Knowledge base

ISO/IEC 17025:2017 – Documentation and Compliance Requirements

This guide explains, clause by clause, what a laboratory needs to document and what an auditor or assessor may ask to see as evidence.

Prem Kumar Dvivedi · 12. September 2026

It covers the key requirements of ISO/IEC 17025:2017 across five main areas. It is written as a set of requirements rather than a simple checklist.

A checklist only asks, “Do you have this?” This guide goes further by explaining what is required and what evidence can demonstrate compliance. This is especially useful when establishing or improving a laboratory management system.

________________________________________

4. Impartiality and Confidentiality

Clauses 4.1.1 to 4.1.5 and 4.2.1 to 4.2.3

Impartiality

The laboratory must perform its activities fairly and independently, without allowing personal, commercial, financial or other pressures to influence the results.

Evidence may include:

• A formal commitment to impartiality from top management.

• An organisational structure that protects impartiality.

• Identification of commercial, financial and other pressures that could affect results.

• Evidence that employees are not rewarded or pressured based on the results they report.

• A regular assessment of risks to impartiality.

• Records showing the risks identified and the actions taken to control them.

The laboratory must continuously review risks to impartiality, including risks related to:

• Ownership and management

• Financial interests

• Contracts

• Marketing activities

• Shared resources

• Client relationships

• Governance arrangements

Confidentiality

The laboratory must protect information received from clients.

Evidence may include:

• Confidentiality agreements signed by employees, contractors and other persons working for the laboratory.

• Arrangements for protecting client information.

• Records showing how legally required information disclosures were handled.

If information must be disclosed because of a legal requirement, the client should normally be informed unless the law prevents this.

Information received about a client from another source must also be treated as confidential.

________________________________________

5. Structure and Organisation of the Laboratory

Clauses 5.1 to 5.7

The laboratory must be a legal entity or a clearly defined part of a legal entity.

Evidence may include:

• Legal registration documents.

• Written authorisation from the parent organisation, where applicable.

The laboratory must have management with overall responsibility for its activities.

The laboratory must clearly define the activities for which it claims compliance with ISO/IEC 17025.

The documented scope should identify work performed:

• At permanent laboratory locations

• At temporary or mobile facilities

• At customer sites

• At other locations covered by the laboratory's activities

The laboratory must carry out its work in accordance with:

• ISO/IEC 17025 requirements

• Client requirements

• Regulatory requirements

• Requirements of organisations providing recognition or accreditation

The laboratory must have a documented organisational structure showing:

• Management

• Technical activities

• Supporting functions

• Responsibilities and authorities

• Relationships between different roles

Personnel must have sufficient authority and resources to operate, maintain and improve the management system and identify problems or deviations.

Management must also ensure that changes to the system do not negatively affect its effectiveness.

________________________________________

6. Resources – People, Facilities, Equipment and External Providers

Clauses 6.2 to 6.6

Personnel

Laboratory personnel must:

• Work impartially.

• Be competent for their assigned activities.

• Follow the laboratory's management system.

The laboratory must define the competence required for each role, including:

• Qualifications

• Education

• Training

• Knowledge

• Skills

• Experience

Evidence may include:

• Competence requirements for each position.

• Training records.

• Qualification records.

• Experience records.

• Competence evaluation records.

Each person must have clearly defined:

• Duties

• Responsibilities

• Authorities

The laboratory must have a process for:

• Selecting personnel

• Training personnel

• Supervising personnel

• Authorising personnel

• Monitoring competence

Personnel must be specifically authorised for the activities they perform.

Competence must be monitored continuously, not only when a person is first authorised.

Examples of evidence include:

• Witnessed testing

• Blind samples

• Repeat testing

• Supervised activities

• Review of results

Competence records must be maintained for permanent, temporary and contract personnel.

________________________________________

Facilities and Environmental Conditions

The laboratory must ensure that its facilities and environmental conditions are suitable for the work being performed.

The laboratory must identify and control conditions that could affect results, such as:

• Temperature

• Humidity

• Pressure

• Vibration

• Lighting

• Dust

• Microbial contamination

• Electromagnetic interference

Evidence may include:

• Facility descriptions.

• Environmental requirements.

• Monitoring records.

• Environmental condition logs.

If environmental conditions go outside acceptable limits, the laboratory must take appropriate action and assess whether previous results were affected.

Access to areas that could affect laboratory activities must be controlled.

