Blog

19 Jun

KTL News

Comments: No Comments

Tech Corner: What Makes a Good Compliance Management System

Many organizations use compliance management systems to help comply with industry standards (e.g., ISO, GFSI), internal requirements, and/or regulations. These systems range from manual, siloed processes to digital systems that support compliance across departments.

Not all compliance management systems deliver the same benefits. When systems are outdated, fragmented, overly manual, or not tailored, organizations can experience frustration and compliance failures. But when implemented effectively, compliance management systems reduce manual effort, increase consistency, and enhance compliance.

Key Elements of a Robust Compliance Management System

While some organizations still rely on paper, many have transitioned to a digital platform for storing compliance and management system information. However, strong compliance management systems go well beyond simply storing documents. They are designed to help organizations track, manage, and demonstrate adherence to industry standards, internal policies, and government regulations.

Instead of relying on scattered spreadsheets, emails, manual tracking, or even paper trails, a robust compliance management system centralizes compliance activities. This includes:

  • Policy and procedure management.
  • Regulatory and standards monitoring.
  • Risk assessment and control.
  • Audit preparation and reporting.
  • Workflow-driven processes and data collection.
  • Continuous improvement and corrective action.

When implementing a compliance management system, the following key characteristics are important in making sure the system is effective at managing compliance requirements, documents, and activities, and will deliver the most value to the organization:

  • Centralization and Visibility: Provides a single reference point for compliance activities across the organization.
  • Automation of Workflows: Automates repetitive tasks to reduce manual effort.
  • Real-Time Monitoring and Alerts: Creates immediate visibility into compliance status, including alerts.
  • Ease of Use: Employs customizable, user-friendly interfaces to improve adoption and increase user engagement.
  • Audit Readiness: Enables data collection and document management to help organizations quickly demonstrate compliance during audits.
  • Scalability and Flexibility: Is customizable, scalable, and adaptable for when organizations or requirements change vs. following a one-sized-fits-all approach.

KTL’s Approach

KTL’s approach to building a robust compliance management system involves leveraging Microsoft 365 and the Power Platform. This allows us to focus on leveraging what organizations already have (i.e., no new licensing) and building solutions in a phased process to add value to the organization at a comfortable pace.

The general process includes the following steps:

  • Align Technology with Business Needs: KTL works to understand current processes and compliance requirements to tailor the compliance management solution to the organization’s specific needs, resources, and schedule requirements.
  • Follow a Phased Approach: We don’t jump into development; rather, we typically begin with planning and assessing current systems and processes, followed by initial development, review, and refinement. This structured approach helps prioritize needs and build a solution that delivers value while evolving over time.
  • Iterative and Collaborative Development: KTL builds our solutions incrementally with continuous input from stakeholders. This allows for adjustments based on feedback throughout the process to ensure the final system meets real-world needs.
  • Focus on Practical Outcomes: Our goal is to help organizations centralize data, automate workflows, improve reporting, and reduce risk through a scalable compliance management system that enhances efficiency without unnecessary complexity.

Overall, KTL’s approach is about maximizing value from existing technology while delivering a flexible, user-driven compliance solution that grows with the organization.

Get Started

If your organization is looking to build a new or improve an existing compliance management system, KTL can help you navigate this process by assessing your needs and building a strong system that meets your organization’s requirements. Reach out today to schedule a no-obligation demo to discuss how a compliance management system built in the Microsoft ecosystem can improve your compliance processes.



10 Jun

Safety

Comments: No Comments

Celebrating 30 Years of National Safety Month

Every June, the National Safety Council (NSC) observes National Safety Month to bring additional attention to occupational health and safety (OHS) issues, reinforce the importance of having a strong safety culture, and encourage employers and individuals to be safety role models. This June marks 30 years of celebrating National Safety Month and keeping people safe—from the workplace to anyplace.

NSC has established four focus areas for 2026:

  • Moving Safety Forward
  • Staying Safe on the Roads
  • Promoting Holistic Worker Health
  • Preventing Slips, Trips, and Falls

KTL digs deeper into each focus area below:

Moving Safety Forward: OHS Document Management Systems

An OHS Document Management System provides a company-wide framework for central, secure storage and organization of safety-related documents and records to elevate workplace safety and move it forward in the organization. This includes policies, procedures, training records, inspection reports, and regulatory documentation to comply with Occupational Safety and Health Administration (OSHA) requirements.

