<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
  <title>SystemPath Insights</title>
  <link>https://devbox.tail10a27d.ts.net/insights</link>
  <description>Food safety insights, HACCP guides, regulatory updates, and industry news from SystemPath.</description>
  <language>en-US</language>
  <lastBuildDate>Tue, 08 Sep 2026 19:37:32 +0000</lastBuildDate>
  <atom:link href="https://devbox.tail10a27d.ts.net/insights/feed" rel="self" type="application/rss+xml"/>
  <item>
    <title>The Brief: Week of August 31, 2026</title>
    <link>https://devbox.tail10a27d.ts.net/insights/the-brief-week-of-august-31-2026</link>
    <guid isPermaLink="true">https://devbox.tail10a27d.ts.net/insights/the-brief-week-of-august-31-2026</guid>
    <pubDate>Fri, 04 Sep 2026 16:27:51 +0000</pubDate>
    <category>The Brief</category>
    <author>Jeffrey Strout</author>
    <description>A ready-to-eat Listeria recall expands, FDA warning letters focus on sanitation verification, and SQFI holds the line on the Edition 10 audit start.</description>
    <content:encoded><![CDATA[<p>Three items this week worth your time: an expanding ready-to-eat recall with a familiar root cause, a run of warning letters that all cite the same verification gap, and a firm date you should already be planning against.</p><h2>Recalls and alerts</h2><p><strong>RTE sandwich recall expands to a second production line.</strong> A Midwest ready-to-eat sandwich producer widened last week&#039;s Listeria monocytogenes recall after follow-up swabs found the organism on a slicer frame two rooms away from the original positive.</p><p><strong>What it means: </strong>Harborage moves on wheels, racks, and people. If your corrective action for a positive stops at the site of the find, it is not finished.</p><p><strong>Frozen dessert alert for undeclared peanut.</strong> A private-label frozen dessert line was pulled after a retailer complaint traced to a shared filling line and a changeover that skipped allergen verification.</p><p><strong>What it means: </strong>Label checks catch label errors. Only a verified changeover catches a line that still carries the previous run.</p><h2>FDA and USDA</h2><p><strong>Warning letters cluster on sanitation verification.</strong> Four warning letters published this week cite sanitation preventive controls verified by sign-off alone, with no ATP, swab, or visual standard behind the signature.</p><p><strong>What it means: </strong>A signature is attestation, not verification. Auditors and investigators both read it that way now.</p><h2>Standards and schemes</h2><p><strong>SQFI confirms Edition 10 audits begin January 2, 2027.</strong> SQFI reiterated the audit start date and pointed sites to the published Code for the culture, change management, and environmental monitoring additions.</p><p><strong>What it means: </strong>Certificates issued in late 2026 will be the last written against Edition 9. If your recert window lands in Q1 2027, you are transitioning now whether you planned to or not.</p>]]></content:encoded>
  </item>
  <item>
    <title>Third Shift Is Where Monitoring Programs Go to Die</title>
    <link>https://devbox.tail10a27d.ts.net/insights/third-shift-is-where-monitoring-programs-go-to-die</link>
    <guid isPermaLink="true">https://devbox.tail10a27d.ts.net/insights/third-shift-is-where-monitoring-programs-go-to-die</guid>
    <pubDate>Mon, 31 Aug 2026 16:27:56 +0000</pubDate>
    <category>Field Notes</category>
    <author>Steven Moussawer</author>
    <description>Day shift has the QA manager, the supervisors, and the visitors. Third shift has the same CCPs and none of the audience. What we changed after our own logs told on us.</description>
    <content:encoded><![CDATA[<p>Pull your monitoring records and sort them by shift. If your facility is like most, the checks logged between 2 and 5 a.m. are more punctual, more uniform, and more perfect than anything day shift produces. That is not because your overnight crew is better. It is because some of those checks are getting pencil-whipped, and perfect is what pencil-whipping looks like.</p><h2>The audience problem</h2><p>Day shift runs its checks in front of an audience: QA in the hallway, supervisors on the floor, the occasional customer tour. Third shift runs the same CCPs alone. Nothing about the hazard changed at midnight, but everything about the accountability did. We found our own version of this the boring way, during an internal records review that noticed the 3 a.m. metal detector checks were logged at suspiciously even intervals.</p><h2>What did not work</h2><p>A retraining session and a memo. It worked for about three weeks, which is how long motivation lasts against structure. The checks were still boring, still unwitnessed, and still easiest to fill in from memory at the end of the shift.</p><h2>What worked</h2><ul><li><p>Checks that capture a reading, not a checkmark, because a number has to come from somewhere</p></li><li><p>Timestamps recorded by the system at entry, ending end-of-shift backfill</p></li><li><p>A supervisor verification step inside the shift, so the first review happens before day shift arrives</p></li><li><p>Fewer, better checks: we cut two redundant logs, which bought credibility for the ones that matter</p></li></ul><p>Compliance did not become perfect, and that is the point. The records now show occasional late checks and honest misses, which is what a real program looks like, and every one of them is visible the same night instead of at the annual audit.</p>]]></content:encoded>
