Why Laboratories Face a Choice Between Two Standards
If you manage quality in a laboratory, you have probably been asked at some point whether your facility should be certified to ISO 9001 or accredited to ISO 17025. Sometimes the question comes from a client. Sometimes it comes from a regulator. Occasionally it comes from senior management who have heard both terms used interchangeably and want to know what the difference actually is.
On this page
The short answer is that they are not the same thing, they serve different purposes, and choosing the wrong path can cost your organisation significant time and money. This article explains what each standard requires, where they overlap, where they diverge, and how to decide which one applies to your laboratory.
What ISO 9001 Is and What It Is Not
ISO 9001 is a quality management system standard. It applies to virtually any organisation that wants to demonstrate its ability to consistently provide products or services that meet customer and regulatory requirements. It is a general purpose standard, meaning it was not written specifically for laboratories. A hospital, a construction company, a software firm, and a testing laboratory can all certify to ISO 9001.
ISO 9001 focuses on how an organisation manages its processes, how it handles customer requirements, how it controls documented information, and how it drives continual improvement. It asks whether your system is working. It does not tell you how to perform a specific test, how to calibrate a particular instrument, or what uncertainty of measurement means for your results.
This is an important distinction. ISO 9001 certification tells the world that your quality management system is sound. It says nothing specific about the technical competence of your staff to perform testing or calibration activities, nor does it validate the accuracy of your results.
Exemplar Global Recognised Training ProviderRTP No. 310970What ISO 17025 Is and Why It Exists
ISO/IEC 17025 is the international standard for the competence of testing and calibration laboratories. It was developed specifically to address what ISO 9001 cannot: the technical requirements that determine whether a laboratory produces valid, reliable results.
ISO 17025 covers two broad areas. The first is management requirements, which overlap significantly with ISO 9001. The second is technical and metrological requirements, which are unique to laboratory operations. These include method validation, measurement uncertainty, equipment calibration, sampling, handling of test items, and the competence of personnel to perform specific tests.
Critically, ISO 17025 leads to accreditation, not certification. Accreditation is granted by a national accreditation body. In Australia, that body is the National Association of Testing Authorities, known as NATAS. Accreditation means an independent body has assessed your laboratory and confirmed that it is technically competent to perform the specific tests or calibrations listed in its scope of accreditation. This is a much stronger and more specific claim than ISO 9001 certification.
The Core Difference: System vs Technical Competence
The simplest way to explain the difference to someone unfamiliar with either standard is this. ISO 9001 asks whether your organisation has a well managed system for delivering consistent outputs. ISO 17025 asks whether your laboratory is technically capable of producing accurate, reliable test or calibration results.
A laboratory could have an excellent ISO 9001 quality management system and still produce technically flawed results if its methods are not validated, its equipment is poorly calibrated, or its staff lack the specific competence to perform the tests in question. Conversely, a highly competent laboratory with excellent technical practices might have gaps in its broader management system around things like risk management, supplier evaluation, or continual improvement.
This is why some laboratories hold both. ISO 9001 addresses the management system. ISO 17025 addresses the technical credibility of the results.
Where ISO 9001 and ISO 17025 Overlap
Because ISO 17025:2017 was revised to align more closely with the harmonised structure used by ISO 9001 and other management system standards, there is now meaningful overlap between the two. If your laboratory is already accredited to ISO 17025, a significant portion of the management system requirements are already addressed.
The areas of overlap include:
- Document and record control: Both standards require controlled documented information and records that demonstrate conformity.
- Internal audits: Both require a programme of internal audits to verify the system is being maintained.
- Management review: Both require top management to periodically review the system and make decisions about resources and improvement.
- Corrective action: Both require a process for identifying nonconformities and taking corrective action to address root causes.
- Continual improvement: Both expect the organisation to improve the effectiveness of its system over time.
- Competence: Both require that personnel have the education, training, and experience necessary for their roles.
- Customer focus: Both require the organisation to understand and meet customer requirements.
If you are auditing a laboratory that holds ISO 17025 accreditation and is seeking ISO 9001 certification, you will find that many of the management clauses are already addressed. The gap analysis is usually narrower than organisations expect.
Where ISO 17025 Goes Further Than ISO 9001
This is where the real distinction lies. ISO 17025 contains requirements that have no equivalent in ISO 9001, because they are specific to laboratory operations and the production of technically valid results.
Method Validation and Verification
ISO 17025 requires laboratories to validate the methods they use for testing and calibration. Validation means demonstrating that a method is fit for its intended purpose. For non-standard methods or methods developed in-house, this involves extensive testing to establish parameters like linearity, precision, accuracy, detection limits, and selectivity. ISO 9001 has no equivalent requirement. It requires you to control processes, but it does not require you to prove that your test methods actually work as intended.
