Test report and acceptance records: proving the provenance of measurement data
A test report states that a material meets declared values. An acceptance record closes out a supply, starts a warranty clock and often releases the last tranche of payment. Both are produced in a laboratory or on a plant floor, and both resurface on somebody's desk months later, when a number is questioned.
The measurement itself is usually sound. The trouble comes from the journey it makes before it becomes a document: the instrument produces a raw reading, the operator exports it, the file lands in a spreadsheet, photographs of the test bench stay on the phone of whoever was there, and weeks later the whole thing is assembled into a signed PDF. By the time somebody objects, the measurement is beyond reproach but its provenance cannot be demonstrated.
So how do you prove that the numbers and images in a test report come from the instrument, the sample and the moment they claim? A test report survives a quality audit and a contractual dispute only if each piece of evidence is certified at the instant it is produced. Digital provenance is built during the test. It is not reconstructed afterwards.
What a test report has to prove
A test report records the results of tests carried out on an identified item, using a stated method, by people who can be named. It has to let a third party retrace the work without asking the author for help. Three settings depend on it: industrial supply, testing laboratory, plant or works.
Test report, acceptance record and acceptance certificate
Three documents attest three different facts, and mixing them up is expensive in supply disputes.
| Test report | Inspection or acceptance record | Acceptance certificate | |
|---|---|---|---|
| What it attests | The result of a test, with method and measurement uncertainty | The outcome of a witnessed check against the agreed specification | Formal acceptance of the delivery, with or without reservations |
| Who issues it | The technical manager of the testing laboratory | The inspector, the test witness or the appointed inspection body | The buyer or the buyer's representative |
| What it covers | An identified sample or specimen | A machine, a system, a batch, a stage of works | The whole supply or works package |
| Standard reference | ISO/IEC 17025, clause 7.8 | FAT and SAT protocols, contract, inspection and test plan | Contract terms and the agreed acceptance criteria |
| Weight in a dispute | Technical evidence, worth as much as its traceability | Establishes what was observed and when | Starts warranty periods and notice deadlines |
Signatures cause a recurring confusion. A digital signature attests who signed a document and that nothing changed afterwards. A qualified timestamp attests that a given content existed in a given form at a given moment. These are different guarantees, and not interchangeable: a report signed three weeks after the test carries the date of the signing, not the date of the reading.
What a usable test report contains
A document survives hostile reading when it lets somebody else mentally repeat the work. The minimum content:
- unique identification of the sample, the equipment or the delivered item;
- the test method applied, its revision and any deviation from it;
- the instrument used, with a reference to its calibration certificate;
- environmental conditions, where they influence the result;
- the actual date and time of the operation;
- who performed the test and who reviewed the results;
- results, measurement uncertainty where applicable, and the raw data behind them;
- authorisation to issue, plus the signatures of the parties present for an acceptance test.
One element is almost always missing, and it is the one most often attacked: proof that the data and the images were not touched between the reading and the drafting. The same gap shows up in the requirements for court-ready digital evidence.
Where measurement data loses its provenance
Provenance is lost in the intermediate steps, not at the moment of measurement. Every hand-off between instrument, operator, spreadsheet and final document breaks the link between a value and its origin, because none of those steps leaves a trace an outsider can check.
The transfer chain from instrument to signed document
A typical cycle involves at least four jumps: the instrument generates the value, the operator exports it, the file is tidied up and merged with photographs, a technician assembles the report and sends it for signature. The spreadsheet is the weakest link, since it can be edited without recording who changed what.
Photographs deserve separate attention. A shot taken on a personal phone carries metadata that looks decisive, but the EXIF metadata of a photograph can be rewritten with free tools, and the edit leaves nothing obvious behind.
Objections in a dispute, findings in an audit
Two pressures arrive from opposite directions and hit the same target. In a dispute the other side rarely attacks the measured value: it attacks the claim that the value belongs to that test, that sample, that date. In an audit the finding appears when the assessor cannot rebuild a result from end to end.
| Objection or finding | Countermeasure |
|---|---|
| "The photograph is not of this item" | Certified capture carrying location and batch reference |
| "Nothing proves when the reading was taken" | Qualified timestamp applied at the moment of capture |
| "The spreadsheet may have been edited" | Hash of the file as exported from the instrument |
| "The value cannot be tied to the stated instrument" | Certified capture of the control system screen |
| "The records do not allow the test to be repeated" | Method, conditions and operator recorded on the spot |
| "The amendment was not tracked" | Original value retained alongside the corrected one |
Non-conformities in ISO/IEC 17025 assessments cluster around record traceability, measurement uncertainty, method suitability and technical review. Findings are written when the assessor cannot trace a result end to end, from the request through method and equipment to raw data, review and the final report. The competence of the laboratory is rarely what is being questioned. What is questioned is whether its work can be reconstructed, which is where data provenance and data lineage stop being an abstraction. When a test report is challenged, the strongest defence is not the signature on the PDF but the ability to trace back to the original reading.
