A Complete Guide to ISO/IEC 17025 Document Control for Labs

Quick Summary

ISO/IEC 17025 document control is the structured management of laboratory documents and records, ensuring that only approved, current, identifiable, and retrievable information is used. For calibration and metrology labs, it supports traceability, repeatable methods, competent work, reliable certificates, audit readiness and ongoing accreditation.

Key takeaways:

  • ISO/IEC 17025 document control helps your lab keep approved, current and traceable documents available where work is performed.
  • Clause 8.3 covers management system documents; clause 8.4 covers records, with close links to technical records under 7.5 and data systems under 7.11.
  • Calibration and metrology labs should control SOPs, methods, uncertainty budgets, worksheets, certificates, equipment records and training evidence.
  • Strong control reduces audit findings, supports repeatability and protects accreditation.
  • A document management system like Cognidox can simplify versioning, access, approvals, training sign-off, and audit trails.

What is ISO/IEC 17025 Document Control?

Document control is the process of creating, approving, distributing, revising, retaining and archiving laboratory information in a controlled way. For calibration and metrology labs, ISO/IEC 17025 protects the evidence behind your results: procedures followed, equipment used, environmental conditions, measurement uncertainty, technician competence, and certificate issue history.

ISO/IEC 17025 is the international standard for testing and calibration laboratories, focused on competence, impartiality, and consistent operation.  It is the recognised international reference for laboratories that need to demonstrate they can produce valid results. In the United States, many calibration laboratories also work to ANSI/NCSL Z540.3 for certain customers, particularly in defence and aerospace, alongside their ISO/IEC 17025 accreditation.

Good control helps your lab prove traceability, repeatability, competence, risk-based thinking, and audit readiness. Poor control creates doubts like whether the right method was used, whether the technician was trained, and whether the record is complete.

What does ISO/IEC 17025 require for document control?

The standard treats documents and records as two related but distinct disciplines. Documents tell you how to do the work; records prove what you actually did.

ISO/IEC 17025 clause 8.3 requires labs to control management system documents. In practical terms, your lab should ensure that documents are approved before use, uniquely identified, up to date, available to authorised users, and protected from unintended use once obsolete.

ISO/IEC 17025 clause 8.4 requires records to be controlled. Records must remain legible, identifiable, retrievable, and protected from loss, damage, unauthorised change or inappropriate disposal.

These clauses connect directly to clause 7.5 (technical records), which requires sufficient technical detail to enable laboratory activities to be repeated or evaluated. They also link to clause 7.11 (control of data and information management), which covers the systems used to collect, process, store, or report lab data.

It is worth separating the two senses of the word traceability. Metrological traceability, addressed in clause 6.5, is the documented unbroken chain of calibrations that links a measurement result back to the SI, usually through a national measurement institute such as NIST in the United States or NPL in the United Kingdom. Document control does not create that chain. What it does is preserve the records that evidence it, so the calibration establishes metrological traceability and document control proves it was held at the time the work was done.

Which documents and records fall under control?

Typical controlled documents include:

  • Quality system procedures and policies
  • Standard operating procedures
  • Calibration and test methods
  • Measurement uncertainty budgets
  • Equipment maintenance procedures
  • Forms, worksheets, and templates
  • Training procedures and competence criteria

Typical records include:

  • Calibration and test worksheets
  • Equipment calibration and maintenance records
  • Environmental monitoring records
  • Certificates and reports
  • Training and competence sign-offs
  • Internal audit, corrective action, and management review records

Core elements of a compliant system

Your lab should define and apply these controls:

  1. Identification and status: Use clear titles, IDs, revision numbers, effective dates, and status labels.
  2. Approval and authority: Define who can draft, review, approve, and release each document type.
  3. Change control: Record what changed, why, who approved it, and when it became effective.
  4. Access and distribution: Make current documents available at the point of use; restrict sensitive or obsolete content.
  5. Review and re-approval: Set review intervals based on risk, method stability, and accreditation expectations.
  6. Training sign-off: Confirm affected staff have read, understood and, where needed, demonstrated competence.
  7. Retention and disposal: Define retention periods for certificates, worksheets, equipment records, and quality records.
  8. Audit trails: Preserve who did what, when, and under which version.
  9. Data integrity and backups: Protect electronic records against loss, unauthorised change, and corruption.
  10. Multi-site control: Ensure all locations use the same released version unless local variations are approved.

