Preparing instruments for an ISO 17025 or ISO 9001 audit
Checklist for the instrument side of an ISO/IEC 17025 or ISO 9001 audit: inventory, status, certificates, intervals and out-of-tolerance records.
Also available in: Deutsch
Audits are won or lost on evidence, and the instrument side produces more findings than almost any other area. Not because companies do not calibrate, but because the proof is scattered: a spreadsheet here, a folder of PDFs there, a label on the device that says something else. This post is a checklist for the instrument side of an ISO/IEC 17025 or ISO 9001 audit: what the auditor will ask for, where the typical gaps are, and how to have the answer ready in minutes rather than days.
What the two standards actually require
The requirements are shorter than their reputation suggests.
ISO 9001:2015, clause 7.1.5 covers monitoring and measuring resources. Where traceability is a requirement or a customer expectation, instruments must be calibrated or verified at specified intervals against standards traceable to international or national standards, identified so their status can be determined, and protected from adjustments or damage that would invalidate the result. If an instrument turns out to be unfit, the organisation must determine whether previous results are affected and act on it. Evidence of fitness for purpose must be retained.
ISO/IEC 17025:2017, clause 6.4 is written for laboratories and goes further. Equipment must be verified before use, calibrated where accuracy or uncertainty affects the validity of results, labelled with its calibration status including the due date, and taken out of service when defective, with the effect of the defect examined. The laboratory needs a calibration programme that is reviewed and adjusted, intermediate checks where needed, and detailed records for each item: identity including software and firmware, manufacturer and serial number, location, calibration dates, results, adjustments, acceptance criteria, due dates, maintenance and any damage. Clause 6.5 adds metrological traceability as a requirement in its own right.
If you are certified to IATF 16949 or ISO 13485, the same checklist applies. Both build on the ISO 9001 requirements for measuring equipment; IATF 16949 adds its own demands on calibration records and measurement system analysis, and ISO 13485 carries an equivalent clause for monitoring and measuring equipment.
All of these standards point to the same chain of evidence. An auditor follows it instrument by instrument.
The checklist
Work through the list for a sample of instruments before the audit. If you cannot answer a point in two minutes, that is where a finding would come from.
1. One complete inventory
Every instrument that influences a measurement result or a conformity decision appears on one list, with a unique identifier, location, responsible person and current status. The auditor will pick an instrument from the shop floor and ask to see its entry. If the device is not on the list, nothing else matters.
Decide explicitly which instruments are excluded as "indication only" and label them, so the exclusion reads as a decision rather than an oversight.
2. The status of every instrument
For each entry: is the calibration valid today, when is it due, and does the label on the device agree with the record? Overdue instruments are the most common finding of all, and the second most common is a label that says one date while the certificate says another.
This is where reminders earn their keep. Instrument management such as the digical app sends an e-mail before a certificate expires, so overdue status is caught by the system rather than by the auditor.
3. Certificates at hand, and readable
The auditor will open certificates and look for a traceability statement, the measurement uncertainty, the accreditation symbol where applicable, and a conformity decision if one was made. A missing uncertainty or an unclear traceability chain is a finding even when the instrument is fine.
If your laboratories deliver digital calibration certificates, validate them on receipt. A DCC checked against the official PTB schema proves that the file is complete and unaltered, and the measured values can be compared with the previous certificate without retyping. The DCC Viewer does this for a single file; the digical app does it for every upload and keeps the original downloadable.
4. The right calibration scope
A valid certificate is not automatically the right one. Check that the calibrated range, the measurement points and the tolerance match how the instrument is actually used. A calliper calibrated at three points up to 150 mm says nothing about a measurement at 280 mm, and a certificate without a conformity decision leaves the pass or fail judgement to you. The common pattern is that the scope was defined once, years ago, and has been reordered unchanged ever since. Review it with your laboratory whenever the instrument's use changes, and record that review.
5. Intervals with a reason
Neither standard dictates how often to calibrate, so the auditor asks why you chose your interval. "Twelve months, because that is what we have always done" is a weak answer. "Twelve months, because the drift over the last three certificates stayed within a quarter of the tolerance" is a strong one. That answer needs the calibration history. If only the latest certificate is on file and the earlier ones were discarded, the interval cannot be justified from data, and the auditor will notice. Keep every certificate with the instrument record, note the reasoning for the interval there, and for ISO/IEC 17025 show that the programme was reviewed.
6. Out-of-tolerance results handled and documented
When a certificate shows an instrument was outside tolerance, there must be a record of what happened next: which measurements since the last calibration could be affected, whether products or results were reassessed, whether customers were informed, and who decided. The decision can be "no impact"; what counts is that it was made and written down.
7. Handling, intermediate checks and defects
For laboratories: a procedure for handling, transport, storage and use; intermediate checks between calibrations where confidence requires them; and evidence that defective instruments were taken out of service and the effect of the defect examined. For ISO 9001 companies the equivalent question is simpler: how do you protect instruments from unauthorised adjustment, and what happens when one is dropped?
8. Records that match clause 6.4.13
If you work under ISO/IEC 17025, compare your record for one instrument against the list in clause 6.4.13 item by item. Software and firmware versions and acceptance criteria are the fields most often missing.
Audit day: show it in minutes
Preparation decides whether the audit is a conversation or a search. The difference on the day comes from three abilities:
- Filter the inventory live. Show every instrument due in the next 30 days, every overdue instrument, every instrument at a given location.
- Jump from instrument to certificate and back. The auditor names a device; you open its record, its current certificate and its history in one place.
- Export the evidence. A report of the inventory with status and due dates, produced on the spot, closes most questions before they are asked.
Together these turn a spreadsheet-and-folder exercise into a few clicks. The digical app is built around exactly this chain: instruments linked to their certificates, validated DCCs with the original kept, expiry reminders and reports. Every plan includes the full feature set; see the pricing page for details.
Before the audit: a one-hour rehearsal
Pick five instruments at random. For each, run the eight points above with a stopwatch. Anything that takes longer than two minutes to answer is your preparation list. Done a month before the audit, this exercise finds the same gaps the auditor would, with time left to close them.
Frequently asked questions
Does every instrument in the building need a calibration certificate?
No. Both standards ask for calibration where the measurement affects the validity of results or product conformity. Instruments used for indication only can be excluded, but the exclusion must be a documented decision and the instrument should be labelled accordingly.
Is a manufacturer's certificate enough as evidence of traceability?
Only if it shows an unbroken chain to national or international standards, usually with a traceability statement and measurement uncertainty. A certificate from an accredited laboratory makes this straightforward; a plain factory test report usually does not.
A certificate expired last week. Is that a non-conformity?
An overdue calibration becomes a finding when nobody noticed. If the overdue status was detected, the instrument was blocked or assessed, and the recalibration is ordered, the auditor sees a controlled process. Document that decision before the audit.
Can we set calibration intervals ourselves?
Yes. Neither standard prescribes intervals. You define them and must be able to justify them, for example from the drift seen in successive certificates, manufacturer recommendations and how critical the measurement is. ISO/IEC 17025 additionally asks for the programme to be reviewed.
What is the difference between ISO 9001 and ISO/IEC 17025 on this point?
ISO 9001 clause 7.1.5 covers monitoring and measuring resources for any company and focuses on fitness for purpose, traceability and action when an instrument is found unfit. ISO/IEC 17025 clause 6.4 is written for laboratories and is more detailed, with explicit record requirements, intermediate checks and a reviewed calibration programme.