Next Article in Journal
Strang Splitting Combined with Periodically Fitted Adams–Bashforth–Moulton Method for High-Precision Simulation of Multiplicative Noise SDEs with Periodic Drift
Previous Article in Journal
Research on Mathematical Modeling of Infectious Disease Spread on Cruise Ships
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Computing with HACCP Risk and Safety Characterizations

1
Department of Industrial Engineering and Management, Oulu University, 90570 Oulu, Finland
2
Environmental Health, City of Rovaniemi, 96200 Rovaniemi, Finland
3
Department of Computing Science, Umeå University, 901 87 Umeå, Sweden
*
Author to whom correspondence should be addressed.
AppliedMath 2026, 6(7), 116; https://doi.org/10.3390/appliedmath6070116
Submission received: 31 May 2026 / Revised: 24 June 2026 / Accepted: 15 July 2026 / Published: 20 July 2026

Abstract

The focus of this paper is the semi-quantitative approach to risk analysis in HACCP (Hazard Analysis and Critical Control Points), where we show how alternative computations in the risk matrix, combining probability and impact, can be provided based on algebraic and many-valued logical techniques. Doing so, we further show how applying such computations requires being formal concerning underlying information structures, which in turn enables being formal concerning functional representation of mappings between information structures appearing within risk analysis in risk management. Our mathematical algebraic framework also enables a more formal treatment of the duality between threat and opportunity.

1. Introduction

Socrates would say “Thou shouldst eat to live; not live to eat”, whereas modern times acknowledge the pleasure of eating. Epicurean nudging brings that pleasure forward to being on a path to healthier eating, so that eating pleasure may even be an effective lever for healthy eating. In our times, we would thus rather say “we eat to live, and we live to eat”, combining health and pleasure, but thereby, unfortunately, also being forced to deal with safety issues related to food and eating.
Food safety systems and processes are applied in order to ensure that food reaching the consumer is safe. Risk management in food safety on national levels is based on international standards like the Codex Alimentarius [1], WHO/FAO’s guideline on Risk characterization of microbiological hazards in food [2], and the European Commission NOTICE 2022/C 355/01 [3].
Food-related hazards can be managed using different methods, of which HACCP is one of the most well known. The HACCP system has evolved over decades into a widely recognized standard endorsed by the Codex Alimentarius Commission [4]. HACCP has revolutionized food safety management by providing a structured framework for hazard identification, risk assessment, and monitoring [5].
Mathematical and computational modeling within HACCP’s process descriptions, traditionally based on statistics and probability theory, has been extended with semi-quantitative approaches developed at the turn of the 21st century [2]. The influence of this computational extension is still strong today [3,6].
In this article, building upon [7], we examine the semi-quantitative approach to risk analysis from a mathematical and logical perspective, leaning on algebraic models, extending the arithmetic-based risk analysis that has been at the heart of risk calculation for the last twenty years. Thereby, we also focus more on sets and structures of risk sources and on formalizing functional and algebraic relations between such structures, thus improving the functional modeling of the food safety management process. The algebraic approach complements numeric approaches as traditionally provided within HACCP’s probability theory-based computational approach.
This paper aims to reveal the weakness of computations adopted within traditional risk analysis and risk matrices, or more precisely, the lack of acceptance that we may have computations beyond simply using arithmetic operations. We present a complemented, improved, and extended model that better reflects reality in the sense that reality calls for embracing a larger scope and variety of computations. The restriction only to use arithmetic operations in many cases enforces a computational straitjacket on assessment, whereas moving from arithmetic to include more general algebraic computations opens up a spectrum of assessment operations. Color coding commonly used in risk matrices is thereby also more clearly and logically explained within the algebraic machinery.
Our mathematical algebraic framework also enables us to more formally treat the ‘duality’ between threat and opportunity.
The outline of the paper is as follows. In Section 2, we provide a brief overview of HACCP. In Section 3, we discuss the dualities within risk and safety. Section 4 introduces the formalism adopted within our functional approach, and the approach is applied in Section 5 for nomenclatures and definitions in guidelines and standards. Section 6 extends the mathematical modeling by using the algebraic technique proposed in this paper to provide a formal description of how risk and safety are antinomies. In Section 7 we discuss some examples and concrete cases where a broader approach to risk matrix computations is required. Section 8 concludes this paper. Additionally, in Appendix A, we provide an overview of quantales and their properties, and in Appendix B, we discuss some concepts in probability theory and how there is sometimes confusion about these concepts. Appendix C presents a brief vocabulary and short summary of mathematical notation used in this paper.

2. HACCP

HACCP was originally developed to ensure food safety for NASA’s space program in the 1960s. Later on HACCP came to be used also for non-food processes or activities [4,8,9]. In 1993, the Codex Alimentarius [1], led by FAO and WHO [2], adopted the HACCP system as part of the Codex Guidelines [10]. In 1994, the Codex formed the basis for the international food safety requirements for trade, and the guidelines play a significant role in harmonizing the HACCP system in international practice [11].
Nowadays, HACCP is seen as a proven and scientifically based system, and the use of HACCP is required in most countries for organizations anywhere within the food chain, from primary production to consumption. HACCP systems are expected to be promoted by national and local health departments as they can effectively determine food safety procedures [3,7,8,9], and, as stated in [12], adherence to HACCP is indispensable and should be adopted at all levels of the food industry to maintain food safety and quality for the public. The use of HACCP is also important in regions that have ecological problems [13]. HACCP is promoted nationally and within regions by authorities, and it differs from country to country, and within countries, even from region to region.
Within organizations, an understanding of HACCP is required at all levels, although it is mainly used at operational levels. Hazard assessment methods aim to ensure food safety and that risks are minimized by monitoring, and further by controls throughout a process rather than through inspections at the end of the process. The technique provides a structured model for identifying sources of risk, i.e., threat and hazard, and putting controls in place in all relevant process steps [9,14]. HACCP is used mainly in relation to health and safety issues of a product and not so much with respect to other perspectives, such as quality, defense, and authenticity of the product. However, the principles of HACCP are the basis of most food assurance systems [6,14].
The CODEX presents HACCP as formed from twelve CODEX HACCP application steps. The first five steps are preliminary actions, and the rest are the seven CODEX HACCP Principles. CODEX’s preliminary actions are the following ([15], p. 33):
  • Step 1: assemble HACCP team
  • Step 2: describe product
  • Step 3: identify intended use
  • Step 4: construct flow diagram
  • Step 5: on-site confirmation of flow diagram
In HACCP procedures, presented in different context for example in ([15], p. 33) and [7,14], these preliminary actions may be formulated differently in comparison with the CODEX definitions. There are also differences in the number of preliminary steps, and the descriptions vary depending on the source. The same goes also for descriptions of the seven principles. Depending on the context of the application, what is done in each step may vary.
The seven CODEX HACCP Principles are the following:
  • Principle 1: Conduct a hazard analysis
  • Principle 2: Determine critical control points (CCPs)
  • Principle 3: Establish critical limits
  • Principle 4: Establish a system to monitor control of the CCPs
  • Principle 5: Establish corrective actions
  • Principle 6: Establish verification procedures to confirm HACCP effectiveness
  • Principle 7: Establish record-keeping and documentation procedures
The strength of the HACCP risk assessment technique is that, as a structured process, it provides documented evidence of quality control and the identification and reduction in risks. It focuses on practical questions of how and where sources of risk can be found and controlled in the process. HACCP encourages proactive risk management throughout the process, rather than relying on the inspection of the final product. It focuses on the risk and on preventive control given critical control points, at times during or after control implementation [9,14,15].
The limitations of the technique are that HACCP requires that hazards are identified, i.e., the risks represented as defined, and that their significance is understood as input to the process. Appropriate controls must also be defined, and HACCP might need to be combined with other tools to provide these inputs. Taking action only when control parameters exceed the defined limits can miss gradual changes in control parameters that are statistically significant, and hence such changes should be considered and added into implementations [9,16].
The starting point for an effective HACCP system for food safety is the implementation of the planning steps, hygiene practices, and prerequisite programs, which are in place and in operation. Based on these, the HACCP technique can be applied in accordance with the seven HACCP principles, identifying specific risk points in production and determining risk management methods for them [7,14].
HACCP begins with a hazard analysis, based on flow diagrams. In a hazard analysis, at a general level, products or product groups are defined and listed, hazards and risk factors related to production processes are identified and assessed, and the probability and severity of the risk are assessed. After this, critical control points, their control measures, monitoring, monitoring assurance, and documentation are determined. If the nature of the hazard makes it inappropriate to use critical control points, control points/O-PRP can be selected, and the monitoring procedures to be used in them are determined [7,14,15]. Finally, verification procedures are established for recording and documenting the resulting data for the monitoring of critical control points. Hazard assessment should cover the entire operation and interact with the food safety management system [7,14].
In the following, we discuss HACCP Principles 1–5 in some more detail.
HACCP Principle 1 is the “information critical” principle in the sense that it involves not just identifying hazards and providing a listing of (all) potential biological, chemical, or physical hazards appearing at all stages of production, but also involves the evaluation of each and every hazard in terms of severity and occurrence. Once the severity and occurrences of hazards have been estimated using pre-defined levels, the levels of severity and occurrence are combined into overall qualifications of risk related to these hazards. The aggregation of severity and occurrence levels into a risk level is a non-trivial task since there is no “universal formula” for defining a risk matrix, and so that it can be claimed as valid for all types of hazards. In Section 5 and Section 7 we present various options for the provision of such risk matrices.
HACCP Principle 2 identifies specific CCPs, where the CCPs are points or procedures within the production process, to which sublists of hazards reached in P1 are assigned, and where loss of control may lead to unacceptable risk.
Corrective actions according to HACCP Principle 5 are then applied to eliminate, reduce, or prevent the hazard from appearing within acceptable limits established by HACCP Principle 3.
Monitoring according to HACCP Principle 4 involves observations and measurements in support of determination whether or not critical limits are being met and maintained.
HACCP Principles 1–5 can be seen as implemented in a feedforward workflow that also benefits from backward reinforcement, in particular when the establishment of critical limits turns out to be connected with uncertainties. In terms of general aspects of risk analysis, the Codex Alimentarius [1] recognizes that risk analysis is an iterative process, and interaction between risk managers and risk assessors is essential for practical application. It is also stated that the risk management options selected should reflect the degree of uncertainty and the characteristics of the hazard. This essentially calls for reinforcing experiences from Principle 5 backward to Principle 3.

3. Understanding Risk and Safety

Risk assessment in HACCP, one of the most relevant risk assessment techniques to food safety, and risk assessment more broadly, involves many terms like safety, risk, threat, probability, and severity. The terminology is not uniform, and different sources define and use terms in various ways. This can be confusing. Effective risk management requires agreement on the terminology used [2,16,17].
In general, it is important to understand that risk assessors and others define terms based on their own understanding. The terms are then more or less subjective and should be critically examined [2]. The approach in this paper is similar in that our use of terms also reflects our understanding, and in particular, as we propose complementary computational models. We do not attempt to define the terms exhaustively, but we do aim to define the terms from a mathematical perspective and primarily so that mathematical modeling discussed in relation to food safety risk assessment can be rigorously explained.
Let us start with the terms risk and safety. From the point of view of the risk management process, it is important to define the term ‘risk’ so that risk can be identified and characterized. Identification and characterization are prerequisites for risk assessment because unidentified risks cannot be managed [2,16].
There is no clear consensus on the definitions of risk and safety, where ambiguity in nomenclatures and definitions is also seen within and between various standards related to risk and safety. Over time, there have been many definitions of ‘safety’. Overviews of contemporary definitions and interpretations of safety are presented in [18,19,20].
We may agree that risk is indeed crucially linked to safety. Since in this paper we are considering risk from a functional perspective, we should define risk due to the relationship between cause, risk, and effect. Risk as an object has two dimensions, namely uncertainty, described as “probability”, and effect on objectives, described as “impact”. A risk is then defined as any uncertainty that, if it occurs, will affect one or more objectives [16,21].
Uncertainty is associated with risk, and risk can be defined as the effect of uncertainty [15,16,21]. Uncertainty can be seen as the root source of risk, namely any kind of “deficiency of information” [21], which matters in relation to objectives ([16], p. 24), and thereby specifies the relationship between these two terms, so that risk is a measurable uncertainty and uncertainty is an unmeasurable risk. Notions of uncertainty related to probability and likelihood are discussed in more detail in Appendix B.
Risk has a focus on minimizing and eliminating the downsides of risk sources identified within the working processes, whereas safety has a focus on maximizing and maintaining the upsides of activities promoted within these processes. Maintaining safety and proactively augmenting its upsides is at least as important as preventing risk and reactively abate its downsides.
Safety is frequently understood as the successful avoidance of risk, whereas here we describe safety as also including commitment to continuous improvement. These two types of safety, i.e., successful avoidance of risk and commitment to promoting upsides, is in [20] called “Safety-I” and “Safety-II”.

