Keystone
by CloudVoro
Guide · Compliance

BRCGS traceability requirements,
explained in plain English.

Clause 3.9 of BRCGS Food Safety BRCGS traceability requirements is short, barely a page, but it is one of the clauses most often cited in non-conformances, because it demands proof, not policy. This guide walks through what the clause actually requires, how it interlocks with the recall and authenticity clauses, and the specific evidence auditors ask to see.

10 min read Updated 2026-07-08By the CloudVoro team

What clause 3.9 actually requires

Clause 3.9 requires the site to be able to trace all raw material product lots (including primary packaging) from their supplier, through all stages of processing and dispatch, to the customer, and vice versa. Both directions, one step up and one step down at minimum, with the internal processing steps fully connected in between.

Three things in the wording catch producers out. First, packaging is included, if your film or labels lot cannot be traced to the batches it wrapped, that is a gap. Second, the trace must pass through processing, which means intermediate stages (silos, brine baths, ageing rooms, rework) must preserve lot identity or document the commingling. Third, the standard requires the system to be tested, not merely described: an annual traceability test achieving full traceability within 4 hours, including a mass balance.

The annual traceability test and the 4-hour rule

The test must take a lot, finished product or raw material, and demonstrate the full chain in both directions, with quantities reconciled. The 4-hour window is measured from nomination of the lot to completed reconciliation. The choice of test lot should vary year to year, and a test that only ever runs the easy product is itself something auditors comment on.

Mass balance is where most tests wobble. The quantity of raw material received must reconcile against the quantity used in production, plus stock, plus waste, plus rework and samples. The standard does not print a universal tolerance figure, your procedure defines one and justifies it, but an unexplained discrepancy is treated as a traceability failure regardless of how fast the trace ran.

Auditor behaviour on the day
Most BRCGS auditors run a live vertical audit: they pick a lot from your warehouse or your dispatch records during the audit and ask you to trace it while they watch. The annual test report proves the system works on a good day; the vertical audit proves it works on a random one. Prepare for both.

The clauses that interlock with 3.9

3.11, Incident management, withdrawal and recall
Your recall procedure must be tested at least annually. Traceability is the engine of that test: you cannot demonstrate recall capability without demonstrating trace capability first.
5.4, Product authenticity, claims and chain of custody
Vulnerability assessments and claim substantiation (e.g. organic, provenance, single-origin) depend on lot-level traceability through the supply chain.
3.5, Supplier approval and raw material acceptance
Goods-in records, supplier lot codes, delivery dates, COAs, are the upstream anchor of every trace. Weak goods-in discipline makes clause 3.9 unfulfillable.
4.7 / rework handling
Wherever rework is used, lot identity must be preserved: which batches contributed to the rework, and which batches the rework went into.

The evidence pack auditors ask for

RecordWhat the auditor checks
Goods-in / intake recordsSupplier lot codes captured for every delivery, including packaging; linked to COAs where relevant
Production / make recordsRaw-material lots consumed per batch; intermediate stages preserve identity
Rework logOrigin batches and destination batches of all rework, with quantities
Dispatch recordsBatch/lot per dispatch line, per customer, with quantities
Annual traceability test reportBoth directions, timed, mass balance closed, corrective actions for gaps
Recall test report (3.11)Decision chain rehearsed, draft notifications, contact lists current

Private-label and customer code traceability

If you supply retailers under their own label, your traceability has an extra hop: the retailer's SKU code and description on the dispatch note is not your internal product code. Clause 3.9 does not mention this explicitly, but the vertical audit exposes it immediately, the auditor picks a retailer dispatch line and asks which production batch it was. If the mapping between customer codes and internal codes lives in someone's head, the trace stalls in front of the auditor.

The fix is a maintained, dated customer–SKU mapping: every customer code linked to the internal product it resolves to, with effective dates so historic dispatches still resolve after a spec change. Keystone maintains this bidirectionally, a trace can start from your code or from the retailer's, which is precisely the situation the vertical audit creates.

