Standard 7 — Examination: Process & Safety
Criteria in this standard
7.2 — Internal Quality Control Run Before Patient Results Released
7.3 — External Quality Assessment Participation
7.4 — Critical Value Communication, Verified Received
7.5 — Personal Protective Equipment, Available and Used
7.6 — Exposure Incident: Documented Response Protocol
7.7 — Information System Access Controlled and Logged
7.8 — Result Amendment Traceable to Original
Method Validation Before Clinical Use
Non-Negotiable
In plain terms: Every test method was properly checked and proven to work correctly before it was ever used on a real patient — not after, as paperwork catching up.
| Facility category | Standalone lab | Hospital lab | Clinic lab |
|---|---|---|---|
| Applicability | Full | Full | Full |
Why this matters
Validation completed after a method is already in clinical use defeats its entire purpose — the point is to confirm a method works correctly before any patient result depends on it, not to retroactively document that it probably worked. A validation date that falls after the method’s first recorded clinical use is a clear, specific signal that paperwork was assembled to satisfy a review rather than to genuinely protect patients.
What good looks like
- Validation completion predates first clinical use, verifiably.
- Manufacturer data is locally verified, not relied on alone.
- Reference intervals match the laboratory’s actual patient population.
Common failure modes
- Validation paperwork is dated after clinical use already began.
- Manufacturer insert data is used without any local verification.
- Reference intervals are copied wholesale without population relevance review.
Worked example
If you are starting from zero — do this first
- Pull validation records for your most recently introduced method and check the dates.
- Confirm manufacturer data has been locally verified, not simply adopted.
- Check reference intervals against your own patient population’s characteristics.
Self-assessment questions
Evidence: Validation record with completion date
Evidence: Local verification record
Evidence: Reference interval verification record
Common reasons for a PARTIAL answer
- Satellite or point-of-care deployments bypass the central validation process.
- Reference intervals are adopted wholesale without population review.
Implementation plan
| When | What |
|---|---|
| Week 1 | Audit recent method introductions for validation-before-use dating. |
| Week 2 | Build a hard rule extending to every site, including satellite locations. |
| Week 3 | Review reference intervals for population appropriateness. |
| Ongoing | Require validation sign-off before any new method deployment, anywhere. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| DOCUMENT | Validation date cross-check | Compares validation completion date against first recorded clinical use date. |
Evidence base
Internal Quality Control Run Before Patient Results Released
Non-Negotiable
In plain terms: Quality control gets checked and approved first, before any real patient results from that same run go out — every single time, no exceptions.
| Facility category | Standalone lab | Hospital lab | Clinic lab |
|---|---|---|---|
| Applicability | Full | Full | Full |
Why this matters
Releasing patient results before confirming quality control is acceptable inverts the entire purpose of quality control — the check exists specifically to catch a problem before it reaches a patient, and releasing first removes that protection entirely. This failure mode often emerges not from carelessness but from workflow pressure, where results are queued for release automatically while quality control review happens “in parallel” rather than strictly first.
What good looks like
- No instance exists of results released before quality control review.
- A real, tested response procedure exists for quality control failure.
- Quality control frequency is justified, not just minimized.
Common failure modes
- Automated systems release results before a human confirms quality control passed.
- A written failure-response procedure exists but has never actually been followed in practice.
- Quality control frequency is set at the bare minimum with no documented justification.
Worked example
If you are starting from zero — do this first
- Check your actual system configuration — is release truly gated on quality control, or just reviewed in parallel?
- Test your quality control failure response procedure for real, don’t just read it.
- Document the justification for your current quality control frequency.
Self-assessment questions
Evidence: System configuration and release logs
Evidence: Quality control failure response record
Evidence: Frequency justification document
Common reasons for a PARTIAL answer
- Automated release isn’t genuinely gated on prior quality control confirmation.
- The failure-response procedure exists but has never actually been exercised.
