ISO/IEC 17020:2026: what changes for inspection evidence

A disputed inspection outcome and a finding raised during an accreditation assessment look like different problems. They are the same problem wearing different clothes. Both end with someone asking you to show, months or years after the visit, exactly what your inspector saw on site and why nobody could have altered it since. ISO/IEC 17020 sets the requirements for bodies that perform inspections: their independence, their competence, and the way they carry out and record inspection work. Accreditation bodies use it to assess inspection bodies worldwide.

With the 2026 edition, the quality of those records stops being a matter of internal good practice and becomes something the standard asks about directly. The requirements on the control of data and information have been strengthened, and they now sit alongside an explicit expectation that the body has thought about the risks attached to its data.

Here is the uncomfortable part. In most inspection bodies, the weakest data in the entire management system is the photograph taken on the inspector's phone. It gets sent through a messaging app, saved to a shared folder, renamed, compressed, and pasted into a report. By the time anyone questions it, there is no way to prove when it was taken, where, by whom, or whether the file in the report is the file that came off the camera. Everything else in the system is controlled. That is not.

Closing that gap does not mean rewriting your procedures. It means changing the moment at which the evidence becomes protected: at the point of capture, rather than at the point of filing.

The ISO/IEC 17020 transition and the dates that matter

ISO/IEC 17020:2026 was published on 27 March 2026 and replaces the 2012 edition. Inspection body accreditation granted against the 2012 edition stops being recognised on 27 March 2029, at the close of the transition period agreed through ILAC. National accreditation bodies are setting their own intermediate deadlines inside that window, and those local dates are the ones that will actually bite.

Date What happens Source
27 March 2026 ISO/IEC 17020:2026 is published and supersedes the 2012 edition ISO
30 April 2026 National adoption of the European version begins to appear, for example UNI CEI EN ISO/IEC 17020:2026 UNI
From September 2026 Assessments against the new edition become available at national level, in the UKAS example UKAS
From January 2028 Assessments against the new edition become mandatory, in the UKAS example UKAS
27 March 2029 Accreditations against the 2012 edition stop being recognised under the ILAC arrangement UKAS

Read that table backwards and the picture changes. The 2029 date is the one that gets quoted in newsletters, but it is not your deadline. Your deadline is the first surveillance or reassessment visit where your accreditation body expects to see ISO/IEC 17020:2026 applied, and for bodies working with a national scheme like the UKAS one, that visit falls in 2027 at the latest. Whatever you intend to change about the way your inspectors collect evidence needs to be running, and producing records, before an assessor turns up to look at it.

There is a second reason not to wait. Anything you change about evidence collection has to survive contact with real inspectors on real sites, in the rain, on a roof, with a client waiting. That takes a season to settle, not a weekend.

What changed in ISO/IEC 17020:2026 against the 2012 edition

ISO/IEC 17020:2026 keeps the structure of the old one recognisable but shifts its centre of gravity. It asks for less box-ticking and more demonstrated judgement: fewer prescriptive requirements, more performance criteria, a stronger expectation that the body has identified its own risks, and closer alignment with the common elements shared across the ISO/CASCO conformity assessment standards. The national standards bodies publishing the adopted version have summarised the same set of changes, as UNI did for the European version.

Independence is now type A or type non-A

The old independence classification has been simplified. Inspection bodies are now either type A, meaning independent of the parties involved, or type non-A, covering everything else. If you were a type B or type C body, the reclassification is not cosmetic: it changes how you describe yourself to clients, what your scope document says, and which safeguards you have to be able to point at.

Impartiality is treated separately from independence

This is the change that catches people out. Independence describes your structural position relative to the parties. Impartiality describes whether the inspection result was actually formed and reported free from influence. A body can be structurally independent and still produce a result that was influenced after the fact, which is precisely what a hostile lawyer will suggest. Separating impartiality from independence means you now need evidence for each, and the evidence for impartiality is largely evidence about what happened to your data after the inspector left the site.

Risk-based thinking runs through the requirements

Rather than prescribing controls, ISO/IEC 17020 asks the body to identify risks and opportunities and to act on them proportionately. For an inspection body, the interesting risk is rarely the one in the template. It is the risk that an inspection result cannot be defended because the underlying evidence cannot be authenticated. That risk belongs in your register, with a treatment attached to it.

Data management, technology and method validation have been revisited

The requirements covering how data is managed, how technology is used in inspection work, and how inspection methods are validated have all been revised. This matters more than it sounds. Inspection bodies have quietly digitised over the past decade: tablets, apps, drones, remote video, cloud storage. Very little of that arrived with a validation file attached. ISO/IEC 17020:2026 assumes you can explain and justify the technology you rely on, and Accredia, the Italian accreditation body, singles out the same revision in its note on the new editions.

