Knowledge base
ISO/IEC 17025:2017 – Documentation and Compliance Requirements
This guide explains, clause by clause, what a laboratory needs to document and what an auditor or assessor may ask to see as evidence.
Prem Kumar Dvivedi · 2026 оны есдүгээр сарын 12
It covers the key requirements of ISO/IEC 17025:2017 across five main areas. It is written as a set of requirements rather than a simple checklist.
A checklist only asks, “Do you have this?” This guide goes further by explaining what is required and what evidence can demonstrate compliance. This is especially useful when establishing or improving a laboratory management system.
________________________________________
4. Impartiality and Confidentiality
Clauses 4.1.1 to 4.1.5 and 4.2.1 to 4.2.3
Impartiality
The laboratory must perform its activities fairly and independently, without allowing personal, commercial, financial or other pressures to influence the results.
Evidence may include:
• A formal commitment to impartiality from top management.
• An organisational structure that protects impartiality.
• Identification of commercial, financial and other pressures that could affect results.
• Evidence that employees are not rewarded or pressured based on the results they report.
• A regular assessment of risks to impartiality.
• Records showing the risks identified and the actions taken to control them.
The laboratory must continuously review risks to impartiality, including risks related to:
• Ownership and management
• Financial interests
• Contracts
• Marketing activities
• Shared resources
• Client relationships
• Governance arrangements
Confidentiality
The laboratory must protect information received from clients.
Evidence may include:
• Confidentiality agreements signed by employees, contractors and other persons working for the laboratory.
• Arrangements for protecting client information.
• Records showing how legally required information disclosures were handled.
If information must be disclosed because of a legal requirement, the client should normally be informed unless the law prevents this.
Information received about a client from another source must also be treated as confidential.
________________________________________
5. Structure and Organisation of the Laboratory
Clauses 5.1 to 5.7
The laboratory must be a legal entity or a clearly defined part of a legal entity.
Evidence may include:
• Legal registration documents.
• Written authorisation from the parent organisation, where applicable.
The laboratory must have management with overall responsibility for its activities.
The laboratory must clearly define the activities for which it claims compliance with ISO/IEC 17025.
The documented scope should identify work performed:
• At permanent laboratory locations
• At temporary or mobile facilities
• At customer sites
• At other locations covered by the laboratory's activities
The laboratory must carry out its work in accordance with:
• ISO/IEC 17025 requirements
• Client requirements
• Regulatory requirements
• Requirements of organisations providing recognition or accreditation
The laboratory must have a documented organisational structure showing:
• Management
• Technical activities
• Supporting functions
• Responsibilities and authorities
• Relationships between different roles
Personnel must have sufficient authority and resources to operate, maintain and improve the management system and identify problems or deviations.
Management must also ensure that changes to the system do not negatively affect its effectiveness.
________________________________________
6. Resources – People, Facilities, Equipment and External Providers
Clauses 6.2 to 6.6
Personnel
Laboratory personnel must:
• Work impartially.
• Be competent for their assigned activities.
• Follow the laboratory's management system.
The laboratory must define the competence required for each role, including:
• Qualifications
• Education
• Training
• Knowledge
• Skills
• Experience
Evidence may include:
• Competence requirements for each position.
• Training records.
• Qualification records.
• Experience records.
• Competence evaluation records.
Each person must have clearly defined:
• Duties
• Responsibilities
• Authorities
The laboratory must have a process for:
• Selecting personnel
• Training personnel
• Supervising personnel
• Authorising personnel
• Monitoring competence
Personnel must be specifically authorised for the activities they perform.
Competence must be monitored continuously, not only when a person is first authorised.
Examples of evidence include:
• Witnessed testing
• Blind samples
• Repeat testing
• Supervised activities
• Review of results
Competence records must be maintained for permanent, temporary and contract personnel.
________________________________________
Facilities and Environmental Conditions
The laboratory must ensure that its facilities and environmental conditions are suitable for the work being performed.
The laboratory must identify and control conditions that could affect results, such as:
• Temperature
• Humidity
• Pressure
• Vibration
• Lighting
• Dust
• Microbial contamination
• Electromagnetic interference
Evidence may include:
• Facility descriptions.
• Environmental requirements.
• Monitoring records.
• Environmental condition logs.
If environmental conditions go outside acceptable limits, the laboratory must take appropriate action and assess whether previous results were affected.
Access to areas that could affect laboratory activities must be controlled.
The laboratory must also prevent:
• Contamination
• Interference
• Cross-contamination
• Conflicts between incompatible activities
The same controls must apply when work is performed at temporary, mobile or client locations.
