Traceability in Manufacturing: Requirements and Implementation

Written by Amadeus Lederle | 28.7.2026

Ask a production manager if his or her facility is traceable, and the answer is almost always yes. Ask which serial numbers are affected by a defective batch of materials, and the answer will require several days of research. It is precisely this gap that determines whether a facility has traceability or merely data.

Traceability is one of the most commonly misunderstood concepts in manufacturing quality. Many companies believe they are traceable simply because they store data. In reality, however, a product is only truly traceable when its data is linked to a specific unit and can be retrieved system-wide. Data in ERP, MES, and paper archives that are not interconnected does not constitute proof of traceability.

This article explains what traceability in manufacturing actually requires: the four questions a system must answer, the two levels of granularity and when each is necessary, the relevant standards and their specific requirements, a maturity model for self-assessment, and a five-step roadmap that begins with defining objectives and ends with tested recall capability.

THE MOST IMPORTANT POINTS AT A GLANCE
  • Traceability is the ability to provide complete documentation for every shipped product, showing what materials it consists of, under what process conditions it was manufactured, what test results are available, and who approved it and when. Stored data alone does not constitute traceability; it is only when linked to a specific component or batch that it becomes traceable.
  • Traceability has two levels of granularity: Batch traceability links a production lot to material, process, and testing and is sufficient for most applications. Serial number traceability links each individual component and is mandatory for safety-critical components in the automotive industry.
  • IATF 16949 Section 8.5.2.1 requires component-level traceability for safety-critical Class A parts. Missing or incomplete traceability is one of the most common serious audit findings and can lead to the loss of supplier approval.
  • The economic core of traceability lies in containing the impact in the event of a defect. Those who can identify affected products at the component level can block individual units rather than entire production runs and limit each recall to the quantity actually affected.
IN A NUTSHELL
  • Traceability is not a data repository, but a capability to respond. The benchmark is whether four questions about each product can be answered in minutes rather than days.
  • Compliance pressure is increasing simultaneously from multiple directions: IATF 16949, the EU Product Liability Directive 2024 with a reversal of the burden of proof, the EU MDR, and industry-specific requirements.
  • Value is not created by storing more data, but by linking it together. Disparate data in ERP, MES, and paper archives does not constitute proof of traceability.

CONTENTS OF THIS ARTICLE

  1. What Traceability Exactly Means in Manufacturing
  2. The four questions a traceability system must answer
  3. Batch or serial number traceability: which level do you need?
  4. Which standards require traceability and what specific requirements they entail
  5. Why Separate Data in ERP and MES Does Not Constitute Traceability
  6. Maturity model: Where does your traceability stand?
  7. The 5-step roadmap to seamless traceability
  8. CSP IPM: Traceability as a Byproduct of Production
  9. Frequently Asked Questions

 

What Traceability Exactly Means in Manufacturing

Traceability is the ability to clearly track the path of a product or component throughout its entire production and life cycle. This includes what was produced, when and under what conditions it was produced, and which components are incorporated into it.

The key lies in the word “link.” Modern traceability is no longer limited to batch or serial numbers, but involves the complete integration of production, quality, and system data into a searchable chain. A test result that is not uniquely assigned to a component, a process parameter with no reference to a specific unit, a material batch that appears only in the goods receipt record and not on the finished product: all of this is stored information, but it does not constitute traceability evidence.

8.5.2.1 up to 25 J. Class A 2 levels
Section of IATF 16949 on traceability Obligation to provide evidence under the EU Product Liability Directive 2024 Audit finding class in the event of a lack of traceability Granularity: Batch or serial number
IATF 16949:2016 EU Product Liability Directive 2024 CSP Project Data 2024/25 CSP Traceability Practices

 

The Four Questions a Traceability System Must Answer

Traceability is not an end in itself, but rather a structured response to four questions. These questions are asked in two situations—during an audit and in the event of a claim—and a system that cannot fully answer even one of them is not an audit-ready traceability system. The four questions also form the chain from raw materials to delivery.

01 What is the product made of?
The material question: Which raw material batches, purchased parts, and components are used in this specific unit?

Required data points

  • Material batch per component
  • Supplier and incoming goods inspection
  • Purchased part serial numbers
  • Consumables and operating materials used

What it does

→ Traces the recall back through the supply chain

→ Without this field, it is not possible to narrow down suppliers

→ Verified by at least two independent data points

Note: Without a material link, traceability ends at the plant gate
02 Under what conditions was it manufactured?
The process question: Which equipment, which parameters, which tools, and which shift produced this unit?

Required data points

  • Equipment, tool, and fixture
  • Process parameters with timestamps
  • Shift and operator
  • Software and recipe version

What it does

→ Determines whether a process deviation was the cause

→ Narrows down affected units to a specific time window

→ Links errors to a specific process signature

Note: Process data without component references is statistical data, not evidence
03 How was it tested?
The quality question: What measured values, test results, and graphs prove that this unit met the requirements?