New definitions and new process requirements

ISO/IEC 17020:2026 introduces revised definitions and adds operational process requirements, including the review of requests, tenders and contracts, which the same Accredia note records alongside the separation of impartiality from independence. Contract review is worth a second look, because that is where you agree what evidence the client will receive and what it will be capable of proving.

Control of data and information: the requirement that reaches the field

Control of data and information means the inspection body can demonstrate that the data it relies on is what it claims to be: correctly attributed to a person, a place and a moment, unchanged since it was produced, protected against loss or tampering, and retrievable when somebody asks for it. Applied to field evidence, that covers the photograph, the video clip, the instrument reading and the note written on site, from the second they come into existence to the day they are read again in a dispute. ISO/IEC 17020:2026 strengthens these requirements and connects them to the body's assessment of risks and opportunities. That connection is the operative part. It is no longer enough to store records carefully. You are expected to have asked what could go wrong with your data, and to have done something about the answer.

Most quality managers read that requirement and think about their document management system, their backups, their access permissions, their retention schedule. All of that is usually in reasonable shape. The system stops at the office door.

Think about what actually happens on a site visit. The inspector photographs a weld, a label, a guardrail, a meter reading. The image sits in the camera roll among personal photos. It travels through a messaging app that strips the location data and recompresses the file. It lands in a folder named after the client, gets renamed to something meaningful, and is pasted into a report a few days later. Nobody did anything wrong. But at the end of that journey, the file has no reliable connection to the moment it was created. The capture time can be edited on most devices in a few seconds. The location may have been discarded. The chain between the scene and the report is a chain of good faith.

That is not a controlled datum. It is an uncontrolled datum inside a controlled system, and the control ends exactly where the evidential value begins. The same problem appears wherever an inspector's own device is the primary instrument of record, which is why digital evidence in workplace safety inspections has become such a recurring argument in safety disputes.

The risk framing makes this easier to handle internally. You do not have to argue that photographs are dangerous. You have to record a risk that already exists, in the terms your management system already uses: there is a credible possibility that a photographic record supporting an inspection result cannot be authenticated if challenged, with consequences for the client, for the body's liability and for its accreditation. Then you treat it. Treating it means moving the point of control forward, to the moment of capture.

If you want to see what that looks like before committing to it, ask us to walk your inspectors through a live capture on one of your own sites.

What ISO/IEC 17020 asks of records and inspection reports

Records have to show how the inspection was actually carried out, not only what it concluded. That means traceability back to the inspector, the equipment, the date and the location; completeness, so that the reasoning behind the result can be reconstructed; and retention in a form that stays readable and unaltered for as long as the body has committed to keep it.

The inspection report is the visible product. The record is what defends it. Clients read reports; assessors, lawyers and courts read records. When an inspection result is attacked, nobody argues with the conclusion in the abstract. They go looking for the gap between the conclusion and the material behind it.

A useful test: pick a report your body issued eighteen months ago and try to reconstruct, from the records alone, the sequence of the visit. Who was on site. What was inspected first. Which photograph corresponds to which finding. Whether the image in the report is identical to the image captured. Most bodies get through the early questions comfortably and stall on the last one. That last question decides how much the earlier answers are worth.

This is territory that court-appointed technical experts have had to formalise long before inspection bodies did, and the discipline they apply to chain of custody in property expert work transfers almost directly to inspection records.

Where the evidence chain breaks

The chain rarely breaks during the inspection. It breaks afterwards, in situations where somebody who was not present is asked to trust what somebody who was present recorded. The pressure comes from different directions, and each one exposes a different weakness.

When the outcome is challenged

A client refuses the finding. An insurer disputes a claim. A contractor rejects a defect and threatens to sue. Now your photograph becomes an exhibit, and the opposing side does not need to prove it is false. They only need to establish that its authenticity cannot be verified, which shifts the argument away from the technical merits of the inspection and onto the credibility of the inspector. That is a fight you lose slowly even when you are right, because it costs time, legal fees and reputation regardless of the outcome. Field-based claims handling has already run into this wall, which is why certified evidence in insurance field inspections has moved from a nice-to-have to an operating requirement in several markets.

