ISO 15189 Certification in USA

ISO 15189 is the international standard for quality and competence in medical laboratories, and ISO 15189 certification is the third-party audit that checks your laboratory against it. The current edition is ISO 15189:2022. It was written for the place where a patient sample is received, examined and reported. Not for a factory. Not for a generic office quality system. The whole document follows the sample: how it is ordered, collected, transported, logged, examined, verified, reported and stored.

That focus is why the assessment feels different. An auditor will look at your documents, yes. But the bigger part of the visit is watching whether the people doing the work can actually do it, and whether you can prove your results are right. Most laboratories underestimate that second half.

Asked for ISO 15189 certification and not sure where to begin? Start with the certification process, then talk to IAS about scope and timing for your lab. If you are weighing several standards at once, the range of ISO certification services is a useful map.

What ISO 15189 certification covers

The standard is built in two halves that work together.

The management requirements cover what a quality lead will recognize: document and record control, nonconformity handling, corrective action, internal audit, management review, complaints, purchasing, risk and improvement.

The technical requirements are what separate this standard from a general quality system. Personnel competence. Accommodation and environmental conditions. Equipment, reagents and consumables. Pre-examination processes. Examination processes, including validation and verification. Measurement uncertainty where it applies. Quality control. External quality assessment. Reporting and release of results.

A certificate covers a defined scope naming the laboratory, the sites and usually the disciplines in use. It does not silently cover a new site, a new analyzer or a discipline you added last quarter. If you open a satellite draw station or bring a new platform online, that change belongs in front of your auditor.

Who IAS is, and who accredits IAS

This matters more than most pages admit, so here it is plainly.

IAS is a certification body. IAS audits your laboratory against ISO 15189 and, if the evidence supports it, issues a certificate. IAS is accredited by UQAS. UQAS is the accreditation body that assesses IAS.

That accreditation is an assessment of IAS — of how IAS selects and trains auditors, how it decides scope, how it makes certification decisions, how it handles appeals and impartiality. It is not an endorsement of your laboratory, your results or your management. No accreditation body has looked at your bench. When you hold a certificate issued by IAS, what you can honestly say is that an accredited certification body audited you and issued a certificate within a stated scope.

The accreditation chain for this scheme: UQAS accredits IAS as a certification body, IAS audits the medical laboratory against ISO 15189, and the labo
The accreditation chain for this scheme: UQAS accredits IAS as a certification body, IAS audits the medical laboratory against ISO 15189, and the laboratory holds a certificate for a defined scope.

The diagram above shows the chain in one picture. Each arrow is an assessment of the party below it, and each stops where it stops. If you want the background on how conformity assessment bodies are structured, the overview of certification bodies and the piece on what accreditation actually means cover it without jargon. You can also read about IAS directly, or work through the IAS articles on standards and auditing at your own pace.

Certification to the standard and laboratory accreditation are not the same thing

This page uses the word “certification” throughout, because that is what clients ask for and that is what IAS issues. It is worth one honest paragraph on what that word carries.

In the conformity assessment world, laboratories are usually accredited to ISO 15189 by a national or regional accreditation body, which assesses the laboratory’s technical competence test by test and publishes a formal scope of accreditation. Certification to ISO 15189 by a certification body is a different service. It is a third-party audit of your laboratory against the same standard, resulting in a certificate for the scope agreed with the certification body. The requirements you are audited against come from the same document. The route, the assessing organization and the standing of the output differ. If a payer, a hospital network, a tender or a regulator has asked you specifically for laboratory accreditation, a certificate is not an automatic substitute, and you should check the exact wording of the request before you commit. Ask them what document they need to see. It takes one email and saves a great deal of rework. Where medical laboratory certification is what the requesting party means, the route below is the one that applies.