What ISO/IEC 17025 and regulated environments require
The standard and the rules for electronic records ask for the same thing in different words: a record is worth what its origin is worth. ISO/IEC 17025 calls it traceability of technical records. Regulated environments call it data integrity and measure it against ALCOA+.
Technical records and metrological traceability
Clause 7.5.1 is explicit. Technical records shall include the date and the identity of the personnel responsible for each activity and for checking data, and original observations and calculations shall be recorded at the time they are made. Not at the end of the shift. Clause 7.5.2 requires that when a record is amended, both the original and the amended value survive, with the date, the subject of the change and the person responsible. Clauses 7.11.2 and 7.11.3 ask for an information management system validated before use and protected against tampering.
Metrological traceability is defined as the property of a measurement result that relates it to a reference through a documented, unbroken chain of calibrations. Apply the same logic to data rather than to instruments and you get the same requirement: an unbroken chain, documented while it happens.
Electronic records in regulated environments
Where a plant falls under 21 CFR Part 11 or EU GMP Annex 11, expectations are tighter. Records have to be attributable, legible, contemporaneous, original and accurate, then complete, consistent, enduring and available. Audit trails have to be secure, computer generated and time stamped. Teams working to the 21 CFR Part 11 requirements for electronic records already know the uncomfortable part: a scanned signature page says nothing about the record it covers, and a photograph pasted into a qualification report is an orphan unless something ties it to a moment in time.
Where FAT and SAT disputes actually start
The dispute starts in the gap between the factory acceptance test and the site acceptance test. A FAT is a structured, witnessed test at the supplier's premises that verifies conformity to the approved design before shipment. A SAT repeats the check in the installed environment, with real utilities, real interfaces and real product.
Practice is unambiguous about the record: every result is recorded with timestamps, methodology, data and pass or fail outcomes, signed off by the participants. A properly built FAT checklist heads off most arguments before they form, and the sequence is worth naming: FAT, release for shipment, pre-shipment inspection, delivery, installation, commissioning, SAT, final acceptance certificate, warranty start.
The classic argument is the supplier claiming that the FAT sign-off amounts to final acceptance, usually raised after the package fails SAT on an interface problem. Guidance on what each test proves before you release payment is blunt about it: a FAT proves the equipment worked in the supplier's conditions. Settling the argument means going back to what was observed in each session, which in manufacturing means panel screenshots, cycle recordings and exported values that nobody can date. Where attendance itself is contested, proof of a technician's visit is the same problem in a smaller frame.
What does certifying test evidence at source mean?
TrueScreen, the Data Authenticity Platform, captures photos, videos and instrument screens using forensic methodology, fixing the date and integrity at the moment of capture. The difference from common practice is timing. Signing a document downstream proves who signed it and when; it says nothing about whether the value written there is the value the instrument displayed during the test. On the content it collects, the platform applies a qualified timestamp and an electronic seal issued by qualified third-party QTSPs integrated through API, and produces a file with a chain of custody that a third party can verify. TrueScreen is not a QTSP and not a certificate authority: it integrates the seal of qualified providers and guarantees that it is applied at source, where the reading is taken rather than where the report is drafted.
What gets sealed and how
The scope covers photographs and videos of the test, screenshots of control systems and dashboards, technical documents, inspection reports, test results, product and batch identifiers. Each item receives a hash, date, time and location at the moment of capture, in line with eIDAS and with the ISO/IEC 27037 standard for digital evidence on identification, collection, acquisition and preservation.
During the acceptance test of a packaging line, the operator certifies a photograph of the flow meter display, records the sequence on video and captures the control software screen. The report signed three days later refers to the identifiers of those acquisitions. If anything is contested, the buyer verifies the individual items instead of trusting the PDF.
