Blog

2026.08.13

Record Digitization for Audit Response 2026: Time-to-Evidence

Record Digitization for Audit Response 2026: Time-to-Evidence

Ask a plant that has just been written up in a customer audit why it happened, and the answer is almost always the same. “We had the records. We just could not produce them on the spot.” The real driver behind record digitization for audit response is not missing records but slow retrieval. This article uses the time it takes to produce evidence, which we call time-to-evidence, as the measure, and puts numbers on cost and payback using a Tier 2 automotive parts supplier in Thailand as the model. Here is the conclusion up front. If you digitize for audit response alone, you will not earn the investment back.

Record digitization for audits covers three different situations

Requests that begin with “we want to digitize records for audits” usually arrive with three completely different situations mixed together. The required speed, the form the evidence has to take, and the damage caused by failure are all different. Unless you separate them first, the scope of the investment ends up misaligned.

The three are customer audits (2nd party audits), certification audits (3rd party audits), and traceability enquiries triggered by a recall or a field defect. The word “records” is the same in all three, but a customer audit asks whether you can produce them within a few minutes in the meeting room, a certification audit asks whether they have reliably survived for a defined period, and a recall asks whether you can fix the affected scope within a defined time. The unit of speed is different in each case: minutes, years, and hours.

Customer audits (2nd party): can you produce it on the spot?

For Japanese-owned Tier 2 suppliers in Thailand, audits by Tier 1 customers are the most frequent type. Our model plant assumes six of them per year. The total internal workload per audit is 96 hours. That figure is the combined time of the quality assurance department covering advance record collection and cross-checking, handling the audit day itself, and answering the corrective actions afterwards.

What often happens in this setting is the moment when the auditor, standing on the production line, points at a label on an actual part and says: “Please show me the first-article inspection record and the in-process inspection record for this lot number, plus the record of the most recent 4M change.” Consider what follows. The quality engineer walks back to the office, pulls the monthly binder off the shelf, flips through it by date, and hunts for the lot number by eye. The in-process inspection records sit in a separate file in production control, the 4M change notice is in the manufacturing department’s proposal file, and the material mill sheet is in the incoming inspection file in purchasing. Three forms, in three departments, on three different shelves.

The problem is that the auditor is waiting all this time. And while waiting, the auditor does not simply sit idle. Another question starts. Another sample is added. The moment you hear “then show me the same thing for a different lot,” the same search runs all over again. Rather than the records being unavailable, it is the slowness of producing them that invites extra samples, and extra samples invite new findings. This chain is the typical route by which scores drop in a customer audit.

Certification audits (IATF 16949 / FSSC 22000): do you meet the retention period?

What a certification audit tests is not speed but duration and completeness. IATF 16949 clause 7.5.3.2.1 requires certain records to be retained for “the period the product is active for production and service requirements, plus one calendar year” (source). The records covered include production part approvals, tooling records, product and process design records, purchase orders, and contracts.

What is worth noticing here is that this retention period is not written as a fixed number of years. Because you add one calendar year to the period the product is active, meaning the period during which mass production continues and there is an obligation to supply service parts, the effective number of years varies with the life cycle of the vehicle model. If you run on paper binders, reconciling this variable-length retention obligation against physical warehouse space becomes an annual exercise. And the judgement that “this should be old enough to throw away by now” gets made at the shop floor’s discretion, without a documented basis. The most dangerous state in an audit is when that judgement is not documented.

IATF 16949 also requires all QMS processes to be internally audited within the three-year certification cycle (source). The model plant assumes internal audits twice a year at 60 hours each. In addition, IATF keeps its official Sanctioned Interpretations up to date, and the November 2025 version was published in January 2026 (source). Even when the text of the standard does not change, an updated interpretation changes how the point is viewed in an audit.

On the food side, the additional requirements of FSSC 22000 v6 play the same kind of role (source). The internal workload spent on certification audits is set at 160 hours per year in the model plant.

Recalls and field defects: do trace-back and trace-forward actually work?

The third situation is the one with the largest potential damage. When a defect appears in the market or at a customer, what gets tested is tracking in two directions.

Trace-back runs from the problem finished product upstream to the manufacturing conditions, the equipment, the operator, and the material lot. You use it to identify the cause. Trace-forward runs from a suspect material lot or a suspect time window downstream to the finished products that used it and the customers they shipped to. You use it to fix the containment scope.

