ISO/IEC 17025 document control is the structured management of laboratory documents and records, ensuring that only approved, current, identifiable, and retrievable information is used. For calibration and metrology labs, it supports traceability, repeatable methods, competent work, reliable certificates, audit readiness and ongoing accreditation.
Key takeaways:
Document control is the process of creating, approving, distributing, revising, retaining and archiving laboratory information in a controlled way. For calibration and metrology labs, ISO/IEC 17025 protects the evidence behind your results: procedures followed, equipment used, environmental conditions, measurement uncertainty, technician competence, and certificate issue history.
ISO/IEC 17025 is the international standard for testing and calibration laboratories, focused on competence, impartiality, and consistent operation. It is the recognised international reference for laboratories that need to demonstrate they can produce valid results. In the United States, many calibration laboratories also work to ANSI/NCSL Z540.3 for certain customers, particularly in defence and aerospace, alongside their ISO/IEC 17025 accreditation.
Good control helps your lab prove traceability, repeatability, competence, risk-based thinking, and audit readiness. Poor control creates doubts like whether the right method was used, whether the technician was trained, and whether the record is complete.
The standard treats documents and records as two related but distinct disciplines. Documents tell you how to do the work; records prove what you actually did.
ISO/IEC 17025 clause 8.3 requires labs to control management system documents. In practical terms, your lab should ensure that documents are approved before use, uniquely identified, up to date, available to authorised users, and protected from unintended use once obsolete.
ISO/IEC 17025 clause 8.4 requires records to be controlled. Records must remain legible, identifiable, retrievable, and protected from loss, damage, unauthorised change or inappropriate disposal.
These clauses connect directly to clause 7.5 (technical records), which requires sufficient technical detail to enable laboratory activities to be repeated or evaluated. They also link to clause 7.11 (control of data and information management), which covers the systems used to collect, process, store, or report lab data.
It is worth separating the two senses of the word traceability. Metrological traceability, addressed in clause 6.5, is the documented unbroken chain of calibrations that links a measurement result back to the SI, usually through a national measurement institute such as NIST in the United States or NPL in the United Kingdom. Document control does not create that chain. What it does is preserve the records that evidence it, so the calibration establishes metrological traceability and document control proves it was held at the time the work was done.
Typical controlled documents include:
Typical records include:
Your lab should define and apply these controls:
A workable lifecycle for any controlled document could be:
An example document naming convention could be:
CAL-SOP-023-R04: Micrometer Calibration Procedure
Where the ID convention breaks down as:
CAL = Function or document family, in this case, calibration.
SOP = Document type, in this case, standard operating procedure.
023 = Unique sequential document number within that category.
R04 = Revision number, meaning this is revision 4.
Micrometer Calibration Procedure = Plain-English document title describing the controlled content.
So the full ID means: ”Calibration-standard operating procedure-number 023-revision 4, titled “Micrometer Calibration Procedure.”
And an example change log entry could look like:
R04 | 12 Jun 2026 | Updated acceptance criteria and uncertainty reference | Technical Manager | Approved by Quality Manager | Effective 19 Jun 2026
Conventions like this make audit conversations easier. Instead of searching folders and emails, you can show the approved document, change reason, approver, training evidence, and previous revision.
Common nonconformity audit findings include obsolete procedures in use, missing evidence of approval, uncontrolled spreadsheets, incomplete worksheets, weak traceability of certificates, and staff using methods before training is complete.
They can be fixed by tightening release controls, removing local copies, validating key spreadsheets, locking approved templates, requiring mandatory fields on worksheets, and linking training sign-off to document release.
Another common issue is inconsistent retention. To mitigate this, define retention by record type, accreditation body expectations, customer contracts, and regulatory obligations.
| Nonconformity | Fix |
| Obsolete SOP in use at the bench | Controlled distribution and automatic withdrawal of prior versions |
| No evidence of periodic review | Scheduled review dates with recorded outcomes |
| Staff working from uncontrolled copies | A single controlled source with read-and-understand tracking |
| Records altered without traceability | Audit trails that capture who changed what, when, and why |
Before an ISO/IEC 17025 assessment, confirm that:
Manual control with shared drives and spreadsheets rarely survives a rigorous accreditation assessment, whether by UKAS in the United Kingdom or A2LA, NVLAP, or ANAB in the United States; bodies that operate under the ILAC mutual recognition arrangement.
A purpose-built document management system (DMS) can reduce manual effort by controlling versions, role-based access and permissions, configurable approval workflows, read-and-understand training, reusable templates, audit trails and retention, and integrates with the tools your lab already uses. For metrology lab document management, this is especially useful when methods, equipment records and certificates must remain traceable across teams or sites.
Cognidox is a strong option for compliance-led labs that need configurable workflows, role-based access, controlled templates, electronic approvals, and clear document history without forcing unnecessary process complexity.
By automating these controls, maintaining a single source of truth, and providing review and training evidence on demand, Cognidox helps make accreditation maintenance a steady-state routine rather than a pre-audit scramble.
ISO/IEC 17025 document control gives your lab confidence that the right people use the right information at the right time. For calibration and metrology labs, that confidence directly supports reliable results, fewer nonconformities, and stronger accreditation evidence.
Ready to strengthen document control, audit trails, and training evidence across your lab? Book a demo of the Cognidox DMS to see how your lab can retire spreadsheets and version chaos for controlled, audit-ready document management built for ISO/IEC 17025 compliance.
Documents describe how work should be done, such as methods, SOPs, and policies, and are naturally revised over time. Records capture evidence to prove what was actually done, such as calibration results, completed worksheets, certificates, and training sign-offs, and are not altered without a traceable, authorised correction that preserves the original entry.
Yes. Electronic records are acceptable provided the system controlling them is validated, access is restricted, changes are traceable, and data is protected, backed up, and retrievable, in line with Clause 7.11. Your lab should manage access, audit trails, data integrity, and retention for electronic systems.
ISO/IEC 17025 does not prescribe one universal review frequency. Many labs set risk-based review cycles, such as annual or two-yearly reviews, with earlier reviews after method changes, audit findings, equipment changes, or customer requirements.
Show that only the current version is in use, that obsolete versions are withdrawn and marked, and that a change log links each revision to its reason, author, and approver. Audit trails should evidence this without manual reconstruction. You should also show that staff were trained on the version in use.
Both share document and record control principles, but ISO 9001 document control is broader and applies to many organisation types, while ISO/IEC 17025 adds laboratory-specific emphasis on technical records, valid results, competence, data systems, and traceability that ISO 9001 does not address.