ISO/IEC 17025 Accreditation Is an Evidence Problem Before It Is an Audit Problem

Table of Contents
5
min read
Laboratory analyst retrieves method, equipment, and technical records to support an ISO/IEC 17025 test result.

Laboratories often prepare for an ISO/IEC 17025 assessment by reviewing controlled documents, checking calibration certificates, completing internal audits, and closing outstanding actions. Those activities matter. But they do not answer the most revealing readiness question:

Can the laboratory retrieve and explain the complete evidence behind one completed result?

That question goes beyond whether records exist somewhere in the organization. It tests whether authorized laboratory personnel can show how a result was generated, reviewed, released, and controlled.

ISO/IEC 17025:2017 specifies general requirements for the competence, impartiality, and consistent operation of testing and calibration laboratories. The standard is used in laboratory accreditation, rather than conventional management-system certification, and assessments consider the laboratory’s people, methods, equipment, technical work, and management system within its applicable scope.

A laboratory can have a controlled method library, a training system, calibration records, instrument software, a LIMS, shared folders, and a QMS, and still struggle to answer a basic assessor question quickly. The problem is often not that records are absent. It is that the evidence path between them is unclear.

Test one result, not every system

A laboratory may maintain its technical and quality records across several specialist systems. The LIMS may manage samples and results. Instrument software may retain raw data. A document-control system may manage methods. A training platform may hold competence evidence. A calibration-management tool may retain equipment records. A QMS may manage nonconforming work and corrective actions.

Each of these systems may work as intended. The difficulty appears when a laboratory must establish the complete story behind a reported result.

An assessor might begin with a test report and ask to see the method used. They may then ask who performed the work and whether that person was authorized or competent for the activity. They may request the equipment identity and relevant status at the time of use, the technical record and associated calculations, evidence of review, and any nonconforming-work record or equipment event that could have affected the result.

If answering that request requires multiple spreadsheets, disconnected folders, email searches, and the memory of a long-serving analyst, the laboratory has an evidence-retrieval problem.

The goal is not to force every record into one application. It is to ensure authorized users can find the relevant evidence, understand how the records relate, and identify the authoritative source for each record.

The evidence behind one result

A practical readiness test follows one completed result from method through report and any relevant quality response:

Flow diagram with six steps connected by arrows: Method, Authorized person, Suitable equipment, Technical record, Review and report, Quality response if required.

Each link answers a different question.

Table with two columns, Evidence area and What the laboratory should retrieve and explain. Rows: Method, the approved method, applicable revision, authorized changes, and relevance to the activity performed. Person, the person who performed and reviewed the work, plus relevant authorization, training, competence, or supervision evidence. Equipment, the equipment identity and relevant calibration, verification, maintenance, qualification, or intermediate check status. Sample or item, the identity, receipt, handling, storage, condition, and traceability information for the test or calibration item. Technical record, raw or source data references, observations, calculations, environmental conditions, amendments, and meaningful deviations. Review and report, the review evidence, issued result or certificate, authorization, and release record. Quality response, any relevant nonconforming work, deviation, equipment event, change, or corrective action, including impact assessment.

The specific evidence will vary by method, laboratory activity, risk, and accredited scope. A calibration laboratory, for example, may need to emphasize measurement uncertainty and metrological traceability. A testing laboratory may need to demonstrate sample handling, environmental conditions, method performance, or reporting decisions relevant to the activity.

The principle remains the same: a reported result should be understandable without manually rebuilding its history.

Why the evidence chain matters

ISO/IEC 17025 is concerned with whether laboratory activities are carried out competently, impartially, and consistently. Those requirements become visible through the evidence attached to real work—not only through policies held in a document repository.

A controlled method is necessary, but it does not by itself show that the version used was applicable. An equipment calibration certificate is valuable, but it does not show which result may have been affected by an equipment issue. A training record can demonstrate completed training, but it does not necessarily establish whether an individual was authorized to perform a particular method at the time of work.

The evidence chain connects these records to the technical activity.

This also matters outside an assessment. When a customer questions a result, when equipment is found out of tolerance, when a method changes, or when nonconforming work is identified, the laboratory needs to determine impact. It must be able to identify the relevant methods, equipment, samples, results, reports, and actions without relying on informal knowledge.

A weak evidence path creates audit-day friction. It also slows investigations, impact assessments, corrective actions, and knowledge transfer every day.

Run a result-retrieval test

Select one recently completed result from within the accredited scope. Avoid choosing the cleanest or easiest example. A better test is representative routine work, especially work involving a frequently used method, critical equipment, a customer-facing report, or a recent quality event.

Ask an authorized person who did not perform the work to retrieve and explain the evidence.

They should be able to find the approved method and the version used; the performer’s relevant authorization or competence record; the equipment identity and status when the activity occurred; the sample or item identity and handling history; the technical record, including data references, observations, and calculations; the review and authorization evidence; and any related nonconforming-work, deviation, equipment event, change, or corrective action.

Measure the result of the exercise. Record the time required to retrieve the evidence path, the number of systems or repositories accessed, the manual reconstruction needed, the number of missing identifiers or attachments, unclear ownership, and any uncertainty about the authoritative source.