  </item>
  <item>
    <title>The Brief: Week of August 24, 2026</title>
    <link>https://devbox.tail10a27d.ts.net/insights/the-brief-week-of-august-24-2026</link>
    <guid isPermaLink="true">https://devbox.tail10a27d.ts.net/insights/the-brief-week-of-august-24-2026</guid>
    <pubDate>Fri, 28 Aug 2026 16:27:51 +0000</pubDate>
    <category>The Brief</category>
    <author>Jeffrey Strout</author>
    <description>An undeclared milk recall in chocolate, the FSMA 204 records clock, and a BRCGS clarification on trend review.</description>
    <content:encoded><![CDATA[<p>Allergens again this week, plus two compliance clocks that keep ticking whether or not anyone at your facility is watching them.</p><h2>Recalls and alerts</h2><p><strong>Chocolate recall for undeclared milk.</strong> A confectioner recalled dark chocolate bars after routine retail sampling found milk protein well above trace levels, pointing to shared equipment rather than cross-contact in ingredients.</p><p><strong>What it means: </strong>Dark chocolate on a milk line is a formulation-level risk decision. If your allergen assessment treats it as a trace cross-contact issue, it is understating the hazard.</p><h2>FDA and USDA</h2><p><strong>FSMA 204 enforcement holds at July 20, 2028.</strong> FDA reaffirmed the traceability rule enforcement date in a stakeholder call and pointed processors to the Critical Tracking Events and Key Data Elements tables.</p><p><strong>What it means: </strong>Two years sounds long. It is one budget cycle and one ERP change. The records you capture from the first lot forward are the ones that count.</p><h2>Standards and schemes</h2><p><strong>BRCGS clarifies expectations on environmental monitoring trend review.</strong> A BRCGS position brief clarified that Issue 9 sites are expected to show documented trend review with follow-up actions, not just result logs.</p><p><strong>What it means: </strong>A folder of passing swabs is data. A dated review that asks why zone 2 drifted in March is a program.</p>]]></content:encoded>
  </item>
  <item>
    <title>The Brief: Week of August 17, 2026</title>
    <link>https://devbox.tail10a27d.ts.net/insights/the-brief-week-of-august-17-2026</link>
    <guid isPermaLink="true">https://devbox.tail10a27d.ts.net/insights/the-brief-week-of-august-17-2026</guid>
    <pubDate>Fri, 21 Aug 2026 16:27:52 +0000</pubDate>
    <category>The Brief</category>
    <author>Jeffrey Strout</author>
    <description>Metal in snack products, the FSIS Salmonella framework moves, and GFSI puts culture in the benchmark.</description>
    <content:encoded><![CDATA[<p>Foreign material leads this week, and both regulators and scheme owners keep converging on the same theme: show the system working, not the paperwork existing.</p><h2>Recalls and alerts</h2><p><strong>Snack producer recalls two SKUs for metal fragments.</strong> Consumer complaints, then an X-ray audit, traced fragments to a fractured sieve upstream of the detector, with detector logs showing passing test pieces all week.</p><p><strong>What it means: </strong>A passing metal detector proves the detector works. It says nothing about equipment integrity upstream. Sieve and screen checks belong on the same schedule.</p><h2>FDA and USDA</h2><p><strong>FSIS advances its Salmonella framework for poultry.</strong> The agency moved another step toward final product standards keyed to serotype and level, rather than presence alone.</p><p><strong>What it means: </strong>If you buy or further-process poultry, your supplier specifications will need to speak this language within a year or two.</p><h2>Standards and schemes</h2><p><strong>GFSI benchmarking now expects a culture program with evidence.</strong> The updated benchmarking requirements ask certification programs to verify sites can show a working food safety culture plan, with measurement.</p><p><strong>What it means: </strong>Every scheme under GFSI inherits this. A slide deck from 2024 is not a culture program; a plan with a baseline, actions, and a re-measure is.</p>]]></content:encoded>
  </item>
  <item>
    <title>Can an LLM Draft a Usable CAPA? We Measured It</title>
    <link>https://devbox.tail10a27d.ts.net/insights/can-an-llm-draft-a-usable-capa-we-measured-it</link>
    <guid isPermaLink="true">https://devbox.tail10a27d.ts.net/insights/can-an-llm-draft-a-usable-capa-we-measured-it</guid>
    <pubDate>Wed, 19 Aug 2026 16:27:55 +0000</pubDate>
    <category>Research</category>
    <author>Steven Moussawer</author>
    <description>We scored 240 AI-drafted corrective actions against what our QA team actually shipped. Where the drafts held up, where they failed, and why the failures cluster.</description>
