Compliance 11 min read

QMS for Laboratory Operations: ISO 17025 and GLP

J

Jared Clark

July 27, 2026

Most laboratories don't fail compliance because they lack procedures. They fail because their quality management system treats ISO 17025 and GLP as separate checklists rather than as two angles on the same underlying discipline: control over what happened in that room, with that sample, on that day.

That distinction — checklist versus discipline — is where most lab QMS implementations go sideways. And it's expensive to discover during an inspection.

What ISO 17025 and GLP Actually Require

Let me start with the frameworks themselves, because the differences matter more than most people realize.

ISO 17025:2017 is an international standard for testing and calibration laboratories. It governs technical competence — your equipment, your personnel, your methods, your measurement traceability. An accredited laboratory has demonstrated to an accreditation body (NVLAP, A2LA, UKAS, and their equivalents) that its results are technically valid and reproducible. More than 70,000 testing and calibration laboratories hold ISO 17025 accreditation through ILAC-affiliated bodies worldwide — a number that has grown substantially over the past decade as global supply chains have tightened their supplier qualification requirements.

GLP (Good Laboratory Practice) is a regulatory framework — not a voluntary standard — that governs the conduct of non-clinical safety studies submitted to regulatory authorities. In the United States, FDA's GLP regulations live at 21 CFR Part 58. The OECD GLP Principles, adopted by more than 40 member and non-member economies, extend this globally. GLP is fundamentally about study integrity: who directed the work, whether raw data is attributable, and whether the record has been protected from after-the-fact alteration.

Here is the thing that trips up a lot of labs: these frameworks overlap considerably, but they are asking different questions. ISO 17025 asks, "Are you technically competent?" GLP asks, "Can we trust what you documented?" A laboratory can hold accreditation under ISO 17025 and still produce GLP-deficient studies. The inverse is also true. You can run a GLP-compliant study with a poorly organized technical program that would fail ISO 17025 scrutiny.

The place where both frameworks converge — and where a well-designed QMS does its heaviest lifting — is the documentation and records layer.

Where the Two Frameworks Diverge in Practice

Requirement Area ISO 17025:2017 GLP (21 CFR Part 58 / OECD)
Governing purpose Technical competence and result validity Study integrity for regulatory submissions
Primary audience Accreditation bodies, customers Regulatory agencies (FDA, EPA, OECD monitors)
Personnel requirements Competence, training records, authorized signatories Study Director designation, principal investigator roles
Document control Controlled procedures, version history Master Schedule, protocols, amendments
Data integrity Result traceability, calibration records Raw data attribution, ALCOA+ principles
Equipment Calibration and maintenance records Equipment logs, qualification records
Audits / inspections Internal audits, management review QAU inspections, regulatory authority inspections
Nonconformances Corrective actions, preventive actions Deviations, amendments, final report corrections
Sample handling Sample identification, chain of custody Specimen identification, chain of custody
Subcontracting Approved subcontractors Phase conduct, transfer documentation

What this table shows is that both frameworks are asking you to build the same underlying infrastructure — controlled procedures, credible records, accountable people — but through different lenses and with different regulatory consequences. ISO 17025 non-conformances typically result in accreditation findings or corrective action requests. GLP violations can result in FDA Warning Letters, study rejection, and in serious cases, criminal referrals. The stakes are not symmetric.

Why Most Lab QMS Implementations Fail Both

I've watched two recurring failure modes play out in laboratory quality systems, and they both trace back to the same root cause.

Failure mode one: siloed documentation. The lab has an ISO 17025-compliant quality manual, a separate set of GLP SOPs, and possibly a third body of procedures for clinical testing, environmental sampling, or another regulated activity. These documents were written at different times by different people. They use inconsistent terminology for the same activities. When something goes wrong — a nonconformance, an equipment failure, a data anomaly — the staff member dealing with it has to figure out which system applies, which form to use, which supervisor to notify. That moment of uncertainty is where documentation integrity breaks down.

