Knowledge base
ISO/IEC 17025:2017: documentation and compliance requirements
Everything ISO/IEC 17025:2017 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checkli
Prem Kumar Dvivedi · 2026 оны есдүгээр сарын 12
This is what ISO/IEC 17025:2017 requires you to have, clause by clause, and what an auditor will ask to see for each of it. It covers 138 requirements across 5 areas.
It is deliberately not a checklist. A checklist asks whether you have something; this says what is required and what counts as evidence, which is the question that matters when you are building a system rather than testing one. If you would rather find out where you stand first, the same ground is covered by our free ISO/IEC 17025:2017 readiness assessment, which scores you out of 100.
4 Being fair and keeping things confidential
Clauses 4.1.1, 4.1.2, 4.1.3, 4.1.4, 4.1.5, 4.2.1, 4.2.2, 4.2.3.
The must be laboratory run so that its work is impartial, and is that a stated commitment.
Evidence: A commitment to impartiality from top management.
The must be laboratory structured and managed so that impartiality is protected.
Evidence: The organisational arrangements. Where the lab sits inside a bigger organisation with a commercial interest in results, this is the first thing an assessor looks at.
You must make sure commercial, financial or other pressures do not affect impartiality.
Evidence: Evidence that pressure to change a result has been recognised and resisted. Remuneration not linked to the result reported.
You must look for risks to impartiality on an ongoing basis, from every source.
Evidence: A risk to impartiality assessment covering ownership, governance, management, shared resources, finance, contracts, marketing and relationships with clients. Reviewed, not done once.
When you find such a risk, you must remove it or reduce it.
Evidence: Records of risks found and what was done about each.
You must have legally enforceable commitments to keep client information confidential.
Evidence: Signed confidentiality undertakings covering staff, contractors, external bodies and individuals acting for the lab.
If you have to release information by law, you must tell the client first, unless prohibited.
Evidence: The arrangement, and records of any release.
Information you get about a client from someone other than the client must be treated as confidential.
Evidence: The arrangement covering third-party sources.
5 How the laboratory is set up
Clauses 5.1, 5.2, 5.3, 5.4, 5.5, 5.6, 5.7.
The must be laboratory a legal entity, or a defined part of one.
Evidence: The legal entity documents, or the parent organisation's written authorisation.
There must be management with overall responsibility for the laboratory.
Evidence: Named management with defined responsibility.
You must have written down the range of laboratory work you claim meets this standard.
Evidence: A documented scope of activities, including work done at permanent premises, away from them, at temporary or mobile sites, and at client sites. Work provided by others on an ongoing basis is excluded from what you can claim.
The must be work carried out so that it meets this standard, your clients, the authorities and any organisation giving recognition.
Evidence: Evidence the work meets all four.
The must be structure documented, showing where the lab sits and how it relates to other functions.
Evidence: An organisation chart covering management, technical operations and support services.
It must be written down who is responsible for, who has authority for, and how people relate to each other in work that affects results.
Evidence: Documented procedures covering responsibility, authority and interrelationships.
You must have enough people, with the authority and resources, to run the system and spot problems.
Evidence: Named roles for implementing, maintaining and improving the system, and for identifying deviations.
You must be able to answer: Does management make sure the system stays whole when changes are made, and that people understand why the work matters?
Evidence: Communication about effectiveness and about meeting client requirements. Change records showing system integrity was preserved.
6 Resources — people, premises, equipment and suppliers
Clauses 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11, 6.4.12, 6.4.13, 6.5.1, 6.5.2, 6.5.3, 6.6.1, 6.6.2, 6.6.3.
You must be able to answer: Do all personnel act impartially, work competently and follow the system?
Evidence: Their commitments and how you check.
You must have written down the competence needed for each function, covering qualification, training, knowledge, skills and experience.
Evidence: Documented competence requirements per function.
Your people must be competent to do the work assigned to them, and to judge how far results deviate.
Evidence: Competence records per person.
You must have written down the duties, responsibilities and authorities of each role.
Evidence: Role definitions covering method development, result review, opinions and interpretations, and reporting.
You must have a procedure for selecting, training, supervising, authorising and monitoring people.
Evidence: The procedure, plus records for each stage.
Each must be person specifically authorised for the activities they perform.
Evidence: Authorisation records naming the person and the exact activities they may carry out.
You must monitor competence after authorisation, not just at the start.