Implementation plan
| When | What |
|---|---|
| Week 1 | Audit system configuration for true release-gating on quality control. |
| Week 2 | Reconfigure if a gap is found. |
| Week 3 | Document quality control frequency justification. |
| Ongoing | Periodically audit for any release-before-review instance. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| DOCUMENT | Configuration and log audit | Checks system configuration and historical logs for any release-before-review instance. |
Evidence base
External Quality Assessment Participation
Non-Negotiable
In plain terms: The lab proves to an outside party, regularly, that it’s actually getting results right — not just trusting its own internal checks.
| Facility category | Standalone lab | Hospital lab | Clinic lab |
|---|---|---|---|
| Applicability | Full | Full | Full |
Why this matters
Internal quality control confirms consistency within a laboratory’s own system, but it cannot reveal a systematic bias shared across that entire system — external quality assessment is specifically designed to catch exactly that blind spot by comparing results against an independent, external benchmark. A discipline quietly excluded from participation, often simply because it’s smaller or newer than the laboratory’s main services, loses this safeguard entirely without anyone necessarily deciding that deliberately.
What good looks like
- Every operated discipline with an available scheme is currently enrolled.
- Results are genuinely reviewed by the accountable person, not just filed.
- Unsatisfactory performance triggers a real, documented investigation.
Common failure modes
- A newer or smaller discipline was never enrolled in a scheme at all.
- Certificates are filed without genuine review of the underlying performance.
- An unsatisfactory result has no documented follow-up.
Worked example
If you are starting from zero — do this first
- List every testing discipline currently operated, including smaller or newer ones.
- Check enrollment status for each against available schemes.
- Enroll any gaps found immediately.
Self-assessment questions
Evidence: Enrollment records
Evidence: Review sign-off record
Evidence: Investigation record
Common reasons for a PARTIAL answer
- A newer discipline was never formally enrolled.
- Certificates are filed but genuine review isn’t documented.
Implementation plan
| When | What |
|---|---|
| Week 1 | List all operated disciplines and check enrollment status. |
| Week 2 | Enroll any gaps found. |
| Week 3 | Build a mandatory enrollment step into new-service launch checklists. |
| Ongoing | Review every round’s results with the accountable person. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| DOCUMENT | Enrollment and review check | Verifies current enrollment for every operated discipline and checks for documented result review. |
Evidence base
Critical Value Communication, Verified Received
Non-Negotiable
In plain terms: A genuinely dangerous result reaches a real clinician, directly, fast — and the lab actually confirms it landed, not just that a call was attempted.
| Facility category | Standalone lab | Hospital lab | Clinic lab |
|---|---|---|---|
| Applicability | Full | Full | Full |
Why this matters
A critical value left on voicemail or sent through a channel with no delivery confirmation can sit unseen for hours, during which exactly the urgent clinical response the alert was meant to trigger never happens. The read-back verification step — having the receiving clinician repeat the value back — exists specifically because verbal communication under time pressure is genuinely error-prone, and this is the step most often skipped when staff are busy.
What good looks like
- A written list defines exactly what counts as a critical value, per analyte.
- Communication logs show genuine read-back verification, not just a call attempt.
- A defined escalation path exists for a failed first contact attempt.
Common failure modes
- “Critical” is left to individual judgment with no written definition.
- A voicemail is left and treated as communication complete.
- No escalation path exists if the first call attempt isn’t answered.
Worked example
If you are starting from zero — do this first
- Confirm a written critical value list exists for your major analytes.
- Check whether your communication log shows read-back verification or just call attempts.
- Build a defined escalation path for failed first contact.
Self-assessment questions
Evidence: Written critical value list
Evidence: Communication log with read-back record
Evidence: Escalation procedure
Common reasons for a PARTIAL answer
- Voicemail is treated as sufficient communication.
- No escalation path exists for a failed first attempt.
