<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=2281761&amp;fmt=gif">
Skip to the main content.

11 min read

ISO/IEC 17025 LIMS Requirements: What Labs Need to Know for Accreditation

ISO/IEC 17025 LIMS Requirements: What Labs Need to Know for Accreditation
25:15

What ISO IEC 17025 Requires of a LIMS

ISO/IEC 17025 (often shortened to ISO 17025) is the international standard for the competence, impartiality, and consistent operation of testing and calibration laboratories. Most articles on LIMS and accreditation stay general. This one is specific. The 2017 edition of the standard names laboratory information management systems directly and sets requirements for how they are validated, protected, and controlled.

This article covers what accreditation demonstrates and what clause 7.11 requires of a LIMS. It maps the standard’s main requirements to the records a LIMS can hold, and it shows what an assessor may actually trace through your system. One point is worth stating clearly up front: a LIMS supports accreditation evidence, but it does not confer accreditation. Competence is demonstrated by the laboratory, its people, and its methods.

Key Takeaways

  • The standard names LIMS directly. Clause 7.11 of ISO/IEC 17025:2017 sets explicit requirements for laboratory information management systems. These include validation before use, control of configuration changes, protection against tampering and loss, and oversight of externally hosted systems.
  • Accreditation is scope-specific. An accreditation body grants it for defined testing or calibration activities. ISO or IEC does not grant it.
  • A LIMS can connect much of the evidence an assessor examines. That includes sample handling, personnel authorization, equipment status, quality control, record amendments, and reporting.
  • Cloud and SaaS LIMS are permitted. The laboratory remains responsible for ensuring that its provider meets the standard’s requirements.
  • Validation focuses on your configuration. Unmodified commercial software may be considered sufficiently validated within its intended range. Your configurations, calculations, and interfaces need their own evaluation.

What Is ISO/IEC 17025?

ISO/IEC 17025 is published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC); the “ISO/IEC” prefix identifies those two bodies. The current edition, ISO/IEC 17025:2017, applies to any organization performing testing, calibration, or associated sampling, regardless of size.

The 2017 edition is organized into five requirement areas:

  • Clause 4, general requirements: impartiality and confidentiality.
  • Clause 5, structural requirements: legal entity, organization, and responsibilities.
  • Clause 6, resource requirements: personnel, facilities, equipment, metrological traceability, and externally provided products and services.
  • Clause 7, process requirements: from contract review through sampling, item handling, technical records, measurement uncertainty, reporting, nonconforming work, and data and information management.
  • Clause 8, management system requirements: document and record control, risk, corrective action, internal audits, and management review.

A LIMS touches nearly every part of clauses 6 and 7, and several parts of clauses 4 and 8.

What Does ISO 17025 Accreditation Demonstrate?

Accreditation demonstrates that an independent accreditation body has assessed the laboratory as competent to perform specific testing or calibration activities. The laboratory’s scope of accreditation lists those activities. It should not be presented as recognition of everything the laboratory does.

Assessors examine both technical competence and the management system. Evidence typically includes:

  • personnel competence and authorization;
  • suitable, calibrated equipment;
  • method verification or validation;
  • metrological traceability;
  • measurement uncertainty;
  • quality assurance of results;
  • controlled reporting.

The IAS accreditation overview describes these areas and the assessment process.

Many accreditation bodies are signatories to the ILAC Mutual Recognition Arrangement. Under this arrangement, signatory bodies in other countries recognize accreditation granted in one country. This is a major reason accredited results have value in international trade.

Accreditation vs. ISO 9001 Certification

ISO 9001 certification evaluates a quality management system. It does not, by itself, recognize technical competence for specific laboratory methods.

The two standards do interact. Clause 8.1 of ISO/IEC 17025 gives laboratories two options for meeting the management system requirements:

  • Option A: meet clauses 8.2 to 8.9 directly.
  • Option B: maintain a management system conforming to ISO 9001 that supports the laboratory’s 17025 requirements.

Either way, the technical requirements in clauses 6 and 7 still apply in full.