Evidence: Witnessed testing, blind samples, supervised repeats or result review, with records and dates.
You must keep competence records for everyone, including temporary and contract staff.
Evidence: Records covering all personnel on the same basis.
You must be able to answer: Are the premises and conditions suitable, and do they not adversely affect results?
Evidence: Facility description. Evidence conditions are suitable for the work.
You must have written down what conditions are needed, and you must monitor and control them.
Evidence: Documented requirements. Monitoring and recording of temperature, humidity, pressure, vibration, light, interference, dust or microbial contamination, as the method requires.
You must stop work when the conditions go outside the limits, and act on it.
Evidence: Records of out-of-limit conditions, the action taken, and any effect on results already produced.
Access must be to areas affecting results controlled.
Evidence: Access control arrangements.
You must prevent contamination, interference and incompatible activities affecting each other.
Evidence: Separation of incompatible work. Contamination controls.
Where you work away from your own premises, the same must requirements apply.
Evidence: Controls applied to mobile, temporary and client-site work.
You must have the equipment needed, and access to it.
Evidence: An equipment inventory.
Where you use equipment outside your permanent control, you must make sure it still meets the requirements.
Evidence: Arrangements for borrowed, leased or client equipment.
You must have a procedure for handling, transporting, storing, using and maintaining equipment.
Evidence: The procedure and the maintenance records.
You must check equipment meets the requirements before you put it into service, or return it to service.
Evidence: Verification records before use.
The must be equipment capable of the accuracy or uncertainty the method needs.
Evidence: Capability evidence per method.
Equipment must be calibrated where accuracy or measurement uncertainty affects the reported result.
Evidence: A calibration programme with intervals and the basis for them. Calibration certificates with the result, the uncertainty and the traceability.
You must have a calibration programme that is reviewed and adjusted.
Evidence: The programme and evidence of review.
The must be calibration status of equipment clear to the people using it.
Evidence: Labels, coding or records showing status and next due date.
Equipment must be that is faulty, overloaded, mishandled or giving wrong results taken out of service.
Evidence: Records of equipment removed. Clear labelling.
When that happens, you must examine the effect on previous results and issue corrected reports if needed.
Evidence: The examination recorded, and any amended reports issued.
Where intermediate checks are needed to keep confidence between calibrations, you must do them.
Evidence: An intermediate check procedure and the records.
Where calibration produces correction factors, they must be updated and applied correctly.
Evidence: Evidence the current factors are in use, including in software.
Safeguards must be in place to stop equipment settings being changed and invalidating results.
Evidence: Access controls, seals or password protection on instrument settings.
You must keep the records the standard requires for each piece of equipment.
Evidence: Identity, manufacturer and serial number, verification evidence, current location, calibration data and due dates, reference material records, maintenance history, and damage or malfunction records.
Metrological traceability must be established for your measurement results.
Evidence: A traceability plan or statement per measurement.
Traceability must be achieved through an unbroken chain of calibrations, each contributing to the uncertainty.
Evidence: Calibration certificates from a competent laboratory, with evidence of that competence such as accreditation for the specific calibration. Certified reference materials from a competent producer.
Where traceability to the SI is not technically possible, you must use an appropriate alternative and document it.
Evidence: The reference used — a certified reference material, an agreed method or a consensus standard — with the justification.
You must make sure that products and services you buy in, that affect the work, are suitable.
Evidence: A procedure covering externally provided products and services.
You must define what you need, evaluate providers, monitor them and re-evaluate them.
Evidence: Criteria, evaluation records, monitoring and re-evaluation for calibration services, subcontracted testing, reference materials, consumables, proficiency testing providers and maintenance.
You must keep records of the actions arising from those evaluations.
Evidence: Action records.
You must tell providers exactly what you require.
Evidence: Purchase orders and specifications stating the requirements, including any competence or system requirements.
7 Doing the work
Clauses 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.2.1.1, 7.2.1.2, 7.2.1.3, 7.2.1.4, 7.2.1.5, 7.2.1.6, 7.2.1.7, 7.2.2.1, 7.2.2.2, 7.2.2.3, 7.2.2.4, 7.3.1, 7.3.2, 7.3.3, 7.4.1, 7.4.2, 7.4.3, 7.4.4, 7.5.1, 7.5.2, 7.6.1, 7.6.2, 7.6.3, 7.7.1, 7.7.2, 7.7.3, 7.8.1, 7.8.2, 7.8.3, 7.8.4, 7.8.5, 7.8.6, 7.8.7, 7.8.8, 7.9.1, 7.9.2, 7.9.3, 7.9.6, 7.10.1, 7.10.2, 7.10.3, 7.11.1, 7.11.2, 7.11.3.
