Navigating 21 CFR Part 11 with LabWare
Discover how LabWare simplifies 21 CFR Part 11 compliance with built-in controls for data integrity, validation, and secure record management.
11 min read
LabWare Published

ISO/IEC 17025 (often shortened to ISO 17025) is the international standard for the competence, impartiality, and consistent operation of testing and calibration laboratories. Most articles on LIMS and accreditation stay general. This one is specific. The 2017 edition of the standard names laboratory information management systems directly and sets requirements for how they are validated, protected, and controlled.
This article covers what accreditation demonstrates and what clause 7.11 requires of a LIMS. It maps the standard’s main requirements to the records a LIMS can hold, and it shows what an assessor may actually trace through your system. One point is worth stating clearly up front: a LIMS supports accreditation evidence, but it does not confer accreditation. Competence is demonstrated by the laboratory, its people, and its methods.
ISO/IEC 17025 is published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC); the “ISO/IEC” prefix identifies those two bodies. The current edition, ISO/IEC 17025:2017, applies to any organization performing testing, calibration, or associated sampling, regardless of size.
The 2017 edition is organized into five requirement areas:
A LIMS touches nearly every part of clauses 6 and 7, and several parts of clauses 4 and 8.
Accreditation demonstrates that an independent accreditation body has assessed the laboratory as competent to perform specific testing or calibration activities. The laboratory’s scope of accreditation lists those activities. It should not be presented as recognition of everything the laboratory does.
Assessors examine both technical competence and the management system. Evidence typically includes:
The IAS accreditation overview describes these areas and the assessment process.
Many accreditation bodies are signatories to the ILAC Mutual Recognition Arrangement. Under this arrangement, signatory bodies in other countries recognize accreditation granted in one country. This is a major reason accredited results have value in international trade.
ISO 9001 certification evaluates a quality management system. It does not, by itself, recognize technical competence for specific laboratory methods.
The two standards do interact. Clause 8.1 of ISO/IEC 17025 gives laboratories two options for meeting the management system requirements:
Either way, the technical requirements in clauses 6 and 7 still apply in full.
Clause 7.11, “Control of data and information management,” is the part of the standard most directly relevant to laboratory software. It applies to computerized and non-computerized systems alike. Its main requirements, paraphrased, are summarized below. Consult the standard itself for the exact wording.
The laboratory must validate the functionality of its LIMS, including proper interface operation, before introducing it. The laboratory must authorize, document, and validate changes before implementation. This includes changes to the software’s configuration and modifications to commercial off-the-shelf software.
A note to this clause states that commercial off-the-shelf software in general use within its designed application range can be considered sufficiently validated. In practice, this means validation effort belongs where the risk is: your configured workflows, calculations, specifications, interfaces, permissions, and report templates. Revalidating the vendor’s core product is not where the effort should go.
The LIMS must meet several requirements:
The clause also requires laboratories to record system failures, along with the immediate and corrective actions taken. This requirement is easy to overlook. Your incident and downtime records are part of your evidence.
When a LIMS is managed and maintained off-site or through an external provider, the laboratory must ensure that the provider complies with the applicable requirements. This connects to clause 6.6 on externally provided products and services, which requires laboratories to define, evaluate, and monitor such providers.
Instructions, manuals, and reference data relevant to the LIMS must be readily available to personnel.
Calculations and data transfers must be checked in an appropriate and systematic manner. This applies to initial validation, and it is also an ongoing control. Instrument interfaces, result calculations, and exports to reports or external systems should all be covered.
The table below shows where a configured LIMS commonly supports evidence for specific clauses. The right configuration depends on your scope, methods, and documented procedures.
