The certificate comes back on a Thursday morning and one line on it changes your week. As found: out of tolerance. The wrench you sent out on a routine cycle was not measuring what it said it was measuring, and an out of tolerance calibration result is not a statement about the tool sitting on the bench in front of you. It is a statement about every job that tool touched before it left.
Nobody on the floor reacts to the wrench. They react to the calendar.
Here is the moment where it actually gets hard. The last passing calibration was six weeks ago. In those six weeks the wrench went out of the crib and came back thirty-odd times, in the hands of nine people, across two cells and one weekend of overtime. Somewhere in that window is a population of fasteners that were torqued by a tool that was wrong. You now have to decide how big that population is, whether the error was large enough to matter, and what you are going to do about the parts that already shipped.
That backward reconstruction has a name. It is called reverse traceability, and it is the part of calibration management that almost nothing published on the internet will help you with. The tool tracking vendors write about the forward case, which is flagging an expired tool before somebody checks it out. The calibration laboratories write about their own paperwork obligations under their own accreditation standard. If you are standing between those two, holding a bad wrench and a month of finished jobs, neither of them is talking to you.
This article walks the reconstruction in the order it actually gets done, names the standards that put the obligation on you rather than on your lab, corrects a regulatory citation that most pages on this topic are still getting wrong, and says plainly which link in the chain a tool tracking system supplies and which link it does not. That last part is short and it is the most important paragraph here, so it comes second rather than last.
Start with the limit, because everything else you decide depends on it.
A tool check-in and check-out record gives you four facts, and they are genuinely useful facts:
Here is what that record does not contain, and no amount of tagging changes this:
Say it as one sentence you can carry into the meeting where somebody asks whether buying something would have prevented this. Tool tracking narrows the suspect population. It does not eliminate it, and it does not produce the torque value.
That is not a small contribution. The difference between re-inspecting a named list of jobs and re-inspecting a quarter’s output is the entire cost of the event. But it is a narrowing, and anybody who tells you otherwise is selling you a data field that does not exist. The mechanism itself is ordinary: our RFID check-in and check-out page describes the three ways a crib transaction typically gets captured, and the honest summary of all three is that they produce custody, not measurement.
Reverse traceability is the process of identifying everything an instrument touched between its last passing calibration and the out of tolerance finding, then deciding whether the measured error was large enough to have changed any of those outcomes.
Two things in that sentence do the work.
The window is bounded by evidence, not by convenience. It opens at the last calibration the tool actually passed, not at the last time it was calibrated. If a tool was calibrated in March, passed, calibrated in June, failed, the window is March to June. If it was adjusted in June and failed again in September, you have a harder problem and possibly two windows.
The finding is the as-found reading, not the certificate verdict. This is the distinction that decides how expensive your week is. A calibration report carries as-found data, the readings taken before any adjustment, and as-left data, the readings after. The as-left data tells you the tool is fine now. The as-found data is the only evidence you have about how the tool was behaving while it was in service. An instrument can leave the lab fully adjusted and passing and still carry an out of tolerance flag on the as-found side, and that flag is the one that starts the clock running backward.
Then comes the part that separates a proportionate response from a panic. The magnitude of the error against your process tolerance decides the outcome, not the existence of the flag. A click wrench reading two percent low against a specification that already carries a ten percent band is a different situation from a wrench reading twenty percent low on a joint with a narrow preload window. The first may be a documented monitor-and-move-on. The second is a re-inspection, and possibly a recall. Both start with the same line on the same certificate.
Hex Technology, writing about torque tool calibration and verification from the bolting side rather than the tracking side, states the underlying problem more bluntly than any vendor page will. In their words: “How many fasteners did that torque wrench touch while out of calibration? There is no good way to tell.”
That is an industry admission of exactly the gap this article is about, from a source with nothing to sell you in the tracking business. It is also, read carefully, a statement about records rather than about physics. There is no good way to tell because the record that would tell you does not usually exist.
A common and expensive misreading is that the calibration laboratory is handling this.
The laboratory operates under ISO/IEC 17025, and clause 7.10 of that standard is titled Nonconforming work. That clause governs what the laboratory does when the laboratory’s own work does not conform: control it, evaluate it, notify the customer, recall results where necessary. It is a real obligation and accredited labs take it seriously.
It is also entirely about the lab. Clause 7.10 does not ask your lab to work out what your wrench did to your product. The lab’s duty in an out of tolerance event is to report the as-found condition accurately and tell you about it. At that point the problem is transferred, completely, to you.
