Skip to main content

Back to blog

Compliance September 22, 2026 By FourFoxes Team

Your water is an ingredient. Your records probably don't treat it like one.

You track every pepper lot. Then you turn on the tap, and the biggest input by volume goes in with no record. Water that touches food must be safe and of adequate sanitary quality (21 CFR 117.37(a)), and your hazard analysis has to account for it. Here's how to record water as the traceable input it is.

Your water is an ingredient. Your records probably don't treat it like one.

You track every pepper lot, every jar of spice, every case of bottles. You know the supplier, the lot code, the day it arrived. Then you turn on the tap, and thousands of gallons go into your product with no lot, no record, nothing on the batch sheet.

Water is usually the largest single input by volume in a fermented beverage, a hot sauce, a broth, a brined product. And for most small producers, it's the one input the traceability system pretends isn't there.

Nobody notices that gap until the day something forces them to.

Is water considered an ingredient for food traceability? Functionally, yes. Water that contacts food must be safe and of adequate sanitary quality under 21 CFR 117.37(a), and your written hazard analysis must consider your raw materials and other ingredients for biological, chemical, and physical hazards under 21 CFR 117.130. The regulation doesn't require you to assign water a lot number, but treating water as a traceable input is the practical way to meet those requirements and prove you met them for any specific batch.

What the rules actually require

Two things, and the difference between them matters, because a lot of vendor content in this category implies more than the regulation says.

First, the water itself. Under the FDA's Current Good Manufacturing Practice rules, any water that contacts food, food-contact surfaces, or food-packaging materials must be safe and of adequate sanitary quality (21 CFR 117.37(a)). That's a standard your finished product has to meet, not a note about your plumbing, and "adequate sanitary quality" is a claim you make about every batch you ship.

Second, the hazard analysis. If you're a covered facility, you have to conduct a written hazard analysis, and it has to consider your raw materials and other ingredients against known or reasonably foreseeable biological, chemical, and physical hazards (21 CFR 117.130). The chemical hazards it names aren't hypothetical. The rule lists things like natural toxins and residues, and water is a plausible route for several of them.

Now the honest part. The regulation does not tell you to give water a lot number. It doesn't say "add water as a line on your BOM" or "keep a supplier record for your municipal system." Those are practices, not mandates. What the rule requires is that the water be safe, that you've worked through the hazards your inputs can carry, and that you can back up both. Treating water as a traced input is the most reliable way we've found to meet that requirement and, more to the point, to prove you met it on the day a specific batch was made.

Why "adequate sanitary quality" is a records problem

Think about how you'd actually demonstrate it.

Your municipality issues an annual water quality report. Your well gets tested on some schedule. Maybe you run a carbon filter or a UV step. Every one of those is a record that says your water was fit for food use during a window of time. None of it is worth anything to you if you can't connect it to the batch in question.

An auditor doesn't ask "is your water generally okay?" The useful question, the one a recall investigator asks, is narrower. On the day you made lot #0914, what water went into it, and can you show it met standard? If your answer is a filter you're pretty sure was working and a water report in a drawer somewhere, you don't have traceability. You have a story.

This is the same trap the spreadsheet sets for everything else. A spreadsheet can hold a water test result. It can't tie that result to the specific batches it covers, flag you when the test window lapses, or reconstruct the chain in seconds while someone's waiting on the phone. When a recall hits, a spreadsheet can't prove compliance. It can only suggest it.

The founder's stake

If you own the brand, this is a liability question before it's an operations question.

Picture the ingredient recall you've already rehearsed in your head. A supplier lot goes bad, you get the notice, and you need to know which finished products it touched, fast. You've built that muscle for solid ingredients. Now run the same drill for water. A boil-water advisory hits your town for three days. A well test comes back with elevated coliform. Which of your batches were made in that window? Which retail accounts got them?

If you can't answer that in under a minute, water is a hole in a traceability system you otherwise trust. And a system with a known hole isn't audit-ready. It's audit-hopeful.

The water record is cheap to keep and expensive to reconstruct after the fact. You build the habit now, at four employees, or you scramble for it later under conditions you don't control.

The operator's reality

None of this matters if capturing it slows the shift down, because then it won't get captured.

The person running production doesn't need a water compliance philosophy. They need water to already be on the batch the same way flour is: one more input that's there when they start the record, not a separate binder to go find and a separate form to fill out from memory at the end of the day. Retroactive logging is where records go wrong. A water step logged Thursday from Tuesday's memory is the kind of entry that quietly becomes fiction.

So the bar is simple. If water is part of the batch, recording it should take zero extra thought, and pulling "what water covered this batch" should be a lookup, not an excavation.

How FourFoxes handles it

This is the gap the system is built to close, and it does it in three places:

  • Water as an ingredient with its own lot. You add water to a recipe or BOM like any other input, and it carries into the batch record automatically. When someone pulls the batch, the water's right there with everything else. No separate system, no missing line.
  • Attach the proof. A municipal water quality report, a well test, a filter certification: you attach the actual record where it belongs, so the document that says your water met standard is connected to the batches it covers instead of sitting in a drawer.
  • A monitoring or CCP check on water. If you run a treatment step like filtration or UV, it can be a logged check like any other critical control point, timestamped and attributed to whoever ran it, in the moment, on a phone.

That's the whole move. Water stops being the one input your records ignore and becomes one more thing you can trace, prove, and forget about until you need it. Zero spreadsheets. One system your whole team uses.

The short version

If water touches your product, the FDA already treats it as something you have to keep safe and account for in your hazard analysis. The regulation stops short of telling you how. The producers who sleep well are the ones who close the gap on their own terms, before an advisory, a well test, or an inspector closes it for them.

Your next audit is coming. Make sure the water can be traced too.

Frequently asked questions

Does the FDA require me to give water a lot number?

No. There's no rule that says water needs a lot code or a supplier record. The rules require that water contacting food be safe and of adequate sanitary quality (21 CFR 117.37(a)) and that your hazard analysis account for your inputs (21 CFR 117.130). Assigning water a traceable record is a recommended practice for meeting and demonstrating those requirements, not a mandate.

We use municipal water. Isn't the city responsible for its quality?

The city is responsible for delivering water that meets drinking-water standards. You're responsible for the safety of your finished food, which includes the water in it. Keeping the municipal water quality report attached to the batches it covers is how you connect their responsibility to your records.

We're on a well. What changes?

The standard is the same, safe and of adequate sanitary quality, but the proof is on you, since no municipality is testing for you. Well test results become a record you keep and tie to the production windows they cover.

How do I record water without slowing down production?

Add it to the recipe or BOM as an input so it's already on the batch when an operator starts the record, rather than a separate log they fill out later. Any treatment step like a filter or UV can be a monitoring or CCP check logged in the moment on a phone.

Know what's in every batch, including the water. See how FourFoxes traces every input →