Safety records often have strict retention and security requirements and must be accessible for an audit at any time. A structured OHS Document Management System can help ensure that these critical files are not only retained according to OSHA requirements, but also are standardized, easily searchable, and available to the right people when they need them. Read more…

Staying Safe on the Roads: Fleet Safety

A fleet is not limited to tractor-trailers or large delivery operations. If employees drive cars, vans, pickups, or other vehicles for work, the organization likely has fleet exposure and should manage it accordingly. Essentially, if vehicles are used in commerce, employers need to define fleet scope; evaluate applicable requirements; and treat driving as a safety, liability, and operational risk issue.

Fleet safety requires several core controls, including a written Fleet Safety Policy, driver screening and qualification, defensive driving training, and refresher training. Policies should address seat belt use; distracted driving; drug and alcohol prohibitions; and reporting of crashes, theft, and vehicle damage. If employees drive for work, fleet safety needs to be formalized to protect employees and the organization. Read more…

Promoting Holistic Worker Health: Psychological Safety

Workplace safety and health goes beyond the physical. A strong safety culture focuses on the whole person, and that includes ensuring psychological safety. Psychological safety is the shared belief that it is okay to take risks, express concerns and ideas, ask questions, speak up, and admit mistakes in the workplace without fear of being punished or humiliated.

Psychological safety is a critical concept for building effective teams and, many would argue, a critical concept for encouraging workplace innovation and success. According to the Center for Creative Leadership research, teams with high degrees of psychological safety report higher levels of performance and lower levels of interpersonal conflict. This is because employees who feel their workplace is psychologically safe are more willing to engage in behaviors that contribute to greater organizational innovation. Read more…

Preventing Slips, Trips, and Falls: Walking-Working Surfaces

Slips, trips, and falls routinely hit the top of OSHA’s Top 10 Violations. Walking-working surfaces include any horizontal, vertical, or inclined surface employees use to walk, work, or access a work area. That includes floors, stairs, ladders, platforms, scaffolds, ramps, and roofs. It’s important to remember that slip, trip, and fall risk is not limited to elevated work. Same-level hazards such as clutter, spills, cracks, holes, unmarked surface changes, and poor housekeeping can be just as significant and need to be managed as routine safety control issues.

OSHA 29 CFR 1910 Subpart D is the primary general industry standard for walking-working surfaces. To meet these standards and keep employees safe, there are several core controls employers should implement, including keeping surfaces clean and orderly, maintaining dry conditions where feasible, correcting defects promptly, ensuring safe access and egress, and confirming surfaces can support intended loads. In short, employers should treat walking-working surface hazards as an inspection, maintenance, and training issue, not just a housekeeping issue. Read more…

Additional Resources

As part of National Safety Month, NSC is offering free resources in these four areas (and more!) to help prevent injuries and safe lives. Check out these resources and take the NSC SafeAtWork Pledge to commit to:

  • Actively helping your employer improve safety programs.  
  • Reporting hazards promptly and suggesting solutions.
  • Being a good safety role model for coworkers, friends, and family, even off the job.
22 May
Tech Corner: Are Your Workflows Working?

Many SharePoint compliance management systems incorporate automated processes powered by workflows to streamline repetitive business processes and keep operations moving. Workflows help streamline manual tasks to maximize resources and increase efficiency. When these workflows break, companies can experience stalled approvals, missed communications, and shift back to manual workarounds.

Recently, many workflows in SharePoint stopped working. So, what happened?

The Root Cause: End of SharePoint Designer Workflows

For years SharePoint relied on workflows built in SharePoint Designer to automate repetitive business processes like approvals, notifications, and task management. However, these workflows were built on legacy technology that does not align with Microsoft’s modern, cloud-first direction. As a result, Microsoft set April 2, 2026, as the official end-of-life for the legacy workflows.

In short, that means workflows that have worked seamlessly for years have been turned off, with no warnings for when the workflows don’t run. In most cases, the only sign of an issue is that critical business processes suddenly stop functioning. This leads to inconsistent manual workarounds, or, in some cases, important tasks just not being completed.

Modern Workflow Solutions

The good news is that legacy workflows can be replaced with modern Microsoft tools, such as Power Automate, Azure Logic Apps, and Co-Pilot Agent Flows.

  • Power Automate provides a user-friendly, low-code platform for building approval processes, notifications, and integrations directly within the Microsoft 365 ecosystem.
  • Azure Logic Apps offer advanced capabilities, including robust integration and greater control over workflow logic for more complex or enterprise-scale scenarios.
  • Co-Pilot Agent Flows introduce deep artificial intelligence (AI) integration into the traditional workflow process, enhancing automation with intelligent decision-making.

