THIS EXPLANATION
THE ROOM
ENV·35 Environment, Agriculture & Food 6 MIN · 8 STATIONS

Pathogen testing limits

A Socratic walk-through of pathogen testing limits — reasoned out one step at a time, not lectured.

abcdefgh
a

The question we started with

THE QUESTION #

Why can no laboratory certify that a shipment of lettuce carries no pathogen at all?

A buyer asks a simple-sounding thing of a laboratory: certify that this pallet of lettuce is free of E. coli O157. The lab runs the accredited method, the enrichment comes up clean, and the certificate says "not detected". The buyer reads that as "none present". Those are not the same sentence, and the gap between them is not a technicality — it is the whole subject.

What is worth questioning first is not the laboratory's competence but the shape of the request. Before asking whether a test is good enough, ask what kind of answer a test of this sort is able to produce. If it turns out that no achievable amount of testing can produce the answer being asked for, then the problem was never in the lab.

b

Reasoning it through

REASONING #

Begin with the physical fact that a microbiological test destroys what it examines. To test lettuce you take some, macerate it, enrich it in broth for a day or so, and look for growth. So you can never test the shipment; you can only test a sample and infer. The certificate is always an inference from a part to a whole — and inference from a part is exactly where the limits live.

Now ask how much of the whole a real test actually sees. The standard unit for Salmonella or Listeria in the ISO methods is a 25 gram analytical portion. Suppose the lab draws ten of them: 250 grams examined out of a pallet weighing, say, half a tonne. Roughly one twenty-thousandth of the consignment has been looked at. What can one twenty-thousandth tell you?

Do the arithmetic honestly. Suppose one percent of the units in the lot are contaminated, and suppose — generously — that the contamination is scattered at random, so each sample has a one percent chance of being a bad one. The chance that a single sample misses is 0.99. The chance that ten samples all miss is 0.99 to the tenth, about 0.90. So a clean result on ten samples is the expected outcome for a lot that really is one percent contaminated. It carries almost no news.

How many would it take? To be ninety-five percent sure of catching a one percent prevalence you need about 300 samples, because 0.99 raised to the 300th power is roughly 0.05. Push the target down to one contaminated unit in a thousand and you need around 3,000 samples — some 75 kilograms of lettuce destroyed to make a claim about one lot, and you would still only have "ninety-five percent sure", never certainty. Does anything about that curve ever reach zero? No. It approaches it, at a cost that rises without limit.

And now the part that makes the arithmetic optimistic rather than pessimistic. That calculation assumed contamination is randomly scattered. It usually is not. Pathogens arrive in events — an irrigation contamination, one animal intrusion, a single harvest crew, a spot on a cooling coil — and they arrive in patches. A clustered contamination is harder to find than a random one at the same overall prevalence, because most of the lot is genuinely clean and the bad part is small and localised. So random-sampling maths gives a best case.

Which leaves the honest reading of a negative certificate. It does not say "there is none". It says: if there had been contamination above roughly such-and-such a level, we would probably have found it. It is an upper bound with a confidence attached, and its strength depends entirely on how many samples were drawn — which is why "tested and passed" without a stated sampling plan tells you very little. This is why sampling plans in the ICMSF tradition are written as an explicit set of numbers — how many samples, how many positives are tolerable, at what level — rather than as a verdict.

c

The analogy

THE ANALOGY #
THE FIGURE

Imagine being asked to certify that a large dark warehouse contains no mice. You are given a torch with a narrow beam and told the beam may be pointed 300 times. Every sweep comes up empty. What have you established? Not that the warehouse is mouse-free — only that if it had been overrun, you would very likely have seen one. And a single mouse in a corner you never lit is entirely consistent with everything you observed.

WHERE IT BREAKS DOWN

you could in principle keep sweeping the warehouse all night, whereas each microbiological sample consumes the food it examines, so the search does not merely get expensive — past a point it destroys the very shipment it was meant to release.

d

Clarifying the model

THE MODEL #

A few refinements follow from this, and one common misconception is worth correcting gently.

