ISO/IEC 17025 and laboratory data integrity: from measurement to test report

A test report leaves your laboratory. It states a concentration, a strength, a calibration value, with an uncertainty attached to it. Someone signs it, the customer files it, and for a while nothing happens.

Then, eleven months later, an email arrives. A batch was rejected on the basis of that number, or a permit was refused, or a supplier is being held liable for a shipment. A lawyer wants to know how you arrived at that figure. Not whether your method was validated: that part is easy to answer, because the validation file exists and the accreditation covers it. The question is narrower and much harder. Between the detector and the line printed on the report, what happened to the number, who touched it, and can you show that what you issued is what your instrument produced?

Most laboratories answer that question with people. The analyst remembers. The technical manager reconstructs. Someone opens the instrument software and hunts for the sequence. It usually works out. It also takes days, and it rests on memory rather than on evidence, which is an uncomfortable place to be when the other side has a lawyer and you have a spreadsheet.

This article is about that stretch of the process: the part of the measurement chain that ISO/IEC 17025 addresses through its requirements on the management of information, and that most quality systems govern more loosely than everything before it.

What ISO/IEC 17025 is, and who it applies to

ISO/IEC 17025 sets out the requirements for the competence, impartiality and consistent operation of testing and calibration laboratories. It is published by ISO together with IEC, and the current edition is the 2017 one.

It applies to any laboratory performing testing or calibration, whatever its size and whatever it sits inside. A dedicated commercial laboratory falls under it. So does a laboratory embedded in a manufacturer, a hospital, a utility or a public authority, when that laboratory wants its results to be recognised beyond its own walls. Sampling, when the laboratory performs it, comes within the same frame, which matters a great deal in environmental and food work where the sample is often taken far from the bench.

Before going further, a distinction the market confuses constantly.

Accreditation is not certification. A laboratory is accredited by an accreditation body, which assesses its technical competence to perform specific tests or calibrations. That assessment is granular: it names methods, matrices, ranges, sites. A company is certified against a management system standard by a certification body, which is a different exercise with a different meaning. When a customer asks whether you are "ISO 17025 certified", the honest answer starts by correcting the verb.

There is a further distinction, and it is the one this article turns on. Accreditation covers the competence to produce a result. It does not, on its own, guarantee that the result printed on the report is the result the instrument produced, and neither does it try to. That guarantee comes from how the laboratory controls its data.

The 2017 edition is still the current one

There is confusion in the accreditation world right now, and it is worth clearing up before anything else.

ISO/IEC 17025 has not been revised. The edition in force is the one published in 2017. If you manage a laboratory, you do not have a transition to plan, no deadline to count down to, no gap analysis to commission.

The confusion comes from the neighbours. ISO/IEC 17020, which covers inspection bodies, came out in a new edition in 2026, and inspection bodies do have a transition on their hands. Other documents in the same family of conformity assessment standards have moved in the same period. Consultants and training providers have been busy, LinkedIn has been noisy, and a fair number of laboratory managers have come away with the impression that something is about to land on them too.

Nothing is. No published source announces a new edition of ISO/IEC 17025, and you should treat any claim that one is imminent as sales talk until an ISO publication says otherwise. The standards in this family do get aligned with each other over time, and that alignment is documented, but alignment work is not a revision and does not come with a date.

What this means practically is that the requirements you have to satisfy today are the ones written in 2017. Which turns out to be good news for the subject of this article, because the 2017 edition already says quite a lot about data.

How the standard is built

The standard organises its requirements around a handful of ideas that hold the whole thing together.

Competence comes first. The laboratory has to demonstrate that its personnel, its equipment and its methods are fit for the work it performs, and not in general terms: for the specific tests and calibrations in its scope of accreditation.

Impartiality and confidentiality sit alongside it. The laboratory has to identify what could bias its results and manage that risk, and it has to protect what its customers entrust to it.

Then comes metrological traceability, the spine of the whole discipline and the reason calibration laboratories exist at all: a measurement result has to be linked, through an unbroken chain of calibrations, to a stated reference.

The validity of results is treated as an ongoing obligation rather than a one-off exercise. Methods have to be validated or verified, measurement uncertainty has to be evaluated, and the laboratory has to monitor whether its results stay valid over time, including through proficiency testing and internal quality control.

And the standard requires the management of information: the laboratory has to control the data it handles, including in computer systems, and protect records from loss, unauthorised access and undetected alteration.