QuestionCertification to ISO 15189Laboratory accreditation
Who performs the assessmentA certification body, such as IASA national or regional accreditation body
What is assessedYour laboratory against the ISO 15189 requirementsYour laboratory against the same requirements, usually test by test
What is issuedA certificate naming a defined scopeA schedule of accreditation naming specific examinations
How the assessor is overseenIAS is accredited by UQASThe accreditation body operates under its own peer arrangements
When it fits your situationThe request says “certified to ISO 15189” or names a certification bodyThe request names accreditation, or names an accreditation body by name
What to do if unsureAsk the requesting party for the exact wording they needAsk the same question before starting either route

Competence is assessed, not just the quality system

This is the part laboratories underestimate.

A general quality standard asks whether you defined competence and kept training records. ISO 15189 goes further. It asks whether each person is competent for the examinations they perform and sign out, and whether you can show how you decided that.

In practice an auditor will pick a technologist and follow them. What are they authorized to perform? Who authorized them? On what evidence — direct observation, a blind sample, a review of their results, a written test? When was competence last reassessed? What happens when a person returns after a long absence, or when a method changes?

Supervision of trainees gets tested the same way. So does the authorization of anyone who interprets results or adds a comment to a report. If your competence file is a stack of attendance sheets, expect a finding. Attendance proves someone sat in a room. It does not prove they can run the assay.

Training helps, and it is legitimate evidence. ISO 15189 internal auditor training prepares the people who will audit your own processes. ISO 15189 lead auditor training suits quality leads who will run the program. Both sit alongside the wider ISO lead auditor training programme and the wider ISO training catalogue, and the course dates and training schedule tell you when the next sessions run. Neither replaces bench competence assessment.

The testing path, end to end

ISO 15189 follows the sample, and so does the audit.

Pre-examination. Request forms and electronic orders. Patient identification. Collection instructions, tubes and order of draw. Labeling at the point of collection. Transport time and temperature. Acceptance and rejection criteria.

Examination. Verification of a method you bought, or validation of one you developed or modified. Calibration. Internal quality control rules and what you do when a rule fails. Measurement uncertainty where it is relevant. Reagent lot changes. Equipment maintenance and function checks.

Post-examination. Result review and authorization. Reference intervals and where they came from. Critical result identification and the call to the clinician. Amended reports and how a corrected result is flagged. Turnaround time monitoring. Sample retention.

Most first-audit findings sit in pre-examination and post-examination, not in the analyzer. Rejected samples with no root cause review. Critical calls with no record of who was told and when. Reference intervals carried over from a previous instrument without verification.

What a strong file looks like, and what auditors usually find

AreaWhat a strong file looks likeWhat auditors commonly find instead
CompetenceNamed authorizations per examination, dated observation records, periodic reassessmentAttendance sheets and a signed job description
Method verificationPrecision, accuracy and reportable range data with acceptance criteria set in advanceVendor claims filed as if they were your own verification
Internal quality controlDocumented rules, evidence that failures stopped reporting, closed investigationsQC charts printed and filed with no action on out-of-control points
External quality assessmentEnrollment across the reported menu, investigation of every poor score, corrective action closedEnrollment that covers only part of the reported test menu
Critical resultsA defined list, a recorded call with time, recipient and read-backA policy that exists but no records that it was followed
EquipmentMaintenance, function checks and calibration traceable to the specific instrumentA shared logbook with no serial numbers and gaps in dates
Amended reportsClear flagging, notification of anyone who received the original, trend reviewSilent corrections in the LIS with no audit trail
Point-of-care testingIncluded in scope, same competence and QC discipline as the main labTreated as outside the quality system because “it is nursing”

Who does what during ISO 15189 certification

ActivityYour laboratoryIAS
Define the scope requestLists sites, disciplines and examinationsReviews it and confirms what can be audited
Documented systemWrites and maintains itReviews it before the on-site audit
Internal audit and management reviewCompletes both before the auditChecks that both happened and had teeth
On-site assessmentProvides access, records, staff and witnessingAudits against ISO 15189 and records findings
NonconformitiesInvestigates root cause and correctsReviews the evidence and decides acceptance
Certification decisionNot involvedMade by people independent of the audit team
Certificate and scopeUses it within the stated scopeIssues and maintains it
Logo and claim wordingFollows the published rulesPublishes the logo usage guideline and monitors misuse

