The facility had a mezzanine above production. Packaging storage. No food. No moisture. No conducive conditions. No pest history — not last month, not last year, not ever.

The QA Manager knew this. The trend data confirmed it. The pest management provider had documented it consistently across multiple service cycles.

Then an auditor walked through, looked up at the mezzanine, and said four words that would cost the facility time, money, and clarity: "You need devices there."

Four monitoring devices were installed. Months passed. Nothing was captured. Nothing will be captured. Because the science never supported placing them there.

But they are on the map. They are numbered. They get inspected. They get logged. And at the next audit, someone will check that box.

What Risk-Based Placement Actually Means

Risk-based pest management is not a philosophy. It is a documented methodology with specific criteria. Device placement should be justified by one or more of the following: conducive conditions (food, moisture, harborage, entry points), documented activity history, or a structural vulnerability identified through risk assessment.

In the case of this mezzanine, none of those criteria existed. The risk assessment said so. The service records said so. The trend data — showing zero activity in that area across the full monitoring history — said so.

⚠️ Key Finding

The audit scheme under which this facility operated did not require devices in areas without documented risk or activity. The auditor's requirement had no basis in the standard being applied. That is not a gray area — it is a case where a pest control decision was made without entomological justification.

The Three Things the Facility Had — and Didn't Use

What makes this case instructive is not that the facility lacked information. It had everything it needed to push back:

1. A risk assessment documenting the area as low-risk. The mezzanine had been evaluated. The absence of food, moisture, and conducive conditions was documented before the audit began.

2. A trend report showing zero activity. Multiple service cycles. Multiple technicians. Consistent results: no pest pressure in that zone. That trend report was in the binder the auditor reviewed.

3. A pest management provider who understood the science. The PCO had the entomological expertise to explain why device placement in that area was not warranted. That knowledge was available on request.

None of it was used. Because in the moment — with the audit ending in two hours — the easier decision was to write "install 4 devices on mezzanine" as a corrective action and move on.

What Compliance Theater Costs

When a device map includes locations added under audit pressure rather than risk analysis, the map no longer reflects actual facility risk. A technician inspecting that mezzanine monthly is spending time that could be allocated to areas with genuine pressure. A QA Manager reviewing the log is reading data that tells them nothing about real conditions.

More critically: if real pest pressure emerges somewhere in the facility, the attention diluted across unnecessary devices may mean the signal arrives later than it should.

A program that looks more complete is not always a program that is more effective. 21 CFR 117.35(c) evaluates the second standard, not the first.

What Should Have Happened in That Room

The QA Manager had three legitimate options when the auditor pointed to the mezzanine:

Any one of these responses is professional, data-driven, and defensible. All of them require confidence in the facility's own evidence.

FSAI360 PCI Intelligence · Audit Finding Framework

Evidence Should Drive Placement. Not Audit Pressure.

Risk Assessment
Device placement must be justified by documented conducive conditions or activity history. No history = no requirement.
Trend Data
Zero activity across multiple service cycles is evidence. It should be used as a defense, not ignored under pressure.
Standard Basis
Every auditor requirement should have a traceable clause. Facilities have the right to ask which one applies.
Effectiveness
21 CFR 117.35(c) asks if the program is effective — not if it satisfied an auditor who lacked the entomological basis to require more.

The Confidence Gap

The real finding from this case is not about device placement. It is about what happens when a QA Manager does not trust their own program documentation enough to defend it under audit pressure.

Data that is not trusted is data that does not protect. Four devices are now on a mezzanine that will never tell anyone anything useful. The audit passed. The program got larger. It did not get more effective.

💡 PCI Insight — Juan Prieto, ACE · PCQI

Risk-based device placement is a documented standard, not an auditor's discretion. When placement decisions are made under audit pressure rather than risk analysis, the monitoring program loses its predictive value. Facilities that defend their own evidence consistently outperform those that expand their programs reactively.

Regulatory References

Translate any pest finding into regulatory requirements instantly

FSAI360's free Audit Finding Translator identifies the exact regulations, root causes, corrective actions, and auditor guidance for any pest finding — with scheme-specific guidance for SQF, BRCGS, FSSC 22000, AIB, and more.

Try the Translator — Free →