The Record Can Be Right and the System Can Still Fail
The Record Can Be Right and the System Can Still Fail By 0pcter
A company can keep an accurate record of what it received, processed, and shipped and still be unable to prove where a product came from. Its supplier may also have accurate records, as may the distributor and retailer. Nothing has to be falsified or secretly altered for the chain to break. The failure can occur when one organization's record has to connect with another organization's record. Traceability depends not only on preserving information, but on preserving the relationships between it.
The U.S. Food and Drug Administration encountered this problem while testing readiness for its Food Traceability Rule. FDA conducted exercises across six food supply chains involving fifteen voluntary participants, from producers and processors to distributors, retailers, and restaurants. Companies were asked to retrieve specified traceability information and return it electronically within 24 hours. Most met the deadline, demonstrating that much of the requested information existed and could be retrieved. Yet several exercises still could not trace the selected food all the way back to its original source.
The weakness became clearer when FDA examined the identifiers intended to connect those records. A Traceability Lot Code was available, although sometimes inconsistently, in 80 percent of participant records, and information identifying the source of that code appeared in 73 percent. But only 40 percent properly recorded the lot code across every relevant tracking event they performed. Only 27 percent completely recorded the source information across those events. FDA cautioned that the small voluntary sample does not represent the entire food industry, but the exercises exposed how easily individually available information can fail to form a continuous history.
In one exercise, a company could not definitively identify its immediate previous supplier, leaving investigators without a reliable place to send the next request. Other participants possessed a lot code but could not properly identify where it originated, while some had source information without the corresponding code needed to connect it to the product. Another exercise stopped when a distributor did not continue providing information. These were not necessarily cases of corrupted databases or fraudulent records. The larger history failed because essential relationships between records disappeared at organizational boundaries.
That distinction matters. A record can be authentic, searchable, unchanged, and available within minutes while still failing to identify what happened immediately before or after the event it describes. Findability asks whether someone can locate the necessary record. Integrity asks whether that record has changed. Interoperability asks whether records created independently can still be connected and understood when they cross from one system into another.
FDA's exercises also challenge the assumption that sophisticated technology automatically creates better traceability. Participants used everything from paper documents and spreadsheets to enterprise software, warehouse-management systems, barcodes, and RFID. Larger companies often had more advanced systems, but FDA found that technology itself was less important than alignment between trading partners. Companies that coordinated beforehand on what information to collect and how to exchange it were better positioned to respond. In some exercises, that coordination allowed information covering an entire supply chain to be returned within the initial 24-hour period rather than through successive requests that FDA estimated could take 48 to 96 hours or longer.
There is already a conventional answer to much of this problem. GS1 standards provide common ways to identify products, locations, organizations, and supply-chain events, while EPCIS gives different systems a common structure for exchanging event information. The goal is not to place every company inside one database. It is to allow independently operated systems to describe the same event in ways the other participants can understand. Before information can be independently verified, participants first have to agree on what that information means.
This exposes an important weakness in many blockchain supply-chain arguments. A blockchain can timestamp a commitment, establish ordering, preserve transaction history, and make later alteration of committed information detectable. It cannot decide which identifier a processor should attach to a transformed product or tell another company what that identifier means. If two organizations describe the same event differently, putting both records on an immutable ledger preserves the disagreement. A blockchain can therefore maintain incompatible information with exceptional integrity.
Bitcoin does not solve that problem. It cannot recover a lot code that nobody captured, identify a supplier recorded ambiguously, or force companies to use compatible definitions. It also cannot determine whether information entered at the beginning of the chain was truthful. Timestamping an incorrect record establishes that the record existed; it does not make the underlying claim correct. Standards, shared identifiers, operational procedures, and compatible data structures have to solve those problems first.
A different question emerges once those foundations exist. Suppose several organizations successfully record a chain of events using compatible identifiers, but months later they disagree about what one participant originally reported. Digital signatures can establish authorship, audit systems can preserve changes, and conventional timestamping services can provide additional evidence. A commitment to an independently maintained public transaction history could provide another reference against which the disputed record could later be tested. Its purpose would not be to create traceability, but to make alteration of previously committed evidence independently detectable.
Even there, Bitcoin has to compete with simpler alternatives. PKI, signed records, transparency logs, trusted timestamp services, replicated databases, and conventional audit systems can already provide strong integrity guarantees. For many organizations those systems may be sufficient, cheaper, and easier to operate. Bitcoin becomes materially interesting only where independence from the organizations maintaining the underlying records provides enough additional value to justify another infrastructure layer. The ability to put information on a blockchain is not evidence that the information belongs there.
The FDA exercises therefore expose a broader infrastructure problem than food traceability alone. Modern systems generate enormous amounts of information, but accumulating records is not the same as reconstructing history. Integrity protects information from undetected alteration; interoperability allows information to retain meaning as it moves between systems. Provenance connects information to its origin, while findability determines whether the relevant evidence can actually be retrieved. Treating these as interchangeable problems leads to technologies being applied where they cannot solve the failure that matters.
The same distinction appears in healthcare, software supply chains, financial systems, industrial maintenance, and government records. Each depends on information crossing boundaries between organizations that may use different systems and operate under different incentives. Future machine-to-machine commerce will make those boundaries even more important as software increasingly exchanges information and value without a human reconciling every discrepancy. Preserving trustworthy records will matter, but trustworthy records cannot reconstruct a history they were never designed to share. Verification begins to matter only after the records can describe the same chain of events.
There is a persistent temptation to search for one technology capable of making an entire system trustworthy. The evidence points toward a less satisfying but more useful conclusion. Standards establish common meaning, operational systems capture events, security controls protect access, signatures establish authorship, and verification mechanisms preserve evidence. Bitcoin may strengthen the final layer where independent historical verification provides a genuine advantage. It cannot substitute for the infrastructure that makes the history coherent in the first place.
That is the deeper lesson in FDA's exercise. Every participant in a chain can possess records that are individually correct while investigators remain unable to reconstruct what happened across the whole system. The missing piece may not be a stronger database or a more permanent ledger. It may be the agreement that allows one organization's record to remain meaningful when it becomes another organization's evidence. Making information harder to alter cannot repair relationships that were never recorded. A trustworthy record is not enough when the system cannot connect it to what happened next.