Home / Insights / Governance

POCT governance framework for multi-site services: a practical guide

GovernancePublished 2026-09-0810 min readUnited Kingdom

How to structure point-of-care testing governance when the testing happens in many places: the committee and its terms of reference, who is accountable for what, the six policies you need, what changes with scale, and the evidence an assessor will ask for.

Written and reviewed by the Catenix team. How these guides are written and checked.

In brief

  • MHRA guidance and ISO 15189:2022 Annex A between them expect clear accountable management, laboratory involvement appropriate to the service and its accreditation scope, a multidisciplinary POCT committee, a named coordinator, a written policy set and a quality assurance programme that reaches every site where testing happens.
  • The committee's terms of reference should state its authority (approving devices and tests, withdrawing them, signing off policy), its membership, its meeting cycle and where it reports, so that decisions have a home.
  • Six documents form the working policy set: the POCT policy, device procurement and verification, training and competency, QC and EQA, incident reporting, and document control.
  • Many sites change four things above all: you lose direct visibility, so you need standardised devices and procedures, lot-level control of reagents and controls, and a live device inventory.
  • Assessors ask for evidence per governance element; the table in this article maps each element to the record they will want to see and where it usually lives.

Take it with you: POCT readiness checklist · Catenix for labs one-pager (PDF, no form).

Why POCT needs its own governance

Point-of-care testing (POCT) is laboratory testing performed outside the laboratory, by people who are not laboratory staff, on devices the laboratory does not see every day. Everything that makes it useful, speed and proximity to the patient, also makes it harder to control. Most errors in POCT are not analytical. They are the wrong patient, the wrong sample, an expired strip, an untrained operator, a result written on a glove and never recorded. Governance exists to close those gaps.

Two documents define what good looks like in the United Kingdom. The Medicines and Healthcare products Regulatory Agency (MHRA) guidance Management and use of IVD point of care test devices recommends that any organisation using POCT has a multidisciplinary POCT committee, a POCT policy, a named coordinator, a training and competency programme, quality control and external quality assessment, and a route for reporting adverse incidents. It applies to hospitals, general practice, pharmacies, community services and private providers alike.

The second is ISO 15189:2022, the standard that the United Kingdom Accreditation Service (UKAS) assesses medical laboratories against. Its Annex A, which replaced ISO 22870:2016, places POCT under the laboratory's responsibility and asks for a documented governance structure, a group with authority over POCT, a quality assurance programme and a training and competence programme. Our page on ISO 15189:2022 and POCT covers the detail. Outside the UK the same skeleton applies: accreditation bodies assess POCT against ISO 15189, and the United States uses CLIA and the College of American Pathologists (CAP) Point-of-Care Testing Checklist to ask for the same elements in different words.

The POCT committee and its terms of reference

The committee is where POCT decisions are made and recorded. Without one, decisions are made by whoever bought the device. Its terms of reference should be a short controlled document that answers six questions.

  1. Authority. The committee approves new devices and tests before purchase, approves the policy set, can suspend or withdraw a device or a site, and signs off the annual quality report. Say so explicitly, because an assessor will ask whether the committee can stop a test, not only recommend.
  2. Membership. Chair (usually the laboratory director or a consultant with responsibility for POCT), the POCT coordinator, the quality manager, a clinical lead from each major user group, a senior nurse, a representative from informatics, procurement or finance, and, in a multi-site service, a lead from each site or site group. Name roles, not people, in the document.
  3. Frequency and quorum. Quarterly is typical; more often during a large rollout. Define the quorum so that decisions made at a thin meeting still stand.
  4. Reporting line. The committee reports upward, usually to the clinical governance or quality committee and from there to the board. It also reports downward: minutes and decisions go back to the sites.
  5. Standing agenda. Actions from last time, incidents and nonconformities, the quality metrics pack, training and competency status, new device requests, device and lot issues, EQA performance, policy documents due for review, audit findings.
  6. Review. The terms of reference themselves have a review date and a version number.

