Skip to content
faceela

Batch Traceability and Recall: The Forty-Eight Hour Question

· 12 min read · Faceela

It is twenty to five on a Thursday and the quality manager's phone rings. A distributor has a complaint from one of its customers, and there is a batch code printed on the pouch. The caller reads it out. It is nine characters, one of which might be a five or an S.

Everything that happens over the next two days is determined by data that was captured — or was not captured — over the preceding several months, by people who were not thinking about this phone call. Nothing you do on Thursday evening improves it. The only decisions available now are how wide to cast the net and how quickly, and both of those are set by the quality of records nobody looked at when they were being made.

There are exactly three questions to answer, and they never change. Which batches are affected? Where did they go, to whom, in what quantities? And how much of it is still under your control, in your warehouse, at your distributor, or on a shelf?

A company that can answer all three by Friday afternoon recalls a defined set of batches from a defined list of recipients. A company that cannot recalls everything it is not sure about, which is a much larger number and is paid for in product, in freight, in customer confidence and in the several weeks of senior management time that a wide recall consumes.

What "one step forward, one step back" actually demands

The phrase comes from food law, where it is the baseline obligation in the major regimes: you must be able to identify who supplied you and to whom you supplied, at the level of the consignment. It sounds like two queries. It is in fact a chain of linked records, and it breaks at whichever link is weakest.

For a manufacturer the chain has five joints, and each of them has to hold a specific fact.

LinkWhat must be recordedThe usual failure
Goods receiptSupplier lot number against your internal lot, per delivery, per itemThe supplier lot is on the delivery note and never keyed in, so the chain starts at your door
StorageWhich lot is in which location, and which lot was pickedStock held by item and quantity only, so any lot could have been the one issued
ConsumptionWhich lot was consumed by which production order, and how muchConsumption booked against the item at the standard quantity, backflushed, with no lot
Production outputWhich lot was produced, when, on which line, in what quantityAn output lot with no recorded parents, or a lot number that is really a date
DispatchWhich output lot went on which delivery, to which customer, in what quantityDelivery recorded by item and quantity, lot chosen by the picker and not captured

Notice what the table implies. Traceability is not a module and it is not a report. It is a property that emerges when every one of those five transactions carries a lot identity, and it is destroyed by any single one of them that does not. This is the reason a plant can hold a certificate, pass an audit and still take three days to answer the phone call: the audit examined the procedure, and the procedure describes what should happen at each of those five points.

There is a sixth requirement that separates a real traceability capability from a nominal one: mass balance. Given an input lot, can you account for the whole of it? So many kilograms received, so many consumed on these orders, so many still in stock, so much scrapped, so much returned. If the numbers do not add up, the trace is incomplete and the missing quantity is exactly the part you cannot rule out, which is to say exactly the part that widens the recall.

Batch size is a decision, not a fact

Before any of the mechanics there is a design question most factories have never consciously answered: how big is a lot?

The size of the batch is the size of the recall. A plant that produces in single daily lots per product recalls a day of output. A plant that closes a lot per shift, or per production order, or per silo change, recalls a fraction of that. The finer definition costs something — more lot numbers, more discipline at changeover, more segregation in the store — and it buys a smaller worst case.

The way to frame that trade in a management meeting: what would it cost us to recall one lot of our highest-volume product, and would we accept that number twice in a year? If the answer is no, the lot is too big, and making it smaller is cheaper than any system.

Where the chain actually breaks

Every plant with a procedure has the straightforward path working: material in, one production order, product out, one delivery. The chain breaks at the exceptions, and the exceptions are where product spends a surprising share of its life.

Rework

A batch fails, is held, and is later reworked into subsequent production — a few per cent added into each of the next several batches. This is the single most common break, and it is the one that turns a small recall into a large one, because a defective input lot now has children it did not have when the chain was first drawn.

For the record to survive, the rework must be a transaction: the held lot is consumed by the new production order and appears among its parents. If the material is simply added on the floor and the paperwork stays silent, the trace forward stops at the batch that failed — and the defect walks quietly into three later batches that look clean.