Implementation plan
| When | What |
|---|---|
| Week 1 | Confirm or build a written critical value list. |
| Week 2 | Build a required read-back verification step into the communication log. |
| Week 3 | Build and brief staff on an escalation path for failed contact. |
| Ongoing | Audit critical value logs for genuine read-back completion. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| DOCUMENT | Communication log review | Reviews recent critical value communications for read-back verification and timely resolution. |
Evidence base
Personal Protective Equipment, Available and Used
Non-Negotiable
In plain terms: The right protective gear isn’t just sitting somewhere in the lab — it’s right there where it’s needed, and staff actually wear it, genuinely, even when busy.
| Facility category | Standalone lab | Hospital lab | Clinic lab |
|---|---|---|---|
| Applicability | Full | Full | Full |
Why this matters
PPE compliance is one of the most well-documented gaps between written policy and actual practice — availability alone says nothing about use, and self-reported compliance is notoriously unreliable since staff know the expected answer. Direct observation during an actual, unannounced moment of bench work is the only way to genuinely assess whether PPE use is a real habit or a policy that exists mainly on paper.
What good looks like
- PPE is actually observed worn correctly during real bench work.
- PPE is physically located at the point of use, not requiring a trip to retrieve.
- Any stockout is logged as a safety event, not quietly absorbed.
Common failure modes
- PPE is available but not consistently worn under time pressure.
- PPE is stored somewhere inconvenient, discouraging use.
- Stockouts happen occasionally and go unrecorded.
Worked example
If you are starting from zero — do this first
- Observe actual bench work during a busy period, not a calm one.
- Check PPE’s physical location relative to each workstation.
- Relocate supplies if retrieval friction is discouraging use.
Self-assessment questions
Evidence: Direct observation, ideally unannounced
Evidence: Bench inspection
Evidence: Safety event log
Common reasons for a PARTIAL answer
- PPE is available but located too far from actual point of use.
- Compliance drops specifically during high-volume periods.
Implementation plan
| When | What |
|---|---|
| Week 1 | Observe actual PPE use during a genuinely busy period. |
| Week 2 | Relocate PPE supplies to each point of use if friction is found. |
| Week 3 | Build a stockout logging mechanism. |
| Ongoing | Conduct periodic unannounced compliance spot-checks. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| OBSERVE | Bench work observation | Directly observes actual bench work, ideally during a busy period, for genuine PPE compliance. |
Evidence base
Exposure Incident: Documented Response Protocol
Non-Negotiable
In plain terms: If someone has an actual exposure incident, there’s a real, known plan everyone can follow immediately — not a document to go find and read for the first time in that moment.
| Facility category | Standalone lab | Hospital lab | Clinic lab |
|---|---|---|---|
| Applicability | Full | Full | Full |
Why this matters
The first minutes after a biological exposure incident genuinely matter for post-exposure outcomes, and this is precisely the moment staff have the least capacity to calmly look up and read an unfamiliar procedure from scratch. A protocol that exists only as a document, without having been actively taught or drilled, functions very differently in theory than it does during the stress of a real event.
What good looks like
- Staff can describe the first steps without needing to consult a document.
- A recent actual incident’s response genuinely matched the written protocol.
- Post-exposure medical follow-up is a real, responsive arrangement.
Common failure modes
- Staff know a protocol exists but can’t describe its actual first steps.
- The referenced occupational health service doesn’t respond promptly when called.
- The protocol has never been drilled, only distributed as a document.
Worked example
If you are starting from zero — do this first
- Ask two or three staff members right now to describe the exposure protocol’s first steps.
- Test your referenced occupational health service’s actual response time.
- Consider a quick-reference card at each bench, not just a policy manual entry.
Self-assessment questions
Evidence: Staff interview
Evidence: Incident record or drill record
Evidence: Occupational health service responsiveness check
Common reasons for a PARTIAL answer
- Staff read the protocol once at onboarding and never again.
- The occupational health referral exists on paper but hasn’t been tested for real responsiveness.
