Blog

2026.09.07

Food Factory Traceability System: RFP and 90-Day Deployment

Food Factory Traceability System: RFP and 90-Day Deployment

A food factory traceability system should not be selected merely because it can scan a barcode or display an attractive genealogy screen. The real test is whether it can reproduce which raw-material and packaging lots entered which process, what output lots resulted, and where those outputs were shipped—including rework, relabelling and network failures. This guide is for food manufacturers in Thailand preparing an RFP. It covers data design, shop-floor controls, ERP/MES/WMS and scale integration, mock recalls, FAT/SAT and a practical 90-day deployment.

Executive decision: select an evidence-producing operation, not a search screen

There are three essential decisions. First, model backward tracing from finished goods to ingredients and packaging, and forward tracing from a received lot to affected inventory and customers, around explicit input-output transformations. Second, test exceptions—label reissue, cancellation, split, merge, carryover, rework and offline recovery—with the same seriousness as routine production. Third, accept the system on quantity reconciliation, permissions, timestamps, correction reasons and interface retries, not search speed alone.

A strong lot management system does more than store data. It helps operators verify the intended material before posting, preserves the history of a correction instead of overwriting it, and produces an explainable scope for a recall decision. An RFP should therefore ask vendors to execute representative scenarios and provide evidence, not simply tick “supported” beside a feature.

1. Define lots, dates, raw materials and packaging separately

The word “lot” is too broad for a design. Distinguish supplier lot, receipt lot, internal stock lot, production batch, filling lot, packaging lot, finished-goods lot and shipment. Define when each identifier is created and how it changes. For expiry or best-before dates, specify whether a source value is inherited, calculated from production date, or reassessed after repacking. Keep master-data rules separate from actual event records.

Packaging is often omitted even though an incorrect allergen statement, language, date print, barcode or film specification may require affected shipments to be identified. Decide by risk whether to track labels, bags, cartons, caps, ink and ribbon. Maximum granularity is not automatically best; the system must balance recall scope with reliable execution.

ObjectMinimum identityMain eventsDesign question
Raw materialItem, supplier lot, receipt lot, dateReceive, inspect, store, issue, consumeHow are split containers and remnants traced?
PackagingItem, artwork version, supplier lotReceive, issue, use, return, scrapHow are obsolete versions blocked?
Work in processBatch, equipment, time window, quantityMix, heat, cool, transfer, holdHow are merge, split and carryover represented?
Finished goodsLot, date, packaging linePack, inspect, hold, release, shipIs genealogy retained after rework or repack?
ShipmentShipment, customer, location, time, quantityAllocate, pick, load, returnHow is 3PL/export data exchanged?

2. Raw-material lot tracking is built on input-output transformation

The core genealogy event records what entered a process and what came out. Inputs may include raw materials, intermediate product, rework and packaging; outputs may include intermediate or finished product, by-product, sample and waste. The model must support many-to-one blending, one-to-many splitting, continuous production, overnight runs, shared piping and reprocessing.

If sugar lots S1 and S2, flavour F7 and intermediate B12 become intermediate B13, a sample and waste, recording only B13 prevents reconciliation. Link actual quantities, unit conversions, scale ID, event time, work order, equipment and operator or device. Planned quantity is a plan; actual quantity is evidence. Do not overwrite one with the other.

Food Factory Traceability System: RFP and 90-Day Deployment - figure 1

In continuous production, a time window alone can make the affected scope too broad or too narrow. Define physical boundary events such as tank change, sanitation completion, pipe routing, line clearance, and first/last conforming unit. If the boundary is uncertain, return a conservative scope and explain why. A consistently executed boundary is often more valuable than a complex algorithm that operators cannot maintain.

3. Build trace scenarios before writing the RFP

Feature-list RFPs invite every vendor to answer “yes.” Create five to ten plant scenarios first, including routine production, blend, split, packaging change, label reissue, return, rework and offline recovery. Each scenario should state starting data, operator actions, expected outcome, prohibited outcome and required evidence.