The misconception is that better methods would fix it. Faster and more sensitive detection — PCR, whole genome sequencing, lower limits of detection — genuinely improve what happens within a sample. They do nothing about the fraction of the lot the samples represent. The binding constraint is sampling, not analysis, and no advance in the assay moves it.

The second refinement is what "absence of evidence" properly licenses. A negative result is real information: it shifts belief downward, and the more samples behind it the further it shifts. What it cannot do is reach the proposition "zero", because that proposition is not the sort of thing finite sampling can establish. Treating a certificate as proof of absence is not scepticism about testing; it is over-reading it.

Third, and most practically, this is why food safety systems put their weight on process control rather than end-product testing. If you cannot inspect safety into a lot, you have to build it in — controlling water quality, animal intrusion, harvest hygiene, cooling and time-temperature — and use testing to verify that the controls are working, on many lots over time, rather than to clear each lot individually. Testing has more statistical power as a monitor of a process than as a gate on a consignment, because the process is sampled repeatedly and a shipment only once.

e

A picture of it

THE PICTURE #
Pathogen testing limits
Pathogen testing limits Each bar is one sampling plan. Read the height as the probability that the plan finds contamination in a lot where one unit in a hundred is genuinely bad. Ten samples -- a realistic commercial plan -- catch it about one time in ten, so a clean result there is almost uninformative. Follow the bars rightwards and notice two things: the climb is steep at first and then flattens, and the last bar stops at 95, not 100. No number of samples you could add would put a bar on the ceiling. {"generator":"[email protected]","source":"../Socrates/.diagram-cache/_src/pathogen-testing-limits.md","sourceIndex":1,"sourceLine":4,"sourceHash":"8a10481ab3baad645a3ed4dbca668d294ab737f2f69dd938799a2408afe629b4","diagramType":"xychart","layoutVariant":"source","repairedDuplicateIds":[],"motion":"entrance-with-reduced-motion-fallback","presentation":"editorial","attempt":1,"viewBox":{"x":0,"y":0,"width":790,"height":668},"qa":{"passed":true,"findings":[]}} 10 30 60 150 300 Samples drawn from the lot 100 90 80 70 60 50 40 30 20 10 0 Chance of at least one positive

How to readEach bar is one sampling plan. Read the height as the probability that the plan finds contamination in a lot where one unit in a hundred is genuinely bad. Ten samples — a realistic commercial plan — catch it about one time in ten, so a clean result there is almost uninformative. Follow the bars rightwards and notice two things: the climb is steep at first and then flattens, and the last bar stops at 95, not 100. No number of samples you could add would put a bar on the ceiling.

f

What became clearer

WHAT CLEARED #
WHAT CLEARED

A negative pathogen test is a statement about the sampling plan, not about the shipment. It sets an upper bound on how contaminated the lot plausibly is, and that bound is only as tight as the number of samples drawn — so certifying "none at all" is not a hard goal that laboratories have failed to reach, but a claim of a kind that finite, destructive sampling can never make.

g

Where to go next

ONWARD #
  • How ICMSF two-class and three-class attributes plans encode the trade-off in explicit numbers.
  • Why clustered contamination defeats random-sampling assumptions, and what stratified sampling recovers.
  • Whether environmental monitoring of a facility beats product testing as an early signal.
h

Key terms

TERMS #
TermWhat it means
Analytical portionthe mass actually examined in one test, conventionally 25 grams for Salmonella and Listeria under the ISO methods.
Prevalencethe fraction of units in a lot that are contaminated; the quantity a sampling plan is trying to bound.
Limit of detectionthe smallest amount an assay can find within the portion it is given; distinct from, and much easier to improve than, sampling coverage.
Attributes sampling plana specification of how many samples are drawn and how many positives are tolerated, which is what actually determines the strength of a "not detected" result.

Every term the collection defines is gathered in the glossary.

Nearby on the shelf

4