This is why the search results on this topic split so cleanly and so uselessly. Search one way and you get equipment vendors describing how to prevent an expired tool from being checked out. Search the other and you get accredited laboratories and quality consultancies describing clause 7.10 and their own nonconforming-work paperwork. The reconstruction in between, the part where a person has to define a population of affected work and defend that definition to an auditor, belongs to the manufacturer, and very little is written about it.
Three regimes cover most readers of this page. They say close to the same thing in different vocabularies, and one of them changed recently in a way that most published guidance has not caught up with.
ISO 9001:2015 clause 7.1.5.2 is titled Measurement traceability. The ISO 9001 Auditing Practices Group, a joint ISO and IAF body, published a short guidance paper on it that quotes the clause’s opening requirement: when measurement traceability is a requirement, or is considered by the organization to be an essential part of providing confidence in the validity of measurement results, measuring equipment shall be calibrated or verified, identified, and safeguarded. The same paper tells certification auditors to seek demonstrable and objective evidence of that traceability.
The obligation that matters for reverse traceability is at the end of that clause, and it is the one nobody quotes. The organization has to determine whether the validity of previous measurement results was adversely affected when equipment is found unfit for its intended purpose, and take appropriate action.
AS9100D carries the same clause number and adds to it. The Manufacturing Extension Partnership center at the University of Utah, describing the aerospace version, summarizes the additions as “a register, recall method and the organization shall determine the validity of previous measurements when the equipment is found unfit for its intended use,” and then makes an observation worth pinning above a desk:
“One of the most common findings in an AS9100D audit is not meeting the requirement to take action based on the ‘As Found’ condition.”
Read that twice if you run an AS9100D shop. The finding is not that the tool went out of tolerance. Tools go out of tolerance. The finding is that nothing happened afterward.
The same page adds a second point that is easy to miss and cheap to fix. If you pull a tool out of service for any reason, measure it against a standard first to establish its as-found condition, and if it is out of tolerance, run the same response you would run if the lab had found it. A tool that gets quietly retired to a drawer takes its window with it.
If you make devices, the reference you have seen everywhere is 21 CFR 820.72. The sentence people are pointing at is in paragraph (b), and it reads, verbatim: “When accuracy and precision limits are not met, there shall be provisions for remedial action to reestablish the limits and to evaluate whether there was any adverse effect on the device’s quality.”
That section is no longer part of the CFR.
FDA published the final rule “Medical Devices; Quality System Regulation Amendments” on February 2, 2024, and the resulting Quality Management System Regulation took effect February 2, 2026. Part 820 was retitled from Quality System Regulation to Quality Management System Regulation. FDA’s own overview of the QMSR lists the regulation’s sections in full: 820.1 Scope, 820.3 Definitions, 820.7 Incorporation by reference, 820.10 Requirements for a quality management system, 820.35 Control of records, and 820.45 Device labeling and packaging controls. Section 820.72 is not among them. The current table of contents for part 820 at Cornell LII shows Subpart A, Subpart B, and then “Subparts C-O [Reserved]”. Former 820.72 sat in Subpart G.
The requirement did not go away. It moved. Section 820.7 incorporates ISO 13485:2016 by reference, and the impact-assessment obligation now lives in clause 7.6, control of monitoring and measuring equipment.
You do not have to take that mapping on faith, and you do not have to buy the standard to see what the obligation is. FDA hosts the Medical Device Single Audit Program audit approach, which is written as a task list for auditors and states plainly what clause 7.6 requires. Its Task 14 is titled “Impact analysis of monitoring and measuring device found out of specifications,” and it instructs the auditor to:
“Confirm that the medical device organization assesses and records, the validity of previous measurements when equipment is found not to conform to specified requirements, and takes appropriate action on the equipment and any product affected.”
The same document has a section headed “When equipment is found to be out-of-tolerance” which says the organization “must assess and record the validity of previous measuring results and take appropriate action on the equipment and any product affected.”
That is reverse traceability, described by an auditor’s checklist, in language nobody can argue with.
Two practical consequences. First, if your internal out of tolerance procedure cites 21 CFR 820.72 by section number, it is now citing a reserved section, and that is a document control problem waiting to be written up. Second, if you are reading guidance on this topic that dates itself later than February 2026 and still points at 820.72, that page has not been checked, and you should treat everything else on it with the same suspicion.