ScenarioStarting conditionExpected resultProhibited result
Backward traceOne finished lotAll material, packaging, process and inspection linksExpansion to unrelated production for the entire day
Forward traceOne supplier lotAffected WIP, finished goods, stock and customersMissing shipped quantity or consignee
Merge and splitMultiple inputs and outputsAll many-to-many links and reconciliationKeeping only a representative lot
Label reissueReprint for the same containerOld label cancelled; reason and approver retainedTwo simultaneously valid labels
Network lossTerminal temporarily offlineRecovery without duplication and with sync historyLost record, double consumption or silent overwrite

Run these with anonymized plant data, not only a vendor demo database. Inspect exports, APIs, audit logs, errors and retry queues as well as screens. Make the scenarios contractual FAT/SAT items so “delivered” cannot be confused with “operationally accepted.”

4. What a food factory traceability system RFP must contain

Structure the RFP into process, data, devices, integration, non-functional controls, implementation/support and acceptance. Mark each requirement Must, Should or Could. Require the vendor to identify standard capability, configuration, customization or exclusion, together with assumptions, price and schedule. “Possible” without a demonstration path is not a comparable answer.

SectionRequirements to specifyEvidence
ProcessReceipt, inspection, hold, consumption, transformation, pack, ship, returnScenario demo and operation record
DataLot granularity, dates, units, reconciliation, versionsData model and sample output
Shop floorScanner, printer, scale, tablet, glove useTest on actual or equivalent hardware
IntegrationERP/MES/WMS, scale, inspection, 3PLInterface design, retry and deduplication test
Non-functionalAccess, audit, availability, backup, offlineLogs, recovery test and operating procedure
Delivery/supportThai-language support, training, SLA, spares, change controlStaffing, support desk and parts list
AcceptanceFAT/SAT, mock recall, performance, migration, handoverPass criteria and submitted evidence

Clarify data ownership, export format, contract-exit return, API limits, hosting region and retention before quotation. Traceability history is long-lived, so evaluate storage, calls, terminals, labels, printer support and future change—not subscription alone. See our Thailand traceability system cost guide for a wider total-cost framework.

5. Label reissue and cancellation are controls, not print functions

A reissue is not merely printing identical content again. The system must establish one valid identity and retain the old label’s state, reason, requester, approver, time, container, printer and print count. Misprint, damage, quantity split and corrected content require distinct reason codes.

Because a physical label cannot be digitally erased, cancellation must invalidate its identifier and cause a warning or block if scanned again. Risk determines whether destruction or recovery needs dual verification. Reports should identify unusual reprint volume that might indicate misuse or failing hardware. A print history alone does not prevent two labels from moving forward as valid.

6. Offline operation requires consistency, not just “sync later”

Paper capture during Wi-Fi loss may be a necessary contingency, but routine back-entry weakens time, sequence, quantity and accountability. Limit offline-capable locations and define which masters and orders are cached, how identifiers avoid collision, whether stale master data can permit a wrong material, and how conflicts are resolved on reconnection.

Food Factory Traceability System: RFP and 90-Day Deployment - figure 2

One design is to distribute time-limited work orders and masters, then assign every event a device ID and monotonic local number. The server must process repeated receipt idempotently, hold out-of-order events, and retain failures and retries. Conflicts should not be silently overwritten; a supervisor should see the difference and compare it with physical stock.

Test disconnection before scan, after weighing, after label printing and during consumption confirmation. Include reboot, battery loss, clock drift and a second device scanning the same container. Replace the vague claim “works offline” with explicit limits: zero tolerated loss, permitted synchronization delay and the role monitoring unsynchronized events.

7. Permissions and audit: correct without erasing history

Separate permissions by action: receipt, inspection decision, hold release, consumption reversal, label reissue, date change, master change, shipment release and audit-log viewing. Where a small plant cannot achieve full segregation, use secondary approval or daily review for high-risk actions.

An audit log should contain before and after values, reason, actor, approver, server time, device and related lot. Include privileged database or administrator activity. Time synchronization, named accounts, prompt removal of leavers and periodic access review belong in the operating procedure. Electronic-record and retention obligations differ by product, customer, destination and certification, so confirm them with quality and legal owners.

8. Assign the source of truth across ERP, MES, WMS and scales

Integration begins by deciding who owns each fact. ERP may own items, parties, purchase/sales orders and financial inventory; MES or the execution layer may own work orders, consumption-output and equipment times; WMS may own container location, movement and allocation. Actual responsibility varies. Avoid allowing unrestricted correction of the same quantity in several systems.

