The Mock Recall: How to Test Traceability in 4 Hours (With Template)
A mock recall is a rehearsal: you pick one finished lot, pretend it is being recalled, and find out how fast and how completely you can answer three questions. What went into it? Where did it go? How many units are affected? You are not producing a report. You are timing how long the truth takes to assemble.
Why You Have to Do This
Food safety certification schemes such as BRCGS expect a periodic traceability test as part of the audit: the auditor picks or asks for a lot and watches you reconcile it end to end. Outside of certification, regulators in most markets take the same practical position — if you sell a physical product, you are expected to be able to bound a recall: know what is affected, what is not, and get the affected units off the market. The mock recall is how you find out whether you can do that before an auditor, a customer, or a real contamination event asks.
The drill also has a second, quieter audience: your own operations. Most first mock recalls fail not because traceability is impossible but because nobody ever practiced it. Records turn out to be scattered, travelers get mis-filed, and a number that should take minutes takes days. If you want the underlying mechanics first, start with lot traceability and recall genealogy; this article is the exercise.
The 4-Hour Drill, Step by Step
Run it with one competent person plus whoever holds the records. Four hours is the target for a mid-size factory with mostly manual records. Here is the timing:
| Step | What you do | Time | Clock |
|---|---|---|---|
| 1. Pick the lot (T+0) | Randomly choose one finished-goods lot shipped in the last month. Not your favorite lot — a random one. Record lot code, product, production date, quantity. Tell nobody in advance. | 15 min | 0:00–0:15 |
| 2. Trace backward | List every raw material and packaging lot consumed, with supplier and lot number. Walk back through WIP: which intermediate batches fed it, on which line, at which stations, with which operators and machine settings. | 90 min | 0:15–1:45 |
| 3. Trace forward | From the finished lot, list every shipment: customer, quantity, delivery date, invoice or delivery note. Include any lot that sat in the warehouse, was reworked, or was scrapped. | 60 min | 1:45–2:45 |
| 4. Quantify | Total units produced, units shipped, units still on hand, units scrapped. Estimate the exposure: product value, freight, customer notifications needed. | 30 min | 2:45–3:15 |
| 5. Write findings | Where did the drill stall? Which records were missing, which systems had to be opened, which numbers did not reconcile. Assign one owner per gap with a deadline. | 45 min | 3:15–4:00 |
A few rules while you run it. First, no stopping to fix anything mid-drill. If a record is missing, note it and move on — you are measuring the present state, not improving it as you go. Second, the trace must close through actual records, not memory. "Ketut says that batch used the flour from Tuesday" is not traceability; it is a lead that takes another hour to confirm. Third, count rework. Any lot that was reworked carries both its own identity and the identity of what it absorbed, and that is exactly where drills blow up.
The Pass/Fail Bar
The bar is simple: 100% lot reconciliation within the window, or the drill failed. Every unit of the picked lot must be accounted for — shipped to named customers, on the shelf with a location, consumed in rework, or scrapped — and every input lot must trace to a named supplier with a lot number. 99% is a fail, because the 1% you cannot locate is the part that turns a bounded recall into a market-wide one.
Speed is secondary to completeness, but it is not optional. If reconciliation took eight hours with three people, you technically passed and practically lost: in a real recall, eight hours of delay is eight more hours of product in the market. Record the time anyway and treat it as the metric to beat next quarter.
What Typically Breaks
After enough of these drills, the failure list stops surprising you. The usual suspects:
- Records in four systems. Materials in the ERP, production on paper, shipments in the accounting system, quality in a shared drive. Reconciliation means four logins and a manual join nobody does routinely.
- Operator memory. The shift supervisor remembers which silo the sugar came from. The supervisor is on leave. The record that should have captured this does not exist.
- Paper travelers mis-filed. The traveler for the lot exists — in the wrong folder, in a drawer, or still on the line. Someone goes hunting for 40 minutes.
- Excel files named FINAL_v7_repaired.xlsx. Production records live in spreadsheets with no version control and no single owner. The one that reconciles is not the one that is current.
- Time zones and shift boundaries. A lot that started at 22:40 on night shift and finished at 06:10 the next morning crosses two dates, two shift rosters, and possibly two supervisors. If your records key on date only, the drill stalls exactly there.
None of these are exotic. All of them are invisible until a drill — or a real recall — pulls the thread.
Scoring Your Result
Use one compound score so improvement is comparable across drills:
score = hours spent × people involved × % of lots reconciled
The benchmarks we see:
- Under 2 hours, one person, 100% — strong. Your records are joined well enough that one person can walk the chain. This is where a digitized operation lands.
- Half a day with a team, 100% — typical. You can do it, but it takes a room of people and a lot of walking around. Passable for an audit, expensive in a real event.
- A week — you are the case study. If a single lot takes a week to bound manually, a recall will be a memory-driven scramble. Fix the records before anything else.
Grab the mock-recall drill template (.xlsx) — it has the lot-selection sheet, the backward and forward trace sheets, the reconciliation tally, and the scoring cell pre-wired.
After the Drill: Fixing What Broke
The findings list is the actual deliverable. Each break — the missing traveler, the four systems, the shift-boundary lot — gets one owner and one fix with a date. The next drill, one quarter later, should be faster on exactly the steps that stalled. If the same thing breaks twice, the fix was not real.
Two directions for the fixes. Process fixes first: one filing rule, one owner per record, shift IDs instead of dates. Then, when the process is stable and still too slow, digitize the chain — that is what a MES does; see how an electronic batch record holds up in a BPOM audit for what the end state looks like when the regulator is the one asking.
Frequently Asked Questions
How often should we run one?
At least once a year is the common minimum expectation under certification schemes; twice a year is the practical recommendation if you produce across multiple lines or sites, and quarterly until you pass cleanly once. The drill only proves today's state — reorganize the warehouse or switch suppliers and yesterday's pass means nothing.
Who picks the lot — us or the auditor?
Both, eventually. Run internal drills with your own random pick first; many certification auditors will select the lot (or ask you to pick under observation) during the traceability portion of the audit. If your internal drill only ever uses lots you chose because they were easy, the audit will find that out.
Should we include packaging materials or only ingredients?
Include them. Primary packaging is part of most recall scopes — a mislabeled film or an incorrect date code is a recall trigger as real as contamination — and packaging lots are, in practice, the worst-traced records in most factories. A drill that traces ingredients but not the film, cartons, and labels is testing half the chain.
Make the Next Drill a Query
Voltrus MES keeps lot genealogy as you produce: every input, batch, and shipment linked at the point of record. The four-hour drill becomes a search that returns in seconds — pick a lot, get the full chain.
See Voltrus MES