Technical is key for ERM

Your Board Has a Risk Register. Your Technical Team Is Half of It.

For eight years I owned the crisis management programme at Aldi GB and Ireland. That meant I was the person who thought, on a normal Tuesday, about the abnormal day. The batch that should never have shipped from suppliers. The ingredient that turned out not to be what the specification said leading to a call from a supplier. The supplier three tiers back that was supplying into your supplier’s supply chain. Before that, at PepsiCo, I approved the ingredients and raw materials coming into the business across Europe, which is another way of saying I decided what the company was allowed to expose itself to. I recall a point in time where I was placed under intense pressure to approve a raw material which I resisted – I was proved correct when a colleague went to China and confirmed my initial recommendation.

I did not think of either job as risk management at the time. It was just the job. Looking back, that is exactly what it was, and it is the reason I now think most food businesses have a blind spot in the boardroom. They have a risk register. They discuss cyber, cash, people and market. And sitting one floor down, doing the single most exposed job in the building, is a technical team that almost nobody at that table treats as a risk function.

 

The reframe worth making

Enterprise risk management sorts a company's threats into five categories. Strategic, operational, financial, compliance, reputational. The useful thing about food manufacturing is that a single technical failure lands in four of those categories at once.

A product recall is operational, because the line stops, the product is temporarily delisted by retailers and stock is destroyed. It is financial, because the cost runs from the destroyed product through the customer penalties to the potential lost listings. It is compliance, because a regulator and a retailer are now both involved. And it is reputational, in a way that outlasts all of the above, because a shopper who impacted by a recall does not forget the brand on the sleeve.

The technical function is the standing control against that whole cluster. Not a support service. Not a cost of doing business. The control. When a business underfunds it, delays its decisions or overrules it commercially, the risk does not disappear. It simply moves off the technical team's desk and onto the enterprise's balance sheet, where it is larger and no longer visible until it goes wrong.

That is the argument in one line. The technical team is enterprise risk management for the part of the business that can actually harm or kill someone. Everything below is what that looks like in practice.

 

Customer standards are risk you have agreed to hold

When a retailer hands a supplier its code of practice, it is not handing over a wish list. It is transferring risk. The retailer has decided which hazards it refuses to carry, and the code is the mechanism by which it pushes those hazards down the chain to the people who make the product. Every clause is a piece of risk the supplier has agreed to own on the retailer's behalf.

This is why "delivering to customer standards" is not the administrative chore it is often treated as. Meeting the standard is the supplier holding up its end of a risk transfer it signed. Failing to meet it is the risk snapping back, and it snaps back at the worst possible moment, in front of a retail technical manager during a visit, or in a complaint that reaches the retailer's own quality team or an EHO before it reaches yours.

The businesses that understand this run their customer standards as a live risk position, not a folder. They know which retailer requirements they are strongest against and which ones they are quietly carrying on trust, and they close the gaps on the second group before a visit or audit finds it. The businesses that do not understand it treat every retailer requirement as equally important, which in practice means none of them gets the attention it needs, and they learn the ranking the hard way when a product listing is put at risk.

 

The BRCGS audit is a risk test, not an exam

I have sat on both sides of the audit table – setting retailer standards and being audited. The thing I would want every site leader to understand is that a BRCGS audit is not really a test of your paperwork. It is a test of whether your risk controls work when you are not personally standing over them.

The grade is the output that matters to the market, because it is the signal your customers read. An A or AA grade tells a retailer that the risk they transferred to you is being held competently. A grade below that tells them to look harder, ask more questions and, in some categories, reconsider the relationship. The grade is a price on your risk, set by someone else, and published. Some retailers have a B grade as a red line for doing business – I recall a retailer visiting a site and walking away because of the audit grade. Let’s be clear some retailers consider the BRCGS audit a licence to trade and will follow-up with their own audits which focus on what they believe are the highest risks to their business and brand.

Run the audit as an annual event and you get an annual scramble, a scramble of tidying and a result that reflects how good your team is at short-term effort i.e. the audit window and on the day. Run it as a continuous risk position and the audit becomes a confirmation of something you already knew. The difference is not more work. It is the same work moved from the window before the auditor arrives to the time when nobody is watching, which is the only time it actually protects you.

The most common non-conformities across recent BRCGS audits are not exotic. They cluster around fabrication and the basics, premises and equipment cleanliness, equipment condition, chemical control, the state of doors and walls. Read that list as a risk register and it tells you something plain. The failures that most often surface at audit are the ones a business stops seeing precisely because they are always there. A technical function that looks at its own site as an auditor would is the cheapest insurance available against that audit blindness.

 

Horizon scanning is the part that earns the board's attention

Most of what I have described so far is about holding today's line. Horizon scanning is the discipline of seeing the line move before it moves under you, and it is the clearest reason technical belongs in a strategic risk conversation rather than an operational one.

