A Batch Turns Suspect and Nobody Has Called Yet. Can You Trace It in Four Hours?

The trigger is usually internal. A stability or in-process result comes back out of specification three weeks after dispatch. A supplier writes in to say a lot they shipped you last quarter was off-spec. An operator finally reports the tank that ran without a proper changeover on a Saturday shift.

Nobody outside the plant knows yet. This is the best position you will ever be in, and it lasts only as long as it takes to answer one question: what did that material touch, and where is it now?

The answer comes back in a predictable order. Which production orders consumed the suspect lot. Which subassemblies and WIP batches carried it forward. Whether any of it left the plant for heat treatment or plating and came back under a different number. Whether rejected material from those runs was reworked into later batches. Whether output was split, repacked or relabelled. Which of it is still on your floor, and which is already with customers.

Assembling that from five departments, three spreadsheets and one person’s memory is not traceability. It is reconstruction, and every hour it takes is an hour the decision gets made for you instead of by you.

Batch traceability in manufacturing is the ability to connect a finished batch or serial number to the actual materials, components, intermediate batches, production operations and external processing that created it, and then identify every downstream product, inventory location and customer affected by those inputs. It follows actual production genealogy, not only the planned bill of materials.

That last distinction carries more weight than it appears to.

The BoM tells you what should have gone in

Batch genealogy in manufacturing from raw material lot to customer shipment with three breakpoints

The BoM tells you what should have gone into the product. Genealogy tells you what actually went into the batch that shipped.

A real lineage runs through several identities. A steel coil lot becomes a stamped component batch, which goes out for heat treatment, comes back into a subassembly batch, and is consumed in the finished batch that reaches the customer. Five transformations, each one a hop in a chain. A BoM explosion reproduces the shape of that chain perfectly and proves not one link in it.

The failure is mechanical rather than conceptual. Where components are backflushed at the parent level with automatic FIFO lot assignment, the system is not recording what was consumed. It is calculating what should have been consumed, from a rule. Those match on most days. They do not match on the day a supervisor pulled a part-used tote from the previous shift because the fresh one had not been released.

Run the diagnostic yourself this week. Take one finished lot from last month, ask which intermediate lot fed it, then ask which raw material lot fed that intermediate. Most systems answer the first question cleanly. The second answer degrades into a date, a shift, or a list of everything open that day. That degradation point is where your exposure stops being a number and starts being a guess.

The honest tradeoff: capturing real identity at every level costs scan time, and operators resent scans that produce nothing they can see. So make the rule narrower than full coverage. Any operation where lots co-mingle or split needs its own identity. A single-input, single-output operation can inherit.

Break one: the subcontracted operation

The most common break in Indian manufacturing sits at the job work boundary. A component lot goes out for plating and comes back under the vendor’s own number. The question that matters is whether the system can prove the outbound lot, the external operation and the returned lot are one lineage, without opening a spreadsheet or reading a free-text note. In most plants it cannot, because the return posted as an ordinary receipt against a service PO rather than against the issued lot.

The mechanism compounds. Vendors return in partial batches over weeks. They top up with their own consumables. Some combine your material with another customer’s in the same tank or furnace. Yield loss means quantity back never matches quantity out, so reconciliation happens monthly, by quantity, in stores. At that point genealogy stops being data and becomes an estimate.

The handle is unglamorous. The subcontract receipt must reference the specific issued lot, not the vendor or the PO. You are already raising a job work challan under GST, so make it the trace document rather than a parallel record, and require lot-wise consumption declared against it. Reconcile per challan, not per month. If your job work reconciliation balances only on quantity, that is the early signal, and it usually travels alongside inventory value quietly vanishing inside subcontracting.

Break two: rework is a genealogy event

Eighty units fail inspection. Twenty are scrapped, sixty are corrected and returned to production. If the system records rework quantity equals 60, the physical material continues down the line while its digital lineage stops dead.

Both recovery options in common use fail, in opposite directions. Re-enter the material under its original lot number and a forward trace on that lot will correctly pull in batches produced weeks later, widening your exposure over production that had nothing to do with the fault. Re-enter it as fresh stock under an unrelated number and the forward trace misses batches that genuinely contain suspect material. That is the under-count, and it is the version that ends with someone else expanding your scope for you, in public.

The rule that resolves it: reworked material takes a new lot identity carrying a machine-queryable link to its source lot, the rework order, the deviation or NCR, and the post-rework quality status. New identity, preserved lineage. The graph then shows exactly what the rework touched and nothing beyond it.

Break three: the repack bench changes identity without changing product

A finished batch of 5,000 units becomes 2,000 in one pack size, 2,000 in another, and 1,000 under a customer’s private-label code. The physical product never changed. The commercial identity changed three times.

In most configurations that posts as a stock move or a UOM conversion. It is neither. It is a transformation with one parent and several children, and the old-to-new mapping has to be queryable by the system, not readable in a comment field. The test runs both ways: when the private-label code turns up in a complaint, the system should land on the parent batch immediately, and when the parent becomes suspect, that private-label population should appear in the forward exposure list without anyone remembering it exists.

