ISO 15189:2022 readiness checklist

Last updated 4 September 2026 · Medical laboratories · UKAS assessment preparation

Every clause of ISO 15189:2022, in plain English, with the question an assessor tends to open with. Free, no sign-up, nothing to download. Use it to find the gaps while you still have time to close them.

What this is, and what it isn't. This is our own plain-language summary of what each clause is driving at — written for the people doing the work, not for lawyers. It is not the standard, does not reproduce it, and is no substitute for the published text. Buy the standard from BSI or ISO; you need the actual wording to be accredited against it. We're not affiliated with ISO or UKAS.

How to use it

Work down the questions and, for each one, ask two things: can we answer it, and can we show the evidence today. Those are different, and the second is where assessments go wrong. Most laboratories know how they meet a clause; what they can't always do is put a hand on the current, in-date record that proves it.

Mark anything you can answer but not evidence. That list is your real preparation plan.

If you only have an afternoon

Clause 7 covers the examination pathway end to end, and it is where the largest share of findings tends to land — much of it in pre-examination, where the sample is out of your hands and the accountability is not. If you are short of time, start at 7.2 and work outwards.

4  General requirements

Impartiality, confidentiality, and obligations owed to patients.

ClauseWhat it's asking forWhat an assessor tends to ask
4.1
Impartiality
Risks to impartial examination and reporting are identified and managed on an ongoing basis. What relationships, targets or funding could influence a reported result, and how do you show they do not?
4.2
Confidentiality
Patient and laboratory information is protected, with access controlled and disclosure governed. Who can see identifiable patient data, how is that access restricted, and what happens when disclosure is legally required?
4.3
Requirements regarding patients
Laboratory practice puts patient welfare and interests first across the whole examination pathway. How does the laboratory demonstrate that patient interest, not convenience, drives its practice?

5  Structural and governance requirements

Legal identity, the director, defined activities, authority and risk.

ClauseWhat it's asking forWhat an assessor tends to ask
5.1
Legal entity
The laboratory is a legal entity, or a defined part of one, legally responsible for its activities. Which legal entity carries responsibility for laboratory activities, and where is that stated?
5.2
Laboratory director
A named director is competent for the role, carries defined responsibilities, and may delegate them explicitly. Who is the director, what evidences their competence, and which duties are delegated to whom in writing?
5.3
Laboratory activities
The scope of activities is defined, conforms to requirements, and includes advice to users. What is in scope, and how do you advise clinicians on test selection and interpretation?
5.4
Structure and authority
Organisational structure, reporting lines and quality management responsibilities are defined. Draw the structure: who reports to whom, and where does quality management authority sit?
5.5
Objectives and policies
Objectives and policies are set, aligned to patient need, and reviewed. What are your quality objectives, how were they chosen, and when did you last review them?
5.6
Risk management
Risks to patients arising from laboratory activities are identified, evaluated and controlled. Which risks to patients have you identified, and what controls exist for the highest of them?

6  Resource requirements

People, facilities, equipment, calibration, reagents, agreements and suppliers.

ClauseWhat it's asking forWhat an assessor tends to ask
6.1
General
The resources needed to run examinations reliably are determined and provided. What resources does each examination need, and how do you confirm they are in place?
6.2
Personnel
Competence requirements are defined, and qualification, training, authorisation and continuing development are recorded. For each role, how is competence defined, assessed, authorised and kept current?
6.3
Facilities and environmental conditions
Premises, storage, personnel and collection facilities do not compromise result validity or safety. Which environmental conditions could affect results, and how are they controlled and recorded?
6.4
Equipment
Equipment is selected, accepted, instructed, maintained, repaired and recorded, with adverse incidents reported. Which results depend on which equipment, and how do you show it is fit for use today?
6.5
Equipment calibration and metrological traceability
Calibration is planned and results are traceable to appropriate references where applicable. Which measurands need traceability, to what reference, and how is the calibration chain evidenced?
6.6
Reagents and consumables
Reagents and consumables are received, stored, accepted, used and recorded so they cannot degrade a result. How do you know a reagent in use today is within date, correctly stored and verified for use?
6.7
Service agreements
Agreements with users, and with point-of-care operators, are defined and reviewed. What have you agreed with requesting clinicians and POCT operators, and when was it last reviewed?
6.8
Externally provided products and services
Referral laboratories, consultants and suppliers are selected, reviewed and approved. Which referral labs and suppliers affect your results, and how were they evaluated and approved?

