Under FSMA, most food facility records must be kept for a minimum of two years from the date they were created or obtained. The U.S. Food and Drug Administration also requires that records be retrievable within 24 hours of a request, which means storage alone is not enough. Your single most important action right now: verify that your sensor exports and monitoring logs are accessible from your facility and contain the required metadata on every entry.
Three immediate steps to ensure compliance:
- Assign a records custodian who owns retrieval and knows where every log type lives.
- Pull a recent sensor export and confirm it includes facility name, date, time, measured values, and operator signature on each entry.
- Spot-check five corrective action records for completeness. Missing signatures or backdated entries are the most common triggers for FDA-483 observations.
Table of Contents
- What records does FSMA require your facility to keep?
- How long do you need to keep each type of FSMA record?
- What metadata must every FSMA record entry include?
- How to manage digital records from sensor systems
- Building an audit-ready traceability plan for FTL foods
- How to prepare your records and staff for an FDA inspection
- A short retention-policy template your team can use today
- Key Takeaways
- The part most facilities get wrong
- Gembalabs makes FSMA record retention easier to manage
- Useful sources and recommended reading
What records does FSMA require your facility to keep?
FSMA's prevention-based model generates several distinct record categories. Each one maps to a specific part of your food safety system.
| Record Type | What It Documents | Why It Exists |
|---|---|---|
| Monitoring logs | CCP/preventive control measurements | Proves controls ran as designed |
| Corrective action records | Deviations and responses | Demonstrates the facility acted on failures |
| Verification records | Calibration, review, and re-analysis | Confirms controls remain effective |
| Supplier/supply-chain records | Approved supplier program, COAs | Supports prevention at the ingredient level |
| Training logs | Employee food safety training completion | Shows personnel are qualified |
| Sanitation logs | Sanitation monitoring and corrective actions | Documents prerequisite program execution |
| Calibration records | Equipment calibration results and schedules | Ties measurement accuracy to control validity |
| Traceability/FTL records | KDEs for Food Traceability List items | Enables rapid trace-back for high-risk foods |
The food safety plan itself is a special case: it must remain on-site at the facility at all times. Other records may move off-site after six months, provided they can be retrieved within 24 hours. For facilities handling Food Traceability List items, the traceability records carry their own key data element (KDE) requirements on top of standard monitoring documentation. A daily production report is a practical way to capture several of these categories in one place.
How long do you need to keep each type of FSMA record?
The FSMA baseline is two years for most records. Equipment and process adequacy records carry a two-year post-use retention requirement after the equipment or process is discontinued. FSMA is not your only clock, though.

| Record Category | FSMA Minimum | Common Longer Requirement |
|---|---|---|
| Monitoring, corrective action, verification | 2 years | Insurance/contract: often 3–5 years |
| Food safety plan | On-site, no defined end | Retain while in use + 2 years after revision |
| Equipment/process adequacy records | 2 years post-use | Warranty or insurer may require longer |
| FTL traceability records (KDEs) | 2 years | Per traceability rule |
| Tax and employment records | N/A (IRS governs) | 3–7 years depending on situation |
| Training and HR records | 2 years | Employment law often requires 3+ years |
Professional guidance recommends annual policy review to reconcile FSMA minimums with what your insurer, tax advisor, or contracts actually require. Employment tax records must be kept for the period required by the IRS. A note on the traceability rule: FDA has proposed extending the compliance date for certain FTL recordkeeping requirements to July 20, 2028, though facilities should treat current requirements as active and prepare accordingly.
What metadata must every FSMA record entry include?
Records must be created contemporaneously — at the time of the activity, not reconstructed later. That rule catches more facilities than almost any other requirement.
Required metadata fields for each entry:
- Facility name and location
- Date and time of the activity (not the shift end, not the next morning)
- Measured values with units (temperature in °F, pH, water activity, etc.)