Measurement Uncertainty
One of the most technically demanding requirements in ISO 17025 is the estimation and reporting of measurement uncertainty. Every test result has some degree of uncertainty associated with it. ISO 17025 requires laboratories to identify, quantify, and report this uncertainty. This is fundamental to the scientific credibility of laboratory results. ISO 9001 does not mention measurement uncertainty at all.
Metrological Traceability
ISO 17025 requires that all measurements be traceable to national or international standards through an unbroken chain of calibrations. This means your reference standards must be calibrated by a body with the appropriate accreditation, and that calibration must be documented. ISO 9001 requires control of monitoring and measuring equipment but does not prescribe the same rigorous traceability requirements that ISO 17025 demands.
Sampling
When laboratories collect samples as part of their testing activities, ISO 17025 requires documented procedures for sampling, including how samples are selected, handled, transported, and stored. ISO 9001 addresses handling of products and outputs but does not contain sampling requirements in the laboratory sense.
Reporting of Results
ISO 17025 has detailed requirements for how test and calibration reports must be presented, including what information must appear on a report, how results must be expressed, and when measurement uncertainty must be stated. These requirements exist to ensure that clients and end users can correctly interpret the results. ISO 9001 requires that outputs meet customer requirements but does not prescribe the technical content of reports.
Technical Competence of Personnel
Both standards address competence, but ISO 17025 goes further by requiring that personnel be authorised to perform specific activities. A laboratory must be able to demonstrate that the person who performed a particular test was competent and authorised to do so. This is more granular than ISO 9001, which requires competence for roles but does not typically require authorisation records at the individual test level.
Where ISO 9001 Goes Further Than ISO 17025
ISO 9001 also addresses areas that ISO 17025 does not cover in the same depth. Laboratories seeking ISO 9001 certification alongside or instead of ISO 17025 accreditation will need to address these gaps.
Risk Based Thinking Across the Organisation
ISO 9001 Clause 6.1 requires the organisation to determine risks and opportunities across its entire quality management system and plan actions to address them. While ISO 17025:2017 introduced some risk-based thinking, ISO 9001 takes a broader view that extends beyond laboratory operations to the organisation as a whole, including commercial risks, supplier risks, and operational risks.
Context of the Organisation
ISO 9001 Clause 4.1 requires the organisation to understand its internal and external context, including factors that affect its ability to achieve intended outcomes. Clause 4.2 requires identification of interested parties and their relevant needs. ISO 17025 addresses this less explicitly. For a laboratory operating within a larger organisation, or one that has diverse stakeholders including regulators, clients, and funding bodies, the ISO 9001 approach to context can add genuine value.
Design and Development
If a laboratory develops new test methods or products, ISO 9001 Clause 8.3 on design and development may be relevant. The controls around design inputs, design outputs, design review, verification, and validation provide a structured framework for method development that complements the validation requirements of ISO 17025.
Supplier Management
ISO 9001 Clause 8.4 on control of externally provided processes, products, and services is broader than the equivalent provisions in ISO 17025. For laboratories that rely on reference materials, subcontracted testing, or specialist reagents from external suppliers, the ISO 9001 approach to supplier evaluation and monitoring can strengthen the overall system.
Which Standard Does a Laboratory Actually Need?
The answer depends on what the laboratory does and who its clients are.
If your laboratory issues test reports or calibration certificates to external clients, and those clients need to rely on the technical accuracy of your results for decisions about safety, regulatory compliance, product release, or legal matters, then ISO 17025 accreditation is almost certainly what you need. Regulators in Australia, including those in food safety, environmental testing, and medical testing, typically require NATAS accreditation rather than ISO 9001 certification. ISO 9001 certification alone would not satisfy these requirements.
If your laboratory is an internal function within a larger organisation, performing testing to support manufacturing, product development, or internal quality control, and you are not issuing accredited test reports to external parties, then ISO 9001 certification may be sufficient. In this context, the laboratory is part of a broader quality management system, and ISO 9001 provides the framework for managing it.
Some laboratories pursue both. A contract laboratory might hold ISO 17025 accreditation for its core testing activities and ISO 9001 certification for its broader management system, including commercial operations, client management, and continual improvement. This is not uncommon in larger testing organisations.
Auditing a Laboratory Under ISO 9001: What to Focus On
If you are an internal auditor or lead auditor conducting an ISO 9001 audit in a laboratory environment, there are some specific areas that deserve close attention.
First, calibration and measurement equipment. ISO 9001 Clause 7.1.5 requires that monitoring and measuring equipment be calibrated or verified at specified intervals against measurement standards traceable to international or national measurement standards. In a laboratory, this is a substantial area. You should be checking calibration records, confirming that calibration is current, and verifying that out-of-tolerance equipment is identified and withdrawn from service.
Second, competence. Laboratory work is highly specialised. When auditing Clause 7.2, go beyond checking that training records exist. Ask how the organisation determines whether a person is competent to perform a specific test. Look for evidence of authorisation, practical assessment, or witnessed performance.
Third, control of nonconforming outputs. In a laboratory, a nonconforming output might be a test result that falls outside expected parameters, a sample that was compromised, or a report issued with an error. Check that the laboratory has a clear process for identifying, containing, and investigating these situations.
Fourth, documented information. Laboratories generate a large volume of records. Raw data, instrument readings, chain of custody records, and calculation sheets all need to be controlled. Verify that records are legible, identifiable, and protected from unintended alteration.
For a deeper look at what auditors examine in laboratory quality systems, including calibration, competence, and records, the article on auditing laboratory quality systems covers these areas in practical detail.
Common Nonconformities Found in Laboratory ISO 9001 Audits
Having conducted audits across testing and calibration laboratories, there are a handful of nonconformities that come up repeatedly.
- Calibration records not maintained for all equipment: Laboratories often calibrate major instruments but overlook supporting equipment like balances, thermometers, or timing devices.
- Competence records not linked to specific activities: Training records exist but cannot demonstrate that a particular person is authorised to perform a particular test.
- Nonconforming outputs not consistently identified: When a result falls outside expected ranges, the investigation and containment process is not always triggered.
- Internal audit programme not risk based: Laboratories sometimes audit all areas at the same frequency regardless of the criticality or history of nonconformances in those areas.
- Management review inputs incomplete: Clause 9.3 requires specific inputs including customer feedback, quality objective performance, and audit results. Some laboratories treat management review as a formality rather than a genuine decision-making process.
Understanding what auditors look for in an ISO 9001 quality management system more broadly can help laboratory managers prepare for both internal and external audits. The article on what auditors look for in an ISO 9001 quality management system provides useful context.
Exemplar Global Recognised Training ProviderRTP No. 310970Can ISO 9001 Certification Help a Laboratory Seeking ISO 17025 Accreditation?
Yes, in a practical sense. If a laboratory already holds ISO 9001 certification, the management system foundations are in place. The internal audit programme, document control, corrective action process, and management review are all functioning. When pursuing ISO 17025 accreditation, the laboratory can focus its effort on the technical requirements: method validation, measurement uncertainty, traceability, and the specific competence requirements for each test in scope.
Assessors from NATAS will still evaluate the management system requirements, but a laboratory with a mature ISO 9001 system typically has less ground to cover in that area. The reverse is also true. A laboratory with ISO 17025 accreditation seeking ISO 9001 certification will find that most of the management system requirements are already addressed, and the gap is usually in areas like context of the organisation, risk-based thinking at the organisational level, and supplier management.
Practical Advice for Quality Managers in Laboratory Settings
If you are a quality manager in a laboratory and you are trying to decide how to approach this question, here is what I would suggest.
Start by understanding your regulatory environment. If your laboratory produces results used for regulatory decisions, accreditation to ISO 17025 is almost certainly required. Check with the relevant regulator rather than assuming ISO 9001 will suffice.
Next, consider your clients. If clients are asking for accredited test reports, ISO 9001 certification will not satisfy that requirement. If clients simply want confidence in your quality management system and are not relying on your results for regulatory or legal purposes, ISO 9001 may be appropriate.
If you are pursuing ISO 9001 certification as part of a broader organisational certification programme, make sure the laboratory-specific processes are properly addressed in the scope. Calibration, competence, and nonconforming outputs need particular attention in a laboratory context.
Finally, if you are building auditor skills in this area, understanding the differences between ISO 9001 and ISO 17025 will make you a more effective auditor in any laboratory setting. The ability to recognise what each standard requires and where the gaps lie is a genuine differentiator.
At Audit Workshop, our ISO 9001 internal auditor and lead auditor courses are built around real audit practice rather than theory alone. If you are working in a laboratory environment or auditing laboratory quality systems, the practical skills developed through our training will help you ask the right questions and gather meaningful evidence. You can explore our ISO 9001 training options to find the level that suits where you are in your auditing career.