Failure mode two: records that exist but cannot be reconstructed. Both ISO 17025 and GLP require you to be able to reconstruct what happened. ISO 17025 Clause 7.11 requires retaining records long enough to reproduce results and ensure traceability. GLP requires raw data to be attributable, legible, contemporaneous, original, and accurate — the ALCOA principles, extended in most modern frameworks to ALCOA+. If your records live across a combination of paper logs, Excel spreadsheets, instrument software exports, and email threads, you technically have documentation. But you cannot reconstruct a study in any coherent, auditable sequence. A regulatory inspector or accreditation assessor will find that gap.

UK's MHRA has documented in its data integrity guidance that the majority of data integrity failures they observe are attributable to systemic weaknesses — inadequate controls, poor system design — rather than intentional fraud. That finding should reframe how labs think about compliance. The answer usually isn't more training. It's better system architecture.

What a Lab QMS Needs to Actually Do

A quality management system for laboratory operations has to solve three things at the same time.

Unified Document Control Across Both Frameworks

The same document management environment should govern your method validations (ISO 17025), your study protocols (GLP), your calibration procedures (both), and your personnel training records (both). Not separate folders. Not separate software instances. One controlled document environment where every document has an owner, a revision history, an effective date, and a defined review cycle.

This is operationally difficult because labs grow organically. Procedures get written to satisfy immediate needs rather than to fit a coherent system. A QMS implementation project in a mature lab often means consolidating hundreds of documents that were never designed to live together — many of them overlapping, some of them contradicting each other.

Data Integrity by Design, Not by Policy

ALCOA+ is frequently treated as a training topic. You cover it in onboarding, you put it on a poster in the lab, and you hope people remember it under time pressure.

The problem is that this approach locates the compliance burden in individual behavior rather than in the system. A well-designed QMS removes the manual steps where data integrity failures cluster: transcription between systems, retroactive documentation, unsigned entries, undated corrections. These failures are almost never deliberate. They happen because the system makes it easier to take the shortcut than to do it right.

When the path of least resistance is the compliant path, compliance rates improve without any additional training investment. That's the design target.

Audit-Ready Records at All Times

FDA GLP inspections can be unannounced. Accreditation assessments give you a window, but the volume of records they request can overwhelm a lab that hasn't maintained them continuously. A lab that has to scramble to produce records during an inspection is already in a compromised position — even if the underlying work was sound, the appearance of disorganization undermines credibility with inspectors and assessors.

The QMS should make records production routine rather than exceptional. Every record should be findable, complete, and attributable on any given day, not reconstructed in the week before the assessor arrives.

The Technology Question

The laboratory informatics market — LIMS, ELN, QMS software, calibration management tools — is valued at approximately $3.4 billion globally as of 2024 and growing at roughly 7-8% annually. That investment reflects real demand. Labs are spending heavily on digital infrastructure. But software investment alone doesn't solve the architecture problem.

A LIMS is not a QMS. A LIMS manages sample and test data. A QMS manages the governance layer — the documents, the training, the nonconformances, the audits, the risk assessments. Most labs end up running both, plus separate tools for calibration management, electronic lab notebooks, and instrument data collection. The integration points between these systems are usually where the data integrity problems live.

What AI-powered quality management changes, in my view, is the intelligence layer. Traditional QMS software is essentially a filing system with workflow automation. It can route documents for approval and flag overdue calibrations. What it cannot do well is identify patterns across records — the instrument that keeps generating out-of-tolerance findings before its calibration interval expires, the SOP that shows repeated deviations suggesting it no longer reflects current practice, the analyst whose training status correlates with a cluster of nonconformances. Those patterns are visible in the data, but extracting them manually requires time and analytical capacity that lean lab teams rarely have.

An AI-powered QMS can surface those patterns continuously. It can flag anomalies in study documentation before they become inspection findings. It can help a quality manager understand where the system is under stress, not just where it has already failed. That's a fundamentally different kind of quality support than a checklist, and it's one of the things Nova QMS is built to provide.