That last one is where this article lives, and it is the point most summaries of the standard rush past. It is not an appendix or an IT footnote. It sits alongside traceability and validity as a condition for the result to mean anything.

Why ISO/IEC 17025 already speaks about data

When people talk about data integrity in laboratories, they usually reach for pharmaceutical regulation, because that is where the vocabulary was born. It is a reasonable instinct and it produces a slightly wrong conclusion: that data integrity is a pharma topic which other laboratories may adopt voluntarily.

The 2017 edition of ISO/IEC 17025 contains requirements on the management of information covering laboratory information systems, the protection of data, the authorisation of access, the control of changes and the safeguarding of records. Written before the current wave of interest in the subject, and applying to every accredited laboratory regardless of sector.

Read those requirements without the pharma vocabulary and they say something simple. The laboratory has to be able to show that the data in its systems are what the laboratory put there, that changes to them happened on purpose and by someone entitled to make them, and that a record can be produced later in the state it was in when it was created.

The reason so many laboratories are thin on this is not negligence. It is that the requirement lands on the least equipped part of the process. Instruments are qualified, methods are validated, balances are calibrated, analysts are trained and their competence is monitored. All of that is heavily documented because all of that is what assessors historically asked about. The stretch where a result becomes a report has grown up around whatever tools were available, and the tools available were email, spreadsheets and file shares.

The journey of the datum, and where it loses its guarantees

Follow a single number through a working day. The specifics change by discipline, but the shape does not.

At the instrument

A chromatograph, a spectrometer, a testing machine or a calibrator produces a raw signal and stores it in its own software, with an acquisition sequence, an operator identity and a timestamp. In a well-run laboratory this is the strongest link in the chain. The instrument was qualified, the calibration curve is traceable, the software keeps its own record of what was acquired and when.

Nothing has gone wrong yet. Everything that follows is where the guarantees start to thin out.

The first transformation

A raw signal is not a result. A peak area becomes a concentration through a calibration model. A load curve becomes a yield strength through a criterion someone has to apply. A set of readings becomes a calibration value with an uncertainty attached, and that uncertainty comes from a budget maintained in a document that is usually a spreadsheet.

Some of this happens inside the instrument software, where it is recorded. Some of it happens outside, where it is not. Reintegrating a chromatogram to correct a baseline is a legitimate technical decision that analysts make every week. What has to survive is the reason it was made and the state of the data before and after, and that is exactly what tends not to survive when the work moves out of the instrument software and into a general purpose tool.

The spreadsheet layer

Almost every laboratory has one, including laboratories with a full information management system, because there is always a calculation the system does not do, a customer who wants a different unit, a blank correction applied by hand, a report template that lives somewhere else.

A spreadsheet has no memory. It records the last save, not the sequence of decisions that produced it. Who changed the cell, when, and why, is information the file was never designed to hold. If a formula is dragged one row too far, the number changes and nothing announces it. If an uncertainty budget is copied from a previous job and one line is not updated, the certificate states an uncertainty that was never calculated for that measurement.

This is not a hypothetical failure mode. Ask any technical manager who has run a root cause investigation after a proficiency testing outlier: a meaningful share of them end in a spreadsheet.

Sampling and field data

For environmental and food laboratories the chain starts before the bench. The time and place of sampling, the identity of the sampler, the transport temperature, the condition of the container on arrival: all of it conditions the validity of the result, and all of it is frequently captured on paper, photographed with a phone, and retyped later by someone who was not there.

A retyped figure is a new figure. It may be identical to the original, and usually is. But its origin now rests on the assertion of the person who typed it, which is a weaker thing than a record of the moment it was taken.

Review, approval and issue

The result reaches the report. Someone with the authority to do so reviews it and approves it. The report is generated, signed and sent, usually as a document attached to an email.

At that moment the laboratory loses sight of it. The file sitting in the customer's folder is almost certainly the one you issued, and you have no practical way of demonstrating that a year later, because a document in someone else's system carries no evidence of its own history. When a report is challenged, one of the first things worth establishing is whether the document being contested is actually the document you issued. Laboratories are rarely in a position to settle that question quickly.

Everything before the result, and everything after

Everything before the result is governed by requirements, verified by assessors and supported by dedicated tooling. Everything after it is governed by habit. The guarantees do not fail at the instrument, where the laboratory invests most of its attention. They thin out in the stretch where the number is moved, transformed, reformatted and transmitted, and that stretch is precisely what the requirements on the management of information are pointing at.