    <content:encoded><![CDATA[<p>Every food safety software vendor now claims AI can draft your corrective actions. We wanted a number instead of a claim, so we ran one: 240 deviation records from our own certified facility, each drafted by the model, each scored against the version our QA team ultimately approved.</p><h2>How we scored it</h2><p>Each draft was graded on four axes: root cause plausibility, corrective action specificity, regulatory grounding, and whether the effectiveness check would actually detect recurrence. A draft passed only if a QA manager could sign it with edits taking under five minutes.</p><h2>What we found</h2><ul><li><p>Roughly three quarters of drafts passed the five-minute bar on routine deviations: monitoring misses, documentation gaps, single-point equipment failures</p></li><li><p>Drafts failed hardest on root cause, defaulting to retraining when the honest answer was a design or scheduling problem</p></li><li><p>Effectiveness checks were the weakest section: the model proposes verification that confirms the action happened, not that it worked</p></li><li><p>Regulatory citations were accurate when the source requirement was in context, and confidently wrong when it was not</p></li></ul><h2>The &quot;retrain the operator&quot; reflex</h2><p>The most instructive failure mode: when the record did not contain enough to find a root cause, the model filled the gap with the industry&#039;s own worst habit, blaming the person and prescribing training. It learned that from us. The fix is structural: the draft has to be grounded in the deviation record, the equipment history, and the schedule, and when the ground is thin, it should say so instead of guessing.</p><h2>What this means for review</h2><p>The human is not there to fix grammar. The reviewer&#039;s real job is the two sections the model is worst at: interrogating the root cause and demanding an effectiveness check that would actually catch recurrence. A review process that knows where the failures cluster reviews five times faster than one that reads every word with equal suspicion.</p>]]></content:encoded>
  </item>
  <item>
    <title>The Brief: Week of August 10, 2026</title>
    <link>https://devbox.tail10a27d.ts.net/insights/the-brief-week-of-august-10-2026</link>
    <guid isPermaLink="true">https://devbox.tail10a27d.ts.net/insights/the-brief-week-of-august-10-2026</guid>
    <pubDate>Fri, 14 Aug 2026 16:27:52 +0000</pubDate>
    <category>The Brief</category>
    <author>Jeffrey Strout</author>
    <description>A leafy greens traceback, FDA reorganization lands on inspections, and Edition 10 scoring math worth memorizing.</description>
    <content:encoded><![CDATA[<p>A produce traceback with a lesson for every processor, and the scoring change that will decide more Edition 10 audit outcomes than any new clause.</p><h2>Recalls and alerts</h2><p><strong>Leafy greens traceback closes in under two weeks.</strong> A multistate E. coli cluster was traced to a single harvest window in days rather than months, credited to lot-level records at the processor and distributor.</p><p><strong>What it means: </strong>Speed came from records that already existed. That is the whole FSMA 204 argument in one outbreak.</p><h2>FDA and USDA</h2><p><strong>Human foods program reorganization reaches the field.</strong> FDA continued shifting inspection resources under the unified human foods program, with risk-prioritized assignments replacing some routine coverage.</p><p><strong>What it means: </strong>Fewer routine visits, more targeted ones. The facilities that get attention will be the ones whose history, category, or complaints earn it.</p><h2>Standards and schemes</h2><p><strong>Edition 10 core-clause scoring: a Core Minor costs 2, a Core Major costs 7.</strong> SQFI&#039;s updated scoring weights findings against core clauses harder than the same finding elsewhere in the Code.</p><p><strong>What it means: </strong>Two core majors and a scattering of minors can now move a rating. Know which of your clauses are core and treat findings there as rating risks, not paperwork.</p>]]></content:encoded>
  </item>
  <item>
    <title>SQF Edition 10: What Actually Changes and How to Get Ready</title>
    <link>https://devbox.tail10a27d.ts.net/insights/sqf-edition-10-what-actually-changes-and-how-to-get-ready</link>
    <guid isPermaLink="true">https://devbox.tail10a27d.ts.net/insights/sqf-edition-10-what-actually-changes-and-how-to-get-ready</guid>
    <pubDate>Sun, 09 Aug 2026 16:27:53 +0000</pubDate>
    <category>Guides</category>
    <author>Jeffrey Strout</author>
    <description>Edition 10 is a structural update, not a refresh. The five changes that take real work, in the order to start them, from a former SQF auditor.</description>
    <content:encoded><![CDATA[<p>SQF Edition 10 was published March 2, 2026, and audits against it begin January 2, 2027. That gives every certified site one certification cycle to close the gap. This guide covers the five changes that take real work and the order to start them, based on what early transitions are teaching us.</p><h2>The five changes that matter</h2><ul><li><p>Food safety culture becomes explicit and auditable, with a plan, a baseline measure, and evidence of action</p></li><li><p>Environmental monitoring moves to risk-based, hazard-justified sampling with documented trend review</p></li><li><p>Change management gets a dedicated clause: significant changes need impact assessment and verification</p></li><li><p>Core-clause scoring hits harder: a Core Minor deducts 2 points, a Core Major deducts 7</p></li><li><p>Cybersecurity enters the food defense plan for connected systems that touch food safety</p></li></ul><h2>Start with culture, because you cannot backfill it</h2><p>Every other change on the list can be documented in weeks once you decide to do it. Culture cannot. The clause expects a baseline, visible leadership behavior, and a re-measure showing movement. That cycle takes two to three quarters at minimum. If your recertification lands in the first half of 2027, the baseline survey should be running this quarter.