Labelling deserves particular attention here. In the food sector, label errors alone drove 45.5% of recalls in 2024. If artwork version and print run are not attached to the child lot, a label defect cannot be bounded to the packs carrying it, and the whole parent lot goes.

Backward trace defends you. Forward trace tells you what you are holding

These get discussed as a matched pair, which hides the fact that only one of them is hard.

Backward TraceForward Trace
Core questionWhat made this batch?What did this material affect?
Starting pointFinished batch or serialRaw material, component or intermediate lot
Typical TriggerCustomer complaint, field failureSupplier defect notice, out-of-spec result, process deviation
Primary OutputManufacturing history, root-cause evidenceExposure population, containment scope
Main riskMissing an upstream contributorMissing a downstream customer or location

The backward trace is the one auditors request and the one your annual test rehearses. It reliably passes. The forward trace is the one you need when you find the problem yourself, and it fails far more often, because it has to cross every break described above in the outbound direction and then join cleanly to dispatch records.

A January 2026 case shows the cost. Neogen recalled all unexpired lots of a veterinary sterile solution after microbial contamination was confirmed in certain lots of a single vial size, and the product had been made by an unaffiliated third-party supplier. Both features of the wide-recall pattern in one incident: a subcontracting boundary, and a forward trace that could not narrow the answer below everything. Component-level genealogy typically reduces recall scope by 60 to 90%, and since most recall cost scales with scope, that difference lands on the P&L directly.

The Four-Hour Manufacturing Trace Test

Four-hour manufacturing trace test scorecard for a quarterly batch traceability drill

Four hours is a recommended internal readiness benchmark, not a universal regulatory requirement. Some food-sector certification schemes expect full forward and backward trace with mass balance inside that window, which is useful supporting evidence, but the reason to adopt it in general manufacturing is commercial. Four hours is roughly the width of the window in which you still control the response. Past it, the scope gets set by whoever asks first.

Run the drill quarterly, because configuration drifts faster than annually. New SKUs, new job work vendors, a rework route added after a bad quarter. Each one changes the graph.

The drill: at 9:00 a.m. someone outside quality names a suspect input lot from about three months ago, unannounced, on a normal production day. First thirty minutes, resolve identity, site, work orders and every alias attached to it. To ninety minutes, run the forward trace through WIP, finished goods, inventory and shipments. To 150 minutes, take one affected finished batch and trace it backward across all levels using actual consumption. To 180, deliberately attack the subcontract, rework and repack transitions. To 210, reconcile produced, scrapped, reworked, on-hand, shipped and returned quantities. The last thirty minutes produce a management-ready exposure statement.

A passing statement reads like this: the suspect lot fed three production orders across two manufacturing levels, one of which underwent subcontracted heat treatment, with no unresolved genealogy breaks. Of 4,800 finished units produced from it, 720 remain on hand and 4,080 shipped across 11 customer locations.

Fail conditions, applied honestly: anyone opens a spreadsheet living outside the system, anyone phones the subcontractor, mass balance exceeds tolerance, or the answer arrives as a date range instead of lot numbers. Manual cross-referencing across ERP, MES and warehouse records takes four to eight hours for a single batch, so a plant running on reconciliation cannot pass this on arithmetic alone. Most discover on the first attempt that their real capability rests on two people and a spreadsheet nobody officially owns.

The dangerous answer is: we found most of it

No records at all is a bad result that everyone recognises as bad. Partial lineage is worse, because it looks like success.

When genealogy is precise, you isolate the affected population and act on it while the problem is still yours to manage. When it is incomplete, you have to assume a larger one, and that assumption converts directly into quarantined stock, held shipments, customers contacted unnecessarily, disrupted production and frozen working capital. A missing 5% of lineage at one subcontract or relabel event can decide whether a single batch is implicated or an entire production window has to be treated as suspect.

So grade the drill in three states. Green means both directions reconcile and every break category is linked or genuinely not applicable. Amber means core lineage holds while secondary evidence is pending that cannot change the known population. Red means a missing edge, alias or quantity could change the population, and the correct posture is to contain conservatively and stop claiming isolation.

The configuration decision sits upstream of QA

Regulatory direction keeps tightening. Late June 2026 amendments to India’s Drugs Rules, 1945 pulled additional drug categories into the QR code track-and-trace framework, and while that is sector-specific, the expectation behind it is spreading: prove the trace, do not assemble it afterwards. Export customers and Tier 1 buyers are already asking during audits rather than after incidents.

The uncomfortable part for a plant head is that none of the breaks here belong to quality. QA consumes the trace. Production configuration, job work process design and how the repack bench posts its output determine whether the trace exists at all, which is why decisions of this kind belong in board-level conversations rather than a compliance folder.

Pick a suspect input lot from three months ago. Do not tell the team which one. Start the clock at nine. What you have by one o’clock is your real exposure, and the cheapest possible day to find that out is a day when nothing has actually gone wrong.

More
articles