Many teams go looking for a single traceability standard. In reality, there isn’t one, but seven different layers, each doing a different job. Knowing which layer you’re standing on saves you a rebuild later.
Most traceability projects begin with a simple question: “How do we meet this regulation?” It might come from FSMA 204 in the US, Article 18 in the EU, or EUDR if your business imports commodities. These regulations explain what your business needs to achieve, but they don’t always say how to build a system that meets those requirements. This is where food traceability standards like ISO 22005 step in. It helps you understand what your traceability system should include and how it should work.
Rather than a certification checklist, ISO 22005 provides a framework for designing a traceability system that fits your business. To use it effectively, you also need to understand how it connects with other food traceability standards.
This guide breaks down ISO 22005 in detail on what each standard does, how they work together, and what your team should focus on when building a traceability system.
What ISO 22005 Actually Is
As said before, ISO 22005 is a standard for designing and implementing traceability systems in the food and feed supply chain. In simple terms, it helps businesses decide what they need to track, where that information should come from, and how the records should connect.
Published in 2007, ISO 22005 is titled “Traceability in the feed and food chain - General principles and basic requirements for system design and implementation.” People assume something that old must be retired by now, but ISO reviewed and confirmed it in 2022, and it remains the current edition.
The Eight Pages That Matter
ISO 22005 is only eight pages long, and yet it is international. These pages explain what a traceability system should do, while leaving businesses to decide how to implement it. A dairy, co-op, spice exporter, and contract packer will naturally need different approaches.
The Six Decisions to Make
Before choosing software, ISO 22005 requirements come down to six questions you need to answer.
| Decision | What the Standards Expect | What Happens If You Skip It |
|---|---|---|
| Objectives | Define whether traceability is for recalls, quality, origin claims, or compliance | You collect data without knowing what it is actually for |
| Scope | Define how far upstream and downstream you need to trace | Traceability stops at your own facility |
| Product & Lot Definition | Decide what counts as one traceable unit | Recalls affect more product than necessary |
| Information Collected | Decide which data travels with the unit and which stays in records | Data exists but doesn’t connect properly |
| Documentation | Define how the records are created, stored, and retrieved | Critical knowledge stays with one person |
| Verification & Review | Test the system regularly and after changes | Problems surface during an actual recall |
None of these six decisions is about technology, and that’s the point. ISO 22005 helps you define what your traceability system needs to accomplish before you decide how to build it.
What ISO 22005 Is Not
Three common misunderstandings can create problems when businesses use ISO 22005 as their traceability framework.
It’s Not a Certificate
ISO 22005 does not have an accredited certification scheme like ISO 22000. A company can declare that its system conforms to the standard, and consultants can provide compliance letters, but neither is the same as an accredited third-party traceability certification.
A Useful Habit: If a supplier claims to be “ISO 22005 certified,” ask which accreditation body backs the certifying organization. That answer can help you understand what the claim actually means.
It Does Not Pick Technology
ISO 22005 doesn't tell you to choose barcode, GTINs, a specific data format, or a particular software platform. Those technology and data decisions are left to your business.
It Does Not Cover Legal Duties
It also doesn’t make you automatically compliant with FSMA 204, EUDR, or Article 18. ISO 22005 helps you design the traceability system. Applicable regulations still define your legal obligations.
Understanding the 7 Food Traceability Standards
The confusion that is revolving around food traceability standards often comes from treating them as competing standards. Actually, they aren’t. Each one handles a different part of the traceability process, and a complete programme may need several of them working together.
| Layer | Standard | What It Governs | Certifiable |
|---|---|---|---|
| Policy | Codex CXG 60-2006 | Principles regulators use when developing traceability requirements | No |
| Design | ISO 22005:2007 | How to design the traceability system | No |
| Management | ISO 22000:2018 | Food safety management including traceability under Clause 8.3 | Yes |
| Management | ISO 9001 | Quality management, including identification and traceability | Yes |
| Claims | ISO 22095:2020 (+ Parts 2 & 3) |
How claims are linked to materials through the supply chain | Via sector schemes |
| Data | GS1 Standards | Identifiers, event records, and barcodes | No |
| Audit | GFSI-recognized schemes | Requirements customers and auditors inspect | Yes |
Think of the layers as a chain. Codex (the international food standards body set by FAO/WHO) helps shape what regulators require. ISO 22005 helps you design the traceability system. ISO 22000 traceability provides certifiable food safety management requirements.
ISO 22095 handles supply chain claims, while the GS1 traceability standard helps different companies identify and exchange traceability data. Finally, GFSI-recognized schemes cover the requirements your customers may audit against.
1. Policy: Codex CXG 60-2006
Codex CXG 60-2006 product-tracing guideline is mainly for regulators. It helps explain how the authorities think about traceability when creating regulations. You don’t normally build your system around Codex, but it can help you understand where regulatory requirements come from.