Blending and continuous processes

A blend has many parents by design. A tank, a silo or a hopper is a moving mixture in which yesterday's material and today's are not separable, and the honest answer to which input lot is in this output is "several, in proportions nobody measured".

The practical treatment is a time-based lot rule with the assumption written down: the tank is deemed to turn over across a defined period, so an output lot inherits every input lot charged within that window. It is an approximation, and stating it plainly makes it defensible. What is not defensible is a system that models a many-to-many relationship as one-to-one, which is what happens whenever a production order allows one lot per component and the floor is charging three.

Repacking and relabelling

Bulk into retail packs, drums into pails, a private-label run for a customer whose artwork changes but whose product does not. Each creates a new lot, and the new lot must inherit its parent. Repacking is a quick operation done under time pressure, often in a different part of the building and sometimes at a third party, which is why it is the operation most likely to be recorded as a plain stock conversion with the linkage lost. Take a repacked item and ask what bulk lot it came from: if the answer requires someone to reason about what was probably being packed that week, the link does not exist.

Subcontracted operations

Material sent out for a process — coating, sterilisation, milling, printing, irradiation — leaves your building as one lot and comes back as something else, frequently under the subcontractor's own lot number or with none at all. Their records are not yours and their retention policy is not yours either.

Three things fix it, none of them technical: the outgoing document carries your lot and requires it to be quoted back; the incoming receipt records what went against what returned; and the contract obliges them to keep records for at least as long as you must. The same point governs stock accuracy, since material at a subcontractor is still your stock and needs a location that represents them.

Samples, replacements and everything that left without an invoice

This is the category that ruins mock recalls, and it is always underestimated. Product goes out for laboratory testing, to a trade exhibition, to a prospective customer, to a distributor as a free replacement for a damaged case, to staff, to a photographer. Almost none of it goes through the normal dispatch process, because that process is tied to a sales order and there is no sales order.

The result is product in the market with no record of where it went. In a mass balance it is an unexplained difference; in a recall it is a set of units you cannot retrieve and cannot rule out. Nothing should leave the building without a document recording the lot and the recipient, whatever the commercial nature of the movement.

Returns put back into stock

Goods come back, are inspected, are found to be fine and go back on the rack — very often without their original lot, because the return document records an item and a quantity. One unit of unknown provenance in a location contaminates every subsequent trace out of that location.

Recovered and reprocessed material

In plastics, scrap becomes regrind and regrind goes back into later production, which means the genealogy runs through the waste stream as well as the product stream. The auditor's question is which resin lot went into the scrap that became the regrind that went into this part, and answering it requires the regrind itself to be a lot with parents. The same shape appears wherever material is recovered — offcuts remelted in a foundry, trim reprocessed on an extrusion line, cable remainders re-drummed under a new drum number.

Bought-in finished goods

A distributor's chain has fewer links and one hard dependency: if the supplier's lot number is not captured at receipt, the chain ends at your door and you are relying on the supplier to tell you which of their lots you received. That is a phone call to another company's records at the worst possible moment, and it can take days.

Running a mock recall properly

A mock recall is not a documentation exercise and it should not be comfortable. Certification schemes generally require a traceability test on a defined cycle with a mass balance included, and auditors commonly expect it completed in hours rather than days; the specific target is one you set and have to defend. What follows is how to make it useful rather than how to pass it.

Start from the far end and pick at random. The weak version starts with a production record you have already opened. The strong version starts the way reality starts: a code read off a physical unit, chosen by someone who did not know which one they would pick, ideally from stock at a customer or on a shelf.

Run both directions and clock them separately. Backward, to every input lot and every supplier. Forward, to every customer, every quantity and every date. Forward is the one that fails, because the dispatch link is the one most often broken, and forward is the one a recall depends on.

Include the mass balance. Reconcile the whole input lot: consumed, in stock, scrapped, sampled, returned, dispatched. Report the unexplained quantity as a percentage. That percentage is the most honest single measure of your traceability, and it will be higher than anybody expects the first time.