These modern tools offer several key advantages to legacy Designer workflows:

  • Enhanced Functionality: Modern workflows integrate with hundreds of connectors across Microsoft 365 and third-party services (e.g., Teams, Outlook, Dynamics, Salesforce).
  • User-Friendly Design: The user interfaces feature a low-code/no-code interface that simplifies workflow creation and maintenance, making automation more accessible to business users.
  • Improved Monitoring and Governance: Built-in analytics and monitoring tools provide greater visibility into workflow performance.
  • AI-Driven Automation: Modern workflows incorporate AI to enhance decision-making, automate content generation, and provide intelligent recommendations.

Getting Your Workflows Working

If you think your workflows are no longer working, leveraging SharePoint experts who can take a structured approach to replacing Designer workflows can help effectively restore them:

  • Assess: Inventory all existing workflows, evaluate which workflows aren’t functioning, identify critical processes, and determine what needs to be migrated, redesigned, or retired.
  • Plan: Determine how each workflow will be recreated, accounting for functional differences and opportunities for improvement.
  • Migrate: Rebuild workflows using modern tools, testing thoroughly to ensure they meet business requirements and function as expected.
  • Optimize: Take advantage of modern capabilities to enhance workflows, integrate additional systems, and improve overall efficiency.

It’s important to note that there is no direct one-to-one conversion from SharePoint Designer workflows to modern workflows. Many workflows will need to be reimagined rather than simply recreated. While this requires effort, it also presents an opportunity to improve processes and reduce complexity.

Moving Forward

The end of SharePoint Designer workflows is no longer a distant future consideration; it is a current reality that organizations must address. Without migration to modern solutions, business processes will continue to fail, leading to disruptions and inefficiencies.

If your organization relied on SharePoint Designer workflows, KTL can help you navigate this required transition by assessing your current environment, redesigning workflows, and implementing modern solutions that restore and improve functionality. Reach out today to schedule a no-obligation demo and ensure your SharePoint environment continues to run effectively.

21 May

Safety

Comments: No Comments

New ASSP Guidelines for Assessing and Managing Risks

In April 2026, the American Society of Safety Professionals (ASSP) published ANSI/ASSP Z310.1-2026, the first U.S.-based standard that provides guidelines for assessing and managing risk across an organization. It establishes principles, a framework, and a process to help organizations develop a structured approach to risk management that builds on concepts published in ISO 31000:2019, Risk Management Principles and Guidelines.

The new ANSI/ASSP standard is intended to provide more practical and simplified implementation-focused guidance, while remaining aligned with the global ISO standard.

Key Elements

ASSP’s new guidelines are designed for organizations of any size or sector to apply them across the organization’s lifecycle and to decision-making at all levels. Importantly, the guidelines expand beyond safety and compliance to inform organizational risk management. Specifically, the guidelines include the following key elements:

  1. Integrate risk management into the organization’s management systems and operations. Risk management should not be treated as a separate or occasional exercise. It should be fully integrated into an organization’s management system, governance, leadership, strategy, and daily operations to help improve decision-making and create business value
  2. Use a structured and consistent approach to risk management. The standard outlines a systematic process to identify, assess, address, monitor, and review risks consistently rather than informally or ad hoc.
  3. Customize the approach to the organization’s context. The risk management approach should be tailored to the organization’s size, sector, operating environment, objectives, and specific risk profile rather than applied as a one-size-fits-all model.
  4. Support decision-making at all levels. The standard supports and informs strategic, tactical, and operational decisions, not just safety or compliance functions.
  5. Engaging stakeholders and being inclusive. Effective risk management should involve relevant internal and external stakeholders to ensure risk information is complete, practical, and actionable.
  6. Using timely, clear, and available information. Risk decisions should be based on current and understandable information; however, the guidance recognizes that decisions often must be made under uncertainty when that information is not available.
  7. Accounting for human and cultural factors. Organizational culture, behavior, and human factors affect how risks emerge, are perceived, and are controlled.
  8. Remaining dynamic and evolving to continually improve. Organizations should anticipate change and monitor new or evolving risks to regularly improve their risk management practices over time.

Aligning with the Standard

ANSI/ASSP Z310.1-2026 is a voluntary guidance standard rather than a regulation. In practice, organizations typically demonstrate alignment by showing that risk management is documented, integrated into decision-making, applied consistently, and reviewed for effectiveness.