Required Data Points

  • Measured values per test characteristic
  • Screw-in and process curves
  • Test equipment and calibration status
  • Pass/Fail decision based on limit value

What it does

→ Determines whether the defect was visible during the inspection

→ Identifies testing gaps and undetected defects

→ Serves as the primary evidence for the OEM

Key point: A test result without a clear component assignment is worthless
04 Who approved it, and when?
The question of responsibility: Who approved the unit for shipment, when, and based on what data?

Required data points

  • Approval decision with timestamp
  • Person or role responsible
  • Special approvals and deviations
  • Shipping and delivery data

What it does

→ Addresses the issue of liability in the event of a dispute

→ Demonstrates due diligence in the event of a reversal of the burden of proof

→ Closes the chain from material to customer

Key point: Without documented approval, the final link in the chain is missing

THE MOST COMMON PRACTICAL MISTAKE

Companies invest in more data collection, even though the problem is the lack of integration. Additional measurement values, graphs, and logs are stored, but without a consistent primary key, they remain separate collections.

The consequences only become apparent in an emergency: All the data is available, but no one can consolidate it into a single unit within the required time. Verification fails not because of missing data, but because of missing connections.

 

Batch or serial number traceability: Which level do you need?

Traceability has two basic levels of granularity. The choice between them is not a matter of technical preference, but rather depends on the product, customer requirements, and the need for a precise scope of investigation in the event of a claim.

Batch traceability links a production batch to the materials used, the process parameters, and the test results. It is sufficient for most industrial applications. Serial number traceability goes a step further: Each individual component is linked to its specific production data and test results. It is required when OEM specifications mandate it or when safety-critical components are involved.

Levels of traceability granularity and their typical applications
Traceability Type Granularity What is linked Typical Use
Material Traceability Coarse Batch-to-batch, no reference to individual parts Standard series with no safety implications
Batch traceability Medium Lot linked to material, process, and inspection Mass production, general industry
Serial number traceability Detailed Each component is individually identified Safety-critical automotive parts
Component plus process signature Very fine Individual part with complete process history OEM specifications, Class A components

The practical implication is a cost consideration. The finer the granularity, the greater the effort required for tracking, but the more precisely the scope can be narrowed in the event of damage. Blocking a single serialized component is less expensive than blocking an entire batch, and blocking a batch is less expensive than blocking an entire production period. The appropriate level is the one at which the sum of the data collection effort and the expected risk of a claim is the lowest.

Why the data model is identical at both levels

An often-overlooked advantage: The underlying data model is structurally the same for both batch and serial number tracking. Only the first field differs in terms of granularity—in serialization, a serial number for exactly one unit; in batch tracking, a batch number for a lot. If you set up your data model properly from the start, you can refine the granularity later without having to rebuild the architecture. The eight required fields of an audit-ready data model remain the same in both cases.

Direct Comparison of Batch and Serial Number Traceability
Criterion Batch Traceability Serial Number Traceability
Identifies A production lot Each individual unit
Primary Key Batch number Serial number
Scope of the recall At the lot level At the component level
Data entry effort Lower Higher, per unit
Typical trigger General mass production OEM specifications, safety-related
Data model 8 required fields 8 required fields, identical

 

Which standards require traceability and what specific requirements they entail

Traceability is a regulatory requirement in many industries, and pressure is mounting from multiple directions simultaneously. The following regulatory frameworks are the most relevant for manufacturing in the DACH region. They differ in scope and the level of detail required, but they share a core requirement: complete, linked, and long-term accessible records.

01 IATF 16949, Section 8.5.2.1
Automotive industry: component-level traceability for Class A safety-critical components.

Specific Requirements

  • Clear start and end points of the affected batch
  • Documented traceability procedures
  • Risk-based system across all stages
  • Verification of subcontractors

Consequences

→ Most common serious audit finding in case of a violation

→ Up to loss of supply authorization

→ VDA Volume 6.3 specifies requirements in the process audit

Classification: The de facto standard against which automotive suppliers are measured
02 EU Product Liability Directive 2024
Stricter liability: Reversal of the burden of proof and long-term documentation requirements for products placed on the market.

Specific Requirements

  • Reversal of the burden of proof to the manufacturer
  • Record-keeping obligations for up to 25 years
  • Also covers software and updates
  • Applies across all industries

Consequence

→ Makes complete documentation a line of defense

→ Increases the value of audit-proof archiving

→ Those who cannot provide proof are liable

Classification: Transforms traceability from an optional feature into a legal liability requirement
03 EU MDR and industry-specific requirements
Regulated industries: medical devices, pharmaceuticals, and food, each with their own regulatory frameworks, some of which are more stringent.

