
A chilled food storage temperature above 8°C is a legal breach in England, Wales and Northern Ireland; the Food Standards Agency recommends 5°C as the operating target. A once-daily paper check can miss an excursion that happens at 2am and self-corrects by the time the morning shift arrives — while the stock, and the audit trail, are both already compromised.
The sheet on the clipboard has a tick against 6am. It has one against 2pm too. Both are signed. What it does not have is any record of what happened at half past midnight, when the compressor cycled out and never came back — because nobody was there to see it, and the paper check only asks what the temperature was when somebody looked.
By the time the morning shift opened up, the display cabinet had spent seven hours above threshold. The stock was already gone. The log said the check was done, because it was — the check was done, it just could not see the seven hours it wasn't looking.
A daily paper check does not fail because someone is careless. It fails because it can only ever report one moment, and the moment that matters is rarely the one that gets checked.
Cold storage compliance runs on the assumption that a spot check, done properly, stands in for continuous knowledge. Across a single site with one fridge, that assumption mostly holds — someone is usually nearby, and a failure gets noticed by smell or by sight long before the paperwork catches up.
Across a multi-site retail estate, the assumption stops holding at exactly the moment it matters most. Deep freezes, display cabinets and walk-ins fail outside trading hours more often than not, because that is when nobody is in the building to notice a compressor cycling wrong or a door left slightly open. A twice-daily check has, at best, a two-point sample of a 24-hour period. Everything between those two points is invisible until the next check — or until the stock is visibly spoiled, which is the same information arriving far too late to act on.
Multiply a single overnight failure by an estate of three hundred sites and the pattern is not an edge case. It is a recurring cost that shows up as shrinkage, written off month by month, with no single failure large enough to trigger an investigation into why it keeps happening.
Cold food storage in England, Wales and Northern Ireland has a legal maximum: 8°C. The FSA's own guidance sets 5°C as the operating target, to allow for normal fluctuation without breaching the legal limit, and describes the range between 8°C and 63°C as the "danger zone" in which bacteria multiply fastest. Frozen storage sits at the other end of the scale — the FSA describes commercial freezer temperatures of -18°C to -21°C as the range that halts bacterial growth, though it does not kill the bacteria already present, which is why a frozen product that has previously excursed above threshold carries risk even if it reads correctly cold when checked.
None of that requires continuous monitoring by name. What it requires is evidence — and a written log with two entries a day is evidence of two moments, not of the period in between. When an Environmental Health Officer asks for proof that a chilled cabinet stayed under 8°C through a bank holiday weekend with the site closed, "we checked it on Friday and again on Tuesday" is not an answer that holds up, however genuinely both checks passed.
The problem it solves. A compressor failure at half past midnight, invisible until the first person walks in and finds the stock already spoiled.
What changes:
The outcome. The failure is caught inside the hour it happens, not discovered seven hours later by someone opening a door.
Deployment reality: anomaly detection live from day 90 across the estate.
Solution: Cold Storage Monitoring.
The stock loss from a single overnight failure is the visible cost. It is rarely the largest one. Every incident like it also generates an audit gap — a period the paper record cannot account for — and across an estate large enough to trigger scheduled EHO visits, a pattern of unexplained gaps is what turns a routine inspection into an enforcement conversation.
Device selection matters here in a way that a single-site operator never has to think about. A deep freeze and a display cabinet fail in different ways, at different rates, and need different sensors to monitor reliably — a probe built for a walk-in will not survive or accurately read a display cabinet's defrost cycle, and the reverse is equally true. An estate standardised on one device across every environment gets the compromise sensor everywhere, which is what produces the false alerts that train a busy site team to start ignoring the app within a few months. Choosing per environment rather than per supplier contract is what keeps the alert stream trustworthy at scale.
Existing refrigeration and building management points are read rather than replaced where they already exist — the sensor layer sits alongside what is already installed rather than requiring a full re-fit before any data starts flowing.
The problem it solves. A single device standard applied across deep freezes, display cabinets and walk-ins, generating false alerts in whichever environment it fits worst.
What changes:
The outcome. An alert that a site team trusts enough to act on immediately, because it has stopped being wrong often enough to ignore.
Deployment reality: device mix agreed per environment at day 1, before a single unit is dispatched.
Solution: Cold Storage Monitoring.
The shift that matters for an audit is not from manual to automatic. It is from a record of moments to a record of a period. A continuous log covering every minute the site was open or closed answers the question an EHO actually asks — not "was it checked," but "was it in range the whole time" — and it does so without anyone having to reconstruct what probably happened between two signatures.
That record also becomes the thing that proves the freezer failure was caught and acted on, not just that it happened. A timestamped alert, a logged response, and a continuous temperature trace either side of the incident is a stronger position in front of an inspector than a clean sheet with no gap in it at all — a suspiciously perfect paper log invites more scrutiny than an honest, continuous digital one that shows exactly when something went wrong and how fast it was fixed.
The problem it solves. A written log that can only prove what happened at the two moments someone looked, defended after the fact rather than during the incident.
What changes:
The outcome. Zero stock loss from undetected excursions, and audit readiness that does not depend on which two moments a paper check happened to catch.
Deployment reality: a validated, continuous record from day 60, across the estate.
Solution: Cold Storage Monitoring.
The useful first step is not replacing every fridge thermometer at once. It is knowing which sites and which asset types carry the most exposure right now, so the rollout starts where an overnight failure would cost the most.
Get your IoT audit — thirty minutes, no obligation, and you finish with a scoped deployment plan for your estate: device mix per environment, an install schedule sequenced the same way a 335-site, roughly 6,000-sensor rollout was run, and the gate dates that make it a project with an end, not an open-ended one.
.avif)

