The tracker on the truck was never watching your cargo

Apple Ko
Apple Ko
August 16, 2026
📖 11 min read min read
The tracker on the truck was never watching your cargo
Two accurate measurements of two different things. The unit reports on the equipment; the probe reports on the goods.

Consider a familiar pattern. A pallet of chilled product leaves a distribution centre in the morning and reaches a retail depot that evening. The reefer telematics report for the trailer is clean: setpoint held, no alarms raised, no door-open events in the log.

At intake, the receiver measures product temperature out of specification and rejects the load.

Both parties are looking at real data, and neither dataset is fraudulent. The carrier's record describes how the refrigeration equipment behaved. The receiver's measurement describes the condition of the goods. Nothing in either record establishes when the exposure occurred or which custody segment caused it — and that is the question the claim will turn on.

It is also worth noting what the clean log does not establish. If the trailer had no door sensor fitted, or the sensor was not functioning, the absence of a door-open event is not evidence that no door opened. A gap in instrumentation and a confirmed non-event look identical in a report.

What is cargo-level evidence?

Cargo-level evidence is a record produced by a device that travels with the goods rather than with the vehicle, capturing condition and location on a single time base across every custody segment of a shipment. It differs from vehicle telematics in what it is attached to: the shipment, not the asset moving the shipment. That distinction determines whether the record can answer the question a dispute actually asks — what happened to this cargo, where, and during whose leg. In a temperature-controlled context it is the difference between a monitoring feed and usable cold chain evidence.

The failure pattern recurs across verticals: the instrumentation was installed on the wrong object, and nobody noticed until the data was needed as proof.

A shrink-wrapped pallet inside a refrigerated trailer with temperature, location, humidity, door, shock and motion channels radiating from a clock at the centre of the load, representing a cargo-level record on one shared time base.
Cargo-level evidence attaches to the shipment rather than the vehicle, and ties every channel to one clock. The shared time base is what turns separate readings into a single record that can be reconciled.

What does a reefer unit actually measure?

For cargo-condition purposes, the primary temperature signals from a refrigeration unit are air measurements associated with the refrigeration system. Depending on configuration and commodity, a unit typically senses return air, supply or discharge air, or both, and controls against a selected strategy and setpoint. Units also report ambient temperature, coil state, fuel, power, and alarms — but the temperature figure that reaches a compliance report is almost always an air measurement taken at the unit, not a measurement taken inside the product.

A pallet is not air. It has mass and packaging, so it warms and cools slowly and unevenly. A case on the outer face of a pallet near the door can follow a different thermal history than a case in the centre of the same pallet, during the same trip, under the same setpoint, recorded by the same clean telematics report.

This is not a defect in the refrigeration unit or in the telematics system attached to it. Both are performing correctly and reporting accurately on what they were built to observe. The problem is scope. A reefer report is a statement about equipment performance. A cold chain dispute is a question about product condition. Equipment performance is evidence toward product condition; it is not a substitute for it.

The gap widens with every variable the unit cannot see: how long the door stood open during a multi-stop route, how warm the dock was during staging, how long the pallet waited on an unrefrigerated apron for a bay, whether airflow was blocked because the load was stacked to the ceiling.

A clean reefer log and a rejected load are not a contradiction. They are two accurate measurements of two different things.

Why does vehicle data stop at the dock door?

The second structural limit is custody. A tracker bolted to a trailer produces data for exactly as long as the cargo is inside that trailer. The moment the pallet is unloaded, cross-docked, staged, consolidated onto a different vehicle, or held in a third-party facility, the vehicle's record ends and a new gap begins.

Multi-leg shipments change hands more than once, and each handoff creates a window in which no vehicle-mounted system is observing the goods. Some of those windows are well controlled — plenty of cross-docks are refrigerated and disciplined. But the uncontrolled ones cluster here, because a handoff is when product is most likely to sit on a dock waiting, and the vehicle record is blank for exactly that interval.

The result is a record with structural holes at some of the moments most likely to matter. This is the same pattern examined in why cold chain visibility breaks at every handoff, viewed here from the hardware side rather than the process side.

A device travelling with the cargo removes that particular discontinuity. It keeps recording across trailers, docks, and reconsolidations, so its record is organised around the shipment rather than around any one asset. It introduces different failure modes — the battery can die, the device can be removed or separated when a pallet is split, connectivity and satellite fix can both drop inside a building — but those are failures of a single record rather than gaps designed into the architecture.

