A checklist tells you whether today was right. A plan tells you why those are the things being checked, and it is the document a small restaurant is least likely to have written down. In many jurisdictions some version of it is required; in all of them it is the thing that turns a folder of signed sheets into an argument that you know what you are doing.
🗺 What a plan actually is
Stripped of the acronyms, a food safety plan answers four questions about your own operation, in writing:
- Where can something go wrong here? Not in restaurants generally — in your kitchen, with your dishes and your equipment.
- Which of those points actually control the outcome? The places where, if you get it right, the hazard is dealt with, and if you get it wrong, nothing downstream saves it.
- What do we do at each one, and how do we know it worked? The limit, and the measurement that proves it.
- What happens when it does not? The corrective action, decided in advance rather than at eleven at night.
That is the whole idea. Everything else — the forms, the terminology, the numbered principles — is the formal expression of those four questions, and the formality is what your authority tells you about. The thinking is yours and nobody can do it for you, because it depends on what you actually cook.
🎯 Finding your own control points
Most small restaurants have somewhere between three and six points that genuinely control the outcome, and the exercise of finding them is worth more than the document that comes out of it.
Take your menu and follow two or three dishes all the way through: delivery, storage, prep, cooking, holding, cooling, reheating, service. At each step ask what could make somebody ill and whether a later step fixes it. If a later step fixes it, that step is not the control point — the later one is.
Done honestly, most kitchens end up with a short and unsurprising list: cooking to temperature, cooling, cold storage, and cross-contamination during prep. Sometimes reheating. If you serve anything raw or lightly cooked, or you do anything unusual — curing, vacuum packing, cooking long and low — that is its own control point and it is the one an inspector will ask about first, because it is where the ordinary rules stop being enough.
The dish-by-dish walk is also what makes the allergen work from the food safety course concrete, and it uses the same route: the difference is that there you were following contact, and here you are following the hazard.
📝 Writing it so somebody else can use it
The plan has to survive you being away, which means it is written for the person who is there, not for the person who wrote it. Two sides of paper is a perfectly good plan for a twelve-person restaurant; twenty pages copied from a template is a plan nobody will ever open.
- One line per control point, in the kitchen's own words: what the step is, what the limit is, who checks it, how often, what they record.
- The corrective action next to it. "If the reading is out of range: move the product, record it, tell the manager." Decided now, when it is calm.
- The name of a person, exactly as with every list in the compliance course. A plan owned by "the kitchen" is not owned.
- A review date. A plan written for a menu you no longer serve is worse than none, because it demonstrates a system that stopped being true.
- Point it at the logs rather than repeating them. The plan says the temperature is checked twice a day; the log is where the readings live. Two documents, one job each.
And then the part that everybody underestimates: the people doing the steps have to know the plan exists and what their bit is. An inspector who asks a cook what happens if the reading is high and gets a shrug has learned more about your plan than by reading it, which is exactly what the next topic is about.
🔗 Where this sits with everything else
It is worth being clear about how the three documents in this run relate, because they are easy to confuse and they do different jobs.
The plan says what is controlled and why. The checklists from the compliance course are how the controls get done each day. The logs are the evidence they were. The plan is the smallest of the three and the only one that explains the other two; without it, a folder of records is a set of answers with the question missing.
If you already have the checklists and the logs from the previous two courses, writing the plan is a couple of hours and mostly consists of putting words to decisions you have already made. If you do not have them, the plan is the wrong place to start — go back and build the folder first.