7  Process requirements

The examination pathway end to end, plus data, complaints and continuity.

ClauseWhat it's asking forWhat an assessor tends to ask
7.1
General
Processes across the examination pathway are defined and controlled. Which documented processes cover the pathway, and who owns each?
7.2
Pre-examination processes
Information for users, requesting, collection, transport, receipt, handling and storage before examination. How do you control what happens to a sample before it reaches the bench — and who is accountable outside the lab?
7.3
Examination processes
Verification and validation of methods, measurement uncertainty, reference intervals, documented procedures and ongoing validity. For one method: was it verified or validated, what is its uncertainty, and how do you show results stay valid?
7.4
Post-examination processes
Reporting of results and the handling of samples after examination. What does a report contain, who may authorise it, and how are critical results escalated?
7.5
Nonconforming work
Work that does not conform is identified, acted on, and the impact on patients evaluated. Show a recent nonconformity: how was patient impact assessed and what was done about it?
7.6
Control of data and information management
Information systems are authorised, managed, protected, and covered by downtime and off-site arrangements. What happens to reporting when the LIMS is down, and who has authority over system changes?
7.7
Complaints
Complaints are received, handled and resolved through a defined process. How does a complaint reach you, who resolves it, and how is the complainant told the outcome?
7.8
Continuity and emergency preparedness
Plans exist to continue or safely suspend service through disruption. What is your plan if the laboratory becomes unavailable, and when was it last tested?

8  Management system requirements

Documentation, records, risk, improvement, nonconformity, evaluation and review.

ClauseWhat it's asking forWhat an assessor tends to ask
8.1
General requirements
A management system is established that supports and sustains the other requirements. Which option have you taken for management system conformity, and where is that recorded?
8.2
Management system documentation
Policy, objectives, commitment and documentation are defined and accessible to personnel. Where is the quality policy, and can staff on shift actually reach the documents they need?
8.3
Control of management system documents
Documents are approved, versioned, distributed and withdrawn under control. Pick a procedure: who approved this version, and how do you know no obsolete copy is in use?
8.4
Control of records
Records are created, amended traceably, and retained for defined periods. How is an amended record shown to have been amended, by whom, and when?
8.5
Actions to address risks and opportunities
Risks and improvement opportunities are identified and acted upon. What did you identify, what did you do, and how do you know it worked?
8.6
Improvement
Continual improvement is pursued, informed by feedback from patients, users and personnel. What feedback have you gathered, and name one change it caused.
8.7
Nonconformities and corrective actions
Nonconformities trigger action, effectiveness is checked, and records are kept. Show a corrective action closed in the last year: how was effectiveness verified rather than assumed?
8.8
Evaluations
Quality indicators and internal audits evaluate whether the system performs. Which quality indicators do you track, and what did your last internal audit actually find?
8.9
Management reviews
Management review takes defined inputs and produces decisions and actions. What went into the last management review, and what changed because of it?

The part a checklist can't do

A checklist tells you where you stood on the day you filled it in. It doesn't tell you that the competence record you evidenced in March expired in August, or that the procedure you mapped to a clause last year was superseded and nobody re-mapped it. That drift between assessments is what turns a clean visit into a finding at the next one.

That's the problem ClauseMap exists for: your clauses mapped to your controls, your controls to your evidence, and the evidence ageing visibly so you find out before an assessor does.

See it working. Open the demo — a real, read-only account with a working readiness dashboard and deliberate gaps in it. No sign-up, no email address, nothing to install. About two minutes.

Your evidence stays yours. ClauseMap holds quality records — procedures, certificates, competence files. It holds no patient or participant data, and never asks for any.