Include the notification. A list of affected batches is half the job. Can you produce the contact details, the quantity each recipient received and the dates, in a form that goes out as a notice within the hour? A trace that ends at a spreadsheet of customer codes has not finished.

Run it when the person who knows is away. If the exercise depends on the production manager who remembers everything, you do not have traceability; you have an employee.

Score it and fix one thing. Record the time in each direction, the unexplained quantity, and every point where a document had to be found rather than queried. Then change one process before the next test.

What to measure in a mock recallWhy it matters
Time to complete the backward tracePredicts how fast you can identify a cause
Time to complete the forward tracePredicts the width of the recall you will have to declare
Unexplained quantity in the mass balanceThe part you cannot rule out is the part you must recall
Number of records found outside the systemEvery one is a person-dependency and a delay
Completeness of recipient contact dataDecides whether notification takes an hour or a day
Whether samples and free issues were capturedThe usual source of unreachable product

Why uncertainty is paid in product

The width of a recall is not set by the extent of the defect. It is set by the precision with which you can bound the defect. If the records prove that only lots 4471 and 4472 could contain the affected input, then two lots are recalled. If they cannot exclude the rest of that week's production, the week goes, because no quality manager and no regulator will accept a boundary that rests on somebody's recollection.

That is the whole economic case, and it is why the argument does not depend on the probability of a recall being high. The expected cost is the probability multiplied by the width, and the width is the part you control. Everything above — the supplier lot at receipt, rework as a transaction, the samples documented — reduces the width.

The same data bounds an argument as well as a recall. A complaint tied to a specific lot, with the input certificates attached, ends a commercial dispute in one email. The same complaint without lot data becomes a negotiation about goodwill.

For a food business the exposure is straightforward and immediate: the difference between recalling one day's output and recalling everything you are not sure about is the difference between an incident and an event that reshapes the year. For a device business the obligation is structurally similar but the clock is more explicit — device regimes generally require distribution records sufficient to locate affected units, a unique identifier carried on the device and its packaging, and a report to the regulator when a correction or removal is made to reduce a risk to health. The trace forward often has to reach the named recipient rather than the invoiced customer, since a distributor's customer is a hospital and the units may already be in use.

What to fix first

The order matters, because each step makes the next one cheaper.

Capture the supplier lot at goods receipt, on every lot-controlled item, without exception. Nothing downstream is worth doing while the chain starts at your door.

Make lot capture mandatory at consumption and at dispatch, and remove the ability to override it. A field that can be skipped will be skipped on the day everyone is busy, which is the day the batch you will later care about is made.

Turn rework, repacking and subcontracting into transactions rather than movements, so that parentage is recorded by the act of doing the work rather than by someone remembering to note it.

Close the sample and free-issue route: one document type, always, for anything that leaves the building.

Then run a mock recall, from a random unit, timed, with a mass balance. Whatever it tells you is your actual position, and it will differ from the procedure on the wall. Repeat it quarterly and after any change to the process.

Most of this is configuration and discipline rather than development — lot control, enforced at the points where it is easiest to skip, in a system that already has the capability. What it needs is somebody with the authority to keep the fields mandatory when the line is behind schedule, which is why it belongs in the design of how the system will be governed after go-live rather than in a configuration backlog. The wider sequence for getting the production data underneath it right is set out in what a manufacturing implementation has to establish, and in what order.

Regulatory detail above is described structurally rather than quoted. The traceability obligations, certification test cycles and device reporting requirements that apply to your products depend on your markets, your customers' schemes and your own certifications, and should be confirmed against those rather than against this article.

Next step

Is this happening in your company?

If the article described your situation, the useful next move is a diagnosis rather than another article. Tell us the one thing that is not working.

Monday to Friday, 9:00 AM – 6:00 PM (GST)

Prefer we call you?

Leave your WhatsApp number and we will reach out.

We reply on WhatsApp first. Include your country code.

No newsletter, no reselling your number. We use it to reply to you — see our privacy policy.

WhatsApp us