The laboratory must also prevent:

• Contamination

• Interference

• Cross-contamination

• Conflicts between incompatible activities

The same controls must apply when work is performed at temporary, mobile or client locations.

________________________________________

Equipment

The laboratory must have suitable equipment and access to all equipment required for its activities.

Evidence may include:

• Equipment inventory.

• Equipment identification records.

• Equipment maintenance records.

• Verification records.

• Calibration records.

Equipment must be properly:

• Handled

• Transported

• Stored

• Used

• Maintained

Before equipment is put into service or returned to service, the laboratory must confirm that it meets the required specifications.

Equipment must be capable of achieving the accuracy or measurement uncertainty required by the relevant method.

Where necessary, equipment must be calibrated.

A calibration programme should define:

• What needs to be calibrated

• Calibration intervals

• Calibration requirements

• The basis for the calibration frequency

Calibration records should provide appropriate information about:

• Calibration results

• Measurement uncertainty

• Traceability

The calibration programme should be reviewed and updated when necessary.

The calibration status of equipment must be clear to users, for example through:

• Labels

• Identification codes

• Electronic records

Faulty or damaged equipment must be removed from service and clearly identified.

The laboratory must assess whether equipment problems affected previous results and issue amended reports where necessary.

Where required, intermediate checks must be performed between calibrations.

Correction factors must be properly controlled and updated.

Controls must also prevent unauthorised changes to equipment settings.

Equipment records should normally include:

• Equipment identification

• Manufacturer

• Model and serial number

• Location

• Verification records

• Calibration information

• Calibration due dates

• Maintenance history

• Damage or malfunction information

________________________________________

Metrological Traceability

Measurement results must be traceable to appropriate references.

Normally, traceability should be established through an unbroken chain of calibrations, with each step contributing to measurement uncertainty.

Evidence may include:

• Calibration certificates from competent laboratories.

• Evidence of accreditation or competence of calibration providers.

• Certified reference materials from competent providers.

• A documented traceability plan.

Where direct traceability to the SI system is not technically possible, the laboratory must use a suitable alternative and document the justification.

________________________________________

External Products and Services

Products and services purchased from external providers must be suitable for laboratory activities.

This can include:

• Calibration services

• Subcontracted testing

• Reference materials

• Consumables

• Proficiency testing

• Equipment maintenance

The laboratory must:

• Define its requirements.

• Evaluate suppliers.

• Monitor supplier performance.

• Re-evaluate suppliers when necessary.

• Keep records of evaluations and actions.

Purchase orders and specifications should clearly communicate the requirements to suppliers.

________________________________________

7. Laboratory Activities

Clauses 7.1 to 7.11

Review of Requests, Tenders and Contracts

The laboratory must have a process for reviewing requests, tenders and contracts before accepting work.

The review should confirm that:

• Requirements are clearly understood.

• The laboratory has the necessary resources.

• The laboratory has the competence to perform the work.

• The selected method can meet the requirements.

If a client requires a statement of conformity, the decision rule must be agreed with the client unless it is already defined in the relevant standard or specification.

Differences between the client's request and the contract must be resolved before work begins.

If the agreed requirements change, the laboratory must review the changes and communicate them to the relevant personnel.

Records of reviews and important discussions with clients must be maintained.

________________________________________

Methods and Procedures

The laboratory must use suitable and current methods for its activities.

Methods and supporting documents must:

• Be approved.

• Be kept up to date.

• Be available to staff where the work is performed.

• Have proper version control.

The latest valid version of a method should normally be used unless there is a justified reason not to use it.

When the client does not specify a method, the laboratory must select an appropriate method and inform the client.

Before introducing a method, the laboratory must verify that it can properly perform the method.

Evidence may include:

• Method verification records.

• Performance results.

• Method approval records.

________________________________________

Method Development and Validation

Where the laboratory develops its own methods, the activity must be planned and assigned to competent personnel.

Deviations from a method must be:

• Documented.

• Technically justified.

• Authorised.

• Accepted by the client where applicable.

Non-standard, laboratory-developed, modified or out-of-scope methods must be validated.

Validation records should show:

• The validation procedure.

• Requirements.

• Performance characteristics.

• Results obtained.

• Conclusions regarding suitability for the intended use.

If a validated method is changed, the laboratory must assess the impact and perform revalidation where necessary.

________________________________________

Sampling

Where sampling is part of the laboratory's activities, the laboratory must have an appropriate sampling plan and method.

