How to build the Subpart G supply-chain program the Preventive Controls rule requires when a supplier controls a hazard before it reaches you — deciding which ingredients need it, approving the supplier, matching a verification activity to how serious the hazard is, and keeping the proof where receiving can reach it.
Chef Diego runs a real food plant. If this page didn't get you there, tell us — a person reads every message.
After this lesson you can look at your ingredient list and pick out the ones whose hazard your supplier controls, approve those suppliers on the record before the first delivery, choose the verification activity that fits how dangerous the hazard is, and file the proof where your receiving crew can actually reach it — instead of trusting a supplier because you always have.
When the hazard is controlled before it reaches you
The previous lesson covered the preventive controls you run inside your own four walls — process, allergen, sanitation. This one is about the hazard you do not control, because someone upstream already did.
The rule has a name for that. A is defined in 21 CFR 117.3 as exactly that: a control for a hazard that is handled before receipt. And 21 CFR 117.135(c)(4) makes the program that manages those controls a preventive control in its own right — the fourth category, sitting alongside your process, allergen, and sanitation controls.
Here is the part first-timers get wrong: you do not owe a supply-chain program for every ingredient. Section 117.405(a) ties it to your hazard analysis. You establish and implement the program only for the raw materials and ingredients where your hazard analysis identified a hazard requiring a supply-chain-applied control. The trigger is the analysis, not the shopping list.
A worked example makes the line clear. Say you buy roasted tree nuts to fold into a granola you bake but do not further heat-treat for pathogens. The pathogen kill for those nuts happened at the roaster — your supplier controls it, before the nuts ever reach your dock. That is a hazard requiring a supply-chain-applied control, so those nuts need a program. Now say you buy raw spice you will cook into a sauce at a temperature that controls the same class of hazard yourself. You control it in your own process, so it is a process control, not a supply-chain one. Same category of hazard, different owner — and the owner decides which kind of control it is.
The "supplier" is the maker, not the middleman
Before you can approve a supplier, you have to know who the rule means by the word, because it is narrower than everyday use.
A is defined in 21 CFR 117.3 as the establishment that manufactures or processes the food, raises the animal, or grows the food provided to you — without further processing by anyone else, beyond trivial relabeling. So if you buy through a distributor or a broker, that middleman is usually not your "supplier." The supplier is whoever actually made, grew, or raised the material and controlled the hazard. Your verification has to reach that entity, which means you need to know who they are even when you buy through someone else.
The flip side of that definition is your own role. A is, per the same section, a facility subject to the rule that processes a material it receives from a supplier. That is you. The program is your obligation, not the supplier's — a distinction that turns out to matter a great deal in a moment.
Approve the supplier before the first delivery
The program starts with approval, and approval comes before receiving — not after, and not as a formality.
Section 117.415(a) makes it your job to approve suppliers, and 21 CFR 117.420 says you approve and document that approval before you receive material from them. What goes into that decision is spelled out in 117.410(d):
1
The hazard analysis for the food
What hazard the supplier is controlling, and how serious it is. A supplier controlling a pathogen kill carries more weight in your decision than one controlling a low-risk defect.
2
Who is actually applying the control
The entity responsible for the hazard requiring a supply-chain-applied control — which, per the definition above, may be a maker further up the chain than the company on your invoice.
3
The supplier's performance
Their procedures and practices around the safety of the material, their record with applicable FDA food safety regulations (an FDA warning letter or import alert is on this list), and their food safety history with you — test results, audit results, and how they responded when something went wrong.
Approval is not the whole receiving story, though. Section 117.420(b) also requires written procedures for receiving, so that material comes in only from approved suppliers — with a narrow, temporary exception for an unapproved supplier whose material gets adequate verification before you use it — and it requires you to document that those procedures are followed. Approval on paper does nothing if the receiving dock cannot tell an approved supplier from an unapproved one.
Match the verification activity to the hazard
Approving a supplier is a judgment about the company. Verification is the ongoing proof that the control they are responsible for actually keeps happening. Section 117.410(b) lays out the menu of a :
An onsite audit of the supplier.
Sampling and testing of the raw material or ingredient.
A review of the supplier's relevant food safety records.