</p><h2>Rework the environmental monitoring justification</h2><p>Most existing EMPs were built from a template and inherited their sampling sites from whoever set them up. Edition 10 asks a harder question: why these sites, why these organisms, why this frequency. Write the hazard justification down, then check that your trend review is a documented act with follow-up actions, not a spreadsheet nobody reads.</p><h2>Put change management on paper</h2><p>You already assess changes; you do it in meetings and email threads. The new clause asks for a record: what changed, who assessed the food safety impact, what verification confirmed the assessment. One form and one routing rule cover it. Build it now and run a few real changes through it so the record exists before the auditor asks.</p><h2>Learn the scoring math</h2><p>Know which of your clauses are core. A finding there is worth triple or more against your rating. When you run your internal audit, score it the Edition 10 way and see where the rating lands. That number, not the clause list, is what tells you whether you are ready.</p><blockquote><p>The sites that struggle with Edition 10 will not be the ones with weak documents. They will be the ones that started the culture work six months too late.</p></blockquote>]]></content:encoded>
  </item>
  <item>
    <title>The Brief: Week of August 3, 2026</title>
    <link>https://devbox.tail10a27d.ts.net/insights/the-brief-week-of-august-3-2026</link>
    <guid isPermaLink="true">https://devbox.tail10a27d.ts.net/insights/the-brief-week-of-august-3-2026</guid>
    <pubDate>Fri, 07 Aug 2026 16:27:52 +0000</pubDate>
    <category>The Brief</category>
    <author>Jeffrey Strout</author>
    <description>Listeria sampling in frozen vegetables, sesame enforcement matures, and the culture clause needs the longest runway.</description>
    <content:encoded><![CDATA[<p>A sampling assignment worth reading as a preview of your category&#039;s next year, and a reminder that the softest-sounding Edition 10 clause is the hardest one to backfill.</p><h2>Recalls and alerts</h2><p><strong>FDA sampling assignment targets frozen vegetables.</strong> A new assignment has investigators collecting frozen vegetable samples for Listeria across processors and cold storage, following patterns from earlier assignments in other categories.</p><p><strong>What it means: </strong>Sampling assignments become recall clusters. If you are in the category, act like your lot is the one that gets pulled: verify your environmental program and your hold-and-release logic now.</p><h2>FDA and USDA</h2><p><strong>Sesame enforcement moves past the grace period.</strong> Warning letters now treat sesame like the other major allergens, including in shared-line cross-contact findings, not just labeling.</p><p><strong>What it means: </strong>If sesame entered your building after 2023 and your allergen map was not redrawn, that map is wrong.</p><h2>Standards and schemes</h2><p><strong>The culture clause has the longest lead time in Edition 10.</strong> Practitioners working early transitions report that culture plans need a baseline measure, visible leadership actions, and a re-measure to satisfy the clause, a cycle that takes quarters, not weeks.</p><p><strong>What it means: </strong>You can write a change management SOP in a month. You cannot backfill a year of culture evidence in one. Start with the baseline survey.</p>]]></content:encoded>
  </item>
  <item>
    <title>What 7,500 Audits Taught Me About the First Ten Minutes</title>
    <link>https://devbox.tail10a27d.ts.net/insights/what-7500-audits-taught-me-about-the-first-ten-minutes</link>
    <guid isPermaLink="true">https://devbox.tail10a27d.ts.net/insights/what-7500-audits-taught-me-about-the-first-ten-minutes</guid>
    <pubDate>Tue, 04 Aug 2026 16:27:56 +0000</pubDate>
    <category>Field Notes</category>
    <author>Jeffrey Strout</author>
    <description>By the time the opening meeting ends, an experienced auditor has usually formed the hypothesis the rest of the audit will test. Here is what those first minutes are actually measuring.</description>
    <content:encoded><![CDATA[<p>After several decades and more than seven thousand audits, I will tell you a trade secret that is not really a secret: the audit starts in the parking lot, and the first ten minutes usually write the hypothesis the next two days test. Not the score. The hypothesis.</p><h2>What those minutes actually measure</h2><p>Not cleanliness, exactly. Coherence. Does the person who signs me in know the visitor procedure or improvise it? When I ask for the HACCP plan, does someone walk to it, or does a search party form? Does the QA manager answer the first question, or do they answer every question including the ones I asked the sanitation lead? Each of those is a tiny read on the same variable: does this program run daily, or was it assembled for me.</p><h2>The tell I trust most</h2><p>I ask an operator what happens when a check fails. A facility with a working program gets me an answer in one breath: stop, hold, call, tag. A facility with a paper program gets me a glance toward the supervisor. The operator is not failing in that moment; the system is, because the system never made the answer automatic.</p><h2>You cannot stage it, and that is the good news</h2><p>Facilities try to manage the first impression with fresh paint and a rehearsed opening meeting, and experienced auditors discount both automatically. The only way to pass the first ten minutes is to run a real program for the year before the audit, which happens to be the only way to pass the next two days too. Everything I have ever taught about audit preparation reduces to that sentence.</p>]]></content:encoded>