One footnote for precision. The MDSAP crosswalk cites FDA 21 CFR 820.72(a) alongside ISO 13485 clause 7.6 for that task, while the sentence about evaluating adverse effect is textually in 820.72(b). The distinction never mattered much in practice and matters less now that the section is reserved.
For hand torque tools specifically, ISO 6789 is the standard that governs calibration and recalibration. Hex Technology’s summary is that “ISO 6789 states that manual torque wrenches shall be calibrated once every 12 months.”
The interesting number in the same article is the next sentence. From their own studies, they report that “roughly 60% of manual torque wrenches will be out of calibration at the end of 12 months.” That is one organization’s finding rather than an industry consensus figure, and it should be read that way. But it points at something structural: if the annual interval is the only control, then the out of tolerance event is not an anomaly you occasionally handle. It is a recurring event you should have a standing procedure for.
They also note, from a study in which pipefitters checked torque tools out at the start of a shift and returned them at the end, that “roughly 5% of all wrenches will be out of calibration during a turnaround, which we would consider moderate usage.” Usage drives drift, and a fixed calendar interval is blind to usage.
Our own compliance page’s ISO 6789 section describes the forward half of this: tag each torque wrench, track its recalibration interval, let a technician confirm cert status before use, alert on overdue tools, keep the calibration history on record. All of that is correct and all of it is prevention. This article is the other half, which is what you do on the morning prevention did not work.
Seven steps. Notice where the tracking system appears, which is fourth, and notice what it hands you when it gets there, which is a candidate list rather than an answer.
1. Quarantine the tool and preserve the certificate. Tag it, pull it from service, and keep the as-found data. Every measurement made after the notification lands is a measurement knowingly taken with a nonconforming instrument, and an auditor reads those very differently from measurements taken in good faith.
2. Fix both ends of the window. The start is the date of the last calibration the tool passed. The end is the moment it came out of service, which is not always the date on the certificate. If the tool sat in a drawer for three weeks before it went to the lab, the end of the exposure window is when it stopped being used, and somebody has to be able to say when that was.
3. Establish the magnitude against your process tolerance. Which parameter failed, at which point in the range, by how much, against what your process actually needs. This is the step that decides whether the response is a note in a file or a recall, and it is engineering judgment applied to metrology, not a database query.
4. Build the usage population. Now, and only now, does the tool record earn its place. The question is which jobs, cells, shifts and people were exposed during the window. A crib with no checkout record answers this with a guess. A crib with RFID tool tracking answers it with a list of custody events: this tool, these dates and times, these holders, these locations.
That list is a genuine narrowing and it is where most of the savings in the entire event come from. It is also not the answer. It tells you where to look for affected work. It does not tell you what work was affected.
5. Intersect the usage population with the work records. This is the join that decides whether step 4 was worth anything, and it happens outside the tool system entirely. Travelers, job cards, router steps, torque sheets, MES transactions, shift logs. If your work records carry the operation, the time and the operator, the intersection is mechanical. If they carry only a date and a lot number, the intersection is coarse and your affected population inflates accordingly.
6. Decide: monitor, re-inspect, or recall. A named person makes this call, in writing, with the magnitude analysis and the affected population in front of them. It is a quality engineering decision. No system makes it and no system should be described as making it.
7. Close it out and fix the interval. Document the assessment, the decision, the actions and the evidence. Then treat the out of tolerance result as what it is, which is evidence that the interval, the handling, or the environment was wrong for that tool. Shorten the interval, add in-process verification, fix the drop or the overload, or all three.
Steps 1, 2, 3, 6 and 7 are procedure and judgment. Step 5 is your existing shop-floor records. Step 4 is the only one where hardware helps, and it helps a lot, and it is still one step out of seven. That ordering is the same one we argue for everywhere: our piece on why you should map the process before quoting anything makes the same point in a different setting, which is that the walk tells you what the record does not.
Step 5 deserves its own section, because it is where most reconstructions actually fail and it is not a technology problem.
The tool-side record and the work-side record have to share a key. In practice the key is some combination of time, person and location. The tool system says wrench 4471 was out from 06:12 to 14:38 on the fourteenth, held by badge 220, in cell B. The work record has to be able to say what badge 220 was working on in cell B during that window, at a resolution finer than “the day shift.”
If your job records carry operator and timestamp at the operation level, your affected population may come out as eleven units. If they carry a date and a work order covering a batch of four hundred, your affected population is four hundred, and the tool record you were so pleased to have did not save you, because the coarser record governs the intersection.