How should a lab manage the document lifecycle?

A workable lifecycle for any controlled document could be:

  1. Draft: The document owner creates or updates the procedure, method, form, or record template before formal review.
  2. Technical review: A competent technical reviewer checks that the content is accurate, practical, and suitable for the lab activity.
  3. Quality review: Quality checks that the document meets ISO/IEC 17025 requirements, internal formatting rules, and control procedures.
  4. Approval: An authorised person formally confirms the document is ready for controlled release.
  5. Release: The approved version is made available to authorised users and marked as the current controlled version.
  6. Training sign-off: Affected staff confirm they have read and understood the document, and demonstrate competence where required.
  7. Use: Lab personnel apply the current approved version during calibration, testing, reporting, or quality activities.
  8. Change request: A user raises a controlled request to update the document due to a method, equipment, audit, risk, or process change.
  9. Revision: The document is updated, reviewed, and approved as a new version with a clear change history.
  10. Archival: Superseded versions are removed from routine use but retained securely for traceability and audit evidence.

Sample naming convention and change log

An example document naming convention could be:

CAL-SOP-023-R04: Micrometer Calibration Procedure

Where the ID convention breaks down as:

CAL = Function or document family, in this case, calibration.
SOP = Document type, in this case, standard operating procedure.
023 = Unique sequential document number within that category.
R04 = Revision number, meaning this is revision 4.
Micrometer Calibration Procedure = Plain-English document title describing the controlled content.

So the full ID means: ”Calibration-standard operating procedure-number 023-revision 4, titled “Micrometer Calibration Procedure.” 

And an example change log entry could look like:

R04 | 12 Jun 2026 | Updated acceptance criteria and uncertainty reference | Technical Manager | Approved by Quality Manager | Effective 19 Jun 2026

Conventions like this make audit conversations easier. Instead of searching folders and emails, you can show the approved document, change reason, approver, training evidence, and previous revision.

Common audit nonconformities and how to fix them

Common nonconformity audit findings include obsolete procedures in use, missing evidence of approval, uncontrolled spreadsheets, incomplete worksheets, weak traceability of certificates, and staff using methods before training is complete.

They can be fixed by tightening release controls, removing local copies, validating key spreadsheets, locking approved templates, requiring mandatory fields on worksheets, and linking training sign-off to document release.

Another common issue is inconsistent retention. To mitigate this, define retention by record type, accreditation body expectations, customer contracts, and regulatory obligations.

 Nonconformity   Fix 
 Obsolete SOP in use at the bench  Controlled distribution and automatic withdrawal of prior versions
 No evidence of periodic review  Scheduled review dates with recorded outcomes
Staff working from uncontrolled copies A single controlled source with read-and-understand tracking
Records altered without traceability Audit trails that capture who changed what, when, and why

A short audit-readiness checklist

Before an ISO/IEC 17025 assessment, confirm that:

  • Current SOPs and methods are approved and accessible.
  • Every controlled document shows version, status, and approver.
  • Review dates are current, and outcomes are recorded.
  • Obsolete versions are archived and blocked from routine use.
  • Technical records identify personnel, equipment, methods, and conditions.
  • Certificates link back to source data and authorised sign-off.
  • Training sign-off is complete for all affected staff.
  • Training records match current document revisions.
  • Electronic records have backups, access controls, and audit trails.
  • Records are retrievable, legible, and within retention.
  • Data backups and electronic signatures are validated.
  • Multi-site document access is consistent and controlled.

