY. No em dash characters anywhere. No emoji. - Put this line at the top of `limits-to-be-confirmed.md`, at the foot of `haccp-plan.html` and at the end of `README.md`: "Working document prepared for the owner's environmental health officer, food safety adviser or local authority to check before it is relied on. It is not legal advice and it does not determine whether a business complies with food hygiene law." ## Return The absolute path of each of the ten files, the number of processes marked `yes` and `no` in `scope.csv`, the number of flow steps, the number of critical control points, how many of those carry a transcribed limit with a named source, how many carry `to be confirmed with our adviser`, and the number of entries in `limits-to-be-confirmed.md`. State plainly that no critical limit was originated here.
Built from the best public work on this
Sources for haccp-plan
Everything below was opened and read on 14 September 2026. Nothing is cited that could not be loaded. One source we wanted, the Food Standards Agency's MyHACCP guidance, could not be loaded at all and is reported honestly at the end.
1. Legislation.gov.uk, "Regulation (EC) No 852/2004 on the hygiene of foodstuffs, Article 5"
https://www.legislation.gov.uk/eur/2004/852/article/5, retained EU legislation as it applies in the UK (paragraph 5 of the Article was omitted on 31 December 2020 by UK exit legislation), read 14 September 2026.
This is the whole skeleton of the skill, because the seven HACCP principles are not a consultant's framework, they are the text of the law. Article 5(1) is the duty: "Food business operators shall put in place, implement and maintain a permanent procedure or procedures based on the HACCP principles."
Article 5(2) then lists the principles, and each one became a numbered step:
(a) "identifying any hazards that must be prevented, eliminated or reduced to acceptable levels" is step 4, and the four-way biological, chemical, physical, allergen split is the skill's own practical device for making sure the hunt is systematic rather than imaginative.
(b) "identifying the critical control points at the step or steps at which control is essential" is step 5. The word "essential" is what licenses the skill's ruthlessness about keeping the list short, and the reason cleaning the bar taps goes in the prerequisite list instead.
(c) "establishing critical limits at critical control points which separate acceptability from unacceptability" is step 6. "Separate acceptability from unacceptability" is the phrase that rules out "cooked thoroughly": a limit that two people can read differently separates nothing.
(d) "establishing and implementing effective monitoring procedures at critical control points" and (e) "establishing corrective actions when monitoring indicates that a critical control point is not under control" are both step 7, deliberately joined, because a monitoring line with no paired corrective action is the most common defect in a downloaded plan.
(f) "establishing procedures, which shall be carried out regularly, to verify that the measures outlined in subparagraphs (a) to (e) are working effectively" is step 8.
(g) "establishing documents and records commensurate with the nature and size of the food business to demonstrate the effective application of the measures" is step 9, and "commensurate with the nature and size" is quoted because owners overwhelmingly read the duty as "more paperwork is safer", which it is not.
Article 5(4) supplied the three duties quoted in step 9 word for word: "provide the competent authority with evidence of their compliance with paragraph 1 in the manner that the competent authority requires, taking account of the nature and size of the food business", "ensure that any documents describing the procedures developed in accordance with this Article are up-to-date at all times", and "retain any other documents and records for an appropriate period".
Where the skill departs: Article 5 contains no flow diagram, no HACCP team, no scope statement and no preparatory stages. Those come from the Codex Alimentarius method that the principles are drawn from, not from the enacted text, so steps 1 and 3 are labelled as good practice in the skill rather than presented as a legal requirement. That distinction matters, because an owner told that a flow diagram is "the law" will eventually be told otherwise by someone and will then discount everything else they were told.
2. GOV.UK / Food Standards Agency, "Managing food safety"
https://www.gov.uk/government/publications/managing-food-safety/managing-food-safety, updated 21 August 2026, read 14 September 2026.
This is the Food Standards Agency's plain-language statement of the same duty, and it supplied the parts of the skill that Article 5 does not cover: training, review and proportionality.
