How to Prepare for an ISO/IEC 17025 Surveillance Audit

ISO/IEC 17025:2017 surveillance audits follow a set shape. Still, they are hard on detail. The assessor checks that your quality system runs the way it was built. They also check that the work you ship fits your scope of accreditation. Most findings land in four spots: scope drift, traceability records, decision rule consistency, and corrective action closure. This article walks a quality manager through the calibration side of that prep.

What surveillance assessors review in the calibration program

A surveillance audit is narrower than a first assessment. It is just as strict. The review runs in four stages.

First, scope verification. The assessor confirms your work matches your written scope of accreditation. Any job outside that scope must be flagged and handled the right way.

Second, traceability evidence review. The assessor takes a sample of certificates and traces each one back through your records. They look for reference standards, uncertainty math, and traceability statements that are complete and match.

Third, decision rule and uncertainty review. The assessor checks that you apply decision rules the same way each time. They also check that your measurement uncertainty math meets ILAC P14 rules.

Fourth, corrective action closure. The assessor looks at open items from past audits. They check that you found the root cause. They also check that you ran the follow-up test to prove the fix worked.

A surveillance audit goes deep on a few jobs, not wide across the whole scope. Findings show up in the same four spots each time. That makes prep work easy to plan.

Common findings against ISO/IEC 17025:2017 clauses 6 and 7

The same patterns come up again and again. A seasoned assessor spots them fast:

  • Scope drift. Jobs get run outside the written scope, and the certificate does not say so. That is a finding under clause 7.8, reporting of results.

  • Traceability gaps. A standard’s calibration record leaves out the measurement uncertainty. Your own math then rests on a gap. That is a finding under clause 6.5, metrological traceability.

  • Decision rule inconsistencies. Two certificates for like work use two different rules, with no reason on file. Under clause 7.8.6, you must apply the rule the same way each time, or defend why you did not.

  • Corrective action backlog. A past nonconformity was closed on paper, with no proof the root cause was fixed. The same thing shows up again. That is a repeat finding under clause 8.7, corrective action.

The patterns repeat. So do the fixes. That is why a pre-audit checklist pays off.

Pre-audit checklist for the calibration function

You can work through these items in the weeks before an assessor shows up.

Reference standard recall status. Each standard in your scope should sit inside its calibration interval. Each should have a current certificate from a traceable source. Any standard due for recall during the audit window should be calibrated first.

Calibration certificate sample pull. Pull a fair sample of the certificates you issued since the last audit. Check each one for scope fit, a full traceability statement, a stated decision rule, and reported uncertainty. Flag any gaps and write up the fix.

Personnel training records. Check that every tech doing accredited work has current training records, a signed qualification, and proficiency test results where they apply. Clause 6.2, personnel competence, comes up often.

Internal audit completion. Clause 8.8 requires internal audits. Check that you ran the whole planned schedule, wrote up the findings, and closed the fixes before the assessor arrives.

Management review record. Clause 8.9 requires a management review with set inputs and outputs. Check that your last review covered every required topic. Then check that its action items are done.

This list is not the whole job. But clear it, and you knock out the most common findings.

Verifying traceability and scope of accreditation evidence

The best use of your prep time is a traceability matrix. It lists every parameter on your scope of accreditation. For each one, it names the reference standard used, where that standard was calibrated, its calibration and recall dates, and what it adds to your uncertainty.

The matrix shows problems you cannot see from one certificate. A standard with no logged uncertainty taints every job that uses it. A standard calibrated by a non-accredited source raises a clause 6.5 concern. A standard due for recall during the audit window must be calibrated or pulled from the floor.

The matrix is also the best thing to hand the assessor on day one. Assessors find problems faster than they build context. Give them that context up front. The audit runs shorter, and fewer stray questions turn into findings. Mature labs keep the matrix current instead of rebuilding it each year. For them, a surveillance audit is a check, not a hunt.

Closing corrective actions before the assessment

Open items from past audits are the most likely source of a repeat finding. Before the assessor arrives, walk through each one. Confirm you found and wrote down the root cause. Confirm you ran the follow-up test and that the fix held. Where an issue keeps coming back, log it along with the wider action you took to kill the cause.

This is the area you control most. A clean register tells the assessor your quality system works the way it should.

Building documentation discipline into routine work

If your lab serves regulated industries, the surveillance audit is when your records meet the assessor’s bar. Labs that turn out audit-ready calibration documentation as part of daily work have an easier time than labs that cram for the audit. Build that habit into the routine, and audits stay low-impact.

Frequently Asked Questions

How do you prepare for an ISO/IEC 17025:2017 surveillance audit?

Prep work covers four areas: scope, traceability evidence, decision rule consistency, and corrective action closure. Check recall status on every reference standard. Pull a sample of certificates and review them. Verify training records. Finish the planned internal audits. Close every open item from past audits. A current traceability matrix is the best single thing to hand the assessor.

What do ISO/IEC 17025 assessors look for during a surveillance audit?

They check that your work matches your written scope. They trace certificates back through the reference standards and look for full uncertainty math. They check that decision rules follow clause 7.8.6 every time. They check that past corrective actions closed with a logged root cause and a follow-up test. The audit goes deep on a few jobs, not wide across the whole scope.

What are common ISO/IEC 17025 audit findings on calibration programs?

Findings land in four areas. Scope drift means jobs run outside the written scope. Traceability gaps mean a standard’s record has no uncertainty on it. Decision rule inconsistencies mean like work got two rules with no reason on file. Corrective action backlog means past items closed on paper with no root cause proof. The patterns repeat, which is why a checklist pays off.

What is a calibration traceability matrix?

It is one table that lists every parameter on your scope of accreditation. For each, it names the reference standard used, where that standard was calibrated, its calibration and recall dates, and what it adds to your uncertainty. The matrix shows gaps you cannot see from one certificate. Mature labs keep it current instead of rebuilding it before each audit.

What is the difference between an initial assessment and a surveillance audit?

An initial assessment is the full review that grants accreditation. It covers the whole scope you applied for, often over several days. It tests the management system, the methods, the staff, and the gear. A surveillance audit is narrower. It samples part of the scope, checks that you still meet ISO/IEC 17025:2017, and confirms past corrective actions are closed.

Tra-Cal Laboratories holds ISO/IEC 17025:2017 accreditation for the regulated industries it serves. The habits laid out above show up in every certificate we issue. Request a capability review to talk through audit support for your calibration program.



Previous
Previous

How to Build a Measurement Uncertainty Budget for Pressure Calibration

Next
Next

NIST Traceability and Accredited Calibration: The Practical Difference