Skip to content

Evidence request lists

ISO 15189:2022 - Medical Laboratories Requirements for Quality and Competence

Evidence request list. 39 controls, 39 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Annex A

A.1
Point-of-Care Testing Additional Requirements

Laboratory provides oversight for point-of-care testing including governance, training and quality assurance.

Artefacts an auditor will ask for
  • POCT committee minutes
  • Operator training records
  • QC results
Where this commonly fails
  • POCT users not in competence programme
  • Connectivity to LIS missing

Clause 4: General Requirements

ISO-15189-4.1
Impartiality

Requires laboratories to operate free of bias and conflicts of interest, with identification and management of risks to impartiality.

Artefacts an auditor will ask for
  • Impartiality policy and risk register
  • Declarations of interest from laboratory staff
  • Top management commitment statement
  • Impartiality review minutes
Where this commonly fails
  • No periodic review of impartiality risks
  • Commercial pressures on referring clinicians not assessed
  • Director conflicts not declared
  • Mitigations not documented for identified risks
ISO-15189-4.2
Confidentiality

Requires secure management of patient data with controlled disclosure, including legally enforceable commitments to confidentiality.

Artefacts an auditor will ask for
  • Confidentiality agreements for staff and contractors
  • Patient data handling procedure
  • Disclosure log with legal basis
  • Information security policy referencing patient records
Where this commonly fails
  • Verbal disclosures to clinicians not logged
  • No process for legally compelled disclosures
  • Third party service providers without confidentiality clauses
  • Patient consent for secondary use not captured
ISO-15189-4.3
Requirements regarding patients

Requires consideration of patient input in methods, cost transparency, and obtaining informed consent for examinations.

Artefacts an auditor will ask for
  • Patient information leaflets
  • Informed consent records
  • Test catalogue with turnaround times and cost
  • Patient feedback channel
Where this commonly fails
  • Consent missing for genetic or sensitive tests
  • Pricing information not accessible to patients
  • Vulnerable patient pathways not defined
  • No mechanism to capture patient input on methods

Clause 5: Structural and Governance Requirements

ISO-15189-5.1
Legal entity

Requires the laboratory to be a legal entity or a defined part of a legal entity that is legally accountable for its laboratory activities.

Artefacts an auditor will ask for
  • Certificate of incorporation or equivalent
  • Organizational structure referencing legal parent
  • Liability insurance certificate
  • Scope statement linking entity to laboratory
Where this commonly fails
  • Laboratory operating under undefined organizational unit
  • Insurance limits not reviewed annually
  • Legal accountability split unclear between sites
  • Subsidiary status not reflected in management system
ISO-15189-5.2
Laboratory director

Specifies competence requirements, responsibilities, and authority of the laboratory director including duty delegation.

Artefacts an auditor will ask for
  • Director appointment letter and CV
  • Documented duties of the laboratory director
  • Delegation register with named deputies
  • Director performance review records
Where this commonly fails
  • Director qualifications not aligned with national requirements
  • Delegations verbal and not recorded
  • No deputy named for absence cover
  • Director responsibilities overlap with quality manager without clear split
ISO-15189-5.3
Laboratory activities

Requires documentation of the scope of laboratory activities spanning pre-examination, examination, and post-examination phases.

Artefacts an auditor will ask for
  • Defined scope of laboratory activities
  • Test menu mapped to pre, examination, post phases
  • Point of care testing inventory
  • Outsourced examination list
Where this commonly fails
  • Point of care testing excluded from documented scope
  • Send out tests not part of management system
  • Scope statement not updated when new assays go live
  • Pre and post examination activities not explicitly covered
ISO-15189-5.4
Structure and authority

Requires a defined organizational hierarchy with clear roles, responsibilities, and reporting relationships.

Artefacts an auditor will ask for
  • Organization chart
  • Role descriptions with authorities
  • Quality manager appointment letter
  • Reporting matrix for clinical and operational decisions
Where this commonly fails
  • Quality manager reports to operations creating conflict
  • Authorities not defined for after hours decisions
  • Locum staff not placed in the org chart
  • No documented escalation path for critical issues
ISO-15189-5.5
Objectives and policies

Requires measurable objectives and policies aligned with ISO 15189 and commitment to good professional practice at all levels.

Artefacts an auditor will ask for
  • Quality policy statement
  • Measurable quality objectives
  • Annual quality plan
  • Communication evidence to staff
Where this commonly fails
  • Objectives not measurable or time bound
  • Objectives not cascaded to teams
  • Policy not reviewed annually
  • Progress on objectives not reported to management review
ISO-15189-5.6
Risk management

Requires proactive identification, assessment, and mitigation of risks to patient safety and laboratory operations.

