ISO/IEC 17043:2023 readiness checklist
Every clause of ISO/IEC 17043:2023, in plain English, with the question an assessor tends to open with. Free, no sign-up, nothing to download. Use it to find the gaps while you still have time to close them.
What this is, and what it isn't. This is our own plain-language summary of what each clause is driving at — written for the people doing the work, not for lawyers. It is not the standard, does not reproduce it, and is no substitute for the published text. Buy the standard from BSI or ISO; you need the actual wording to be accredited against it. We're not affiliated with ISO or UKAS.
How to use it
Work down the questions and, for each one, ask two things: can we answer it, and can we show the evidence today. Those are different, and the second is where assessments go wrong. Most laboratories know how they meet a clause; what they can't always do is put a hand on the current, in-date record that proves it.
Mark anything you can answer but not evidence. That list is your real preparation plan.
If you only have an afternoon
Clause 7 is one round, end to end: design, items, analysis, reporting. An assessor samples a few schemes per visit and each has to stand alone, so weakness in scheme design at 7.1 propagates into everything downstream. If you are short of time, start there.
4 General requirements
Overarching obligations on impartiality and confidentiality.
| Clause | What it's asking for | What an assessor tends to ask |
|---|---|---|
| 4.1 Impartiality |
Provider must identify and manage risks to impartiality on an ongoing basis. | What relationships or revenue could influence a result, and how do you show they don't? |
| 4.2 Confidentiality |
Participant and scheme information must be protected and access controlled. | Who can see participant identities and results, and how is that access restricted and logged? |
5 Structural requirements
Legal responsibility, defined organisation, and management of scheme activities.
6 Resource requirements
People, facilities, equipment and external services needed to run schemes.
| Clause | What it's asking for | What an assessor tends to ask |
|---|---|---|
| 6.1 General |
Resources needed to operate schemes competently are identified and available. | What resources does each scheme need, and how do you confirm they're in place before a round? |
| 6.2 Personnel |
Competence requirements defined, records of qualification, training and authorisation maintained. | How do you define and evidence competence for each role involved in a scheme? |
| 6.3 Facilities & environmental conditions |
Premises and environmental conditions must not compromise item quality or the validity of results. | Which environmental conditions could affect item quality, and how are they controlled and recorded? |
| 6.4 Equipment |
Equipment is fit for purpose, maintained, and calibrated where results depend on it. | Which results depend on equipment, and how do you show it's maintained and fit for use? |
| 6.5 Metrological traceability |
Where applicable, measurement results are traceable to appropriate metrological references. | Do your measurands need metrological traceability, or are assigned values consensus/reference-based — and how is that justified per scheme? |
| 6.6 Externally provided products & services |
Externally sourced products and services affecting scheme quality are evaluated and controlled. | Which outsourced products or services affect scheme quality, and how are those suppliers evaluated? |
7 Process requirements
The end-to-end operation of a proficiency testing scheme.
| Clause | What it's asking for | What an assessor tends to ask |
|---|---|---|
| 7.1 Scheme design |
Statistical design, item type, measurand, and evaluation approach defined per scheme. | For each scheme, what's the statistical design, measurand and evaluation approach, and who signed it off? |
| 7.2 Provision of PT items |
Preparation, packaging and distribution of PT items preserves their integrity and suitability. | How do you ensure items reach participants intact and fit for testing? |
| 7.3 Homogeneity & stability |
Assessment that items are sufficiently homogeneous and stable for their intended use. | How do you demonstrate each batch is homogeneous and stable enough for its intended use? |
| 7.4 Statistical design & data analysis |
Assigned values, standard deviation for assessment, and performance scores determined by documented methods. | How are assigned values and assessment standard deviations determined, and are the methods documented? |
| 7.5 Evaluation of performance |
Participant performance is evaluated against criteria defined before the round. | Were performance criteria set before the round, and applied consistently? |
| 7.6 Reports |
Reports are clear, timely, and give participants what they need to interpret their results. | Do reports give participants what they need to interpret their results, and go out on time? |
| 7.7 Communication with participants |
Instructions, changes and scheme information reach participants in a controlled way. | How do scheme changes and instructions reach participants in a controlled way? |
| 7.8 Handling complaints & appeals |
A documented process resolves complaints and appeals fairly and traceably. | How is a complaint or appeal logged, handled fairly, and closed traceably? |
8 Management system requirements
The quality-management machinery that keeps everything above working.
| Clause | What it's asking for | What an assessor tends to ask |
|---|---|---|
| 8.1 Options |
A management system is implemented, either directly or via an equivalent certified system. | Are you running your own management system or leaning on an equivalent certified one — and is that decision documented? |
| 8.2 Management system documentation |
Policies and objectives are documented, communicated and understood. | Are your quality policy and objectives documented and understood by staff? |
| 8.3 Control of documents |
Documents are approved, versioned, and available where the work happens. | How does someone know they're using the current version of a procedure? |
| 8.4 Control of records |
Records stay legible, retrievable and intact for their defined retention periods. | How do you keep records legible, retrievable and intact for their whole retention period? |
| 8.5 Actions to address risks & opportunities |
Risks and opportunities affecting scheme validity are identified and acted on. | How do you identify and act on risks to scheme validity? |
| 8.6 Improvement |
Improvement opportunities are actively sought, evaluated and implemented. | How do you find and act on opportunities to improve — not only fix problems? |
| 8.7 Corrective actions |
Nonconformities trigger correction, root-cause analysis and effectiveness checks. | When something goes wrong, how do you get to root cause and confirm the fix worked? |
| 8.8 Internal audits |
Planned internal audits confirm the management system is followed and remains effective. | How do you check the system is actually being followed, and act on what you find? |
| 8.9 Management reviews |
Management periodically reviews the system for suitability, adequacy and resourcing. | How does management periodically confirm the system is adequate and resourced? |
The part a checklist can't do
A checklist tells you where you stood on the day you filled it in. It doesn't tell you that the competence record you evidenced in March expired in August, or that the procedure you mapped to a clause last year was superseded and nobody re-mapped it. That drift between assessments is what turns a clean visit into a finding at the next one.
That's the problem ClauseMap exists for: your clauses mapped to your controls, your controls to your evidence, and the evidence ageing visibly so you find out before an assessor does.
See it working. Open the demo — a real, read-only account with a working readiness dashboard and deliberate gaps in it. No sign-up, no email address, nothing to install. About two minutes.
Your evidence stays yours. ClauseMap holds quality records — procedures, certificates, competence files. It holds no patient or participant data, and never asks for any.