TrueScreen

TrueScreen

TrueScreen, the forensic acquisition and certification platform

Acquire and certify digital content with legal value, right from the source.

Discover more →

What the standard asks of technical records and test reports

Technical records are the evidence that the work was done as described. The standard requires the laboratory to keep records containing the results, the data and enough information to allow the test or calibration to be repeated under conditions as close as possible to the original, together with the identity of the personnel involved.

It also requires that amendments to records remain visible. When something is corrected, the previous version has to remain retrievable, and the change has to be attributable to whoever made it and dated. The obligation is not to be right the first time. It is to never lose the trace of what was there before.

Test reports and calibration certificates carry their own requirements: the results with their units, the method used, the identification of the items, the date of the activity, the measurement uncertainty where relevant, and clear identification of anything that limits the interpretation of the result. Amendments to an issued report have to be identified as such and traceable to the report they replace.

Read together with the requirements on the management of information, these obligations describe a laboratory that can reconstruct, at any point in the retention period, what it observed, what it calculated, what it issued and who was responsible for each step. Most laboratories can do this. What takes them days, and a certain amount of institutional memory, is doing it in a way that convinces someone who has no reason to take their word for it.

When the test report is challenged

A few situations bring this into the open, and none of them is rare.

Sometimes it is a plain commercial dispute. A food safety result triggers a withdrawal and the producer contests it. An environmental exceedance leads to an enforcement action and the operator's technical consultant asks for the raw data. A materials test underpins the rejection of a delivery worth more than the laboratory's annual revenue. In each case the challenge is not usually aimed at your competence. It is aimed at the space between the instrument and the report, because that is where a competent laboratory is most easily made to look uncertain.

Sometimes it is the assessment itself. Assessment practice has drifted steadily towards data. It is no longer unusual for an assessor to pick a report at random and ask to be walked back from a printed figure to the acquisition that produced it, through every transformation, with the authorisations and the amendments visible along the way. Laboratories that pass this comfortably have generally built something deliberate. Laboratories that pass it uncomfortably have generally relied on the analyst being available that morning.

And sometimes the challenge reaches you second hand, through someone who depends on your certificate. A calibration certificate you issue becomes part of another laboratory's traceability chain, and their accreditation partly rests on it. When their result is questioned, yours is questioned with it. The further your document travels, the less control you have over the copy being examined, and the more useful it becomes to have made the document self-evidencing at the moment it left you.

What a defensible laboratory datum looks like

Before any tool, the criterion.

A laboratory datum is defensible when its state at a given moment can be demonstrated to someone who was not present and has no reason to trust you. That is a deliberately hostile test, and it is the right one, because the moment the question gets asked seriously, the person asking is rarely friendly.

From that criterion, the properties follow.

The origin has to be fixed at the moment the datum is produced, not reconstructed afterwards. A record created when the measurement was taken and bound to it from that instant carries a weight that a later assertion cannot recover, however honest the assertion.

Any subsequent change has to be visible and attributable. Not prevented: laboratories correct data, reprocess results and reissue reports for legitimate reasons every week. What matters is that the previous state remains available and that the transition between states is on the record.

The record has to remain checkable independently of the systems that produced it. Instrument software gets replaced. Information management systems get migrated. Vendors disappear. A record whose credibility depends on a specific application still running in a specific version is not a record you can rely on for the length of a retention period, let alone for the length of a legal dispute.

And it has to survive time. Retention periods in this field run to years, and the challenges that matter tend to arrive near the end of them.

How TrueScreen supports this

TrueScreen is a Data Authenticity Platform. In a laboratory context it addresses the stretch of the chain described above, and it does so in a defined sequence.

Data are acquired with a forensic methodology that protects them at source. The origin is fixed as the record is produced: the moment, the content and the context are bound together at that instant rather than asserted later. This is the property that turns a field observation, a sampling record or a result being transferred out of an instrument environment into something with a demonstrable starting point.

Integrity and authenticity are then verified. The record is checked to establish that what is being examined is what was acquired, and that check does not depend on trusting the laboratory that holds it.

The verified result receives a digital seal and timestamp with legal value recognised internationally. The European framework for electronic seals and timestamps is set out in Regulation (EU) 910/2014, which gives these instruments a defined legal standing across member states and a basis for recognition beyond them. In practice this is what allows the laboratory to stop arguing about whether a record is authentic and move the conversation to what the result actually means.