________________________________________
Equipment
The laboratory must have suitable equipment and access to all equipment required for its activities.
Evidence may include:
• Equipment inventory.
• Equipment identification records.
• Equipment maintenance records.
• Verification records.
• Calibration records.
Equipment must be properly:
• Handled
• Transported
• Stored
• Used
• Maintained
Before equipment is put into service or returned to service, the laboratory must confirm that it meets the required specifications.
Equipment must be capable of achieving the accuracy or measurement uncertainty required by the relevant method.
Where necessary, equipment must be calibrated.
A calibration programme should define:
• What needs to be calibrated
• Calibration intervals
• Calibration requirements
• The basis for the calibration frequency
Calibration records should provide appropriate information about:
• Calibration results
• Measurement uncertainty
• Traceability
The calibration programme should be reviewed and updated when necessary.
The calibration status of equipment must be clear to users, for example through:
• Labels
• Identification codes
• Electronic records
Faulty or damaged equipment must be removed from service and clearly identified.
The laboratory must assess whether equipment problems affected previous results and issue amended reports where necessary.
Where required, intermediate checks must be performed between calibrations.
Correction factors must be properly controlled and updated.
Controls must also prevent unauthorised changes to equipment settings.
Equipment records should normally include:
• Equipment identification
• Manufacturer
• Model and serial number
• Location
• Verification records
• Calibration information
• Calibration due dates
• Maintenance history
• Damage or malfunction information
________________________________________
Metrological Traceability
Measurement results must be traceable to appropriate references.
Normally, traceability should be established through an unbroken chain of calibrations, with each step contributing to measurement uncertainty.
Evidence may include:
• Calibration certificates from competent laboratories.
• Evidence of accreditation or competence of calibration providers.
• Certified reference materials from competent providers.
• A documented traceability plan.
Where direct traceability to the SI system is not technically possible, the laboratory must use a suitable alternative and document the justification.
________________________________________
External Products and Services
Products and services purchased from external providers must be suitable for laboratory activities.
This can include:
• Calibration services
• Subcontracted testing
• Reference materials
• Consumables
• Proficiency testing
• Equipment maintenance
The laboratory must:
• Define its requirements.
• Evaluate suppliers.
• Monitor supplier performance.
• Re-evaluate suppliers when necessary.
• Keep records of evaluations and actions.
Purchase orders and specifications should clearly communicate the requirements to suppliers.
________________________________________
7. Laboratory Activities
Clauses 7.1 to 7.11
Review of Requests, Tenders and Contracts
The laboratory must have a process for reviewing requests, tenders and contracts before accepting work.
The review should confirm that:
• Requirements are clearly understood.
• The laboratory has the necessary resources.
• The laboratory has the competence to perform the work.
• The selected method can meet the requirements.
If a client requires a statement of conformity, the decision rule must be agreed with the client unless it is already defined in the relevant standard or specification.
Differences between the client's request and the contract must be resolved before work begins.
If the agreed requirements change, the laboratory must review the changes and communicate them to the relevant personnel.
Records of reviews and important discussions with clients must be maintained.
________________________________________
Methods and Procedures
The laboratory must use suitable and current methods for its activities.
Methods and supporting documents must:
• Be approved.
• Be kept up to date.
• Be available to staff where the work is performed.
• Have proper version control.
The latest valid version of a method should normally be used unless there is a justified reason not to use it.
When the client does not specify a method, the laboratory must select an appropriate method and inform the client.
Before introducing a method, the laboratory must verify that it can properly perform the method.
Evidence may include:
• Method verification records.
• Performance results.
• Method approval records.
________________________________________
Method Development and Validation
Where the laboratory develops its own methods, the activity must be planned and assigned to competent personnel.
Deviations from a method must be:
• Documented.
• Technically justified.
• Authorised.
• Accepted by the client where applicable.
Non-standard, laboratory-developed, modified or out-of-scope methods must be validated.
Validation records should show:
• The validation procedure.
• Requirements.
• Performance characteristics.
• Results obtained.
• Conclusions regarding suitability for the intended use.
If a validated method is changed, the laboratory must assess the impact and perform revalidation where necessary.
________________________________________
Sampling
Where sampling is part of the laboratory's activities, the laboratory must have an appropriate sampling plan and method.
The sampling method should define the factors that need to be controlled to ensure valid results.
Sampling records should include relevant information such as:
• Date and time
• Sample identification
• Location
• Person who performed sampling
• Equipment used
• Environmental or transport conditions
• Sampling method
• Deviations from the method
If the laboratory does not perform sampling, this requirement may be marked as not applicable with an appropriate justification.