The sampling method should define the factors that need to be controlled to ensure valid results.

Sampling records should include relevant information such as:

• Date and time

• Sample identification

• Location

• Person who performed sampling

• Equipment used

• Environmental or transport conditions

• Sampling method

• Deviations from the method

If the laboratory does not perform sampling, this requirement may be marked as not applicable with an appropriate justification.

________________________________________

Handling of Laboratory Items

The laboratory must have procedures for:

• Receiving

• Transporting

• Handling

• Protecting

• Storing

• Retaining

• Disposing of items

Every item must have a unique identification throughout the laboratory process.

If an item arrives in an unsuitable or damaged condition, the laboratory must consult the client before proceeding where necessary and record the decision.

Required storage or environmental conditions must be monitored and recorded.

Items must be protected from damage, contamination, loss or deterioration.

________________________________________

Technical Records

Technical records must contain enough information to allow the activity to be understood and, where reasonably possible, repeated.

Records should identify:

• The work performed

• Results

• Relevant conditions

• Measurement uncertainty

• Person performing the work

• Person reviewing the work

• Dates

Original observations should be recorded when they are made.

If a record is changed, the original information must remain identifiable, together with:

• What was changed

• Who changed it

• When it was changed

Electronic records should have suitable controls and audit trails.

________________________________________

Measurement Uncertainty

The laboratory must identify and evaluate relevant contributions to measurement uncertainty.

Calibration laboratories must evaluate measurement uncertainty for their calibrations.

Testing laboratories must estimate measurement uncertainty using an appropriate recognised approach.

Where appropriate, uncertainty budgets and supporting calculations should be maintained.

________________________________________

Monitoring the Validity of Results

The laboratory must have a process for monitoring whether its results remain valid and reliable.

Methods may include:

• Reference materials

• Control charts

• Replicate testing

• Retesting

• Intermediate checks

• Blind samples

• Other appropriate quality control activities

The laboratory should participate in proficiency testing or interlaboratory comparisons where applicable.

Results must be reviewed and analysed.

If performance falls outside defined criteria, the laboratory must investigate and take appropriate corrective action before incorrect results are reported.

________________________________________

Reporting Results

Results must be reviewed and authorised before they are released.

Reports must contain the information required by ISO/IEC 17025, such as:

• Laboratory identification

• Report identification

• Client information

• Method used

• Description and identification of the item

• Dates

• Results

• Units

• Relevant deviations

• Name or identification of the person authorising the report

Test reports may also need to include:

• Sampling information

• Relevant environmental conditions

• Measurement uncertainty

• Opinions or interpretations, where applicable

Calibration certificates should include:

• Measurement results

• Measurement uncertainty

• Traceability information

Where sampling results are reported, relevant sampling information should also be included.

________________________________________

Statements of Conformity

When the laboratory states whether a result meets a specification or requirement, it must use a documented decision rule.

The report should identify:

• The decision rule used.

• The relevant specification or requirement.

• The basis for the conformity statement.

________________________________________

Opinions and Interpretations

Opinions and interpretations must only be provided by authorised personnel.

The basis for the opinion or interpretation must be documented.

________________________________________

Amended Reports

If a report is changed after issue, the amended report must be clearly identified and linked to the original report.

________________________________________

Complaints

The laboratory must have a documented complaints process that is available to interested parties.

The process should cover:

• Receiving complaints

• Validating complaints

• Investigating complaints

• Making decisions

• Communicating outcomes

• Maintaining records

The complainant should be kept informed about the progress and outcome.

The person deciding the complaint should be independent from the activity being complained about wherever possible.

________________________________________

Nonconforming Work

The laboratory must have a procedure for handling work that does not meet requirements.

The procedure should define:

• Who can stop the work.

• Who evaluates the issue.

• Who decides what action is required.

• Who can authorise work to restart.

The laboratory must evaluate the effect of nonconforming work, including its possible effect on previous results.

Where necessary, the laboratory may need to:

• Stop work.

• Repeat testing.

• Withhold reports.

• Notify clients.

• Recall previously issued reports.

Records of the issue and actions taken must be maintained.

Corrective action should be taken when the problem could happen again.

________________________________________

Laboratory Information Management Systems

Laboratory information systems must be validated before use and after significant changes.

The laboratory must protect its information systems against:

• Unauthorised access

• Unauthorised changes

• Data loss

• Incorrect processing

Controls should include:

• Access controls

• Backup arrangements

• Restore testing

• Data integrity controls

Calculations and data transfers must be systematically checked.