  </item>
  <item>
    <title>The Brief: Week of July 27, 2026</title>
    <link>https://devbox.tail10a27d.ts.net/insights/the-brief-week-of-july-27-2026</link>
    <guid isPermaLink="true">https://devbox.tail10a27d.ts.net/insights/the-brief-week-of-july-27-2026</guid>
    <pubDate>Fri, 31 Jul 2026 16:27:53 +0000</pubDate>
    <category>The Brief</category>
    <author>Jeffrey Strout</author>
    <description>Ethylene oxide in imported spice, remote regulatory assessments continue, and change management gets a clause of its own.</description>
    <content:encoded><![CDATA[<p>Supply chain week: an import alert with a familiar shape, and a look at the Edition 10 clause most facilities already half-run without documenting.</p><h2>Recalls and alerts</h2><p><strong>Imported spice flagged for ethylene oxide residue.</strong> An import alert added several spice shippers after residue findings, echoing the European EtO recalls of recent years.</p><p><strong>What it means: </strong>If your supplier approval for imported ingredients rests on a COA that does not test for EtO, the COA is answering a question nobody asked.</p><h2>FDA and USDA</h2><p><strong>Remote regulatory assessments stay in the toolkit.</strong> FDA continued scheduling remote assessments for records review ahead of, and sometimes instead of, on-site inspection time.</p><p><strong>What it means: </strong>A remote assessment is a records audit with no walkthrough to soften it. Your documents carry the whole impression.</p><h2>Standards and schemes</h2><p><strong>Change management becomes a formal Edition 10 clause.</strong> Significant changes, new lines, new products, new suppliers, reformulations, will need documented impact assessment and verification under the new clause.</p><p><strong>What it means: </strong>Most facilities already do this in emails and meetings. The clause just asks for the paper trail. Build the form now and the clause costs you nothing on audit day.</p>]]></content:encoded>
  </item>
  <item>
    <title>Building a HACCP Plan That Survives an Audit</title>
    <link>https://devbox.tail10a27d.ts.net/insights/building-a-haccp-plan-that-survives-an-audit</link>
    <guid isPermaLink="true">https://devbox.tail10a27d.ts.net/insights/building-a-haccp-plan-that-survives-an-audit</guid>
    <pubDate>Sat, 25 Jul 2026 16:27:53 +0000</pubDate>
    <category>Guides</category>
    <author>Steven Moussawer</author>
    <description>The difference between a HACCP plan that passes review and one that runs the floor: hazard analysis you can defend, CCPs you can justify, and records that match reality.</description>
    <content:encoded><![CDATA[<p>Most HACCP plans fail audits for the same handful of reasons, and none of them are exotic. The hazard analysis does not match the process as it actually runs. A CCP exists because a template said so, not because the hazard analysis demands it. Monitoring records show perfect compliance that the floor cannot reproduce. This guide walks the build in the order that avoids those failures.</p><h2>Walk the process before you chart it</h2><p>The flow diagram is the foundation everything else stands on, and it is wrong at most facilities. Rework, returns, water, air, and people movement are the usual missing flows. Walk the line at running speed with the diagram in hand and mark every difference. An auditor will do exactly this on day one, and every gap they find discredits the hazard analysis behind it.</p><h2>Do the hazard analysis honestly</h2><p>For each step, ask what can reasonably occur, at what likelihood, with what severity, and write down the reasoning, not just the conclusion. The reasoning is what the auditor reads. A hazard analysis that says &quot;not significant&quot; without saying why is an opinion, not an analysis.</p><h2>Fewer CCPs, defended better</h2><p>A CCP you cannot lose control of is not a CCP, it is a prerequisite program doing its job. Every CCP you carry costs monitoring, verification, validation, and training forever. Carry the ones the hazard analysis genuinely requires, and put the rest where they belong.</p><h2>Set critical limits you can measure at line speed</h2><p>A limit nobody can measure during production becomes a limit nobody measures. If the real check happens in the QA lab an hour later, your monitoring is verification wearing the wrong name, and the deviation you catch is an hour of product deep.</p><h2>Make the records tell the truth</h2><p>Perfect logs are a finding in themselves. Real operations have deviations, and a plan with no recorded deviations in a year tells the auditor the monitoring is theater. What they want to see is a deviation, the corrective action it opened, and the verification that closed it. That chain is the plan working.</p>]]></content:encoded>
  </item>
  <item>
    <title>What an AI Evidence Trail Has to Look Like Before an Auditor Sees It</title>
    <link>https://devbox.tail10a27d.ts.net/insights/what-an-ai-evidence-trail-has-to-look-like-before-an-auditor-sees-it</link>
    <guid isPermaLink="true">https://devbox.tail10a27d.ts.net/insights/what-an-ai-evidence-trail-has-to-look-like-before-an-auditor-sees-it</guid>
    <pubDate>Mon, 20 Jul 2026 16:27:55 +0000</pubDate>
    <category>Research</category>
    <author>Steven Moussawer</author>
    <description>If AI touches a food safety record, the first question on audit day is &quot;who approved this and what did they see?&quot; The evidence structure that answers it, from a facility that runs one.</description>
    <content:encoded><![CDATA[<p>There is no AI clause in SQF Edition 10 or in FSMA. There does not need to be. The existing rules already decide the question: records must be accurate, attributable, and verified by someone competent. If AI drafted the record, those requirements land on the evidence around the draft. We run AI inside a certified facility, so we had to answer this before it was a blog topic.</p><h2>The four things the trail must hold</h2><ul><li><p>What the model saw: the records, documents, and requirements in context when it drafted</p></li><li><p>What it produced: the draft as generated, before any human touched it</p></li><li><p>What the human did: the diff between draft and approved version, and who approved</p></li><li><p>When and under what version: model, prompt, and configuration, timestamped</p></li></ul><h2>The draft is not the record</h2><p>The load-bearing design decision: the AI output is an input to a human decision, and the record the program stands on is the approved version with a named approver. The trail exists so that the approval is inspectable, not so the machine can take responsibility. Machines cannot hold responsibility in a food safety program; name-and-date can.</p><h2>Append-only or it does not count</h2><p>An evidence trail someone can edit after the fact is a liability with extra steps. Ours is append-only: corrections are new entries pointing at what they correct, the way a good lab notebook works. When we handed the structure to an auditor familiar with electronic records, their questions took about ten minutes, because every answer was a lookup, not an explanation.</p><h2>What we would tell a facility evaluating AI tools</h2><p>Ask one question first: show me the record of what the model saw, what it wrote, and who approved it. If the vendor cannot produce that in under a minute, the feature is a demo, not a program tool. Everything else, accuracy included, is negotiable by comparison, because a wrong draft with a real review trail is a caught error, and a right draft with no trail is an unverifiable record.</p>]]></content:encoded>
  </item>
  <item>
    <title>FSMA 204 Traceability: The Records You Need Before July 2028</title>
    <link>https://devbox.tail10a27d.ts.net/insights/fsma-204-traceability-the-records-you-need-before-july-2028</link>
    <guid isPermaLink="true">https://devbox.tail10a27d.ts.net/insights/fsma-204-traceability-the-records-you-need-before-july-2028</guid>
    <pubDate>Fri, 10 Jul 2026 16:27:54 +0000</pubDate>
    <category>Guides</category>
    <author>Jeffrey Strout</author>
    <description>Enforcement is set for July 20, 2028. The Critical Tracking Events, the Key Data Elements, and why the records you capture from the first lot forward are the ones that count.</description>
    <content:encoded><![CDATA[<p>FSMA 204 enforcement is set for July 20, 2028. If your products or ingredients are on the Food Traceability List, you will need to capture and keep specific records at specific points in your process, and produce them to FDA within 24 hours of a request. The rule is less complicated than its reputation, but it punishes late starts, because the records only exist if you were capturing them when the lot moved.</p><h2>First, find out if you are covered</h2><p>Check the Food Traceability List for your products and your ingredients. Coverage follows the food, and a covered ingredient inside your product can pull your process into scope. Many processors are covered by what they receive, not what they ship.</p><h2>The events that must leave a record</h2><ul><li><p>Receiving: what arrived, from whom, and the traceability lot code it carried</p></li><li><p>Transformation: what you made, from which input lots, under which new lot code</p></li><li><p>Shipping: what left, to whom, under which lot code</p></li></ul><p>Each event carries its Key Data Elements: lot codes, dates, locations, and quantities. The linchpin is the traceability lot code staying connected through transformation, because that link is exactly what a traceback follows.</p><h2>The 24-hour test</h2><p>The practical standard is simple to state: given a lot code, can you produce everything it touched, in both directions, within 24 hours, in a sortable electronic format. If the answer involves a person, a filing cabinet, and a weekend, you have your gap. Run the drill once and the gap names itself.</p><h2>Why the smart money starts now</h2><p>Records are not retroactive. The traceability chain you can produce in 2028 is built from what you captured in 2026 and 2027. Retailers are already asking suppliers for FSMA 204 readiness ahead of the deadline, which means the real enforcement date for many facilities is whenever their biggest customer asks.</p>]]></content:encoded>