Aligning with the new guidelines by taking the following steps will help organizations move from fragmented or reactive risk practices to a more disciplined, organization-wide, decision-focused risk management system:

  • Establish a formal risk management policy or framework tied to organizational objectives. Do we have a documented risk management policy, framework, or equivalent guidance approved by leadership?
  • Define governance and accountability, including leadership oversight, roles, responsibilities, and escalation paths. Are roles, responsibilities, decision rights, and escalation paths for risk management clearly defined?
  • Embed risk review into planning and decision-making such as strategy, projects, operations, procurement, and change management. Is risk management integrated into governance, leadership, strategy, and day-to-day operations rather than treated as a standalone exercise?
  • Create a repeatable risk process for identifying, analyzing, evaluating, treating, monitoring, and communicating risks. Do we use a repeatable process to identify risks across strategic, operational, financial, safety, compliance, and other relevant areas?
  • Document risk criteria and methods so risk ratings and treatment decisions are consistent. Do we apply defined criteria and methods to analyze likelihood, impact, velocity, uncertainty, or other relevant factors and evaluate priorities consistently? Have we tailored the risk management approach to our size, sector, objectives, regulatory environment, and risk profile?
  • Engage relevant stakeholders when identifying and evaluating risks. Are relevant internal and external stakeholders engaged when identifying, assessing, and responding to risks?
  • Use reliable data and review it regularly so decisions reflect current conditions. Is risk information used to support strategic, tactical, and operational decisions at all levels? Do risk decisions rely on timely, clear, and available information, and is that information reviewed regularly?
  • Address culture and human factors in how risks are communicated, accepted, and controlled.  Do we consider human behavior, organizational culture, incentives, competence, and communication when assessing and managing risks?
  • Monitor performance and continually improve through periodic reviews, lessons learned, and updates to controls and processes. Do we monitor internal and external changes and emerging risks and update assessments when conditions change? Do we routinely monitor risk indicators, review control effectiveness, and reassess significant risks? Do we use lessons learned, audits, incidents, and reviews to improve the risk management framework and process over time?

KTL’s team includes experienced risk assessors, risk managers, and safety professionals, who regularly apply the concepts included in the new guidance to help organizations effectively understand and manage their safety and organizational risks. If you need assistance interpreting and applying the ASSP/ANZI Z310.1-2026 standard, please contact KTL.

***
Note: The complete ASSP/ANSI Z310.1-2026 standard can be purchased in the ASSP Store.

11 May
The Future of Food Safety Inspections Under BRIDGE

On January 23, 2026, the Food and Drug Administration (FDA) released its 2026 priority deliverables to further advance the Human Foods Program’s (HFP) vision and mission. As KTL reported, food inspection coverage is a critical deliverable under the Microbiological Food Safety focus area. Central to achieving this goal is the Better Regulatory Inspections for Dynamic Government Efficiency (BRIDGE) Project, a major initiative to modernize how domestic food facility inspections are planned, conducted, and coordinated nationwide. 

The BRIDGE Project represents a significant step forward in the Agency’s vision for a more integrated, data-driven, and risk-based food safety oversight system. So what does this all mean, and how does it change your facility inspections?

What Is the BRIDGE Project?

According to FDA, BRIDGE is intended to improve how inspection, compliance, and risk data are shared and used, and to better align inspection planning toward higher risk areas.

Historically, food facility inspections have been carried out independently by federal and state agencies. While this approach has helped to ensure oversight, it has also resulted in duplication of effort, inconsistent coverage, and inefficient use of limited inspection resources. BRIDGE seeks to address these challenges by creating a more coordinated system that leverages FDA’s state, local, territorial, and tribal (SLTT) partners.

BRIDGE builds on the principles of Domestic Mutual Reliance (DMR), where FDA and SLTT partners rely on each other’s inspections, regulatory actions, and data when programs are comparable. The intent is to further the Food Safety Modernization Act’s (FSMA) goal of an Integrated Food Safety System (IFSS) that emphasizes collaboration and shared responsibility across regulatory partners to protect the food supply.

Objectives of the BRIDGE Project

FDA has outlined a comprehensive set of objectives for BRIDGE, all aimed at improving inspection coverage while maintaining strong public health protections. These objectives include the following:

  • Expanding data sharing across federal and SLTT food safety programs.
  • Modernizing digital systems to support interoperability and analytics.
  • Applying risk-based approaches to inspection frequency and scope.
  • Coordinating inspection planning to reduce duplication and close gaps.
  • Leveraging federal and state expertise and regulatory authorities.
  • Testing and scaling new oversight and inspection models.
  • Aligning workforce training, funding, and performance measures.
  • Establishing a sustainable federal-state partnership model.

Together, these goals support inspections that are more responsive, efficient, and capable of targeting food safety risks that pose the greatest threat to public health.

