Standards & accreditation

ISO/IEC 17025 checklist for testing laboratories

What a testing laboratory has to be able to prove under ISO/IEC 17025:2017 — walked through clause by clause, including the points where audits most often get stuck in practice.

Last updated:

In short

ISO/IEC 17025 is the international standard for the competence of testing and calibration laboratories. It requires evidence in five blocks: general requirements (clause 4: impartiality and confidentiality), structural requirements (clause 5), resources (clause 6: personnel, facilities, equipment, metrological traceability), processes (clause 7: methods, handling of items, records, measurement uncertainty, reporting) and the management system (clause 8). What matters is not that rules exist, but that for every single test it is demonstrable who performed it, when, with which calibrated equipment and under which method.

What the standard covers — and what it does not

The current edition is ISO/IEC 17025:2017. It sets out the general requirements for the competence, impartiality and consistent operation of laboratories, and applies equally to testing and calibration laboratories regardless of size, industry or headcount.

An important distinction: ISO/IEC 17025 is not a product standard and does not prescribe test methods. It does not tell you how to test a component; it defines the demonstrable conditions under which a result must be produced for it to be trusted. Equally, it sets no fixed calibration intervals, retention periods or staffing ratios — the laboratory defines these itself and must be able to justify them.

Accreditation is not granted by the standard but by a national accreditation body — DAkkS in Germany, UKAS in the United Kingdom, A2LA or similar bodies in the United States. Accreditation is typically granted for a multi-year cycle and accompanied by surveillance assessments. Between those dates the evidence has to hold continuously, not just on the day of the audit.

Clauses 4 and 5: impartiality, confidentiality, structure

The first two blocks are often underestimated because they have little to do with technology. That is precisely why documents are frequently missing here.

  • Risks to impartiality are identified and evaluated on an ongoing basis — especially where the laboratory is part of a company that develops or sells the products being tested.
  • It is documented how pressure on test results (commercial, financial, or from management) is recognised and removed.
  • Confidentiality of customer information is governed, including the cases where the laboratory is legally required to disclose.
  • The legal entity and the responsibility for laboratory activities are unambiguously defined.
  • The range of laboratory activities for which conformity with the standard is claimed is clearly delimited — including activities that are outsourced.
  • An organisational chart exists showing management, deputies, and the people authorised to release results.

Clause 6: resources — personnel, facilities, equipment, traceability

In practice this is the most demanding clause, because it requires continuously maintained evidence rather than documents written once.

  1. 1

    Personnel (6.2)

    For every activity, the required competence is defined. For every person, it is demonstrated that they hold that competence: qualification, induction, training, supervision, and formal authorisation for specific test procedures. Authorisations must be current — expired qualifications are one of the most common nonconformities.

  2. 2

    Facilities and environmental conditions (6.3)

    Where environmental conditions influence the result (temperature, humidity, vibration, electromagnetic interference), they are specified, monitored and recorded. It is defined that testing stops, or the result is assessed accordingly, when limits are exceeded.

  3. 3

    Equipment (6.4)

    Every instrument that influences the result is uniquely identified and carries a record: manufacturer, serial number, location, current calibration and maintenance status, calibration history, and any damage, malfunction or repair. Equipment that is overdue for calibration or known to be defective must be visibly taken out of service.

  4. 4

    Metrological traceability (6.5)

    Measurement results are traceable to the SI through an unbroken chain of calibrations. In practice: calibration certificates are on file, come from a competent provider (normally accredited), and state the measurement uncertainty. The chain must have no gap.

  5. 5

    Externally provided products and services (6.6)

    Requirements are defined for calibration providers, subcontracted laboratories, reference materials and critical consumables; providers are evaluated and the evaluation is documented.

Clause 7: processes — from enquiry to report

Clause 7 follows a job through the laboratory, so the checklist reads as a walkthrough.

RequirementWhat has to be demonstrable
Review of requests, tenders and contracts (7.1)Before acceptance it is established that method, capacity and competence match the request; any deviation from the order is agreed with the customer and documented.
Selection and validation of methods (7.2)The method applied is named for every test. Standard methods are used in their current edition and verified; in-house or modified methods are validated, with the validation scope documented.
Sampling (7.3)Where the laboratory takes samples itself: a sampling plan, the procedure, and records of location, time and any deviations.
Handling of test items (7.4)Items are uniquely identified from receipt to return; transport, storage, condition on receipt and any deviations are recorded.
Technical records (7.5)Records make it possible to repeat a test under the same conditions. Amendments are traceable: the original value, the amended value, the time and the responsible person all remain visible.
Evaluation of measurement uncertainty (7.6)Contributing quantities are identified and the uncertainty is evaluated — for calibration laboratories on every calibration, for testing laboratories at least where the method requires it or where interpretation of the result depends on it.
Ensuring the validity of results (7.7)Internal quality control (control charts, replicate testing, retests) and external comparisons (interlaboratory comparisons, proficiency testing) are planned, carried out and evaluated — with a defined response when criteria are breached.
Reporting of results (7.8)Test reports contain the information the standard requires, in particular identification of laboratory, customer and test item, the method, dates, results with units, the person authorising release and — where statements of conformity are given — the decision rule applied.
Complaints and nonconforming work (7.9, 7.10)Both processes are described and actually operated: evaluation, immediate action, decision on acceptability, and where necessary recall of reports and notification of the customer.
Control of data and information management (7.11)Laboratory information systems are protected against unauthorised access, backed up, validated before use, and re-checked after changes.