You must have a procedure for reviewing requests, tenders and contracts.
Evidence: The procedure and the review records.
You must confirm the requirements are properly defined, that you have the capability and resources, and that the method chosen can meet them.
Evidence: The review recording all three.
Where a client asks for a statement of conformity, the must be decision rule agreed with them.
Evidence: The decision rule recorded and agreed, unless it is already in the method or the specification.
Differences between the request and the contract must be resolved before the work starts.
Evidence: Records of differences resolved. Both parties in agreement.
If you deviate from the contract, you must tell the client.
Evidence: Notification records.
If the contract changes, you must repeat the review and tell everyone affected.
Evidence: Amendment records and internal communication.
You must cooperate with clients, including letting them witness work, while protecting other clients' confidentiality.
Evidence: Arrangements for client witnessing.
You must keep records of the reviews, including significant changes.
Evidence: Review records retained.
You must keep records of discussions with clients about their requirements or the results.
Evidence: Records of relevant discussions.
You must use appropriate methods for all your work, and keep them up to date.
Evidence: A list of methods with their current version. Evidence the latest valid version is in use.
Your methods, procedures and supporting documents must be kept current and available to staff.
Evidence: Availability at the point of work.
You must make sure you use the latest valid version of a method, unless it is not appropriate.
Evidence: Version control on methods.
When a client does not specify a method, you must select an appropriate one and tell them.
Evidence: Selection records and client notification.
You must verify that you can properly perform a method before you introduce it.
Evidence: Verification records showing you achieved the required performance.
When a method is developed, it must be a planned activity assigned to competent people.
Evidence: Development plan and records. N/A with a reason if you develop no methods.
Deviations from a method must be documented, technically justified, authorised and accepted by the client.
Evidence: Deviation records with all four.
You must validate non-standard, laboratory-developed, modified and out-of-scope methods.
Evidence: Validation records stating the procedure used, the requirements specified, the performance characteristics determined, the results, and a statement of validity for the intended use.
When you change a validated method, you must assess the effect and revalidate if needed.
Evidence: Revalidation records after change.
You must check the performance characteristics of a validated method are relevant to the client's needs.
Evidence: The check recorded.
You must keep the validation records the standard requires.
Evidence: The procedure, the specified requirements, the performance characteristics, the results and the statement of validity.
Where you sample, you must have a sampling plan and method.
Evidence: The plan and method, available where the sampling is done. N/A with a reason if you do not sample.
The sampling must method describe the factors to be controlled so the results are valid.
Evidence: The factors identified in the method.
You must keep the sampling records the standard requires.
Evidence: Reference to the method, date and time, data identifying the sample, the sampler's identity, equipment used, environmental or transport conditions, a diagram or equivalent showing the location, and any deviations.
You must have a procedure for transporting, receiving, handling, protecting, storing, retaining and disposing of items.
Evidence: The procedure covering all of those.
Each must be item uniquely identified, and is that identity kept throughout.
Evidence: The identification system. Sub-division and sub-sampling identified too.
When an item arrives in the wrong condition, you must consult the client before going ahead, and record it.
Evidence: Records of deviations from the specified condition, and the client consultation.
Where items must be stored or conditioned in set conditions, those must be conditions monitored and recorded.
Evidence: Monitoring records for storage conditions.
You must have arrangements to keep items secure and intact.
Evidence: Security and integrity arrangements.
Your technical must records contain enough to repeat the activity under conditions as close as possible to the original.
Evidence: Technical records with the results, the report, and the information affecting the result and its uncertainty.
The records must identify who did the work, who checked it, and when.
Evidence: Names and dates on the records.
Original observations must be recorded at the time they are made.
Evidence: Contemporaneous records, identifiable to the specific task.
When a record is amended, you must be able to still see the original, and who changed it and when.
Evidence: Amendment trail keeping the original and the amended value, the person and the date. Equivalent controls for electronic records, including audit trails.
You must identify the contributions to measurement uncertainty for each measurement.
Evidence: Uncertainty budgets identifying the contributions, including sampling where you sample.