How BRIDGE Works

BRIDGE takes an evidence-driven approach that allows FDA and its partners to refine processes before incorporating them into routine inspections and oversight as part of FDA’s commitment to an IFSS. Under BRIDGE:

  • Inspection, compliance, and risk data are shared across agencies to improve oversight consistency and identify systemic risks.
  • Inspection planning is coordinated so that federal and SLTT regulators are not inspecting the same facilities unnecessarily.
  • Resources can be scaled and redirected to higher-risk facilities or emerging issues when warranted.
  • New inspection and data-sharing approaches are tested in real-world conditions before being expanded.

What BRIDGE Means for Food Facilities

For food manufacturers and processors, BRIDGE does not eliminate inspections; rather, it changes how inspections may look over time. Facilities may experience:

  • More risk-based inspections, with higher risk operations receiving greater scrutiny.
  • Fewer duplicative inspections from multiple regulatory agencies.
  • Greater reliance on SLTT-led inspections conducted under FDA-aligned standards.
  • Increased use of inspection data and past compliance history to determine inspection frequency and scope.

Facilities with strong compliance programs may see more predictable oversight, while those presenting higher risk may be inspected more frequently or in greater depth. Overall, FDA’s goal is to increase inspection coverage and efficiency without compromising public health protections.

Phased Implementation Timeline

The BRIDGE Project is being implemented in three phases:

  • Phase 1 (June–September 2025): Initial planning and assessment of inspection approaches and infrastructure.
  • Phase 2 (October 2025–December 2027): “Proof of process” phase. Currently underway, FDA and selected state partners and co-regulators are testing new inspection models, data-sharing methods, and system readiness to inform future decisions and broader rollout during Phase 3.
  • Phase 3 (January 2028–December 2030): Planned national implementation of approaches that demonstrate improved coordination, efficiency, and inspection coverage.

By 2030, FDA expects BRIDGE to support a coordinated, data-driven model for domestic food safety oversight nationwide.

What Food Facilities Should Do Now

Although the BRIDGE Project is still being tested and refined during Phase 2, food facilities can take proactive steps today to prepare for a more coordinated, data-driven inspection environment in the future:

  • Monitor BRIDGE developments. Stay informed about FDA communications related to BRIDGE and its inspection modernization efforts. Track guidance updates, pilot findings, or changes to inspection models as Phase 2 progresses.
  • Strengthen food safety and compliance programs. Ensure food safety plans, preventive controls, and standard operating procedures (SOPs) are current and fully implemented. Address recurring observations/findings, as inspection history will increasingly influence risk-based inspection planning, and verify that corrective actions are implemented and documented.
  • Improve documentation and data readiness. Maintain complete, organized, and easily accessible inspection records, audit reports, and compliance documentation. A compliance management system can help ensure records are accurate and consistent across internal systems. Prepare for inspectors to rely heavily on historical compliance data when determining inspection scope and frequency.
  • Be inspection-ready at any time. Conduct periodic internal audits to identify gaps in food safety programs and compliance. Train staff to interact with state and federal inspectors, including knowing where records are kept and who is authorized to respond to questions.
  • Recognize the importance of risk-based oversight. Understand how your facility’s risk profile (based on product type, process, compliance history, and food safety performance) may affect inspection frequency. Proactively manage higher risk processes and products to reduce regulatory scrutiny.
  • Foster a strong food safety culture. Reinforce food safety expectations at all levels of the organization and promote continuous improvement, not just inspection-driven compliance.

An Evolution in Oversight

FDA’s BRIDGE Project represents an evolution in food safety oversight toward a coordinated, integrated system that uses shared data and risk-based decision-making. For food facilities, this means inspections will become increasingly targeted, data-informed, and aligned across regulatory partners.

As BRIDGE continues through the Phase 2 testing period, food companies should remain focused on compliance, documentation, and food safety culture, as inspection outcomes and shared data will play a growing role in how oversight is planned in the years ahead.

23 Apr

KTL News

Comments: No Comments

Community Involvement in Action: April Greene Joins KNIB Board

KTL Senior Associate April Greene, CSP, CHMM, was recently invited to join the Board of Directors for Keep Northern Illinois Beautiful (KNIB), an affiliate of Keep America Beautiful. KNIB is an environmental resource center that aims to inspire and educate citizens to take action to improve and beautify their community and environment through waste reduction, recycling, and resource conservation.

A resident of Northern Illinois, April brings over 10 years of environmental, health, and safety (EHS), quality, and food safety experience to her KNIB Board position. She has created corporate programs, plans, policies, and procedures to ensure compliance with regulatory and sustainability requirements, as well as a company Zero Landfill Policy by finding creative and innovative solutions for end-of-life material through lifecycle analysis.