2. Management: ISO 22000 Clause 8.3
If you need a food safety certificate, then ISO 22000 traceability is the one to know. Clause 8.3 requires you to identify the materials coming from suppliers, where finished products go first, and keep records that connect these two.
Let’s think of it this way: ISO 22005 helps you design the traceability system, and ISO 22000 lets that system sit within a certifiable food safety management system. The 2018 edition remains current and is now under revision.
3. Management: ISO 9001
If you’re dealing with quality management outside food, ISO 9001 covers product identification and also traceability.
ISO 9001:2026 was published on September 16, 2026, replacing the 2015 edition. If your procedures still reference the old Clause 8.5.2, don’t copy that number into your new documents without checking the 2026 version first.
4. Claims: ISO 22095
Here’s where the traceability gets a little different. ISO 22005 tracks the physical material, while ISO 22095 tracks claims about that material.
Think about claims such as organic, fair trade, recycled content, or deforestation-free. You can’t always test a finished product and prove where that claim came from. Instead, the claim has to follow the material through records. This is what ISO 22095 chain of custody models help manage. It defines 5 ways a claimed material can be handled.
| Model | What It Means | Can Materials Mix? |
|---|---|---|
| Identity Preserved | Material from one source stays separate through the chain | No |
| Segregated | Certified material can be combined with its group, but separate from non-certified material | Certified only |
| Controlled Blending | Certified and non-certified material can be mixed at a standard ratio | Yes |
| Mass Balance | The certified input and claimed output are balanced by volume | Yes |
| Book & Claim | The claim is traded separately from the physical product | No physical link |
You may wonder why this matters. Because “certified material” doesn’t always mean the same thing. A customer expecting identity-preserved material has different expectations from one accepting a mass-balance claim.
In January 2026, ISO also published ISO 22095-2 for mass balance and ISO 22095-3 for book and claim, giving these two models more specific requirements.
5. Data: The GS1 Traceability Layer
This is what makes traceability data understandable across different firms. ISO traceability standards tell you what your traceability system should attain. GS1 traceability standard provides common ways to identify products, locations, shipments, and events. So that your business and trading partners can exchange that piece of information without creating a new format for every relationship.
You may also see Ambition 2027 and Sunrise 2027 mentioned together. Their names are used for the same broader GS1 transition, with GS1 US using Sunrise 2027. The initiative is voluntary and aims to make retail point-of-sale systems capable of reading GTINs from both traditional and 2D barcodes by the end of 2027.
6. Audit: The Layer Customers Care About
For many food businesses in 2026, the standard that matters more is the GFSI-recognized scheme your customer requires. Common examples include BRCGS, SQF, FSSC 22000, and IFS.
All these cover traceability, but the exact requirements depend on the scheme and its scope. So, don’t just ask, “Are we following GFSI?” Instead, inspect which specific scheme and version your customer expects.
As of September 2026:
- FSSC 22000 Version 7 was released on May 1, 2026. Version 6 audits can continue until April 30, 2027, with the transition to Version 7 continuing afterward.
- SQF Edition 10 has been published, while the applicable audit edition depends on its transition schedule.
- BRCGS Food Safety Issue 9 remains the current audited issue while Issue 10 is being developed.
- GFSI-recognized schemes are aligned with the GFSI Benchmarking Requirements v2024.
7. Security: Where ISO 28000 Fits
ISO 28000:2022 is still called “the supply chain security standard” in a lot of articles. The 2022 revision retitled it as “Security and resilience” and dropped that wording. It’s certifiable, and it answers a different question, which is not where the product has been, but whether the chain has been interfered with.
Need Help Mapping Your Traceability Standards Stack?
From ISO 22005 system design to GS1 EPCIS data sharing and GFSI audit readiness, see how TransGenie connects each layer across your supply chain with zero manual guesswork.
Schedule a Standards ConsultationFood Traceability Regulations Timeline
The regulations are often what push businesses to invest in traceability, so deadlines become crucial. Here are the major dates in order, including the recent changes that older guides may still miss.
| When | What Changes |
|---|---|
| Ongoing | EU Regulation 178/2002, Article 18: EU food and feed businesses must maintain backward and forward traceability |
| 16 Sept 2026 | ISO 9001: 2026 replaces the 2015 edition, with a transition period of about three years |
| 30 Dec 2026 | EUDR applies to large and medium operators |
| 30 Apr 2027 | Last FSSC 22000 Version 6 audits |
| 30 Jun 2027 | EUDR applies to micro and small operators |
| End 2027 | Ambition 2027 target for retail point-of-sale systems to support 2D barcodes. Its voluntary |
| 20 July 2028 | FSMA 204 compliance date for businesses handling foods on the FDA Food Traceability List |
In the meantime, here are the two dates that people get wrong:
FSMA 204 has been delayed, moving its original January 20, 2026, compliance date to July 20, 2028. However, the requirements remain: a written traceability plan, traceability lot codes, key data elements, and records that can be provided within 24 hrs. This is a response-time requirement, not a records-retention period, making connected digital records valuable for covered businesses.