Clause 8: the management system

The standard allows two routes here. Option A means the laboratory operates a management system that meets requirements 8.2 to 8.9 of ISO/IEC 17025. Option B means the laboratory already operates a management system conforming to ISO 9001 that also covers the ISO/IEC 17025 requirements. Both are equally valid; Option B only saves effort if the ISO 9001 system is genuinely lived.

  • Management has documented and communicated a policy and objectives for meeting the standard.
  • Documents are controlled: approval, revision status, availability at the point of use, withdrawal of obsolete versions.
  • Records are controlled: retention periods defined, protected against loss and unauthorised amendment, and retrievable.
  • Risks and opportunities are assessed, and the resulting actions are checked for effectiveness.
  • Corrective actions address the cause rather than the symptom, and their effectiveness is followed up.
  • Internal audits cover all clauses of the standard within the defined cycle and are carried out by people who do not assess their own area.
  • Management reviews take place as planned and address the inputs named in the standard, including results from proficiency testing, complaints and internal audits.

Where audits typically come apart

Most findings are not about missing rules but about the gap between the rule and daily practice. Three patterns recur:

  1. 1

    The evidence exists but cannot be found

    The calibration certificate, the training record and the measurement file all exist — spread across a network drive, a folder and one person's inbox. If assembling them during the audit takes half an hour, the assessor reads that as how it works day to day.

  2. 2

    Equipment status is not linked to the test

    The calibration list shows an instrument is validly calibrated today. The question in the audit is whether it was validly calibrated at the time of one specific, already-reported test — and which reports are affected if it was not.

  3. 3

    Changes to measurement data are not traceable

    A value corrected in a spreadsheet can no longer be distinguished from one originally captured. Clause 7.5 requires exactly that distinction, including the time and the responsible person.

Which part of this software can take over

Software does not make a laboratory conformant — competence, method validation and impartiality are organisational questions. What a system can take over is the evidence layer: the link between item, test, instrument, calibration status, person and result, which in scattered spreadsheets only exists through discipline and erodes over time.

  • Equipment master data with calibration status and history, instead of a separately maintained calibration list (6.4, 6.5).
  • An audit log that records changes to measurement data with original value, time and person (7.5).
  • Test reports that draw their content from the data, instead of being assembled by hand before every dispatch (7.8).
  • Nonconformities attached to the affected test item rather than living in an email thread (7.10).
  • Qualifications and authorisations with expiry dates, visible before they lapse (6.2).

These are the links TestLabIQ models. If you want to check whether that holds up for your laboratory, a demo is the shortest route — we walk the audit case through your own examples rather than a sample data set.

Frequently asked questions about ISO/IEC 17025

Which edition of ISO/IEC 17025 is current?

ISO/IEC 17025:2017. It replaced the 2005 edition and is structured around processes and risk rather than prescriptive management clauses.

Is ISO/IEC 17025 a certification or an accreditation?

An accreditation. The difference is substantive, not just wording: certification confirms that a management system conforms to a standard, while accreditation additionally confirms technical competence for specifically named test procedures.

Does ISO/IEC 17025 prescribe fixed calibration intervals?

No. The standard requires that equipment is calibrated where measurement accuracy affects the result, and that a calibration programme exists. The laboratory sets the actual intervals itself and must be able to justify and adjust them.

Do small laboratories face the same effort?

The requirements apply regardless of size; the appropriate volume of documentation does not. A three-person laboratory does not need a multi-volume quality manual — it needs the same unbroken evidence, on a smaller scale.

How long do records have to be retained?

The standard names no fixed period. The laboratory defines retention itself — usually guided by contractual commitments, legal requirements and product lifetime — and must keep records legible, retrievable and protected against amendment for that period.

Evidence you can find in seconds during an audit

TestLabIQ links test item, instrument, calibration status, measurement data and report — with a complete audit log for every change.

Book a free demo

This guide is editorial orientation, not legal or accreditation advice. The authoritative source is always the text of ISO/IEC 17025 in its current edition, together with the interpretation of the responsible accreditation body.