Artefacts an auditor will ask for
  • Laboratory risk register
  • Risk assessment methodology
  • Patient safety incident reviews
  • Risk treatment plans with owners
Where this commonly fails
  • Risks captured but not scored or owned
  • Patient impact not assessed for new assays
  • Risk reviews not linked to incidents and complaints
  • No prospective risk analysis before method changes

Clause 6: Resource Requirements

27006-6.1
Competence of personnel

Competence requirements for personnel involved in the certification process

Artefacts an auditor will ask for
  • Competence matrix for laboratory personnel
  • Training and qualification records
  • Authorization records for examination activities
  • Continuing professional development log
Where this commonly fails
  • Competence reassessment intervals not defined
  • Authorization tied to job title rather than verified competence
  • No evidence of practical assessment for new methods
  • Training records missing for locum or agency staff
27006-6.2
Personnel Records

Maintain up to date records of qualifications, training, experience and performance for ISMS personnel.

Artefacts an auditor will ask for
  • Personnel files
  • Performance evaluations
  • CPD records
Where this commonly fails
  • Out of date records
  • No performance evidence
ISO-15189-6.1
General

Requires the laboratory to have the resources needed to carry out its activities in accordance with the requirements of this document.

Artefacts an auditor will ask for
  • Resource plan covering staff, space, equipment, consumables
  • Budget approval for laboratory operations
  • Capacity and workload analysis
  • Business case records for resource changes
Where this commonly fails
  • Workload not measured against capacity
  • Resource gaps surfaced only after incidents
  • Budget cycles not aligned with method changes
  • Surge capacity not planned for outbreak scenarios
ISO-15189-6.2
Personnel

Specifies competency requirements, authorization processes, continuing education obligations, and maintenance of qualification records.

Artefacts an auditor will ask for
  • Job descriptions and competence requirements
  • Training plans and records
  • Authorization records for sign out
  • Annual competence reassessment records
Where this commonly fails
  • Reassessment overdue for long serving staff
  • New starter checklist incomplete
  • Competence on rare assays not maintained
  • Locum induction not recorded
ISO-15189-6.3
Facilities and environmental conditions

Requires controls for contamination prevention, adequate ventilation, proper storage, and appropriate amenities.

Artefacts an auditor will ask for
  • Facility layout with zoning and containment
  • Temperature and humidity monitoring logs
  • Biosafety risk assessment and SOPs
  • Access control records for restricted areas
Where this commonly fails
  • Containment level not validated for new agents
  • Environmental excursions not investigated
  • Storage of patient samples not segregated from reagents
  • Cleaning and decontamination logs incomplete
ISO-15189-6.4
Equipment

Requires proper selection, acceptance testing, regular maintenance, and adverse event reporting for all laboratory equipment.

Artefacts an auditor will ask for
  • Equipment inventory with unique identifiers
  • Preventive maintenance schedule and records
  • Installation and operational qualification records
  • Equipment use log per analyser
Where this commonly fails
  • Backup analysers not maintained to same standard
  • Out of service status not flagged in LIS
  • Maintenance carried out by users without training
  • No verification after software upgrades
ISO-15189-6.5
Equipment calibration and metrological traceability

Requires SI unit alignment, documented measurement uncertainty, and metrological traceability of measurement results.

Artefacts an auditor will ask for
  • Calibration programme with intervals
  • Traceability statements for reference materials
  • Certificates from accredited calibration providers
  • Calibration verification records
Where this commonly fails
  • Traceability chain broken to manufacturer working calibrators
  • Calibration intervals not justified by data
  • Reference material lot changes not bridged
  • No measurement uncertainty estimate per assay
ISO-15189-6.6
Reagents and consumables

Requires procedures for receipt, storage, acceptance testing, inventory control, and adverse event reporting for reagents and consumables.

Artefacts an auditor will ask for
  • Reagent inventory with lot and expiry
  • Acceptance criteria for new lots
  • Lot to lot verification records
  • Storage condition monitoring for reagents
Where this commonly fails
  • Lot to lot verification skipped under pressure
  • Expired reagents found in active stock
  • Storage temperature deviations not actioned
  • Critical reagents single sourced without contingency
ISO-15189-6.7
Service agreements

Requires formal contracts with users and POCT operators defining responsibilities, service levels, and expectations.

Artefacts an auditor will ask for
  • Service agreements with referring clinicians and trusts
  • Contract review records
  • Change communication to customers
  • Service level reports
Where this commonly fails
  • Agreements not updated when scope changes
  • Turnaround time commitments not monitored
  • Sample acceptance criteria not in writing
  • No periodic review of agreements
ISO-15189-6.8
Externally provided products and services

Requires supplier qualification processes and ongoing monitoring of performance for externally sourced products and services.