The ISO 15189 certification pathway, from application to certificate

The ISO 15189 certification pathway for a medical laboratory: application and scope agreement, documentation review, stage one readiness assessment, t
The ISO 15189 certification pathway for a medical laboratory: application and scope agreement, documentation review, stage one readiness assessment, the on-site audit, closure of nonconformities, an independent certification decision, and issue of the certificate.

None of these steps are a formality.

Application and scope agreement come first. Be honest about sites, shifts and point-of-care locations. A scope written to look tidy causes problems later.

Documentation review checks that a system exists and addresses the standard. A readiness assessment then looks at whether you are actually prepared — whether internal audits have run, whether management review happened, whether EQA covers the menu you report.

The main audit is the long one. Expect sample tracing, bench observation, staff interviews, record sampling and equipment checks across shifts if you run them. Findings are written up with the evidence attached. You investigate, correct, and show what you did — not just what you promised to do.

The certification decision is made by people who did not perform the audit. That separation is one of the things UQAS assesses when it accredits IAS. The general ISO audit procedure and the ISO certification process cover the mechanics in more detail.

Life after ISO 15189 certification

The certification cycle over three years: initial certification, surveillance audits at planned intervals to confirm the system is still working, and
The certification cycle over three years: initial certification, surveillance audits at planned intervals to confirm the system is still working, and recertification before the certificate expires.

Certification is not a one-time event. The certificate runs for a cycle, with surveillance audits at planned intervals and a recertification audit before it expires.

Surveillance is where laboratories lose ground. The pattern is familiar: a strong push before the first audit, then drift. Internal audits slip. Management review becomes a single slide. Competence reassessment falls behind when the roster changes. New analyzers arrive and nobody tells the certification body. Then surveillance arrives and the same findings reappear with a year of history behind them.

The laboratories that hold up treat internal audit as a real program with trained auditors, not a favor someone does in December. Building that capability in-house is the point of internal auditor training. Laboratories that also hold a general quality system often send the same people to ISO 9001 internal auditor training, so one audit team covers both programs and medical laboratory quality does not slip between them.

What usually goes wrong

Verification done by copying the insert. A manufacturer’s performance claims are their data. You need your own, on your instrument, with your staff and your reagent lots.

EQA that does not match the menu. If you report it, you need a scheme for it or a documented alternative. Enrollment is easy to compare against the reported menu, so gaps are found fast.

Root cause that names a person. “Technologist error” is not a root cause. It is where the investigation stopped. Auditors read that phrase as a signal to look harder.

Point-of-care left outside. Glucose meters on wards, blood gas analyzers in the ICU, rapid tests in clinics. If they sit under the laboratory director, they are in scope.

Amended reports with no trail. A result changed in the LIS with no record of who changed it, when, why, and whether the clinician who acted on the original was told.

Reading a medical laboratory certificate correctly

A certificate says that IAS audited your laboratory against ISO 15189, on sampled evidence, within a stated scope, on stated dates, and that the certification decision was positive.

It does not mean every examination you perform was individually witnessed. Auditing works on sampling. It does not mean every result you have released was correct, or that every future result will be. It is not a guarantee of clinical outcome, turnaround time or any performance level. It is not a warranty on your instruments or suppliers. It does not certify individual staff. And it says nothing about activity outside the scope on the certificate.

What it does give you is a documented, third-party check that your quality system and competence controls were working when they were examined, and a cycle that keeps checking.