- Product and lot identification where applicable
- Operator name or initials (signature for paper; authenticated login for electronic)
- Method of measurement (instrument ID, sensor tag, or manual method)
A sample sensor-log entry looks like this:
| Field | Example Value |
|---|---|
| Facility | Riverside Bakery, Unit 2 |
| Date/Time | 2026-04-14 |
| Measured Value | Internal temp: — |
| Product/Lot | Whole wheat bread / Lot 2604-14A |
| Operator | J. Martinez (login ID: jm04) |
| Instrument | Oven sensor S-—, calibrated 2026-03 |
Sensor systems that auto-populate facility name, timestamp, and measured value cover most of this checklist. The gap is almost always the operator field. Build operator authentication into your sensor workflow so the human sign-off is captured at the moment of the reading, not added later.
How to manage digital records from sensor systems
Electronic records are considered "on-site" only if the facility can retrieve them within FDA's 24-hour window. Cloud storage is fine, but you need a tested process to produce the records locally on demand.
Practical controls to put in place:
- Immutable audit trails: records must not be editable after creation; any correction should create a new entry with a reason note, not overwrite the original.
- Synchronized timestamps: use NTP (Network Time Protocol) to keep sensor clocks aligned; a one-hour drift between a sensor log and an operator entry is a red flag in an inspection.
- Tamper-evident exports: export files should carry a hash or checksum so you can demonstrate the data has not been altered since export.
- Readable formats: CSV or spreadsheet exports that any inspector can open without proprietary software. Hardware and software obsolescence is not an acceptable reason for inaccessible records.
- Backup and archival strategy: at minimum, one off-site backup with a tested restore process, and a migration plan for when you upgrade platforms.
Pro Tip: Run a retrieval drill quarterly. Simulate an FDA request: pick a lot number and a date range, then time how long it takes to produce a complete, readable export. If it takes more than two hours, your process needs work before an inspector shows up.
For a deeper look at how real-time equipment monitoring maps to these requirements, the sensor-to-record workflow is worth reviewing before your next internal audit.

Building an audit-ready traceability plan for FTL foods
A traceability plan is a written document that explains how your facility identifies, tracks, and retrieves critical tracking events (CTEs) and key data elements (KDEs) for Food Traceability List items. Attach it to your food safety plan as a standalone section.
Your traceability plan should cover:
- Which FTL foods you handle and at which CTEs (receiving, transformation, shipping)
- How each KDE is captured (sensor, label scan, manual entry) and where it is stored
- Who is responsible for retrieval and how they access the records
- The format in which records will be produced (electronic sortable spreadsheet per FDA guidance)
- Third-party hosting arrangements, if any, with confirmation that records remain retrievable within 24 hours
Steps to build the plan:
- List every FTL food in your facility and the CTEs your operation performs on each.
- Map each CTE to the data source (sensor tag, receiving log, shipping manifest).
- Assign a named custodian for each record type.
- Document the retrieval procedure step by step, including login credentials and export path.
- Run a mock retrieval: give a team member a lot number and ask them to produce the full KDE record set within one hour. Document the result.
For a practical template, the traceability guide for food manufacturers covers CTE mapping in detail.
How to prepare your records and staff for an FDA inspection
Inspectors move fast. The most common findings — missing signatures, backdated entries, and gaps in monitoring logs — can escalate directly to warning letters if not corrected.
| Pre-Audit Step | Owner | Timing |
|---|---|---|
| Designate records custodian | Operations manager | Permanent role |
| Index records by lot number and date | Records custodian | Ongoing |
| Run cloud export retrieval drill | IT/operations | Quarterly |
| Spot-check five recent entries for metadata completeness | Production lead | Monthly |
| Verify all corrective action records are closed and signed | QA lead | Before any inspection |
Sample inspector requests to practice:
- "Provide all monitoring records for Lot 2604-14A from April 14, 2026."
- "Show me the corrective action taken when the oven temperature dropped below the critical limit on the morning shift."
- "Produce your traceability records for all FTL items received in the last 30 days."
Regular internal audits help catch trivial issues — missing initials, unreadable values — before they become inspection findings. Build the drill into your production calendar, not as a one-time event.
A short retention-policy template your team can use today
A written retention policy does two things: it tells staff what to keep and for how long, and it gives you a defensible record of your own governance decisions.