When the assessor asks how you know

Surveillance assessments under ISO/IEC 17020:2026 will probe the control of data and information more deliberately than before. The question is not whether you have a procedure. It is whether you can demonstrate it worked on a specific job. An assessor picks a file, looks at an image and asks how the body knows that image was captured during that visit and has not changed since. "Our inspectors are trained and trustworthy" is a statement about people, not a control over data. The finding that follows is usually classified as a weakness in the control of records, and it is awkward precisely because it is unanswerable with the evidence you currently hold.

When the inspector is not on site

Remote and hybrid inspection has stopped being an emergency arrangement and become part of the offer. It also removes the single strongest assurance in the traditional model: the physical presence of an accredited professional. When the images arrive from a camera you do not control, held by a person you did not train, the question of what was captured, where, and when becomes the entire question. Bodies operating across dispersed assets have felt this first, and the reasoning behind digital provenance in energy sector field inspections applies to any remote scope. The attention ISO/IEC 17020:2026 pays to the use of technology in inspection work lands squarely on this practice.

What defensible field evidence actually looks like

Defensible field evidence has properties that somebody who was not there, and has no reason to trust you, can check independently. The origin is fixed at capture: the moment, the position and the device are bound to the content as it is produced, rather than asserted later from a file property that anyone can edit. Integrity is verifiable, so any subsequent alteration shows up and the absence of alteration can be demonstrated instead of assumed. An identified person stands behind it. And it has to survive time, because the dispute rarely arrives while the job is still open: the material must still be readable and checkable years later, whatever happened to the folder it was originally saved in. Evidence like that changes the shape of an argument. The other side has to take issue with the finding rather than with the record.

That is the criterion. The tool comes second, and only because the criterion is hard to meet with a standard camera roll.

TrueScreen is the Data Authenticity Platform that inspection bodies use to make field evidence meet that standard. The sequence is what matters. Evidence is acquired with a forensic methodology that protects the data at source, so the content, the moment and the position are bound together as the capture happens rather than reconstructed later. Integrity and authenticity are then verified. The verified result receives a digital seal and timestamp with legal value recognised internationally, within the European framework established by eIDAS. What follows is retention in a form that can be produced and checked long after the visit.

For inspectors, this happens inside the field capture app on the device they already carry, with no additional step at the end of the day. The material is then available from the platform for report preparation and review, and can be held in a certified data room for the retention period the body has committed to. Bodies running their own inspection management software can connect the capture and certification steps directly through the platform API so that inspectors keep working in one system.

To be explicit about the boundary: TrueScreen does not make an inspection body compliant with ISO/IEC 17020, does not issue accreditation, and does not assess conformity to the standard. What it does is strengthen and simplify the fulfilment of specific requirements: the control of data and information, the integrity and traceability of records, and the ability to demonstrate that an inspection result was not altered after it was formed. Accreditation remains a matter between the body and its accreditation body.

A concrete case makes the difference visible. On a construction progress inspection tied to a payment milestone, the dispute never arrives on the day of the visit. It arrives seven months later, when the contractor argues that the works were further advanced than the report says and the client has already withheld payment. If the images were captured with certain date, time and position, and their integrity can be demonstrated, the argument ends in a meeting room. If they were not, it ends with an appointed expert being asked to reconstruct a site that no longer exists in that state. This is the reasoning behind certified construction progress inspection, and it transfers to any inspection whose result carries a financial consequence.

Mapping the requirement to what you have to show

Requirement of ISO/IEC 17020:2026 What you need to demonstrate How TrueScreen helps
Control of data and information That the data collected is intact, attributable and protected along its whole path Acquisition that protects the datum at the moment it is created, with certain date and time, position and context captured together with the content
Inspection records Traceable and complete evidence showing how the inspection was carried out Automatic documentation of the chain of custody, without manual steps left to the inspector
Inspection reports An outcome that a third party can verify A structured record that travels with the evidence and allows it to be checked long after the visit
Impartiality That the result was neither influenced nor altered after collection A digital seal and timestamp with legal value recognised internationally: any later modification becomes detectable
Remote inspection The authenticity of what was collected at a distance Certified acquisition in a protected environment, verifiable at a later date
Risks and opportunities relating to data That the risk of challenge has been assessed and treated Evidence that holds up against third parties, moving the dispute from what people say to what can be proved
TrueScreen field capture app

Feature

Certified capture from the field

TrueScreen lets inspectors capture photos and video that stay verifiable, on the device they already carry.

Discover more →

A realistic transition plan for the next few months

The transition is a management project with a fixed end date, not a documentation exercise. Treat it the way you would treat a scope extension: gap analysis, then procedures, then people, then a period of running the new way of working on real jobs before anyone assesses you on it. Work backwards from your next assessment date rather than forwards from today.

