NABL software: the ISO 15189 records your LIS should keep, and which ones we keep today
NABL software is lab software that produces the records an ISO 15189 assessor checks. Software cannot make a lab NABL accredited, and your lab's accreditation is yours to obtain. What software can do is keep records as a by-product of the daily workflow rather than a register someone has to remember to fill. Below, each clause is marked live, partial or planned, so you know which records PathLab Software keeps today and which you still keep elsewhere.
ISO 15189 clauses mapped to PathLab Software
The clauses assessors most often probe in the LIS, and what PathLab Software records for each. Use this table as the software section of your evidence file.
| Clause | Requirement | What PathLab Software records | Status |
|---|---|---|---|
| 5.3 | Equipment, reagents and consumables | Analyzer register with message logs (matched, unmatched, errors); reagent lot numbers, expiry alerts and consumption. Calibration and maintenance reminders are planned. | Partial |
| 5.4 | Pre-examination: request, collection, transport | Barcode accession with collection time and collector; home-collection proof with geo-tag, time, temperature note and tube photo. Centre-to-hub transfer manifests are planned. | Partial |
| 5.5 | Examination: validation of methods and ranges | Reference ranges by age band and sex per parameter; changes to test settings are in the audit trail. | Live |
| 5.6 | Ensuring quality: internal QC | Daily IQC entry, Levey-Jennings charts and Westgard flags are planned, not in the product yet. Keep IQC in your current system. | Planned |
| 5.7 | Post-examination: review and release | Technician entry, validation only by users with validate rights, H/L/critical flags and delta checks; nothing is released without the second level. | Live |
| 5.8 | Reporting of results | Signed report with unique number and QR verification code, units and ranges on every line, SHA-256 fingerprint, amended status shown on the verification page. | Live |
| 5.9 | Release and critical results | Critical-value auto-call and WhatsApp alert with retries, escalation to the lab in-charge and an acknowledgement log; it supports, never replaces, the lab's duty to inform. | Live (calls sandboxed until voice credentials are added) |
| 4.13 / 4.14 | Records, audit and corrective action | Audit trail of results, validations, sign-offs and sends with user, time and IP; role-based access; read-only Viewer login for assessors. Evidence export on request; self-serve export planned. | Partial |
| 4.3 | Document control | SOP library with versions and read-acknowledgement is planned. | Planned |
Clause numbers follow the ISO 15189 structure used in NABL 112 checklists; your assessor's numbering may differ by edition. The mapping is guidance, not a certification. Status as of October 2026.
What the audit trail actually looks like
Audit trail · LS-24084 · Vignesh K · sample data
| Time | User | Event |
|---|---|---|
| 09:30:12 | R. Priya (Desk) | Registered · CBC, NS1 · Ref City Clinic · WhatsApp consent ✓ |
| 09:31:02 | R. Priya (Desk) | Barcode printed · LS-24084 |
| 10:58:40 | Sysmex XN-350 | 21 parameters received · matched by barcode |
| 11:04:51 | S. Kavitha (Tech) | Entered · PLT 38,000 HH · delta ↓66 % vs 28 Sep |
| 11:05:03 | System | Critical auto-call + WhatsApp → Dr. Ramesh · attempt 1 no answer |
| 11:07:22 | System | Attempt 2 · acknowledged by Dr. Ramesh (pressed 1) |
| 11:12:08 | Dr. S. Anand (Path) | Validated · comment "Repeat advised in 24 h" · report signed |
| 11:12:09 | System | WhatsApp sent · patient 98xxx · doctor 94xxx |
Attributable and append-only
Audit entries are added, never edited through the app. Every entry has a user, a time to the second and an IP address, and changes record the old and new values. We export the trail for any period as CSV on request; a self-serve export button is planned.
Two-level validation, enforced
A technician can enter and save; only a user with validate rights can validate and release. The system will not issue a signed report or send a WhatsApp message for an unvalidated result, so the rule is not a policy, it is a property of the software.
Read-only login for the assessor
Invite the assessor with the read-only Viewer role for the assessment week and remove them afterwards. They browse audit trails and validation records directly. A dedicated, time-limited Assessor role is planned.
Security and data residency
Hosted in India
Application and database on AWS in Mumbai (ap-south-1), encrypted backups kept in India. WhatsApp delivery passes through Meta's platform, encrypted in transit.
Encrypted in transit and at rest
TLS for every connection including the analyzer connector (with HMAC-signed messages); encryption at rest; a QR verification page and SHA-256 fingerprint for every signed report.
Backups
Encrypted daily backups kept for 30 days in India. Ask us for a restore test of your workspace before your assessment.
Roles and sessions
Owner, admin, staff and read-only viewer roles, with validate rights limited to pathologists. Session timeouts and login throttling.
DPDP Act 2023
WhatsApp consent recorded per patient at registration; data used only for reports and reminders; deletion on request; nothing sold.
ABHA capture; ABDM linking planned
ABHA number captured at the desk and shown masked on the report. Pushing reports to ABDM needs your facility's own HFR registration and ABDM approval; that integration is on our roadmap, not live.
Preparing for assessment with PathLab Software
Most small labs approach NABL in three phases: gap analysis, three to six months of running the quality system, then the assessment. The software's job across those phases is to make records exist without extra effort. During the gap phase, define critical limits per test so auto-calls and their logs start, give every staff member their own login, and decide where IQC and SOPs will live (PathLab Software does not hold them yet; keep them in your current system). During the running phase, let the audit trail, validation records and critical-value logs accumulate. By the assessment, you can show months of evidence for clauses 4.13, 5.7, 5.8 and 5.9 from PathLab Software, and 5.6 and 4.3 from the system you chose.
We share an evidence checklist that lists each clause, the PathLab Software screen that supports it, and the records (such as IQC, SOPs and calibration certificates) the software does not produce today and you must keep yourself. Our onboarding team walks through it with you, and the Chain plan includes a quarterly review. Start with the NABL software checklist guide, then see how analyzer interfacing and the critical-value auto-call feed the trail.
Frequently asked questions
Does using PathLab Software make my lab NABL accredited?
No software can. NABL accredits your lab's quality system under ISO 15189. PathLab Software gives you part of the software evidence assessors ask for: audit trail, two-level validation, critical-value logs and reagent lots. Internal QC charts and SOP document control are planned, so keep those in your current system for now. Accreditation remains your lab's own.
Can an assessor get a read-only login?
Yes. Invite the assessor as a user with the read-only Viewer role for the assessment window and remove them afterwards. They can view audit trails and validation records but cannot change anything. A dedicated, time-limited Assessor role is planned.
Where exactly is the data hosted?
On AWS in Mumbai (ap-south-1), with encrypted daily backups kept in India. WhatsApp delivery uses Meta's platform, which encrypts messages in transit; message content passes through Meta to reach the recipient.
How are corrections to a released report handled?
A released report is not edited silently. Re-validating a signed report marks it Amended, re-signs it with the user and time, recomputes its SHA-256 fingerprint and logs the change in the audit trail; the QR verification page then shows the report as amended. Keeping both rendered versions side by side is planned.
Bring your evidence file to the free setup call
We map your current gaps to PathLab Software screens, set critical limits and user roles on day one, and tell you plainly what stays in your current system.