Practical Starting Points for Building a Lab QMS

For labs constructing or rebuilding their quality systems, a few things are worth getting right early.

Assess against both frameworks simultaneously. Most gap assessments are run against one standard at a time, which is efficient for the assessor but creates problems downstream. When you assess against ISO 17025 and GLP in parallel, the overlap becomes visible — the places where one well-written procedure satisfies both requirements — and you avoid building redundant systems with conflicting terminology.

Map your data flows before you write procedures. Data integrity problems in most labs trace back to specific handoff points where data moves between systems or between people. Before writing a new SOP, follow your sample data from receipt to final report and document every point where human intervention occurs. Those intervention points are your integrity risk inventory. Address the design before you address the policy.

Connect training records to document versions. One of the cleanest improvements a lab can make is linking training records to specific document versions. When an SOP is revised, the system should automatically identify who is qualified to the previous version and flag that they need qualification on the new one. This is not a complicated workflow, but it requires training and document control to live in the same system — or to be tightly integrated.

Treat nonconformances as signals, not paperwork. The nonconformance system is among the most underused quality tools in laboratory settings. Most labs use it as a corrective action log — a record of what went wrong and what was done. The more valuable use is trending: what does the pattern of nonconformances tell you about where the system is likely to fail next? ISO 17025 Clause 8.7 explicitly requires trending of nonconformances and preventive actions. GLP requires deviations to be evaluated by the Study Director. Both requirements are often satisfied minimally. Opening a finding, closing it, and moving on leaves the signal value of the nonconformance system entirely on the table.

What Auditors Are Actually Looking For

This is worth naming directly because there's sometimes a gap between what the standard says and what an assessor or inspector actually examines closely.

For ISO 17025 assessments, the areas generating the most findings in recent cycles are measurement uncertainty (Clause 7.6), method validation documentation (Clause 7.2), and — increasingly — metrological traceability for digital systems and software-generated records. Assessors are paying closer attention to whether electronic records meet the same integrity standards as paper.

For GLP inspections, FDA and OECD monitoring authorities consistently cite three areas: Study Director oversight and qualification, raw data integrity and attributability, and quality assurance unit independence. The QAU finding is particularly instructive. Many laboratories have a QAU on paper, but the person in that role is also conducting studies, which compromises the independence requirement entirely. That is a structural problem. No SOP resolves a structural problem.

The consistent thread across both frameworks is that auditors are looking for evidence that the system is real — that procedures are actually followed, that records actually reflect what happened, that problems are actually investigated and closed. A QMS designed to generate authentic records continuously is the only QMS that passes inspection reliably.

When Labs Operate Under More Than Two Frameworks

Some laboratories operate under multiple regulatory regimes simultaneously. A contract research organization might hold ISO 17025 accreditation, conduct GLP studies, and also perform clinical testing under CLIA. A cannabis testing lab might operate under state-specific accreditation requirements alongside ISO 17025. An environmental testing lab might hold ISO 17025 accreditation, EPA certification, and state program certification, each with slightly different requirements for equipment qualification or proficiency testing.

In my view, the answer to multi-framework complexity is not a more complex QMS. It's a more principled one. A quality management system built around the underlying disciplines — competence, data integrity, documentation control, and continual improvement — will satisfy multiple regulatory frameworks more reliably than one that tries to map each standard to a separate procedure set. The frameworks converge on the same fundamental question: can you demonstrate that what you say happened, actually happened, reliably and verifiably?

A QMS designed to answer that question is a QMS designed for all of them. That's not a clever framing. It's the simplest path through what looks like a complicated landscape.


Explore how Nova QMS approaches laboratory quality management with AI-powered document control, audit-readiness tools, and real-time compliance monitoring.

Last updated: 2026-07-27

J

Jared Clark

Founder, Nova QMS

Jared Clark is the founder of Nova QMS, building AI-powered quality management systems that make compliance accessible for organizations of all sizes.