What Does ISO 17025 Require of a LIMS? Understanding Clause 7.11

Clause 7.11, “Control of data and information management,” is the part of the standard most directly relevant to laboratory software. It applies to computerized and non-computerized systems alike. Its main requirements, paraphrased, are summarized below. Consult the standard itself for the exact wording.

Validation Before Use (7.11.2)

The laboratory must validate the functionality of its LIMS, including proper interface operation, before introducing it. The laboratory must authorize, document, and validate changes before implementation. This includes changes to the software’s configuration and modifications to commercial off-the-shelf software.

A note to this clause states that commercial off-the-shelf software in general use within its designed application range can be considered sufficiently validated. In practice, this means validation effort belongs where the risk is: your configured workflows, calculations, specifications, interfaces, permissions, and report templates. Revalidating the vendor’s core product is not where the effort should go.

Protection, Integrity, and System Failures (7.11.3)

The LIMS must meet several requirements:

  • it must be protected from unauthorized access;
  • it must be safeguarded against tampering and loss;
  • it must be operated in an environment that meets supplier or laboratory specifications;
  • it must be maintained in a way that ensures data and information integrity.

The clause also requires laboratories to record system failures, along with the immediate and corrective actions taken. This requirement is easy to overlook. Your incident and downtime records are part of your evidence.

Externally Hosted and SaaS Systems (7.11.4)

When a LIMS is managed and maintained off-site or through an external provider, the laboratory must ensure that the provider complies with the applicable requirements. This connects to clause 6.6 on externally provided products and services, which requires laboratories to define, evaluate, and monitor such providers.

Instructions and Reference Data (7.11.5)

Instructions, manuals, and reference data relevant to the LIMS must be readily available to personnel.

Checking Calculations and Data Transfers (7.11.6)

Calculations and data transfers must be checked in an appropriate and systematic manner. This applies to initial validation, and it is also an ongoing control. Instrument interfaces, result calculations, and exports to reports or external systems should all be covered.

Mapping ISO/IEC 17025 Requirements to LIMS Capabilities

The table below shows where a configured LIMS commonly supports evidence for specific clauses. The right configuration depends on your scope, methods, and documented procedures.

Clause Requirement area How a LIMS can support it
4.2 Confidentiality Role-based access controls; restricted visibility of customer data
6.2 Personnel competence and authorization Training and analyst certification records; blocking unauthorized users from entering or approving results for specific methods
6.4 Equipment Calibration and maintenance records; calibration status checks; preventing use of out-of-calibration instruments
6.5 Metrological traceability Links to calibration certificates and reference standards used for each result
7.4 Handling of test or calibration items Unique sample identification; chain of custody; receipt condition; storage and disposal records
7.5 Technical records Original observations, raw data, calculations, and the identity of the analyst and reviewer, all linked to each result
7.6 Measurement uncertainty Storing and reporting uncertainty values with results
7.7 Ensuring the validity of results QC samples, control charts, trend analysis, and proficiency testing records
7.8 Reporting Controlled report templates with required contents; decision rules for statements of conformity; review and authorization workflows
7.9 / 7.10 Complaints and nonconforming work Logging, investigation, and linkage to affected samples and results
7.11 Data and information management Access control, audit trails, validated configuration, and change control
8.3 / 8.4 Control of documents and records Version-controlled procedures and specifications; retention and retrieval of records; retraining triggered by document changes (with an integrated eQMS)
8.5 / 8.7 Risks and opportunities; corrective action Structured investigations and corrective actions linked to affected results; workflow controls that block reporting while an investigation is open
8.9 Management review Trends in corrective action aging, recurrence, and QC performance as measurable review inputs

How a LIMS Supports Key Requirements in Practice

Sample Identification and Chain of Custody (7.4, 7.5.1)

ISO/IEC 17025 requires each test or calibration item to be uniquely identified throughout its time in the laboratory. Technical records must also capture enough information to identify the factors that affect a result and to allow the activity to be repeated under conditions as close to the original as possible.

