Ask a production manager if his or her facility is traceable, and the answer is almost always yes. Ask which serial numbers are affected by a defective batch of materials, and the answer will require several days of research. It is precisely this gap that determines whether a facility has traceability or merely data.
Traceability is one of the most commonly misunderstood concepts in manufacturing quality. Many companies believe they are traceable simply because they store data. In reality, however, a product is only truly traceable when its data is linked to a specific unit and can be retrieved system-wide. Data in ERP, MES, and paper archives that are not interconnected does not constitute proof of traceability.
This article explains what traceability in manufacturing actually requires: the four questions a system must answer, the two levels of granularity and when each is necessary, the relevant standards and their specific requirements, a maturity model for self-assessment, and a five-step roadmap that begins with defining objectives and ends with tested recall capability.
THE MOST IMPORTANT POINTS AT A GLANCE
|
IN A NUTSHELL
|
Traceability is the ability to clearly track the path of a product or component throughout its entire production and life cycle. This includes what was produced, when and under what conditions it was produced, and which components are incorporated into it.
The key lies in the word “link.” Modern traceability is no longer limited to batch or serial numbers, but involves the complete integration of production, quality, and system data into a searchable chain. A test result that is not uniquely assigned to a component, a process parameter with no reference to a specific unit, a material batch that appears only in the goods receipt record and not on the finished product: all of this is stored information, but it does not constitute traceability evidence.
| 8.5.2.1 | up to 25 J. | Class A | 2 levels |
| Section of IATF 16949 on traceability | Obligation to provide evidence under the EU Product Liability Directive 2024 | Audit finding class in the event of a lack of traceability | Granularity: Batch or serial number |
| IATF 16949:2016 | EU Product Liability Directive 2024 | CSP Project Data 2024/25 | CSP Traceability Practices |
Traceability is not an end in itself, but rather a structured response to four questions. These questions are asked in two situations—during an audit and in the event of a claim—and a system that cannot fully answer even one of them is not an audit-ready traceability system. The four questions also form the chain from raw materials to delivery.
| 01 | What is the product made of? |
| The material question: Which raw material batches, purchased parts, and components are used in this specific unit? | |
|
Required data points
|
What it does → Traces the recall back through the supply chain → Without this field, it is not possible to narrow down suppliers → Verified by at least two independent data points |
| Note: Without a material link, traceability ends at the plant gate | |
| 02 | Under what conditions was it manufactured? |
| The process question: Which equipment, which parameters, which tools, and which shift produced this unit? | |
|
Required data points
|
What it does → Determines whether a process deviation was the cause → Narrows down affected units to a specific time window → Links errors to a specific process signature |
| Note: Process data without component references is statistical data, not evidence | |
| 03 | How was it tested? |
| The quality question: What measured values, test results, and graphs prove that this unit met the requirements? | |
|
Required Data Points
|
What it does → Determines whether the defect was visible during the inspection → Identifies testing gaps and undetected defects → Serves as the primary evidence for the OEM |
| Key point: A test result without a clear component assignment is worthless | |
| 04 | Who approved it, and when? |
| The question of responsibility: Who approved the unit for shipment, when, and based on what data? | |
|
Required data points
|
What it does → Addresses the issue of liability in the event of a dispute → Demonstrates due diligence in the event of a reversal of the burden of proof → Closes the chain from material to customer |
| Key point: Without documented approval, the final link in the chain is missing | |
|
THE MOST COMMON PRACTICAL MISTAKE Companies invest in more data collection, even though the problem is the lack of integration. Additional measurement values, graphs, and logs are stored, but without a consistent primary key, they remain separate collections. The consequences only become apparent in an emergency: All the data is available, but no one can consolidate it into a single unit within the required time. Verification fails not because of missing data, but because of missing connections. |
Traceability has two basic levels of granularity. The choice between them is not a matter of technical preference, but rather depends on the product, customer requirements, and the need for a precise scope of investigation in the event of a claim.
Batch traceability links a production batch to the materials used, the process parameters, and the test results. It is sufficient for most industrial applications. Serial number traceability goes a step further: Each individual component is linked to its specific production data and test results. It is required when OEM specifications mandate it or when safety-critical components are involved.
| Traceability Type | Granularity | What is linked | Typical Use |
|---|---|---|---|
| Material Traceability | Coarse | Batch-to-batch, no reference to individual parts | Standard series with no safety implications |
| Batch traceability | Medium | Lot linked to material, process, and inspection | Mass production, general industry |
| Serial number traceability | Detailed | Each component is individually identified | Safety-critical automotive parts |
| Component plus process signature | Very fine | Individual part with complete process history | OEM specifications, Class A components |
The practical implication is a cost consideration. The finer the granularity, the greater the effort required for tracking, but the more precisely the scope can be narrowed in the event of damage. Blocking a single serialized component is less expensive than blocking an entire batch, and blocking a batch is less expensive than blocking an entire production period. The appropriate level is the one at which the sum of the data collection effort and the expected risk of a claim is the lowest.
