The logic behind the compliance system is fundamentally simple: product data is compared with regulatory rules, resulting in a compliance decision and a document. The complexity arises from the fact that each of these three components is constantly changing.
Why isn't a separate integration system sufficient?
The input for the compliance engine is the company's daily operational data: bill of materials, recipe, supplier records, sales market, and shipping information. Two problems arise when this data is transferred to a separate compliance software. First, the transfer is delayed; second, the data in the two systems becomes decoupled over time.
The bottom line is this: the compliance system evaluates a photograph of the product at a certain time, not the actual product. The recipe has changed, the supplier has changed, the packaging has changed; the compliance system doesn't know this.
Proper handling of missing data.
There are three possible outcomes in compliance assessment, not two: compliant , non-compliant , and data incomplete . Considering the third outcome as "compliant" is the most dangerous mistake in compliance systems.
A well-designed system lists which data is missing for which component of which product and links this list to the supplier request process. Thus, missing data ceases to be a hidden risk and becomes a managed business item.