A LIMS can link the following to a single sample record:

  • sample receipt and the condition of the sample on arrival;
  • storage;
  • the tests performed and the method version used;
  • the analysts involved;
  • instrument data;
  • result review.

LabWare LIMS supports sample lifecycle management, instrument interfacing, and result reporting. These capabilities help laboratories retrieve this history from one connected record. The alternative is reconstructing it from logbooks, spreadsheets, and instrument files.

A note on terminology: in ISO/IEC 17025, “traceability” usually means metrological traceability. That is the link from a measurement result to SI units through an unbroken chain of calibrations, covered in clause 6.5. Sample history is better described as identification and chain of custody.

Personnel Competence and Authorization (6.2)

The standard requires laboratories to keep procedures and records covering competence requirements, training, supervision, authorization, and ongoing competence monitoring. It also requires laboratories to authorize personnel for specific activities, such as:

  • developing or validating methods;
  • analyzing results, including statements of conformity;
  • reviewing and authorizing results.

LabWare supports method-specific analyst certification records, together with restrictions on who can enter or review results. Its electronic signature capabilities support configured approval workflows.

Software permissions enforce an authorization decision, but they do not demonstrate competence. The competence evidence lives in your training records, assessments, and supervision.

Record Amendments and Audit Trails (7.5.2)

ISO/IEC 17025 does not use the term “audit trail.” It requires that amendments to technical records be traceable to previous versions or original observations. Both the original and the amended data must be retained, along with:

  • the date of the change;
  • what was altered;
  • who made the change.

LabWare’s data integrity controls record user identity, timestamps, and before-and-after values for data changes. They also capture reasons for modification. Recording reasons goes beyond what 17025 explicitly requires, but it is good practice and expected under regimes such as GLP. Laboratories should verify which records their configured audit trail covers, and define how audit histories are reviewed, retained, and retrieved.

Equipment, Calibration, and Validity of Results (6.4, 7.7)

Equipment records must cover several points:

  • equipment identity;
  • calibration dates, results, and due dates;
  • maintenance;
  • any damage or malfunction.

Laboratories must also monitor the validity of their results. Typical tools include:

  • reference materials;
  • QC samples;
  • replicate testing;
  • intermediate checks;
  • participation in proficiency testing or interlaboratory comparisons.

A LIMS that links instrument status and QC results to each analytical run makes this monitoring easier to demonstrate. It also helps prevent reporting results from an instrument that was out of calibration at the time. For more on QC workflows, see Achieving Excellence with LIMS Quality Control.

Reporting and Nonconforming Work (7.8, 7.10)

Clause 7.8 lists required report contents, including unique report identification, method identification, results with units, and identification of the person authorizing the report. When reports include statements of conformity, the laboratory must document and apply the decision rule.

Controlled report templates and review workflows in a LIMS help keep reports complete and consistent. When work does not conform, clause 7.10 requires the laboratory to evaluate its significance and act. Linking the nonconformance to the affected samples and results makes recalls and customer notifications far more manageable.

Connecting Quality Events to Laboratory Work (Clause 8)

Clause 8 requires laboratories to control documents (8.3), address risks and opportunities (8.5), take corrective action (8.7), and conduct management review (8.9). In many laboratories, these activities live in separate tools. Investigations happen in email, training records in spreadsheets, and procedures on a shared drive, all disconnected from the results they affect.

An electronic quality management system (eQMS) integrated with the LIMS can link quality events directly to samples, results, instruments, and training records:

  • Nonconforming work and corrective action (7.10, 8.7): an unexpected result can trigger a structured investigation, root cause analysis, and corrective actions with owners and due dates. The record stays linked to the affected results, which makes it easier to evaluate the impact on previously reported work.
  • Document control and competence (8.3, 6.2): when a procedure is revised, retraining can be triggered automatically. Analysts can be blocked from performing the method until their training is current, which supports the requirement to monitor competence.
  • Risk-based controls (8.5): the 2017 edition replaced the earlier standalone “preventive action” clause with actions to address risks and opportunities. Workflow controls are a practical example, such as blocking reporting while an investigation remains open, rather than relying on staff to remember.
  • Management review (8.9): trends in corrective action aging, recurrence, and workflow bottlenecks provide measurable input for management review and show whether corrective actions are working.