As part of the KNIB Board, April is joining a positive force for environmental stewardship and promoting KNIB’s mission to improve the environment through education, public awareness, and community involvement.

20 Apr

KTL News

Comments: No Comments

Top Food Supplier Audit Findings & How to Mitigate Them

Supplier audits play a critical role in protecting food product safety and quality, regulatory compliance, and consumer trust. As food companies continue to expand their networks of co-manufacturers, ingredient suppliers, and packaging partners, the ability to identify and address systemic weaknesses has never been more important.

Turning Risks into Opportunities

KTL conducts second-party supplier audits across the food supply chain to assess compliance with Food and Drug Administration (FDA), U.S. Department of Agriculture (USDA), and Global Food Safety Initiative (GFSI) standard requirements. These audits have revealed a familiar pattern of vulnerabilities that can pose significant risks if left uncorrected or opportunities to strengthen food safety programs if addressed.

The findings below represent some of the most common nonconformances KTL routinely observes when conducting supplier audits across the food industry and recommendations for how to mitigate them.

FDA/USDA Findings

  • Insufficient cleaning and quality inspection before area/equipment release. This is generally a result of sanitation procedures not being consistently followed, documented, or effective and/or pre‑operational (pre-op) inspections not being thoroughly performed. This gap increases the risk of cross‑contamination, introduction of foreign material, and microbial hazards. Recommendations:
    • Implement validated cleaning procedures with defined steps, tools, and chemicals.
    • Use ATP swabbing or microbiological verification before releasing equipment.
    • Conduct pre‑op inspections using standardized checklists.
    • Train sanitation teams and supervisors on verification processes and expectations.
  • Noncompliance with personnel Good Manufacturing Practices (GMP) requirements. Employees may not be consistently following hygiene requirements, such as handwashing, proper gowning, restricted jewelry, or safe food handling behavior. Recommendations:
    • Provide routine GMP training and refresher sessions.
    • Conduct daily GMP walk‑throughs with related coaching, as needed.
    • Improve signage and visual cues in production areas (e.g., handwashing signs in bathrooms, color coding).
  • Inadequate process validation. Process validation helps ensure that critical steps (e.g., cooking, cooling, packaging) consistently deliver the intended food safety outcome. Inadequacies suggest missing scientific data or incomplete validation records. Recommendations:
    • Validate all critical control points (CCPs) using scientific studies or in‑plant data.
    • Document process parameters (e.g., time, temperature, pressure) clearly.
    • Revalidate after equipment changes, formulation changes, or facility modifications.
  • Improper handling and storage of materials. Improper material handling (e.g., incorrect temperatures, poor first-in-first-out (FIFO)/first-expired-first out (FEFO) rotation, or exposure to contaminants) can degrade product quality or safety. Recommendations:
    • Enforce FIFO/FEFO inventory practices.
    • Maintain temperature logs for refrigerated/frozen storage.
    • Segregate allergens and chemicals to prevent cross‑contact or contamination.
    • Train warehouse and production teams on handling and storage requirements.

GFSI Findings

  • Noncompliance with visitor requirements. Visitors may not be following necessary GMP or biosecurity protocols (e.g., sign‑in, health questionnaires, protective clothing) or the facility may not be properly enforcing procedures, increasing the risk of foreign contamination. Recommendations:
    • Establish a formal Visitor Policy with mandatory orientation.
    • Provide required personal protective equipment (PPE) to visitors and escort them throughout the facility.
    • Maintain accurate visitor logs and health screening records.
  • Poor facility maintenance and cleaning. Maintenance deficiencies (e.g., damaged floors, standing water, or buildup in hard‑to‑clean areas) can create harborage points for pests or pathogens. Recommendations:
    • Create a Preventive Maintenance (PM) Program with documented schedules.
    • Address structural issues promptly (e.g., cracked tiles, peeling paint).
    • Perform routine deep cleaning of facility infrastructure.
  • Lack of verification of corrective actions taken. This indicates that corrective actions are being implemented; however, no follow‑up verification is occurring to ensure the issue is effectively resolved. This can lead to recurring nonconformances.Recommendations:
    • Require verification (i.e., inspection, testing, documentation) after every corrective action.
    • Track corrective actions to closure and monitor for recurrence trends.
    • Use root cause analysis tools (e.g., 5‑Why, Fishbone) to address systemic issues.
  • Poor environmental monitoring. The Environmental Monitoring Program (EMP) may be missing, outdated, or insufficient. Weak EMPs fail to detect pathogens like Listeria or Salmonella in time to prevent contamination. Recommendations:
    • Design a robust EMP with Zone 1–4 sampling.
    • Perform routine microbiological testing and trend analysis.
    • Investigate any positive results with immediate containment and vector sampling.
  • Lack of pest control mitigation when issues arise. Pest activity is being detected, but corrective measures are not timely or effective in mitigating pest concerns. This can jeopardize both food safety and regulatory compliance. Recommendations:
    • Partner with a licensed pest control operator (PCO) to conduct routine inspections.
    • Implement corrective action steps immediately after any pest activity; track corrective actions to closure.
    • Seal facility gaps, maintain landscaping, and eliminate pest attractants (e.g., standing water, waste).
    • Trend pest control data to identify patterns.

