Home / Insights / Accreditation
ISO 15189:2022 for POCT: what changed
ISO 15189:2022 withdrew ISO 22870 and brought point-of-care testing inside the laboratory standard through a normative Annex A. What moved, what is new (risk-based thinking, ensuring validity of results, competence), and the records POCT services are now asked to show.
In brief
- ISO 15189:2022 was published in December 2022. It replaced ISO 15189:2012 and withdrew ISO 22870:2016, the separate POCT standard, folding its requirements into a normative Annex A.
- The structure now follows ISO/IEC 17025:2017: general, structural, resource, process and management-system requirements, with impartiality and confidentiality stated up front.
- The emphasis has moved from prescribed documents to risk-based thinking, patient welfare and demonstrating that results are valid (clause 7.3.7: internal QC, EQA and comparability).
- For POCT services the practical change is scope: the laboratory's management system now has to cover devices, operators and records outside the laboratory, and to evidence it.
What happened, and when
ISO 15189:2022, "Medical laboratories: requirements for quality and competence", was published in December 2022 as the fourth edition of the standard. It replaced the 2012 edition and, importantly for point-of-care services, withdrew ISO 22870:2016, which had been the separate standard for POCT accreditation. The requirements specific to point-of-care testing now sit in Annex A of ISO 15189:2022, and the annex is normative: it is part of the requirements, not guidance. Accreditation bodies set a three-year transition, so laboratories accredited to the 2012 edition were expected to have moved to the 2022 edition by December 2025.
The new structure
The 2012 edition was organised around management requirements (clause 4) and technical requirements (clause 5). The 2022 edition adopts the layout of ISO/IEC 17025:2017 so that the two standards read alike:
| Clause | Covers | Notes for POCT |
|---|---|---|
| 4 General requirements | Impartiality, confidentiality, patient-related requirements | Patient welfare and the patient's rights are stated as requirements in their own right. |
| 5 Structural and governance | Legal entity, laboratory director, laboratory activities, structure and authority, objectives and policies, risk management | Risk management (5.6) is now an explicit requirement with a reference to ISO 22367. |
| 6 Resource requirements | Personnel, facilities, equipment, reagents and consumables, service agreements, externally provided products | Competence (6.2), equipment records (6.4) and reagent lot management (6.5) all apply to POCT devices and the staff who use them. |
| 7 Process requirements | Pre-examination, examination (verification, validation, measurement uncertainty, reference intervals, ensuring validity), post-examination, nonconforming work, data control, complaints, continuity | Ensuring the validity of results (7.3.7) covers IQC, EQA and comparability of results between devices and sites. |
| 8 Management system requirements | Options A and B, documentation, control of records, risks and opportunities, improvement, nonconformities and corrective actions, evaluations and internal audits, management review | Internal audits (8.8) and management review (8.9) now need POCT inputs. |
| Annex A (normative) | Additional requirements for point-of-care testing | Replaces ISO 22870. See below. |
Annex A: point-of-care testing inside the standard
ISO 22870 had described POCT as an activity a laboratory could be accredited for alongside ISO 15189. Annex A makes it simpler and stricter: where a laboratory is responsible for POCT, the laboratory's management system applies to it, and the annex adds what is specific. In outline, the annex requires:
- Governance: the laboratory is responsible for the POCT it supports. There must be a defined structure, typically a multidisciplinary group or committee, with authority over device selection, procedures, training and quality assurance across the sites where testing happens.
- A quality assurance programme for POCT that covers internal quality control, external quality assessment and the review of results, applied to each device and location.
- Training and competence of the people performing POCT, who are usually not laboratory staff, with authorisation to test tied to demonstrated competence and its maintenance.
- Documented procedures, controlled by the laboratory, for each device and test, including result reporting, record keeping and what to do with abnormal or critical results.
- Equipment and consumables managed under the same clauses as laboratory equipment: acceptance, records, maintenance, calibration, reagent lot control and storage conditions.
The consequence is that a POCT service can no longer sit slightly outside the laboratory's system with its own arrangements. Its devices are laboratory equipment, its operators are people whose competence the laboratory controls, and its records are laboratory records.
Themes that changed the day-to-day
- Risk-based thinking replaces some prescription. The 2022 edition asks the laboratory to identify risks to patients and to its own operation and to act on them proportionately, rather than listing every document it must hold. A risk register with a defined scoring method and periodic review is the usual evidence.
- Ensuring the validity of results (7.3.7) brings IQC, EQA and comparability into one place. IQC has to be reviewed at a defined frequency with action on rejections; EQA participation is expected where schemes exist, with investigation of unsatisfactory performance; and where the same analyte is measured on more than one device or site, comparability between them has to be demonstrated periodically.
