
Almost every serious instrument in AI governance now requires an organisation to run a risk process. None of them tells the organisation where in its own lifecycle the control points sit, what measurable limit applies at each one, what happens automatically when a limit is breached, or who is competent to verify the measurement. That layer — process control — is missing, and it is the layer on which everything else depends. A management system without control points produces documentation; it does not produce safety. This paper supplies that layer by importing a method that has governed an invisible hazard across a globally distributed production chain for fifty years: Hazard Analysis and Critical Control Points. The claim is deliberately narrow. HACCP is not proposed as a rival to ISO/IEC 42001, to Article 9 of the EU AI Act, or to the NIST AI Risk Management Framework. It is proposed as the process-control layer their architecture presupposes and does not contain, and as the one methodology in existence with a demonstrated property that AI governance urgently needs and currently lacks: scale invariance. The same seven principles govern a village bakery and a multinational dairy — which is why one inspector, one standard and one accreditation system can cover both. Nothing in AI governance has this property today. Version 4.0 differs from version 3.0 in four substantive respects. First, the unit of governance has moved from the international regime to the organisation's own plan: this is a self-control standard, not a treaty proposal. Second, it introduces a three-tier structure — deployer, provider, frontier developer — with an explicit proportionality rule modelled on the flexibility provisions of EU food-hygiene law. Third, it distinguishes three kinds of limit — critical limits, operational limits and indicator thresholds — and reclassifies the compute thresholds now written into law as the third kind. Fourth, it reads the three published frontier safety frameworks as what they structurally are: Tier 3 HACCP plans, independently invented, each written in a private dialect, none of them auditable by a third party against a common form. The paper specifies the method in the full twelve-step Codex sequence, gives a hazard taxonomy, a control-point decision tree, a catalogue of seven control points spanning the lifecycle, a table of critical limits drawn from instruments already in force, three fully worked plans, an auditor's conformity checklist, and a mapping to ISO/IEC 42001, the EU AI Act and the NIST framework so that adoption earns credit against obligations an organisation already has. It also states its own limits without softening: the single most consequential gap in AI-governance infrastructure is metrological — there is no analogue of ISO/IEC 17025 for capability evaluation — and one structural disanalogy has no food-safety precedent at all: a pathogen does not model the control system trying to detect it, and a sufficiently capable AI system may.
