All blueprints

Recall management.

The exact population, each consignee and evidence of effectiveness.

Illustration of a seal beside an open evidence folio containing SOP, training and execution records.
A product recall propagating from health-hazard evaluation through lots, consignees, returns and effectiveness checks

Recall population propagation

Scroll to explore the full-size diagram.

How to read this diagram

Scope is versioned from genealogy, then reconciled through direct and onward distribution to effectiveness and termination.

Risk
Health hazard, uncertainty and classification establish the required action.
Scope v03
Three lots are included; one is excluded with filter and batch genealogy.
Field
Direct and onward consignee populations keep separate contact and product states.
Termination
Open units, contacts and failed checks remain explicit release gates.

Figure 1. Fictional market action RA-024. Scope v03 covers three lots and 18,420 units, with lot L2403 excluded through filter lineage. All 42 direct consignees have been notified, and 5,376 units, 3 consignees and 4 checks remain open before termination.

Summary

The problem
A recall run from shipment lists and a mailing list can miss affected consignees or remove unaffected product, and quantities are recounted for every status report.
Seal’s approach
The recall case connects the signal, health-hazard evaluation, genealogy, distribution, consignee responses, corrections and reconciliation, so scope and progress can be explained at each step.
What changes
Each consignee is a tracked obligation, effectiveness checks test whether product was actually controlled, and termination rests on evidence rather than elapsed time.
Where to start
One difficult multi-market scenario run as a mock recall. Book a demo.

1A recall must reach the right population, not only move quickly.

A recall is a controlled response to product that has left the manufacturer’s direct control. Speed matters, but speed without the correct scope creates two risks: failing to reach affected patients, and removing unaffected product during a shortage.

Seal keeps the recall as one case, from the initiating signal and health-hazard evaluation through affected lots, genealogy, distribution, consignee responses, reconciliation, status reports and termination.¹ Each step draws on the records the previous one produced, so the scope and progress of the action can be explained at any point.

1.1Why teams choose Seal for recalls

A recall run from an ERP shipment list, a mailing tool and a spreadsheet of responses recounts its quantities for every status report. Because manufacturing genealogy, packaging, serials, inventory, distribution, complaints, quality events and communications are related in Seal, the recall can show that the right population was identified, reached, controlled, reconciled and evaluated through termination. Scope is derived from the genealogy rather than estimated from shipments, and each status report reads the same case.

Table 1. Where a connected recall differs from one managed as a mailing exercise.
Recall run from a mailing listSeal
ScopeLots listed from a spreadsheetDerived from genealogy, with each inclusion and exclusion justified
ConsigneesA contact listEach consignee tracked from notification to closure
EffectivenessDelivery receiptsDefined checks on whether product was identified and controlled
QuantitiesRecounted for each status reportA running balance of distributed, returned, corrected, destroyed and open units

2Keep the signal and the hazard evaluation with the action.

A complaint, adverse event, OOS result, stability failure, supplier alert, labelling error or authority request can start an assessment. The original signal, its evidence, the detection and awareness dates, the products involved and the immediate containment remain on the record as understanding changes.

The health-hazard evaluation sets urgency and depth. It weighs the failure mode, exposure, severity, probability, vulnerable populations, reversibility, existing controls and distributed quantity, with medical or technical assessment, and it records dissent and uncertainty. The company’s proposed classification does not replace the authority’s decision in each jurisdiction.

3Start broad, then make the scope precise.

The initial population can be wide: potentially affected products, lots, serials, sites, lines, components, suppliers or labelling versions. Expanding or narrowing it records the evidence, rationale, approver and time. A root cause found later does not rewrite the earlier containment decision.

Genealogy makes the scope precise. Materials, intermediates, packaging orders, labels, serials and released inventory can be traced forward and backward, and transformations that merge or split material keep their contributions and destinations. The scope can then distinguish units made before and after an equipment intervention or an artwork change.

Supplier lot RM-0417

Quality notification

12 containers

8 on hand

4 consumed

Figure 2. A supplier quality notification traced from the affected lot to its containers and the work that consumed them, giving a bounded scope with the reason for each exclusion preserved

Distribution records then identify who received what: consignee, country, shipment, lot, serial, quantity, date and onward distribution where it is known.² Returned, used, quarantined, destroyed and unknown states stay separate rather than being folded into one “recovered” figure.

4Approve the strategy as an executable plan.

The action type, depth, classification, channels, consignee instructions, effectiveness-check design, status-report frequency and termination criteria are approved together. Different markets and product types can follow coordinated strategies without collapsing their legal differences.

Communications come from controlled facts. Product identity, affected lots, hazard, required actions, contacts and deadlines resolve from the approved strategy. Each letter, email, portal notice or phone script keeps its version, approval, recipients, send event, delivery and acknowledgement.