System/deviceRepresentative dataFailure controlRFP test
ERPItems, parties, orders, receipt/shipment, financial stockUnsent queue and variance reportDuplicate, reversal, day boundary
MESProcess, equipment, inputs, outputs, event timeOrder state and sequence controlBlend, split, rework
WMSContainer, location, movement, allocation, FEFOUnknown-lot quarantineWrong location, date inversion, return
ScaleGross, tare, net, unit, stable flagManual-entry reason and equipment statusLink loss, wrong unit, out-of-range
Label printerTemplate, version, identity, issue stateObsolete-version block and reissue approvalDouble print, cancel, media-out

Scale integration should capture units, precision, stable indication, tare, equipment ID and status—not just digits. The application does not prove calibration; connect it with the equipment-control procedure and determine whether overdue status blocks or warns.

Regardless of API, file or message broker, specify event ID, retry, ordering, time zone, encoding, unit and reversal semantics. GS1 EPCIS can be useful when interoperable visibility events must be exchanged between parties. It is an architectural option, not automatic proof of legal compliance; confirm identifiers, event granularity and partner readiness.

9. Shop-floor mistake prevention matters more than screen count

The terminal should prevent the wrong object from progressing. Define warnings, supervisory override or hard blocks for wrong-order material, expired stock, uninspected/held stock, incomplete allergen changeover, obsolete packaging and duplicate consumption. Hard-blocking everything can provoke workarounds, so design exception reasons and authority carefully.

Validate gloves, condensation, dust, cold rooms, sanitation, lighting, mounting and scan range at the workplace. Label stock, adhesive, print durability, spare printer and ribbon inventory are part of availability. Button size, Thai/English wording and audible or visual confirmation affect training and errors.

10. A mock recall measures a decision, not only query speed

Start timing when a material or finished-product alert is received. Continue through scope identification, stock quarantine, customer/consignee list, quantity reconciliation, responsible approval, communication draft and evidence retention. A seconds-fast query does not establish readiness if supplier data is on paper, the 3PL updates tomorrow, or only one specialist can export the result.

Measure milestones separately: data request, preliminary scope, reconciled quantity, management approval and distributable list. Targets should come from risk, contracts, applicable rules, certifications and plant history—not a universal figure. Our recall traceability design guide explains exercise roles in more detail.

After the exercise, assign owners for missing data, query misunderstanding, outdated contacts, quantity variance, access failure and 3PL delay. Vary later drills with night shift, multiple lots, packaging-origin events or a network outage. FDA tabletop materials are useful evidence of the value of operational testing, independently of whether a plant is in the US rule’s scope.

11. FAT and SAT: prove the same scenario in different environments

FAT verifies configuration, functions, reports, interfaces, access and exceptions at the vendor or preproduction environment. SAT verifies them in the actual plant using real devices, networks, printers, scales, users and migrated data. Passing FAT is not a reason to skip SAT.

GateMain checkEvidenceIf not passed
FAT readinessRequirements trace, test data, environment, versionsVersion list, plan, assumptionsDelay or conditional start
FATNormal/exception, access, interface, performance, reportLogs, screenshots, output, defectsCorrect and retest
SAT readinessHardware, network, master, training, migrationChecklist and backupHold go-live decision
SATOperations, offline, print, reconciliationOperation record, audit log, comparisonRoll back or limit use
Go-liveCritical defects, residual risks, supportApproval and issue ownershipDocument conditional approval

Write a starting condition, action, expected data, response, tolerance, log and judge rather than “works correctly.” Exercise peak scanning, continuous label issuance, genealogy query and interface backlog together. Quantity or measurement tolerances must be approved for the product and process; this article does not propose a universal pass threshold.

12. Days 0–30: define scope, physical flow and data

Observe the plant before configuring software. Confirm products, line, warehouse, parties, destination markets, certifications and recall origins. Walk receipt to shipment and record container changes, remnants, shared tanks, rework, carryover, waste and night-shift variations.

