The facility had a mezzanine above production. Packaging storage. No food. No moisture. No conducive conditions. No pest history — not last month, not last year, not ever.
The QA Manager knew this. The trend data confirmed it. The pest management provider had documented it consistently across multiple service cycles.
Then an auditor walked through, looked up at the mezzanine, and said four words that would cost the facility time, money, and clarity: "You need devices there."
Four monitoring devices were installed. Months passed. Nothing was captured. Nothing will be captured. Because the science never supported placing them there.
But they are on the map. They are numbered. They get inspected. They get logged. And at the next audit, someone will check that box.
What Risk-Based Placement Actually Means
Risk-based pest management is not a philosophy. It is a documented methodology with specific criteria. Device placement should be justified by one or more of the following: conducive conditions (food, moisture, harborage, entry points), documented activity history, or a structural vulnerability identified through risk assessment.
In the case of this mezzanine, none of those criteria existed. The risk assessment said so. The service records said so. The trend data — showing zero activity in that area across the full monitoring history — said so.
The audit scheme under which this facility operated did not require devices in areas without documented risk or activity. The auditor's requirement had no basis in the standard being applied. That is not a gray area — it is a case where a pest control decision was made without entomological justification.
The Three Things the Facility Had — and Didn't Use
What makes this case instructive is not that the facility lacked information. It had everything it needed to push back:
1. A risk assessment documenting the area as low-risk. The mezzanine had been evaluated. The absence of food, moisture, and conducive conditions was documented before the audit began.
2. A trend report showing zero activity. Multiple service cycles. Multiple technicians. Consistent results: no pest pressure in that zone. That trend report was in the binder the auditor reviewed.
3. A pest management provider who understood the science. The PCO had the entomological expertise to explain why device placement in that area was not warranted. That knowledge was available on request.
None of it was used. Because in the moment — with the audit ending in two hours — the easier decision was to write "install 4 devices on mezzanine" as a corrective action and move on.
What Compliance Theater Costs
When a device map includes locations added under audit pressure rather than risk analysis, the map no longer reflects actual facility risk. A technician inspecting that mezzanine monthly is spending time that could be allocated to areas with genuine pressure. A QA Manager reviewing the log is reading data that tells them nothing about real conditions.
More critically: if real pest pressure emerges somewhere in the facility, the attention diluted across unnecessary devices may mean the signal arrives later than it should.
A program that looks more complete is not always a program that is more effective. 21 CFR 117.35(c) evaluates the second standard, not the first.
What Should Have Happened in That Room
The QA Manager had three legitimate options when the auditor pointed to the mezzanine:
- Present the risk assessment. "We evaluated that area. The absence of food, moisture, and conducive conditions is documented. We can walk through the methodology."
- Present the trend data. "Our service records show zero activity in that zone across the full monitoring history. We are comfortable with the current device placement based on that data."
- Request the specific standard clause. "Could you point me to the specific requirement that calls for devices in this location? We want to make sure we are addressing the right requirement."
Any one of these responses is professional, data-driven, and defensible. All of them require confidence in the facility's own evidence.
Evidence Should Drive Placement. Not Audit Pressure.
The Confidence Gap
The real finding from this case is not about device placement. It is about what happens when a QA Manager does not trust their own program documentation enough to defend it under audit pressure.
Data that is not trusted is data that does not protect. Four devices are now on a mezzanine that will never tell anyone anything useful. The audit passed. The program got larger. It did not get more effective.
Risk-based device placement is a documented standard, not an auditor's discretion. When placement decisions are made under audit pressure rather than risk analysis, the monitoring program loses its predictive value. Facilities that defend their own evidence consistently outperform those that expand their programs reactively.
Regulatory References
- 21 CFR 117.35(c) — Effective measures for pest control
- AIB International — Device placement criteria, risk-based justification
- SQF 9.0 §11.4 — Pest management device placement requirements
- BRCGS Issue 9 §4.14 — Risk-based pest control documentation
Translate any pest finding into regulatory requirements instantly
FSAI360's free Audit Finding Translator identifies the exact regulations, root causes, corrective actions, and auditor guidance for any pest finding — with scheme-specific guidance for SQF, BRCGS, FSSC 22000, AIB, and more.
Try the Translator — Free →