5Track every consignee and check effectiveness.

Each consignee becomes a tracked obligation: contact attempts, acknowledgement, stock on hand, onward distribution, returns, corrections, questions and closure. Escalation prioritises non-responders by risk, quantity and time.

The effectiveness plan defines the sample population, selection method, attempts, questions, evidence and acceptance criteria before checks begin, and checks stay independent of routine chasing where required. A delivered email is not evidence that affected product was identified and controlled.

Notification, acknowledgement, inventory response, return or correction, verification sample, exceptions and completion form a measurable effectiveness system
Figure 3. Notification, acknowledgement, inventory response, return or correction, verification sample, exceptions and completion form a measurable effectiveness system

6Reconcile the physical product continuously.

Distributed, returned, corrected, destroyed, used and unaccounted quantities form a running balance. Units and quantity bases stay explicit, and serialised and non-serialised populations can coexist without false precision.

Field corrections, relabelling, software updates and replacements follow controlled instructions carried out by qualified personnel. The actual unit or lot state, the work performed and its verification remain traceable, and a failed or incomplete correction returns to the action queue.

7Report from the record and terminate on evidence.

Initial notification, classification, status reports, effectiveness results and proposed termination keep their jurisdiction, version, questions and commitments. Status reports are generated from the current record and fixed as submitted, with later corrections traceable. One defect can lead to recalls in several markets and a device correction; shared evidence and genealogy stay connected while each action keeps its own authority, scope and clocks.

Termination depends on evidence, not elapsed time: response and recovery, correction completion, effectiveness results, reconciliation, product disposition, authority commitments and residual risk. A closed recall remains on record, and complaints and CAPA continue against the historical population.

ERP, WMS, serialisation repositories and distributor systems can remain authoritative for their own records, and Seal does not invent distribution events that partners cannot provide. Seal owns the recall case, the population logic, the obligations, the reconciliation and the decisions.

8Rehearse one difficult recall end to end.

Recall arrangements should be evaluated periodically for their effectiveness.³ Mock recalls used for that evaluation should test difficult branches and stale master data, not only the most recent batch. Start from a supplier defect affecting part of several lots. Trace it through packaging and mixed distribution, approve a multi-market strategy, notify direct and indirect consignees, manage non-responders, returns and corrections, sample effectiveness, reconcile quantities, report status and reach termination.

Include incomplete genealogy, a stale contact, onward distribution, a serial mismatch, a failed field correction and a scope expansion. The model is ready when every unknown remains explicit and has an owner.

References

  1. 121 CFR Part 7, Subpart C, Recalls (Including Product Corrections)—Guidance on Policy, Procedures, and Industry Responsibilities. eCFR
  2. 221 CFR 211.150, Distribution procedures: written distribution procedures must include a system by which the distribution of each lot can be readily determined to facilitate recall. eCFR
  3. 3EudraLex Volume 4, Part I, Chapter 8, Complaints, Quality Defects and Product Recalls (2014). European Commission

AOperating model

Included in this blueprint

  • Health-hazard evaluation
  • Genealogy-based scope
  • Recall strategy and authority
  • Consignee notification
  • Effectiveness checks
  • Product reconciliation
  • Status and termination evidence

Connected across Seal

BCapabilities

Table B.1. What the Product Recall and Market Action Management blueprint covers. Linked capabilities are blueprints of their own.
CapabilityWhat it covers
Health-hazard evaluationWeigh the failure mode, exposure, severity, probability, vulnerable populations and distributed quantity, with the uncertainty, classification and approval recorded.
Genealogy-based scopeTrace materials, lots, serials, packaging and shipments to define the potentially affected population. Each scope version records why items were included or excluded.
Recall strategy and authorityApprove the action type, depth, channels, consignee instructions, effectiveness-check design, status-report frequency and termination criteria together.
Consignee notificationSend communications built from the approved facts, and track each consignee’s acknowledgement, stock on hand, onward distribution, questions and escalation.
Returns and field correctionsReturns, relabelling, software updates and replacements follow controlled instructions, and each unit or lot keeps its custody, work performed and verification.
Effectiveness checksDefine the sample population, selection method, questions and acceptance criteria before checks begin, and record the outcome of each check.
Product reconciliationKeep a running balance of distributed, returned, corrected, destroyed, used and unaccounted quantities, with units and quantity basis explicit.
Status and termination evidenceGenerate status reports from the case record, and base termination on response, recovery, effectiveness, reconciliation and residual risk rather than elapsed time.