Leveraging Internal Audits

While many of the findings listed above are common, they are also highly preventable if organizations know what to look for. Supplier audits remain one of the most powerful tools for uncovering these weaknesses before they escalate into safety or compliance failures that present significant risk. Beyond compliance, leveraging audit results can help organizations make decisions and require supplier improvements that strengthen brand reputation, reduce operational risk, and create a culture where food safety is embedded in every decision and behavior.

16 Apr

KTL News

Comments: No Comments

Tech Corner: Supplier Management Tools for Better Results

Effectively managing supplier data, documents and records, and performance across a large supplier network requires consistent processes and data management practices to effectively verify food safety compliance and mitigate associated risks. Integrating standardized tools and information management solutions can significantly improve supplier program efficiency and streamline supplier management.

Supplier Management System

KTL’s Supplier Management System comprises custom tools built using Microsoft 365 and the Power Platform to streamline how an organization approves and manages suppliers, help control costs and reduce risk, and support compliance with internal requirements and regulations (e.g., Food Safety Modernization Act (FSMA) Foreign Supplier Verification Program (FSVP) Rule).

The Supplier Management System comprises the following:

  • Centralized Supplier Inventory: Maintains a centralized list of all suppliers the organization works with. This includes key details such as contact information, supplied products or services, certifications, supplier-specific requirements, compliance status, performance history, and facility‑specific requirements.
  • Supplier Risk Assessment: Evaluates potential and existing suppliers by identifying and analyzing factors that could introduce risk into the supply chain. It examines elements such as compliance status, performance history, documentation quality, and contract adherence. The tool captures any identified risks and helps ensure they are documented, monitored, and addressed as part of an ongoing Supplier Management Program.
  • Supplier Documents and Records Management: Provides secure and centralized storage and organization of supplier documents and records. When enabled, suppliers can upload their own documents in a secure folder, reducing internal resource requirements. This tool allows for improved document searchability and accessibility, a clear audit trail, and reduced paperwork.
  • Supplier Approval Workflow: Supports a structured, standardized process for both the initial approval and ongoing re-evaluation of suppliers to ensure continued compliance with organizational, regulatory, and performance requirements. This feature uses a standard checklist to review certifications, licenses, risk indicators, and performance history to consistently evaluate suppliers. Through a repeatable process, organizations can reassess supplier performance over time, confirm ongoing compliance, and identify emerging risks or gaps that may require corrective action or follow-up.

Together, these features provide a comprehensive approach to supplier management that improves visibility, consistency, and accountability regarding supplier performance. Implementing a robust Supplier Management System like this can significantly help organizations strengthen supplier relationships, reduce operational and compliance risk, and maintain confidence in their supply chain, particularly when paired with regular supplier audits.

Connecting Supplier Audits

As food companies continue to expand their networks of co-manufacturers, ingredient suppliers, and packaging partners, the ability to identify and address systemic weaknesses has never been more important. Onsite supplier audits are a critical component of an effective Supplier Program, providing direct visibility into supplier operations; verifying compliance with organizational, regulatory, and contractual requirements; and protecting food product safety and quality.

KTL’s Microsoft 365-based Audit Tool provides a consistent, data-driven means to conduct, document, and manage onsite supplier audits. The tool allows auditors to capture and verify audit evidence (i.e., compliance status, operational practices), standardizes audit protocol and criteria, and tracks audit progress from initiation through completion. It also monitors identified corrective and preventive actions (CAPAs) for each supplier, allowing organizations to quickly assess resolution status and trends.

Centralizing audit data and insights as part of the overall Supplier Program helps inform decision-making regarding suppliers, strengthen supplier performance, maintain ongoing compliance, and drive continuous improvement.