A four-stage shipment journey comparing vehicle-mounted visibility, which goes blank during cross-dock and facility dwell, against a cargo-level device that keeps recording continuously from origin loading through to final delivery.
Vehicle-mounted coverage is discontinuous by construction. The blind spots fall on facility dwell — origin staging, cross-dock consolidation, and depot intake — which is exactly where uncontrolled exposure concentrates.
Dimension Vehicle telematics Cargo-level evidence
Attached to The asset The shipment
Measures Supply and return air at the unit Conditions at the pallet or case
Coverage ends At unload At final delivery
Custody segments One per vehicle Continuous across all
Answers in a dispute Did the equipment perform? What happened to the goods?
Control of record
commonly sits with
The carrier or fleet operator Whoever specified and deployed the device

The last row is the one that usually goes unexamined, and it deserves care because the reality is contractual rather than absolute. Access rights to telematics data vary considerably — shipper-owned trailers, leased equipment, broker and 3PL arrangements, and audit clauses all change the picture, and many shippers do have portal access by agreement. But the default arrangement often places practical control of the record with the party whose performance the record is being used to assess. That is not an accusation of bad faith; it is a question worth answering in advance, about retention periods, export formats, and how quickly data can actually be produced when a claim surfaces long after delivery.

Did the FSMA 204 extension change the hardware requirement?

No. The deadline moved; the record requirement did not. The original compliance date for the FDA's Food Traceability Rule was January 20, 2026. Following a proposed 30-month extension and subsequent congressional action, the operative compliance date is now July 20, 2028. The rule's substance is unchanged: traceability lot codes, Key Data Elements, Critical Tracking Events, and the obligation to provide required records to the FDA generally within 24 hours of a request — or within another reasonable time agreed with the agency — with sortable electronic spreadsheet requirements in specified urgent circumstances.

What the extension bought was implementation time. The stated concerns were about coordinating with supply chain partners and building interoperable data systems, not about whether the underlying records were reasonable. Reading the delay as a softening of documentation expectations gets it backwards: a 30-month runway to build interoperable traceability systems signals more intent than a rushed deadline would have.

A related reference in the medicinal-products sector has been in force considerably longer, and it is worth flagging that the two are not equivalents — FSMA 204 is a US food traceability rule, while EU Good Distribution Practice guidelines (2013/C 343/01) govern medicinal products, under a different legal basis and for a different purpose. GDP addresses transportation in Chapter 9, which states that required storage conditions should be maintained during transportation within the limits described by the manufacturer or on the outer packaging. Precision matters on the citation too, because it is frequently miscited: Annex 15 belongs to the EU GMP framework and covers qualification and validation. GDP transport requirements live in Chapter 9.

What the two have in common is narrower, but more relevant than a false equivalence would suggest. Neither prescribes a sensor mounting point. FSMA 204 is organised around traceability lots and events rather than around vehicles; EU GDP Chapter 9 is organised around maintaining the product's required storage conditions in transit. In both cases the subject of the record is the goods. A record scoped to a vehicle therefore answers a narrower question than the one a regulator or a claims adjuster is actually asking.

What makes a cargo record survive a dispute?

Attaching the device to the shipment is necessary but not sufficient. A logger that travels with the pallet and records temperature at, say, fifteen-minute intervals still produces a weak record, because temperature alone cannot attribute anything. It establishes that a problem occurred without establishing where, when, or under whose control.

Four properties separate a record that settles an argument from one that starts a new one.

A single time base. If temperature, position, and door events are timestamped by separate clock sources that are not locked to a common reference, correlating them introduces an uncertainty window. In a liability conversation, that window is where the argument lives. Synchronisation does not eliminate offset — it bounds it and documents it, which is the difference between an offset that can be stated in writing and one that can be challenged.

Context channels alongside temperature. A rising temperature curve is a fact. That same curve, timed against a light sensor registering a door opening while the accelerometer shows the unit stationary and the position unchanged for a sustained dwell, becomes an explanation. Context channels are what turn a symptom into a candidate cause.

Custody segmentation. A record that can be sliced by handoff — this interval was the origin facility, this one was carrier A, this one was the cross-dock — supports attribution in a way an undifferentiated timeline cannot. The important caveat is that a device cannot know legal custody. It knows position, motion state, and time. Segmentation only becomes evidentiary when those observations are reconciled against something external: scan events, geofence definitions, bills of lading, contractual handoff times. Done properly it narrows the argument considerably; on its own it does not settle liability. Without any segmentation at all, though, every party in the chain has the same defence available, which is that it happened on somebody else's leg.