Retention follows, in a form that can be produced and checked long after the analyst has left the company and the instrument has been replaced.

None of this makes a laboratory compliant with ISO/IEC 17025, and none of it accredits anything. Accreditation is granted by an accreditation body after an assessment of technical competence, and no supplier can shortcut that. What it does is strengthen and simplify the fulfilment of specific requirements: the ones on the management of information, on the integrity of technical records, and on the traceability of what appears in a report back to what was actually observed.

Mapping the requirement to what you have to show

Requirement area What you have to be able to demonstrate How TrueScreen strengthens it
Management of information That data held in your systems are protected against unauthorised access and undetected alteration, and that a record can be produced in the state it was in when created Records are sealed at creation, so their state at that moment can be checked independently rather than asserted
Technical records That the original observation is retrievable, that amendments are visible, and that each is attributable and dated The original remains demonstrable after any later revision, and the sequence of states stays on the record
Sampling and field activities That the conditions of sampling were recorded as they occurred, by an identified person, at an identified place and time Capture in the field binds the moment and the context to the record as it is produced, without a retyping step
Test reports and calibration certificates That the document under discussion is the one you issued, and that any amendment is identified as such The issued document carries its own evidence of authenticity wherever it travels
Retention That records remain intelligible and verifiable throughout the retention period Verification does not depend on the instrument software or information system that produced the data

The table describes support for requirements, not a substitute for the management system that has to satisfy them. The procedures, the authorisations and the competence remain yours.

Where ISO/IEC 17025 sits in the family

The standards get mixed up constantly, including by customers writing tender specifications. The distinction is worth having in one place.

One more belongs alongside them for forensic work: how ISO 21043 complements ISO/IEC 17025 matters because the forensic sciences series covers stages the accreditation standard never reaches, such as collecting an item at a scene or presenting an opinion in court.

Standard What it addresses Who it applies to What it produces Recognised through
ISO/IEC 17025 Competence, impartiality and consistent operation in testing and calibration Testing and calibration laboratories Test reports and calibration certificates Accreditation by an accreditation body
ISO/IEC 17020 Competence and impartiality in inspection activities Inspection bodies Inspection reports and certificates Accreditation by an accreditation body
ISO/IEC 17021-1 Requirements for bodies that audit and certify management systems Certification bodies Management system certificates issued to their clients Accreditation by an accreditation body
ISO 9001 Requirements for a quality management system Any organisation, in any sector Certification of the organisation's management system Certification by a certification body

The line that matters most separates ISO 9001 from the accreditation standards above it. ISO 9001 asks whether an organisation has a working quality management system, and says nothing about whether the numbers that organisation produces are technically valid. ISO/IEC 17025 asks the management system question as well, and then asks the harder technical one on top of it. A laboratory can hold a valid ISO 9001 certificate and be unable to demonstrate metrological traceability for a single measurement it makes, which is why customers who need results they can rely on ask for accreditation rather than certification.

The line between 17025 and 17020 is subtler and depends on what is being produced. An inspection body evaluates and judges against requirements, often in the field, often on the basis of professional examination. A laboratory measures, and produces a number with an uncertainty attached to it. The evidence problems look similar from a distance and are quite different up close, which is why the companion piece on ISO/IEC 17020 and inspection evidence deals with photographs, site visits and field records, while this one deals with measurement data and reports. Organisations that hold both accreditations are common, and they generally discover that a single approach to the integrity of their records serves both.

Recognition beyond your own country

An accredited test report is worth more than a test report, and it is worth more in more places than most laboratories realise.

Accreditation bodies that meet the international requirements and pass peer evaluation sign the mutual recognition arrangement operated by ILAC, the International Laboratory Accreditation Cooperation. Signatories accept each other's accredited results, and the arrangement exists to remove the need for goods to be retested when they cross a border. ILAC summarises the principle as "accredited once, accepted everywhere", and describes the arrangement as reducing technical barriers to trade by removing the need for repeated calibration, testing and inspection of imports and exports.

For a laboratory serving exporters, this is the commercial argument for accreditation and it is a strong one. It also raises the stakes on everything discussed above. A report that travels internationally is a report that will be read by people who have never visited your site, cannot assess your culture, and have only the document in front of them. Whatever confidence they place in it comes from the accreditation mark and from what the document itself can demonstrate. The further your reports travel, the more the second part matters.