Learn More at the Food Safety Summit

Join KTL at the 2026 Food Safety Summit in the Tech Tent on May 14 at 10:30 a.m. to learn more about the various tools that can improve Supplier Program efficiency and streamline supplier management, including:

  • The value of onsite second-party supplier audits.
  • Common supplier audit findings and how to address them.
  • How supplier auditing tools streamline audit management.
  • Ways to centralize and analyze supplier audit data.
  • How data-driven tools improve supplier risk prioritization and program efficiency.
01 Apr
KTL Talks Food Safety, IT & Supplier Programs at the Food Safety Summit

Join KTL at one of the premier events in the food industry–the 2026 Food Safety Summit. The Summit offers a unique opportunity for attendees to learn real-world solutions from leaders in food safety and stay informed on the latest food safety trends, innovations, emerging challenges, and more.

  • When: May 11-14, 2026
  • Where: Donald Stephens Convention Center, Rosemont, Illinois
  • Who: Retailers, food processors, distributors, food manufacturers, growers, food service, testing laboratories, importing/exporting, law firms, and other food safety professionals
  • Find KTL: Stop by our booth (#501) in the exhibit hall or attend our Tech Tent presentation (details below)!

Tech Tent Presentation

Be sure to update your agenda to attend KTL’s Tech Tent presentation on Thursday, May 14 at 10:45 am CT:

Supplier Audits: Strategies and Tools for Better Results

A wider reaching and more complex global supply chain exposes our food to increased risks. Supplier audits are essential for identifying and mitigating those risks. Managing audit data, corrective actions, and supplier performance across a large supplier network requires standardized processes and data management tools to effectively verify food safety compliance.

This presentation will highlight strategies for strengthening supplier programs, reducing risks, and improving performance using supplier audits and centralized data management systems.

Attendees will learn:

  • How data-driven tools improve supplier risk prioritization and program efficiency.
  • The value of onsite second-party supplier audits.
  • Common supplier audit findings and how to address them.
  • How supplier auditing tools streamline audit management.
  • Ways to centralize and analyze supplier audit data.
25 Mar
ISO 14001:2026…What You Need to Know

ISO 14001 is the international standard for Environmental Management Systems (EMS). It serves as a management tool for voluntary use by organizations to help improve environmental performance and minimize environmental risks following a plan-do-check-act (PDCA) approach. ISO 14001 was first published in 1996 by the International Standard for Organization. It has since been updated with revised versions in 2004 and 2015. The recent ISO 14001:2026 revision—published in April 2026—marks the first major update to the ISO 14001 standard since 2015.

Impetus for Change

The global sustainability landscape has shifted significantly since ISO 14001:2015 was published, prompting the 2026 updates. Organizations face more stringent regulatory requirements; greater supply chain scrutiny; and heightened demand for environmental, social, and governance (ESG) transparency and accountability. The ISO 14001:2026 updates refine, strengthen, and modernize EMS requirements to align the standard with growing environmental and sustainability pressures and increasing stakeholder expectations.

In addition, ISO 14001:2026 implements the Harmonized Structure (Annex SL) to align with other ISO management system standards. This standard structure allows for easier integration between management systems and improved efficiencies due to familiar terminology and sections. The standard also now includes at what point in the PDCA cycle each clause lands. While this isn’t new for ISO, it is new for ISO 14001:2026.

Major Clause‑Level Changes

The ISO 14001:2026 revision incorporates changes to enhance climate awareness, lifecycle responsibility, supplier oversight, and leadership accountability. The table below outlines the major clause-level changes in the revised standard.

In addition to the major clause changes outlined above, the updated standard:

  • Encourages the use of digital tools and data analytics to improve environmental performance and evidence‑based decision‑making.
  • Introduces clearer, more accessible wording, as well as improved examples and explanations in Annex A.
  • Embeds stronger expectations for integrity, transparency, and environmental governance at the leadership level.­

Transition Timeline: How to Prepare

Organizations will have a three‑year transition period to switch to the new standard. Taking the time to adapt and integrate the new provisions into their operations now will help ensure certification when the transition period is over:

  • Get informed! Start reading up on ISO 14001:2026 to get familiar with how the new standard is structured and how the clause changes impact your organization.
  • Conduct a gap assessment to identify gaps in your existing EMS that will need to be addressed to meet new requirements. If you don’t have an existing EMS, review the requirements and determine what pieces you may already have in place to pursue certification.
  • Develop an implementation plan that integrates leadership accountability, new change management processes, expanded documentation expectations, and more rigorous climate and biodiversity integration. There is a three-year transition period. Plan according to this timeline.
  • Provide training. It is vital to ensure that workers and management are engaged in the EMS and that they are competent in any new skills/responsibilities that may be required.
  • Put your plan into action. Update/develop your EMS to meet the ISO 14001:2026 requirements and provide verification of its effectiveness to help ensure certification when the three-year transition period is over.
Sidebar: