Standard 2 — Management Requirements
Criteria in this standard
2.2 — Corrective Action Closes the Root Cause
2.3 — Preventive Action, Not Only Reactive
2.4 — Management Review, With Minutes and Actions
2.5 — Complaints Logged, Investigated, Closed
2.6 — Impartiality: No Commercial Pressure on Results
2.7 — Conflict of Interest Declared and Reviewed
2.8 — External Service and Supply Evaluation
Internal Audit, On a Fixed Schedule
Non-Negotiable
In plain terms: Every part of the lab gets checked by someone looking specifically for problems, on a real schedule — not just the easy, visible sections.
| Facility category | Standalone lab | Hospital lab | Clinic lab |
|---|---|---|---|
| Applicability | Full | Full | Full |
Why this matters
Internal audit is the laboratory checking itself honestly before an external body does. Audits that only ever cover the same convenient sections — the main chemistry bench, say — while never reaching the satellite point-of-care site or the after-hours coverage arrangement, create a false sense of security. The gaps nobody audits are exactly where problems accumulate unnoticed.
What good looks like
- A schedule covering every section across a defined cycle, not just favorites.
- Audits actually happen on or near their scheduled date.
- Findings are detailed enough for someone outside the audit to understand them.
Common failure modes
- The same easy sections get audited repeatedly; harder-to-reach ones never do.
- Audits slip months behind schedule with no one tracking the slippage.
- Findings are a checklist of ticks with no real detail behind them.
Worked example
If you are starting from zero — do this first
- List every physical location and section the laboratory operates.
- Check which of these your current or most recent audit actually covered.
- Build a multi-year cycle that explicitly includes everything, not just the obvious parts.
- Put real dates on a calendar, not a vague annual intention.
Self-assessment questions
Evidence: Audit schedule
Evidence: Audit completion records
Evidence: Audit report
Common reasons for a PARTIAL answer
- A remote or satellite location was never explicitly added to scope.
- Audits happen but findings are too brief to act on.
Implementation plan
| When | What |
|---|---|
| Week 1 | List every section and location requiring audit coverage. |
| Week 2 | Build a multi-year cycle with explicit scheduled dates. |
| Week 3 | Share the schedule and assign an auditor to the first session. |
| Ongoing | Track schedule adherence and escalate any slippage. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| DOCUMENT | Schedule and report review | Checks the audit schedule’s completeness against actual facility sections, and reviews recent audit report detail. |
Evidence base
Corrective Action Closes the Root Cause
Non-Negotiable
In plain terms: When something goes wrong, the lab fixes the real reason it happened — not just the thing that was visible that day — and checks afterward that the fix actually worked.
| Facility category | Standalone lab | Hospital lab | Clinic lab |
|---|---|---|---|
| Applicability | Full | Full | Full |
Why this matters
“Staff error” is the single most common entry on a corrective action form, and it is almost always incomplete as a root cause. Staff rarely make errors for no reason — a confusing label, an unclear SOP step, inadequate training, chronic understaffing at a particular shift. Stopping at “staff error, retrained” without asking what allowed the error to happen leaves the actual cause fully intact, waiting to produce the same failure again.
What good looks like
- Root cause identified beyond the immediate symptom.
- Effectiveness checked after a defined interval, not assumed.
- Recurrence of the same nonconformance type triggers fresh investigation.
Common failure modes
- “Staff error, retrained” as the entire investigation.
- No follow-up check that the action actually worked.
- The same failure recurs months later with no connection drawn to the earlier one.
Worked example
If you are starting from zero — do this first
- Pull your last five corrective actions and check how many say only “staff error.”
- For each, ask what allowed the error to happen — that’s the real root cause.
- Build in a scheduled follow-up check for every corrective action going forward.
Self-assessment questions
Evidence: Corrective action record
Evidence: Effectiveness check record
Evidence: Nonconformance log showing trend review
Common reasons for a PARTIAL answer
- Root cause analysis stops at the first obvious answer.
- Effectiveness checks are skipped once the immediate fix is in place.
Implementation plan
| When | What |
|---|---|
| Week 1 | Review recent corrective actions for root-cause depth. |
| Week 2 | Train staff involved in investigations on basic root-cause techniques. |
| Week 3 | Add a mandatory effectiveness-check field to the corrective action form. |
| Ongoing | Trend nonconformance types to catch recurrence early. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| DOCUMENT | Corrective action record review | Selects recent corrective actions and assesses root-cause depth and effectiveness follow-up. |
Evidence base
Preventive Action, Not Only Reactive
Core
In plain terms: The lab doesn’t just fix things after they break — it actually looks for early warning signs and acts on those too.
| Facility category | Standalone lab | Hospital lab | Clinic lab |
|---|---|---|---|
| Applicability | Full | Full | Full |
Why this matters
A laboratory that only ever acts after an actual failure is, by definition, always one step behind. The data that could have predicted the failure — a slow drift in quality control values, a near-miss that didn’t quite become an incident, a pattern across external quality assessment rounds — is usually sitting right there, unused, because nobody is specifically assigned to look for it before something breaks.
What good looks like
- At least one real example of action taken from a trend, not an actual failure.
- External quality assessment performance trended across rounds, not just pass/fail.
- A named person responsible for trend review on a schedule.
Common failure modes
- Every documented action traces back to an actual incident.
- Quality data is collected but nobody is assigned to review trends.
- A slow drift goes unnoticed until it crosses an acceptable limit.
Worked example
If you are starting from zero — do this first
- Name a specific person responsible for trend review, not just incident response.
- Set a weekly or monthly schedule for reviewing quality control trends, not just pass/fail.
- Look back at external quality assessment results for any multi-round pattern.
Self-assessment questions
Evidence: Preventive action record
Evidence: EQA trend analysis
Evidence: Role assignment, review schedule
Common reasons for a PARTIAL answer
- Data is collected but review responsibility isn’t clearly assigned.
- Trend charts exist but aren’t actually looked at regularly.
Implementation plan
| When | What |
|---|---|
| Week 1 | Assign a named person to trend review responsibility. |
| Week 2 | Set up Levey-Jennings or equivalent trend charting if not already in use. |
| Week 3 | Review existing EQA history for any missed multi-round patterns. |
| Ongoing | Hold a scheduled trend review, separate from routine pass/fail checks. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| DOCUMENT | Trend record review | Looks for at least one preventive action genuinely triggered by trend data rather than an actual failure. |
Evidence base
Management Review, With Minutes and Actions
Core
In plain terms: Leadership actually sits down once a year, looks at the real quality data, writes down what they decided, and someone checks those decisions actually happen.
| Facility category | Standalone lab | Hospital lab | Clinic lab |
|---|---|---|---|
| Applicability | Full | Full | Full |
Why this matters
Management review is where quality data is supposed to actually reach the people with authority to allocate resources and change direction. A review that happens informally in a hallway conversation, with nothing written down and no required inputs reviewed systematically, provides none of the accountability or traceability the formal process is meant to create.
What good looks like
- Documented minutes with named attendees exist for the most recent cycle.
- Required inputs — audits, complaints, nonconformances, EQA — are all covered.
- Output actions from the previous review are traceable to completion.
Common failure modes
- Review happens but only covers budget, not quality inputs.
- No written minutes, just a verbal assurance “we discussed it.”
- Agreed actions from last year’s review were never followed up.
Worked example
If you are starting from zero — do this first
- Set a fixed annual date for the formal management review.
- Build an agenda explicitly covering audits, complaints, nonconformances, and EQA.
- Take real minutes, name attendees, and assign owners to every output action.
Self-assessment questions
Evidence: Signed meeting minutes
Evidence: Meeting agenda and minutes
Evidence: Action tracker
Common reasons for a PARTIAL answer
- Minutes exist but omit required quality inputs.
- Actions are agreed verbally but never tracked to closure.
Implementation plan
| When | What |
|---|---|
| Week 1 | Set the annual review date and build a structured agenda template. |
| Week 2 | Gather required inputs — audit, complaint, nonconformance, EQA data. |
| Week 3 | Hold the review, take formal minutes, assign action owners and dates. |
| Ongoing | Track output actions to completion before the next cycle. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| DOCUMENT | Minutes and action tracker review | Confirms minutes cover all required inputs and checks prior action completion status. |
Evidence base
Complaints Logged, Investigated, Closed
Core
In plain terms: Every complaint gets written down in one place, actually looked into, and the person who complained finds out what happened.
| Facility category | Standalone lab | Hospital lab | Clinic lab |
|---|---|---|---|
| Applicability | Full | Full | Full |
Why this matters
A complaint handled verbally and resolved on the spot, with nothing logged, is invisible to the quality system — it cannot be trended, cannot inform prevention, and leaves no record that the concern was ever taken seriously. Complaints are often the earliest, most direct signal a laboratory receives that something in its process isn’t working as intended.
What good looks like
- A single complaints register captures every complaint, regardless of source.
- Each entry has a documented investigation outcome.
- The complainant is informed of the outcome where contact exists.
Common failure modes
- Complaints handled verbally by whoever answers the phone, never logged.
- A complaint is received but the outcome is never communicated back.
- Multiple informal logs exist across different staff, none complete.
Worked example
If you are starting from zero — do this first
- Create one single, accessible complaints log, not department-specific lists.
- Tell all staff: every complaint gets logged, no exceptions, even if resolved immediately.
- Build in a step to close the loop with the complainant.
Self-assessment questions
Evidence: Complaints register
Evidence: Investigation outcome record
Evidence: Callback or communication record
Common reasons for a PARTIAL answer
- Verbal complaints resolved on the spot are never logged.
- The register exists but outcomes are rarely communicated back.
Implementation plan
| When | What |
|---|---|
| Week 1 | Build or consolidate a single complaints register. |
| Week 2 | Brief all staff that every complaint, however resolved, gets logged. |
| Week 3 | Add a required closing-the-loop step to the process. |
| Ongoing | Trend complaint types quarterly for recurring themes. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| DOCUMENT | Register review | Selects a logged complaint and verifies investigation outcome and complainant communication. |
Evidence base
Impartiality: No Commercial Pressure on Results
Non-Negotiable
In plain terms: Nobody’s paycheck depends on what a test result says, and staff genuinely feel safe flagging a problem even if it slows things down.
| Facility category | Standalone lab | Hospital lab | Clinic lab |
|---|---|---|---|
| Applicability | Full | Full | Full |
Why this matters
Impartiality is foundational to laboratory credibility — a result is only trustworthy if nothing in how staff are compensated or evaluated creates an incentive, conscious or not, to produce a particular outcome. Volume-linked bonuses are the most direct version of this risk, but subtler pressures — an unspoken expectation that flagging problems reflects badly on performance reviews — can be just as corrosive and are harder to detect from policy documents alone.
What good looks like
- No compensation link to test volume, patterns, or referral relationships.
- A written, genuine non-retaliation policy for raising quality concerns.
- Staff report feeling safe raising concerns, even when confidentially asked.
Common failure modes
- A volume-based bonus structure for technical staff.
- An unwritten culture where flagging delays is discouraged informally.
- Staff privately admit hesitation to raise concerns despite a written policy.
Worked example
If you are starting from zero — do this first
- Review every compensation and bonus structure for any volume or outcome link.
- Write a clear non-retaliation policy if none exists.
- Ask staff confidentially, separately from management, whether they’d feel safe raising a concern.
Self-assessment questions
Evidence: Compensation policy
Evidence: Non-retaliation policy
Evidence: Confidential staff interview
Common reasons for a PARTIAL answer
- A legacy bonus structure was never reviewed for this specific risk.
- A written policy exists but staff don’t genuinely feel it applies in practice.
Implementation plan
| When | What |
|---|---|
| Week 1 | Audit all compensation structures for volume or outcome links. |
| Week 2 | Write or strengthen the non-retaliation policy. |
| Week 3 | Communicate the policy directly and explain any compensation changes. |
| Ongoing | Periodically check staff comfort confidentially, not just via policy review. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| DOCUMENT | Compensation structure review | Examines compensation policy for any volume or outcome link. |
| ASK | Confidential staff interview | Speaks with staff privately, away from management, about comfort raising concerns. |
Evidence base
Conflict of Interest Declared and Reviewed
Core
In plain terms: People who make decisions affecting testing or purchasing say upfront if they have a personal financial stake — and this gets checked again periodically, not just once when they were hired.
| Facility category | Standalone lab | Hospital lab | Clinic lab |
|---|---|---|---|
| Applicability | Full | Full | Full |
Why this matters
Circumstances change after hiring — a staff member’s spouse takes a sales role at a reagent supplier, a manager acquires a financial stake in a referral laboratory. A conflict-of-interest declaration collected once, years ago, and never refreshed captures none of this. The purpose of periodic review is specifically to catch exactly these changes before they quietly influence a purchasing or referral decision.
What good looks like
- Current declarations exist for everyone in a position of influence.
- A named person or body actually reviews declarations and decides on action.
- Identified conflicts have a documented mitigation on record.
Common failure modes
- Declarations collected once at hiring and never refreshed.
- Declarations filed but nobody formally reviews them.
- A genuine conflict is identified but no mitigation is documented.
Worked example
If you are starting from zero — do this first
- Identify everyone with real influence over testing, purchasing, or reporting decisions.
- Collect current declarations if none exist or they’re outdated.
- Set an annual refresh schedule and name who reviews them.
Self-assessment questions
Evidence: Current declaration records
Evidence: Review committee record
Evidence: Mitigation record
Common reasons for a PARTIAL answer
- Declarations exist but have never been refreshed since hiring.
- A conflict was noted but no concrete mitigation was documented.
Implementation plan
| When | What |
|---|---|
| Week 1 | Identify all staff in positions of influence over testing or purchasing. |
| Week 2 | Collect or refresh declarations for everyone identified. |
| Week 3 | Assign review responsibility and set an annual refresh schedule. |
| Ongoing | Document mitigation whenever a genuine conflict is identified. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| DOCUMENT | Declaration and mitigation review | Checks declaration currency and any documented mitigation for identified conflicts. |
Evidence base
External Service and Supply Evaluation
Core
In plain terms: The lab doesn’t just start working with a supplier or reference lab informally — it checks them properly first, and keeps checking over time.
| Facility category | Standalone lab | Hospital lab | Clinic lab |
|---|---|---|---|
| Applicability | Full | Full | Full |
Why this matters
A laboratory’s result quality depends partly on parties it doesn’t directly control — the reference laboratory running referred tests, the technician servicing an analyzer, the supplier shipping reagents. Relationships with these parties often begin informally, through a personal recommendation or convenience, and formal evaluation is treated as paperwork to complete later. Later rarely comes, and the laboratory is left relying on providers it has never actually assessed.
What good looks like
- A documented evaluation exists before the relationship begins in earnest.
- Evaluation is repeated periodically, not only at the start.
- Unsatisfactory performance has a documented laboratory response.
Common failure modes
- A long-standing relationship was never formally evaluated at all.
- Initial evaluation happened but was never repeated.
- Known performance issues continue with no documented response.
Worked example
If you are starting from zero — do this first
- List every reference laboratory, equipment servicer, and critical reagent supplier currently used.
- Check which of these have a documented evaluation on file.
- Build evaluations for any gaps, even for long-standing relationships.
Self-assessment questions
Evidence: Supplier evaluation record
Evidence: Re-evaluation schedule and records
Evidence: Performance response record
Common reasons for a PARTIAL answer
- Long-standing suppliers were grandfathered in without ever being formally evaluated.
- Evaluation happened once years ago and was never repeated.
Implementation plan
| When | What |
|---|---|
| Week 1 | List all critical external service providers and suppliers. |
| Week 2 | Build or complete formal evaluations for each, including long-standing ones. |
| Week 3 | Set a periodic re-evaluation schedule. |
| Ongoing | Document any response to identified performance issues. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| DOCUMENT | Evaluation record review | Checks for documented initial and periodic evaluation of key external providers. |