________________________________________
Handling of Laboratory Items
The laboratory must have procedures for:
• Receiving
• Transporting
• Handling
• Protecting
• Storing
• Retaining
• Disposing of items
Every item must have a unique identification throughout the laboratory process.
If an item arrives in an unsuitable or damaged condition, the laboratory must consult the client before proceeding where necessary and record the decision.
Required storage or environmental conditions must be monitored and recorded.
Items must be protected from damage, contamination, loss or deterioration.
________________________________________
Technical Records
Technical records must contain enough information to allow the activity to be understood and, where reasonably possible, repeated.
Records should identify:
• The work performed
• Results
• Relevant conditions
• Measurement uncertainty
• Person performing the work
• Person reviewing the work
• Dates
Original observations should be recorded when they are made.
If a record is changed, the original information must remain identifiable, together with:
• What was changed
• Who changed it
• When it was changed
Electronic records should have suitable controls and audit trails.
________________________________________
Measurement Uncertainty
The laboratory must identify and evaluate relevant contributions to measurement uncertainty.
Calibration laboratories must evaluate measurement uncertainty for their calibrations.
Testing laboratories must estimate measurement uncertainty using an appropriate recognised approach.
Where appropriate, uncertainty budgets and supporting calculations should be maintained.
________________________________________
Monitoring the Validity of Results
The laboratory must have a process for monitoring whether its results remain valid and reliable.
Methods may include:
• Reference materials
• Control charts
• Replicate testing
• Retesting
• Intermediate checks
• Blind samples
• Other appropriate quality control activities
The laboratory should participate in proficiency testing or interlaboratory comparisons where applicable.
Results must be reviewed and analysed.
If performance falls outside defined criteria, the laboratory must investigate and take appropriate corrective action before incorrect results are reported.
________________________________________
Reporting Results
Results must be reviewed and authorised before they are released.
Reports must contain the information required by ISO/IEC 17025, such as:
• Laboratory identification
• Report identification
• Client information
• Method used
• Description and identification of the item
• Dates
• Results
• Units
• Relevant deviations
• Name or identification of the person authorising the report
Test reports may also need to include:
• Sampling information
• Relevant environmental conditions
• Measurement uncertainty
• Opinions or interpretations, where applicable
Calibration certificates should include:
• Measurement results
• Measurement uncertainty
• Traceability information
Where sampling results are reported, relevant sampling information should also be included.
________________________________________
Statements of Conformity
When the laboratory states whether a result meets a specification or requirement, it must use a documented decision rule.
The report should identify:
• The decision rule used.
• The relevant specification or requirement.
• The basis for the conformity statement.
________________________________________
Opinions and Interpretations
Opinions and interpretations must only be provided by authorised personnel.
The basis for the opinion or interpretation must be documented.
________________________________________
Amended Reports
If a report is changed after issue, the amended report must be clearly identified and linked to the original report.
________________________________________
Complaints
The laboratory must have a documented complaints process that is available to interested parties.
The process should cover:
• Receiving complaints
• Validating complaints
• Investigating complaints
• Making decisions
• Communicating outcomes
• Maintaining records
The complainant should be kept informed about the progress and outcome.
The person deciding the complaint should be independent from the activity being complained about wherever possible.
________________________________________
Nonconforming Work
The laboratory must have a procedure for handling work that does not meet requirements.
The procedure should define:
• Who can stop the work.
• Who evaluates the issue.
• Who decides what action is required.
• Who can authorise work to restart.
The laboratory must evaluate the effect of nonconforming work, including its possible effect on previous results.
Where necessary, the laboratory may need to:
• Stop work.
• Repeat testing.
• Withhold reports.
• Notify clients.
• Recall previously issued reports.
Records of the issue and actions taken must be maintained.
Corrective action should be taken when the problem could happen again.
________________________________________
Laboratory Information Management Systems
Laboratory information systems must be validated before use and after significant changes.
The laboratory must protect its information systems against:
• Unauthorised access
• Unauthorised changes
• Data loss
• Incorrect processing
Controls should include:
• Access controls
• Backup arrangements
• Restore testing
• Data integrity controls
Calculations and data transfers must be systematically checked.
System failures must be recorded and addressed promptly.
If the system is operated by an external provider, the laboratory must ensure that ISO/IEC 17025 requirements continue to be met.
________________________________________
8. Management System
Clauses 8.1 to 8.9
The laboratory must establish and maintain a management system.
It must choose either:
• Option A, or
• Option B
The selected option should be documented.
