Standards alignment

Built against the standard the lab is assessed on.

ISO 15189:2022 §6.6 shapes what is recorded when reagents and consumables arrive; §7.11 shapes how the software itself is validated. Assessment and audit packs are built from these records without changing them. Out-of-service dating and recall actions remain the laboratory's own process.

ISO 15189:2022 §6.6

What is recorded at the door.

§6.6.7

Reception records

Date, lot, expiry, quantity and supplier written to the receiving department's log on every receipt, with the delivery-note number. The receiver is required: in Received By in Chemistry logs, in Comments elsewhere.

§6.6.4

Acceptance before use

Chemistry: every lot cross-checked against the PAT register at the door, with a generated investigation worklist. Other departments: every new lot is flagged and confirmed before it is written, then verified at the bench.

§6.6.2

Condition on reception

Operator-recorded condition, intact and cold chain, written to the logs' Condition column; failures highlighted in red and audit-logged.

§6.6.7 c

Expiry control

Stock expired on arrival is flagged and quarantine-actioned first on the worklist; short-dated stock is flagged amber; expired lots on the shelf are listed for removal. First use of each lot is dated through Date in Use.

§6.8.3

Supplier evaluation

Each supplier's last 12 months: deliveries, short-dated and expired arrivals, condition and QC failures, and how long orders took to arrive, recorded with the outcome of the yearly evaluation.

§7.11

Software validation

A validation dossier issued per build: intended use, risk controls, change control and a release check re-run for every issue, including a fictional-data regression suite.

Change control and validation

Every build identified, every release re-verified.

447/ 447Checks passed in the release check

Re-run before every dossier issue.

1per buildValidation dossier

Marks itself DRAFT if anything disagrees.

7sectionsVersioned independently

A section changed without a new version shows amber.

Release identified

A release number, a version for each of seven sections and the commit, embedded at build time. Shown in the footer and written into every audit record. A section changed without a new version is marked UNRELEASED, uncommitted code MODIFIED; both show amber.

Release check

Reading on fictional and real dockets, column detection, writes into copies, duplicates, pre-acceptance and routing. It also re-proves the section versions, write confinement, the origin guard and the network guard.

Validation dossier

Generated from the build record, the executable's SHA-256 and the release results together. If they disagree, code changed after the build, or a check failed, it marks itself DRAFT. Each build is hash-verified onto the portable drive against the build output.

Answer keys measure the reader. Staff can correct a review to match the paper and save it as an answer key. Before a new reader is released it is scored against every key: code, lot, expiry and quantity. Keys stay on the drive and are never uploaded, because nothing is.

Assessment and audit packs

NATA (ISO 15189) or ISO 9001:2015, built in a minute.

Choose the visit and the dates, enter your initials and press Build the pack. Two files come out: a presentation of the key charts and tables to start with, and a workbook of every record behind it.

What the assessor is shown

  • A checklist of what is looked for, each item In order, Check, Partly covered or Bring separately, with its clause.
  • Receipts, lots received, lots put into use, removals, shelf counts and audit records for the period.
  • Rows to check coloured, with the reason in their first column.

What it will not do

  • Change anything in the logs. The packs are built from the records; the logs remain the record.
  • Flag PAT for products the register does not list; they are exempt and listed on the PAT scope sheet.
  • Flag a blank QC-at-first-use column when that QC is recorded in another system.
Questions assessors ask

Answers, with the record that backs them.

Is the software validated for its intended use?

Yes. A validation dossier is issued per build, covering intended use, risk controls, change control and the release check results. The release shown in the app's footer and the executable's SHA-256 match section 1 of the dossier.

Who entered this receipt, and when?

The log row carries the receiver's initials and a delivery-note stamp, and the audit log carries the Windows username, timestamp and build for the write, hash-chained to the records around it.

How do you know a lot was accepted before it was used?

In Chemistry, every lot's verdict against the PAT register is recorded at receipt and the investigation worklist names the action. First use is dated through Date in Use, and a lot that is not acceptable is refused there and listed with the reason.

Can the record be altered after the fact?

Log workbooks are the laboratory's own controlled documents and remain so. LotWarden's audit log is hash-chained: editing, inserting or deleting a record breaks the chain and the page reports it on the next load. Sign-offs are kept beside the app where they cannot be edited.

Where does the data go?

Nowhere. The app binds to loopback only, a socket-level guard refuses any outbound connection and logs the attempt, and the data on the drive is encrypted at rest.

Bring your last assessment findings to the walkthrough.

We will show you which ones the receiving record now closes.