Implementation plan
| When | What |
|---|---|
| Week 1 | Ask current staff to describe the protocol’s first steps. |
| Week 2 | Conduct a tabletop drill and test occupational health responsiveness. |
| Week 3 | Post a quick-reference card at each bench. |
| Ongoing | Refresh training periodically, not only at onboarding. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| ASK | Staff knowledge check | Asks staff to describe the protocol’s first steps without reference material. |
Evidence base
Information System Access Controlled and Logged
Core
In plain terms: Every person has their own login, not a shared one — and what each person can see or change in the system actually matches what their role genuinely needs.
| Facility category | Standalone lab | Hospital lab | Clinic lab |
|---|---|---|---|
| Applicability | Full | Full | Full |
Why this matters
A shared generic login makes it fundamentally impossible to answer “who actually did this” when a question arises about a specific data access or change — the accountability that individual credentials provide isn’t a bureaucratic nicety, it’s the only mechanism that makes any later investigation of an error or concern possible at all. Over-broad access permissions compound this risk by giving more staff than necessary the ability to alter released results.
What good looks like
- Every staff member has individual, non-shared credentials.
- Access levels genuinely differ by role, restricting amendment permission appropriately.
- The access log is actually reviewed periodically, not just generated.
Common failure modes
- A shared generic login is used for convenience, especially on shared terminals.
- Every staff member has full edit access regardless of actual role need.
- The access log exists technically but nobody ever reviews it.
Worked example
If you are starting from zero — do this first
- Check whether any shared or generic logins are currently in use.
- Review access levels against actual role requirements.
- Schedule a periodic access log review if none currently happens.
Self-assessment questions
Evidence: System credential audit
Evidence: Access level configuration
Evidence: Log review record
Common reasons for a PARTIAL answer
- Shared logins persist on busy, multi-user terminals.
- Access logs exist but are never actually reviewed.
Implementation plan
| When | What |
|---|---|
| Week 1 | Audit current login practice for any shared credentials. |
| Week 2 | Implement individual credentials, including fast methods like badge swipe where needed. |
| Week 3 | Review and correct access levels by role. |
| Ongoing | Review access logs on a fixed schedule. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| DOCUMENT | Credential and access audit | Checks for individual, non-shared credentials and reviews access level assignments. |
Evidence base
Result Amendment Traceable to Original
Core
In plain terms: If a result gets corrected after release, you can still see what it originally said, what it was changed to, why, and by whom — nothing just quietly disappears.
| Facility category | Standalone lab | Hospital lab | Clinic lab |
|---|---|---|---|
| Applicability | Full | Full | Full |
Why this matters
An overwritten original value removes the ability to understand what actually happened — whether the original was a transcription error, an instrument malfunction, or something more concerning, and whether a clinician may have already acted on the incorrect original value. Full traceability, including notification to the ordering clinician, is what allows both internal quality review and appropriate downstream clinical correction.
What good looks like
- The original value remains visible alongside any amendment, never deleted.
- Every amendment shows a documented reason and who made it.
- The ordering clinician is notified when a previously released result is amended.
Common failure modes
- The original value is overwritten with no trace remaining.
- An amendment exists but with no documented reason attached.
- The ordering clinician never learns the result they already saw was amended.
Worked example
If you are starting from zero — do this first
- Check your system configuration — does amendment overwrite or preserve the original?
- Build a mandatory reason field for any amendment.
- Build a required clinician notification step for amendments to released results.
Self-assessment questions
Evidence: Amendment record
Evidence: Amendment reason and attribution
Evidence: Clinician notification record
Common reasons for a PARTIAL answer
- System configuration overwrites rather than preserves the original.
- Clinician notification isn’t consistently completed for amendments.
Implementation plan
| When | What |
|---|---|
| Week 1 | Check system configuration for amendment preservation versus overwrite. |
| Week 2 | Reconfigure if the original is currently overwritten. |
| Week 3 | Build a mandatory clinician notification step. |
| Ongoing | Audit amendment records periodically for completeness. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| DOCUMENT | Amendment record review | Selects an amended result and verifies original preservation, documented reason, and clinician notification. |