NABL

NABL software checklist: what ISO 15189 assessors check

A checklist for small Indian labs: the audit trail, validation, QC, critical-value and document-control records your LIS must produce before an NABL assessment.

Quick answer: NABL does not approve software, but ISO 15189 assessors check the records your LIS produces. Before assessment your lab software should give you an immutable audit trail, enforced two-level validation, reference ranges with history, analyzer traceability, IQC with Westgard flags, logged critical-value calls, self-identifying reports, SOP document control and individual logins with tested backups.

By AvanceZone team · Published 01 Oct 2026 · Updated 04 Oct 2026 · 9 min read

NABL accredits medical laboratories against ISO 15189. The assessors do not accredit software, and no product can call itself "NABL certified". What they do check, usually in the first hour, is whether your laboratory information system produces the records the standard requires without anyone remembering to write them in a register. This checklist covers the software part. Keep it beside your quality manual; the operational records (calibration certificates, staff competence, proficiency-testing results) are yours to maintain and no LIS produces them.

1. Audit trail: every result, every change, every send

  • Each result stores who entered it, who validated it, and the time to the second.
  • Corrections create a new entry with a mandatory reason; the old value stays visible. Nothing is deleted.
  • Printing and sending a report (WhatsApp, email, portal) are logged with the destination.
  • The trail for any date range exports to CSV so you can hand it over.

Ask your vendor to show the trail for one sample from registration to delivery. If any step is missing, the gap will be found on clause 4.13 (control of records).

2. Two-level validation, enforced by the system

Technician enters, pathologist validates, and the software refuses to generate a PDF or deliver a report for an unvalidated result. A policy that says "the pathologist must sign" is weaker than a system that cannot release without the Pathologist role. Check that roles are real (front desk, technician, pathologist, accounts, owner) and that a technician's login genuinely cannot release.

3. Reference ranges with history

Ranges by age band, sex and pregnancy, with the date each range was changed and by whom. Assessors look for biological reference intervals attached to the test method you actually run, and for the evidence that a range change did not silently alter reports already issued.

4. Analyzer traceability

With analyzer interfacing each result carries the instrument, the time it was produced and, ideally, the reagent lot. Manually typed results need a second-person check that the LIS should record. This is where interfacing pays for itself twice: fewer transcription errors and a complete clause 5.5 record.

5. Internal quality control

  • Daily IQC entry per analyzer and per level, with Levey-Jennings charts.
  • Westgard rule flags (1-2s, 1-3s, 2-2s, R-4s) and a corrective-action note linked to the failed run.
  • Monthly QC summary the pathologist reviews and signs off inside the system.

6. Critical values with acknowledgement

Clause 5.9 requires that critical results are communicated promptly and that the communication is recorded: who was told, by whom, and when. A red flag on screen is not a record. PathLab Software's auto-call dials the referring doctor, retries, escalates to the lab in-charge and logs every attempt and the acknowledgement, as a support to (never a replacement for) staff informing the clinician; if you use another LIS, make sure the technician can at least log the call against the result rather than in a notebook.

7. Reports that identify themselves

Unique report number, patient identifiers, collection and reporting times, units and ranges on every line, the name and signature of the releasing pathologist, page numbering, and clear marking of amended reports with the reason. A QR code that resolves to the signed original is not required by the standard, but it answers the "how do you prevent altered printouts" question in one scan.

8. Document control

SOPs with version numbers, approval, an effective date, and a record of which staff have read the current version. Retired versions kept but not usable. Many small labs keep SOPs in a folder; an SOP library inside the LIS with read-acknowledgement is cheaper than the hour the assessor spends on it.

9. Access, backup and data location

  • Individual logins; no shared "lab" password. Session timeouts.
  • Encrypted backups with a restore you have actually tested, and a note of where the data is hosted. Indian hosting simplifies the DPDP Act conversation.
  • A read-only login you can give the assessor for the week.

10. What software cannot do

Equipment calibration, staff competence records, proficiency testing (EQAS) participation, the quality manual itself, management review and internal audit are yours. The best the LIS can do is give these a home: reminders for calibration due dates, an SOP library, and a place to file EQAS results against the analyzer.

11. Patient identification and sample rejection

Assessors trace a sample backwards from the report to the tube. The LIS should hold at least two patient identifiers (name plus age or date of birth, and a unique lab number), the collection time and the collector's ID, and a sample-rejection record: haemolysed, clotted, insufficient or unlabelled, with the reason and what was done. A rejection that lives only in a technician's memory is a finding under clause 5.4. Barcode accession helps here because the label is printed from the order, not handwritten.

12. Turnaround time you can prove

ISO 15189 expects the lab to define turnaround times per test and monitor them. Your LIS already knows when a sample was received, when the result arrived from the analyzer, when it was validated and when the report was delivered. Ask for a monthly TAT report per department and per test, and look at the outliers with your pathologist. A lab that can show "95 % of routine CBCs reported within four hours, and here are the exceptions with reasons" answers a whole line of questions at once.

How to test your current software in one afternoon

  1. Pick one sample from last week and print its full audit trail. Is every step there, from registration to delivery?
  2. Log in as a technician and try to release a report. The software should refuse.
  3. Change a reference range on a test copy, then open an old report. It must still show the range that applied on the day.
  4. Export last month's IQC for one analyzer. Are the Westgard violations and corrective actions in it?
  5. Find last month's critical values. Can you show who was informed, by whom and when, without opening a notebook?

Any "no" is a gap to close before you book the assessment, whichever software you use.

A six-month plan for a small lab

Month 1: switch on IQC entry, define critical limits per test, load SOPs, give every staff member their own login. Months 2 to 5: run; review the QC summary monthly; record corrective actions in the system. Month 6: export the trail, QC charts and critical logs for the period, put them behind the software tab of your evidence file, and book the pre-assessment. The NABL readiness page maps each item above to the PathLab Software screen that produces it and marks which are live, partial or planned (IQC and SOP control are planned), the security page covers hosting and backups, and PathLab Software pricing shows that the audit trail is in every plan from ₹1,999 a month.

Questions people ask

Which ISO 15189 version does NABL use now?

NABL has moved medical laboratories to ISO 15189:2022, with a transition period for labs accredited under the 2012 edition. Clause numbers changed between editions, so map your evidence file to the edition your assessor is using; the software records themselves stay the same.

Is there an NABL-approved list of lab software?

No. NABL does not certify or list software. Assessors evaluate your records and processes under ISO 15189; the software simply has to produce those records reliably.

Can a lab with manual result entry get NABL accreditation?

Yes, with a documented second-person verification of every typed result and the record of it. Analyzer interfacing removes that step and the transcription errors that come with it, which is why most labs interface before assessment.

How long should audit-trail records be kept?

NABL expects records to be retained for the period defined in your quality manual, commonly a minimum of five years for reports and related records; PathLab Software keeps the trail for the life of the account and exports it on request.

Related guides

Your lab, live in two working days.

Free setup and migration from Excel, Word or your current lab software. We connect your analyzers over a screen share and train your staff in Tamil or English. Monthly billing from ₹1,999, no annual lock-in, cancel any month, and a full data export on request at no charge.