A recall is an execution problem built on top of a records problem. When a supplier calls or an internal result comes back positive, your exposure is largely determined by information that either exists or does not: which lots were affected, what they were used in, and who received them.
Companies that handle recalls well are rarely the ones with better crisis communication. They are the ones whose lot identity survives internal handling, whose distribution records can be queried quickly, and whose decision authority is defined in advance rather than negotiated during the event.
What a working recall program contains
A recall plan is required under 21 CFR Part 117 where a hazard requiring a preventive control is identified, and it is expected by every certification scheme. The difference between a compliant plan and a usable one is testing.
- A defined recall team with named roles, deputies and after-hours contact information
- Explicit decision authority: who can initiate a hold, a withdrawal and a recall, and who cannot be bypassed
- Product identification and traceability procedures capable of one-up one-back reconstruction
- Customer and consignee notification templates and distribution lists that are actually current
- Effectiveness checks and a method for measuring recovery
- Disposition and reconciliation procedures for recovered product
- Regulatory notification considerations, including Reportable Food Registry obligations for responsible parties where applicable
- A mock recall exercise on a defined cadence, with the elapsed time measured and the gaps written up
Where traceability breaks
Lot identity is most often lost at predictable points: repacking, case-breaking, bulk commingling, and rework. Each needs an explicit decision about how lot identity is preserved, or how a new lot code is assigned and linked back to its inputs.
Granularity is the other lever. A facility that assigns one lot code per production day will recall a day's output; one that codes by shorter intervals or by batch may recall a fraction of it. That trade-off between operational simplicity and recall scope is worth making deliberately rather than inheriting.
For foods on the Food Traceability List, 21 CFR Part 1 Subpart S may impose additional recordkeeping with key data elements linked by traceability lot code, and may contemplate producing records to FDA within a defined timeframe in a sortable electronic format. Applicability depends on the food and on available exemptions.
During an event
The first hours are about scope determination and containment, not announcements. Establish what is affected and what is not with evidence, place a hold on everything within the plausible boundary, and resist the pressure to narrow scope before the records support narrowing it.
Notification obligations depend on the facts, the product and your role in the supply chain, and this is an area where technical and legal advice genuinely intersect. SURU Compliance provides technical recall support — traceability reconstruction, scope determination, root cause investigation, corrective action and effectiveness verification. We are not a law firm, and regulatory notification and liability questions should involve qualified counsel.
Afterwards, the root cause investigation is the deliverable that determines whether it happens again. Recall events almost always expose a systemic gap: a supplier verification weakness, a label change control failure, an allergen changeover that was never validated. Closing the specific incident without closing that gap leaves the same event available.
SURU Compliance is an independent regulatory consulting practice. We are not the FDA or any other government agency, not a certification body or accredited certifying entity, and not a law firm. We do not provide FDA approval, guaranteed inspection or audit outcomes, or legal advice, and we refer legal matters to qualified counsel. Regulatory applicability depends on your specific products, processes, size and jurisdiction.