- Measurement uncertainty (7.3.4) is expected for quantitative examinations, with a defined procedure, and made available to users on request.
- Competence (6.2) is about demonstrated ability, authorisation and maintenance over time, with records. For POCT, this is the training matrix and the evidence behind it.
- Adverse incidents and field safety notices (6.4.6) require a process for reporting device incidents to the manufacturer and the regulator, and for acting on notices, which means knowing which lots and devices are affected.
- Management review (8.9) lists inputs that now include POCT data: QC, EQA, nonconformities, complaints, audits, risks and the effectiveness of actions.
The records POCT services are now asked to show
| Area | What an assessor typically asks for | Where it usually lives today |
|---|---|---|
| Devices | Acceptance and verification records, maintenance and service logs, calibration, downtime, location, firmware | Device files, engineer reports, a clipboard by the device |
| QC | Charts per device and level, rule violations, failure reviews, periodic review with sign-off | Data manager or middleware, spreadsheets, paper logs |
| EQA | Participation, returns on time, performance, investigation of unsatisfactory results | Scheme reports, email |
| Comparability | Periodic comparison between devices and sites for shared analytes | Spreadsheets, rarely done |
| Competence | Who is authorised on which device, assessed by whom, until when | Training spreadsheet, HR system |
| Reagents and lots | Lot acceptance, storage temperatures, in-use dating, traceability from result to lot | Delivery notes, fridge logs |
| Nonconformities and incidents | Register, root cause, corrective action, effectiveness, device incident reporting | QMS software, Datix, email |
| Management review | Inputs and outputs with POCT included | Slides assembled before the meeting |
A gap check for a POCT service
- A named group with authority over POCT, with terms of reference and minutes
- A device inventory that includes every POCT device, with a verification file and equipment record for each
- A QC procedure per device with rules, review frequency and evidence of review and action
- EQA enrolment where schemes exist, and a record of investigations
- A comparability plan for analytes measured on more than one device or site
- A competence framework for POCT operators with current authorisations
- A procedure for critical and abnormal results at the point of care, and evidence it is followed
- Reagent lot control and storage monitoring at every POCT location
- A route for device incidents and field safety notices that can identify affected lots and results
- POCT inputs in the risk register, the internal audit programme and the management review
Where software helps
Most of the rows above are hard because the evidence is created on wards and in clinics by people whose job is not record keeping. Software that sits where the testing happens can generate the records as a by-product: QC captured from the analyser with rules and a signed monthly review, EQA deadlines and investigations, competence per operator per device, equipment records, lot traceability, and a quality system with an ISO 15189:2022 checklist that includes Annex A and a management-review pack drawn from the live data. Whether a service is accredited is decided by the accreditation body on the evidence; the software's job is to make sure the evidence exists.
Questions people ask
Is ISO 22870 still valid?
No. ISO 22870:2016 was withdrawn when ISO 15189:2022 was published. Its requirements are now in Annex A of ISO 15189:2022, which is normative.
Does a POCT service need its own accreditation?
Under the 2022 edition, POCT is accredited as part of the responsible laboratory's scope, not as a separate scheme. Speak to your accreditation body about how POCT is expressed on the schedule.
What does risk-based mean in practice?
That the laboratory identifies what could harm patients or its own service, scores and prioritises it, acts proportionately, and reviews it. A risk register with a scoring matrix, owners and review dates is the common evidence; the standard references ISO 22367 for risk management in medical laboratories.
Do we need measurement uncertainty for POCT analytes?
For quantitative examinations, yes: a defined procedure for estimating it and the estimates available on request. An approach based on IQC imprecision and bias data, as in ISO/TS 20914, is widely used.
This article is general guidance for laboratory and point-of-care professionals. It is not a substitute for the standards themselves, your accreditation body's requirements or the analyser manufacturer's instructions for use. Catenix does not interpret clinical results and provides no clinical decision support.
Read next
More for coordinators.
How to verify a new POCT analyser
A practical, standards-based sequence for verifying a new point-of-care analyser before patient use: precision (CLSI EP15, EP05), method comparison...
Read →Westgard rules explained for POCT teams
What each Westgard rule detects, which kind of error it points to, how rules combine into a multirule, how sigma decides which rules you need, and...
Read →Take it with you
The buyer's guide, in your inbox.
Nine pages on what POCT connectivity is, the standards in plain English, the cost of doing it by hand and eight questions to ask any supplier.
Get the POCT connectivity buyer's guide
Nine pages, vendor-neutral: what connectivity is, the standards in plain English, the cost of doing it by hand and eight questions to ask any supplier. The PDF also opens directly from the downloads page; leave an email only if you want it in your inbox.
See it done in software.
A 30-minute walkthrough on a live tenant, with your analysers and your allowable-error limits.