EUDR has also been delayed, with compliance beginning December 30, 2026, for large and medium operators and June 30, 2027, for micro and small operators. The core requirements remain unchanged: plot-level geolocation, proof of legal and deforestation-free production, and a due diligence statement. For importers, collecting information several tiers upstream can make the preparation more time-consuming than expected.
The Traceability Unit Decision That Shapes Your Budget
Of the six decisions in ISO 22005, defining the traceable unit can have a major impact on your entire traceability budget. Businesses can sometimes group products by shift without considering how it affects the recall. If a problem is found in that lot, the entire shift’s production may need to be withdrawn, even if only one pallet is contaminated.
Smaller traceable units require more scans, records, and work on the production floor. Larger units may reduce the data collection effort but increase the amount of product affected during a recall. Choosing the right balance is a business decision; that’s not something your production log should decide automatically.
This choice also affects your data structure, software, labels, and ability to respond to traceability requests. Change the definition after the implementation, and you may need to rebuild the parts of the system rather than simply adjusting a setting.
A 30-Minute Test of Your Existing Traceability System
Before evaluating the new software or redesigning your system, run a quick mock recall. This can reveal practical gaps faster than a traditional gap analysis.
- Pick a Finished Product at Random Don’t choose the one with usually good records. Pick any product and trace it.
- Start the Clock Find which raw material lots went into it and which customers received the finished product.
- Note the Dependency If you need a colleague to explain where a record is or what it means, your process depends on that person being available when a real incident happens.
- Count the Format Changes Moving between paper logs, spreadsheets, ERP records, and emails creates multiple points where information can be lost or entered incorrectly.
- Stop at 30 Minutes If you can’t trace the product in both directions within 30 minutes, your system struggles to meet the 24-hour FDA records request when time is critical.
- Record Breakdown Point Recording where the process breaks down will be more useful for defining your requirements than a long list of software features.
The common problem is not always the missing data. It’s the data that exists but can’t be connected quickly. That’s where the GS1 data layer becomes important, helping different systems and trading partners exchange traceability information consistently.
Simplify Regulatory & Audit Compliance in One Platform
Whether preparing for FSMA 204 24-hour record requests, EUDR plot-level geolocations, or upcoming BRCGS and SQF audits, TransGenie automates your end-to-end batch tracking and reporting.
Explore Audit-Ready TraceabilityFood Traceability Compliance Mistakes to Avoid
If you’ve heard any of these recently, they may point to a gap that needs immediate attention.
No accredited certification scheme exists for ISO 22005, so ask what the document actually proves.
That’s actually backwards. Your lot definition should guide the software setup, not be decided by it.
A BRCGS certificate does not automatically satisfy every regulatory requirement. FSMA 204 and EUDR have their own obligations.
Ask which ISO 22095 chain of custody models apply. Mass balance & identity preserved have specific requirements and produce different claims.
Can you produce it within 24 hours for a randomly selected product, even when key people are unavailable?
Rebuilding a mass balance account after a year of production is much harder than recording it correctly from the start.
How to Build a Food Traceability System in Proper Order
A practical traceability programme usually follows this order, because each step gives you the foundation for the next.
- Define Requirements Start by identifying the regulations and requirements that apply to your business. Codex and the relevant regulations define what your traceability system needs to achieve.
- Design the System Use ISO 22005 to design the system. Define your objectives first, then decide what counts as a traceable unit, what a system covers, and what information you need to capture.
- Add GS1 Standards Implement the GS1 layer so that your records can be identified and shared consistently with suppliers, customers, and other trading partners.
- Define Chain of Custody If the claim follows the material, such as sustainable or certified content, apply ISO 22095 and specify the chain of custody models in your contracts.
- Meet Certification Needs Finally, add the traceability certification your customer or market requires, whether that’s ISO 22000 traceability or a relevant GFSI-recognized scheme.
Ready to Build Your End-to-End Traceability System?
Skip messy spreadsheets and rigid custom code. TransGenie gives food processors, manufacturers, and distributors turn-key lot traceability and GS1-compliant data capture.
Book a 1-on-1 Product WalkthroughA Traceability Software That Fits in Your System
Traceability software comes after the system design. The role of the software is to record each product’s movement, link lots to suppliers and customers, store the required traceability data, and quickly provide records during audits, recalls, or regulatory checks.
TransGenie, on the other hand, follows the same approach. You define the products and lots first, then set up the GS1-compatible identification, capture traceability events, and generate the records needed for audits or regulatory requests.
If you’re trying to understand where your current traceability program fits, the TransGenie team can review your existing records and workflows instead of starting with a demo dataset.
Yokesh Sankar