Detailed solution responses for QMS, HACCP, laboratory/LIMS, traceability & recall, regulatory, HSE, and environmental compliance.
10 requirements in this section
QMS document management via SharePoint + Power Automate (Gap G-05):
Document approval: Power Automate routes documents: author → reviewer(s) → approver. Electronic signature/approval recorded. Only the current approved version accessible to operational staff (previous versions archived). Approval status and history maintained per document.
Periodic review: each document has review frequency (annual for most, semi-annual for critical safety). Review due date tracked. Power Automate sends reminders at 30, 7, and 0 days before due. Owner reviews → current (no change) or revises → re-approval. Overdue reviews visible on quality manager dashboard.
D365 Non-Conformance Management: NCR creation from any source (inspection failure, complaint, audit finding, process deviation) with description, affected product/batch, severity. Investigation: root cause analysis (Ishikawa, 5-Why). Disposition: use as-is, rework, regrade, scrap, return. CAPA: corrective/preventive actions with owner, deadline, effectiveness review. Trend analysis in Power BI.
CAPA management: corrective and preventive actions linked to: non-conformances, customer complaints, audit findings, or proactive improvements. Action tracking: description, responsible person, due date, completion status, and effectiveness verification (did the action prevent recurrence?). CAPA completion rate KPI in Power BI.
Internal audit management: annual audit schedule (quality, food safety, environmental, HSE). Auditor assignments, checklists per audit type. Findings recorded as D365 non-conformances with severity. CAPA assigned from findings. Audit reports generated. Management review input compiled.
External audit tracking: audit events recorded with: certification body, audit type (surveillance, recertification), date, findings (major NC, minor NC, observations), corrective action deadlines, and closure status. Certificate validity and renewal dates tracked with alerts.
Change management: change request → impact assessment → approval → implementation → verification. Covers: recipe changes, process changes, equipment changes, supplier changes. Change record: description, reason, risk assessment, approval chain, implementation steps, and verification that change achieved intended outcome.
Customer complaint management: complaint registered with: product, batch, customer, issue description, photos/evidence. Investigation linked to D365 quality non-conformance and batch trace. Root cause analysis documented. Resolution: credit note, replacement, price adjustment, or rejection with documented reason. Trend analysis in Power BI by type, customer, product, period.
Supplier NCR: quality issues on incoming materials recorded as non-conformances linked to the vendor and PO. NC data feeds vendor evaluation scoring. Trends tracked per vendor. Vendor notification and corrective action request process.
7 requirements in this section
HACCP plan management: SharePoint stores HACCP plan documents (hazard analysis, CCP decision tree, flow diagrams) with version control. D365 Quality operationalises CCPs as quality test groups with critical limits, monitoring procedures, corrective actions. Plan revisions trigger D365 quality test configuration review.
CCP monitoring: each CCP as quality test group with parameters, critical limits, frequency. Automated recording from sensors/equipment where integrated. Manual recording via production floor terminals. Deviation from critical limits triggers: immediate alert, production hold, corrective action, mandatory NCR.
CCP deviation alerts: when monitoring values exceed critical limits, Power Automate triggers immediate notification to line supervisor + quality manager. Production hold on affected product. Corrective action procedure initiated per HACCP plan. Mandatory resolution and sign-off before production continues. All events documented.
PRP management: SharePoint for PRP documentation (procedures, schedules). D365 Quality for operational checks: sanitation verification (swab tests), pest monitoring (trap inspections), personal hygiene audits, facility maintenance checks, water quality testing. Scheduled as recurring quality orders.
Allergen management: allergen register per ingredient in D365 product master. BOM roll-up determines finished product allergens. Cross-contamination risk assessment documented. Allergen cleaning verification recorded as quality test results. Label content validation against allergen data (PRC-019/024).
Environmental monitoring: sampling points defined (surfaces, drains, air, water) with scheduled frequency. Test results (Listeria, Salmonella, TVC swabs, ATP) recorded in D365 quality orders. Trend analysis in Power BI. Positive findings trigger intensive sampling and sanitation corrective action.
Water quality: potable and process water testing at scheduled frequency. Results (microbiological, chemical) recorded in D365 quality. Compliance against standards tracked. Deviations trigger corrective action. Reports available for regulatory inspections.
5 requirements in this section
LIMS integration: D365 sends sample requests to LabWare LIMS (sample type, tests, batch reference). LabWare returns test results to D365 quality orders. Results linked to production batches. Integration via Azure Service Bus or file-based exchange. Turnaround tracking.
In-house testing: D365 quality test groups for tests outside LIMS: temperature checks, visual inspections, sensory panels, weight verification. Results entered in quality orders with: test type, value, specification limits, pass/fail. Trend analysis available.