Can you pass BRCGS traceability requirements traceability on spreadsheets?

Yes, the standard is system-agnostic, and auditors certify spreadsheet-based sites every week. What the standard is not agnostic about is speed, completeness and evidence. The honest questions are: can anyone other than the author run the trace? Does it complete inside 4 hours with a closed mass balance? Do the goods-in, production, rework and dispatch records connect without manual re-keying? If yes, spreadsheets are compliant. If the annual test keeps finding the same gaps, the spreadsheet is the root cause the corrective action never names.

Producers moving to Keystone typically do so after the second or third audit cycle of the same finding, trace time collapses from hours to under 30 seconds because the chain (supplier delivery → intake → batch → dispatch → customer branch) is one connected record rather than five reconciled files.

Key takeaways
  • Clause 3.9 requires lot-level trace in both directions, including primary packaging and rework.
  • The system must be tested at least annually: full trace with mass balance inside 4 hours.
  • Expect a live vertical audit: an auditor-nominated lot traced while they watch.
  • Private-label supply adds a customer-code hop your records must resolve without a human translator.
  • Spreadsheets can comply, but the 4-hour timed test with closed mass balance is where they get exposed.
Free 5-part email course
Get audit-ready in five short emails.
The 18-point checklist PDF, the 30-second traceability test, what BRCGS auditors actually flag, and how Cashel Blue got audit-ready, one email every few days. No spam, one-click unsubscribe.
GDPR-friendly: we store your email for this course only. Unsubscribe link in every email.

Frequently asked questions

Does BRCGS require software for traceability?
No. The standard is system-agnostic, paper and spreadsheet systems can be certified. It requires results: lot-level trace in both directions, tested annually, achieving full traceability with mass balance within 4 hours.
What is the 4-hour rule in BRCGS traceability?
The annual traceability test is expected to achieve full traceability, including quantity reconciliation (mass balance), within 4 hours of the lot being nominated. Auditors check the timing evidence in your test report.
Is packaging included in BRCGS traceability?
Yes. Clause 3.9 explicitly includes primary packaging: you should be able to identify which packaging lots were used on which production batches.
How does rework affect traceability under BRCGS traceability requirements?
Rework must preserve lot identity in both directions, which batches contributed to the rework and which batches consumed it, with quantities. Untracked rework is one of the most common reasons a mass balance fails to close.
What is a vertical audit in BRCGS?
A live exercise during the audit where the auditor selects a real lot and follows it through your records, goods-in, production, QC, dispatch, while you drive. It tests whether traceability works on demand rather than only in the rehearsed annual test.

See this done in software, on real production data.

Keystone runs the full chain, supplier delivery → batch → dispatch → customer, in under 30 seconds. 20-minute discovery call, no sales pitch.

Compliance & trust

How we keep your
data and your audits safe.

Enterprise-grade controls as standard, encryption, MFA for every user, tenant isolation and immutable audit trails, on EU cloud or your own servers. Privacy queries go to privacy@cloudvoro.com. Sub-processor list at /legal/sub-processors. Full security posture at /site/security.

Live
Hosted in EU / Ireland, or on-premise
Customer data resides on AWS Ireland (eu-west-1) and never leaves the EU. Local on-premise deployment available where policy requires it.
Live
GDPR · Privacy Contact named
Internal Data Protection Lead handles subject access requests. Owner is ADPO Ireland member.
Live
MFA for every user
TOTP multi-factor authentication across all roles, with rate limiting, brute-force lockout and reCAPTCHA bot protection on public forms.
Live
ISO 27001 · aligned controls
Security controls mapped to the ISO/IEC 27001:2022 Annex A framework, access management, encryption, logging, incident response.
Live
NIS2 · supporting evidence
Tenant isolation, MFA and immutable audit trails give customers in NIS2 scope direct supporting evidence for their obligations.
Live
Encryption · at rest & in transit
TLS 1.3 in transit, industry-standard symmetric ciphers at rest, KMS-managed keys.