Artefacts an auditor will ask for
  • Approved supplier list
  • Referral laboratory accreditation evidence
  • Supplier evaluation records
  • Contract terms for referral testing
Where this commonly fails
  • Referral labs used without accreditation evidence
  • Supplier performance not monitored
  • Critical suppliers not risk assessed
  • No process for handling unaccredited referral results

Clause 7: Process Requirements

ISO-15189-7.1
General

Requires documented procedures for all laboratory processes from pre-examination through post-examination.

Artefacts an auditor will ask for
  • Process map covering pre, examination, post phases
  • Linked SOPs for each phase
  • Roles and responsibilities per phase
  • Process performance indicators
Where this commonly fails
  • Handoffs between phases not documented
  • Indicators tracked for examination only
  • Process map out of date after LIS upgrade
  • No single owner for end to end test journey
ISO-15189-7.2
Pre-examination processes

Covers patient information management, request handling, sample collection, transportation, receipt, and storage procedures.

Artefacts an auditor will ask for
  • Sample collection manual
  • Patient identification procedure
  • Transport conditions and chain of custody
  • Sample rejection criteria and log
Where this commonly fails
  • Phlebotomy staff outside laboratory governance
  • Transport temperature not monitored end to end
  • Rejection criteria applied inconsistently between shifts
  • Mislabelled sample rate not trended
ISO-15189-7.3
Examination processes

Requires method verification/validation, measurement uncertainty evaluation, reference interval establishment, and result validity assurance.

Artefacts an auditor will ask for
  • Validated methods with verification records
  • IQC plan with rules and ranges
  • IQC review evidence with sign off
  • Examination SOPs with revision history
Where this commonly fails
  • IQC rules not chosen based on error budget
  • Verification limited to vendor claims
  • IQC failures closed without root cause
  • Method changes not revalidated
ISO-15189-7.4
Post-examination processes

Covers result reporting, clinical advice, sample retention, and disposal in accordance with regulations.

Artefacts an auditor will ask for
  • Reporting SOP with reference intervals and units
  • Critical results notification log
  • Result amendment and recall procedure
  • Reporting template for each test
Where this commonly fails
  • Critical results notified but not acknowledged
  • Reference intervals not validated for local population
  • Amended results not flagged in downstream systems
  • Interpretive comments inconsistent between reporters
ISO-15189-7.5
Nonconforming work

Requires detection, evaluation, documentation, and correction of nonconforming laboratory work.

Artefacts an auditor will ask for
  • Nonconformity register
  • Containment and recall procedure
  • Patient impact assessment template
  • Communication records to clinicians
Where this commonly fails
  • Patient impact assessed only for severe events
  • Recall actions not closed within target
  • Nonconformities not linked to risks
  • Trend analysis missing across nonconformity types
ISO-15189-7.6
Data and information management

Requires validation of information systems, documented downtime procedures, and oversight of off-site data providers.

Artefacts an auditor will ask for
  • LIS validation records
  • Access control matrix for laboratory systems
  • Backup and restore test evidence
  • Interface validation for instrument and EHR connections
Where this commonly fails
  • LIS changes not revalidated
  • Generic accounts in use for analyser interfaces
  • Backups untested or restores not exercised
  • Audit trails disabled or unreviewed
ISO-15189-7.7
Complaints

Requires structured receipt, investigation, and objective resolution of complaints from patients and other stakeholders.

Artefacts an auditor will ask for
  • Complaints procedure
  • Complaints register with categories
  • Investigation and response records
  • Complaint trend analysis
Where this commonly fails
  • Verbal complaints not captured
  • No target for complaint closure
  • Trends not reviewed in management review
  • Complainants not informed of outcome
ISO-15189-7.8
Continuity and emergency preparedness

Requires business continuity planning with regular testing to ensure service during disruptions and emergencies.

Artefacts an auditor will ask for
  • Laboratory continuity plan
  • Emergency response procedures
  • Backup analyser arrangements
  • Exercise reports and lessons learned
Where this commonly fails
  • Plan not tested in last 12 months
  • Critical assays without backup arrangements
  • LIS failure scenarios not exercised
  • Mutual aid with peer laboratories undocumented

Clause 8: Management System Requirements

ISO-15189-8.1
General requirements

Requires a structured quality management system ensuring consistent compliance with ISO 15189.