Create a data dictionary for item, lot, date, container, location, state, quantity, unit, event and reason code. Check duplicate masters, conversions, time zone, lot length and label space. Assign process ownership, quality approval, IT/OT, vendor, maintenance and 3PL responsibility in a RACI.

Exit with an approved scope, scenarios, current/future process, dictionary, interface list, risks and acceptance strategy. A screen mock-up is insufficient; agree which event creates evidence.

13. Days 31–60: connect the vertical slice and test exceptions early

Configure and connect one representative line. Build a minimal vertical slice that receives items and orders from ERP and returns receipt, consumption, transformation, packaging and shipment results. Connect scanners, printers and scales near actual operating conditions, with version-controlled templates and permissions.

Test exceptions early: unknown or expired lot, over-consumption, wrong order, reissue, cancellation, network loss, printer failure, wrong scale unit, interface duplicate, reversed order and master change. Track every defect with severity, reproduction, workaround, owner and date.

Exit with core FAT scenarios completed, a disposition for critical defects, migration rehearsal, learning materials, SAT plan and rollback plan. Early super-user participation reveals handling and wait time that specifications miss.

14. Days 61–90: prove on the line and transfer ownership

Use the final period for SAT, limited production, mock recall and stabilization. Create real genealogy with real orders and devices, then reconcile quantity, label state, consignee and audit log. Include shifts and alternates, and execute incident escalation and recovery.

Food Factory Traceability System: RFP and 90-Day Deployment - figure 3

The go-live decision should review residual risks, temporary controls, migration variance, training, spares, restore test and support contacts as well as critical defects. Establish weekly monitoring for unsynchronized records, cancellations, manual entry, inventory differences, missing links, retries and support cases.

Ninety days is not a promise to finish every plant. It is a practical window to prove a limited scope and establish a repeatable deployment standard. Product range, interfaces, data quality and validation obligations may change the duration. See our Thailand traceability implementation examples for phased-rollout considerations.

15. Assumption model: calculate payback without double counting

This is arithmetic for comparing proposals, not a market-price claim or benefit guarantee. Assume THB 3.60 million initial investment for one line. Annual benefits are THB 0.72 million recovered labor capacity, THB 0.48 million avoided scrap/rework, THB 0.30 million avoided expiry/inventory loss, and THB 0.20 million recall-readiness value: total THB 1.70 million. Subtract THB 0.25 million annual incremental OPEX, leaving THB 1.45 million net annual benefit. Simple payback is 3.60 / 1.45 = 2.48 years.

ItemAnnual valueCounting rule
Recovered labor capacityTHB 0.72 millionOnly time reassigned; do not also count output uplift
Avoided scrap/reworkTHB 0.48 millionHistorical quantity × approved cost; no overlap with downtime
Avoided expiry/inventory lossTHB 0.30 millionDisposal/write-down delta; separate from working capital
Recall-readiness valueTHB 0.20 millionAgreed proxy such as drill/investigation time; no exaggerated loss avoidance
Total annual benefitTHB 1.70 million0.72 + 0.48 + 0.30 + 0.20
Incremental annual OPEX–THB 0.25 millionSupport, cloud, supplies and recurrent training
Net annual benefitTHB 1.45 million1.70 – 0.25
Initial investmentTHB 3.60 millionSoftware, devices, interfaces, delivery, training, contingency
Simple payback2.48 years3.60 / 1.45; excludes tax, cost of capital and residual value

Recovered capacity does not automatically mean headcount reduction. If the time supports quality checks or additional volume, count one value, not both. Do not overlap scrap and yield, or downtime and throughput, when they share a cause. Begin recall-readiness valuation with auditable proxies, not the full value of a hypothetical disaster. Finance should add sensitivity, tax, capital cost and multi-year cash flow.

16. Translating standards and regulations into requirements

ISO 22005:2007 sets general principles and basic requirements for designing and implementing traceability in the feed and food chain. ISO’s public page shows it was confirmed in 2022 and remains current. It does not mandate one software product, barcode or universal query-time KPI. Confirm how it applies within your certification and customer scope.

Codex CXG 60-2006 addresses traceability/product tracing as a tool within food inspection and certification systems. In August 2026 a revision draft was at Step 3/4; documents were available for CCFICS28, scheduled for 12–17 October 2026. It must not be described as adopted. Recheck final status and wording at the point of use.

The US FDA Food Traceability Rule establishes additional records for certain foods on the Food Traceability List. FDA states that, consistent with congressional direction, it does not intend to enforce the rule before 20 July 2028. This concerns covered US-market activities; it is not general Thai law. Verify applicability, exemptions and supply-chain role with appropriate US advisers.

In Thailand, assess the Food Act, Ministry of Public Health notifications, product/facility rules and the GMP 420 framework. Thai FDA’s official GMP 420 materials are primary sources for understanding manufacturing, equipment and storage requirements, but should not be paraphrased as a universal mandate for one IT feature set. Confirm current notifications and scope with Thai FDA, qualified advisers, certification bodies and customers.

17. Vendor scorecard

Weight genealogy, exception control, shop-floor fit, integration/operations, delivery capability and total cost. Approve the weighting based on plant risk and score scenario evidence, not vendor declarations.

AreaQuestionEvidence
Genealogy/quantityCan it represent many-to-many, units and waste?Graph, reconciliation, export
ExceptionsHow are reissue, cancellation, rework and offline handled?Audit log, error and approval
Shop-floor fitCan it scan, print and weigh in the real environment?Hardware test and operation time
IntegrationHow are retry, duplicate, ordering and monitoring handled?Logs, queue and variance report
Delivery/supportIs Thai support, training and recovery credible?Staffing, SLA, drill and relevant scope
Cost clarityAre customization, storage, devices, API and updates clear?Five-year TCO, assumptions and exclusions

Food-industry references are useful but customer names and counts do not establish fit. Look for comparable blending/splitting, cold or washdown conditions, language, ERP, 3PL and export requirements. An unproven item should be assigned to PoC, FAT or a contractual gate rather than scored as complete.

18. Common failure patterns

One failure is assuming existing lot numbers automatically create genealogy. Numbers may repeat by year or supplier, disappear after splitting, or omit packaging. Test identity uniqueness and transformation first.

Another is integrating everything synchronously and increasing stoppage risk. Separate checks that must stop the process from results that can queue, then design recovery. A third is adding manual entries until data quality falls. Reuse scans, scales and PLC signals where appropriate and ask people only for decisions and reasons.

Finally, do not treat go-live as completion. Update scenarios and tests for new items, packaging versions, equipment and customer requirements. Include access review, risk-based mock recall, restore testing and interface-retry drills in the operating calendar.

19. FAQ

Can food traceability be achieved with barcodes alone?

Barcodes help identify and capture, but genealogy also requires transformations, state, quantity, location, time, authority, cancellation and interface records. The business control after a scan is the core, whether the carrier is a 2D code, RFID or manual identifier.

Is an ERP enough as the lot management system?

It may be enough if it captures receipt, production and shipment at required granularity with exceptions and shop-floor times. When container, second/minute event, equipment, weighing and label state matter, division with MES/WMS or an execution layer is often more practical.

What is the correct recall traceability completion time?

There is no universal number. Set targets from applicable rules, contracts, certifications, product risk and logistics. Measure preliminary scope, reconciliation, approval and distributable list separately through mock recalls.

How far should raw-material lot tracking go?

Consider receipt identity, supplier lot, inspection/state, storage/split, consumption and all affected WIP, finished stock and shipments. Decide packaging, rework, carryover and by-product scope through risk and applicable requirements.

Does EPCIS adoption establish compliance?

EPCIS is a strong standard for interoperable visibility events, but adoption alone does not guarantee compliance. Confirm required identifiers, data, retention, exchange, access and exception controls.

Conclusion

A food factory traceability system succeeds when input-output transformations, reconciliation, packaging, label reissue/cancellation, offline operation, audit access and external interfaces work under plant conditions. Put representative scenarios and evidence in the RFP; prove functions in FAT, the physical environment in SAT, and organizational decisions in a mock recall. Defining on days 0–30, connecting and challenging exceptions on days 31–60, and proving the line on days 61–90 creates a controlled foundation for wider rollout.

TOMAS TECH can support current-state flow mapping, RFP development, ERP/MES/WMS and scale responsibility design, and a representative-line 90-day validation from the concept stage. Discuss a food-factory traceability plan with us.

Sources