| Clause | Requirement area | How a LIMS can support it |
|---|---|---|
| 4.2 | Confidentiality | Role-based access controls; restricted visibility of customer data |
| 6.2 | Personnel competence and authorization | Training and analyst certification records; blocking unauthorized users from entering or approving results for specific methods |
| 6.4 | Equipment | Calibration and maintenance records; calibration status checks; preventing use of out-of-calibration instruments |
| 6.5 | Metrological traceability | Links to calibration certificates and reference standards used for each result |
| 7.4 | Handling of test or calibration items | Unique sample identification; chain of custody; receipt condition; storage and disposal records |
| 7.5 | Technical records | Original observations, raw data, calculations, and the identity of the analyst and reviewer, all linked to each result |
| 7.6 | Measurement uncertainty | Storing and reporting uncertainty values with results |
| 7.7 | Ensuring the validity of results | QC samples, control charts, trend analysis, and proficiency testing records |
| 7.8 | Reporting | Controlled report templates with required contents; decision rules for statements of conformity; review and authorization workflows |
| 7.9 / 7.10 | Complaints and nonconforming work | Logging, investigation, and linkage to affected samples and results |
| 7.11 | Data and information management | Access control, audit trails, validated configuration, and change control |
| 8.3 / 8.4 | Control of documents and records | Version-controlled procedures and specifications; retention and retrieval of records; retraining triggered by document changes (with an integrated eQMS) |
| 8.5 / 8.7 | Risks and opportunities; corrective action | Structured investigations and corrective actions linked to affected results; workflow controls that block reporting while an investigation is open |
| 8.9 | Management review | Trends in corrective action aging, recurrence, and QC performance as measurable review inputs |
ISO/IEC 17025 requires each test or calibration item to be uniquely identified throughout its time in the laboratory. Technical records must also capture enough information to identify the factors that affect a result and to allow the activity to be repeated under conditions as close to the original as possible.
A LIMS can link the following to a single sample record:
LabWare LIMS supports sample lifecycle management, instrument interfacing, and result reporting. These capabilities help laboratories retrieve this history from one connected record. The alternative is reconstructing it from logbooks, spreadsheets, and instrument files.
A note on terminology: in ISO/IEC 17025, “traceability” usually means metrological traceability. That is the link from a measurement result to SI units through an unbroken chain of calibrations, covered in clause 6.5. Sample history is better described as identification and chain of custody.
The standard requires laboratories to keep procedures and records covering competence requirements, training, supervision, authorization, and ongoing competence monitoring. It also requires laboratories to authorize personnel for specific activities, such as:
LabWare supports method-specific analyst certification records, together with restrictions on who can enter or review results. Its electronic signature capabilities support configured approval workflows.
Software permissions enforce an authorization decision, but they do not demonstrate competence. The competence evidence lives in your training records, assessments, and supervision.
ISO/IEC 17025 does not use the term “audit trail.” It requires that amendments to technical records be traceable to previous versions or original observations. Both the original and the amended data must be retained, along with:
LabWare’s data integrity controls record user identity, timestamps, and before-and-after values for data changes. They also capture reasons for modification. Recording reasons goes beyond what 17025 explicitly requires, but it is good practice and expected under regimes such as GLP. Laboratories should verify which records their configured audit trail covers, and define how audit histories are reviewed, retained, and retrieved.
Equipment records must cover several points:
Laboratories must also monitor the validity of their results. Typical tools include:
A LIMS that links instrument status and QC results to each analytical run makes this monitoring easier to demonstrate. It also helps prevent reporting results from an instrument that was out of calibration at the time. For more on QC workflows, see Achieving Excellence with LIMS Quality Control.
Clause 7.8 lists required report contents, including unique report identification, method identification, results with units, and identification of the person authorizing the report. When reports include statements of conformity, the laboratory must document and apply the decision rule.
Controlled report templates and review workflows in a LIMS help keep reports complete and consistent. When work does not conform, clause 7.10 requires the laboratory to evaluate its significance and act. Linking the nonconformance to the affected samples and results makes recalls and customer notifications far more manageable.
Clause 8 requires laboratories to control documents (8.3), address risks and opportunities (8.5), take corrective action (8.7), and conduct management review (8.9). In many laboratories, these activities live in separate tools. Investigations happen in email, training records in spreadsheets, and procedures on a shared drive, all disconnected from the results they affect.
An electronic quality management system (eQMS) integrated with the LIMS can link quality events directly to samples, results, instruments, and training records:
See Practical eQMS + LIMS: CAPA, Investigations, Training, and Document Control in One System for a walkthrough of these workflows in LabWare.
Assessors often test a laboratory's system by selecting a reported result and working backward. A typical trail might include these questions:
In a well-configured LIMS, most of these answers live in connected records that you can retrieve in minutes. Running this exercise internally before an assessment is a practical way to find gaps in your configuration or procedures.
Validation should connect each important requirement to an expected outcome and retained evidence. A practical approach follows these steps:
LabWare’s testing and validation services support requirements definition, risk assessment, test script development, execution, and summary documentation. LabWare’s discussion of authorized data changes shows why access controls and change histories matter once a system is live.
Yes. The standard does not restrict where a LIMS is hosted. Under clause 7.11.4, however, the laboratory remains responsible for ensuring that an external provider meets the applicable requirements. In practice, laboratories should evaluate and document several points:
The supplier evaluation process required under clause 6.6 should cover these points.
LabWare’s SaaS LIMS options provide preconfigured analytical workflows that can shorten implementation. The laboratory still needs to confirm that the selected configuration addresses its scope and procedures, and to validate any laboratory-specific configuration.
Where experimental records matter, LabWare’s Electronic Laboratory Notebook integrates with LIMS to support procedure execution and connected observations.
A LIMS cannot:
The laboratory remains responsible for appropriate methods, competent people, suitable equipment, metrological traceability, quality assurance, internal audits, and management review.
A well-configured LIMS makes that work visible, consistent, and retrievable. It can also help identify gaps before an assessor does.
Accreditation is maintained through surveillance and reassessment, so readiness is ongoing. Keep procedures, LIMS configurations, personnel authorizations, and quality activities aligned between assessments. Use the LIMS to run internal trace-back exercises and to monitor QC trends. Track corrective actions through to closure.
LabWare’s guidance on LIMS audit compliance covers recordkeeping and user training as connected operational concerns. For more articles on accreditation and laboratory quality, browse the ISO/IEC 17025 topic on the LabWare blog.
Preparing for ISO/IEC 17025 accreditation or reassessment? Talk to a LabWare specialist about configuring and validating LabWare LIMS for your scope, or read how integrated eQMS + LIMS workflows support corrective action, document control, and training.
No. The standard does not require laboratories to use a LIMS. If a laboratory uses one, clause 7.11 sets requirements, including validation before use, control of changes, protection against unauthorized access and tampering, and recording of system failures. The same principles apply to paper-based systems.
Clause 7.11 covers control of data and information management. It requires laboratories to:
Yes, especially when integrated with an electronic quality management system (eQMS). Integrated workflows can link investigations and corrective actions to the affected samples and results. They can control procedure versions and trigger retraining when a procedure changes. They can also prevent analysts from performing methods until their training is current. These capabilities support clauses 7.10, 8.3, and 8.7, as well as competence monitoring under 6.2. The laboratory remains responsible for the quality of its investigations and the effectiveness of its corrective actions.
The standard does not use the term “audit trail.” It requires that amendments to technical records be traceable to previous versions or original observations, with the original and amended data retained, along with the date of the change, what was changed, and who changed it. An electronic audit trail is a common way to meet this requirement in a LIMS.
Not automatically. 21 CFR Part 11 applies to electronic records under FDA-regulated activities. An ISO/IEC 17025 laboratory needs to meet Part 11 only if it also falls under FDA requirements. Many laboratories serve both regimes and configure their LIMS to satisfy both.
Yes. Under clause 7.11.4, the laboratory must ensure that the external provider complies with the standard’s requirements. This is typically handled through supplier evaluation and agreements covering access, backup, change management, and data retention.
Not entirely. The standard notes that commercial off-the-shelf software used within its designed range can be considered sufficiently validated. Configurations and modifications still require validation, and so do laboratory-specific calculations, interfaces, permissions, and reports. LabWare validation services help plan and document that evaluation.
ISO/IEC 17025 accreditation recognizes technical competence for a defined scope of testing or calibration activities. ISO 9001 certification evaluates a quality management system. A laboratory with an ISO 9001 system can use it to meet 17025’s management system requirements (Option B in clause 8.1), but ISO 9001 certification alone does not demonstrate technical competence.
LabWare records data changes with user identity, timestamps, reasons for modification, and before-and-after values. How useful these histories are depends on the configured coverage, protection, retention, and review procedures that the laboratory has tested and maintains.
Discover how LabWare simplifies 21 CFR Part 11 compliance with built-in controls for data integrity, validation, and secure record management.
Discover how LabWare’s adaptable LIMS solutions have supported OC San for nearly three decades, driving innovation, compliance, and collaboration.
Boost your Efficient QC Laboratory with streamlined processes, LIMS implementation, reliable testing methods, and effective communication.