Documented uncertainty. A record that states its own limits is more defensible than one that implies precision it does not have. Position may be unavailable inside a metal-walled facility. A sample interval of five minutes cannot resolve a two-minute event. Stating these bounds in the specification is not a weakness in the record — it is what makes the rest of the record credible, because a dataset that never acknowledges a limitation invites the question of what else it is not saying.

How should this change a hardware evaluation?

Most evaluation briefs are organised as a component inventory: temperature accuracy, battery life, IP rating, cellular bands, certifications. Every supplier on a shortlist answers those cleanly, and the answers are usually correct. They are also insufficient, because they describe sensors in isolation rather than the architecture connecting them — and the architecture is what determines whether the output functions as evidence.

Four questions surface the difference, and none of them are exotic:

How are sensor channels time-aligned — one clock source, or multiple timers synchronised periodically? What is the maximum offset between two channels in the same report?

What happens to buffered data during a coverage gap — are readings back-filled with their original capture timestamps, or re-stamped at reconnection?

How is a temperature excursion defined on the device — one sample out of range, or a sustained period? Is that definition configurable per deployment, or fixed in firmware?

Can the record be segmented by custody event, and what identifies a handoff — a manual scan, a geofence, a motion state change?

None of these are trick questions, and a supplier who has thought about the evidentiary use case will have answers ready. The difficulty is that most evaluation forms have no rows for them, so the information is never volunteered — and a supplier who volunteers a qualified answer tends to look less decisive than one who writes a clean number with no conditions attached. The form, in other words, quietly rewards the least careful respondent. This is closely related to the sensor-level gap examined in why FSMA 204 compliance breaks at the physical layer.

The right answers also depend on the deployment. A disposable single-trip logger on a low-value lane and a reusable multi-sensor device on a high-value pharmaceutical lane face different evidentiary thresholds and different cost ceilings. The questions are worth asking in both cases; the acceptable answers are not the same.

Frequently asked questions

Is vehicle telematics data useless for cold chain compliance?

No. Reefer telematics is strong evidence of equipment performance and is genuinely useful for fleet operations, preventive maintenance, and demonstrating that a carrier met its obligations. The limitation is scope: it describes the vehicle's behaviour, not the cargo's condition, and its coverage ends when the cargo leaves the vehicle. It works best as one input alongside a cargo-level record, not as a replacement for one.

Does a data logger in the pallet solve the problem?

Partially. A logger travelling with the goods removes the wrong-object problem and the custody discontinuity. What it typically does not provide is position, context channels, or synchronised multi-channel correlation — so it can establish that a temperature excursion happened without establishing where or under whose control. It answers the first question in a dispute and none of the follow-ups.

Has the FSMA 204 delay reduced the urgency of upgrading hardware?

The compliance date is now July 20, 2028. Whether that is distant depends on the organisation: fleet-wide hardware rollouts typically involve evaluation, pilot, integration, and phased deployment, and for large estates that sequence is measured in years rather than months. Anyone whose replacement cycle runs that long is already inside the decision window. The extension changed the deadline; it did not change what the records have to show.

What is the difference between EU GDP Chapter 9 and Annex 15?

They belong to different frameworks. Chapter 9 of the EU Good Distribution Practice guidelines (2013/C 343/01) covers transportation of medicinal products, including maintenance of storage conditions in transit. Annex 15 belongs to the EU Good Manufacturing Practice framework and covers qualification and validation. The two are frequently conflated in vendor material; for transport requirements, Chapter 9 is the correct reference.

How many sensor channels does a cargo record actually need?

Enough to attribute, which in practice means more than temperature. Position establishes where, a light or door channel establishes whether the container was opened, motion distinguishes transit from stationary dwell, and shock identifies handling events. The specific count matters less than whether the channels share a time base — four synchronised channels produce a more defensible record than seven unsynchronised ones.

Key takeaways

The tracker on the truck was built to watch the truck, and it has been doing that job accurately the whole time. That is worth stating plainly, because the failure being described here is not a hardware defect and not a vendor's fault. It is a scoping decision that was made implicitly, usually years earlier, when someone chose what to instrument. Accuracy in the wrong measurement does not accumulate into evidence about the right one, and no amount of reporting polish will close that gap after the fact.

Working through the evidence requirements for a specific shipment profile, or evaluating hardware against them? Let's discuss your requirements.

Tags
#Cold Chain #Supply Chain Visibility #IoT Hardware #FSMA 204

Share This Article

If you found this article helpful, please share it with your network

Apple Ko

About Apple Ko