These two are often confused on the shop floor, but because their purposes differ, so does the speed each one needs. If trace-back is slow, root cause analysis is delayed. If trace-forward is slow, you cannot determine the extent of the exposure, and while it remains undetermined, the only option is to err on the safe side. Erring on the safe side means holding everything suspect and sorting all of it. As we will see later, this “widen the net because the scope is undetermined” decision generates the bulk of the cost.

To give a sense of scale, here is one public statistic. Automotive recalls in Japan in fiscal 2022 totalled 383 notifications covering 4,649,433 vehicles (source). Even as a Tier 2 supplier, your parts sit somewhere inside that population.

Why plants fail audits even though the records exist: the time-to-evidence measure

This is the heart of the article. Most plants that fail an audit or a defect response are not failing to keep records. If anything, Japanese-owned plants in Thailand keep an excessive volume of records, precisely because they have brought the head office forms with them. And they still fail.

“Having a record” and “presenting evidence” are two different things

A record and a piece of evidence are not the same thing. A record is a copy of a fact that occurred in the process. Evidence is a bundle of records assembled into a form that answers a specific question.

An auditor’s question usually takes the form: “Show me that lot number X was controlled as specified.” To answer it you have to bundle five things into one: the inspection records for that lot, the lot numbers of the materials used together with their incoming inspection records, the daily equipment check records, proof that no 4M change occurred in that time window, and the skill certification of the operator on the job. Every one of those records exists. They exist, but they are not bundled. The bundling is done on the spot by a human being, working from memory and instinct.

This is why the “record completeness rate” KPI that many plants measure says nothing at all about their real audit capability. Even if every form is captured without a gap, if bundling takes 45 minutes the audit rating goes down. What you should measure is not the completeness rate but time-to-evidence: the elapsed time from the moment the auditor asks the question to the moment you present a bundle of records shaped like an answer.

Breaking time-to-evidence into four layers

Time-to-evidence is not a single block of work time. It is the sum of four waiting times of different kinds.

First, the time to confirm that the record exists. Second, the time to identify the records that correspond to the target lot. Third, the time to show that those records have not been altered and were not written after the fact. Fourth, the time to compile and present them in a form the auditor can read.

The countermeasures for these four are completely different. The first is a form design problem, the second a key design problem, the third an audit trail problem, and the fourth a searchability and output format problem. Digitization investments usually fail because these four are not separated and the plant simply “hands out tablets for now.” Handing out tablets solves only Layer 1, and from Layer 2 upward it can even make things worse. On paper, records were at least filed in date order; once digitized, without a search key you no longer know where anything is.

The four-layer model of record digitization: existence, identification, trust, presentation

Record Digitization for Audit Response 2026: Time-to-Evidence - figure 1

Let us turn the four items from the previous section into a model you can use for investment decisions. It is a stack built from the bottom up, and investing in an upper layer has little effect while a lower layer is unmet.

LayerQuestionMain meansWhat happens if it is unmet
Layer 4 PresentationCan you produce it in a readable form within the deadline?Search, report output, retention period managementThe auditor is kept waiting, or the deadline is exceeded
Layer 3 TrustCan you say it was not written after the fact?Audit trail, electronic signature, timestamp, access controlThe evidential value is questioned
Layer 2 IdentificationCan you narrow down to the target lot?Join keys covering lot, equipment, material, operator, timeThe records exist but cannot be bundled
Layer 1 ExistenceIs it recorded at all?Form design, data entry practice, trainingMissing entries, records written after the fact

Layer 1 Existence: are the records being captured?

This is the most basic layer. It is a strength of Japanese-owned plants and is usually satisfied. There are, however, two gaps.

One is when the granularity of the record does not match what the deadline side demands. For example, in a plant that records process conditions once per shift, asking to contain by two-hour lot units is physically impossible. If the granularity is one shift, the containment unit is one shift as well. The other gap is records for abnormal conditions. Records under normal conditions have a defined form and are reliably captured, but for the moment equipment stopped, a material was switched mid-run, or relief operators came in, the form itself sometimes does not exist. What audits and recalls ask about is exactly those abnormal conditions.

Layer 2 Identification: do you have join keys (lot, equipment, material, operator, time)?

Of the four layers, this is the one most often overlooked and the one with the greatest effect.