Start with a gap analysis, and buy the standard

Obvious, and routinely skipped. Somebody in your body needs to read the published 2026 edition in full, against your current manual, requirement by requirement, and produce a written difference list. Do not run this from summaries, including this one. Summaries are useful for orientation and dangerous for compliance, because the wording that an assessor will read to you is the wording in the standard. Where the requirement has moved from prescription to performance, note it explicitly: those are the places where your existing procedure may still be compliant in substance while failing to show the judgement the new edition expects.

The output is not a report. It is a list with an owner and a date against each line.

Settle your type before anything else

If you were a type B or type C body, decide and document where you now sit under the type A and type non-A classification, then check every downstream document that referred to the old category: scope statements, client-facing descriptions, tender responses, the impartiality analysis, the safeguards you rely on. This is administrative work, but it blocks other things. Your impartiality risk analysis cannot be updated sensibly until the classification is settled.

Re-read the evidence procedures, not just the quality manual

Most bodies will handle this transition by editing the manual. The manual is the easy part. The procedures that need real attention are the ones describing how an inspector collects, transfers, stores and retrieves evidence, and in many bodies those procedures are thin, informal or simply absent because the practice grew organically around whatever devices people had.

Write down what actually happens today, not what the procedure says. Follow one job end to end: which device captured the image, which application it passed through, where the file rested, who could have opened or replaced it, how it was matched to the finding, where it lives now, and who can retrieve it in five years. Do this with an inspector present, because the written procedure and the real practice will diverge and the divergence is the finding waiting to happen.

Decide what "controlled" means for each type of data you handle

Photographic and video evidence, instrument readings, handwritten site notes, third-party documents received from the client, remote capture from a camera you do not own: these carry different risks and do not deserve the same treatment. Set a level of control for each, proportionate to the consequences of a challenge. An inspection whose result triggers a payment, a certificate, a sanction or a safety decision needs stronger controls than one that feeds an internal report.

This is also where the new edition's attention to the use of technology becomes practical. If you are using an application to capture evidence, you should be able to say what it does, why you chose it, and what happens to the data inside it. That justification is part of the record now.

Update the risk assessment, and connect it to contract review

Add the authentication risk to the register in the language your system already uses, with a likelihood, a consequence and a treatment. Then take the same reasoning into contract review, which ISO/IEC 17020:2026 brings forward as a process requirement. When you agree a scope with a client, you are also agreeing what the resulting evidence will be capable of proving. Clients in litigious sectors are starting to ask that question directly, and a body that has an answer prepared negotiates from a better position than one that improvises.

Train inspectors on the act of capture

Inspector training for this transition should not be a session about the standard. Inspectors do not need to know which requirement changed. They need to know what to do differently on site, and they need the change to cost them no extra time, because anything that adds minutes to a visit gets abandoned within a month.

Keep it practical: capture the evidence inside the certified flow rather than the camera roll, capture the context before the detail, record the identifying elements that let somebody else locate the subject later, and stop treating the phone gallery as a working archive. Then confirm through observation, not through a signed attendance sheet. Send a senior inspector on a normal visit with a junior one and watch what actually gets photographed.

Run a field trial on live jobs before you commit

Pick a scope, pick a small group of inspectors, and run the new evidence process on real inspections for a defined period. Not a pilot on a mock site: real clients, real time pressure, real weather. You are looking for the points where the process breaks down under pressure, because those are the points where inspectors will quietly revert to the old habit.

Measure the boring things. Did capture time per inspection increase, and by how much. Did the report writer receive everything needed. Did anything fail to upload from a location with no signal. Did any inspector find a workaround, and why. Fix those before scaling, because the second attempt at rolling out a process is always harder than the first.

Rehearse the challenge before somebody else stages it

Before the assessment, run the interrogation on yourself. Take a completed job from the trial and have someone in the role of an opposing expert attack it. How do you know this photograph was taken on that date. How do you know it was taken at that address. How do you know the file in the report is the file that came off the device. Who had access between capture and report, and what would it have taken to substitute the image.

If your answers rest on the inspector's word or on internal procedure alone, you have found the gap while it is still cheap to fix. Do the same exercise from the assessor's side, with a specific job file open in front of you. Each rehearsal exposes a different weakness, and either one is more useful than another revision of the manual.

Sequence the work against your assessment calendar

Anchor everything to the date your accreditation body will look at the new edition, using the national calendar that applies to you. In the UKAS example, assessments against the 2026 edition open from September 2026 and become mandatory from January 2028, as set out in the transition bulletin. Working back from your own date, the gap analysis and the type classification belong at the front, the procedure rewrite and the technology decision in the middle, and the field trial needs to close early enough to leave a run of completed jobs that were performed under the new process. An assessor who sees the new procedure and no records produced under it will ask the obvious question.