Quality specifications: defined per material type with acceptable ranges for all tested parameters: chemical limits (histamine, dioxins, drug residues), microbiological limits (Listeria, Salmonella, TVC), physical criteria (colour, texture). Customer-specific specs where stricter. Centrally maintained and auto-applied.
CoA generation: from completed quality test results per batch. Customer-specific templates (some want full micro panel, others specific params). Attached to shipment documentation. Digital signature by authorised quality personnel.
Shelf-life studies: study protocols managed in D365 with: product, packaging, test regime (time points, parameters), storage conditions. Results recorded at each time point. Validated shelf-life determination from study data. Results feed product shelf-life configuration.
6 requirements in this section
End-to-end traceability: D365 batch trace + AquaMonitor: egg supplier → smolt facility → vaccination → sea site/pen → feed batches → treatments → harvest → processing intake → production batch → product lot → customer shipment. Complete chain queryable from any point.
One-up-one-down per EU Reg 178/2002: from every product, NordHav can identify supplier (one-up: raw material source) and customer (one-down: delivery recipient). NordHav's implementation significantly exceeds this minimum with full internal chain traceability.
Traceability query: given any batch or lot number, D365 batch trace displays the full chain (upstream and downstream) with links to all records: health data, feed, treatments, quality tests, production parameters, customer deliveries.
Mock recall: given a triggering event, D365 batch trace identifies all affected product within 4 hours (BRC/IFS requirement). Scope: affected batches, customer list, volumes, current inventory. Regular drill (minimum annual) with timed execution documented for audit evidence.
Recall management: recall decision with documented reason, scope, severity (Class I/II/III). D365 batch trace defines scope: products, batches, distribution (customers, quantities). Customer notifications generated. Return tracking via D365 returns with quarantine. Regulatory reporting to Mattilsynet. RASFF notification data if cross-border.
Withdrawal register: all product withdrawals and recalls logged with: reason, scope (batches, volumes, customers), actions taken, regulatory notifications sent, and outcome. Register maintained for audit review and regulatory inspection.
6 requirements in this section
Regulatory library: SharePoint library of applicable regulations and standards with: reference number, title, applicability (sites/processes), key requirements summary, review schedule. Linked to QMS procedures that implement each requirement.
Compliance tasks: regulatory reporting dates, certification renewals, equipment inspections, and monitoring schedules tracked with: due dates, responsible person, and completion status. Power Automate reminders before deadlines. Compliance calendar dashboard in Power BI.
Microsoft Sustainability Manager is the central platform for environmental KPI tracking, ingesting activity data from D365 F&O and AquaMonitor:
Chemical register: all chemicals (cleaning, water treatment, fish treatment, processing) in D365 inventory with: SDS document in SharePoint, hazard classification, approved use, storage requirements, quantities on-site. Accessible to all workers.
Waste management in D365 Inventory: waste by type (organic, packaging, hazardous, general), quantity, disposal method, waste hauler, and manifests. Waste data flows to Microsoft Sustainability Manager via Azure Data Factory for inclusion in CSRD/ESRS environmental reporting — waste generation intensity, recycling rates, and circular economy metrics. Power BI dashboards combine operational waste data with ESG targets.
ASC certification data: environmental indicators (lice, treatments, escapes, MOM results from AquaMonitor), social (worker safety, training from D365 HR), feed sustainability (FFDR, sourcing certifications from AquaMonitor), traceability (D365 batch trace). Microsoft Sustainability Manager aggregates carbon footprint and environmental metrics alongside ASC-specific indicators, enabling a single reporting view. Power BI compiles all indicators for efficient annual audit preparation and continuous certification readiness monitoring.
6 requirements in this section
Incident reporting: via D365 or Power Apps form: type (injury, near-miss, hazardous observation, environmental), date/time/location, affected person(s), severity, description, immediate actions. Serious injuries reported to Arbeidstilsynet per AML. Status workflow: Reported → Investigating → Actions → Closed.
Incident investigation: root cause analysis (5-Why, fishbone), contributing factors, witness statements, corrective/preventive actions assigned with owner, deadline, and verification of effectiveness.
Risk assessments: per facility/department/activity with hazard description, risk score (probability × consequence), existing controls, residual risk, additional controls needed, responsible person, review date. Power BI heat maps, high-priority risks, control status.
HSE statistics: Lost Time Injury Frequency Rate (LTIFR), Total Recordable Injury Rate (TRIR), near-miss reporting rate, sick leave %, days since last LTI. Trending by type, location, period. Benchmarks against industry and targets.
SDS management: Safety Data Sheets in SharePoint per chemical, linked to D365 chemical register (QAC-032). Accessible to all workers at applicable locations. Current SDS ensured via review workflow.
PPE management: PPE types tracked per employee in D365 HR: issue date, replacement schedule, certification/inspection status (fall protection, harness testing). Replacement alerts via Power Automate. PPE inventory managed via D365.