Another appropriate activity, chosen for the supplier's performance and the risk of the material.
You conduct one or more of these for each supplier before you use the material and periodically after that, per 117.430(a). Which one, and how often, is not a free choice — it scales with how dangerous the hazard is.
A serious hazard sets a default of an annual onsite audit
When the hazard the supplier controls is a , 117.430(b) sets the default verification activity as an onsite audit of the supplier, conducted before you use the material and at least annually thereafter. You can step down from that — a lighter activity, or a less frequent audit — but only if you make a written determination that the alternative gives adequate assurance the hazard is controlled. The audit-every-year default holds until you write down why something else is enough.
This is where the certificate that shows up with a shipment fits. A is the supplier's own testing of a lot. Section 117.415(a) lets a supplier's sampling and testing of a particular lot count as a verification activity and lets them hand you that documentation — but only on a condition that is easy to miss: you have to review and assess it, and document that review. A COA that arrives, gets filed, and is never read is not verification. The verification is the act of you checking that the numbers meet your spec and recording that you checked.
The supplier can't grade its own homework
The single rule that catches the most people is about who is allowed to do the checking. Because the program is the receiving facility's obligation, the receiving facility — not the supplier — has to stand behind the verification.
Section 117.415(b) says plainly that you may not accept, as a supplier verification activity, any of these:
The supplier deciding what its own verification activities should be.
An audit the supplier conducted of itself.
The supplier reviewing its own food safety records.
Other verification activities the supplier ran on itself.
The logic is simple: a supplier grading its own homework proves nothing you can rely on. There is one clean exception, in 117.415(c): you may rely on an audit the supplier hands you if that audit was done by an independent third party — a , not the supplier's own staff. Any onsite audit that counts under this program has to be performed by a qualified auditor, per 117.435(a), and that audit has to actually look at the supplier's written food safety or HACCP plan for the hazard being controlled, not just walk the floor. A recent government inspection of the supplier can stand in for the audit if it happened within the year, under 117.435(c).
And if any of this tells you the supplier is not controlling the hazard — an audit finding, a failed test, a customer complaint — 117.410(e) requires you to take prompt, documented action so that material from that supplier does not make your product unsafe. Finding the problem is only half the duty; acting on it is the other half.
Where the program lives: the receiving dock
A supply-chain program written into a binder and forgotten is worth nothing. It becomes real at the moment a delivery arrives — when someone has to know this material came from an approved supplier and that its verification is in hand.
Section 117.475 lists what the program has to keep in records: the written program itself, the approval of each supplier, the receiving procedures and evidence they were followed, the determination of which verification activities apply, the audit documentation, the testing and records-review documentation, and any action you took on a supplier that fell short. Section 117.475(b) then requires you to review those records — the same review discipline that governs the rest of your Food Safety Plan. The docs on receiving with QC walk through how a receiving check and a QA hold fit together on the floor; this program is the reason a receiver needs the supplier's proof at hand, not in a back office.
That retrievability is a real operational problem, and there is more than one way to solve it. One is to keep the supplier's certificate of analysis attached to the receipt for the lot it covers and route that receipt through a receiving QC review that records the accept-or-reject decision — so the proof, the decision, and the lot travel together instead of the COA living in a binder nobody opens at the dock. Bettr Manager's receiving flow can attach documents to a receipt and capture that QC review and its accept-or-reject decision on the receipt itself; it does not, though, keep a formal approved-supplier register, so the approval side of the program still lives in your Food Safety Plan records. However you do it, the test is the same: at receiving, can you show this lot came from an approved supplier and that its verification was reviewed?
It belongs in the Food Safety Plan
The supply-chain program is not a side document. Section 117.126(b) names the written supply-chain program as one of the seven required parts of your Food Safety Plan, and 117.126(a) puts that whole plan under a preventive controls qualified individual, who prepares it or oversees its preparation. Section 117.405(b) makes the program written, like everything else in the plan. So the work in this lesson is not extra — it fills in the third of the seven boxes your PCQI signs off on.
With your hazard controls built and your supply-chain program in place, the plan is whole. The question operators ask next is not another regulatory one — it is a market one: which certification, if any, do your buyers actually require, and how do you walk into that first audit ready? That is where this course goes next.