Turning defensible evidence into a commercial argument

Everything above is a cost until you sell it, and it can be sold. Inspection is a mature market where technical competence is assumed and price is the usual battleground. Evidential quality is one of the few things a body can offer that a client can feel the value of without understanding the methodology, because the client has probably lost an argument at some point for lack of proof.

The pitch is short. Our inspections come with evidence you can rely on if this goes wrong. Every photograph in the report is bound to its moment and place, and any subsequent alteration is detectable, so if a counterparty disputes the outcome you are arguing about the finding rather than about whether the picture is real.

Sectors where that argument lands hardest are the ones where inspection results carry money: construction milestones and handovers, insurance loss adjustment, asset condition assessment before a transaction, regulatory and safety inspections with sanctions attached, energy and utility assets spread across territory. In those markets the same clients are already asking suppliers to demonstrate the provenance of digital records, so the conversation is often half started before you arrive.

There is also an internal return. Inspectors stop assembling evidence by hand at the end of the day, report writers stop chasing missing images, and the quality function stops discovering months later that a job file is incomplete. The ISO/IEC 17020 transition is the natural moment to make that change, because you are opening the procedures anyway.

Where to start

ISO/IEC 17020:2026 gives inspection bodies a deadline and a reason to look hard at something most of them have known was fragile for years. The requirements on the control of data and information reach further than the document management system: they reach the inspector's hand at the moment the photograph is taken. That is the point where the fix has to go, and it is a smaller change than rewriting a management system.

If you want to see what certified capture does to your existing process before you commit to anything, talk to us and we will run a demonstration on one of your own inspection scenarios, with your inspectors, on your evidence.

FAQ: ISO/IEC 17020:2026

What is ISO/IEC 17020?
ISO/IEC 17020 is the international standard setting requirements for the operation of bodies performing inspection. It covers independence and impartiality, competence, the way inspections are carried out, and the records and reports produced. Accreditation bodies use it worldwide to assess and accredit inspection bodies. The current edition was published on 27 March 2026.
What changed in ISO/IEC 17020:2026?
The 2026 edition simplifies the independence classification into type A and type non-A, treats impartiality separately from independence, strengthens the requirements on the control of data and information, adds process requirements including the review of requests, tenders and contracts, and replaces prescriptive requirements with performance criteria and a risk-based approach, with closer alignment to the common ISO/CASCO elements. National standards bodies publishing the adopted version have summarised the same changes.
When do accreditations against the 2012 edition expire?
Accreditations held against ISO/IEC 17020:2012 stop being recognised on 27 March 2029, at the end of the transition period agreed through ILAC. National accreditation bodies apply earlier internal deadlines: in the UKAS example, assessments against the new edition are available from September 2026 and become mandatory from January 2028, according to the UKAS transition bulletin.
What is the difference between ISO 17020 and ISO 17025?
ISO/IEC 17020 applies to inspection bodies, which examine products, installations, processes or services and determine their conformity against requirements, often through professional judgement on site. ISO/IEC 17025 applies to testing and calibration laboratories, which perform measurements under controlled conditions. ISO/IEC 17021 sits alongside them and covers bodies auditing and certifying management systems. A single organisation can hold accreditation under more than one of them for different activities.
What does control of data and information mean for field evidence?
It means the body can demonstrate that the data behind an inspection result is attributable, unchanged since capture, protected from loss or tampering, and retrievable on request. For evidence collected on site, that covers photographs, video, instrument readings and site notes from the moment of capture to the moment they are produced in a dispute, which is where an uncontrolled camera roll becomes a problem.
Can certified capture be used for remote and hybrid inspections?
Yes, and remote inspection is where it matters most, because the assurance normally provided by the inspector's physical presence is absent. Certified acquisition binds the content to the moment and the position at the time of capture, so material collected at a distance can be verified later by someone who was not present.
Does TrueScreen certify or accredit inspection bodies to ISO 17020?
No. TrueScreen does not accredit, does not certify conformity to ISO/IEC 17020, and does not make an inspection body compliant with the standard. Accreditation is granted only by an accreditation body. What TrueScreen provides is a way to strengthen and simplify the fulfilment of specific requirements: the control of data and information, the integrity and traceability of records, and the demonstrable authenticity of evidence collected in the field.

Make your inspection evidence defensible

See what certified capture does to your existing process: a demonstration on your own inspection scenarios, with your inspectors, on your evidence.

mockup app