An often-overlooked advantage: The underlying data model is structurally the same for both batch and serial number tracking. Only the first field differs in terms of granularity—in serialization, a serial number for exactly one unit; in batch tracking, a batch number for a lot. If you set up your data model properly from the start, you can refine the granularity later without having to rebuild the architecture. The eight required fields of an audit-ready data model remain the same in both cases.
| Criterion | Batch Traceability | Serial Number Traceability |
|---|---|---|
| Identifies | A production lot | Each individual unit |
| Primary Key | Batch number | Serial number |
| Scope of the recall | At the lot level | At the component level |
| Data entry effort | Lower | Higher, per unit |
| Typical trigger | General mass production | OEM specifications, safety-related |
| Data model | 8 required fields | 8 required fields, identical |
Traceability is a regulatory requirement in many industries, and pressure is mounting from multiple directions simultaneously. The following regulatory frameworks are the most relevant for manufacturing in the DACH region. They differ in scope and the level of detail required, but they share a core requirement: complete, linked, and long-term accessible records.
| 01 | IATF 16949, Section 8.5.2.1 |
| Automotive industry: component-level traceability for Class A safety-critical components. | |
|
Specific Requirements
|
Consequences → Most common serious audit finding in case of a violation → Up to loss of supply authorization → VDA Volume 6.3 specifies requirements in the process audit |
| Classification: The de facto standard against which automotive suppliers are measured | |
| 02 | EU Product Liability Directive 2024 |
| Stricter liability: Reversal of the burden of proof and long-term documentation requirements for products placed on the market. | |
|
Specific Requirements
|
Consequence → Makes complete documentation a line of defense → Increases the value of audit-proof archiving → Those who cannot provide proof are liable |
| Classification: Transforms traceability from an optional feature into a legal liability requirement | |
| 03 | EU MDR and industry-specific requirements |
| Regulated industries: medical devices, pharmaceuticals, and food, each with their own regulatory frameworks, some of which are more stringent. | |
|
Specific Demands
|
Consistency → Require end-to-end data integrity → Require tamper-proof storage → ESG reporting requirements are also applicable |
| Classification: The more regulated the industry, the finer the required level of granularity | |
A lack of traceability is rarely a data problem. Almost always, it is a linking problem that only becomes apparent during an audit or a recall—by which time it is too late to fix it.
— Amadeus Lederle, Chief Technology Executive, CSP Intelligence GmbH
The most common reason traceability fails in an emergency is not a lack of data, but rather the fact that the data is separated. In most companies, the relevant information has long been available—it’s just stored in separate systems: material data in the ERP, process data in the MES, inspection results in the inspection system, and approvals in the paper archive. As long as these systems do not share a common key, traceability requires a manual reconstruction process that can take days.
| Reference | Separate | Linked | Lever |
|---|---|---|---|
| Material reference | Material batch in ERP, products in MES, no connection | Material batch as a field associated with each serial number | Continuous primary key |
| Inspection reference | Test curves without unique component assignment | Test result and curve linked to the serial number | Link at the point of origin |
| Approval | Approval on paper, separate from production data | Approval with timestamp and role in the same data record | One data record per unit |
The solution is rarely a new data collection system, but rather a continuous primary key. In an integrated system, the serial number serves as this key: It runs from goods receipt through every process step and every inspection all the way to release and shipment. Only this single key transforms four separate data collections into a traceability chain.
Before launching a traceability project, it’s essential to clearly understand your current situation. The maturity model classifies companies based on their ability to actually answer the four traceability questions within a reasonable amount of time. Most companies overestimate their level of readiness until the first mock recall exercise reveals the truth.
| Level1: Paper & Silos | Level2: Digital, but Disconnected | Level 3:Linked | Level4: Real-Time Audit-Ready |
|---|---|---|---|
| Data Status: Data stored in ERP, MES, and paper archives, not linked. Searches must be performed manually. | Data Status: All data is digital but stored in separate systems without a common key. | Data Status: Material, process, and inspection data are linked by batch or serial number. | Data Status: Component-specific history, including process curves, archived in an audit-proof manner. |
| PossibleAnalyses: Individual case research takes days. No reliable way to narrow down results. | PossibleAnalyses: Linking possible only with significant effort and system disruption. | PossibleAnalyses: Traceability in minutes; narrowing down to the batch level. | PossibleAnalyses: Recall narrowing down to individual units within minutes, audit-compliant. |
| NextStep: Define a unique primary key for each product | NextStep: Consolidate systems using the serial number or batch | Nextstep: Refine granularity to individual parts and process signatures | Nextstep: Predictive use: Identify anomalies before shipment |
A traceability project rarely fails because of technical issues. It fails because data is collected too early, before it is clear what the system needs to be able to prove. That is why defining the objectives comes first—not the purchase. The following roadmap takes you from initial clarification to tested traceability in four months.