The same logic applies to how your data are held. A laboratory whose records can only be interpreted by someone sitting at a particular workstation has a local record. A laboratory whose records can be verified by anyone holding them has something that works at the distance its reports actually travel.

Where to start

You do not need a project for this, and you certainly do not need a new information management system. You need to know where your own chain is thin.

Take a report you issued a year ago, ideally a complex one, and try to walk it backwards to the acquisition without asking the analyst who produced it. Every point where you have to rely on someone remembering, on a file whose history cannot be established, or on an application that will not exist in five years, is a point where a determined challenge would find something to work with.

Then look at what leaves your laboratory. If a customer, a lawyer or an assessor shows you a document with your letterhead on it, how quickly can you establish whether it is the one you issued? If the answer involves opening an archive and comparing by eye, that is a gap worth closing, and it is one of the cheapest to close.

If you want to look at this against your own workflow rather than in the abstract, get in touch. The useful conversation is not about the standard, which you already know better than any supplier does. It is about the specific stretch between your instruments and your reports, and what it would take to make that stretch as defensible as everything around it.

FAQ: ISO/IEC 17025

What is ISO/IEC 17025?
It is the international standard specifying the requirements for the competence, impartiality and consistent operation of testing and calibration laboratories. Accreditation bodies use it to assess and accredit laboratories, and the current edition is the 2017 one.
Has ISO/IEC 17025 been revised?
No. The edition in force is the 2017 one. The confusion usually comes from other standards in the same family: ISO/IEC 17020 for inspection bodies was reissued in 2026 and inspection bodies do have a transition to manage. Laboratories do not. No published source announces a new edition of ISO/IEC 17025.
What is the difference between ISO 9001 and ISO 17025?
ISO 9001 sets requirements for a quality management system in any organisation, and certification against it says nothing about the technical validity of the results that organisation produces. ISO/IEC 17025 covers both the management system and technical competence: methods, metrological traceability, measurement uncertainty, the qualification of personnel and equipment. A laboratory is accredited against ISO/IEC 17025 by an accreditation body, which is a different exercise from being certified against ISO 9001 by a certification body.
What are the requirements for an ISO 17025 testing laboratory?
The standard requires demonstrated competence of personnel and equipment, impartiality and confidentiality, metrological traceability of measurement results, validated or verified methods with evaluated measurement uncertainty, monitoring of the validity of results including proficiency testing, control of technical records and reports, and management of the information and computer systems the laboratory uses. Accreditation is granted for a defined scope, so the requirements always apply to specific tests, methods and ranges rather than to the laboratory in general.
What does calibration mean under ISO 17025?
Calibration is the operation that establishes the relationship between what an instrument indicates and the corresponding values of a reference, with the associated measurement uncertainty. Under ISO/IEC 17025 a calibration laboratory has to demonstrate metrological traceability, which means the reference used is itself linked through an unbroken chain of calibrations to a stated reference, each with a documented uncertainty. This is why calibration certificates issued by accredited laboratories carry weight that a manufacturer's own declaration does not.
What does the standard require about the management of information?
The 2017 edition includes requirements covering laboratory information systems and the handling of data: protection of records against loss and unauthorised access, authorisation and control of changes, and safeguarding of the information the laboratory holds. In practice you have to be able to show that data in your systems are what you put there, that any change was made deliberately by someone entitled to make it, and that a record can be produced later in the state it was in when it was created.
Are accredited test reports recognised in other countries?
Largely, yes. Accreditation bodies that pass peer evaluation sign the ILAC mutual recognition arrangement, under which signatories accept each other's accredited results. The purpose is to remove the need for repeated testing when goods cross borders, which is why exporters ask their laboratories for accredited reports rather than ordinary ones.
Does TrueScreen make a laboratory ISO 17025 compliant, or accredit it?
No. Compliance is the laboratory's responsibility and accreditation is granted only by an accreditation body after assessing technical competence. TrueScreen strengthens and simplifies the fulfilment of specific requirements: the management of information, the integrity of technical records, and the ability to demonstrate that what appears in a report corresponds to what was actually observed. It is a support to the evidence you have to produce, not a shortcut to the assessment.

Make your laboratory data defensible

See what certified capture changes in your workflow: a demonstration on your own testing scenarios, with your own data.

mockup app