Resources Food and beverage

What the auditor asks, and what your records hold

An audit is a series of questions about your records. Here is what food safety compliance software has to hold to answer them.

A food safety auditor asks five questions about one lot: what went into it, what happened to it on the line, who was qualified to do that work, what the last deviation on that line was, and what else touched the thing that went wrong. In most plants the answers live in a binder, a shared drive, and one person’s memory. Whatever holds your records, binder or food safety compliance software, has to answer those questions the way the auditor asks them: by lot, by moment, by person.

A QA manager at a co-packer outside Atlanta walked me through her last audit. Good plant, good people. Her office is mostly binders. Second shelf, third from the left, critical control point logs. She can put her finger on any single reading in about two minutes, which is genuinely better than most. Then the auditor asked the follow-up. Not show me the reading. Show me every other lot that ran on that line during the window where the reading drifted. She wrote it on a sticky note and said she would have it after lunch. She had it at 4:30, after two calls to maintenance and a walk down to shipping.

The binder answered the first question. It could not answer the second one, because the second one needs several records joined together.

What does a food safety auditor actually ask?

Ask enough QA managers and the list comes out close to the same every time. Every question works backwards from one finished pallet.

  • Show me what went into this. Every input lot, including the rework.
  • Show me what happened to it. Readings, times, the equipment, the crew.
  • Show me who was allowed to do that, and how you know they were trained on the current version.
  • Show me the last deviation on this line, what you decided, and who signed it.
  • Show me everything else that touched the thing that just went wrong.

The first four are answerable from a well-kept binder if you have half a day. The fifth is the one that decides how the rest of the audit goes, and it is also the one nobody keeps a binder for, because it is not a record. It is a question that has to be asked of every record at once.

Why the answer is usually in a binder

The binder is not laziness. It is the honest response to an operation whose records are scattered across systems that were each bought for a different reason.

The scale software holds the weights. The ERP holds the order and the customer. The quality system holds the SOP and its revision history. The sanitation log is on paper because wash-down destroys tablets. The training records are in HR, in a spreadsheet, owned by someone who does not work in the plant. The CCP readings are in the data logger, or handwritten on a form that gets scanned on Fridays.

Every one of those systems is correct about its own piece. None of them holds lot traceability, the fact that a lot is a thing with parents and children. So somebody in the building has to keep the connections in their head, and the binder is where they write them down. It runs at the speed of a person, and it retires when that person does.

What food safety compliance software has to hold

Food safety compliance software is the system that holds the records an audit asks for and the connections between them: lot genealogy, critical control point readings, sanitation and training records, deviations and their outcomes. Not documents. Documents are the easy half.

The part that matters is whether the software stores the things in your plant and how they connect. A lot is a thing that came from other lots and became other lots. A run is a thing that has a line, a shift, a crew, a set of readings, and a start and end. A person is a thing that holds a training record with a date and a document version on it. A deviation is a thing that attaches to a run and to a decision and to the person who made it. Get those relationships stored while the work happens and the fifth question answers itself, because the trail already exists. Store PDFs about your lots instead and you still have a binder, just on a screen.

Test it on a bad week rather than a clean one: a pallet gets split, relabelled for a private-label customer, and half of it comes back as rework three weeks later. That is a normal week in a co-packing plant, and it is where most records break down.

The walkthrough to run this week

You can find out where you stand in an afternoon.

Pick one pallet that shipped last month. Not your cleanest one. Pick one with a rework loop or a split in it. Then ask it the five questions above yourself, with a stopwatch, and write down three things for each answer: where it came from, how long it took, how many people you had to interrupt.

Then run it a second time with a wrinkle. Assume you just learned that a supplier lot from that week is suspect. Find every finished pallet that touched it, including anything that went into rework and came back out under a different code. Time that one too.

The first number is what an audit costs you. The second number is what a customer complaint costs you at 2pm on a Tuesday when you have to decide whether to hold one pallet or forty. The second number is not a little bigger than the first. It is a much bigger problem, and it is the one that shows up on the P&L.

On what you actually owe, the rule text and your compliance professional govern. Nothing here is a reading of the regulation. This is about whether you can produce the answer inside the time you have, which is a different problem and entirely yours.

The auditor is not the risk. The auditor books a date, arrives, asks the questions, and leaves. The risk is the phone call nobody scheduled, about a foreign material complaint on a code you shipped six weeks ago, when you have four hours to decide how wide to go. That call gets answered with whatever your records can tell you in four hours. Everything else in the binder is history you cannot reach in time.

Questions people ask

Food safety compliance software is software that keeps the records an audit asks for: lot genealogy, critical control point readings, sanitation and training records, deviations and what was done about them. The useful ones store the connections between those records, not just the documents.