September 30, 2026

The paper check said the freezer was fine. The freezer was not fine.

A chilled food storage temperature above 8°C is a legal breach in England, Wales and Northern Ireland; the Food Standards Agency recommends 5°C as the operating target. A once-daily paper check can miss an excursion that happens at 2am and self-corrects by the time the morning shift arrives — while the stock, and the audit trail, are both already compromised.

The sheet on the clipboard has a tick against 6am. It has one against 2pm too. Both are signed. What it does not have is any record of what happened at half past midnight, when the compressor cycled out and never came back — because nobody was there to see it, and the paper check only asks what the temperature was when somebody looked.

By the time the morning shift opened up, the display cabinet had spent seven hours above threshold. The stock was already gone. The log said the check was done, because it was — the check was done, it just could not see the seven hours it wasn't looking.

A daily paper check does not fail because someone is careless. It fails because it can only ever report one moment, and the moment that matters is rarely the one that gets checked.

24-hour temperature trace showing two paper checks with an overnight excursion invisible between them

The blind spot in a once-a-day check

A week-long grid comparing manual twice-daily check coverage against continuous monitoring coverage

Cold storage compliance runs on the assumption that a spot check, done properly, stands in for continuous knowledge. Across a single site with one fridge, that assumption mostly holds — someone is usually nearby, and a failure gets noticed by smell or by sight long before the paperwork catches up.

Across a multi-site retail estate, the assumption stops holding at exactly the moment it matters most. Deep freezes, display cabinets and walk-ins fail outside trading hours more often than not, because that is when nobody is in the building to notice a compressor cycling wrong or a door left slightly open. A twice-daily check has, at best, a two-point sample of a 24-hour period. Everything between those two points is invisible until the next check — or until the stock is visibly spoiled, which is the same information arriving far too late to act on.

Multiply a single overnight failure by an estate of three hundred sites and the pattern is not an edge case. It is a recurring cost that shows up as shrinkage, written off month by month, with no single failure large enough to trigger an investigation into why it keeps happening.

What the Food Standards Agency actually requires

Cold food storage in England, Wales and Northern Ireland has a legal maximum: 8°C. The FSA's own guidance sets 5°C as the operating target, to allow for normal fluctuation without breaching the legal limit, and describes the range between 8°C and 63°C as the "danger zone" in which bacteria multiply fastest. Frozen storage sits at the other end of the scale — the FSA describes commercial freezer temperatures of -18°C to -21°C as the range that halts bacterial growth, though it does not kill the bacteria already present, which is why a frozen product that has previously excursed above threshold carries risk even if it reads correctly cold when checked.

None of that requires continuous monitoring by name. What it requires is evidence — and a written log with two entries a day is evidence of two moments, not of the period in between. When an Environmental Health Officer asks for proof that a chilled cabinet stayed under 8°C through a bank holiday weekend with the site closed, "we checked it on Friday and again on Tuesday" is not an answer that holds up, however genuinely both checks passed.

Outcome: catch the excursion at 2am, not at the morning shift

The problem it solves. A compressor failure at half past midnight, invisible until the first person walks in and finds the stock already spoiled.

What changes:

  • Temperature logged continuously at the asset, not sampled twice a day
  • An anomaly alert raised the moment a reading drifts, day or night, trading hours or not
  • The alert routed as a work order into your existing Smart Buildings dashboard, not left in an unmonitored inbox overnight

The outcome. The failure is caught inside the hour it happens, not discovered seven hours later by someone opening a door.

Deployment reality: anomaly detection live from day 90 across the estate.

Solution: Cold Storage Monitoring.

One freezer failure, multiplied by three hundred sites

Three cold storage environments, deep freeze, display cabinet and walk-in, each with the sensor it needs

The stock loss from a single overnight failure is the visible cost. It is rarely the largest one. Every incident like it also generates an audit gap — a period the paper record cannot account for — and across an estate large enough to trigger scheduled EHO visits, a pattern of unexplained gaps is what turns a routine inspection into an enforcement conversation.

Device selection matters here in a way that a single-site operator never has to think about. A deep freeze and a display cabinet fail in different ways, at different rates, and need different sensors to monitor reliably — a probe built for a walk-in will not survive or accurately read a display cabinet's defrost cycle, and the reverse is equally true. An estate standardised on one device across every environment gets the compromise sensor everywhere, which is what produces the false alerts that train a busy site team to start ignoring the app within a few months. Choosing per environment rather than per supplier contract is what keeps the alert stream trustworthy at scale.

Existing refrigeration and building management points are read rather than replaced where they already exist — the sensor layer sits alongside what is already installed rather than requiring a full re-fit before any data starts flowing.

Outcome: the right sensor for each environment, not one compromise device

The problem it solves. A single device standard applied across deep freezes, display cabinets and walk-ins, generating false alerts in whichever environment it fits worst.

What changes:

  • Sensor type selected per environment rather than per supplier agreement, from a hardware-agnostic range of 300+ device types and protocols
  • Existing refrigeration monitoring and BMS points integrated as inputs where they already exist
  • Alert thresholds set per asset type, so a display cabinet's normal defrost cycle is not read as a fault

The outcome. An alert that a site team trusts enough to act on immediately, because it has stopped being wrong often enough to ignore.

Deployment reality: device mix agreed per environment at day 1, before a single unit is dispatched.

Solution: Cold Storage Monitoring.

From a paper log to a defensible record

The shift that matters for an audit is not from manual to automatic. It is from a record of moments to a record of a period. A continuous log covering every minute the site was open or closed answers the question an EHO actually asks — not "was it checked," but "was it in range the whole time" — and it does so without anyone having to reconstruct what probably happened between two signatures.

That record also becomes the thing that proves the freezer failure was caught and acted on, not just that it happened. A timestamped alert, a logged response, and a continuous temperature trace either side of the incident is a stronger position in front of an inspector than a clean sheet with no gap in it at all — a suspiciously perfect paper log invites more scrutiny than an honest, continuous digital one that shows exactly when something went wrong and how fast it was fixed.

Outcome: a digital record that survives an inspection

The problem it solves. A written log that can only prove what happened at the two moments someone looked, defended after the fact rather than during the incident.

What changes:

  • A continuous, timestamped temperature record for every asset, covering the full period the site was open and closed
  • Every alert paired with a logged response, so the record shows resolution, not just deviation
  • Records held centrally across the estate, retrievable by site and by date without a call to a store manager

The outcome. Zero stock loss from undetected excursions, and audit readiness that does not depend on which two moments a paper check happened to catch.

Deployment reality: a validated, continuous record from day 60, across the estate.

Solution: Cold Storage Monitoring.

Where to start

The useful first step is not replacing every fridge thermometer at once. It is knowing which sites and which asset types carry the most exposure right now, so the rollout starts where an overnight failure would cost the most.

Get your IoT audit — thirty minutes, no obligation, and you finish with a scoped deployment plan for your estate: device mix per environment, an install schedule sequenced the same way a 335-site, roughly 6,000-sensor rollout was run, and the gate dates that make it a project with an end, not an open-ended one.

Get your IoT audit
Modern glass office building with landscaped plaza where people in business attire walk and sit under green trees on a sunny day.Illustration of a large hand in a suit building a brick wall with colorful bricks and construction tools below.Black speech bubble icon with three white dots aligned horizontally inside.
Get in touch to see how we can improve the efficiency, compliance, and delivery of your buildings and operations.