How to Audit Lab Practices: A Step-by-Step Guide
Learn how to audit lab practices effectively. This step-by-step guide ensures compliance, quality results, and reliable lab operations.
TL;DR:
- Laboratory audits systematically evaluate management and technical processes to ensure compliance with standards like ISO/IEC 17025. Combining horizontal reviews of documentation with vertical sample tracing provides a comprehensive picture of lab effectiveness. Continuous, root cause-driven audits help labs maintain accreditation and improve result reliability.
A laboratory audit is a systematic, documented evaluation of management and technical processes designed to confirm compliance with recognized standards such as ISO/IEC 17025 and ensure the quality and reliability of lab results. Knowing how to audit lab practices is not optional for labs operating under regulatory scrutiny. It is the mechanism that separates labs that produce reproducible results from those that produce defensible paperwork. A well-executed audit covers everything from personnel qualifications and equipment calibration to sample handling and data integrity. The dual audit strategy combining horizontal and vertical assessments gives quality assurance professionals the most complete picture of where a lab actually stands.
How to audit lab practices: prerequisites and tools
Effective lab audits start before the first checklist item is checked. The audit team must be assembled, the applicable standard must be identified, and all relevant documentation must be gathered in advance. Skipping this preparation phase is the single most common reason audits produce shallow findings.

The applicable standard for most testing and calibration labs is ISO/IEC 17025:2017. Its clauses 6.2 through 7.8 cover technical requirements including personnel competence, equipment, environmental conditions, measurement traceability, and test methods. A compliance checklist for research labs built around these clauses gives the audit team a clause-by-clause framework that leaves no area unexamined.
The audit team should include at minimum one lead auditor with direct knowledge of the standard, one technical specialist familiar with the lab’s methods, and one quality representative. Auditors must not audit their own work. That independence is what gives findings credibility with accreditation bodies and lab leadership alike.
| Audit element | What to prepare |
|---|---|
| Applicable standard | ISO/IEC 17025:2017 clauses 6.2–7.8 |
| Audit checklist | Clause-by-clause checklist covering management and technical sections |
| Documentation package | Quality manual, SOPs, calibration records, training logs |
| Team qualifications | Lead auditor, technical specialist, quality representative |
| Nonconformity forms | Pre-formatted forms for recording observations and grading severity |
Pro Tip: Build your checklist directly from the standard’s clause numbering. Auditors who work from generic checklists miss clause-specific requirements and produce findings that do not map to the standard. A clause-referenced checklist also makes corrective action tracking far easier.
What does a horizontal vs. vertical audit look like in practice?

A robust internal audit combines two distinct approaches: a horizontal audit that reviews all standard clauses broadly, and a vertical audit that traces a single sample through every procedural step. Neither approach alone is sufficient. Together, they cover both the management system and the technical reality on the bench.
Running the horizontal audit
The horizontal audit is a table-top review. The auditor works through the checklist clause by clause, verifying that documented procedures exist, are current, and are accessible to staff. This phase covers management requirements such as impartiality, confidentiality, and document control, as well as technical requirements such as method validation and equipment maintenance.
- Confirm the quality manual references the current version of ISO/IEC 17025:2017.
- Verify all SOPs carry current revision dates and authorized signatures.
- Check that personnel training records align with assigned tasks.
- Review calibration certificates for all critical instruments and confirm traceability.
- Confirm environmental monitoring logs are complete and within specified limits.
- Verify that the lab’s scope of accreditation matches the tests currently performed.
Running the vertical audit
The vertical audit follows one sample or test from receipt through final report. Tracing a sample through every step of a test method verifies technical competence in a way that no document review can replicate. Many labs focus too much on paperwork and neglect this phase entirely.
- Select a recently completed test report at random.
- Trace the sample back to its receipt record and verify chain of custody.
- Confirm the method used matches the validated, approved version.
- Check that the analyst who performed the test holds documented competency for that method.
- Verify instrument calibration was current on the date of testing.
- Review raw data, calculations, and any corrections against the final report.
- Confirm the report format and content meet the standard’s reporting requirements.
Pro Tip: During sample tracing, pay close attention to hand-offs between phases. Errors in preanalytical and postanalytical phases are frequently missed because auditors focus only on the analysis step. Check sample labeling at receipt, storage conditions before testing, and result transcription after analysis.
