When an authority asks a question, an accident is reported or a decision on corrective action is made, a company does not have time to look for the correct version of a file on several drives. It needs answers: which product and batch the event concerns, what data was available, who made the decision and which recipients may be covered by the action.
The audit trail starts before an inspection
It is not possible to reconstruct the process reliably if files were not versioned and approvals were verbal. Each material piece of evidence should have a source, scope, date of receipt and assessment status. Each decision should identify the author, the basis and the products concerned.
It is important to distinguish between a fact, a document and a conclusion. A test report is evidence, but the decision to apply it to a variant requires an assessment. The audit system should show both elements, not pretend that the presence of an attachment settles the matter by itself.
Data needed to determine the scope quickly
A response is facilitated by stable identification of the product, model, variant and batch. Data on the manufacturer, importer, responsible person, suppliers and recipients is also needed to the extent required to trace the chain. Links should be searchable without changing historical records.
If the company does not maintain batch numbers, it should document other available identifiers and sales periods. The broader and less precise the scope, the harder it is to direct the action to the correct units. Therefore, traceability is part of the day-to-day process, not a form created after an incident.
Inspection of documentation
During an inspection, what matters is the ability to present a consistent set, not the number of files. The dossier should lead from product identification through risk analysis, evidence, instructions and warnings to the decision to make available and subsequent changes. Gaps should be visible together with a plan for addressing them.
An export prepared for inspection purposes should state the position as at a specified date. It must not overwrite earlier revisions. If a document was supplemented after a question from the authority, the history should clearly show the time of the change.
Market signal and initial qualification
A complaint, return, injury report or information from a supplier does not always indicate the same level of risk. However, every signal should be entered in a register and linked to the product. The preliminary assessment covers the credibility of the information, potential severity, likelihood, number of products and user groups.
The decision should be escalated according to established responsibilities. A system can monitor the deadline and completeness, but should not independently classify the product as safe or unsafe. Such a conclusion requires a competent assessment and consideration of the relevant legislation.
Corrective actions and withdrawal
Possible actions depend on the situation and may include stopping sales, improving information, a warning, withdrawal from the market or recall of the product from consumers. The scope should follow from the risk assessment and applicable instructions. Each action needs an owner, a deadline, the affected population and a method of confirming completion.
In the event of a product recall, the consumer communication should be clear and must not minimise the risk. GPSR provides for arrangements concerning notifications and remedies offered to consumers. The company should use current templates and consult on the content, rather than relying on an old marketing communication.
Notification and contact channels
If purchasers can be identified, contact details used in accordance with the law help to deliver the warning without delay. Where it is not possible to reach all persons directly, other channels with appropriate reach may be needed. The content, date of sending, recipient group and delivery result should be retained.
Communication with the authority and notifications in EU systems should be handled by authorised persons. The record of the information sent must correspond to what was actually communicated. A draft version must not be confused with an official notification.
Data package ready for action
- product, variant and batch identification,
- sales period and channels,
- entities in the supply chain,
- current and historical risk analysis,
- reports, instructions and warnings,
- market reports and their assessment,
- list of decisions taken,
- scope of the corrective action,
- communications and confirmations of sending,
- closure documentation and conclusions.
Post-incident conclusions
After closing the case, it is worth updating the risk analysis, procedures, document acceptance criteria and user content. The change should be carried over to related products, but must not automatically extend to other variants without assessment.
GPSR / PPWR helps to retain sources, revisions and accountability. As a result, an inspection or corrective action does not start with searching mailboxes, but with a structured product record.