You must be able to answer: Do calibration laboratories evaluate the uncertainty for all calibrations?
Evidence: Uncertainty evaluated for every calibration. N/A with a reason if you do not calibrate.
You must be able to answer: Do testing laboratories evaluate uncertainty, using a recognised approach where rigorous evaluation is not possible?
Evidence: Uncertainty estimates per method, or evidence that a published method specifies the limits and the form of reporting and that you follow it.
You must have a procedure for monitoring the validity of your results, and you must record the data so trends show.
Evidence: The procedure and the data plotted or reviewed statistically.
You must use appropriate monitoring — reference materials, control charts, replicate testing, retesting, intermediate checks or blind samples.
Evidence: The monitoring activities actually in use, with records.
You must take part in proficiency testing or interlaboratory comparisons across your scope.
Evidence: A participation plan and review. Results with performance assessed. Investigation and action where performance was not satisfactory.
You must analyse the monitoring data, and act when it falls outside your criteria — to stop wrong results being reported.
Evidence: Analysis records. Action taken when criteria were not met.
You must review and authorise results before you release them.
Evidence: Review and authorisation records.
Your reports must contain everything the standard requires.
Evidence: Reports checked against the required content: the laboratory identity, a unique report identification on every page, the client, the method, the item description and identification, the dates of receipt and of the work, results with units, any additions or deviations, the person authorising the report, and clear identification of results from external providers.
For test reports, you must include the extra information the standard requires where it is relevant.
Evidence: Sampling information, specific conditions, uncertainty where relevant to validity or application or where the client asks or it affects conformity, and opinions where given.
For calibration certificates, you must include the uncertainty and the traceability.
Evidence: Uncertainty in the same unit as the measurand. Traceability evidence. Calibration interval only where agreed with the client. N/A with a reason if you issue no calibration certificates.
Where you report sampling results, you must include the sampling details.
Evidence: Sampling date, item, location, method, conditions and uncertainty where relevant.
When you state conformity to a specification, you must record and apply the decision rule, and say so on the report.
Evidence: The decision rule documented and applied. The report identifying the rule and the specification the statement relates to.
Opinions and interpretations must be given only by authorised people, with the basis documented.
Evidence: Authorisation records. The basis for the opinion recorded.
When you amend a report, it must be uniquely identified and does it refer to the original.
Evidence: Amended reports identified as such.
You must have a complaints process, and it must be available to anyone who asks.
Evidence: The documented process, published or available on request.
The process must cover receiving, validating, investigating and deciding, and you must keep records.
Evidence: The procedure and the complaint records.
You must acknowledge complaints, keep the complainant informed, and tell them the outcome.
Evidence: Acknowledgement, progress and outcome records.
The must be outcome decided or reviewed by someone not involved in the work complained about.
Evidence: Evidence of independence in the decision.
When work does not conform, you must have a procedure, and it must be clear who decides what happens.
Evidence: The procedure with responsibilities and authorities defined.
You must evaluate how significant the nonconforming work is, including its effect on previous results.
Evidence: The evaluation recorded.
You must halt or repeat work and withhold reports where necessary, and notify the client and recall reports.
Evidence: Records of work halted, reports withheld or recalled, and clients notified.
It must be clear who authorises work to start again.
Evidence: The authority recorded.
You must keep records of the nonconforming work and the action taken.
Evidence: The records retained.
Where the evaluation shows it could happen again, you must take corrective action.
Evidence: Corrective action raised from nonconforming work.
You must have access to the data and information you need to do the work.
Evidence: Access arrangements.
Any laboratory information management system must be validated before use, and after any change.
Evidence: Validation records, including interfaces. Applies to commercial software after configuration too.
The must be system protected from unauthorised access, safeguarded against tampering and loss, and operated as specified.
Evidence: Access controls, backup arrangements and evidence of restore testing.
Calculations and data transfers must be checked in a systematic way.
Evidence: Checking arrangements, including controls over spreadsheets used for calculations.
System failures must be recorded and acted on immediately.
Evidence: Failure records and the action taken.
Where the system is run off site or by a provider, you must make sure the requirements are still met.
Evidence: The arrangement with the provider and how you assure it.
8 The management system
Clauses 8.1.1, 8.2.1, 8.2.4, 8.2.5, 8.3.1, 8.3.2, 8.4.1, 8.4.2, 8.5.1, 8.5.2, 8.5.3, 8.6.1, 8.6.2, 8.7.1, 8.7.2, 8.8.1, 8.8.2, 8.9.1, 8.9.2, 8.9.3.