Artefacts an auditor will ask for
  • Statement of chosen management system option
  • Mapping between laboratory and parent organization systems
  • Quality manual or equivalent overview
  • Management system scope statement
Where this commonly fails
  • Option chosen but integration not documented
  • Conflicts between parent and laboratory procedures
  • Quality manual out of date
  • Scope of management system unclear
ISO-15189-8.2
Management system documentation

Requires documented quality policies, objectives, leadership commitment, and personnel access to documentation.

Artefacts an auditor will ask for
  • Documented information register
  • Quality manual or system overview
  • Procedure and SOP library
  • Document templates with controls
Where this commonly fails
  • Documents stored in multiple locations
  • Procedure scope unclear for multi site labs
  • No master index of controlled documents
  • Inconsistent format across SOPs
ISO-15189-8.3
Control of documents

Requires document approval, periodic review, version control, and access safeguards for management system documents.

Artefacts an auditor will ask for
  • Document control procedure
  • Document approval and review records
  • Version history per controlled document
  • Distribution list and acknowledgement
Where this commonly fails
  • Superseded documents still accessible at the bench
  • Review intervals exceeded
  • External documents not controlled
  • Acknowledgement of new versions not captured
ISO-15189-8.4
Control of records

Requires real-time creation, traceable amendments, and retention based on legal and clinical requirements.

Artefacts an auditor will ask for
  • Records retention schedule
  • Storage and access controls for records
  • Disposal records
  • Backup evidence for electronic records
Where this commonly fails
  • Retention not aligned with national requirements
  • Paper records stored without environmental controls
  • Disposal not authorized or recorded
  • Electronic records not protected against alteration
ISO-15189-8.5
Actions addressing risks and opportunities

Requires identification, evaluation, and prioritization of risks and opportunities for improvement of the management system.

Artefacts an auditor will ask for
  • Risk and opportunity register
  • Planned actions with owners and dates
  • Effectiveness review evidence
  • Linkage to objectives and management review
Where this commonly fails
  • Opportunities not captured alongside risks
  • Actions closed without effectiveness check
  • Risks not refreshed after major changes
  • No traceability between risks, objectives, and audits
ISO-15189-8.6
Improvement

Requires continual enhancement of the management system using audit data, feedback, and performance metrics.

Artefacts an auditor will ask for
  • Improvement project register
  • Performance trend analyses
  • Lessons learned summaries
  • Improvement objectives linked to KPIs
Where this commonly fails
  • Improvement reactive rather than planned
  • Lessons not shared across sites
  • Improvement actions without measurable benefit
  • No staff led improvement channel
ISO-15189-8.7
Nonconformities and corrective actions

Requires immediate correction of nonconformities, root cause analysis, and verification of corrective action effectiveness.

Artefacts an auditor will ask for
  • Corrective action procedure
  • CAPA tracker with root cause and effectiveness
  • Root cause analysis templates
  • Trend analysis of nonconformities
Where this commonly fails
  • Corrective actions limited to fixing the symptom
  • Root cause analysis superficial
  • Effectiveness not reverified after closure
  • No common cause analysis across similar events
ISO-15189-8.8
Evaluations

Requires quality indicators, internal audit planning, and compliance verification through systematic evaluation.

Artefacts an auditor will ask for
  • Internal audit programme and schedule
  • Audit reports with findings and actions
  • EQA participation records and reviews
  • IQC trend analysis and indicator reports
Where this commonly fails
  • Audits do not sample all examination disciplines annually
  • EQA failures not investigated as nonconformities
  • Indicators tracked but not acted on
  • Auditor independence not assured
ISO-15189-8.9
Management reviews

Requires periodic management system assessment with documented decisions, actions, and resource allocation.

Artefacts an auditor will ask for
  • Management review schedule and inputs list
  • Management review minutes
  • Action register from management review
  • Resource decisions tied to review outputs
Where this commonly fails
  • Reviews held but inputs incomplete
  • Patient and clinician feedback missing
  • Actions not tracked between reviews
  • EQA and IQC performance not summarized

Management System

8.9
Management Reviews

Top management reviews QMS at planned intervals to ensure continuing suitability, adequacy and effectiveness.

Artefacts an auditor will ask for
  • Management review minutes
  • Input pack
  • Action register
Where this commonly fails
  • Inputs missing patient safety data
  • Actions without owners

Resource Requirements

6.8
Externally Provided Products and Services

Externally provided products and services that affect laboratory activities are evaluated and approved.

Artefacts an auditor will ask for
  • Supplier evaluation forms
  • Approved supplier register
  • Periodic performance reviews
Where this commonly fails
  • Critical suppliers not re-evaluated
  • Single-source risk untreated
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.