System failures must be recorded and addressed promptly.

If the system is operated by an external provider, the laboratory must ensure that ISO/IEC 17025 requirements continue to be met.

________________________________________

8. Management System

Clauses 8.1 to 8.9

The laboratory must establish and maintain a management system.

It must choose either:

• Option A, or

• Option B

The selected option should be documented.

Under Option B, the laboratory uses an ISO 9001-based management system that supports the consistent fulfilment of ISO/IEC 17025 requirements related to Sections 4 to 7.

________________________________________

Policies and Objectives

The laboratory must have documented management system policies and objectives.

These should demonstrate management's commitment to:

• Competence

• Impartiality

• Consistent laboratory operations

Employees should understand and apply these policies and objectives.

The management system documentation must cover the applicable requirements of Section 8.

________________________________________

Document Control

Management system documents must be:

• Approved before use.

• Available where needed.

• Reviewed regularly.

• Updated when necessary.

• Re-approved after changes.

• Properly version controlled.

Obsolete documents must be removed from use or clearly identified if they are retained.

________________________________________

Control of Records

The laboratory must maintain records that demonstrate compliance with the standard.

Records must be:

• Identified

• Stored

• Protected

• Backed up where necessary

• Retrieved when needed

• Retained for the required period

• Disposed of appropriately

Retention periods should consider regulatory, accreditation and contractual requirements.

________________________________________

Risks and Opportunities

The laboratory must identify risks and opportunities related to its activities.

The assessment should consider:

• Whether the management system achieves its intended results.

• Opportunities for improvement.

• Prevention or reduction of unwanted effects.

• Improvement of laboratory operations.

Actions should be planned and integrated into the management system.

The laboratory must review whether those actions were effective.

________________________________________

Improvement and Customer Feedback

The laboratory should identify opportunities for improvement using information such as:

• Client feedback

• Operational data

• Internal audits

• Management reviews

• Complaints

• Performance results

Both positive and negative client feedback should be considered.

________________________________________

Corrective Action

When a nonconformity occurs, the laboratory must:

1. Respond to the problem.

2. Control and correct it.

3. Address its consequences.

4. Determine whether the cause needs to be removed.

5. Take corrective action where necessary.

6. Review whether the action was effective.

7. Update risks or the management system when required.

Records should be maintained for:

• The nonconformity.

• Its cause.

• Actions taken.

• Results of the actions.

________________________________________

Internal Audit

The laboratory must have an internal audit programme covering the applicable ISO/IEC 17025 requirements.

The audit programme should consider:

• Frequency

• Methods

• Responsibilities

• Planning

• Reporting

• Importance of laboratory activities

• Previous audit results

• Changes in the organisation

Each audit should have a defined:

• Scope

• Criteria

• Objectives

Auditors should be competent and objective and should not audit their own work.

Audit results must be reported to the appropriate management, and required corrective actions should be addressed without unnecessary delay.

________________________________________

Management Review

Management must review the management system at planned intervals.

The review should consider relevant information, including:

• Changes in internal and external issues.

• Achievement of objectives.

• Suitability of policies and procedures.

• Previous management review actions.

• Internal audit results.

• Corrective actions.

• External assessments.

• Changes in the volume and type of work.

• Client feedback.

• Personnel feedback.

• Complaints.

• Improvement activities.

• Resource requirements.

• Risks and opportunities.

• Results related to the validity of laboratory activities.

The management review must produce documented decisions and actions.

These may relate to:

• Effectiveness of the management system.

• Improvement.

• Resource requirements.

• Changes required in the laboratory.

Actions should have clear responsibilities and target dates.

________________________________________

How to Use This Guide

ISO/IEC 17025:2017 does not simply require a large manual, a collection of templates or a complicated filing system.

The real requirement is that the laboratory has appropriate processes, decisions and controls in place — and can demonstrate that they are being followed.

More documentation does not automatically mean better compliance.

A long procedure that employees do not follow can create more problems than a simple procedure that accurately reflects actual laboratory practices.

The key question is:

Can the laboratory demonstrate that its people understand the requirements, follow the defined processes and maintain reliable, technically valid results?

In practical terms, compliance is not about having more documents. It is about having the right controls, competent people, reliable processes and objective evidence to demonstrate that the laboratory consistently performs its work as required by ISO/IEC 17025:2017.

What this covers

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 17025, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles