Start a free trial
Menu

AMedP-4.12

AMedP-4.12 food and water defence

NATO food supply and food services operations, and the contracted food processors, suppliers and caterers that supply or provide for NATO Operations

AMedP-4.12 is NATO's food defence policy for food supply and food services operations, covering the precautions against deliberate contamination of food or water, agreed under STANAG 2556.

Edition
A
Published
2019-03
Evaluated by
customer-audit

What it is

AMedP-4.12 is the NATO Allied Medical Publication that sets food defence policy for NATO food supply and food services operations. Food defence is the document's own term for the precautions taken against deliberate contamination of food or water "by individuals or groups that want to inflict harm to NATO Operations," and it is explicit that this is a separate concern from food safety, which deals with unintentional contamination. The two have to run together in practice, but the document is about the deliberate kind.

It addresses NATO's own food supply depots, retail shops, food services facilities, restaurants and coffee shops, and it extends the same obligations to outside organisations: "contracted food processors, food suppliers and food services operations that supply/provide for/to NATO Operations must have a written Food Defence Plan." A civilian caterer or supplier working a NATO contract sits inside the document's scope on the same terms as a NATO-run facility. Nations record their agreement to use the publication in STANAG 2556; a nation can ratify with reservations, and at promulgation France recorded that it "will not implement AMedP 4.12," while others recorded partial ones. For a contracted supplier, the obligation travels with the contract itself: where food services are contracted out, the contractor has to run the same assessment a NATO-run operation would.

Responsibility, and the recurring obligations

Overall responsibility for food defence sits with commanders at all levels; day-to-day responsibility for a feeding facility sits with its kitchen manager. Around that, the document sets a handful of standing obligations: traceability that runs both upstream, to where food originates, and downstream, to who receives it, so a suspected batch can be found and pulled from the chain in either direction; a recall system that quarantines suspect food immediately and brings in security elements; a procedure for investigating suspected tampering that removes the affected food from every stage of the chain and can call on veterinary, medical and preventive medicine personnel; and a crisis-management and contingency plan so a facility that has to close, in whole or in part, can keep its food services operation running.

The Food Defence Risk Assessment and Plan

Every NATO food supply and food services operation has to complete a Food Defence Risk Assessment, using the questionnaire at Annex A, before it starts work, and that assessment "should be revaluated at least once per year (or more frequently when required)" (clause 1.2.7), in consultation with security elements. The assessment feeds a written Food Defence Plan, which security elements review and give a security designation before it is used. A contracted food processor, supplier or food services operation supporting NATO Operations has to do exactly the same: complete its own risk assessment and hold its own written plan.

Approved sources

Chapter 2 opens with the food and water supply itself, and the operative idea is the "approved source." A source is the location where food or water is actually produced, not a distributor or a distributor's facility, and it counts as approved where it has been audited in accordance with AMedP-4.5 or STANAG 2556, where it is listed in a named US Army directory of sanitarily approved establishments, or where it operates in the European Economic Area under EU legislation or is delivered by an EU/EEA approved exporter. Managers have to keep sourcing records for a minimum of six months so Preventive Medicine or Veterinary personnel can verify them (clause 2.2.3); where a source cannot be identified this way, the product is treated as unapproved. The use of local, in-Theatre sources is discouraged; where one is considered, it can only be approved after a qualified auditor has audited it under the same AMedP-4.5/STANAG 2556 route.

The other three areas Chapter 2 covers

Beyond sourcing, Chapter 2 works through transportation, physical security of food services facilities, and employees and visitors, requiring each to be covered by a documented programme that is brought within the same audit cycle as everything else. Food has to move by authorised means, with documented handling controls and inspection of deliveries. Facilities have to run a documented physical security and access programme. Personnel working in food services need a security clearance appropriate to the role, pre-hiring screening, and food defence training given on a need-to-know basis and reviewed by security elements; visitors need an equivalent clearance or a chaperone for the duration of their visit. The document sets out the operational detail of these programmes at length; that detail belongs to the security element designing and running it, not to a page written for a general reader.