3.1. Two Natures of Risks: Opportunities and Threats

Returning to defining risk, in the early 2000s, risk management professionals have been debating the definition of risk. The debate was about whether the definition of risk includes both threats and opportunities, or whether risk is limited only to threats related to the organization’s objectives [16]. In recent definitions of risk, risk is defined in terms of its positive and negative effects. In [15,21], risk is defined as the effect of uncertainty of objectives, where the effect is a deviation from the expected. Deviation can be positive, negative, or both, and can address, create, or result in opportunities and threats.
In addition, it is interesting how [17,21], and also [15], deal with the concepts of threat and opportunity.
An opportunity is a positive situation and can arise from a positive deviation from a risk, as pointed out in [15,21]. According to [21], the opportunity gain is likely and one has a fair level of control. An opportunity is a combination of circumstances that are expected to be favorable to an organization’s objectives [16]. In [15,21], the relationship between risk and opportunity is described so that opportunity is a positive situation that can arise from a positive deviation from a risk. Taking or not taking an opportunity are both a source of risk, but all positive effects of risk result in opportunities. On the other hand, an opportunity for one party may pose a threat to another, and vice versa [21].
A threat is determined as a negative situation that may damage one’s objectives. It is a potential source of danger, harm or other undesirable outcome [16]. According to [21], a threat is a negative situation in which loss is likely and over which one has relatively little control.
Whereas “risk source” is included in the nomenclatures, “safety source” is not. Generally speaking, a threat can be seen as a risk source, or as part of a situation involving hazards which are related to risk sources. Opportunity can correspondingly be seen as a safety source, or a situation related to a safety source.
Hazard is a source of potential harm and can be a source of risk. Hazard is a factor that has the potential to cause a negative deviation from the expected outcome, either alone or in combination with other factors [21].
Hazard and threat are defined in [21] as being quite similar terms. They describe both the negative effect of risk on the objectives as sources of potential harm. The positive counterpart to a threat is used as an opportunity, but on the other hand, the definitions of the terms are not mirror images. A threat is defined as being relatively difficult to control, while an opportunity is easier to control. There is no direct opposite term for hazard, which as a term describes a possible situation that is difficult to control.
In [16], the risk and safety antinomy is dealt with in terms of threat and opportunity. Risk is more conventionally defined as related to risk-as-threat (“bad things”), whereas opportunity is connected with professional activities in order to maintain safety (“good things”).
In other areas, e.g., as in policy-making, it is said that transformative policy design risks are underestimated, and economic opportunities are not assessed in practice [22], where a “risk-opportunity analysis” extends conventional economic cost–benefit analysis, providing new guiding principles for policy-making.
The antinomy, represented by some order-reversing antinomic mapping, is frequently said not to be “involutive” in the sense that the antinomic mappings are self-inverses, i.e., mapping a point to a point, and “mapping it back” brings us to the same point where we started. However, even if the situation with mappings is not involutive, it may well contain some fixpoints, i.e., some characterizations may be mapped and mapped back to the same original point where the mapping started. This situation is discussed in the context of so-called “Galois connections”, explained in Appendix A.

3.2. Risk Management Needs to Combine Process Views and Information Structures

The understanding of risk management and its process varies in different contexts [1,2,15,16,17]. Our purpose in this paper is to illustrate the risk management process, based on our own understanding, so that we can tie the functional knowledge to the risk management process.
In [17], the risk management process is described as involving the systematic application of policies, procedures and practices to the activities of communicating and consulting, establishing the context and assessing, treating, monitoring, reviewing, recording and reporting risk. This process is illustrated in “Figure 4—Process” in [17].
The risk management vocabulary in [21] provides terminology separately related to “risk”, “risk management” and “risk management process”, where “risk” is seen as a deviation from something expected, and which can result in opportunities and threats. “Risk management” is seen as coordinated activities within an organization, where risks affect their strategic, tactical or operational objectives. A “risk management process” is in [21] defined as a systematic application of management policies, procedures and practices to the activities of communicating, consulting, establishing the context, and identifying, analyzing, evaluating, treating, monitoring and reviewing risk. In this general definition of the risk management process, “risk assessment” is not explicitly mentioned, but appears as defined within the nomenclature as an overall process of risk identification, risk analysis and risk evaluation.
The view on “process” in [2] differs from views represented by [17,21], as it puts risk analysis in focus, saying that risk analysis is a process consisting of risk assessment, risk management and risk communication, having emerged as a structured model for improving food control systems, i.e., focus is placed on the “process of computations”. For the purpose of this paper, and as generally discussed in this section, we adopt both views, recognizing that a formal definition of “risk management” is not needed, and that risk management involves information connected with risk, and processes managing such information, where management includes information handling, and where risk assessment is the most “computing intensive”.
Risk assessment in turn covers the identification, analysis, and evaluation of risk, based on the information scope observed and recorded within a particular context of risk monitoring and communication, corresponding to the view presented in “Figure 4—Process” in [17].
Information within the scope of risk is, within the subprocess of risk identification, recorded for a set of risk sources. Risk identification is followed by the subprocess of risk characterization, where each risk source is annotated with a quantification or qualification by means of a characterization function, defined in Section 4, i.e., risk characterization is a prerequisite to risk analysis.
In this article, we focus on the characterization of risk within risk analysis. We build upon our functional view related to risk sources, uncertainties, probabilities, and consequences associated with this process step. We look at the identified risks based on the assumption that the risks have been correctly identified.
Assessment in “risk assessment” is a generic name for a procedure of working or a general policy, and not to be confused with mathematical functions representing assessment in the computational sense, where computational risk assessment embraces numeric or symbolic estimations or assignments of numeric or symbolic values that appear in the range of functions that map sources in the domain of the function to values in the range of the function.
Risk analysis is frequently used in contexts involving food safety and biochemistry. It is somewhat surprising that modelling success of treatments and interventions in medical contexts shows less involvement of risk analysis. In clinical contexts, clinical guidelines are developed for the purpose of lowering risks, focusing on the use of probabilities. However, impact in the form of adverse events is often not properly included in risk models, including the evaluation of the effect of interventions given diagnostic thresholds on modelled risk [23].

3.3. Food Safety

Risk management and its process, as discussed in general in the previous sub-section, embraces specific food safety risk management, where the main objectives are to protect consumer health and ensure fair practices in food trade ([1], p. 102). However, the most important issue is to protect consumers’ health and safeguard public health [1,8]. In this sub-section, we will look into more detail on food safety and “how to stay safe”.
Food safety is understood through its effects on consumers, i.e., humans and animals. Food is defined as “safe” when it does not cause adverse health effects on consumers. The definition of food safety in this context, however, does not include other aspects of safety, for example, malnutrition (see [2], p. 19 and [15], p. 5).
The term “Food Safety” should not be confused with the terms “Food Security”, “Food Quality”, “Food Defense”, and “Food Authenticity” ([15], p. 5 and [6]). However, Ref. [1] offers the term Food Hygiene, the definition of which is wider, but also includes a safety perspective.
Functionally speaking, risk is a function of the probability of an adverse health effect and the severity of that effect, consequential to one or more hazards in food ([1], p. 104 and [15], p. 5). In [15], the concept of “hazard” is from a probability theory point of view defined fairly well. Saying that (food) safety is related to (the presence of food) safety hazards is obviously saying that safety relates to the presence of hazards, and then it makes sense to say hazards can occur. In that case “hazard” is, from probability point of view, seen as an event, whereas a hazard as an agent ([15], 3.22) would rather be seen as a sample. However, in the discrete case of a random variable, a singleton set of samples is indeed an event. In its “Terms and definitions”, ref. ([15], 3.22) indeed defines food safety hazard [1,24] as a “biological, chemical or physical agent in food”, i.e., a hazard is an agent, which then can be viewed as a risk source, i.e., as a sample in the sample space. See Appendix B for definitions of formal concepts used in probability theory.
Food safety is primarily seen as the occurrence of food safety hazards at the point of consumption when it is prepared and/or consumed according to its intended use, where definitions establish the understanding to ensure that the safety of food occurs at all stages of the food chain, from production to consumption ([1], p. 20 and p. 102, [2], p. 19 and [15], p. 5).
In organizational levels, the management of food safety risks and the assurance of the necessary conditions and measures are carried out by an entity formed by several mutually supporting parts/sub-systems in organizations [7,10,14,15]. In [17], management is generally defined as coordinated activities to direct and control an organization with respect to risk. In the context of food, the management system can be called, for example, a Food Safety Management System (FSMS) ([7], pp. 22–44 and [15], p. vi).
HACCP is included in FSMS sub-systems. It is important to understand that food safety is ensured by an entity, but for the terms used in connection with it, such as FSMS, the understanding of its formation and sub-systems varies depending on the sources and organizations. However, the understanding of HACCP and Good Hygiene Practice is quite universal.
Properly applied prerequisite programs provide the foundation for an effective HACCP system [10,14]. The prerequisite program (PRP) can be defined as the basic conditions and activities that are necessary within the organization and throughout the food chain to maintain food safety. The PRPs needed depend on the segment of the food chain in which the organization operates and the type of organization [7,15].
In other contexts, good agricultural practice (GAP), good veterinary practice (GVP), good manufacturing practice (GMP), good hygiene practice (GHP), good production practice (GPP), good distribution practice (GDP), and good trading practice (GTP) are related to PRP. Sometimes, they can be understood as part of PRP [7,10]. On the other hand, ref. [15] defines these terms as equivalent to PRP.
As part of the Food Safety Management System, risk assessment methods are used to identify risk. Ensuring food safety, significant food safety hazards need to be controlled by control measures [2,15]. From the perspective of risk assessment, the question of how to distinguish risk from significant risks and when it is necessary to control risk by measurement can be considered quite relevant.

4. A Functional Approach to Risk Analysis

In this paper, we focus on analysis in the sense of mathematical and statistical methods of analysis of data, and how such analysis is used to support decision-making as supported by more formal mathematical–logical structures. Doing so, we need to be precise about the functional notation, and we need to be unambiguous about the terms and definitions that appear in the domain and range of selected functions, in particular as far as functional representation in risk characterization is concerned.
Risk characterization is in [1] “defined”, and in [2] adopted, as the qualitative and/or quantitative estimation, including attendant uncertainties, of the probability of occurrence and severity of known or potential adverse health effects in a given population based on hazard identification, hazard characterization and exposure assessment. Obviously, this “definition” does not have the nature of a mathematical or computational supporting definition but is rather a general name for what risk characterization includes.
The notion of attendant uncertainties is mentioned in [1,2] a few times, without further clarification. In the end, it refers also to elements in some set of qualifications, where such elements in [2] are named, e.g., as “high, medium, low, negligible”. However, even if it is stated that logical qualitative reasoning can provide conclusions, it is then stated simply, without drawing any attention to mathematical–logical formalism and languages, that logic cannot “combine” to determine the overall effect. In this paper, we indeed show how the alternatives for such “combinations” are many, which increases the burden, and we believe joy, of the risk assessor to choose the most appropriate “combinators” for given contexts. In [2], it is rightfully stated that probability assessment, with qualitative characterizations, runs the risk of being too subjective if risk assessors apply their own concepts of the meaning of such qualitative characterizations. Obviously, such meanings will differ from person to person, but the argumentation in this paper is that this freedom and subjectivity will be significantly restricted once the many-valued logical framework for the “combinations” guides and supports the assessor indeed to choose contextually appropriate combinators. It is then very important to note how we need not only to provide meaning to the characterization elements but also, and in particular, to the meaning of the “combination” itself, which in this paper is modeled as an algebraic operation, for which we can choose many, rather than lean on simple and straightforward arithmetical operations.
Reference to mathematical logic in [2] is indeed very shallow, if not actually non-existent. A more formal algebraic and many-valued logical definition of qualitative and/or quantitative and uncertainties is discussed in Section 4.1. An introductory discussion on the algebraic structure of the set of characterizations is provided in Section 4.2, and explanations about how to compute with such characterizations, i.e., how to “combine to determine overall effect”, are provided in Section 4.3.
The functional representation starts with using S to denote a set of sources and by Q a set of (quantitative or qualitative) valuations, and then a characterization or evaluation of sources can be represented by a characterization function
f : S Q
which in [2] is called “categorical labeling” in the context of “semi-quantitative risk assessment”. In this situation, the source set S, the domain of the function, may be a set without any structure, i.e., a set of named sources, or it may be a structured set, e.g., capturing how sources are categorized. The source set is often a set of quantifications in the form of numbers, either natural numbers or real numbers, so that in the case of real numbers the function f has the form f : R Q , where Q, the range of the function, is a set of qualifications like
Q = { l o w , m e d i u m , h i g h }
i.e., the function f transforms quantitative-numerical values into qualitative-symbolic values. In [2], values in Q are called “probability phrases” that have to be interpreted, whereas the algebraic view is that elements in Q are graded truth values to be used in various forms of many-valued logic.
It is important to note how we, in the context of occurrence and severity, have separate characterization functions, respectively, for characterizations of occurrence and severity.

4.1. Quantitative and Qualitative Values

The distinction between quantitative and qualitative values is important (even if not needed to be all that formal), as is the distinction between evaluations and transformations. In this distinction, we prefer not to introduce concepts like “semi-quantitative” as used in Appendix 2 in [3], but rather to be sufficiently formal about values whenever they are treated as numeric or symbolic values.
Computing with numerical values almost always makes use of functions and operations within mathematical analysis, where continuity and differentiability are often important and useful properties of such functions. Working with numerical values also enables us to use distance metrics and geometric properties of numbers, vectors, and many-dimensional objects represented by numbers. Quantitative analysis with numerical values indeed makes use of a wide range of mathematical functions, and typically as used within (real-valued random variable-based) probability theory and statistics.
Qualitative analysis is different, where Q is often a finite set of qualifications, and as such is a set of “ordinal values” in the sense that the valuation set Q can be ordered as a partially ordered set or arranged as a lattice, where lattices are special types of partially ordered sets. In finite situations, a lattice is always complete in the sense that it has a smallest element and a largest element. For example, in (2), the intuitive and mostly adopted order is
l o w < m e d i u m < h i g h
which could be graphically represented as
high | medium | low
Note that these qualifications are indeed just names of symbols, where their meaning has to be explained in the context where they are used. We could use the symbols Q = { , a , } for exactly the same qualification context as long as the symbols are explained exactly in the same way. In this case, the symbol ‘⊥’ would represent the “bottom element”, and ‘⊤’ the “top element”. We could even use numbers as symbols for qualification, like in Q = { 0 , 1 , 2 } , with the “equivalent” (isomorphic) graphical representation
2 | 1 | 0
and with the identical contextual explanation, paying attention never to fall for the temptation to compute algebraically or otherwise numerically with the symbols ‘0’, ‘1’ and ‘2’, since in this context they are not numbers.
In [2], it is said that 5-point scales are frequently used in semi-quantitative risk assessment, and “sometimes with a sixth category representing zero for probability and impact, and a seventh ‘certain’ category for probability representing a probability of 1”. From quantales point of view, these sixth and seventh values are, respectively, the bottom and the top element of the lattice. We also see, e.g., in [3], the use of 4-point scales, whereas 3-point scales are rarely used.