See Practical eQMS + LIMS: CAPA, Investigations, Training, and Document Control in One System for a walkthrough of these workflows in LabWare.

What an Assessor May Trace Through Your LIMS

Assessors often test a laboratory's system by selecting a reported result and working backward. A typical trail might include these questions:

  1. Who received the sample, when, and in what condition?
  2. Which method and method version was used?
  3. Was the analyst authorized for that method on that date?
  4. Which instrument was used, and was it within its calibration period?
  5. What were the raw data, and were any values changed? If so, by whom, when, and what were the original values?
  6. Did the QC samples in that batch pass?
  7. Who reviewed and authorized the report?

In a well-configured LIMS, most of these answers live in connected records that you can retrieve in minutes. Running this exercise internally before an assessment is a practical way to find gaps in your configuration or procedures.

Validating Your Configured LIMS

Validation should connect each important requirement to an expected outcome and retained evidence. A practical approach follows these steps:

  1. Define requirements. Base them on your scope, methods, and documented procedures, and reference the clauses they support where useful.
  2. Assess risk. Concentrate testing on configurations that directly affect results or reports, such as calculations, specifications and limits, instrument interfaces, permissions, and report templates.
  3. Write and execute test scripts. Record the actual results and any deviations.
  4. Summarize and approve. Document the outcome before relying on the system for accredited work.
  5. Control changes. Assess, authorize, test, and document configuration changes before implementation, as clause 7.11.2 requires.
  6. Check on an ongoing basis. Systematically verify calculations and data transfers in line with 7.11.6, and record system failures and corrective actions in line with 7.11.3.

LabWare’s testing and validation services support requirements definition, risk assessment, test script development, execution, and summary documentation. LabWare’s discussion of authorized data changes shows why access controls and change histories matter once a system is live.

Can a Cloud or SaaS LIMS Be Used Under ISO 17025?

Yes. The standard does not restrict where a LIMS is hosted. Under clause 7.11.4, however, the laboratory remains responsible for ensuring that an external provider meets the applicable requirements. In practice, laboratories should evaluate and document several points:

  • the provider’s access controls;
  • backup and recovery arrangements;
  • the provider’s change and release management process;
  • incident notification procedures;
  • data retention and retrieval.

The supplier evaluation process required under clause 6.6 should cover these points.

LabWare’s SaaS LIMS options provide preconfigured analytical workflows that can shorten implementation. The laboratory still needs to confirm that the selected configuration addresses its scope and procedures, and to validate any laboratory-specific configuration.

Where experimental records matter, LabWare’s Electronic Laboratory Notebook integrates with LIMS to support procedure execution and connected observations.

What a LIMS Cannot Do

A LIMS cannot:

  • establish personnel competence;
  • validate an analytical method;
  • estimate measurement uncertainty on your behalf;
  • grant accreditation.

The laboratory remains responsible for appropriate methods, competent people, suitable equipment, metrological traceability, quality assurance, internal audits, and management review.

A well-configured LIMS makes that work visible, consistent, and retrievable. It can also help identify gaps before an assessor does.

Building Sustained Readiness

Accreditation is maintained through surveillance and reassessment, so readiness is ongoing. Keep procedures, LIMS configurations, personnel authorizations, and quality activities aligned between assessments. Use the LIMS to run internal trace-back exercises and to monitor QC trends. Track corrective actions through to closure.

LabWare’s guidance on LIMS audit compliance covers recordkeeping and user training as connected operational concerns. For more articles on accreditation and laboratory quality, browse the ISO/IEC 17025 topic on the LabWare blog.

Preparing for ISO/IEC 17025 accreditation or reassessment? Talk to a LabWare specialist about configuring and validating LabWare LIMS for your scope, or read how integrated eQMS + LIMS workflows support corrective action, document control, and training.

FAQs About ISO/IEC 17025 and LIMS

Does ISO/IEC 17025 require a LIMS?

No. The standard does not require laboratories to use a LIMS. If a laboratory uses one, clause 7.11 sets requirements, including validation before use, control of changes, protection against unauthorized access and tampering, and recording of system failures. The same principles apply to paper-based systems.

What does clause 7.11 of ISO/IEC 17025 cover?

Clause 7.11 covers control of data and information management. It requires laboratories to:

  • validate LIMS functionality and interfaces before use;
  • authorize, document, and validate changes;
  • protect systems from unauthorized access, tampering, and loss;
  • record system failures and corrective actions;
  • ensure that external providers comply;
  • keep instructions available;
  • systematically check calculations and data transfers.

Can a LIMS support ISO 17025 corrective action and document control?

Yes, especially when integrated with an electronic quality management system (eQMS). Integrated workflows can link investigations and corrective actions to the affected samples and results. They can control procedure versions and trigger retraining when a procedure changes. They can also prevent analysts from performing methods until their training is current. These capabilities support clauses 7.10, 8.3, and 8.7, as well as competence monitoring under 6.2. The laboratory remains responsible for the quality of its investigations and the effectiveness of its corrective actions.

Does ISO/IEC 17025 require audit trails?

The standard does not use the term “audit trail.” It requires that amendments to technical records be traceable to previous versions or original observations, with the original and amended data retained, along with the date of the change, what was changed, and who changed it. An electronic audit trail is a common way to meet this requirement in a LIMS.

Is 21 CFR Part 11 required for ISO/IEC 17025 laboratories?

Not automatically. 21 CFR Part 11 applies to electronic records under FDA-regulated activities. An ISO/IEC 17025 laboratory needs to meet Part 11 only if it also falls under FDA requirements. Many laboratories serve both regimes and configure their LIMS to satisfy both.

Can a cloud or SaaS LIMS be used for accredited work?

Yes. Under clause 7.11.4, the laboratory must ensure that the external provider complies with the standard’s requirements. This is typically handled through supplier evaluation and agreements covering access, backup, change management, and data retention.

Does a preconfigured LIMS remove the need for validation?

Not entirely. The standard notes that commercial off-the-shelf software used within its designed range can be considered sufficiently validated. Configurations and modifications still require validation, and so do laboratory-specific calculations, interfaces, permissions, and reports. LabWare validation services help plan and document that evaluation.

What is the difference between accreditation and certification?

ISO/IEC 17025 accreditation recognizes technical competence for a defined scope of testing or calibration activities. ISO 9001 certification evaluates a quality management system. A laboratory with an ISO 9001 system can use it to meet 17025’s management system requirements (Option B in clause 8.1), but ISO 9001 certification alone does not demonstrate technical competence.

How does LabWare support audit trail evidence?

LabWare records data changes with user identity, timestamps, reasons for modification, and before-and-after values. How useful these histories are depends on the configured coverage, protection, retention, and review procedures that the laboratory has tested and maintains.

Navigating 21 CFR Part 11 with LabWare

Navigating 21 CFR Part 11 with LabWare

Discover how LabWare simplifies 21 CFR Part 11 compliance with built-in controls for data integrity, validation, and secure record management.

Read More
Orange County Sanitation and LabWare: A 30-Year Partnership in Innovation and Environmental Stewardship

Orange County Sanitation and LabWare: A 30-Year Partnership in Innovation and Environmental Stewardship

Discover how LabWare’s adaptable LIMS solutions have supported OC San for nearly three decades, driving innovation, compliance, and collaboration.

Read More
Efficient Food & Beverage QC Laboratory: Streamlining Processes with LIMS

Efficient Food & Beverage QC Laboratory: Streamlining Processes with LIMS

Boost your Efficient QC Laboratory with streamlined processes, LIMS implementation, reliable testing methods, and effective communication.

Read More