A join key is a shared identifier that lets records written on separate forms be matched mechanically. In practice the minimum set is five: lot number, equipment number, material lot number, operator ID, and time. If all five appear on every form in the same format, you can bundle records as often as you like afterwards. Conversely, if the inspection record carries only the date and the part number while the production daily report carries only the equipment number and the time, then matching the two leaves a human being to reason that “the part running that day must have been on machine number 3.” That inference is exactly what time-to-evidence consists of, and it is also the weak point auditors probe hardest.

There are two reasons this layer tends to collapse in Thai plants. One is that forms are operated in three languages, Thai, Japanese and English, so the same machine gets written three ways as “3号機”, “Machine 3” and “เครื่อง 3”. The other is that lot numbering rules are defined independently by process, so lots in the moulding process and lots in the assembly process belong to different systems. With those two present, the keys exist but cannot be joined.

Note also that 4M change records cannot be separated from join key design. Which of man, machine, material or method changed, and to which lots, from when to when, does that change apply? Only once you can specify that interval can you follow the correlation between a change point and a defect. We cover this in detail in How to design a 4M change management system.

Layer 3 Trust: do you have an audit trail (the ALCOA+ view)?

Once records are digitized, the question “could these have been rewritten later?” always follows. The framework that answers it is ALCOA+.

ALCOA+ consists of nine principles: the five elements of Attributable (you can tell who made the record), Legible, Contemporaneous (recorded at the time), Original and Accurate, plus Complete, Consistent, Enduring and Available (source). On the technical control side, this corresponds to audit trails, electronic signatures, timestamps and access control.

The practical point is that an audit trail cannot be added retroactively. An audit trail is a mechanism that records who changed which value, when, and from what to what, at the same moment as the change, in a form the person making the change cannot erase. If you run for six months and then announce that “we have added the trail function,” you cannot demonstrate contemporaneity for those six months of data. That is why Layer 3 has to be in place from day one of digitization. It is not a function you can bolt on later.

One more point. A shared Excel file does not satisfy this layer. There is no record of who wrote what, saving over the file erases the previous value, and the whole file can be copied. Where a plant says “we have digitized” and the reality is Excel, treat it as satisfying Layer 1 but having zero Layer 3.

Layer 4 Presentation: can you produce it within the deadline (retention and searchability)?

The final layer is an output problem. The trap here is that being able to search is not the same as being able to present.

Even if the system screen can display the relevant data, presentation is not complete until it is in a form you can hand to the auditor. What auditors ask for is usually a fixed format, typically “one PDF sheet per lot” or “a list covering the relevant period.” Whether you decide and freeze this submission format in advance makes a large difference to how long the audit day takes. Showing someone a screen and explaining it verbally is not presentation.

Retention period management belongs to this layer too. The “active period plus one calendar year” that IATF 16949 requires can be configured per product in the system, so that items reaching the limit are raised as deletion candidates. Once that practice is running, the retention decision is taken out of the shop floor’s discretion.

Deadlines differ by standard: four hours, 24 hours, on the spot

The target value for time-to-evidence is not something you set yourself. The applicable standards and customer requirements set it. And this is where a lot of confusion arises, because “numbers a standard explicitly requires” and “numbers that are widely shared industry practice” are mixed together. Get this distinction wrong and you either make an investment you did not need or drop a response you did need.

DeadlineNatureOrigin
On the spot, within minutesCustomer requirement and common practiceHow 2nd party audits are run in practice
4 hoursIndustry practice, not an explicit requirementOriginates from BRCGS, widely shared including FSSC and SQF
24 hoursExplicit regulatory requirementUS FDA FSMA 204
Active period plus one calendar yearExplicit standard requirementIATF 16949 7.5.3.2.1

The four-hour convention for recall exercises

In food plants you sometimes hear that “a mock recall has to be completed within four hours.” Those four hours are not a figure explicitly required by the text of the standard. It is a way of thinking that originated with BRCGS and became established as industry practice widely shared across the sector, including FSSC 22000 and SQF (source).

This does not mean that “it is not an explicit requirement, so you do not have to meet it.” In practice, both auditors and customers look at four hours as a benchmark. However, if you write in an internal target or an investment proposal that “the standard requires this,” you will not be able to explain yourself when asked for the basis. The accurate wording is: “this is industry practice that is widely shared, and we adopt it as our own target value.” Being able to write the explicit requirements of a standard and your own target values separately is itself a sign of maturity in a quality assurance system.