Annex A - the risk assessment questionnaire

The Food Defence Risk Assessment itself is a self-assessment questionnaire that a food supply depot or food services manager completes before starting operations and at least annually, working through each area of the operation and recording whether a given practice is in place, not applicable, or unknown, together with what will be done to close any gap. It is signed and dated on completion. The document notes that the questionnaire is "adopted and adapted from" guidance published by the US Food and Drug Administration; this is the only outside civil scheme or method the document draws on.

How you are evaluated

There is no third-party certification against AMedP-4.12. Compliance is checked two ways, and both run through NATO rather than an accredited outside body. Audits: "food defence audits as part of the overall audit system should be conducted by NATO representatives," folded into the normal food safety inspection cycle and held at the same frequency, though the frequency can be adjusted against a Theatre threat assessment. Self-assessment: the facility or contracted operation completes the Annex A questionnaire itself and uses it to build and keep current its own Food Defence Plan. Separately, a supplier's "approved source" status is established by an audit against AMedP-4.5 or STANAG 2556, or the EU/EEA route described above - that audit assesses the source, not AMedP-4.12 itself.

Standards it references

  • STANAG 2556 is the agreement this publication sits under: "the agreement of nations to use this publication is recorded in" it, and it is also one of the two routes by which a food source's audit can establish it as approved.
  • AMedP-4.5 is the Allied Medical Publication on audit principles that AMedP-4.12 ties "approved source" status, and food defence audits more generally, to.
  • AMedP-4.7 is named once, alongside AMedP-4.5, as also carrying the applicable food defence audits.

Getting the document

AMedP-4.12 is free of charge, published by the NATO Standardization Office. We do not sell it or host a copy. It can be retrieved from the NATO Standardization Document Database, where NATO should be credited on reproduction.

How we help

AMedP-4.12 is an operational document. The work it describes - running a food defence audit, screening and training staff, inspecting a delivery, keeping a Food Defence Plan current - happens in the day-to-day running of a food supply or food services operation, not in software. What an organisation still has to hold, and what a NATO representative's audit or its own security element will ask to see, is the paper trail behind that work: the current Food Defence Risk Assessment and Food Defence Plan, evidence that the plan was reviewed on schedule and in consultation with security elements, records of staff food defence training, the sourcing documentation that establishes a food source as approved, and the corrective action raised after an audit finding or a tampering investigation. ComplyTrain gives a supplier, caterer or operator a controlled place to hold, version and produce those documents and records on demand, and to keep the training record that shows staff were trained against the current plan.

It does not conduct the food defence audit, run the risk assessment on an organisation's behalf, or carry out the physical security, screening or inspection work the document describes. That work is done on the ground, by a NATO representative or the organisation's own security element, not by a compliance platform. If you hold or are bidding on a contract that carries a food defence obligation, the standards explorer lists the related publications, or talk to us about how we support the evidence side of that work.

Standards it references

Questions

Is AMedP-4.12 mandatory for a food supplier or caterer?

It binds nations through their agreement in STANAG 2556, and a nation can ratify with reservations - France, for example, recorded that it will not implement it. It reaches a contracted supplier or caterer because the contract for NATO food or water services requires the same Food Defence Risk Assessment and Food Defence Plan that a NATO-run operation holds, not because the document exists in NATO's catalogue.

What is the difference between food defence and food safety in this document?

Food defence is defined as the precautions against deliberate contamination of food or water by someone intending harm; food safety concerns unintentional contamination. AMedP-4.12 treats them as distinct disciplines that nonetheless have to be run together, with food defence audits folded into the existing food safety inspection cycle rather than a separate process.

Does AMedP-4.12 offer a certification?

No. NATO does not certify organisations against this document. Compliance is checked by NATO representatives auditing food services operations directly, at the same frequency as food safety inspections, and by the operation's own Annex A self-assessment. A food source's "approved" status is a separate audit outcome, assessed against AMedP-4.5 or STANAG 2556, not against AMedP-4.12.

How often does the Food Defence Risk Assessment have to be reviewed?

At least once a year, or more often when required, and in consultation with security elements. It has to be completed before an operation starts, and a contracted food processor, supplier or food services operation supporting NATO Operations has to complete the same assessment.

What edition of AMedP-4.12 is current?

Edition A, Version 1, promulgated in March 2019. The document gives no indication of an earlier edition it supersedes.