  </item>
  <item>
    <title>The Week Before the Audit: A Prep Sequence That Actually Happens</title>
    <link>https://devbox.tail10a27d.ts.net/insights/the-week-before-the-audit-a-prep-sequence-that-actually-happens</link>
    <guid isPermaLink="true">https://devbox.tail10a27d.ts.net/insights/the-week-before-the-audit-a-prep-sequence-that-actually-happens</guid>
    <pubDate>Tue, 30 Jun 2026 16:27:56 +0000</pubDate>
    <category>Field Notes</category>
    <author>Steven Moussawer</author>
    <description>Not the 40-item checklist from a consultant deck. The five things we actually do in the last week, in order, because they are the ones that change the outcome.</description>
    <content:encoded><![CDATA[<p>Audit prep advice comes in two flavors: the year-round program you should be running, and the 40-item final checklist nobody has ever completed. This is the third flavor: what a working facility with production to run actually does in the last week, in the order that pays.</p><h2>Monday: sample your own records like an auditor</h2><p>Pick three lots at random and pull everything they touched. Not to fix anything, backdating is how minor findings become certificate-level ones, but to know where your gaps are before someone else finds them. An honest gap you can explain beats a perfect record you cannot.</p><h2>Tuesday: walk the floor at the auditor&#039;s pace</h2><p>Slowly, upstream to downstream, looking at what is actually true: torn door sweeps, a hose on the floor, the allergen cart parked in the wrong zone. Fix what can be fixed in a day, log what cannot as a finding with an owner, because an auditor respects an open corrective action far more than a fresh coat of paint.</p><h2>Wednesday: close the loop on your own findings</h2><p>The record that gets read hardest is your internal audit and whatever it opened. Every finding should be closed with evidence or open with an owner and a date. The worst answer on audit day is a finding from last year with no story attached.</p><h2>Thursday: brief the people who will be asked</h2><p>Ten minutes per shift, three messages: answer what you know, say &quot;I would check the SOP&quot; when you do not, and know your stop-and-hold. Nobody gets scripted. Scripts collapse under the second follow-up question anyway; confidence in the real procedure does not.</p><h2>Friday: stage the paper, then stop</h2><p>Certificates current, document list printed, a room for the auditor with the records they always ask for first. Then go home. The audit was decided over the last year, and the last-minute all-nighter has never once changed a rating, though it has produced plenty of exhausted QA managers answering opening-meeting questions on four hours of sleep.</p>]]></content:encoded>
  </item>
  <item>
    <title>Environmental Monitoring: Zones, Sampling, and the Trend Review That Counts</title>
    <link>https://devbox.tail10a27d.ts.net/insights/environmental-monitoring-zones-sampling-and-the-trend-review-that-counts</link>
    <guid isPermaLink="true">https://devbox.tail10a27d.ts.net/insights/environmental-monitoring-zones-sampling-and-the-trend-review-that-counts</guid>
    <pubDate>Thu, 25 Jun 2026 16:27:54 +0000</pubDate>
    <category>Guides</category>
    <author>Jeffrey Strout</author>
    <description>An EMP that finds nothing is not a clean facility, it is a program that is not looking. Zoning, site selection, and the review cycle that turns results into a defense.</description>
    <content:encoded><![CDATA[<p>The purpose of an environmental monitoring program is to find the organism before it finds the product. That sentence decides every design question that follows. A program built to produce passing results is answering the wrong question, and both auditors and FDA investigators have learned to spot one.</p><h2>Zones, briefly</h2><p>Zone 1 is product contact. Zone 2 is adjacent to product contact: frames, panels, drip shields. Zone 3 is the room: drains, floors, wheels. Zone 4 is outside the processing area. Most programs under-sample zones 2 and 3, which is exactly where a resident organism lives while it waits for a reason to move.</p><h2>Pick sites the hazard justifies</h2><p>Edition 10 and BRCGS Issue 9 both now expect the sampling plan to trace back to a hazard rationale: why these sites, why these organisms, why this frequency. Wet processing, drains, harborage points, and traffic paths belong on the map because the organism&#039;s ecology puts them there, not because the template had ten blank rows.</p><h2>A positive is the program working</h2><p>The response to a zone 2 or 3 positive is where programs earn their keep: expanded vector swabbing, corrective action on the site, and a documented return to baseline. A program with years of unbroken negatives in a wet facility does not read as clean. It reads as a program designed not to find.</p><h2>The trend review is the record that defends you</h2><p>Individual results age out fast. The trend is what shows a drift in zone 2 in March, the deep clean in April, and the recovery by May. Put the review on a calendar, name an owner, record the questions asked and the actions taken. When an auditor or an investigator asks what you did about a pattern, that review is the answer, and it only exists if you wrote it down.</p>]]></content:encoded>