That is worth knowing before you buy anything. Three questions, answerable this week by your own staff with no vendor in the room:
Question 3 is your business case, and it is the only number in this article that is specific to your plant. If the answer is that nobody remembers because it was handled informally, that is also an answer, and it is the one an auditor will find.
Question 2 points at the real ceiling. Tool identity on the job record is the single highest-value change available here, it usually costs a field and a habit rather than a capital project, and it is the one improvement that converts a custody list into a definitive affected-parts list. Shops running a manufacturing execution or plant-floor system usually have somewhere to put it already.
For maintenance and turnaround work the pressure runs the other way. Crews are temporary, tools move between cribs, and the shift boundary is often the finest time resolution anyone has. That is exactly the environment Hex was measuring when they found five percent of wrenches drifting out during a single turnaround, and it is why MRO operations tend to have the widest windows and the weakest joins at the same time.
Stated plainly, inside what the hardware really does.
Passive UHF RFID is the EPC Gen 2 standard at 902 to 928 MHz in the United States. The tags have no battery, they cost from roughly a dime to a few dollars depending on form factor and volume, and they read at typically 5 to 20 feet. In a tool crib that buys you two things: a checkout transaction that captures the individual tool rather than a tool type, and a sweep. A technician with a handheld reader can walk a crib, a gang box or a staging area and reconcile what is physically there against what the system thinks is there, in minutes. Fixed readers such as the Zebra FX9600, Zebra FXR90 or Impinj Speedway R420 connect over LLRP and cover a crib window or a gate, so a tool crossing that point writes a timestamped event without anybody doing anything.
For reverse traceability, that is the value and it is real: the window’s custody list stops being a memory exercise.
Active mesh tags are a different product line with different economics. InfinID’s V-Tag is battery powered and talks over a self-healing IEEE 802.15.4 Zigbee mesh at 2.4 GHz. It reports zone-level presence rather than a coordinate, with a settle time of roughly three to four minutes, and it carries shock and temperature sensing. Tags cost tens of dollars rather than cents, which makes them appropriate for a limited population of high-value tools and wrong for tagging every socket in the building. The shock sensor is worth a mention in this specific context, because a dropped torque wrench is a documented reason to pull a tool for verification, and an alert at the moment of the drop is better evidence than somebody remembering.
Neither one is a live map. We have written separately about what “real time” actually delivers in this class of system, and the short version is that the phrase promises a precision the physics does not supply and the budget would not justify if it did. Zone-level presence with a few minutes of settle is a useful record. It is not a moving dot.
And the limit that governs this entire use case: a read event is not a torque record. It is evidence that a tagged object was in radio range of a reader at a point in time. It says nothing about what the tool did while it was there. There is also a narrower identity question worth understanding before you lean on read data as evidence, which we cover in our piece on whether RFID tags can be cloned during an asset audit: a read proves that a tag answered, and the step from there to “this specific tool was present” depends on how the tag is attached and controlled.
None of these require a purchase. All of them make the next out of tolerance event cheaper.
1. Write the window rule down before you need it. Define, in your procedure, that the exposure window opens at the last passing calibration and closes when the tool came out of service, and define who determines the second date. Arguing about the window while the clock is running is how scope inflates.
2. Record an as-found condition whenever a tool leaves service, not only at the lab. A tool pulled because it “felt wrong,” or retired at the end of a project, should be measured against a standard before it goes in a drawer. Otherwise its window closes unexamined.
3. Put tool identity on the work record. One field. The specific tool, not the tool type. This is the single change that converts a custody list into an affected-parts list, and it is worth more than any hardware on this page.
4. Name the owner of the impact assessment in advance. Not a department. A role, with a named backup, and an escalation time. The most common failure mode is not a wrong decision, it is no decision, carried forward to the next cycle.
5. Set intervals on usage, not only on the calendar. If a wrench does four hundred cycles a week and another does forty, a shared annual interval is a shared annual gamble. Add in-process verification with a torque tester between calibrations and the window you ever have to reconstruct shrinks from twelve months to the gap between verifications.
Plainly, because the alternative is a marketing claim.
We are not a calibration provider. We do not calibrate torque tools, we do not issue calibration certificates, and nothing we sell substitutes for calibration or for verification against a standard.