This is not an accreditation assessment rehearsal, and it is not a substitute for internal audit. It is a focused operational test of whether the laboratory can explain the evidence behind its work.

What weak retrieval reveals

A difficult retrieval exercise usually exposes one of four structural issues.

Identifiers do not travel

A method identifier, sample identifier, equipment number, report reference, or quality-event number may be captured in one system but not carried into the next. The laboratory cannot reliably follow evidence from the technical activity to its review or related quality response.

For example, an equipment event may identify the instrument but not the test reports, samples, or data files potentially affected. An investigator then has to reconstruct the impact through date ranges, personal memory, and manual searches.

Record relationships are informal

The connection may exist only in an analyst’s notebook, an email thread, a local spreadsheet, or the knowledge of a particular team member.

This creates a continuity risk. If another authorized person cannot understand how a result, method, instrument, and quality event relate, the laboratory cannot depend on that relationship during an assessment, investigation, or customer inquiry.

The authoritative source is unclear

Users may find several versions of a procedure, certificate, calculation file, report, or instrument export but be unable to determine which version is controlled, current, approved, or applicable to the result.

Duplicate copies are not always avoidable. Uncontrolled ambiguity is.

The laboratory should define which system is authoritative for each evidence type and how users access the approved version.

Quality events are separated from technical context

A nonconforming-work record, deviation, equipment issue, or corrective action may exist in the QMS but lack references to the affected method, sample, item, instrument, data set, report, or result.

This makes impact assessment slower and less reliable. It also weakens the organization’s ability to explain what was evaluated, which results were affected, what action was taken, and how the decision was reviewed.

Improve the evidence path

Improvement does not require replacing every specialist system. A LIMS, document-management system, instrument-data platform, training system, calibration-management tool, and QMS may each remain authoritative for the records they are designed to manage.

The laboratory needs a controlled way to connect them.

Start by assigning clear ownership for each evidence type. Define which system is authoritative for controlled methods, staff competence, equipment status, samples or items, technical records, reports, and quality events. Then establish stable identifiers for methods, samples, equipment, people, reports, and quality events.

These identifiers should travel through the process. A test record should identify the applicable method and equipment. A report should link back to the test record. A nonconforming-work record should identify the affected method, equipment, sample or item, relevant results, and any report or customer impact where applicable.

The laboratory should also define retrieval routes for authorized users. If records are distributed, users need a documented and practical way to navigate from one authoritative record to another. This should not depend on a private spreadsheet or a person who knows where historical data is stored.

Controls should reduce uncontrolled duplication. The objective is not to prohibit all copies; it is to ensure users can distinguish supporting copies from the controlled, authoritative record.

Start with the result that matters

Choose a result linked to a high-value or recurring activity. This could be a frequently used method, a critical instrument, a customer-facing report, a recently revised method, work affected by a supplier or equipment change, or an activity that has previously generated a quality event.

Then ask:

Can an authorized person explain the evidence behind this result, from method through review and report, including any relevant quality response, without a prolonged manual search?

If the answer is no, the laboratory has found a concrete starting point for improving evidence readiness.

The purpose is not to build a perfect record map before the next assessment. It is to make the evidence behind laboratory work easier to retrieve, understand, review, and defend. That improves assessment readiness, but it also strengthens the laboratory’s ability to investigate problems, assess impact, transfer knowledge, and support confidence in its results.

FAQs

What is ISO/IEC 17025?

ISO/IEC 17025 is the international standard that sets general requirements for the competence, impartiality, and consistent operation of testing and calibration laboratories. It is used by accreditation bodies, laboratory customers, regulators, and other stakeholders to evaluate whether a laboratory can produce reliable testing and calibration results.

Is ISO/IEC 17025 certification or accreditation?

Laboratories are generally accredited to ISO/IEC 17025 rather than certified to it. Accreditation evaluates a laboratory’s competence to perform defined laboratory activities within its accredited scope. The scope may cover particular tests, calibrations, measurements, methods, ranges, or fields of activity. The precise accreditation process and expectations depend on the applicable accreditation body, jurisdiction, and laboratory scope.

What evidence may an assessor request for one completed result?

The exact request varies by laboratory activity and assessment scope. In practice, an assessor may ask for the approved method and applicable version, evidence of personnel authorization or competence, equipment identity and status, sample or item traceability, technical records and calculations, review and report authorization, and any related nonconforming-work or corrective-action evidence. The laboratory should be able to retrieve these records and explain how they relate to the reported result.

Does ISO/IEC 17025 require every laboratory record to be in one system?

No. Laboratories may use separate systems for LIMS workflows, instrument data, document control, training, equipment management, and quality events. The key requirement is not a single application. It is controlled, reliable access to the records required to support laboratory activities. Users should be able to identify the authoritative source for each record and retrieve related evidence without depending on informal knowledge or uncontrolled copies.

How can a laboratory test ISO/IEC 17025 evidence readiness?

Choose a representative completed result within the accredited scope. Ask an authorized person who did not perform the work to retrieve the associated method, personnel authorization, equipment status, sample or item traceability, technical record, review evidence, issued report, and any relevant quality event. Measure the time required, systems accessed, manual reconstruction needed, missing relationships, and ambiguity about record ownership or authoritative sources. The findings can identify practical improvement priorities before an assessment or internal audit.