"Food safety management is about complying with food hygiene and food standards. You must ensure that you have food safety management procedures in place." HACCP is described here in owner's English as "a system that helps you identify potential food hazards and introduce procedures to make sure those hazards are removed or reduced to an acceptable level."
Two duties in the list shaped steps 8 and 9 directly: "keep up-to-date documents and records relating to your procedures" and "regularly review your procedures to ensure they reflect what you produce or how you work". That second one is why step 9 ends with a trigger list rather than only a date, because the common failure is a plan that is reviewed annually while the menu changed in March.
The training sentences are quoted verbatim in the skill. For the person who owns the plan: "If you are responsible for developing and maintaining a business's food safety management procedures, you must have had suitable training on food safety and hygiene to do this." For everyone else: "You must make sure that any member of staff who handles food is trained in food hygiene and safety, including allergens, before they start work."
The page also carries the proportionality line that keeps the skill honest at the small end: "Food safety procedures may not be necessary if processes in your business are very simple." It points small caterers in England and Wales at the Safer Food, Better Business packs, and businesses in Northern Ireland at the food safety management guides for caterers and retailers, and it states that records "need to be kept up-to-date and be available for inspections at all times".
Where the skill departs: the page treats supplier and customer traceability records as part of managing food safety. The skill does not build traceability into the HACCP plan, because it is a separate duty with a separate record shape, and it appears only as an item in the prerequisite list in step 2. Folding it in would have produced a plan that is really three plans.
3. GOV.UK, "Food safety management systems"
https://www.gov.uk/food-safety-management-systems, no publication date shown on the page, read 14 September 2026.
Short, and it does one job for this skill: it establishes that the output is written. A food safety management system is "A written set of processes, checks, rules and records", covering cleaning and hygiene rules, safe cooking and storage procedures, allergen controls, staff training and temperature checks. That list is close to the prerequisite list in step 2, and it is where the skill got the instinct to separate the standing basics from the critical control points rather than mixing them.
The page states the duty simply, "If you run a food business, you need to have a food safety management system to make sure your food is safe to eat", and ties it to the principles: "Your food safety management system must meet the Hazard Analysis and Critical Control Point (HACCP) principles." Its own rendering of the principles ends with an instruction aimed at a person rather than a lawyer, "Keep records of your food safety systems, checks and how you've put things right", and it explains why any of it matters: "If your business is involved in a food safety incident, you will need to show your records as evidence of how you keep food safe."
Where the skill departs: this page lists allergen controls alongside temperature checks as though they sit at the same level. The skill treats allergens as a hazard kind to be considered at every step (step 4) and as a prerequisite programme (step 2), but does not make allergen information a critical control point with a numeric limit, because there is no number to set and pretending otherwise would produce an unmonitorable line in the plan.
4. Legislation.gov.uk, "The Food Safety and Hygiene (England) Regulations 2013, regulation 19"
UK Statutory Instruments 2013 No. 2996, https://www.legislation.gov.uk/uksi/2013/2996/regulation/19/made, read 14 September 2026.
Article 5 says what you must do. This says what happens if you do not, and it is why the skill refuses to treat a HACCP plan as an optional bit of admin. Regulation 19(1): "Subject to paragraphs (4) to (8), any person who contravenes or fails to comply with any of the specified EU provisions commits an offence." Regulation 19(2): "Subject to paragraph (3), a person guilty of an offence under these Regulations is liable - (a) on summary conviction to a fine not exceeding the statutory maximum; or (b) on conviction on indictment to imprisonment for a term not exceeding two years, to a fine or to both."
This shaped the rules section rather than a step. It is the reason the skill will not call any plan compliant, and the reason it insists a plan must describe the kitchen that exists: a document that overstates your controls is evidence of what you said you would do.
Where the skill departs: it does not reproduce the penalty wording in the body of the plan, and it does not tell the owner what any particular breach would cost them. This instrument applies to England. Wales, Scotland and Northern Ireland have their own, and the skill's rules say so rather than letting an owner in Cardiff or Belfast assume the England instrument is theirs.