CConnected records

Entity hierarchy
What it records
Kind
Market Action Signal
Complaint, deviation, OOS, safety, supplier, inspection, labelling, data or authority trigger.
entity
Health Hazard Evaluation
Defect, exposure, severity, probability, populations, consequences, uncertainty and classification.
entity
Affected Population
Products, lots, serials, packs, markets, date ranges, genealogy basis and scope history.
entity
Lot and Shipment Recall Scope
Genealogy filters, lots, packs, markets, shipments, consignee population, rationale and versions.
template
SCOPE-TX10 v03
Expanded population of 18,420 cartons across 142 direct consignees.
record
Market Action
Recall, correction, removal, advisory, recovery, scope, strategy, authority, state and termination.
entity
Human Drug Voluntary Recall
Hazard evaluation, scope, strategy, authority, notifications, responses, returns, checks and termination.
template
REC-TX10-2026-02
Class II voluntary recall of selected TX-10 lots for stopper-fragment risk.
record
Consignee
Recipient, location, contact, shipments, onward distribution, affected quantity and response state.
entity
Recall Notification
Approved content, recipient, channel, version, send, delivery, acknowledgement and follow-up.
entity
Urgent Drug Recall Notice
Product recognition, defect, risk, lot list, immediate action, response, return and contact.
template
NOTICE-TX10-US v02
Approved US notification issued after scope expansion.
record
Consignee Response
Inventory, onward distribution, used, returned, corrected, destroyed, unavailable, questions and evidence.
entity
Effectiveness Check
Population, sample, method, attempts, questions, evidence, outcome, failure and escalation.
entity
Level B Effectiveness Check
Risk-based sample, independent contact, questions, evidence, acceptance, failure and escalation.
template
EFF-TX10-WAVE-02
Second-wave check with 48 of 50 successful contacts and two escalations.
record
Product Reconciliation
Produced, distributed, controlled, used, returned, corrected, destroyed and unknown quantity states.
entity
Recall Quantity Reconciliation
Distributed, used, stock, returned, corrected, destroyed, unavailable, unknown and verified quantities.
template
RECON-TX10-2026-02
Live balance retaining 71 unaccounted cartons and documented follow-up.
record
Authority Status Report
Frozen scope, contacts, responses, product, effectiveness, issues, CAPA, commitments and submission.
entity
Figure C.1. Record types, templates and the relationships between them in this blueprint.

DQuestions and answers

What is product recall management software?

It keeps a recall as one case, from the initiating signal and health-hazard evaluation through scope, strategy, notification, responses, reconciliation and termination. The aim is to reach the right population, not only to move quickly.

Can Seal manage both drug and device recalls?

Yes. Shared controls for scope, communication, responses, effectiveness and reconciliation can be configured with product- and jurisdiction-specific recall, correction, removal and reporting requirements.

How is the affected population identified?

Manufacturing genealogy, packaging, serials, date windows, markets and distribution records define a versioned scope. The scope can start broad and be narrowed or expanded, with the evidence for each change recorded.

Can Seal track indirect consignees?

Yes, where distribution information is available. Direct recipients report onward distribution, and each downstream consignee becomes a tracked obligation for notification, response, quantities and follow-up.

What are recall effectiveness checks?

They verify that recipients received, understood and acted on the recall or correction. The sample, questions, evidence and acceptance criteria are defined before checks begin, and checks stay separate from routine chasing where required.

How are returned products reconciled?

Each return keeps its identity, quantity, custody, inspection and final disposition. It then joins the running balance of distributed, used, corrected, destroyed and unaccounted product.

Can Seal manage field corrections?

Yes. Corrections follow approved instructions carried out by qualified personnel. The exact units, work performed, software or label version and verification are recorded, including any failures.

How are recall communications controlled?

Letters, emails, portal notices and scripts are built from the approved facts: product identity, affected lots, hazard, required actions and deadlines. Each version, send, acknowledgement and response is recorded.

Does Seal replace ERP or serialisation systems?

No. Those systems can remain the source for shipments, inventory and serial events, and Seal does not invent distribution events that partners cannot provide. Seal connects their records to the recall scope, obligations, effectiveness and decisions.

Can Seal run mock recalls?

Yes. A mock recall tests genealogy and distribution retrieval, contact data, quantity balance and simulated responses without contacting real consignees. It is most useful when it includes difficult branches and stale master data.

What is required to terminate a recall?

Termination depends on evidence rather than elapsed time. That includes response and recovery, correction completion, effectiveness results, reconciliation, product disposition, authority commitments and acceptable residual risk.

What should the first implementation prove?

Rehearse one difficult scenario with incomplete genealogy, a stale contact, onward distribution, a serial mismatch, a failed field correction and a scope expansion. Check that each unknown remains explicit and has an owner.

See your process in Seal.

Bring a procedure or a recurring problem. See how your team can use Neil to build the workflow, investigate the results and improve the next version.

Book a demo