4.2. Finite and Infinite

Generally speaking, quantification values, numbers and numerical values mostly appear as elements in infinite sets, whereas qualification values, symbols mostly, are included in finite sets.
There are indeed many different types of infinite sets of numbers, and we may often deal with a continuum of decimal numbers either being an interval or the whole range of all real numbers. In probability theory, the continuum of probabilities is the unit interval [ 0 , 1 ] . Loosely speaking, in [3], “likelihood” is said to be the “probability that the hazard is occurring”. Likelihood should not be confused with probability, as likelihood is the “likelihood of a model, " modeling achieved by parameterizing the probability of events, whereas probability is the “probability of an event, whenever a certain model is given. Likelihood and probability values are both in [ 0 , 1 ] , but should indeed be understood differently, in particular when likelihood and probability values are discretized to be represented by symbolic values like ‘High’, ‘Medium’, ‘Small’ and ‘Very small’. In this case, we may have a characterization function, e.g., of the form
f : [ 0 , 1 ] { V e r y S m a l l , S m a l l , M e d i u m , H i g h }
with Q = { V e r y S m a l l , S m a l l , M e d i u m , H i g h } graphically represented as
High | Medium | Small | VerySmall
and with Q being a finite set of qualifications as the range of the qualification function f.
A Likelihood–Impact matrix is discussed in [25], where a nonlinear/geometric labeling scheme supports matrix comprehension better, particularly when likelihood and impact scales are nonlinear.
Qualification values in finite sets and as ranges of qualification numbers appear in many-valued logic as truth values, and ordered as ranging from “totally false” to “totally true”, where the “in-between” truth values are understood as qualifications of truth or degrees of certainty. Note that many-valued logic in this sense should not be confused with fuzzy logic, where Q is taken to be the unit interval [ 0 , 1 ] , and where “fuzzy values” in the unit interval, as set membership values, are not to be confused with probabilities.
We may note that valuation sets Q may be used in different ways in various contexts. The case Q = R may be understood as involving quantitative valuations derived from observations or measurements, where the function f with domain S and range R is more like a random variable
X : S R
with S being a sample set, and R is the set of outcomes, i.e., the outcome of a sample s S is X ( s ) . However, we may note that the nomenclature and terminology in probability theory is not always in consensus concerning the distinction between sample and outcome, sample and event, density and distribution functions and their cumulation, etc., as we point out in Appendix B.

4.3. Computing with Qualification

The finite set Q of qualified valuations is often an algebra with some operations. We need to further consider the situation that we are dealing with multiple valuations of risk sources, typically at least for occurrence and severity. We may also have multiple sources, like in situations, e.g., involving sources of biological and chemical hazards, where relations between sources are qualified rather than quantified.
Source sets for biological and chemical hazards, S b i o l and S c h e m , may indeed be equipped with relations R being subsets of the product S b i o l × S c h e m , i.e., R S b i o l × S c h e m .
A relation R between these two source sets S b i o l and S c h e m can equivalently be written in a functional form ϕ R : S b i o l × S c h e m { 0 , 1 } so that for a source a S b i o l and a source b S c h e m we have ϕ R ( a , b ) = 1 if and only if a and b are related with respect to R, i.e., ( a , b ) R . In relational calculus, it is often written “ a R b ” to mean “a and b are related with respect to the relation R”.
In these relational situations, we see how a pair of sources is either related or not related. However, relations can also be many-valued and qualified by some Q, so that a many-valued relation of sources can functionally be represented by
ϕ : S b i o l × S c h e m Q
In this situation, it is important to note how a many-valued relation between sources is indeed qualified, not quantified, even if sources themselves can be both quantified as well as qualified. A quantification related to a pair of sources would be more like a “geometric distance” between the sources, not to be confused with looking for “similarity between sources”, which is qualified. In the two-valued situation, similarity is equality, i.e., based on an equality relation “a = b”, where equality and similarity is indeed qualified, not quantified.
In the case of sets Q of qualitative valuations of specific risk source sets, we may typically have separate qualifications for occurrence and severity, and we may include other types of qualifications, e.g., for detectability, with all qualifications separately denoted, e.g., by Q o c c , Q s e v , and Q d e t .
Concerning severity, assume that we have the following situation. In order to kill a certain type of pathogens, a High-Temperature Short-Time (HTST) pasteurization at 72 °C for 15 s will suffice to ensure food safety, alternatively using higher temperatures up to Ultra-High Temperature (UHT) pasteurization at shorter time or Low-Temperature Long-Time (LTLT) pasteurization. Outcomes of measurements in a pasteurization process can then be triples of values and symbols, e.g., like ( 72   ° C , 15 s , H T S T ) , ( 70   ° C , 25 s , H T S T ) and ( 77   ° C , 13 s , H T S T ) . In this situation, we have an obvious question about the “critical control point”, whether the control point is just “72”, with “at least 15 s” being hidden data, and “HTST” seen as a context for the measurement rather than part of the outcome data itself. If the risk source relates to the whole triple “(temperature, duration, pasteurization type)”, and we have, say, two such triples ( T 1 , d 1 , p 1 ) and ( T 2 , d 1 , p 2 ) , where in a special pasteurization situation we would have p 1 = p 2 = H T S T . What are then the criteria for saying ( T 1 , d 1 , H T S T ) “is less than” ( T 2 , d 2 , H T S T ) , and how do we categorize such triples? If we would use categorization of severity, e.g., as informally defined in [3] according to limited, moderate, serious and very serious, with a valuation function f : S Q s e v and S as the set of sources in the form of such triples, what is the order relation to choose so that for a triple ( T , d , p ) we can determine, e.g., whether f ( T , d , H T S T ) = l i m i t e d or f ( T , d , H T S T ) = m o d e r a t e for a certain temperature T and a recorded duration d of time?
Note on occurrence how occurrence of illness due to a hazard is not to be confused with the occurrence of a hazard. In [8], “occurrence” is mentioned in connection with hazard evaluation within HACCP’s Principle 1, saying that each potential hazard is evaluated based on the severity of the potential hazard and its likely occurrence. Reducing the occurrence of foodborne illnesses is an objective typically appearing in guidelines for managing food safety [26].
Concerning detectability we should note that detectability e.g., in [1,2] appears mostly in the context of a (microbiological) “limit of detection”, i.e., detectability is related to a quantified value appearing in R rather than as a qualified value as we typically see within FMEA (Failure Mode and Effect Analysis) [27], where severity, occurrence and detectability is treated “side-by-side”, and aggregation of related qualification valuations are provided by simple arithmetics to arrive at the Risk Priority Number (RPN). The simplicity of proposed aggregations in HACCP and FMEA is indeed mathematically comparable even if the context for “risk” and the content of “sources” is very different. Concerning the intertwining of the logical and probabilistic machinery presented in this paper for HACCP, it is expected that it may well be useful also for similar developments of computational contexts for FMEA. However, the discussion of a possible “spill-over” to FMEA is outside the scope of this paper.

4.4. Risk Functions and Matrices

The source of a risk is a named and ideally also a coded source within some dedicated nomenclature and ontology. This in turn enables one to create a contextual set or structure S of sources, for which, possibly distinguished at each point in time, we have a characterization function f o c c : S Q o c c for occurrence, and a characterization function f s e v : S Q s e v for severity, so that the risk matrix given by
R i s k = O c c u r r e n c e S e v e r i t y
can be established with a suitable choice of an algebraic operator
ρ : Q o c c × Q s e v Q r i s k
as the functional form of risk matrix, where the suggestion in this paper is to consider operations ∗ in quantales ( Q , ) as suitable candidates for risk matrix computations. In this, case the quantales Q o c c , Q s e c and Q r i s k are assumed to be “structurally identical” in the sense of being algebraically isomorphic, even if the elements in each quantale are equipped with different types of semantic explanations.
It is important to clearly distinguish between “table” and “matrix”. The product Q × Q is a risk table, where the operation ρ : Q × Q Q is a risk matrix. Note that a table is empty until we fill some or all cells with content, where that content functionally is a mapping of risk sources into a risk table defined by the function
σ : S Q × Q
In the special situation of mapping risk sources into the occurrence-severity risk table Q o c c × Q s e v , the characterization functions f o c c : S Q o c c and f s e v : S Q s e v can be used to define σ : S Q o c c × Q s e v according to
σ ( s ) = ( f o c c ( s ) , f s e v ( s ) )
The risk function
f r i s k : S Q r i s k
can then be provided by the composition
f r i s k = ρ σ
where ρ : Q o c c × Q s e v Q r i s k is the risk matrix, and σ : S Q o c c × Q s e v is the mapping of risk sources in S into the occurrence-severity risk table Q o c c × Q s e v .
If the risk matrix ρ is represented by the (quantale) operation ∗, then the computation in the risk matrix is
f r i s k ( s ) = f o c c ( s ) f s e v ( s )
which is now the formal functional representation of the widely used and accepted informal expression “ R i s k = O c c u r r e n c e S e v e r i t y ”.
The use of algebraic approaches, like those provided and enabled by quantales, for the operation ‘∗’, thus introduces an algebraic calculus of risk characterizations.
In these functional representations, the set S of risk sources remains mostly unspecified. In practical situations, S may take the form of a “sample set”, where we may have even just one risk source but several sample values for that risk source. In this case, risk calculations apply to a set of sample values for a single risk source rather than to a set of different types of risk sources. In other situations, we may have single sample values for a set of different risk sources. Therefore, in the functional context, it is always important to explain the elements appearing in the respective sets, whether in the domain or range of a function.
Quantales as risk matrices can be depicted as in Table 1 with the operation ‘ a b ’ presented “row-by-column” as ‘ r o w s y m b o l c o l u m n s y m b o l ’, i.e., as x r o w x c o l .
A quantale is a semigroup operation over a complete lattice, where the operation is join-preserving in both variables. Quantales and their properties are formally defined and explained in Appendix A.
In Table 2, the 5 × 5 risk matrix, for Q being the 5-point chain, is the meet operation, i.e., the many-valued logical “ A N D ”, of the underlying lattice, where the operation is quantale 5.5.723 in [28].
A quantale operation being join-preserving in both variables means, in particular, that the operation is increasing in both variables, which in Table 2 shows as the risk level remaining unchanged or increasing when shifting rightward and downward in the risk matrix. Computing with the bottom value ‘0’ of the quantale will always produce ‘0’, which essentially means that combining anything with a ‘total problem’ or ‘totally unacceptable’ means that the overall risk is also ‘totally unacceptable’. In Section 5 we show more examples of quantale-based risk matrices.

5. Nomenclatures and Definitions in Guidelines and Standards

The nomenclature and definitions that appear and are adopted within HACCP lean mostly on [1,2,3]. These guidelines in turn lean on nomenclatures appearing, e.g., in [15,17,21].
In the following, we focus on [1,2], and particularly in [2] showing how we find implicit functional content not explicitly formulated.
The Codex Alimentarius [1] is a collection of internationally accepted food standards in a uniform manner, the purpose of which is to guide and promote the establishment and consolidation of food definitions and requirements in order to harmonize them. The main nomenclature and definitions of sources referenced in this article, for the modeling of the HACCP method, are more or less influenced by the Codex Alimentarius. The significance of Codex Alimentarius for food safety is undeniable, even if the framework it provides is very general. Further, in terms of modeling food safety risk management, it is limited and allows for a wide variation.
“Risk analysis” is in [1] seen as an overarching and undefined conglomerate of activities, as it is stated that it is recognized that risk analysis is an iterative process. Therefore, “analysis” in “risk analysis” in [1] is not to be confused with “analysis” in “hazard analysis” as explained in HACCP’s first principle (Conduct a hazard analysis) of its Seven Principles.
Further, in [1], there is a more specific understanding of “assessment” in “risk assessment” as it is said that there should be a functional separation of risk assessment and risk management. However, “assessment” refers here to the four steps [...] for setting action levels for residues of veterinary drugs detected in foods of animal origin [...], referring to the Guidelines on the Application of Risk Assessment for Feed (CXG 80-2013) and risk assessment approaches, where step 1 is “Assess animal dietary exposure assessment” and step 2 is “Estimate anticipated residue levels in food commodities of animal origin”. The meaning of “assessment” is thus not specifically connected to mathematical and statistical methods of analysis typically seen as being part of “assessment”. Step 3 is “Set Action levels”, and Step 4 is “Evaluate human dietary exposure assessment”.
In its Section 4.1 in [1] on “Working principles for risk analysis for application in the framework of the Codex Alimentarius”, there are 41 principles in ([1], pp. 99–103), grouped according to
  • Scope (Principles 1–3)
  • Risk Analysis—general aspects (Principles 4–12)
  • Risk assessment policy (Principles 13–26)
  • Risk management (Principles 27–36)
  • Risk communication (Principles 37–41)
  • Principle 9 states that “there should be a functional separation of risk assessment and risk management”, but guidelines, suggestions, or examples of such separations are not provided, nor is “functional” defined. Principle 11 states that “the degree of uncertainty and variability [...] should be explicitly considered”, but provides no suggestions on how risk management options “should reflect the degree of uncertainty and the characteristics of the hazard”. Principle 19 states that “risk assessment should be conducted in accordance with statements 13–16 in Appendix Section A1.2” [1], e.g., where statement 15 simply repeats what is stated in Principle 9 on “functional separation of risk assessment and risk management”. Statement 16 trivially states that “risk assessment should use available quantitative information to the greatest extent possible”, similar to what is stated in Principle 20, including “based on all available scientific data”, without any indication of how such information appears in functional contexts.
The Codex Alimentarius indeed underlines the need to be “functional”, but suggestions or indications about how such mappings and functions, e.g., involving risk sources and their characterizations, are not provided in any style or format comparable to our functional notation provided in Section 4.
For functional modeling, Ref. [2] is more important and sufficiently detailed, and Ref. [2] is indeed a central source in modeling food safety risk management. The guideline also has a wide influence and serves as the basis for the food safety risk management methods used in [3].
In ([2], p. 12), it is said that risk assessment is the science-based component of risk analysis, i.e., in [2], “assessment” is more clearly connected with biological, chemical and physical methods of observations and measurement together with mathematical and statistical methods of analysis of data derived from such observations and measurements.
Examples discussed in Section 4 on “Semi-quantitative risk characterization” in [2] intuitively scratches the surface of algebra and logic even if the examples never enter its formal mathematical treatment embedded in algebraic notation. The examples can indeed be described algebraically using notation in Section 4, as we do in the following, and which will show how the “semi-quantitative risk assessment” in fact means “algebraic and many-valued logical risk assessment”, where “score” is an element in the characterization quantale. In [2], “semi-quantitative” risk assessment is said to “provide an intermediary level between the textual evaluation of qualitative risk assessment and the numerical evaluation of quantitative risk assessment, by evaluating risks with a score”, i.e., “semi-quantitative mathematics” would be something between non-mathematical text evaluation and mathematical-numerical evaluation using probability theory. Obviously, the mathematical disciplines of algebra and logic are not situated between non-mathematics and probability theory, but we should rather view algebra as the foundation of many-valued logic as a complementary approach to knowledge representation together with the corresponding but different representation provided within and by probability theory.
Sets Q O c c T 4 . x and Q S e v T 4 . x of characterizations can be seen in [2] given as
Q O c c T 4 . x = Q S e v T 4 . x = { V e r y H i g h , H i g h , M e d i u m , L o w , V e r y L o w , N o n e }
corresponding to the content of Tables 4.1, 4.2 and 4.4 in [2]. It is implicitly assumed that Q O c c T 4 . x and Q S e v T 4 . x are chains as partially ordered sets, i.e., we have
V e r y H i g h < H i g h < M e d i u m < L o w < V e r y L o w < N o n e
with V e r y H i g h as the bottom element. The bottom element labeled ‘Death’ in Table 4.2 in [2] is the characterization V e r y H i g h Q S e v T 4 . x .
Table 4.1 in [2] defines a mapping
f O c c T 4 . x : [ 0 , 1 [ Q O c c T 4 . x
from probabilities to characterization given by
f O c c T 4 . x ( p ) = N o n e , if p = 0 V e r y L o w , if 0 < p < 10 4 L o w , if 10 4 p < 10 3 M e d i u m , if 10 3 p < 10 2 H i g h , if 10 2 p < 10 1 V e r y H i g h , if 10 1 p < 1
At this point, it is appropriate to underline that our algebraic extension of traditional “semi-quantitative” risk characterization, as part of probability theory-based risk analysis, is indeed an extension and not by any means a replacement of statistical methods used in risk management. What our algebraic extension does is to show that “arithmetic aggregation” of characterization values is unnecessarily restrictive, and the use of algebraic operations opens up a wider spectrum of such aggregations, which in a many-valued logical context establishes an algebraic-logical formalism in support of the decision-making processes, following the preceding statistical–analytical processes.
The algebraic-logical approach, based on the algebraic calculus of risk characterizations, indeed complements the statistical–analytical approach, where a bridge between the two needs to be constructed, and a main objective of this paper is indeed to contribute to the design of that bridge.
In Appendix B we discuss the statistical–analytical machinery in more detail, together with connecting values and observations used with formal concepts, well known within the mathematical and measure theoretical understanding of probability theory, and so that sets and functions used in statistical analysis and probability theory are connected with corresponding mathematical objects within the algebraic-logical modeling as presented in Section 4 and Appendix A.
Returning to tables as presented in [2], Table 4.2 in [2] does not formally define a function as it only gives an impact description of each characterization in Q S e v T 4 . x . Table 3 shows a general version and candidate for understanding the elements in Q S e v T 4 . x .
In Table 4.4 in [2], the notion of the P-I (probability–impact) table is introduced, saying that the “numbers in the table are indices for identified risks”. We may write an “identified risk” as r i , and write S 15 for the set of those 15 “risks”, or risk sources, i.e.,
S 15 = { r 1 , , r 15 }
In [2] it is now implicitly assumed that each risk source in S 15 maps to a probability in [ 0 , 1 [ , i.e., there is mapping
g : S 15 [ 0 , 1 [
so that a function of the form (1) can be given as the composition
f O c c T 4 . x g : S 15 Q O c c T 4 . x
Together with a corresponding severity characterization
f S e v T 4 . x : S 15 Q S e v T 4 . x
Table 4.4 in [2], with “IMPACT” for severity and “EVENTS PER YEAR” for occurrence, is uniquely given by the function
σ : S 15 Q O c c T 4 . x × Q S e v T 4 . x
defined by
σ ( r 1 ) = ( H i g h , M e d i u m ) , σ ( r 2 ) = ( V e r y H i g h , V e r y H i g h ) , , σ ( r 15 ) = ( H i g h , H i g h )
The definition of the mapping f O c c T 4 . x can be seen as the very spot in [2] where the risk table invites to use arithmetic operations for risk scoring, i.e., where we might even say that HACCP’s “arithmetization of risk matrices” originates from the approach that, as stated in [2], “a log scale is used to define each categorical scale”.
To see this “arithmetization” more clearly, let the elements in Q, the “categorical labels”, be isomorphically represented by the “numbers as symbols”
0 ( V e r y H i g h ) < 1 ( H i g h ) < 2 ( M e d i u m ) < 3 ( L o w ) < 4 ( V e r y L o w ) < 5 ( N o n e )
and allow these symbols to play the role of numbers n as exponents in power expression 10 n , n = 0 , 1 , 2 , . Since we have n = l o g 10 10 n , we might say that “semi-quantification” focuses on the exponents from probability values represented by powers, as shown in Table 4.5 in [2] for the probability score. In other words, in situations where occurrence has an exponential behavior so that the corresponding log scale is linear, in [2] it is stated that “if a log scale is used to define each categorical scale [...] the probability and impact scores can be designed such that the severity score of a risk is then the sum of the probability and impact scores”.
The exponential situation thus seems to be a main justification for using addition as the operator aggregating occurrence and severity scores into an overall risk score, as seen in Table 4.6 in [2], even if it is also stated that one could use “some other simple mathematical equation”. Here we should obviously speak about “operation” rather than “equation”, and, as pointed out in Appendix A, there are 11,329 quantales available for such an operation on 6-point chains.
We should also note how the probability approach in [2] almost desperately holds on to characterization levels as symbols and elements in algebras, but nevertheless treats these symbols as numbers in order to enable the use of the arithmetic machinery in risk calculations. The “probability score” e.g., in Table 4.5 in [2] is essentially based on a hidden mapping
π : Q N
assigning a characterization level as an element in the quantale Q to a natural number n N appearing as an exponent in some value expression or interval including a power expression like a · 10 n . This clearly shows how the risk computational framework in [2] either ignores or is reluctant to compute with symbolic values q Q , since the arithmetic machinery enforces risk scoring to compute with numeric values π ( q ) N .
A main point of this paper is that the “addition algebra” ( N , + ) is just one algebra, whereas the algebras represented by quantales ( Q , ) are many, and indeed quite many.
On associativity (A1) of the operator, we may also note how in Table 4.8 in [2] the M A X operator is used for determining an overall severity score involving three different impact types, respectively, for ‘Health’, ‘Econonomic’ and ‘Social’.
Since addition “adds”, and even if it is used in calculating “mean”, addition is logically more like a “disjunctive” operator, whereas the M A X operator more clearly is a disjunction. Notably, M A X is associative. Particularly, here, there is no reason not to consider the use of quantale operations. Presenting a “transfer back into logs” as another option for an overall severity score simply shows how the risk matrix computational framework in [2] remains loyal to arithmetic operation.
The risk matrix in Table 4.9 in [2], shown in Table 4 excluding ‘NIL,’ which always computes to ‘NA’, is presented within a 5 × 5 risk table, where only three risk levels, ‘High severity’, ‘Medium severity ’, and ‘Low severity’, are used in the range of the operator, and therefore the algebraic properties of the operator remain unclear.
Table 4.9 in [2] is in Table 4 depicted row-by-column as a p r o b a b i l i t y × i m p a c t risk matrix, where in [2] the probability dimension is named “EVENTS PER YEAR” and the impact dimension is named “IMPACT”.
The characterization ‘VHI’ (very high), ‘HI’ (high), ‘MED’ (medium), ‘LO’ (low), and ‘VLO’ (very low) in Table 4.9 in [2] correspond in Table 4, respectively to ‘1’, ‘2’, ‘3’, ‘4’, and ‘5’, where in Table 4 the bottom element ‘0’ is added as corresponding to ‘certain’ (totally unacceptable risk), which combined with anything results in total unacceptability. Therefore, in our example tables below, we use
Q = { 0 , 1 , 2 , 3 , 4 , 5 }
as the underlying quantale, and again we remind ourselves that the elements of Q are ordinal symbols, and not numbers.
We have in Table 4 further, as one option, identified ‘High severity’ with ‘2’ (‘HI’), ‘Medium severity’ with ‘3’ (‘MED’), and ‘Low severity’ with ‘4’ (‘LO’). Doing so, a first observation is that the risk operator in Table 4.9 in [2] is not associative, since we have the counterexample
( V H I M E D ) M E D = H I M E D = M E D H I = V H I M E D = V H I ( M E D M E D )
At this point, we remark how in [2] it is stated that it is “imperative that the categories are carefully constructed”, but nothing is said about the need to carefully select the operation. After all, the 6-point chain is an ordinal structure, not a numerical one. Sub-section 4.3.3 in [2] on “Limitations of semi-quantitative risk assessment” presents the limitations as being caused by the scoring scale, but no discussion is provided on these limitations possibly arising due to the acceptance only of arithmetic operations for the overall risk scoring.
In the following, we present a few quantales that might be seen as candidates to be similar to the risk matrix depicted in Table 4.
Before doing so, we may note how the addition operation used in Table 4.9 in [2] essentially introduces a certain form of a “disjunction” of probability and impact. In our candidate tables, when represented by unital quantales, we will see, e.g., how the position of the unit makes the risk computation intuitively being positioned relatively to the additive operation, i.e., being clearly below the “addition” corresponds intuitively more to a logical conjunction, a many-valued “ A N D ”, whereas comparable to the “addition” corresponds intuitively to a logical disjunction, a many-valued “ O R ”.
Table 5 shows a quantale which is commutative and unital, with risk level ‘2’ as the unit, i.e.,
2 q = q 2 = q
for all q Q .
Table 6 shows a quantale which is non-commutative and unital, with risk level ‘3’ as the unit, i.e.,
3 q = q 3 = q
for all q Q .
The ‘∗’ operator in Table 5 appears to be somewhat more “additive” and “disjunctive”, whereas the ‘∗’ operator in Table 6 is intuitively more “conjunctive”. However, Table 4 seems to be more in between the two, thus not being as “additive” and disjunctive as expected, and maybe due to the way the added numbers in Table 4.9 in [2] are lumped together to appear as clustered within respective risk levels. Indeed, addition is more of a disjunction but the categorization of the results of additions may bring the matrix operation “downwards” towards being more neutral between conjunction and disjunction.
As explained in Appendix A, quantale operations generate certain forms of many-valued logical implications, which as consequence relations can be seen as the logical counterpart to causation and conditionality in probability theory.
The use of quantales for risk matrix computation shows that algebraic approaches beyond using only arithmetic open up a wider spectrum of options for risk matrix computation. It also shows how an algebraic approach complements traditional approaches based only on probability theory and, in fact, increases the underlying mathematical complexity of risk management, particularly when dealing with “semi-quantitative” risk modelling.
On semi-quantitative risk management, in [2] a general statement is made saying that “it does not require the same mathematical skills as quantitative risk assessment”. By “mathematics” is then obviously meant probability theory and statistics, thus ignoring methods potentially provided by algebraic and mathematical logical techniques, as described in this paper. It is further said that “nor does it require the same amount of data”, where in fact the algebraic approach makes use of precisely the same data as probability theory and statistics, where that data is expected to have been properly typed and structured within the original information sources from where that data has been extracted. Probability theory and statistics use numerical values only, with logical expression integrated ad hoc whenever needed. Probability theory as used in [2] is thus more or less disconnected from the understanding of mathematical logic and algebra.

6. Risk and Safety as Antonyms and Antinomies

In this section, we look at some formal algebraic aspects which may become interesting to further investigate with respect to the relation between risk and opportunity, i.e., on the duality and connection between avoiding risk and maintaining safety. A more in-depth formal treatment is outside the scope of this paper, but some further algebraic subtleties are provided in Appendix A.
Risk and safety, as names in nomenclatures, may appear and be treated as antonyms, whereas they appear more like antinomies when dealing with their respective many-valued logical characterizations. The degrees of safety and risk are related more with respect to the underlying lattice, whereas their characterization values are treated more with respect to the underlying quantale. A higher degree or characterization value of safety intuitively means a corresponding lower degree or characterization value of risk.
Formalizing such an antinomic view of risk and safety calls for dealing with mappings (functions) between risk and safety, as well as “opposite” mappings between safety and risk, and further invites to identifying the algebraic properties of such pairs of mappings. In [16], the relations and mappings between the antinomies threat and opportunity are discussed on an intuitive level only, without formalization of such relations and mappings. For instance, it is in ([16], p. 102) said that a risk including both threat and opportunity can be treated simply as a particular case of different impact types. A “double P-I Grid” (“table” is in [16] called “Grid”) is recommended, and in ([16], p. 103) it is said that a useful alternative is the so-called “mirror P-I Grid”, where the opportunity side is rotated by reversing the impact scale, creating a symmetrical double grid. The “Attention Arrow” in Figure 3 in ([16], p. 104) covers the worst threats and the best opportunities, which together should be the focus of management attention and action ([16], p. 103). The size of that zone can and should indeed be modified to reflect the reality and objectives in specific contexts, but there should also be some relation between respective table values together with suitable algebraic properties between them, in order to explain the relational structure between threat and opportunity.
In order to introduce algebraic aspects of this relation between threat and opportunity, let us first note that an antinomy is often seen as a contradiction, or an “opposite truth” in some logical sense, with opportunity being the antinome of risk, and vice versa, risk being the antinome of opportunity, whatever the precise definition of “antinome” might be.
Algebraically and logically speaking, such antinomies can be modeled by order-reversing functions, or using many-valued logical negation.
To be more precise, a function f is said to be order-reversing (also called antitone) if f ( x ) f ( y ) whenever x y , i.e., being order-reversing is dual to being order-preserving (also called monotone or isotone) if f ( x ) f ( y ) whenever x y .
For reasons previously explained, in this paper we have recommended the quantale Q r for risk characterizations to have its top element r as a “no problem”, i.e., meaning “no risk”. If the corresponding quantale Q o for opportunity characterizations has its top element o similarly as a “no problem”, but in this case in the sense “highest and best possible opportunity”, then the antinomic relation between risk and opportunity is suitably modeled by order-reversing mappings
f : Q r Q o , g : Q o Q r
Note in the risk matrix that Q r and Q o are “identical” (or isomorphic) as quantales, even if the names of the elements in respective quantales are understood differently.
The composition of the order-reversing functions (mappings) f and g gives order-preserving mappings
f g : Q o Q o , g f : Q r Q r
An assumption that these compositions are identities, i.e., f g = ι o (the identity mapping for Q o ) and g f = ι r (the identity mapping for Q r ), would be a very strong assumption, leaving less freedom for interpretation of the antinomic relation between risk and opportunity. A weaker assumption providing a special and interesting connection between f and g is the so-called Galois connection, which for a risk characterization x r Q r and an opportunity characterization x o Q o means that we have an equivalence
x o f ( x r ) x r g ( x o )
In this case the compositions g f and f g are idempotent, i.e.,
( g f ) ( g f ) = ( g f ) , ( f g ) ( f g ) = ( f g )
and, moreover, we have that f ( x o ) is the largest opportunity characterization x o such that x r g ( x o ) , and that g ( x o ) is the largest risk characterization x r such that x o f ( x r ) .
If f and g form such a Galois connection, then
x r ( g f ) ( x r ) , x o ( f g ) ( x o )
for all x r Q r and all x o Q o .
Tarski’s fixed-point theorem (also called the Knaster–Tarski theorem) [29] guarantees the existence of fixed points for both g f and f g , i.e., there exists (at least one each) x r and x o sich that
( g f ) ( x r ) = x r , ( f g ) ( x o ) = x o
which shows how g f and f g are not identities but indeed some kind of “incomplete identity functions”.
The antinomic relation between characterizations of risk and opportunity in terms of many-valued truth can further be defined and explained by using the quantale to construct logical negations. A quantale defines left and right implications, which can be arranged in functional forms so as to form a Galois connection. Details are shown in Appendix A.
These discussions show how the formalization of the intertwining of and antinomic relation between risk and safety, and between threat and opportunity, can be provided within algebraic and logic frameworks, not recognized, e.g., in [16,20], where the antinomic relation is treated more intuitively and from viewpoints of appearance in practical and/or professional situations in risk management.
Further subtleties, beyond the additional discussion as provided in Appendix A, connected with these algebraic and logical treatments are mostly outside the scope of this paper. However, these views invite further development, where Appendix A serves the purpose of including basic notions of quantales in support of further extensions related to such treatments.

7. Case and Examples

In previous sections, we have extended the mathematical modeling of risk analysis, focusing on risk matrices as they appear within the HACCP method. The functional approach, and more generally, the algebraic approach to risk analysis, as introduced in Section 4, is in Section 5 shown to apply suitably to risk analysis within HACCP. Traditional statistical methodology in HACCP [2,30] provides mappings from probabilities to characterizations, and we have shown how the methodology can be extended with an algebraic calculus of characterizations enabled by quantales.
In this section, we illustrate the challenges of arithmetic-based spreadsheets through practical examples, and we show how a broader use of algebraic calculus complements traditional arithmetics based approaches.
Our case discussed in this paper is drawn from [7], which describes reindeer meat cutting and slicing processes, based on developments within a cooperation project with a reindeer meat cutting and slicing company in Finland. Internal discussions within the company, in particular concerning methods used and the reality about the CCPs of metal detectors, was the background to and underlying motivation for developments presented in [7], and also became the motivation to develop the functional model as presented in this paper.
In this example case, we will arrive at risk matrices for risk sources represented by foreign object hazards, respectively, for metal and reindeer botfly found in reindeer meat within these processes. We will demonstrate the advantages of adopting the functional approach and the use of quantale-based risk matrices for these risk sources. We thereby indicate how our algebraic calculus in risk analysis can potentially be exploited in real situations and within risk management processes.
Before going into case detail, it is important to understand the legislative framework based on which food operators like reindeer meat cutting companies implement their food safety actions when creating their own risk management system and self-monitoring plan. In these respects, for risk assessment in Finland, national legislation sets minimum requirements for ensuring food safety. This national legislation is largely based on the requirements set by the European Union, which in turn takes effect from international guidelines [1,2]. In addition, food operators are affected by various standards [7]. Finnish food operators comply well with both legislation and standards, and with models and methods presented in [1,2,3], a compliance driven and enforced by the Finnish Food Authority.
In order to understand the existing challenges, we will now dive into detail concerning the reindeer meat cutting and slicing process. The production processes of a reindeer meat cutting plant are fairly simple and straightforward from a HACCP perspective. The hazard analysis performed for reindeer meat, particularly in its cutting and food production, examines biological, chemical, and physical risks, and sometimes also allergens and radiological risks. Overall, reindeer meat can currently be classified as a low-risk food in Finland. In general, the health of reindeer is good, and there are no dangerous diseases transmitted through reindeer meat, and in this context, we consider reindeer meat products intended for heat treatment [31].
Biological risks are caused, among others, by bacteria and parasites. The risk of infection is mainly related to eating uncooked or poorly cooked meat. Common parasites found in meat include the reindeer botfly (Hypoderma tarandi) [31]. Even if botfly larvae can cause myiasis if such ectoparasites have penetrated the skin of humans, the appearance of such larvae in reindeer meat does not cause harm to humans if that reindeer meat is properly processed and used in food production. That is, the botfly larva itself, as a risk source, does not contribute to risk, whereas incomplete or insufficient food processing increases risk. Logically, we may say that the combination “reindeer botfly larvae AND proper heating (of reindeer meat)” is risk-free, whereas “reindeer botfly larvae AND improper heating” comes with risk. This shows that we need to understand the role of the (logical operator) “AND”. We also need to note how the risk source “improper heating” itself, in general, may lead to consumers becoming susceptible to harm. This, in turn, means that the risk matrix for “presence of a risk source s AND improper heating” will depend on the risk source s.
The situation “reindeer botfly larvae in reindeer meat AND proper heating of reindeer meat” will indeed not impose any risk at all, which means that the risk matrix in this situation is given by the quite rare “risk-free matrix” shown as the left-hand side quantale in Table 7. This is indeed an extreme situation, where quite the opposite risk situation as represented by the right-hand side quantale would correspond to a situation where the risk is constantly “total” for whatever characterization values related to probability and impact. Such risk situations are also rare.
Other types of risks, like chemical risks, arise from contamination of reindeer meat by various chemicals in the environment and toxins produced by plants and microbes. In the slaughtering process, chemical contamination can occur, among other things, from detergents and disinfectants, technical chemicals, packaging materials, pest control agents, possible paint surfaces or building materials [31].
Physical hazards like metal and glass are caused by foreign objects ending up in reindeer meat. Foreign objects can come from, among other things, the environment, people, contact materials such as work tools and protective clothing, and from packaging materials. In the case of metals, foreign objects can come from breaking knives and saw blades, pieces detached from carcass rails, rail grease, or from rust and parts of equipment. In addition, with regard to reindeer meat, there is a possibility of finding bullets from shotguns that may have been fired at animals [31].
In the case of metal objects, they all have different impacts. In some cases, the impact is less severe, in other cases more so. Moreover, the probability of their occurrences, estimated for each impact level, is not the same, not even for one particular foreign object, when occurrences are observed over time within one and the same production process. This obviously calls for paying attention to the choice of a quantale or quantales for the risk matrix annotated to a certain foreign object or to a set of similarly impacting foreign objects. The quantale(s) selected to model the risk must indeed match the outcomes and consequences observed within the production processes and correspond to experiences and lessons learned in production. Obviously, this type of algebraic risk modeling must also be aligned with rules and regulations as provided and imposed by the authorities.
In the production processes of reindeer meat cutting and slicing, a more specific problem is that foreign objects can be identified as “death” hazards with a low probability but high severity in some cases. Such a hazard can be caused, for example, by metal pieces that have ended up in food from metal blades used in production. In the risk matrix proposed in [3], a low probability with a high-severity hazard is never placed in the “red area”, but in the “orange area”, which does not correspond to reality [7].
Characterizing the occurrence of physical hazards like metal is quite different from characterizing the severity of such foreign body ingestion, particularly in pediatric cases. Metal and glass objects are the most involved sharp or pointed foreign bodies, where endoscopic retrieval is difficult in about 4% of cases [32]. However, perforation during gastrointestinal passage is very rare.
If we consider the “death” hazard for the risk source being metal pieces from metal blades, Table 8 shows a quantale suitable for a corresponding risk matrix, and it explains a main point of this paper, namely, that we first provide characterized values and then select the operator to be used for computations in the risk matrix. In the general risk formula
R i s k = O c c u r r e n c e S e v e r i t y
traditional risk analysis first constrains the operator ‘∗’ to be of arithmetic type, and in some cases, like in HACCP, anticipates that it will be “arithmetically additive”. In some other cases in risk management at large, there may be intuitive justifications that the operator is “arithmetically multiplicative”. Whatever the choice of arithmetic style operator in these traditional cases, the decision to use arithmetic for computing with characterized values comes before characterizations of O c c u r e n c e and S e v e r i t y have been provided. In HACCP, we have seen the use of the log scale for characterizing occurrences seems natural without any detailed justification, or even worse, the use of the log scale may be understood as justified indeed because the use of arithmetic addition has been determined and fixed in advance. The characterization of severity, like in Table 4.2 in [2] and Table 3 in Section 5, is generic and assumed to be essentially independent of the characterization of occurrences. This means that the characterization of occurrences also essentially comes before the characterization of severity. Thus, in HACCP, the choice of the operator and the characterization of severity is given before the characterization of the occurrences is provided, which means that the characterization of the occurrences will be affected by the given characterization of severity and the fixed and “universal choice” of adopting arithmetic for computing with characterizations of occurrences and severity.
In our approach, we suggest being aware of the order of providing characterizations and selecting operators. We essentially say that “first, characterize occurrences and severity, and then choose the operator”. If we adopt this order, characterization of occurrences may remain to be performed within the realm of statistics and probability theory, and the characterization of severity may follow traditions within HACCP and risk management in general. A key point in our paper is that selecting the operator after having provided characterizations of occurrence and severity will open up an avenue of using a much wider spectrum of operators within the realm of the discipline of algebra, and computing with symbols rather than arithmetically computing with numbers.
The need to choose the operator after having provided characterizations is further justified as illuminated in the following situation in ([16], p. 103), where the challenge of symmetric risk assessment tables and matrices is discussed. In assessing the significance of a risk, most risk assessors’ intuitive understanding is that the impact of the risk is not of “equal significance” as compared with the probability of the risk, but the impact should be considered more important than the probability. For example, if risk source s A has a low probability but a large impact, and risk source s B has a high probability but a small impact, most risk assessors would prefer to say “A is more important than B”. The relative importance of these two cases is clearer at the extremes. For example, when considering threats, a small chance of a disaster is more important than an almost certain small harm.
Designing a risk matrix in the case of the “death” hazard would typically start off by fixing a few expected risk values, and arriving at an incomplete risk matrix as shown on the left-hand side of Table 8. Given these preferences for selected positions in the risk table, i.e., representing certain fixed conditions for the risk matrix, the right-hand side shows quantale 6.15.7902 as being one particular quantale that is a completion of that incomplete quantale.
There are often several alternatives for the choice of the completing quantale. In these situations, assessors could either seek to justify a particular choice or add further preferences in other selected positions in the risk table. The pdf file [28] that lists all quantales up to 6 points can be used to develop various “semi-automatic” searches of quantales, and the quantale suggested in Table 8 was reached, for the purpose of this paper, using a heuristic search method. The underlying data structure of the listing in [28] has not been disclosed. However, demonstrators can be developed, where the choice of particular quantales is simplified. In the end, the suitability and practicality of such demonstrators depend on the particular application context. As stated in [33], SAT solvers were used to enumerate quantales on up to 6 elements, and later on Mace4 was used for quantales up to 9 elements. The scope of all quantales up to 9 points, and there are hundreds of millions of them, has been described [33], but not fully documented. The pdf file [28] for quantales up to 6 points is already quite large, so the documentation of quantales up to 9 points must be done in different ways, explaining which is beyond the scope of this paper.
Note in Table 8, with row-by-column being Probability-by-Impact (or Occurrence-by-Severity), how values in certain blank positions in the left-hand side risk table cannot be chosen as any value in the quantale, as the algebraic properties of quantales means, e.g., that the semigroup operation ‘∗’ in the quantale is order-preserving in both its arguments. For instance, since 2 2 = 1 and 2 4 = 1 , then also 2 3 = 1 . Obviously, since 1 1 = 1 and 5 1 = 1 , then q 1 = 1 for all q = 1 , 2 , 3 , 4 , 5 . Further, since 2 4 = 1 and 4 4 = 2 , we expect to have either 3 2 = 1 or 3 2 = 2 . Simularly, since 5 3 = 3 and 5 5 = 5 , we expect to have either 5 4 = 3 , 5 4 = 4 or 5 4 = 5 .
The quantale 6.15.7902 in [28] is indeed one option that fits the selected and fixed values for the “death” hazard case in the left-hand table in Table 8. One may wonder if we can be dissatisfied with one or two values in the right-hand side quantale and modify the values, still respecting the order-preservation. In such cases, we have to be careful, since changing a few values, even if respecting the order-preservation, might destroy the associativity property (A1) of the quantale.
In our example case, we should also remark that for the reindeer meat cutting and slicing processes examined in [7], it was not possible to demonstrate any CCPs by using risk assessment methods, but only CPs. Unlike the output produced by the risk matrix, in reality, the risks of foreign objects could require that metal detectors be determined as a CCP. However, the BRCGS (Brand Reputation through Compliance Global Standards) assesses the risk of a foreign object as high if the X-ray machine points are always determined as a CCP. BRCGS requires the inspection of raw materials and finished products using an X-ray machine.

8. Conclusions

The practice of risk management is multidimensional, in particular, as it is concerned with the duality of opportunity and threat, where we might sometimes see threat as requiring insurance as an additional option to guard against threats, whereas fertilization of opportunity is expected to be interest-yielding. There is indeed a variety of objectives for risk management, and how organizations decide to take action based on risk analysis.
From the viewpoint of food risk management, we live in our modern society where the meaning of food is no longer to serve solely as a source of energy, and modern supply chains are inherently complex. Food safety management has focused mainly on ensuring that food is safe to consumers. Food safety is more than just ensuring safety, and methods can also be used to ensure the quality and authenticity of food, as pointed out e.g., in [2,6,34]. In addition to health risks, risk assessment further takes into account other types of effects, such as financial losses or deterioration in quality of life. Other perspectives of food management obviously introduce not only multiple risks but also multiple risk tables and related matrices. Complexity increases the need for Safety II based [20] thinking in risk management, and on the other hand, new types of risk assessment and methods.
As we point out in this paper, the probability–impact risk table and matrix can be constructed in a wide variety of ways, not restricted to the use only of arithmetic operations but also more generally making use of algebraic operations like quantales, thereby opening up a wider spectrum of applications of the risk matrix computationally defined based on its risk table.
HACCP is undeniably an important tool in ensuring food safety. In [6], the application of the familiar food safety tool HACCP is presented more broadly in ensuring food assurance, so that it takes into account risks related to food defense (TACCP), food authenticity (VACCP) and food quality in addition to food safety. Furthermore, as pointed out in [16], the HACCP method can be applied more broadly, not only to hazards but also to possibilities.
In this paper, we have discussed risk management, its terminology, process modeling and functionality at a general level and examined it from the HACCP perspective of food safety. We might say that HACCP and many other risk assessment methods like FMEA and HAZOP indeed follow the ISO 31000 [17] process to some extent. However, user communities connected with different risk assessment methods could consider whether risk management can be modeled even more accurately in the future based on the ISO 31000 process and ISO 31073 [21] definitions and terms. Risk management can be seen as very general regardless of the field and could benefit from more comprehensive uniformity.

Author Contributions

Conceptualization, D.S. and P.E.; methodology, D.S. and P.E.; validation, D.S. and M.S.; formal analysis, D.S. and P.E.; investigation, D.S. and M.S.; resources, D.S. and M.S.; writing—original draft preparation, D.S. and P.E.; writing—review and editing, D.S., M.S. and P.E.; funding acquisition, P.E. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Data Availability Statement

The original contributions presented in the study are included in the article; further inquiries can be directed to the corresponding author.

Acknowledgments

We are grateful to the anonymous reviewers, whose comments have helped us significantly improve the content of this paper.

Conflicts of Interest

The authors declare no conflicts of interest.

Appendix A. Quantales

As we in this paper advocate the use of quantales for operations represented in HACCP’s risk matrices, in this appendix, we present a sufficiently self-contained explanation of the algebraic properties of quantales as semigroups that are join-preserving over complete lattices. For more detail on quantales, see [35].
These algebras can also be understood as an “algebraization” of “semi-quantitative” risk estimation as proposed and generally outlined in [3] based on arithmetic operations.
Many readers may be familiar with a wide range of algebraic structures, whereas familiarity with quantales is less common, in particular to the extent where quantales are suitable and advocated in applications involving many-valued logic and its logical operators.
As explained in Section 4, “semi-quantification” implicitly invites the introduction of transformations of numeric values into symbolic values, where the order relation is preserved and “quantity” is replaced by “quality”. In order to understand algebraic operations and their properties from this transformation point of view, let us first note how the fundamental arithmetic operation “addition on the real line” is a binary operation ‘+’ on the set R of real numbers, i.e.,
+ : R × R R
where we obviously use the infix notation ‘ x + y ’ more than the prefix notation ‘ + ( x , y ) ’.
Arithmetic multiplication ‘ x y ’ is similar, and we may note how addition logically appears to “reside between OR and AND”, whereas multiplication has an “AND-like flavour”, in the sense that “a AND b” expectedly is less true than both a and b separately, i.e., A N D ( a , b ) a and A N D ( a , b ) b , whereas “a OR b” expectedly is more true than both a and b separately, i.e., O R ( a , b ) a and O R ( a , b ) b .
In what follows, we define quantales as semigroups that are join-preserving over complete lattices, and we therefore, and for sake of self-containment, also include definitions of semigroups and lattices.

Semigroups, Lattices and Quantales

A semigroup  ( X , ) consists of a (base) set X and an operation : X × X X that is associative, i.e., satisfies
x ( y z ) = ( x y ) z
for all x , y , z X .
Here we should note that an operator ‘∗’ not fulfilling associativity will not be able to uniquely compute ‘ x 1 x 2 x 3 ’ unless parentheses are included. A risk matrix indeed typically combines only two values, but the same operation or similar operations often need to combine several severities or occurrences into one overall severity or occurrence to be used in the risk matrix.
A semigroup is said to be commutative if
x y = y x
for all x , y X .
Here we may note how commutativity is quite a restrictive condition, as it disables the operation ‘∗’ to distinguish, whenever necessary, between x y and y x , as discussed in Section 4.
Commutativity must be a matter of choice in a certain context for the risk matrix. If the operation is commutative, then the risk matrix is symmetric around its diagonal, and then a “very high” occurrence combined with a “very low” severity would provide the same overall risk value as compared with the situation with a “very low” occurrence combined with a “very high” severity. In some cases, a risk matrix may indeed be symmetric, but, in most case, imposing commutativity for the operator would be a restriction not complying with reality and practicability of the risk management context.
We should also recall how addition + : R × R R and multiplication · : R × R R are commutative semigroups, where e.g., ‘ 2 + 3 ’ is not distinguished from ‘ 3 + 2 ’.
Before introducing lattices, we may first note how in a risk matrix the ‘∗’ operation is used for combining characterizations that appear in some order, i.e., one characterization x 1 is “less than”, or “less than or equal”, to another characterization x 2 , i.e., x 1 < x 2 or x 1 x 2 . In these circumstances, for a third characterization q we would at least, for x 1 x 2 expect to have a x 1 a x 2 and x 1 a x 2 a .
For quantales our requirement is slightly stronger as we require that operating with a “maximum” of a certain number of characterizations amounts to the same value as applying the maximum on operating separately with each of the characterizations, i.e., intuitively we have “a ∗ (maximum of C)”, where “C” is a set of characterizations, to be the same as “maximum for all c in C of the separate operations (ac)”, and we would require that condition to be valid also similarly for “(maximum of C) ∗ a” to be the same as “maximum for all c in C of the separate operations (ca)”. This requirement for quantales is said to mean that ‘∗’ is “join-preserving in both variables”, as defined below.
Formally, for orders between elements, a lattice  ( X , , ) consists of binary operations ∧, called ‘meet’ (“minimum”), and ∨, called ‘join’ (“maximum”), that are, respectively, idempotent ( x x = x and x x = x ), commutative and associative, and further satisfying the absorption laws
x 1 ( x 1 x 2 ) = x 1 x 1 ( x 1 x 2 ) = x 1
for all x 1 , x 2 , x 3 X . For lattices, idempotency of ∨ and ∧ follows from the absorption laws.
A lattice indeed defines a partial order, but not always the other way around. Given a lattice, the partial order ‘≤’ is defined by x y if and only if x = x y , or equivalently, if and only if y = x y .
A finite lattice, i.e., a lattice with a finite base set, is a complete lattice  ( X , , , , ) with ⊥ as the smallest element, given the partial order generated by the lattice, and ⊤ as the largest element.
A lattice is distributive if
x 1 ( x 2 x 3 ) = ( x 1 x 2 ) ( x 1 x 3 ) x 1 ( x 2 x 3 ) = ( x 1 x 2 ) ( x 1 x 3 )
for all x 1 , x 2 , x 3 X .
Whenever X is 2-pointed or 3-pointed, i.e., X = { 0 , 1 } or X = { 0 , 1 , 2 } , the chain is the only lattice.
For the 4-pointed set X = { 0 , 1 , 2 , 3 } , the chain and the diamond
Appliedmath 06 00116 i001
are the only lattices.
The diamond lattice is an example that shows why we should be careful here about the understanding of “minimum” and “maximum”. From the lattice point of view, we have “1 join 2 = 3”, i.e., the “maximum” of ‘1’ and ‘2’ is not one of ‘1’ or ‘2’. Similarly, “1 meet 2 = 0”, i.e., the “minimum” of ‘1’ and ‘2’ is again not one of ‘1’ or ‘2’.
For the 5-pointed set X = { 0 , 1 , 2 , 3 , 4 } , there are 5 lattices, below depicted as in [28].
Appliedmath 06 00116 i002
For 6-pointed sets, there are 15 lattices, for 7-pointed sets, there are 53 lattices, and so on.
We are now in position to introduce the structure of a quantale  ( Q , , , , , ) , where ( Q , ) is a semigroup over a complete lattice ( Q , , , , ) , so that the semigroup operation is join-preserving in both variables, i.e., satisfying
x ( a A Q a ) = a A Q ( x a ) ( a A Q a ) x = a A Q ( a x )
for all x Q and all A Q .
The theory of quantales uses the convention that the supremum of the empty set is the bottom element, i.e., = , which implies the condition
x       =       x   =  
for all x Q . In some applications, this condition may seem to be unnecessarily strong, but for the purpose of using quantales for representing characterization values in HACCP, the condition is in most cases quite suitable, as a “complete unacceptable” or “total problem” value for either occurrence or severity provides complete unacceptability or total problem in the overall risk assessment.
As a special case of a quantale, note how a distributive lattice is a quantale with the join as the semigroup operation in the risk matrix.
Quantales may be equipped with further properties. Here, we mention a few of them. For an overview of additional properties of quantales, see [33].
A balanced quantale is a quantale satisfying
=
This may seem a natural property always to be fulfilled, and in most practical cases it is indeed so, but in such situations we may simultaneously have x x x , for some x .
A unital quantale  ( Q , , e , , , , ) is a quantale with a unit e Q satisfying
x e = e x = x
for all x Q , i.e., operating with the unit e leaves the value of operating with x unchanged.
As we have pointed out, the use of arithmetic operations in risk matrices limits the number of operations to one or just a few. When using quantales in risk matrices, the number of choices for operations is very large as the number of elements in the set of characterizations is allowed to be larger. There are 2 quantales on a 2-pointed set, 12 quantales on a 3-pointed set, 129 quantales on a 4-pointed set, 1852 quantales on a 5-pointed set, and 33,391 quantales on a 6-pointed set, 11,329 of which are quantales over the 6-point chain. All lattices and quantales up to 6 points are listed and shown in [28]. Table A1 shows the number of quantales per lattice in the case of the 5-point lattices [28].
Table A1. Number of quantales per lattice with 5 elements.
Table A1. Number of quantales per lattice with 5 elements.
Lattice (♯)Number of Quantales
1213
278
3337
4221
51003
As pointed out in Section 4, units in unital quantales are candidates for being interpreted as “unknown” or “not yet known” values appearing in a risk matrix. From an application point of view, unital quantales over lattices with the unit being a sideline element may be particularly interesting. Lattice nr 13 (out of 15 6-point lattices) in [28] has ‘not (yet) known’ as “optimistically” sidelined with the generic 5-scale.
Appliedmath 06 00116 i003
There are 2830 quantales for the 6-point lattice nr 13. Of these, 57 are unital with the sidelined ‘not known’ as the unit, so that
x N o t K n o w n = N o t K n o w n x = x
for all values x in the generic 5-scale, i.e., aggregation with unknown values is not affected or enforced by missing values.
We conclude this Appendix by showing how quantale operations define implication operators.
Given a quantale ( Q , ) , right implication  R : Q × Q Q is for x , y Q defined as
x R y = { q Q x q y }
and similarly, left implication  L : Q × Q Q is for x , y Q defined as
x L y = { q Q q y x }
The right and left implications appear in Galois connections as follows. We first fix an element q Q . Then we define f r : Q Q by f r ( x ) = x q , and g r : Q Q by g r ( x ) = q R x . Doing so will make f r and g r form a Galois connection. Similarly, if we define f l : Q Q by f l ( x ) = q x , and g l : Q Q by g l ( x ) = x L q , then f l and g l will form a Galois connection.
In the special case when Q = { 0 , 1 } , and the quantale is the 2-valued Boolean ‘ A N D ’ operator, then the left and right implications coincide and are the same as the Boolean implication ‘⇒’, i.e.,
x R y = y L x = x y = ¬ x y
Generelly, whenever a quantale is commutative, left and right implications will coincide.
Table A2 shows the left and right implications for the commutative quantale nr 6.15.9177 in [28]. The implication matrices coincide once the right-hand side left implication matrix has been transposed.
Table A2. Coinciding right ↘ and left ↙ implications for the commutative quantale in Table 5.
Table A2. Coinciding right ↘ and left ↙ implications for the commutative quantale in Table 5.
012345012345
05555550500000
10224451521000
20123452522000
30002253543210
40001254544220
50000055555555
Table A3 shows the left and right implications for the non-commutative quantale nr 6.15.8746 in [28], and we can see that the implication matrices do not coincide.
In Table A3 we see e.g., how
2 R 3 = 3
whereas
3 L 2 = 2
reflecting a situation due to the underlying quantale being non-commutative.
Table A3. Coinciding right ↘ and left ↙ implications for the non-commutative quantale in Table 6.
Table A3. Coinciding right ↘ and left ↙ implications for the non-commutative quantale in Table 6.
012345012345
05555550500000
10333451541100
20133452543200
30123453543300
40111454544440
50000055555555

Appendix B. Probability Theory

Risk, as we have seen, is not mathematically well-defined, but rather generally described as something undesirable, for which we want to know the probability of its occurrence, where related events include risk sources. In [21], risk is defined as an effect of uncertainty on objectives, where “effect” is understood as a deviation. From functional modeling point of view, risk sources and hazards need not be distinguished, where hazards in [21] are defined as sources of potential harm.
Whereas risk is allowed to be vaguely defined, probability is in this paper understood exclusively as in probability theory-based on strict mathematical notations, where a probability measure is a function that maps events to values in the unit interval, and where events are elements in a σ -algebra over a sample space.
Uncertainty is a further concept used within probability, not to be confused with the use of uncertainty in many-valued logic, where “degree of uncertainty” is synonymous with “degree of truth”, i.e., a value q in a quantale Q can be called a “degree of uncertainty”. In [16], uncertainty (within probability theory) is viewed as “related to a lack of knowledge about possible outcomes”, and it is further said that “Risk is measurable uncertainty; Uncertainty is unmeasurable risk”. In [21], the view of uncertainty is similar, as it is defined as a “state, even partial, of deficiency of information related to understanding or knowledge”. Since we view risk in the mutually complementary functional contexts of probability theory and algebra, we avoid trying to search for a consensual definition of uncertainty in risk management.
We now provide an overview of mathematical notations used in probability theory, and we will restrict to the case where random variables are real-valued. Notions like “measure” and “measurable” are strictly defined within measure theory, upon which probability theory resides, but we avoid defining measure-theoretic notions in this brief overview of mathematical notations in probability theory. For detail concerning measure theoretic notions, see [36].
Notions in probability theory build upon a set S of samples, where S is often called the sample space. In this paper, we view a risk source, also known as a hazard, as a “sample” in some sample space (of risk sources). In [21], ‘event’ is generally seen as a subset of risk sources, or a subset of hazards. However, in [21] there is no strictly defined connection between the concepts of ‘risk source’, ‘event’ and ‘hazard’, and how they appear within the concepts of ‘probability’ as they are mathematically well defined within probability theory.
The notion of randomness, over the sample space S, is defined by the real-valued random variable as being a (measurable) function X : S R , where R is the continuous range of real numbers assigned to samples, and over R we assume to have the Borel σ -algebra (not further explained in this paper). Thus, when a risk source is viewed as an element s S , we have X ( s ) R as the value or “observed measurement” of the risk source s. Note indeed that the value is just the numerical value assigned to and describing the risk source, without any auxiliary information per se about other characteristics of the risk source.
The use of ‘space’ in ‘sample space’ is a bit misleading since S is just a set without any structure whatsoever. We should thus call S a ‘sample set’ rather than a ‘sample space’, since the use of ‘space’ falsely indicates that S would possess some structure beyond being just a set of points.
There is often a confusion between the notions of “sample”, “outcome” and “event”, in particular in the situation involving real-valued random variables, where the confusion between “sample” and “outcome” is due to the notation “ X x ”, which is not a statement, but is the set { s S X ( s ) x } of samples, i.e., not a set of values in R . Thus, whereas s is a “sample”, an “outcome” may be understood as the sample s S together with its value X ( s ) R given by the underlying random variable X : S R , i.e., we might speak of an “outcome of a sample”, rather than “outcome as a sample”.
Needless to say, a random variable is not a “variable” as understood in logic and computer science, but indeed a function that, we could say, “randomly assigns” real numbers to samples.
In statistical analysis, the random variable is unfortunately often “hidden” or ignored altogether in the sense that samples are identified with their observed values, i.e., the sample space S is viewed as R . Therefore, the random variable becomes trivially X : R R and moreover just chosen to be the identity function. In this case, there is obviously no distinction between “sample” and “outcome”. It is indeed important to realize that in analysis we compute with X ( s ) values and not with the samples s.
Kolmogorov’s axiomatic foundations of probability theory [37] was written in German, and the sample set was simply called a “set of elements” (eine Menge von Elementen), and the elements were named elementare Ereignisse, which in the English translation [38] appear as “elementary events”. Events as sets of samples are in [37] named zufällige Ereignisse, and in the English translation [38] appearing as random events.
In the common nomenclature for probability theory, there is seldom explanations on the distinction between “sample” and “outcome”, other than an “outcome” being seen as a sample in a “trial” or “experiment”, which is seen as a sequence of samples s with their values X ( s ) . The notion of “sampling”, or “conducting an experiment”, or “executing a trial”, usually refers to creating such a sequence of samples by repeatedly “drawing” samples from a set of samples.
In many practical situations, “sampling” means selecting a subpopulation, e.g., of humans, from a larger population, sometimes called a “lot”, and making observations on individual humans in that subpopulation, with the objective to arrive at conclusions concerning the lot, i.e., the whole population.
In [30], a lot is basically a population, as a set of elements, defined by a collection of criteria that determine whether or not an element qualifies to be a member of that population. The sample set is then a randomly chosen subset of the lot set, so that the elements in the sample set can be seen “representative” for the elements in the lot set. Probability theory uses the sample set, but does not define the lot set, and in this paper it suffices to view a lot as corresponding to a population, defined in a wider sense. For risk management in food safety, we may recall the definition of lot in [39], saying that by a lot of unsatisfactory quality is meant one that contains more than a specified proportion of defective pieces. In food production, we would expect no more than a certain proportion of delivered lots to be unsatisfactory in quality. As analysis will be restricted to the use of the sample set, it is important to ensure lot quality, techniques for which are provided, e.g., in [40].
We now come to the formal definition of probability, which is defined within a ‘probability space’, building upon a selected sample set S. A probability is a “probability of an event”, where an event is a subset of samples in S, and the probability is a value in the unit interval [ 0 , 1 ] . An event is formally defined as an element of a σ -algebra over S, i.e., closed under formation of complements and unions of subsets of S, and we may denote this σ -algebra as E . An event A E is thus a subset of S, i.e., A S . A probability is now defined as a function, the probability function (as a measurable function) P : E [ 0 , 1 ] , which is required to satisfy P ( S ) = 1 and P ( A 1 A 2 ) = P ( A 1 ) + P ( A 2 ) whenever A 1 A 2 = .
The triple ( S , E , P ) forms a probability space. Now note that for an event A E we indeed have its probability P ( A ) . However, we still have not defined “distribution”, for which we will need a random variable X : S R . A “distribution” is thus not given until we have a random variable, and once we do have both a probability space ( S , E , P ) and a random variable X : S R , we will be able to define the intertwining of probability and the distribution of it.
There is a widespread confusion about “distribution” and “distribution function”. Textbooks almost always include precise definitions e.g., for PDFs and CDFs, where a PDF is a probability density function and a CDF is a cumulative distribution function.
Before sorting out this confusion, we need to note the shorthand notational praxis in probability theory related to the informal expression “ X x ”. Formally and precisely, an expression like “ P ( X x ) ” is the probability value in [ 0 , 1 ] of the event “ X x ”, which, as already pointed out above, is the subset of samples A = { x S X ( s ) x } , x R .
We are now in a position to discuss the “distributions” and the “distribution functions”. We usually understand a CDF to be given by a PDF as follows. A PDF is a function
f : R [ 0 , [
such that
f ( x ) d x = 1
Note that if f ( x ) 0 only for a finite set of values { x 1 , , x n } , then we call f a probability mass function, and it fulfills the property
i = 1 n f ( x i ) = 1
Given such a PDF f, we can define the corresponding CDF
F : R [ 0 , 1 ]
by
F ( x ) = x f ( t ) d t
and we thereby assume that F ( x ) is the probability of the event “ X x ”, i.e., we assume that
F ( x ) = P ( X x )
Doing so gives us the impression that we first have a PDF, then we can define a CDF, and that essentially defines the probability function. However, in probability theory, it is just the other way around, since we are first given the probability space, including the probability measure
P : E [ 0 , 1 ]
Then we select a real-valued random variable
X : S R
so that we can define F according to (A7). In order to define f, we need to rely on the Radon-Nikodym Theorem, that guarantees the existence a function f of the form (A2) satisfying
P ( A ) = A f d λ
where A E and λ is the Lebesque measure over the Borel σ -algebra over R . Thus, we first have P, using which we define F according to (A7), and given P, we use (A10) to arrive at the existence of f. Finally, the relation between F and f is given by (A6), which means that
f ( x ) = F ( x )
i.e., a PDF is the derivative of its corresponding CDF, and, because of (A10), this derivative is called the Radon-Nikodym derivative.
We conclude this Appendix by providing a brief overview of probabilistic methods for quantifying risk sources within food safety.
Guides and guidelines for adoption of probabilistic methodology are many, one of which is the guidance [30] that the European Food Safety Authority (EFSA) requested from the Panel on Plant Protection Products and their Residues to provide on probabilistic methodology. The focus in [30] is on methodology in support of conducting dietary exposure assessments for pesticides, and particularly on the way assumptions about probabilistic models affect experts in their decisions on various judgments, e.g., concerning inclusion and exclusion of risk sources.
In [30], probabilistic assessment is outlined mainly for basic assessment rather than refined assessment, where basic probabilistic assessment aims to focus on upper and lower bound probability distributions for assumed but not found “true” distributions. These distributions, considered to be upper and lower bounds, are called, respectively, “pessimistic” and “optimistic” models.
Notably, as stated in [30], if the results of the pessimistic model raise no concern for risk managers, it can be assumed that the true dietary exposure would also cause no concern, so the assessment can stop, and such a situation it is not necessary to conduct the optimistic model run. Perhaps more importantly and rationally, if both the optimistic and pessimistic estimates raise concern, and if the level of concern indicates an unacceptable risk, then it can be assumed that the true exposure would also raise a similar level of concern, where in that case further refinement is unlikely to be worthwhile if the assessment is acute, whereas in a chronic assessment, refinement may require the use of parametric modeling. Refined approaches may be needed if pessimistic models turn out to be too conservative, and as the models are progressively refined, the results of the optimistic and pessimistic runs will gradually converge.
For pessimistic models in basic probabilistic assessment, it is in [30] proposed that the proportion of residues below the “limit of reporting” should be modeled independently using a binomial distribution, and for basic probabilistic assessment in general it is proposed that lognormal distribution is used. The choice of distribution function is often difficult, and guided only by the general nature of the analysis task. For instance, in predictive microbiology, Weibull’s distribution is typically used for predicting bacterial inactivation. We may note that Weibull’s distribution is often also used in predictive maintenance for analyzing the “remaining useful life” for machines of various kinds.
On the relation between probability theory and many-valued logic, section on “Methods for quantifying uncertainty” in [41], in its Section 11.1.3 on Expressing uncertainty using possibility, includes a quite shallow historical background of algebraic methodology for many-valued logic as used in this paper. That subsection, including references to “fuzzy logic” and “possibility theory, ” is very brief and should not be understood as any kind of summary of or introduction to the algebraic and logical foundations of many-valued logic as used in this paper for the very reason to complement probabilistic methodology used in risk management with algebraic and many-valued logical methodology. We may also recall that ever since Lotfi Zadeh introduced “Fuzzy sets” [42] in 1965, he spoke on numerous occasions about the distinction of fuzzy logic in the broader sense and in the “narrow sense”, the latter being a name for the more theoretical discipline of “fuzzy sets and systems”, particularly focused on the algebraic foundations of fuzzy and many-valued logic. In these algebraic foundations, it was immediately seen how the formal description of “uncertainty” in probability theory connected with probability must not be confused with uncertainty as a truth level in many-valued logic. However, within “fuzzy logic in the broader sense”, essentially referred to in [41], probability theory was a burden, as the fuzzy systems research community often heard Lotfi Zadeh view fuzzy set theory as an alternative and being in a competitive role as compared with probability, in particular in discussions on the practical use of the concept of “uncertainty”. Fuzzy sets in this broader or broadest view are based on an unstructured view of a “universe of discourse”.
The approach in [43] on “Possibility theory” was an effort to establish a bridge over the gap between probabilistic and fuzzy views of uncertainty. In [44], there was an effort to discuss relations between artificial intelligence and uncertainty modeling, in particular regarding the role of fuzzy set theory and many-valued logics. However, the treatment is more pragmatic and even philosophical than formally logical and mathematical. There were at that time efforts to accelerate developments of “probabilistic logic”, i.e., to identify logical substance within probability theory, rather than complementary to probability theory.
In [41], it is implicitly stated that fuzzy methodology in risk management is quite sparse, and this is indeed a correct observation. Some results exist, and are based on traditional fuzzy set modeling, like e.g., seen in [45], where “fuzzy HACCP” is suggested in the form of a fuzzy decision tree. However, even if providing a brief overview of fault tree analysis, it does not include detail on fuzzy fault tree analysis, which dates back to [46].
In this paper, our algebraic approach builds upon algebraic structures, e.g., like quantales [35], and our approach is to view algebra, many-valued logic, and probability theory as appearing complementarily and mutually supportive in relation to each other rather than competitively or mutually exclusive.

Appendix C. Glossary

In Table A4, we provide a list of the main mathematical notations used in this paper and briefly explain their use in specific contexts and how they might appear in a related or broader context.
Table A4. Mathematical notations in specific contexts and in other appearances.
Table A4. Mathematical notations in specific contexts and in other appearances.
NotationSpecific ContextOther Appearance
ssource; risk sourcesample
Sset of sources; set of risk sourcesset of samples (sample space)
s S s is a source in the source set Ss is a sample in the sample set S
s S s is a source in the source set Ss is a sample in the sample set S
qelement in a quantalecharacterization or evaluation
Qquantalequantale of characterizations
q Q q is an element in the quantale Q
Q o c c quantale of occurrences
Q s e v quantale of severities
Q r i s k quantale of risk levels
Q × Q risk table
Q o c c × Q s e v occurrence-severity risk tablein [2] called P-I (probability–impact) table
f : S Q mapping of risk sources to values in a quantale
f o c c : S Q o c c characterization function for occurrence, i.e., mapping of risk sources to occurrence values
f s e v : S Q s e v characterization function for severity, i.e., mapping of risk sources to severity values
f r i s k : S Q r i s k risk function, i.e., mapping of risk sources to risk values
σ : S Q × Q mapping of risk sources into a risk table
σ : S Q o c c × Q s e v mapping of risk sources into values in the occurrence-severity risk table
ρ : Q × Q Q risk matrix
ρ : Q o c c × Q s e v Q r i s k occurrence-severity risk matrix
: Q × Q Q quantale operationrisk matrix represented by a quantale operation

References

  1. Food and Agriculture Organization of the United Nations (FAO); World Health Organization (WHO). Codex Alimentarius Commission Procedural Manual, 31st ed.; Food and Agriculture Organization of the United Nations (FAO): Rome, Italy; World Health Organization (WHO): Geneva, Switzerland, 2025. [Google Scholar] [CrossRef]
  2. FAO (Food and Agriculture Organization of the United Nations); WHO (World Health Organization). Risk Characterization of Microbiological Hazards in Food: Guidelines; Microbiological Risk Assessment Series No. 17; Food and Agriculture Organization of the United Nations (FAO): Rome, Italy; World Health Organization (WHO): Geneva, Switzerland, 2009; Available online: https://www.who.int/publications/i/item/9789241547895 (accessed on 14 July 2026).
  3. European Commission. COMMISSION NOTICE on the Implementation of Food Safety Management Systems Covering Good Hygiene Practices and Procedures Based on the HACCP Principles, Including the Facilitation/Flexibility of the Implementation in Certain Food Businesses; European Commission (2022/C 355/01); European Union: Luxembourg, 2022. [Google Scholar]
  4. Wallace, C.A.; Holyoak, L.; Powell, S.C.; Dykes, F.C. Re-thinking the HACCP team: An investigation into HACCP team knowledge and decision-making for successful HACCP development. Food Res. Int. 2012, 47, 236–245. [Google Scholar] [CrossRef]
  5. Liu, F.; Rhim, H.; Park, K.; Xu, J.; Lo, C.K. HACCP certification in food industry: Trade-offs in product safety and firm performance. Int. J. Prod. Econ. 2021, 231, 107838. [Google Scholar] [CrossRef]
  6. Zhou, J.; Brereton, P.; Campbell, K. Progress towards achieving intelligent food assurance systems. Food Control 2024, 164, 110548. [Google Scholar] [CrossRef]
  7. Semenoja, D. Development of a Process-Based HACCP System for Lapin Poro ja Riista Oy. Master’s Thesis, University of Oulu, Oulu, Finland, 2023. Available online: https://oulurepo.oulu.fi/handle/10024/43144 (accessed on 14 July 2026).
  8. United States Public Health Service; Food and Drug Administration. Food Code; 18 January 2023 Version; United States Public Health Service Food and Drug Administration: College Park, MD, USA, 2022. [Google Scholar]
  9. International Electrotechnical Commission (IEC). Risk Management—Risk Assessment Techniques; International Electrotechnical Commission (IEC): Geneva, Switzerland, 2019. [Google Scholar]
  10. Codex Alimentarius Commission. General Principles of Food Hygiene. Codex Alimentarius Code of Practice, No. CXC 1-1969; World Health Organization: Geneva, Switzerland, 2022. [Google Scholar]
  11. Motarjemi, Y.; Käferstein, F.; Moy, G.; Miyagawa, S.; Miyagishima, K. Importance of HACCP for public health and development the role of the World Health Organization. Food Control 1996, 7, 77–85. [Google Scholar] [CrossRef]
  12. Sazali, M. Importance of Hazard Analysis Critical Control Points (HACCP): A Review. Borneo Epidemiol. J. 2025, 5, 1–10. [Google Scholar] [CrossRef]
  13. Baikadamova, A.; Yevlampiyeva, Y.; Orynbekov, D.; Idyryshev, B.; Igenbayev, A.; Amirkhanov, S.; Shayakhmetova, M. The effectiveness of implementing the HACCP system to ensure the quality of food products in regions with ecological problems. Front. Sustain. Food Syst. 2024, 8, 1441479. [Google Scholar] [CrossRef]
  14. Awuchi, C.G. HACCP, quality, and food safety management in food and agricultural systems. Cogent Food Agric. 2023, 9, 2176280. [Google Scholar] [CrossRef]
  15. ISO 22000:2018; Food Safety Management Systems—Requirements for Any Organization in the Food Chain Maintenance—Maintenance Terminology. International Organization for Standardization (ISO): Geneva, Switzerland, 2018.
  16. Hillson, D. Effective Opportunity Management for Projects: Exploiting Positive Risk, 1st ed.; CRC Press: Boca Raton, FL, USA, 2003. [Google Scholar] [CrossRef]
  17. ISO 31000:2018; Risk Management Guidelines. International Organization for Standardization (ISO): Geneva, Switzerland, 2018.
  18. Raheemy, Y.; Sherratt, F.; Hallowell, M.R. What is safety? contemporary definitions and interpretations across North America. Saf. Sci. 2025, 185, 106798. [Google Scholar] [CrossRef]
  19. Balderson, D. Safety Defined: A Means to Provide a Safe Work Environment. Prof. Saf. 2016, 61, 63–68. [Google Scholar]
  20. Hollnagel, E. Safety-I and Safety-II: The Past and Future of Safety Management, 1st ed.; CRC Press: Boca Raton, FL, USA, 2014. [Google Scholar]
  21. ISO 31073:2022; Risk Management—Vocabulary. International Organization for Standardization (ISO): Geneva, Switzerland, 2022.
  22. Mercure, J.F.; Sharpe, S.; Vinuales, J.E.; Ives, M.; Grubb, M.; Lam, A.; Drummond, P.; Pollitt, H.; Knobloch, F.; Nijsse, F.J. Risk-opportunity analysis for transformative policy design and appraisal. Glob. Environ. Change 2021, 70, 102359. [Google Scholar] [CrossRef]
  23. Lemmens, S.M.P.; Lopes van Balen, V.A.; Röselaers, Y.C.M.; Scheepers, H.C.J.; Spaanderman, M.E.A. The risk matrix approach: A helpful tool weighing probability and impact when deciding on preventive and diagnostic interventions. BMC Health Serv. Res. 2022, 22, 218. [Google Scholar] [CrossRef] [PubMed]
  24. Gizaw, Z. Public health risks related to food safety issues in the food. Environ. Health Prev. Med. 2019, 24, 68. [Google Scholar] [CrossRef] [PubMed]
  25. Sutherland, H.; Recchia, G.; Dryhurst, S.; Freeman, A.L. How People Understand Risk Matrices, and How Matrix Design Can Improve their Use: Findings from Randomized Controlled Studies. Risk Anal. 2022, 42, 1023–1041. [Google Scholar] [CrossRef] [PubMed]
  26. Food and Drug Administration. Managing Food Safety: A Manual for the Voluntary Use of HACCP Principles for Operators of Food Service and Retail Establishments; U.S Department of Health and Human Services, Food and Drug Administration: College Park, MD, USA, 2006. [Google Scholar]
  27. German Association of the Automotive Industry (VDA). Quality Assurance in the Process Landscape—Sections 1–4; VDA: Berlin, Germany, 2022. [Google Scholar]
  28. Shamsgovara, A.; Eklund, P.; Winter, M. A Catalogue of Finite Quantales; Technical Report; Umeå University: Umeå, Sweden, 2019; Available online: https://urn.kb.se/resolve?urn=urn:nbn:se:umu:diva-239055 (accessed on 14 July 2026).
  29. Tarski, A. A lattice-theoretical fixpoint theorem and its applications. Pac. J. Math. 1955, 5, 285–309. [Google Scholar] [CrossRef]
  30. EFSA Panel on Plant Protection Products and their Residues (PPR). Guidance on the Use of Probabilistic Methodology for Modelling Dietary Exposure to Pesticide Residues. EFSA J. 2012, 10, 2839. [Google Scholar] [CrossRef]
  31. Sauli, L. Tunne Poro; Wazama Media Oy: Kuusamo, Finland, 2016. [Google Scholar]
  32. Quitadamo, P.; Battagliere, I.; Del Bene, M.; Caruso, F.; Gragnaniello, P.; Dolce, P.; Caldore, M.; Bucci, C. Sharp-Pointed Foreign Body Ingestion in Pediatric Age. J. Pediatr. Gastroenterol. Nutr. 2023, 76, 213–217. [Google Scholar] [CrossRef] [PubMed]
  33. Shamsgovara, A. Enumerating, Cataloguing and Classifying All Quantales on up to Nine Elements. In Proceedings of the Relational and Algebraic Methods in Computer Science; Glück, R., Santocanale, L., Winter, M., Eds.; Springer: Cham, Switzerland, 2023; pp. 224–240. [Google Scholar]
  34. Spink, J.; Moyer, D.C. Defining the Public Health Threat of Food Fraud. J. Food Sci. 2022, 76, R157–R163. [Google Scholar] [CrossRef] [PubMed]
  35. Eklund, P.; García, J.G.; Höhle, U.; Kortelainen, J. Semigroups in Complete Lattices: Quantales, Modules and Related Topics; Developments in Mathematics; Springer International Publishing: Cham, Switzerland, 2018. [Google Scholar]
  36. Halmos, P.R. Graduate Texts in Mathematics. In Measure Theory; Springer: New York, NY, USA, 1974; Volume 18. [Google Scholar]
  37. Kolmogorov, A.N. Grundbegriffe der Wahrscheinlichkeitsrechnung; Springer: Berlin/Heidelberg, Germany, 1933. [Google Scholar]
  38. Kolmogorov, A.N. Foundations of the Theory of Probability; Chelsea Publishing Company: San Francisco, CA, USA, 1950. [Google Scholar]
  39. Dodge, H.F.; Romig, H.G. A Method of Sampling Inspection. Bell Syst. Tech. J. 1929, 8, 613–631. [Google Scholar] [CrossRef]
  40. WHO Global Programme for Vaccines and Immunization. Monitoring Immunization Services Using the Lot Quality Technique; Number WHO/VRD/TRAM/96.01; World Health Organization: Geneva, Switzerland, 1996; Available online: https://iris.who.int/handle/10665/63177 (accessed on 14 July 2026).
  41. EFSA Scientific Committee; Benford, D.; Halldorsson, T.; Jeger, M.J.; Knutsen, H.K.; More, S.; Naegeli, H.; Noteborn, H.; Ockleford, C.; Ricci, A.; et al. The principles and methods behind EFSA’s Guidance on Uncertainty Analysis in Scientific Assessment. EFSA J. 2018, 16, e05122. [Google Scholar] [CrossRef] [PubMed]
  42. Zadeh, L.A. Fuzzy sets. Inf. Control 1965, 8, 338–353. [Google Scholar] [CrossRef]
  43. Dubois, D.; Prade, H. Possibility Theory: An Approach to Computerized Processing of Uncertainty; Plenum Press: New York, NY, USA, 1988. [Google Scholar]
  44. Dubois, D.; Prade, H. Possibility Theory, Probability Theory and Multiple-Valued Logics: A Clarification. Ann. Math. Artif. Intell. 2001, 32, 35–66. [Google Scholar] [CrossRef]
  45. Bertolini, M.; Rizzi, A.; Bevilacqua, M. An alternative approach to HACCP system implementation. J. Food Eng. 2007, 79, 1322–1328. [Google Scholar] [CrossRef]
  46. Tanaka, H.; Fan, L.T.; Lai, F.S.; Toguchi, K. Fault-Tree Analysis by Fuzzy Probability. IEEE Trans. Reliab. 1983, R-32, 453–457. [Google Scholar] [CrossRef]
Table 1. A quantale as a risk matrix.
Table 1. A quantale as a risk matrix.
x c o l
x r o w x r o w x c o l
Table 2. A 5 × 5 (colored) risk matrix.
Table 2. A 5 × 5 (colored) risk matrix.
01234
000000
101111
201222
301233
401234
Table 3. A general view on (occurrence independent) characterization of severity.
Table 3. A general view on (occurrence independent) characterization of severity.
CategoryDescription of Impact
Noneno impact
Very Lowfeeling slightly affected and ill, without a need to seek help
Lowhaving gastroenteric of other symptoms, treated with self care
Mediumsymptoms and illness, that requires to seek medical attention
Highlong-lasting or chronic medical condition, caused by the illness
Very Highterminal illness or death
Table 4. Algebraic adaptation of Table 4.9 in [2].
Table 4. Algebraic adaptation of Table 4.9 in [2].
012345
0000000
1022233
2022334
3023344
4023444
5034444
Table 5. Quantale 6.15.9177 in [28], which is unital, with ‘2’ as the unit.
Table 5. Quantale 6.15.9177 in [28], which is unital, with ‘2’ as the unit.
012345
0000000
1011335
2012345
3033555
4034555
5055555
Table 6. Quantale 6.15.8746 in [28], which is unital, with ‘3’ as the unit.
Table 6. Quantale 6.15.8746 in [28], which is unital, with ‘3’ as the unit.
012345
0000000
1011145
2012245
3012345
4014445
5055555
Table 7. The left-hand matrix is quantale 6.15.11329 and the right-hand matrix is quantale 6.15.1 in [28].
Table 7. The left-hand matrix is quantale 6.15.11329 and the right-hand matrix is quantale 6.15.1 in [28].
012345012345
00000000000000
10555551000000
20555552000000
30555553000000
40555554000000
50555555000000
Table 8. The left-hand table is an incomplete matrix, and the right-hand matrix is quantale 6.15.7902 in [28].
Table 8. The left-hand table is an incomplete matrix, and the right-hand matrix is quantale 6.15.7902 in [28].
012345012345
00000000000000
101 1011111
20 1 122011112
30 2 3011223
40 2 4011224
50123 55012335
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Semenoja, D.; Sinkkonen, M.; Eklund, P. Computing with HACCP Risk and Safety Characterizations. AppliedMath 2026, 6, 116. https://doi.org/10.3390/appliedmath6070116

AMA Style

Semenoja D, Sinkkonen M, Eklund P. Computing with HACCP Risk and Safety Characterizations. AppliedMath. 2026; 6(7):116. https://doi.org/10.3390/appliedmath6070116

Chicago/Turabian Style

Semenoja, Darija, Minna Sinkkonen, and Patrik Eklund. 2026. "Computing with HACCP Risk and Safety Characterizations" AppliedMath 6, no. 7: 116. https://doi.org/10.3390/appliedmath6070116

APA Style

Semenoja, D., Sinkkonen, M., & Eklund, P. (2026). Computing with HACCP Risk and Safety Characterizations. AppliedMath, 6(7), 116. https://doi.org/10.3390/appliedmath6070116

Article Metrics

Back to TopTop