AssetWorx does not perform an impact assessment. It does not calculate measurement uncertainty, it does not decide whether an error was large enough to matter, it does not write a nonconformance report, and it does not determine a recall scope. It does not record an applied torque value, because no RFID tag measures torque. Those functions belong to your quality system and your metrology function, and they should stay there.
What asset identification contributes is the custody and presence record: which tool, whose hands, what window, what area. That record is step 4 of seven, it is the step that most shops currently answer from memory, and improving it is worth real money on the morning a certificate comes back wrong. It is also, by itself, not enough, which is why step 5 of that list points at your job records rather than at us.
We are publishing this anyway, because three of the five fixes above cost nothing, the most valuable one is a field on a form we do not own, and a shop that can answer the three questions in the join section is in better shape than a shop that instruments a crib and still cannot say who worked what.
What does “out of tolerance” mean on a calibration certificate? It means that during calibration, one or more of the instrument’s as-found readings fell outside the accuracy specification it is required to meet. The critical word is as-found, meaning the readings recorded before any adjustment or repair. An instrument can leave the lab adjusted and passing on its as-left data and still carry an out of tolerance flag, because the as-found condition describes how it was performing while it was in service on your floor. Out of tolerance results are also parameter-specific: a tool can fail at one point in its range and pass everywhere else, and the response should be scoped to the failure, not to the tool in general.
What do I do first when a tool comes back out of tolerance? Quarantine the tool and preserve the as-found data, then establish the two ends of the exposure window before anything else. The window opens at the last calibration the tool actually passed and closes when the tool stopped being used, which is not necessarily the date on the certificate. Only then work out magnitude against your process tolerance, because magnitude determines whether the outcome is monitoring, re-inspection or recall.
What is reverse traceability in calibration? It is the backward reconstruction of everything an instrument touched between its last passing calibration and the out of tolerance finding, followed by an assessment of whether the measured error was large enough to have changed any of those outcomes. Forward traceability establishes that your measurements chain up to national standards. Reverse traceability answers what happens when that chain turns out to have been broken for a period of time.
Does ISO 9001 require an impact assessment after an out of tolerance result? Yes. Clause 7.1.5.2, Measurement traceability, requires the organization to determine whether the validity of previous measurement results was adversely affected when measuring equipment is found unfit for its intended purpose, and to take appropriate action. AS9100D carries the same clause number with additional requirements including an equipment register and a recall method. Failing to act on the as-found condition is a commonly cited audit finding, which suggests a lot of organizations have the procedure and not the habit.
Is 21 CFR 820.72 still the rule for medical device manufacturers? No. FDA’s Quality Management System Regulation took effect February 2, 2026. Part 820 was retitled and restructured, FDA’s list of QMSR sections runs 820.1, 820.3, 820.7, 820.10, 820.35 and 820.45, and the subparts that contained the old section are now reserved. Section 820.7 incorporates ISO 13485:2016 by reference, and the impact-assessment obligation now sits in clause 7.6. The substance is the same, which is that you assess and record the validity of previous measurements and take appropriate action on the equipment and any affected product. The citation is not. If your internal procedure names 820.72, update it.
Whose job is it to figure out which product was affected, mine or the calibration lab’s? Yours. The laboratory works under ISO/IEC 17025, whose clause 7.10, Nonconforming work, governs what the laboratory does about the laboratory’s own nonconforming work, including notifying you. The lab’s obligation is to report the as-found condition accurately. Determining what your instrument did to your product, and deciding what to do about it, is entirely on the manufacturer.
Can RFID tell me which bolts an out of calibration torque wrench touched? No, and any page that implies otherwise is describing a data field that does not exist. RFID tool tracking gives you the tool identity, the person who checked it out, the time window and the location or zone. It does not give you the fastener, the applied torque value or the part serial number. What it does is narrow the population of potentially affected work from everything that happened in the window to a specific list of jobs, cells, shifts and people. Turning that into a list of affected parts requires your work records, and it is only as precise as those records are.
How do I make the next out of tolerance event cheaper? Put the specific tool identity on the work record, not just the tool type. That single field is what converts a custody list into an affected-parts list, and it is usually a configuration change rather than a project. After that, write the window rule into your procedure before you need it, name the owner of the impact assessment in advance, record an as-found condition whenever a tool leaves service for any reason, and set calibration intervals on usage rather than only on the calendar.
All sources below were retrieved and read on September 17, 2026. Regulatory text was read at Cornell LII; eCFR and federalregister.gov were not used, for the reason given in the rejected sources note.