GS1 Global Standards - Supply Chain Traceability and Data Security
GS1: Traceability, Healthcare/Food/Pharma Sectors, EU FMD/MDR/IVDR/TPD, FDA DSCSA/UDI Coordination

GS1 Global Standards - Supply Chain Traceability and Data Security Traceability-Healthcare-FMD-MDR-DSCSA-UDI: GS1 Supply Chain Traceability, Healthcare + Pharma + Food Sectors, EU FMD + MDR + IVDR + TPD, FDA DSCSA + UDI

GS1 SUPPLY CHAIN TRACEABILITY + sectoral applications. END-TO-END TRACEABILITY MODEL: GS1 traceability is built on (a) Critical Tracking Events (CTEs) - significant supply chain events (e.g. creation + shipping + receiving + transformation + selling + recall); (b) Key Data Elements (KDEs) - data points captured per CTE (GTIN + lot + serial + date + location + party + quantity); (c) one-up + one-down traceability (each party knows its immediate suppliers + customers) + full chain via EPCIS event sharing; (d) one-step vs full traceability vs lot tracing vs item-level traceability. PHARMA (EU + US): EU FALSIFIED MEDICINES DIRECTIVE (FMD, Directive 2011/62/EU) effective February 2019 - serialised GS1 DataMatrix (GTIN + Serial Number + Batch + Expiry) on pharma packs + verification at point-of-dispense via EU Hub + National Medicines Verification Systems (NMVS); EU eToken + UI (Unique Identifier) standards; ~20K+ pharma products serialized. US DSCSA (Drug Supply Chain Security Act, 2013 Pub.L. 113-54) - 10-year phased implementation completing 2023-2024 + Nov 2024 enforcement; serialized GS1 codes + interoperable exchange + verification + saleable returns + suspicious-products investigation; multiple compliance extensions through 2024-2025. MEDICAL DEVICES: EU MDR (Regulation (EU) 2017/745) + IVDR (Regulation (EU) 2017/746) - UDI (Unique Device Identification) via GS1 GTIN + UDI Production Identifier + EUDAMED database; phased implementation through 2025-2027. FDA UDI - GTIN-based UDI for medical devices + GUDID (Global UDI Database). FOOD + FOODSERVICE: GS1 traceability + recall capability + FDA Food Traceability Final Rule (2024) + EU General Food Law + supply chain accountability + retailer mandates (Walmart + Costco + Tesco + Carrefour + Whole Foods); MOCK RECALL + WITHDRAWAL TESTING (annual + GS1-aligned). TOBACCO: EU TPD (Directive 2014/40/EU) - GS1-based traceability for tobacco products + UI + EU verification + suspicious activity detection. RETAIL + CONSUMER: GS1 + Walmart + Amazon + Costco + Tesco + Carrefour + retailer mandates for GTIN + GS1 codes + GDSN master data + supplier compliance. AUTOMOTIVE + AEROSPACE: GS1 SSCC + CPID for parts + traceability + recall + warranty. CONSTRUCTION + REAL ESTATE: GS1 + building product traceability + sustainability + Digital Product Passport. RECALL + WITHDRAWAL: GS1 codes enable rapid product recall + withdrawal + targeted recall + customer notification + regulatory reporting (FDA + EMA + EU + national + Codex).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 60 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CFR211-C-48 Section 211.48 - Plumbing
  • CFR211-F-113 Section 211.113 - Control of Microbiological Contamination
  • CFR211-I-176 Section 211.176 - Penicillin Contamination
  • CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records

API 1164 · 3 controls

  • AQAP2110-1 Quality Management System Aligned to ISO 9001 plus NATO Supplementary Requirements
  • AQAP2110-2 Government Quality Assurance Representative (GQAR) Authority and Access
  • AQAP2110-6 Subcontractor Supply Chain Control plus Counterfeit Material Prevention

SWIFT CSCF · 3 controls

  • SWIFTCSCF-3 Physically Secure the Environment (Objective 3)
  • SWIFTCSCF-4 Prevent Compromise of Credentials (Objective 4)
  • SWIFTCSCF-7 Plan Incident Response (Objective 7)
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • AEO-2 Demonstrated Compliance with Customs Requirements
  • AEO-4 Financial Viability
  • CPG-6.A Vendor and Supplier Incident Reporting
  • CPG-6.B Supply Chain Incident Reporting
  • 3.16 System and Services Acquisition
  • 3.17 Supply Chain Risk Management
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing

PCI DSS 4.0 · 2 controls

  • 2.1.1 All security policies and operational procedures that are identified in Requirement 2 are: • Documented. • Kept up to date. • In use. • Known to all affected parties
  • 2.1.2 Roles and responsibilities for performing activities in Requirement 2 are documented, assigned, and understood
  • 2.1.3 Food Safety and Quality Culture
  • 2.7.2 Food Fraud Plan
  • 58.49 Laboratory Operation Areas
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • Clause 3 Suppliers and service providers
  • CJIS-19 Supply Chain Risk Management
  • A.1 Point-of-Care Testing Additional Requirements

ISO 27005 · 1 control

  • 8.5 Control effectiveness review

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27011:2024 · 1 control

  • 27011-5.6 Supplier relationships and telecom supply chain

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-3 A03:2025 Injection Including Cross-Site Scripting
  • AODACAN-2 Accessible Procurement of Goods, Services, Facilities

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in GS1: Traceability, Healthcare/Food/Pharma Sectors, EU FMD/MDR/IVDR/TPD, FDA DSCSA/UDI Coordination

Query this from an agent

The graph holds this control, the 60 it maps to, and the evidence behind each claim, over MCP and REST.