You must have chosen Option A or Option B for your management system, and is that written down.
Evidence: A statement of which option you follow. Under Option B you need an ISO 9001 system that supports and demonstrates consistent fulfilment of sections 4 to 7.
You must have documented policies and objectives for the management system.
Evidence: Policies and objectives, with top management's commitment to competence, impartiality and consistent operation.
Those must be policies and objectives addressed and acknowledged at all levels.
Evidence: Evidence they are known and applied, not just written.
The documentation must cover everything section 8 requires.
Evidence: The documentation set mapped against the requirements.
Management system documents must be approved before issue, and available where they are needed.
Evidence: Approval records. Availability at points of use.
Documents must be reviewed, updated and re-approved, with changes and current status identified.
Evidence: Review evidence. A master list showing version and status.
Obsolete documents must be prevented from being used by mistake, and marked if kept.
Evidence: Removal or marking of superseded documents.
You must keep the records needed to show the requirements are met.
Evidence: Records retained and legible.
You must have controls for identifying, storing, protecting, backing up, archiving, retrieving, retaining and disposing of records.
Evidence: A records procedure covering all of those. Retention periods, which for technical records are often set by your accreditation body or by regulation and are longer than in other systems.
You must have considered the risks and opportunities associated with the laboratory activities.
Evidence: A record of the risks and opportunities considered, covering assurance that the system achieves its results, enhancement of opportunities, prevention or reduction of undesired impacts, and improvement.
You must have planned actions to address them, and integrated them into the system.
Evidence: Actions planned and built in.
You must evaluate whether those actions were effective, and they must be proportionate to the impact on results.
Evidence: Effectiveness evaluation records.
You must identify and select opportunities for improvement.
Evidence: Improvement opportunities from client feedback, operational data, audits and review.
You must seek feedback from clients — positive and negative — and use it.
Evidence: Feedback sought, analysed and used, with records.
When something does not conform, you must react to it and deal with the consequences.
Evidence: Nonconformity records with the immediate action.
You must evaluate whether action is needed to remove the cause so it does not happen again or elsewhere.
Evidence: The evaluation and the cause analysis.
You must review whether the corrective action was effective, and update risks and the system if needed.
Evidence: Effectiveness review. Updates to the risk register or the system.
You must keep records of the nonconformity, its causes, the action taken and the results.
Evidence: The records covering all four.
You must have an internal audit programme covering all the requirements at planned intervals.
Evidence: The programme with frequency, methods, responsibilities, planning and reporting, taking account of the importance of the work, changes and previous results.
Audit criteria and scope must be defined for each audit, and are auditors objective.
Evidence: Audit plans. Auditor competence and independence — nobody auditing their own work.
Audit results must be reported to relevant management, and is action taken without undue delay.
Evidence: Reporting evidence. Correction and corrective action closed.
You must be able to answer: Does management review the system at planned intervals?
Evidence: Review dates and attendance.
The review must cover every input the standard lists.
Evidence: An agenda covering: changes in internal and external issues, objectives met, suitability of policies and procedures, previous actions, recent internal audits, corrective actions, assessments by external bodies, changes in the volume and type of work, client and personnel feedback, complaints, effectiveness of improvements, adequacy of resources, results of risk identification, results of assuring the validity of results, and other relevant factors.
The review must produce recorded decisions and actions.
Evidence: Outputs on effectiveness of the system and its processes, improvement, resource needs and any change needed. An action list with owners and dates.
Using this document
Nothing above asks for a manual, a template pack, or a filing system. It asks for decisions that have been taken deliberately and can be shown to have been taken — which is a far smaller job than most organisations expect, and a different one.
Length is not compliance. A procedure nobody follows is worse than no procedure, because an auditor finds the gap between the two. The test we apply is whether the person who has to do the job recognises their own work in what is written down.
What this covers
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 17025, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- DPDP Act: documentation and compliance requirements
Everything DPDP Act requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
2026 оны есдүгээр сарын 12
- GDPR: documentation and compliance requirements
Everything GDPR requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
2026 оны есдүгээр сарын 12
- HIPAA: documentation and compliance requirements
Everything HIPAA requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
2026 оны есдүгээр сарын 12