How can a DMS help ISO/IEC 17025 labs?

Manual control with shared drives and spreadsheets rarely survives a rigorous accreditation assessment, whether by UKAS in the United Kingdom or A2LA, NVLAP, or ANAB in the United States; bodies that operate under the ILAC mutual recognition arrangement. 

A purpose-built document management system (DMS) can reduce manual effort by controlling versions, role-based access and permissions, configurable approval workflows, read-and-understand training, reusable templates, audit trails and retention, and integrates with the tools your lab already uses. For metrology lab document management, this is especially useful when methods, equipment records and certificates must remain traceable across teams or sites.

Cognidox is a strong option for compliance-led labs that need configurable workflows, role-based access, controlled templates, electronic approvals, and clear document history without forcing unnecessary process complexity.

By automating these controls, maintaining a single source of truth, and providing review and training evidence on demand, Cognidox helps make accreditation maintenance a steady-state routine rather than a pre-audit scramble.

Conclusion 

ISO/IEC 17025 document control gives your lab confidence that the right people use the right information at the right time. For calibration and metrology labs, that confidence directly supports reliable results, fewer nonconformities, and stronger accreditation evidence.

Ready to strengthen document control, audit trails, and training evidence across your lab? Book a demo of the Cognidox DMS to see how your lab can retire spreadsheets and version chaos for controlled, audit-ready document management built for ISO/IEC 17025 compliance.

New call-to-action

FAQs

1. What is the difference between documents and records in ISO/IEC 17025?

 Documents describe how work should be done, such as methods, SOPs, and policies, and are naturally revised over time. Records capture evidence to prove what was actually done, such as calibration results, completed worksheets, certificates, and training sign-offs, and are not altered without a traceable, authorised correction that preserves the original entry.

2. Are electronic records acceptable under ISO/IEC 17025?

 Yes. Electronic records are acceptable provided the system controlling them is validated, access is restricted, changes are traceable, and data is protected, backed up, and retrievable, in line with Clause 7.11. Your lab should manage access, audit trails, data integrity, and retention for electronic systems. 

3. How often should SOPs be reviewed?

ISO/IEC 17025 does not prescribe one universal review frequency. Many labs set risk-based review cycles, such as annual or two-yearly reviews, with earlier reviews after method changes, audit findings, equipment changes, or customer requirements.

4. How do you demonstrate version control in an audit?

Show that only the current version is in use, that obsolete versions are withdrawn and marked, and that a change log links each revision to its reason, author, and approver. Audit trails should evidence this without manual reconstruction. You should also show that staff were trained on the version in use.

5. How is ISO/IEC 17025 document control different from ISO 9001?

Both share document and record control principles, but ISO 9001 document control is broader and applies to many organisation types, while ISO/IEC 17025 adds laboratory-specific emphasis on technical records, valid results, competence, data systems, and traceability that ISO 9001 does not address.

Tags: Document Management and Control

Alexander Thomson

Written by Alexander Thomson

Alexander Thomson is CEO of Cognidox, a document control and quality management platform used by medical device, biotech and pharmaceutical organisations worldwide to stay audit-ready as they scale. His team works closely with quality and regulatory functions to replace manual and fragmented processes with controlled, compliant systems that support faster product development. He writes about eQMS, ISO 13485, FDA 21 CFR Part 11 and practical approaches to maintaining compliance without slowing innovation. See how Cognidox helps regulated teams stay audit-ready.

Related Posts

Controlling management system documents: an ISO/IEC 17025:2017 clause 8.3 checklist for labs

Quick Summary Clause 8.3 of ISO/IEC 17025:2017 consists of two parts. Clause 8.3.1 requires you to ...

AI in Your Document Management System: What Works, What Doesn’t, and What You Need to Think About

Quick summary AI features in a document management system can speed up search, classification, ...