Under Option B, the laboratory uses an ISO 9001-based management system that supports the consistent fulfilment of ISO/IEC 17025 requirements related to Sections 4 to 7.
________________________________________
Policies and Objectives
The laboratory must have documented management system policies and objectives.
These should demonstrate management's commitment to:
• Competence
• Impartiality
• Consistent laboratory operations
Employees should understand and apply these policies and objectives.
The management system documentation must cover the applicable requirements of Section 8.
________________________________________
Document Control
Management system documents must be:
• Approved before use.
• Available where needed.
• Reviewed regularly.
• Updated when necessary.
• Re-approved after changes.
• Properly version controlled.
Obsolete documents must be removed from use or clearly identified if they are retained.
________________________________________
Control of Records
The laboratory must maintain records that demonstrate compliance with the standard.
Records must be:
• Identified
• Stored
• Protected
• Backed up where necessary
• Retrieved when needed
• Retained for the required period
• Disposed of appropriately
Retention periods should consider regulatory, accreditation and contractual requirements.
________________________________________
Risks and Opportunities
The laboratory must identify risks and opportunities related to its activities.
The assessment should consider:
• Whether the management system achieves its intended results.
• Opportunities for improvement.
• Prevention or reduction of unwanted effects.
• Improvement of laboratory operations.
Actions should be planned and integrated into the management system.
The laboratory must review whether those actions were effective.
________________________________________
Improvement and Customer Feedback
The laboratory should identify opportunities for improvement using information such as:
• Client feedback
• Operational data
• Internal audits
• Management reviews
• Complaints
• Performance results
Both positive and negative client feedback should be considered.
________________________________________
Corrective Action
When a nonconformity occurs, the laboratory must:
1. Respond to the problem.
2. Control and correct it.
3. Address its consequences.
4. Determine whether the cause needs to be removed.
5. Take corrective action where necessary.
6. Review whether the action was effective.
7. Update risks or the management system when required.
Records should be maintained for:
• The nonconformity.
• Its cause.
• Actions taken.
• Results of the actions.
________________________________________
Internal Audit
The laboratory must have an internal audit programme covering the applicable ISO/IEC 17025 requirements.
The audit programme should consider:
• Frequency
• Methods
• Responsibilities
• Planning
• Reporting
• Importance of laboratory activities
• Previous audit results
• Changes in the organisation
Each audit should have a defined:
• Scope
• Criteria
• Objectives
Auditors should be competent and objective and should not audit their own work.
Audit results must be reported to the appropriate management, and required corrective actions should be addressed without unnecessary delay.
________________________________________
Management Review
Management must review the management system at planned intervals.
The review should consider relevant information, including:
• Changes in internal and external issues.
• Achievement of objectives.
• Suitability of policies and procedures.
• Previous management review actions.
• Internal audit results.
• Corrective actions.
• External assessments.
• Changes in the volume and type of work.
• Client feedback.
• Personnel feedback.
• Complaints.
• Improvement activities.
• Resource requirements.
• Risks and opportunities.
• Results related to the validity of laboratory activities.
The management review must produce documented decisions and actions.
These may relate to:
• Effectiveness of the management system.
• Improvement.
• Resource requirements.
• Changes required in the laboratory.
Actions should have clear responsibilities and target dates.
________________________________________
How to Use This Guide
ISO/IEC 17025:2017 does not simply require a large manual, a collection of templates or a complicated filing system.
The real requirement is that the laboratory has appropriate processes, decisions and controls in place — and can demonstrate that they are being followed.
More documentation does not automatically mean better compliance.
A long procedure that employees do not follow can create more problems than a simple procedure that accurately reflects actual laboratory practices.
The key question is:
Can the laboratory demonstrate that its people understand the requirements, follow the defined processes and maintain reliable, technically valid results?
In practical terms, compliance is not about having more documents. It is about having the right controls, competent people, reliable processes and objective evidence to demonstrate that the laboratory consistently performs its work as required by ISO/IEC 17025:2017.
What this covers
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 17025, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Automotive Suppliers Face Stricter Cybersecurity Assessments
Cybersecurity is becoming a key part of supplier evaluations in the automotive industry. Vehicle manufacturers now check how suppliers protect data and systems alongside quality, cost, and delivery.
2026 оны есдүгээр сарын 13
- Automotive OEM Vendor Cybersecurity Assessment: Controls, Scoring and ISO Standards Mapping
What does an automotive vendor cybersecurity assessment cover?
2026 оны есдүгээр сарын 13
- Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask For
The nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.
2026 оны есдүгээр сарын 13