A note on law and regulation

This page makes no claim about the law in any country, state or jurisdiction, and nothing here is legal advice. Requirements for clinical laboratories vary by location, payer, program and type of testing, and they change. Do not treat certification to ISO 15189 as satisfying any statutory or licensing obligation. Your legal duties are a matter for your own advisers, your compliance function and the bodies that regulate your laboratory.

✓ IAS is accredited by UQAS | ✓ Certification decisions independent of the audit team | ✓ Scope written to match your real sites and menu | ✓ Auditors who understand laboratory work

Getting your laboratory ready

Start with a gap assessment against the standard, clause by clause, with evidence named for each one. Fix the technical gaps first, because they take longest: verification data, competence records, EQA enrollment, uncertainty where it applies.

Run a real internal audit with people trained to do it, and let the findings be uncomfortable. Hold a management review that looks at EQA performance, complaints, nonconformities, turnaround time and resources, and record the decisions. Then apply.

Few laboratories hold only one thing. Calibration and testing outside clinical examination often sits under ISO 17025, and labs inside device manufacturers may also work under ISO 13485. Where these overlap, integrate the shared parts — document control, internal audit, corrective action, management review — and keep the technical requirements separate. Do not force laboratory competence evidence into a generic system certification template. It never fits.

The same is true of the systems that surround the bench. A laboratory inside a pharmaceutical manufacturer is often audited against cGMP requirements as well, with GMP training for the staff who work to them. Biosafety, sharps and chemical handling tend to be managed under ISO 45001 occupational health and safety; clinical waste streams under ISO 14001 environmental management; and access control over the LIS and patient records under ISO 27001 information security. Share the document control and audit machinery across them. Keep the laboratory technical evidence its own.

Useful next steps: the ISO certification requirements overview and the frequently asked questions page.

Frequently asked questions

Is ISO 15189 certification the same as laboratory accreditation?

No. Certification is issued by a certification body after an audit against the standard. Laboratory accreditation is granted by an accreditation body, usually with a published scope listing specific examinations. If the party asking you named accreditation, confirm what they need before you start.

Who accredits IAS?

IAS is accredited by UQAS. That accreditation assesses how IAS runs its certification work — auditor competence, impartiality, scope decisions and the certification decision itself. It is an assessment of IAS, not of any laboratory IAS certifies.

Can we use ISO 9001 instead of ISO 15189 certification?

Not for the technical side. ISO 9001 does not address examination validation, quality control, measurement uncertainty, external quality assessment or bench competence. Many laboratories run both and share the common processes, and ISO 9001 certification is a separate audit against a separate standard.

Does point-of-care testing have to be included?

If it operates under the laboratory director’s responsibility and you want it covered, it must be in scope. Testing left out of scope is not covered by the certificate. Decide deliberately rather than by omission.

What happens if the auditor raises nonconformities?

You investigate the cause, correct the problem, and submit evidence. IAS reviews that evidence before a certification decision is made. Findings are normal. A first audit with none is unusual.

How much documentation do we actually need?

Enough to show how the work is controlled and to reconstruct a result’s history. Procedures staff actually follow beat a thick manual nobody opens. Auditors compare what is written to what happens at the bench.

Do our technologists need external training?

Not for bench competence — that is assessed in-house against your own criteria. Training matters for the people running the quality program and performing internal audits.

What if we add a new analyzer or a new site after ISO 15189 certification?

Tell IAS. A significant addition may need assessment before it is covered. Using the certificate for work outside the stated scope is a misuse of the mark.

Can we say we are accredited once we hold the certificate?

No. You hold certification issued by IAS, and IAS is accredited by UQAS. Describe it that way. The logo usage guideline sets out what you may and may not claim.

What is the most common reason a laboratory is not ready?

Competence evidence. The quality manual is usually presentable. The proof that each person can perform and release the examinations they sign out is usually thin.

Ready to scope an ISO 15189 audit for your laboratory? Contact IAS with your sites and test menu, or review the certification process first. If ISO 15189 certification is one of several routes you are considering, the IAS associate partner network and the IAS website list what else is available.