The automotive parts sector has no common explicit figure equivalent to the four hours, but customer quality assurance agreements often state a reporting deadline for containment, which functions in practice as a deadline of the same nature. Start by checking your own agreements.

The FSMA 204 24-hour submission (20 January 2026)

The US FDA’s FSMA 204, known as the Food Traceability Rule, requires records of Critical Tracking Events (CTEs) and Key Data Elements (KDEs) to be maintained for covered foods and to be submittable to the regulator within 24 hours of a request. The compliance date is 20 January 2026 (source).

This is an explicit regulatory requirement. And what deserves attention is that what is required is not “holding the records” but “being able to submit them within 24 hours.” The regulator’s interest has moved from possession of records to speed of submission. That is precisely why this article uses time-to-evidence as its measure. For plants in Thailand shipping food or food contact materials to the United States, or supplying the raw materials for them, the compliance date has already arrived, and checking whether you are in scope is no longer something that can be postponed.

Record retention periods under IATF 16949

As noted above, IATF 16949 clause 7.5.3.2.1 requires certain records to be retained for “the period the product is active for production and service requirements, plus one calendar year.” This is not a speed requirement to produce something on the spot; it is a duration requirement.

That said, a duration requirement becomes an indirect speed requirement. Even if you retain records for lots from years ago, if finding them takes a long time, in the audit room it risks being treated the same as not retaining them at all. The longer the retention period, the stronger the demand on searchability. Searchability is exactly the point at which the cost structures of paper storage and electronic storage reverse.

Requirements on the Thai side (traceability expectations in the 2026 Thai FDA regulation)

Within Thailand, expectations around traceability are rising in connection with the Thai FDA’s new 2026 food registration regulation. Identification methods such as QR codes, Data Matrix and sequence numbers are being discussed (source).

The details, however, are not yet fixed, and as of the time of writing they should not be treated as confirmed requirements. A reasonable practical stance goes as far as leaving room in product design and packaging design to print an identifier. Deciding the print area and the numbering rule in advance costs less than rushing to change packaging once the details are fixed. This applies beyond food; the same thinking works for automotive parts.

A model calculation for a Thai plant: where time-to-evidence is lost

From here we break down time-to-evidence for the model plant set out at the start. The assumptions are a Tier 2 automotive parts supplier in Thailand with 450 employees, monthly output of 240,000 pieces over 24 working days, giving 10,000 pieces per day, running two shifts of 16 hours with a two-hour lot unit, giving 8 lots per day.

The times below are model calculation values, not measured values from any specific plant. The structure of where the time is lost, however, is common to many plants.

Record Digitization for Audit Response 2026: Time-to-Evidence - figure 3
SituationCurrentAfter digitization
Presenting on the spot in a customer audit (inspection records for a specified lot)45 minutes3 minutes
Trace-back (finished product to material lot identification)6 hours20 minutes
Trace-forward (material lot to delivery destination identification)4 hours15 minutes
Fixing the recall scope (against the 4-hour convention)10 hours, deadline exceeded40 minutes
FSMA 204 24-hour submission18 hours2 hours

45 minutes to present on the spot in a customer audit. The breakdown is walking and searching. The audit takes place in a meeting room while the records sit on shelves in the office and on the shop floor. The quality engineer leaves the table, looks for the binder, flips through by date, takes a copy, and returns to the meeting room. The round trip for each form adds up. The 3 minutes after digitization is the time to search, bring the forms for the relevant lot up on screen, and output them in the format decided in advance.

6 hours for trace-back. From the finished product label to the shipping record, from the shipping record to the production date, from the daily production report to the lot and the equipment, and from there to the material receiving ledger and the mill sheet. Along that chain, the department that holds the referenced form changes three times. Every time the department changes, waiting time to catch the responsible person is added. If it happens during the night shift, everything stops until the next morning. What is being lost here is not work time but waiting time between people.

4 hours for trace-forward. This is the work of identifying, from a material lot number, the production lots that consumed it, and then the shipments and destinations those lots went into. It is faster than the reverse direction because the shipping ledger is usually consolidated in one place. However, in plants where the record at the point of material issue contains only the material name and quantity and not the material lot number, this route does not work at all. It is a textbook case of a missing Layer 2 join key.

