There is a question that FDA inspectors and third-party auditors are trained to ask — and that most QA Managers are not trained to answer.
It is not "Do you have a pest control contract?" It is not "Are your service reports filed?" It is not even "When was your last service visit?"
The question is: "How do you know your pest control program is working?"
That question is the operational translation of 21 CFR 117.35(c). And the gap between what most facilities can answer and what the regulation actually requires is where audit citations are born.
What 21 CFR 117.35(c) Actually Says
The relevant text requires that food facilities take "effective measures to exclude pests from the manufacturing, processing, packing, and holding areas and to protect against the contamination of food on the premises by pests."
The operative word is effective. Not present. Not contracted. Not documented. Effective.
Most QA Managers believe they comply with 21 CFR 117.35(c) if they can show a signed pest control contract, monthly service visits, monitoring devices on a map, and service reports on file. That belief is incomplete. Those elements are necessary. They are not sufficient.
Under FDA's preventive controls framework, effectiveness is not assumed from the existence of a program. It must be demonstrated. The distinction matters because it shifts the compliance burden from operational activity to documented outcomes.
The Three Documents That Answer the Question
When an FDA inspector or third-party auditor asks how a facility knows its pest control program is working, there are three documents that provide the answer — and most facilities have, at best, one of them.
1. The trend report. Not the pest control company's summary. The facility's own analysis of activity patterns over time, by zone, by species, by device type. A trend report that shows cockroach captures dropping from six in Q1 to one in Q3 is evidence of effectiveness. A log of monthly service visits is not.
2. The corrective action record. Every pest finding should generate a traceable corrective action — linked to the specific device, location, and service report. The corrective action record shows that the facility identified a risk, responded to it, and verified the response worked. That chain is what "effective measures" looks like on paper.
3. The risk assessment. The pest management program should be built on a documented risk assessment that justifies service frequency, device placement, and monitoring intensity based on facility-specific conditions.
The Three Documents Auditors Actually Want to See
Why QA Managers Confuse the Container for the Evidence
A binder full of service reports tells an auditor that pest control visits occurred. It does not tell the auditor whether those visits prevented anything, whether the corrective actions from the last finding were effective, or whether the facility understands what its own data is showing.
I have reviewed documentation packages for facilities that had three binders of chronologically organized, signed, and dated service reports — and still received major nonconformances at audit. The problem was not the volume of documentation. It was that none of it answered the auditor's actual question: Is your program working?
How GFSI Schemes Interpret the Same Standard
The major GFSI-benchmarked schemes all require documentation that goes beyond service records:
SQF 9.0 requires trend analysis and corrective action records as facility-owned documents.
BRCGS Issue 9 requires an effectiveness check as part of every corrective action closure.
AIB International requires that QA teams be able to explain the rationale behind service frequency, device placement, and response protocols — not just present the records.
Across all of these schemes, the auditor's question is the same one FDA asks: How do you know it is working?
The Practical Test
Before the next audit, apply this test: Pull a service report from six months ago. Without looking at any other document, answer: What was found? What was the corrective action? Was it verified as effective? Is that location currently showing any activity?
If you can answer all four questions from the documentation chain — you can demonstrate effectiveness. If any link is missing, that is where the citation will come from.
Effectiveness under 21 CFR 117.35(c) is a documentation standard, not just an operational one. The pest control company provides the data. The QA team owns the evidence. That distinction is where most facilities lose audit findings they should not have received.
Map any finding to its regulatory requirements instantly
FSAI360's free Audit Finding Translator identifies the exact regulations, root causes, corrective actions, and auditor guidance for any pest finding — with scheme-specific guidance for SQF, BRCGS, FSSC 22000, AIB, and more.
Try the Translator — Free →