Keystone
by CloudVoro
Guide · Compliance

One-up, one-down traceability:
what the law requires, and what it quietly doesn't.

Every food business in the EU is legally required to know where its inputs came from and where its outputs went, one step up, one step down. That sentence hides two traps: the law does not require internal traceability, and one-up-one-down alone will not survive a retailer audit. Here is the full picture, with a worked example.

9 min read Updated 2026-07-08By the CloudVoro team

What Article 18 of EU food safety regulations says

Article 18 of Regulation (EC) No food safety, the General Food Law, requires food business operators to be able to identify any person from whom they have been supplied with a food, a food-producing animal, or any substance intended to be incorporated into a food (one step back), and to identify the businesses to which their products have been supplied (one step forward). This information must be available to the competent authorities on demand.

Article 19 adds the operational teeth: if you have reason to believe food you placed on the market is not safe, you must immediately withdraw it, inform the competent authorities, and, where product may have reached consumers, effectively and accurately inform them and recall it if necessary. In Ireland the competent authority framework runs through the FSAI and its official agencies.

Notice what Article 18 does not require: it does not mandate internal traceability (linking a specific incoming lot to a specific outgoing batch inside your factory), it does not mandate lot-level granularity, and it does not set a time limit. Those obligations arrive from elsewhere, certification standards and customer contracts.

A worked example: one wheel of blue cheese

Take a farmhouse dairy making blue cheese. Tuesday's milk arrives from three farms and is pooled into one silo. Wednesday's make-day consumes that silo into batch B-1042, 214 wheels. Over the following weeks, wheels from B-1042 are dispatched to an Irish multiple (under a private-label code), a UK distributor, and a Dublin cheesemonger.

QuestionOne-up-one-down answerWhat an incident actually needs
A farm reports a residue failure in Tuesday's milkWe received milk from farms X, Y, Z on TuesdayWhich batches used Tuesday's milk, which wheels, which customers received them, how many are still in stock
The multiple queries a private-label SKUWe supplied that customer on those datesWhich internal batch that SKU line resolves to, its full QC record, its milk origin
The FSAI asks who received batch B-1042List of direct customersSame, plus quantities per customer and dates, ideally within hours

The left column is legal compliance. The right column is what your customers, your certifier and, in a real incident, your own survival require. The gap between the two columns is internal traceability: the documented links between intake, silo, batch and dispatch that Article 18 never mentions.

What BRCGS, retailers and export markets add on top

BRCGS (clause 3.9)
Full lot-level traceability through processing, both directions, tested annually with mass balance inside 4 hours, internal traceability made mandatory.
Retailer own-label standards
Typically require recall exercises twice a year, customer-code level trace, and response inside hours. Contractual, and enforced through technical audits.
Export certifications
Third-country requirements (US FSMA foreign supplier verification, Middle East conformity schemes) frequently demand documented lot lineage before shipment clearance.
EU sector rules
Certain sectors carry stricter regimes than food safety, e.g. beef labelling traceability, fishery products (catch area and gear on labels through the SFPA), eggs and sprouts. Check your sector's lex specialis.

The minimum record set that satisfies both law and audit

Goods-in register
Supplier, delivery date, product, supplier lot code, quantity, for every input including packaging. This is your one-step-back evidence.
Production / batch records
Which input lots each batch consumed, with quantities. This is the internal link the law skips and the audit demands.
Dispatch register
Customer, date, product, your lot code, quantity per line. One-step-forward evidence. Business customers only, Article 18 does not require tracing to individual consumers.
Retention
EU guidance commonly points to 5 years as a default retention for traceability records, shorter for highly perishable goods. Your customers may specify longer, keep the strictest applicable.

From legal minimum to operational capability

One-up-one-down is a floor, not a system. The producers who suffer in incidents are rarely missing the legal records, they are missing the connections between them, so answering "which customers got Tuesday's milk" means a person manually walking intake books, make sheets and dispatch folders under pressure.

This is the specific problem Keystone models: every supplier delivery, silo run, batch and dispatch line is one connected chain, so the incident question, either direction, is answered in under 30 seconds with a signed PDF for the authority or customer. The legal one-up-one-down evidence falls out of the same records automatically.

Key takeaways
  • Article 18 of EU Reg food safety requires one step back and one step forward, available to authorities on demand.
  • The law does not require internal traceability or lot-level granularity; BRCGS and retailer standards do.
  • Article 19 imposes immediate withdrawal, authority notification and consumer-level recall duties when food is unsafe.
  • The gap that hurts producers in incidents is the missing internal links between legally-kept records.
  • Keep traceability records for at least 5 years unless a stricter customer or sector rule applies.
Free 5-part email course
Get audit-ready in five short emails.
The 18-point checklist PDF, the 30-second traceability test, what BRCGS auditors actually flag, and how Cashel Blue got audit-ready, one email every few days. No spam, one-click unsubscribe.
GDPR-friendly: we store your email for this course only. Unsubscribe link in every email.

Frequently asked questions

What does one-up, one-down traceability mean?
You must be able to identify the immediate supplier of every input (one step back) and every business customer who received your product (one step forward). It comes from Article 18 of EU food safety regulations and applies to all food and feed businesses in the EU.
Does EU law require internal traceability?
No, Article 18 stops at your walls. Linking specific incoming lots to specific outgoing batches (internal traceability) is required instead by certification standards like BRCGS and by most retailer own-label contracts.
Do I need to trace sales to consumers?
No. One-step-forward applies to businesses you supplied, not the final consumer. Direct-to-consumer sales (farm gate, markets) still count in your dispatch quantities for mass balance purposes.
How long must food traceability records be kept?
European Commission guidance on EU food safety regulations commonly points to 5 years as the general default, with shorter periods acceptable for highly perishable products. Retailer contracts and sector rules may require longer, apply the strictest.
What happens if I cannot trace a product during an incident?
Article 19 obligations do not wait for your records: if you cannot identify which lots are affected, the withdrawal scope widens to everything potentially affected, more product destroyed, more customers notified, more reputational damage. Precision of trace is what limits the blast radius.

See this done in software, on real production data.

Keystone runs the full chain, supplier delivery → batch → dispatch → customer, in under 30 seconds. 20-minute discovery call, no sales pitch.

Compliance & trust

How we keep your
data and your audits safe.

Enterprise-grade controls as standard, encryption, MFA for every user, tenant isolation and immutable audit trails, on EU cloud or your own servers. Privacy queries go to privacy@cloudvoro.com. Sub-processor list at /legal/sub-processors. Full security posture at /site/security.

Live
Hosted in EU / Ireland, or on-premise
Customer data resides on AWS Ireland (eu-west-1) and never leaves the EU. Local on-premise deployment available where policy requires it.
Live
GDPR · Privacy Contact named
Internal Data Protection Lead handles subject access requests. Owner is ADPO Ireland member.
Live
MFA for every user
TOTP multi-factor authentication across all roles, with rate limiting, brute-force lockout and reCAPTCHA bot protection on public forms.
Live
ISO 27001 · aligned controls
Security controls mapped to the ISO/IEC 27001:2022 Annex A framework, access management, encryption, logging, incident response.
Live
NIS2 · supporting evidence
Tenant isolation, MFA and immutable audit trails give customers in NIS2 scope direct supporting evidence for their obligations.
Live
Encryption · at rest & in transit
TLS 1.3 in transit, industry-standard symmetric ciphers at rest, KMS-managed keys.