Specific Demands

  • EU MDR: UDI and Lifecycle Tracking
  • FDA 21 CFR Part 11: Audit Trails
  • EU Regulation 178/2002: Food
  • GMP: Tamper-Resistant Records

Consistency

→ Require end-to-end data integrity

→ Require tamper-proof storage

→ ESG reporting requirements are also applicable

Classification: The more regulated the industry, the finer the required level of granularity

 

A lack of traceability is rarely a data problem. Almost always, it is a linking problem that only becomes apparent during an audit or a recall—by which time it is too late to fix it.

Amadeus Lederle, Chief Technology Executive, CSP Intelligence GmbH

 

Why Separate Data in ERP and MES Does Not Equate to Traceability

The most common reason traceability fails in an emergency is not a lack of data, but rather the fact that the data is separated. In most companies, the relevant information has long been available—it’s just stored in separate systems: material data in the ERP, process data in the MES, inspection results in the inspection system, and approvals in the paper archive. As long as these systems do not share a common key, traceability requires a manual reconstruction process that can take days.

Separate Data vs. Linked Traceability
Reference Separate Linked Lever
Material reference Material batch in ERP, products in MES, no connection Material batch as a field associated with each serial number Continuous primary key
Inspection reference Test curves without unique component assignment Test result and curve linked to the serial number Link at the point of origin
Approval Approval on paper, separate from production data Approval with timestamp and role in the same data record One data record per unit

The solution is rarely a new data collection system, but rather a continuous primary key. In an integrated system, the serial number serves as this key: It runs from goods receipt through every process step and every inspection all the way to release and shipment. Only this single key transforms four separate data collections into a traceability chain.

 

Maturity Model: Where Does Your Traceability Stand?

Before launching a traceability project, it’s essential to clearly understand your current situation. The maturity model classifies companies based on their ability to actually answer the four traceability questions within a reasonable amount of time. Most companies overestimate their level of readiness until the first mock recall exercise reveals the truth.

Level1: Paper & Silos Level2: Digital, but Disconnected Level 3:Linked Level4: Real-Time Audit-Ready
Data Status: Data stored in ERP, MES, and paper archives, not linked. Searches must be performed manually. Data Status: All data is digital but stored in separate systems without a common key. Data Status: Material, process, and inspection data are linked by batch or serial number. Data Status: Component-specific history, including process curves, archived in an audit-proof manner.
PossibleAnalyses: Individual case research takes days. No reliable way to narrow down results. PossibleAnalyses: Linking possible only with significant effort and system disruption. PossibleAnalyses: Traceability in minutes; narrowing down to the batch level. PossibleAnalyses: Recall narrowing down to individual units within minutes, audit-compliant.
NextStep: Define a unique primary key for each product NextStep: Consolidate systems using the serial number or batch Nextstep: Refine granularity to individual parts and process signatures Nextstep: Predictive use: Identify anomalies before shipment

 

The 5-Step Roadmap to Seamless Traceability

A traceability project rarely fails because of technical issues. It fails because data is collected too early, before it is clear what the system needs to be able to prove. That is why defining the objectives comes first—not the purchase. The following roadmap takes you from initial clarification to tested traceability in four months.

01 Timeframe: Weeks1–2 Defineverification questions and granularityGoal: to know what the system must be able to prove

Tasks

  • Specify the four verification questions for your own products
  • Review customer and regulatory requirements: IATF, OEM specifications, MDR
  • Determine the required level of granularity for each product family
  • Derive retention periods from the strictest applicable requirement

Result

A documented traceability target for each product family

02 Timeframe: Weeks3–5 Clarifydata sources and primary keys; goal: a consistent key across all systems

Tasks

  • Take inventory of existing data in ERP, MES, inspection systems, and the archive
  • Define the serial number or lot number as a consistent primary key
  • Identify gaps: Which process steps currently do not provide data?
  • Check machine connectivity via OPC UA and REST; use manual data entry where necessary

Result

A data map with a key and identified gaps

03 Timeframe: Weeks6–12 Establishing Connections Instead ofCollectingData: Goal—Turning Data Silos into a Searchable Chain

Tasks

  • Link material, process, and inspection for each unit via the primary key
  • Close data gaps on the production line: scanners, curve data capture, mandatory confirmation
  • Establish an approval step with a timestamp and designated responsible party
  • Set up audit-proof archiving for the required retention period

Result

A seamless traceability chain that can be queried on a per-unit basis

04 Time Period: Weeks 13–16 Testingcallback capability: Goal: to test response speed under real-world conditions

Tasks

  • Dry run for callbacks: Identify affected units for a specific material lot
  • Measure response time and compare it to the target of a few hours
  • Audit simulation: Answer the four questions for a randomly selected product
  • Document weaknesses and address them specifically

Result

Proven recall containment in minutes instead of days

05 Ongoing Establishtraceability in operations; Goal: Transition the project into an operational state

Tasks

  • Include traceability completeness as a KPI in quality reporting
  • Integrate new systems and products using the same key schema
  • Continuously incorporate standard changes and new OEM specifications
  • Use data for process improvement, not just for documentation

Result

Traceability as a continuously maintained, audit-proof capability


 

CSP IPM: Traceability as a Byproduct of Production

PRACTICAL TIP

CSP IPM – Traceability via the Serial Number as a Consistent Primary Key

CSP IPM records material, process data, inspection results, and approvals as a byproduct of the ongoing production process and links them via the serial number as a continuous primary key. As a result, the four traceability questions can be answered for each unit in a matter of minutes, without the need for retroactive reconstruction.