5. GOV.UK / Food Standards Agency, "Safer food, better business (SFBB)"
https://www.gov.uk/government/publications/safer-food-better-business-sfbb/safer-food-better-business-sfbb, published 5 June 2025, applies to England and Wales, read 14 September 2026.
Included because most owners reading this skill will already have heard of SFBB, and the skill needs to say clearly how the two relate. The page describes it as the Food Standards Agency's own route: "Safer food, better business (SFBB) details the food safety management procedures for small businesses", covering "cross-contamination, cleaning, chilling, cooking, management, using the diary", and states that "This pack must be completed for all your food operations and must outline the food safety practices in place with daily records kept in the diary."
It shaped step 7's insistence that every monitoring line ends with where the reading is recorded, because in a small kitchen that place is almost always a daily diary, and a plan that specifies monitoring with no home for the record produces nothing an officer can read.
Where the skill departs: this skill writes a plan from the owner's own process rather than filling in a pack. That is a deliberate choice for the owner who does something SFBB's pre-written safe methods do not cover, or who wants a document that reads like their kitchen. It is not a claim that SFBB is inadequate, and the skill says explicitly that SFBB is one published way of meeting the same duty.
Could not be loaded
The Food Standards Agency's MyHACCP guidance, at https://myhaccp.food.gov.uk/help/guidance/preparatory-stages and https://myhaccp.food.gov.uk/help/guidance/introduction-myhaccp, returned HTTP 403 Forbidden on 14 September 2026 and could not be read. Its eight preparatory stages would have been the natural source for steps 1 to 3, so those steps are built instead from Article 5's own text plus what the skill labels as good practice, and nothing from MyHACCP is quoted or cited anywhere in this skill. Also unreadable: the FSA's "Chapter 4.2 HACCP Based Procedures" page now redirects to the Manual for Official Controls landing page at https://www.gov.uk/guidance/food-standards-agency-manual-for-official-controls, which carries no substantive text and sends readers to a separate portal.
Best public prompt we found for this job
There is no credible public prompt or skill for writing a UK HACCP plan, and saying so is more useful than promoting a weak one. A stars-sorted search of api.github.com for HACCP and food safety repositories (https://api.github.com/search/repositories?q=HACCP+food+safety&sort=stars&order=desc, fetched 14 September 2026) returned nothing above two stars in the top ten. The field is portfolio pages, coursework and month-old side projects.
The nearest in purpose was **OsamahAlmhammadi/Smart-Haccp-Analayzer**, https://github.com/OsamahAlmhammadi/Smart-Haccp-Analayzer, star count read from https://api.github.com/repos/OsamahAlmhammadi/Smart-Haccp-Analayzer on 14 September 2026: **1 star**, no licence declared, created 12 May 2026, last pushed 7 August 2026. Its description is "A Python tool for automated food safety risk assessment based on HACCP and ISO 22000 standards."
The one idea worth taking from it is in that description: running the assessment step by step rather than as a single judgement, which is what steps 4 to 7 of this skill do across the flow diagram.
What we did not copy, and why. It is built to ISO 22000 as well as HACCP, and ISO 22000 is a voluntary certification standard, not UK law; importing its vocabulary into a small caterer's plan would put words in front of an environmental health officer that answer a question nobody asked. It declares no licence, so its content could not be reused even if it were suitable. It is not UK specific, and every critical limit in a UK plan has to trace to UK guidance. Most importantly, it automates the risk judgement, and this skill deliberately does not: which of your steps is critical, and what number belongs at it, is the part the owner and their adviser must decide and be able to defend, not the part to hand to a scoring function.
Want this running in your business?
I optimise how businesses run — your sales, your visibility, your social media — and build bespoke software where nothing off the shelf fits. The first conversation is free. Work starts from £150 a day.
Foxera