What documentation and data integrity checks are essential?
Documentation review is where most audit failures become visible. Audit documentation must comply with ALCOA+ principles, meaning every record must be Attributable, Legible, Contemporaneous, Original, Accurate, Complete, Consistent, Enduring, and Available. Labs that assume data integrity by result correctness alone routinely fail this check.
ALCOA+ is not a bureaucratic framework. It is a practical test of whether a record tells the full story of what happened, who did it, and when. A chromatogram with a correct peak area but no analyst signature fails ALCOA+. A logbook entry corrected with correction fluid rather than a single line and initials fails ALCOA+. These are not minor issues. They are the kind of findings that trigger accreditation suspensions.
The documentation review before report finalization must cover instrument logbooks, chromatograms, dilution factors, and standard potency references. Each item must be cross-checked against the corresponding raw data and the final report. Discrepancies between raw data and reported results are a critical nonconformity under ISO/IEC 17025.
Key documents to verify during a laboratory procedure review:
- Quality manual: Current version, signed by lab director, references the applicable standard.
- SOPs: Revision history present, staff sign-off on current versions documented.
- Calibration records: Certificates traceable to national or international standards, within validity period.
- Training logs: Competency assessments completed, not just training attendance recorded.
- Sample logbooks: Chain of custody unbroken from receipt to disposal.
- Instrument logbooks: Maintenance, calibration, and any anomalies recorded contemporaneously.
- Chromatograms and raw data: Unaltered originals retained, corrections made per GMP rules.
Pro Tip: Check whether your lab’s quality control checkpoints include a formal pre-report documentation review step. Labs that build this into their workflow catch ALCOA+ violations before the auditor does, which dramatically reduces critical findings.
How do you manage audit findings and corrective actions?
Finding a nonconformity is not the end of the audit process. It is the beginning of the improvement cycle. Passing an audit requires a 5-step corrective action process that addresses root causes, not just symptoms.
- Understand the finding. Read the nonconformity statement carefully. Identify exactly which clause was not met and what evidence the auditor cited.
- Perform root cause analysis. Ask why the gap exists, not just what went wrong. A wrong calculation may trace back to a non-standardized spreadsheet formula or a training gap, not simple human error.
- Define the corrective action. The action must address the root cause. Retraining a single analyst does not fix a systemic formula error.
- Assign responsibility and set a deadline. Every corrective action needs one named owner and a specific completion date.
- Verify effectiveness. After implementation, confirm the action actually closed the gap. Re-audit the specific area if needed.
Root cause analysis is the step most labs rush or skip. Treating symptoms alone causes the same finding to reappear in the next audit cycle. That pattern signals to accreditation bodies that the lab’s quality system is not functioning.
| Step | Action | Owner | Deadline |
|---|---|---|---|
| 1. Understand finding | Document the nonconformity and the clause reference | Lead auditor | Audit close-out |
| 2. Root cause analysis | Use 5-Why or fishbone diagram | Quality manager | Within 5 business days |
| 3. Define corrective action | Write specific, measurable action statement | Process owner | Within 10 business days |
| 4. Assign and schedule | Name one owner, set firm deadline | Lab director | At action definition |
| 5. Verify effectiveness | Re-audit or review evidence of closure | Lead auditor | 30–90 days post-action |
Pro Tip: Use a 5-Why analysis for every finding that involves a human error. The first “why” almost always points to the person. The fifth “why” almost always points to a system, process, or training gap that the lab can actually fix.
What are the most common audit mistakes to avoid?
Labs that struggle with audits typically make the same errors. Recognizing these patterns before the audit begins is the most efficient way to improve outcomes.
Many labs lack constructive alignment in their audit approach. They verify that procedures are documented but do not confirm that staff actually follow those procedures during testing. An audit that only checks paperwork misses the gap between what the SOP says and what happens at the bench.
Top five audit mistakes to avoid:
- Treating audits as periodic events. Audit readiness must be a continuous state, not a sprint before the accreditation visit.
- Skipping the vertical audit. Document reviews alone do not verify technical competence. Sample tracing is not optional.
- Confusing data correctness with data integrity. A correct result recorded incorrectly still fails ALCOA+.
- Assigning corrective actions without root cause analysis. Symptom-level fixes produce repeat findings.
- Auditing only the quality department. Technical staff, analysts, and instrument operators must all be included in scope.
The primary goal of audits is to align technical and management processes with standards to guarantee consistency and reliability. Labs that internalize this goal stop dreading audits and start using them as a genuine quality tool. That shift in mindset is what separates labs that pass once from labs that maintain accreditation year after year.
Pro Tip: Schedule a mini vertical audit quarterly, not just annually. Pick one test method, trace one sample, and check three ALCOA+ criteria. This 90-minute exercise catches drift before it becomes a nonconformity.
Key Takeaways
A successful lab audit requires both a horizontal clause-by-clause review and a vertical sample trace, backed by ALCOA+ documentation checks and root cause-driven corrective actions.
| Point | Details |
|---|---|
| Use a dual audit approach | Combine horizontal checklist reviews with vertical sample tracing for complete coverage. |
| Build checklists from ISO/IEC 17025 | Reference clauses 6.2–7.8 directly to avoid gaps in technical and management review. |
| Apply ALCOA+ to all records | Every document must be attributable, contemporaneous, and complete, not just correct. |
| Address root causes in corrective actions | Use 5-Why analysis to fix systems, not just individual errors, to prevent repeat findings. |
| Make audit readiness continuous | Quarterly mini-audits catch procedural drift before it becomes a formal nonconformity. |
Why most labs are auditing the wrong thing
After working through hundreds of lab quality reviews, the pattern I see most often is this: labs spend 80% of their audit preparation on documentation and 20% on what actually happens during testing. That ratio should be closer to 50/50.
The vertical audit is where real quality lives. I have seen labs with immaculate quality manuals that could not trace a sample from receipt to report without finding three undocumented steps. The paperwork looked perfect. The bench practice did not. Accreditation bodies know this, which is why experienced auditors always ask to watch a test being performed, not just read the SOP.
The other thing I would push back on is the idea that corrective actions are a sign of failure. They are not. A lab that finds ten nonconformities and closes all ten with verified root cause fixes is in a stronger position than a lab that finds two and patches them superficially. Audits are the mechanism by which labs get better. The labs that treat them as a threat to be managed are the ones that keep failing the same clauses.
Leadership engagement is the variable that determines whether an audit culture sticks. When lab directors review corrective action status in monthly meetings, quality becomes everyone’s job. When audits are delegated entirely to the quality department, they stay a compliance exercise. The difference in outcomes is not subtle.
— Ragnar
Herbilabs and audit-ready lab supplies
Audit readiness does not stop at procedures and paperwork. The reagents and solutions your lab uses must also meet the traceability and purity standards that auditors check.

Herbilabs supplies research-grade bacteriostatic water, sterile diluents, and reconstitution solutions manufactured to strict purity standards in a dedicated facility. Every product ships with documentation that supports your chain-of-custody records and reagent traceability requirements. For labs that need to demonstrate reagent quality during a laboratory procedure review, Herbilabs products provide the certificate trail that auditors expect. Browse the full range at the Herbilabs shop and keep your reagent documentation audit-ready from the first delivery.
FAQ
What is a laboratory audit?
A laboratory audit is a systematic, documented evaluation of a lab’s management and technical processes against a recognized standard such as ISO/IEC 17025. Its purpose is to verify compliance and identify gaps that affect result reliability.
What is the difference between a horizontal and vertical audit?
A horizontal audit reviews all standard clauses broadly using a checklist. A vertical audit traces a single sample through every procedural step to verify technical competence in practice.
What are ALCOA+ principles in lab audits?
ALCOA+ stands for Attributable, Legible, Contemporaneous, Original, Accurate, Complete, Consistent, Enduring, and Available. These principles define the minimum integrity requirements for all lab records reviewed during an audit.
How do you write a corrective action after an audit finding?
A corrective action must identify the root cause using a method such as 5-Why analysis, define a specific fix, assign one named owner, set a deadline, and include a plan to verify effectiveness after implementation.
How often should a lab conduct internal audits?
ISO/IEC 17025 requires internal audits at planned intervals, typically annually at minimum. Labs with active accreditation or high-risk testing benefit from quarterly targeted reviews of specific methods or processes.