| 01 | Timeframe: Weeks1–2 | Defineverification questions and granularityGoal: to know what the system must be able to prove |
|
Tasks
|
Result A documented traceability target for each product family |
|
| 02 | Timeframe: Weeks3–5 | Clarifydata sources and primary keys; goal: a consistent key across all systems |
|
Tasks
|
Result A data map with a key and identified gaps |
|
| 03 | Timeframe: Weeks6–12 | Establishing Connections Instead ofCollectingData: Goal—Turning Data Silos into a Searchable Chain |
|
Tasks
|
Result A seamless traceability chain that can be queried on a per-unit basis |
|
| 04 | Time Period: Weeks 13–16 | Testingcallback capability: Goal: to test response speed under real-world conditions |
|
Tasks
|
Result Proven recall containment in minutes instead of days |
|
| 05 | Ongoing | Establishtraceability in operations; Goal: Transition the project into an operational state |
|
Tasks
|
Result Traceability as a continuously maintained, audit-proof capability |
|
|
PRACTICAL TIP CSP IPM – Traceability via the Serial Number as a Consistent Primary KeyCSP IPM records material, process data, inspection results, and approvals as a byproduct of the ongoing production process and links them via the serial number as a continuous primary key. As a result, the four traceability questions can be answered for each unit in a matter of minutes, without the need for retroactive reconstruction.
→ Schedule a demo: csp-sw.de/ipm |
There is none. “Traceability” is the English term, and “Rückverfolgbarkeit” is the German equivalent; both refer to the same capability: the ability to seamlessly document the path of a product or component—including all materials, process steps, and test results—from manufacturing to the customer. In practice, a distinction is often made between tracking (tracking the current location forward) and tracing (reconstructing the history backward); a complete traceability system does both.
IATF 16949 Section 8.5.2.1 requires that an organization be able to determine clear start and end points for the affected batch of products that may contain safety- or quality-related defects at the customer’s site or in the field. For Class A safety-related components, this means traceability down to the individual component level: For each individual component, the material batch, process parameters, test results, and release decisions must be retrievable. The standard requires documented procedures and a risk-based system across all stages of the value chain.
That depends on the product and customer requirements. Batch traceability links a production lot to materials, process parameters, and test results and is sufficient for most industrial applications. Serial number traceability links each individual component to its specific data and is required when OEM specifications demand it or when safety-critical components are involved. The rule of thumb: The more precisely the source of a defect must be identified, the finer the required level of granularity. Blocking a single serialized component is more cost-effective than blocking an entire batch.
There is no legally mandated deadline, but industry practice sets the standard: If, in the event of an OEM escalation, you cannot identify within a few hours which serial numbers or batches are affected, you lose control over the containment process. As a precaution, everything within reach is then blocked, and a single component issue turns into a shutdown of entire production periods. Response speed is therefore the true performance test of a traceability system, not the volume of stored data.
The retention period is determined by the strictest applicable requirement. In the automotive industry, retention periods are based on OEM specifications and product lifespans. The EU Product Liability Directive 2024 tightens the requirements with lengthy documentation obligations of up to 25 years for certain products. For medical devices, the EU MDR requires traceability throughout the entire product lifecycle. It is crucial that the data not only remains available throughout the entire period but also remains audit-proof and actually retrievable.
In-house development appears cost-effective initially because a database and a few scripts are inexpensive to set up. The fallacy lies in the ongoing costs: changing equipment, new OEM specifications, changes in standards, and staff turnover drive maintenance costs over the product’s lifespan far beyond those of a standard solution. In-house development only makes sense if there is a very specific process for which no standard solution exists. In series production with a heterogeneous machine park, standard software is almost always the more cost-effective option.
The cleanest approach is through open standards. OPC UA has established itself as a cross-vendor protocol that allows machines from different manufacturers to be read uniformly, supplemented by REST interfaces for connecting to higher-level systems. Where equipment does not offer a modern interface, handheld scanners, barcode and QR code capture, or RFID on the production line are used. It is crucial that all captured data is ultimately linked to the same primary key—the serial number or lot number—otherwise separate data silos will form once again.
The direct costs are only half the story. Without precise containment, entire batches or production periods often have to be held up, even though only individual components are affected—which multiplies the volume of the recall. Added to this is the audit risk: Missing or incomplete traceability is one of the most common serious audit findings under IATF 16949 and can lead to a production shutdown until the issue is verified as resolved and, in extreme cases, to the loss of certification and thus the right to supply. The most costly aspect is the loss of trust with the OEM, which does not appear on any invoice.