  • Serial number as the primary key from goods receipt to shipment, end-to-end
  • Machine integration via OPC UA and REST, readable across manufacturers
  • Process parameters and test curves are directly linked to the unit, not stored in parallel systems
  • Batch and serial number granularity within the same data model, with the option for later refinement
  • Audit-proof archiving for long traceability periods in accordance with IATF and EU product liability regulations
  • Recall scope limited to individual units rather than entire production periods

→ Schedule a demo: csp-sw.de/ipm

 

Frequently Asked Questions

What is the difference between traceability and Rückverfolgbarkeit?

There is none. “Traceability” is the English term, and “Rückverfolgbarkeit” is the German equivalent; both refer to the same capability: the ability to seamlessly document the path of a product or component—including all materials, process steps, and test results—from manufacturing to the customer. In practice, a distinction is often made between tracking (tracking the current location forward) and tracing (reconstructing the history backward); a complete traceability system does both.

 

What specifically does IATF 16949 Section 8.5.2.1 require?

IATF 16949 Section 8.5.2.1 requires that an organization be able to determine clear start and end points for the affected batch of products that may contain safety- or quality-related defects at the customer’s site or in the field. For Class A safety-related components, this means traceability down to the individual component level: For each individual component, the material batch, process parameters, test results, and release decisions must be retrievable. The standard requires documented procedures and a risk-based system across all stages of the value chain.

 

Is batch traceability sufficient, or do I need serial numbers?

That depends on the product and customer requirements. Batch traceability links a production lot to materials, process parameters, and test results and is sufficient for most industrial applications. Serial number traceability links each individual component to its specific data and is required when OEM specifications demand it or when safety-critical components are involved. The rule of thumb: The more precisely the source of a defect must be identified, the finer the required level of granularity. Blocking a single serialized component is more cost-effective than blocking an entire batch.

 

How quickly must a traceability system respond in the event of a recall?

There is no legally mandated deadline, but industry practice sets the standard: If, in the event of an OEM escalation, you cannot identify within a few hours which serial numbers or batches are affected, you lose control over the containment process. As a precaution, everything within reach is then blocked, and a single component issue turns into a shutdown of entire production periods. Response speed is therefore the true performance test of a traceability system, not the volume of stored data.

 

How long must traceability data be retained?

The retention period is determined by the strictest applicable requirement. In the automotive industry, retention periods are based on OEM specifications and product lifespans. The EU Product Liability Directive 2024 tightens the requirements with lengthy documentation obligations of up to 25 years for certain products. For medical devices, the EU MDR requires traceability throughout the entire product lifecycle. It is crucial that the data not only remains available throughout the entire period but also remains audit-proof and actually retrievable.

 

Should we develop our own traceability solution or purchase software?

In-house development appears cost-effective initially because a database and a few scripts are inexpensive to set up. The fallacy lies in the ongoing costs: changing equipment, new OEM specifications, changes in standards, and staff turnover drive maintenance costs over the product’s lifespan far beyond those of a standard solution. In-house development only makes sense if there is a very specific process for which no standard solution exists. In series production with a heterogeneous machine park, standard software is almost always the more cost-effective option.

 

How are machines from different manufacturers integrated into traceability?

The cleanest approach is through open standards. OPC UA has established itself as a cross-vendor protocol that allows machines from different manufacturers to be read uniformly, supplemented by REST interfaces for connecting to higher-level systems. Where equipment does not offer a modern interface, handheld scanners, barcode and QR code capture, or RFID on the production line are used. It is crucial that all captured data is ultimately linked to the same primary key—the serial number or lot number—otherwise separate data silos will form once again.

 

What is the cost of a lack of traceability in an emergency?

The direct costs are only half the story. Without precise containment, entire batches or production periods often have to be held up, even though only individual components are affected—which multiplies the volume of the recall. Added to this is the audit risk: Missing or incomplete traceability is one of the most common serious audit findings under IATF 16949 and can lead to a production shutdown until the issue is verified as resolved and, in extreme cases, to the loss of certification and thus the right to supply. The most costly aspect is the loss of trust with the OEM, which does not appear on any invoice.