10 hours to fix the recall scope. Measured against the four-hour convention, the deadline is exceeded. This situation is the heaviest because it requires both trace-back and trace-forward to be completed, and then a judgement on scope on top of that. And when time runs out, the action the shop floor takes is predictable. Widen the scope. That feeds directly into the costs in the next section.

18 hours for the FSMA 204 24-hour submission. It is inside the deadline, but there is no margin. It can easily be exceeded if the request spans a weekend or if one responsible person is absent. Against a 24-hour deadline, 18 hours is not what you would call a controlled state.

What breaking down time-to-evidence reveals is that most of the time lost is not “work” but “searching” and “waiting.” That is why adding people does not shorten it. Adding people raises the degree of parallelism in searching, but it does not reduce the waiting time between departments.

Cost and payback: digitizing for audit response alone does not pay back

This is the core of the article. With the same plant and the same platform, the way you draw the scope of the investment changes the payback period completely. And counter to intuition, the narrower the scope, the slower the payback.

Record Digitization for Audit Response 2026: Time-to-Evidence - figure 2

First, the unit rate assumptions. The hourly rate for quality staff is a monthly salary of 35,000 THB x a factor of 1.2 / 160 hours = 262.5 THB/h. For administrative staff it is a monthly salary of 28,000 THB x a factor of 1.2 / 160 hours = 210.0 THB/h. Workers are 90 THB/h. For sorting unit costs, in-house sorting is 90 / 200 pieces = 0.45 THB per piece, outsourced sorting is 3.55 THB per piece, and we use a 50:50 average of 2.00 THB per piece.

There are six annual benefit items.

#BenefitCalculationAmount (THB/year)
1Audit preparation hours856 total hours (6 customer audits x 96h + 160h certification + 2 internal audits x 60h) x 65% collection and cross-checking x 70% reduction = 389.48h x 262.5102,238.50
2Corrective action on record-related findings(5 findings – 2 findings) x 24h x 262.518,900.00
3Sorting cost for containment6 suspect cases, scope 15,000 pieces down to 1,875 pieces (= 15,000 x 2/16), difference of 13,125 pieces x 2.00 x 6 cases157,500.00
4Avoided emergency air freight6 cases x (50% – 15%) = 2.1 shipments x 95,000199,500.00
58D report preparation(40h – 16h) x 6 cases x 262.537,800.00
6Daily transcription hours2 shifts x 3 people x 1.5h x 24 days x 12 months = 2,592h/year x 75% = 1,944h x 210.0408,240.00
Total924,178.50

Benefit 3 deserves a note on the reasoning. When a suspicion arises, the current practice is to contain back to the most recent point at which good product was confirmed, which inflates the scope to 15,000 pieces. That is more than a full day’s output of 10,000 pieces. If join keys run through the whole process, the containment unit can be narrowed to the lot. A lot is two hours and daily operation is 16 hours, so 15,000 x 2/16 = 1,875 pieces. The difference of 13,125 pieces is the volume that never needed sorting. Multiply that by the average sorting unit cost of 2.00 THB per piece across 6 cases a year and you get 157,500 THB.

Benefit 4 has the same structure. When scope determination is late, shipments cannot be stopped in time and replacement parts have to be sent later by emergency air freight. Assuming the share of the 6 suspect cases that end in air freight falls from 50% to 15%, that is 6 cases x (50% – 15%) = 2.1 shipments, at 95,000 THB each, giving 199,500 THB.

In other words, the containment and air freight benefits arise directly from short time-to-evidence. They are not audit response benefits. Separating the two is what the following comparison of three scopes is about.

Scope A, audit response only (payback 6.87 years)

We are struggling with audits, so let us just do audit response. This is the most natural line of thinking. Audit trail and retention platform at 240,000 THB, join key design limited to the forms shown in audits as a minimum configuration at 180,000 THB, giving an initial total of 420,000 THB. Annual cost is 60,000 THB.

The benefits obtained are benefit 1 (audit preparation hours, 102,238.50) and benefit 2 (corrective action on record-related findings, 18,900.00), a total of 121,138.50 THB. After subtracting the annual cost, the net benefit is 61,138.50 THB. Against the initial 420,000 THB, payback is 6.87 years (82.4 months).

6.87 years is not a number that gets an investment approved. Measured against the internal payback criteria for capital investment used in many plants, this proposal is dropped in the early review stage. And once it is dropped, the conclusion becomes “it is still too early for us to digitize,” and time-to-evidence stays at 45 minutes and 10 hours. This is the most common ending in plants that examine digitization with audit response as the objective.

Why does it not pay back? Because audits are events that occur only a handful of times a year. Six customer audits, two internal audits, plus the certification audit. Event-driven work has a ceiling on how often it occurs, no matter how much you improve its efficiency. The numerator, the benefit, has a ceiling, while the denominator, the platform cost, is carried in full. That is what 6.87 years really represents.

Scope B, adding a narrower containment scope (3.80 years)

To A we add an electronic form platform used on the shop floor with 20 terminals at 450,000 THB, and integration with existing systems at 520,000 THB. The initial cost is 1,390,000 THB and the annual cost is 150,000 THB.

What changes with this? Shop floor records are entered on the spot with join keys attached, and material lots, production lots and delivery destinations become mechanically connected. As a result trace-back and trace-forward are shortened, and the containment scope can be narrowed to the lot unit.

To the benefits of A are added benefit 3 (sorting cost for containment, 157,500.00), benefit 4 (avoided emergency air freight, 199,500.00) and benefit 5 (8D report preparation, 37,800.00), for a total of 515,938.50 THB. The net benefit is 365,938.50 THB. Payback is 3.80 years (45.6 months).

The initial investment has more than tripled, yet the payback period has come down from 6.87 years to 3.80 years. The added investment generates benefits faster than it adds cost.

Scope C, adding the elimination of daily transcription (2.38 years)

To B we add join key extension across all processes at 200,000 THB and training and multilingual adoption at 160,000 THB. The initial cost is 1,750,000 THB and the annual cost is 190,000 THB.

What comes in here is benefit 6, daily transcription hours. Three people on each of two shifts spend 1.5 hours a day re-keying paper records into Excel. Over 24 days and 12 months that is 2,592 hours a year. Cutting that by 75% gives 1,944 hours, and at the administrative staff rate of 210.0 THB per hour that is 408,240 THB.

Benefit 6 is the largest single item of the six. What is more, it has nothing to do with audits or recalls, and it occurs every day. Total benefits reach 924,178.50 THB, the net benefit is 734,178.50 THB, and payback becomes 2.38 years (28.6 months).

ScopeInitial (THB)Annual cost (THB)Annual benefit (THB)Annual net benefit (THB)Payback
A Audit response only420,00060,000121,138.5061,138.506.87 years (82.4 months)
B A plus narrower containment scope1,390,000150,000515,938.50365,938.503.80 years (45.6 months)
C B plus elimination of daily transcription1,750,000190,000924,178.50734,178.502.38 years (28.6 months)

Why a wider scope pays back faster

There are three reasons.

First, platform cost is not proportional to scope. The foundation of audit trails, retention, authentication and access control costs roughly the same whether it is used only for audit forms or across every process. Scope A carries the cost of that foundation on audit events that happen a few times a year. Widening the scope means sharing the same foundation across more of the business.

Second, a join key can be built once and reused indefinitely. The lot, equipment, material, operator and time keys described in Layer 2 work just as well for containment and for eliminating transcription, even if they were built only for audit response. Putting join keys only into “the forms we show in audits,” as Scope A does, means building the most expensive part and then using the fruit of it for a single purpose.

Third, the benefits occur at different frequencies. Audits happen six times for customers and twice internally, plus the certification audit; suspect cases occur 6 times a year. Transcription, by contrast, happens every day on both shifts. The higher the frequency of the activity, the larger the annual benefit from the same improvement rate. That is why the payback period drops a step the moment you bring a high-frequency area into scope.

The practical lesson that follows is clear. Audit response is a valid “motive” for digitization, but it is far too narrow as a “scope.” Let the motive be audits. But draw the investment scope so that the join keys that shorten time-to-evidence run through every process, including daily transcription. Otherwise the audit response investment itself will be shelved because it does not pay back. If you want to break the cost structure down further, see also Traceability system build cost and how to proceed.

What to do in 90 days: start with the join keys

Submitting a Scope C proposal straight away will not get approval. There is an order to follow. In 90 days you can assemble the material the investment decision needs.

Day 1-30, take stock of the join keys

For the first 30 days, do not discuss systems at all. Just take stock of the forms.

There are three things to do. First, list every form referenced in audits and recalls, and collect one physical copy of each. Inspection records, daily production reports, equipment check records, 4M change notices, incoming inspection records, shipping ledgers, training records. Second, fill in a matrix showing, for each form, whether the lot number, equipment number, material lot number, operator ID and time are “written” and whether they are “in the same format.” Third, list the places where the formats do not match.

In Thai plants, this stage almost always surfaces notation inconsistencies across three languages. Cases such as writing the same equipment as “3号機”, “Machine 3” and “เครื่อง 3”. Making the decision here to unify the numbering rule and the notation makes everything downstream dramatically easier. Skip this step and you will end up repeating the same discussion after the system is installed.

These 30 days cost almost nothing. The only cost is quality assurance department hours. And what you get is a map for deciding the scope of the investment.

Day 31-60, measure time-to-evidence and identify the bottleneck

In the next 30 days, measure your own time-to-evidence. Not the model calculation values in this article, but the numbers from your own plant.

The method is simple. Without warning, nominate one past lot number and use a stopwatch to time how long it takes to bundle and present that lot’s inspection records, material lots, equipment, operator and any 4M changes. Do the same for trace-back and trace-forward. In food, run it as a mock recall and see how you stand against the four-hour convention.

What matters is recording “where you waited” while you measure. Time spent searching, time spent waiting for a colleague, time spent walking, time spent making copies. As described in the previous section, what is lost is usually searching and waiting. With that breakdown in hand, you can determine which layer the investment should go into.

These measured values are the strongest material for an investment proposal. Your own measurement result of “it took 45 minutes” carries more weight than any general argument.

Day 61-90, freeze the submission formats and rehearse the audit

In the final 30 days, decide the form of submission. This is the Layer 4 discussion.

The form usually requested in a customer audit, the form required in a certification audit, and the form handed to the customer during a recall. Fix these three output formats as actual templates. A one-sheet-per-lot evidence package, a list covering the relevant period, and an impact scope list by delivery destination. With these formats decided, the requirements definition for the system becomes concrete. Instead of “a system that can do traceability,” you can write “a system that can output this template using this key.”

Then run an audit rehearsal. Have someone from another internal department play the auditor and repeat the same unannounced exercise as in Day 31-60. Simply fixing the formats shortens some of the time even while you are still on paper. What does not get shorter is the area that a system investment should solve.

At the end of the 90 days you are left with three things: a current-state matrix of join keys, measured time-to-evidence values with their breakdown, and frozen submission formats. With those three, you can debate whether to choose Scope A, B or C using your own numbers. If you also want to reorganise how quality data itself is held, An approach to quality data management systems is a useful reference.

Four common failures

Turning paper into PDFs and stopping there. Scanning documents and putting them on a server, and treating that as digitization. In terms of the four-layer model, it satisfies Layer 1 only. The contents of the PDF are images, so they cannot be searched (Layer 2 fails), only the scan time remains, so contemporaneity cannot be shown (Layer 3 fails), and in the end people still hunt by file name and folder structure. Time-to-evidence barely improves. If anything, records that were at least physically filed in date order on paper can get worse once the folder structure becomes disorganised.

Handing out terminals before deciding the join keys. 20 tablets go out to the shop floor and people enter data on them. Entry becomes easier and the shop floor likes it. But while the key format still differs from form to form, the bundling work stays with human beings. Most enquiries that begin with “we digitized but audit response did not get any easier” are this. The order is reversed; the keys should be decided before the terminals go out. Do not skip Day 1-30.

Trying to bolt on the audit trail later. As described in Layer 3, an audit trail cannot be created retroactively. A plan that says “let us start with digitizing the records and do the trail in the next phase” produces a result in which, by the time the next phase arrives, the historical data cannot be used. If budget constraints force a phased rollout, narrow the processes covered rather than cutting the functions. Start with a single process if that is all you can afford, but run it through from Layer 1 to Layer 4. That is what a correct phased rollout looks like.

A collision between retention periods and PDPA deletion requests. With Thailand’s Personal Data Protection Act (PDPA) in mind, some plants remove operator IDs and names from records, or delete them after a set period. But the join keys include the operator ID. Remove the operator and you can no longer cross-check against skill certification, and you cannot answer the audit question of who performed the work. Conversely, if you prioritise the retention period IATF requires and hold personal data for a long time, accountability arises on the PDPA side. This collision can only be resolved through operating rules. In practice, a common design is to record operators by internal ID rather than by name, and to keep only the mapping table to names in a separate table under access control. Unless legal and quality assurance sit in the same room at the design stage, this issue is certain to blow up later.

FAQ

What is record digitization for audit response?

It means moving the records required in audits and defect response from paper and Excel into a mechanism with search and an audit trail. The essence, however, is not replacing the input method. The purpose is to reach a state where you can submit a bundle of records shaped like evidence, within the deadline, in response to a question from an auditor or a regulator. This article calls that elapsed time time-to-evidence and addresses it across four layers: existence, identification, trust and presentation. Simply turning paper into PDFs satisfies only one of those four layers.

What do customer audits look at in traceability?

For a specified lot number, they look at whether you can bundle and present the inspection records, the lot numbers of the materials used together with their incoming inspection records, the equipment check records, whether any 4M change occurred in that time window, and the skill certification of the operator involved. Rather than whether the individual records exist, what is tested is whether you can show mechanically that they all tie to the same lot. In addition, they check whether the record was written at the time (contemporaneity) and whether it has been changed afterwards (audit trail). Taking a long time to present tends to lead to requests for additional samples.

What is the difference between trace-back and trace-forward?

Trace-back runs from the problem finished product upstream to the manufacturing conditions, equipment, operator and material lot, and is used to identify the cause. Trace-forward runs from a suspect material lot or time window downstream to the finished products that used it and their delivery destinations, and is used to fix the containment scope. Because their purposes differ, the speed each needs differs too, and when trace-forward is slow the scope cannot be determined, so you err on the safe side and sort a wider range. In the model calculation in this article, that width of scope generates most of the cost.

How much does record digitization cost?

For the model plant in this article, a Tier 2 automotive parts supplier in Thailand with 450 employees, we calculate three cases depending on the scope of investment. Scope A, audit response only, is 420,000 THB initial and 60,000 THB annual cost. Scope B, which also covers narrowing the containment scope, is 1,390,000 THB initial and 150,000 THB annual cost. Scope C, which also covers eliminating daily transcription, is 1,750,000 THB initial and 190,000 THB annual cost. Payback is 6.87 years, 3.80 years and 2.38 years respectively, becoming shorter as the scope widens.

Are digitized records accepted as formal evidence in an audit?

They are accepted, but there are conditions. They have to satisfy ALCOA+, the nine principles of attributable, legible, contemporaneous, original and accurate, plus complete, consistent, enduring and available. Technically this corresponds to audit trails, electronic signatures, timestamps and access control. The important point is that an audit trail added later does not apply to past data. A shared Excel file, which keeps neither a record of who wrote what nor a change history, does not meet this requirement. Enable the trail from the first day of deployment.

Summary

The cause of failure in audits and recalls is not the absence of records. The records are there. The cause is being unable to assemble them into the form of evidence within the deadline. That is why what you should measure is not the record completeness rate but time-to-evidence.

Time-to-evidence can be broken into four layers: existence, identification, trust and presentation. The most effective one is Layer 2, the join keys of lot, equipment, material, operator and time. Without those in place, however much you invest in the upper layers, the work of bundling records stays with human beings.

Deadlines differ by standard. The “active period plus one calendar year” in IATF 16949 clause 7.5.3.2.1 is an explicit retention requirement, the 24 hours in FSMA 204 is an explicit submission requirement, and the four hours for recall exercises is not an explicit requirement but a widely shared industry practice. Being able to write these distinctions correctly in investment proposals and internal procedures shows the maturity of your system.

Then there is the cost. With audit response alone as the objective, payback is 6.87 years, and the proposal will most likely not be approved. Adding a narrower containment scope brings it to 3.80 years, and adding the elimination of daily transcription brings it to 2.38 years. Platform cost is not proportional to scope, join keys can be built once and reused indefinitely, and benefits are larger for higher-frequency activities. That is why payback gets faster as the investment scope widens. The motive can perfectly well be audits. But if you draw the scope around audits, the investment itself never happens.

Start with 90 days: take stock of the join keys and measure your time-to-evidence. It costs almost nothing.

If you want a starting point for the discussion internally, it is enough to pick one past lot number and time how long it takes to produce the full set of evidence for it. Was it 45 minutes, or three hours? Having that one number makes the discussion about investment scope concrete. TOMAS TECH works with Japanese-owned manufacturers in Thailand on how to measure this time-to-evidence and how to move from join key design through to freezing the submission formats. You are welcome to get in touch while you are still at the review stage and have not decided on any deployment, through our contact page.