Policy template structure:
- Scope: which records and facilities this policy covers
- Retention schedule: record type, minimum period, owner, storage location
- Archival procedure: how records move from active to archive after six months
- Destruction procedure: how records are securely deleted or shredded at end-of-life, with a disposition log entry for each batch destroyed
- Review cadence: annual review, signed by the operations manager, with version number and date
Governance checklist:
- Reconcile FSMA minimums with IRS, insurer, and contract requirements annually.
- Document every policy change with a version number and effective date.
- Keep a destruction log: record type, date range destroyed, method, and who authorized it.
- Confirm that archived digital files remain readable after platform upgrades.
Pro Tip: When you destroy records at end-of-life, log the destruction. An undocumented gap in your records looks the same as a missing record to an inspector. A one-line entry — "Monitoring logs 2022-Q1, destroyed 2026-04-15, shredded, authorized by J. Smith" — closes that gap.
Key Takeaways
FSMA requires a minimum retention period for most food facility records, records must be retrievable within a day of a request, and contemporaneous entry with complete metadata on every log.
| Point | Details |
|---|---|
| Two-year baseline | Most FSMA records must be kept for at least two years from creation or receipt. |
| 24-hour retrieval | Electronic records in cloud storage must be producible within 24 hours; test this with quarterly drills. |
| Metadata on every entry | Each record needs facility name, date, time, measured values, lot ID, and operator signature. |
| Annual policy review | Reconcile FSMA minimums with IRS, insurance, and contract requirements every year. |
| Gembalabs integration | Gembalabs captures timestamped sensor data alongside operator inputs, covering the metadata and contemporaneous-entry requirements in one workflow. |
The part most facilities get wrong
The compliance conversation almost always focuses on how long to keep records. The harder problem is the metadata gap: a perfectly retained log that is missing operator signatures or has mismatched timestamps is treated the same as no record at all during an inspection.
The fix is not more storage. It is closing the loop between your sensor stream and your human sign-off at the moment of the activity. Time-sync errors between a sensor and an operator entry are easy to miss until an inspector lines them up side by side. A quarterly drill where someone actually pulls a lot record and reads it critically, not just confirms it exists, catches these problems early. The standard work practices that formalize operator documentation are worth the effort before an inspection, not after.
Gembalabs makes FSMA record retention easier to manage
Food manufacturers using sensor-based monitoring already generate most of the data FSMA requires. The gap is usually in how that data is captured, linked to operator inputs, and made retrievable on demand.

Gembalabs connects equipment sensor streams with operator-entered verification notes in a single workflow, so every monitoring record carries the metadata an inspector expects: facility, timestamp, measured value, and authenticated operator input. Exports are formatted as readable spreadsheets, and the audit trail is tamper-evident by design. For small and mid-sized facilities that need to meet the 24-hour retrieval window without a dedicated IT team, that combination matters. Bilingual support (English and Spanish) means your operators can enter notes accurately in the language they work in, which reduces transcription errors in the record.
See how the intelligence features map to your FSMA obligations, or request a pilot to walk through your specific record types and retrieval workflow.
Useful sources and recommended reading
| Source | What It Covers | Best Used For |
|---|---|---|
| FDA Food Traceability Rule Q&A | KDEs, CTEs, 24-hour retrieval, compliance timeline | Traceability plan, retention timeline |
| eCFR 21 CFR Part 117, Subpart F | Electronic records, on-site accessibility rules | Digital records, audit preparation |
| Preventive Controls recordkeeping guidance | Contemporaneous entry, food safety plan retention | Metadata requirements, what records section |
| IRS records retention guidance | Tax record retention periods (3–7 years) | Annual policy reconciliation |
| ICPAS retention guidelines | Annual review, financial/operational retention | Retention policy template |
| NY State Archives retention guidance | Obsolescence, readable formats, destruction | Digital records best practices |
| LegalClarity FSMA recordkeeping | Common inspection findings, 483 observations | Audit preparation, pre-audit checklist |
This article is general information, not legal or regulatory advice. Confirm current requirements with the FDA's official guidance pages or a qualified food safety professional for your specific situation.