  </item>
  <item>
    <title>Where AI Fails at Document Review: Failure Modes From a Year of SOP Conflict Checks</title>
    <link>https://devbox.tail10a27d.ts.net/insights/where-ai-fails-at-document-review-failure-modes-from-a-year-of-sop-conflict-checks</link>
    <guid isPermaLink="true">https://devbox.tail10a27d.ts.net/insights/where-ai-fails-at-document-review-failure-modes-from-a-year-of-sop-conflict-checks</guid>
    <pubDate>Mon, 15 Jun 2026 16:27:55 +0000</pubDate>
    <category>Research</category>
    <author>Steven Moussawer</author>
    <description>We let AI cross-check SOPs against each other and against the standard for a year. It catches conflicts humans miss, and it misses conflicts in ways worth knowing before you rely on it.</description>
    <content:encoded><![CDATA[<p>Document conflicts are the quiet audit finding: the sanitation SOP says one concentration, the master cleaning schedule says another, and both were approved by people acting in good faith two revisions apart. This is exactly the cross-referencing work humans are worst at and machines should be best at. After a year of running AI conflict checks across our controlled documents, here is the honest scorecard.</p><h2>Where it beats human review outright</h2><p>Exhaustiveness. The model compares every document against every other document every time, which no human reviewer has ever done in the history of document control. Numeric mismatches, contradictory responsibilities, and orphaned references to retired procedures surface reliably, including conflicts that had survived multiple annual reviews.</p><h2>The three failure modes that matter</h2><ul><li><p>Implication blindness: two procedures that conflict only through their consequences, with no shared vocabulary to match on</p></li><li><p>Authority confusion: flagging a deliberate site-specific deviation from a corporate template as if it were an error</p></li><li><p>Confident scope drift: reviewing a document against a standard edition it was never written to meet</p></li></ul><h2>Design review around the failure modes</h2><p>The pattern across all three: the model is weakest exactly where context lives outside the documents. So we changed what we feed it, edition bindings and deviation registers ride along with the documents, and we changed what reviewers do with the output: a flagged conflict is a finding to verify, and a clean pass on implication-heavy procedure pairs is treated as no information, not as clearance.</p><p>That last sentence is the one we would put on a poster. Knowing where the tool returns no information, and treating its silence there accordingly, is the difference between AI-assisted document control and AI-flavored false confidence.</p>]]></content:encoded>
  </item>
  <item>
    <title>Supplier Approval That Holds Up: COAs, Qualifications, and the Paper Trail</title>
    <link>https://devbox.tail10a27d.ts.net/insights/supplier-approval-that-holds-up-coas-qualifications-and-the-paper-trail</link>
    <guid isPermaLink="true">https://devbox.tail10a27d.ts.net/insights/supplier-approval-that-holds-up-coas-qualifications-and-the-paper-trail</guid>
    <pubDate>Wed, 10 Jun 2026 16:27:54 +0000</pubDate>
    <category>Guides</category>
    <author>Steven Moussawer</author>
    <description>Your product inherits every risk your suppliers ship you. A working approval program: risk-ranking, the documents that matter, and what to actually do with a COA.</description>
    <content:encoded><![CDATA[<p>Every ingredient that crosses your dock brings its supplier&#039;s program with it. The approval file is your evidence that you know what you are inheriting. Here is what a defensible program looks like at a facility that also has production to run.</p><h2>Rank suppliers by what they can do to you</h2><p>An allergen-bearing ingredient from a broker deserves a deeper file than shrink film from a national distributor. Rank by hazard of the material, history of the supplier, and your ability to detect a problem at receiving. The ranking decides the qualification depth, so you spend your effort where the exposure is.</p><h2>The documents that actually matter</h2><ul><li><p>A current GFSI certificate or your own audit, matched to the risk rank</p></li><li><p>Ingredient specifications you have agreed to, not just received</p></li><li><p>Allergen and country-of-origin statements that match the spec</p></li><li><p>A COA arrangement that names the tests, methods, and limits</p></li></ul><h2>A COA you do not verify is a rumor</h2><p>The certificate says what the supplier&#039;s lab found in their sample. Periodically test against it, at a frequency your risk rank sets, and record the comparison. The first time your result disagrees with their certificate is the day the whole program pays for itself.</p><h2>Requalification is where programs go quiet</h2><p>Approval is an event; the audit question is about the ongoing state. Certificates expire, specs drift, and suppliers change processes without telling you. Put expiry dates and review cadences on a calendar with an owner, and let receiving be the tripwire: a COA that stops matching the spec is a requalification trigger, not a filing task.</p>]]></content:encoded>
  </item>
</channel>
</rss>