How it fits an existing test process
Adoption does not require rewriting test procedures. Organizations use TrueScreen to attach to the test report evidence with a hash, date and location that a third party can verify, without changing their existing forms. The technician who photographs a display today photographs it through the app; the laboratory exporting instrument data sends it for certification through the API already wired to the quality management system, the ERP or the PLM. The same mechanics carry product defect and claims certification and audit evidence in third-party inspections.
| Aspect | Evidence collected the usual way | Evidence certified at source |
|---|---|---|
| When certification happens | When the report is drafted, days or weeks later | At the instant the evidence is generated |
| Proof of date | The date written in the document, backed by recollection | Qualified timestamp issued by an integrated QTSP |
| Content integrity | Checkable only by comparing copies, if any exist | Hash verifiable on every single file |
| Context metadata | EXIF metadata, editable or stripped when shared | Date, time and location certified with the file |
| Rebuilding for an audit | Searching backwards through folders and personal devices | An ordered, verifiable file per job |
Frequently asked questions
What is a test report?
A test report is the document a laboratory issues to record the results of tests performed on an identified sample. Clause 7.8 of ISO/IEC 17025 sets out what it has to carry: unique identification of the item tested, the method applied with any deviation, the date of the test, the results with their units, measurement uncertainty where relevant, and authorisation to issue. Environmental conditions belong in it whenever they influence the result. Where a statement of conformity is given, the decision rule behind it has to be stated as well.
What is the difference between a test report and an acceptance certificate?
A test report attests a technical result on an identified sample: this specimen, this method, this value, this uncertainty. An acceptance certificate attests a contractual event: the buyer has accepted the supply or the works, with or without reservations. The consequences differ. A test report feeds a technical argument and can be attacked on its traceability. An acceptance certificate starts warranty periods and notice deadlines, and is usually what releases the final payment. An acceptance process typically refers to several test reports, but the two documents are not substitutes for each other.
What does ISO/IEC 17025 require for technical records?
Clause 7.5.1 requires technical records to carry the date and the identity of the personnel responsible for each laboratory activity and for checking data, with original observations and calculations recorded at the time they are made rather than reconstructed later. Clause 7.5.2 requires amendments to be traceable, keeping the original value alongside the amended one, together with the date, what was altered and who altered it. Clauses 7.11.2 and 7.11.3 add that the information management system has to be validated before use and protected against unauthorised access and tampering.
What is the difference between a factory acceptance test and a site acceptance test?
A factory acceptance test is run at the supplier's premises, witnessed by the buyer, to verify that equipment matches the approved design before it ships. A site acceptance test repeats the verification after installation and commissioning, in the real environment, with real utilities, interfaces and product. The two prove different things. A FAT proves behaviour under the supplier's conditions; a SAT proves behaviour where the equipment will actually run. Passing a FAT does not amount to final acceptance unless the contract says so in those words.
Does signing a test report digitally prove when the measurement was taken?
No. A digital signature attests who signed the document and that it has not been altered since. It says nothing about when the underlying measurement happened or which data made it into the report. A report drafted on Friday and signed the following month carries the date of signing. Proving the date of the reading requires a qualified timestamp applied to the evidence at the moment it is produced, together with a hash of the content, so that an independent party can recompute the value and compare.
What should an inspection and test plan cover?
An inspection and test plan sets out, for each stage of a supply or works package, what will be checked, against which specification, by which method, by whom, and what record the check produces. It assigns hold points and witness points, states the acceptance criteria and names the documents each step generates: test reports, inspection records, certificates. The useful version also says how evidence will be captured and retained, which is the part usually left implicit and the part that fails first when somebody challenges a result.
How do you prove that measurement data was not altered after the test?
You need a reference created at the origin. A cryptographic hash of the content and a qualified timestamp, both applied at the moment of capture, let an independent party recompute the value and compare it against the record. Anything created afterwards proves only the state of the file at that later moment. This is why data integrity frameworks insist on contemporaneous recording: ALCOA+ and clause 7.5.1 of ISO/IEC 17025 both ask for the record to be made while the work happens, not assembled at the end of the day.
Why do auditors raise findings on test reports?
Findings usually concern reconstruction rather than competence. An assessor tries to follow one result from the customer request through the method, the equipment and its calibration status, into the raw data, the technical review and the issued report. When any link is missing or ambiguous, a non-conformity is written. The recurring themes are record traceability, measurement uncertainty, method suitability and technical review of results. A laboratory can be technically excellent and still collect findings because its evidence trail depends on people remembering what happened.