The current view is busy, and it is worth being specific because the specifics are what a board can act on.

  1. Packaging has become a live compliance risk, not a future one. The EU Packaging and Packaging Waste Regulation applies from August 2026 and reaches any business placing packaged goods on the EU market, including UK exporters. Its obligations phase in through 2040, so the risk is not a single deadline but a rolling series of them, and the data to meet them originates at the format and specification level, inside the technical and development functions.

  2. Food defence guidance has just been rewritten. PAS 96 was fully revised in 2026, replacing the 2017 edition. It puts more weight on cyber threats, on supply shocks of the kind Covid exposed (some sites closed because of the rampant infections), and on the way climate pressure and cost pressure are pushing fraud, including substitutions and allergen fraud, into the supply network. If your TACCP assessment still reflects the old edition, your defence position is out of date by design.

  3. Allergen risk keeps tightening. Precautionary allergen labelling and the direction of travel since Natasha's Law mean the tolerance for a weak allergen control has fallen and will keep falling. This is the hazard most likely to turn into a fatality and a prosecution, and it is the one where "we have always done it this way" is the most dangerous sentence in the building.

  4. Deforestation and origin due diligence are becoming data problems. The requirement to prove where a commodity came from, down to the plot in some cases, turns supplier approval into an evidence exercise that has to be right at intake, because you cannot reconstruct it later. And your whole end to end traceability system needs to show component traceability and roll this up into mandatory annual reporting.

  5. Climate and geopolitics are now ingredient risks. Crop failures, price spikes and sudden unavailability force reformulation and resourcing under time pressure, which is exactly the condition in which fraud and corner-cutting enter a supply network. Retailers like stability in their supply chain, bringing “issues” with ingredients to your Technical Manager can start to raise questions. And there is the associated cost of updating specifications in an ad hoc manner.

None of these is a problem the finance director spots first. They are spotted by a technical function that reads its supplier requirements, understands the sector and watches its regulators then tells the board what is coming while there is still time to choose a response rather than absorb a shock. A business without that radar is not running lower risk. It is running the same risk with the lights off.

 

The front door: gatekeeping what comes into the business

Everything a food business sells is assembled from things other people made. The largest single category of risk most manufacturers carry walks in through goods-in, and the control on it is supplier approval and verification.

 

I spent years doing exactly this at PepsiCo, and the lesson that stayed with me is that supplier approval is not a form you complete once. It is a position you hold and keep testing. A supplier who was safe at approval can drift, change site, change sub-supplier, lose a key person or come under cost pressure that quietly lowers a standard. The approval that is not verified against reality is not approval. It is a hope with a date on it.

Good gatekeeping does a few things at once. It sets the standard a material must meet before it is allowed near your product. It verifies that the supplier actually meets it, by audit, by testing and by data, rather than by their say-so. It watches for the vulnerability that turns an ordinary supplier into a fraud risk, which is the heart of the VACCP and TACCP work that PAS 96 now pushes harder on. And, increasingly, it carries the ethical and modern slavery due diligence that a retailer and the law both expect.

Get this wrong and every control downstream is working on a false premise, because the hazard is already inside the fence. Get it right and most of the crises I used to plan for never start, because the material that would have caused them was refused at the door.

 

The uncomfortable part for leaders

The awkward truth is that the technical function is usually the first place a business looks to cut when margins tighten, and it is close to the last place it should look. Cutting it does not remove the risk the team was holding. It transfers that risk to the enterprise, uninsured, at exactly the point in the cycle when the business can least afford a recall, a delist due to poor performance or a failed audit.

Treating technical as a risk function changes the conversation at the top of the business. It stops being a question of how little compliance the business can get away with and becomes a question of how much exposure the business is choosing to hold, and whether it knows the size of it. That is a board-level question. It deserves a board-level answer, informed by the people who actually hold the risk every day.

If you recognise your own business here, a technical team doing serious work that the board treats as overhead, I would be glad to talk about how to put it where it belongs, on the risk register and in the room where the risk is priced.

 

David Roos

Seasoned Quality Director with over two decades of experience in the food industry, specialising in quality assurance, compliance, and sustainability.

I excel in leading initiatives that enhance food safety and quality across multiple manufacturing sites, achieving top audit results and substantial improvements in KPIs.

My expertise includes developing comprehensive technical strategies that align with global standards and customer expectations, significantly reducing costs and enhancing product standards. Committed to sustainability, I have successfully delivered plans to reduce carbon footprints and achieve Net Zero commitments.

As a strong communicator and strategic negotiator, I thrive in building and nurturing relationships with key stakeholders, including major retail and QSR customers.

https://Www.ukwazi.co.uk
Next
Next

Who Owns the Check?