Minutes should record decisions, owners and dates: an assessor sampling a device will ask when the committee approved it and want to read that minute.

Roles and who is accountable for what

Accountability is the part of governance assessors test hardest, because it is where organisations are vaguest. Every role below should appear in the POCT policy, and every person holding one should be able to describe it.

Laboratory director (or head of the laboratory service). Accountable for POCT under ISO 15189:2022 Annex A. Chairs or sponsors the committee, holds the accreditation scope, and is the person UKAS holds responsible for the quality of results wherever they are produced.

POCT coordinator. The person who makes the programme run: maintains the device inventory, writes and controls the procedures, runs or oversees training and competency assessment, monitors QC and EQA, investigates incidents, visits sites and prepares the committee pack. In a multi-site service this is often a small team, with deputies at large sites.

Clinical lead. A clinician for each service using POCT (emergency department, diabetes, anticoagulation, primary care, sexual health). Owns the clinical case for the test, agrees the clinical pathway, and is the escalation point when results are questioned.

Ward, clinic or site link nurse. The local owner. Keeps the device list for the area current, chases competency renewals, checks QC is being run, reports faults and incidents, and is usually trained as a local assessor. Without link nurses, the coordinator becomes a bottleneck at the tenth site.

Device users. Nurses, healthcare assistants, pharmacists, GPs, physiotherapists, anyone running a test. Their responsibilities are simple and should be stated as such: use only devices and tests you are authorised for, follow the procedure, run QC when required, report anything unusual, never share a login.

Quality manager, informatics, procurement. Supporting roles: the quality manager runs the management system POCT sits inside, informatics owns the connectivity to the clinical system, procurement ensures nothing is bought without committee approval.

The policy set: six documents

A single enormous POCT policy is hard to maintain and harder to read. Six controlled documents, each with an owner and a review date, work better, as chapters of one manual if each can be updated on its own.

1. POCT policy

The overarching statement: scope (which sites, which settings), governance structure, roles, the principle that no POCT is introduced without committee approval, and the rule that all POCT results are recorded in the patient record. Signed at board or executive level.

2. Device procurement and verification

The route for a new device or test: business case, clinical need, laboratory review of the method, connectivity assessment, consumables and cost per test, and verification before patient use. The verification requirement comes from ISO 15189:2022 clause 7.3.2; our guide to verifying a new POCT analyser sets out a practical protocol. This policy is also where you state that donated, trial and self-purchased devices fall under the same rules.

3. Training and competency

Who trains, who assesses, what the assessment contains, the reassessment interval and its rationale, the triggers for early reassessment, how records are kept per person, per device and per test, and the lockout rule for lapsed operators.

4. Quality control and EQA

The internal quality control (QC) schedule for each device type, the acceptance rules (Westgard or manufacturer limits), what happens on failure, and the requirement that every test is enrolled in an external quality assessment (EQA) scheme where one exists, with named owners for distribution, submission and review of returns. This gives effect to ISO 15189:2022 clause 7.3.7.

5. Incident reporting

How a POCT incident or near miss is reported internally (usually through the organisation's incident system), how it reaches the coordinator and the committee, how it is investigated as a nonconformity, and when it is reported to the MHRA through the Yellow Card scheme as a device adverse incident.

6. Document control

How procedures are versioned, approved, distributed and withdrawn (ISO 15189:2022 clause 8.3). In a multi-site service this is the policy that fails most quietly: a site is still working to version 3 of a procedure the laboratory replaced with version 5 a year ago.

What changes when the service spans many sites

The framework above is the same for one site or fifty. What changes with scale is the effort required to know what is happening, and four things move from nice-to-have to essential.

Visibility

On one site the coordinator can walk the wards. Across a district of GP practices, a chain of clinics or a network of community diagnostic centres (CDCs) they cannot. Governance then depends on data arriving from the sites without anyone having to fetch it: QC results, EQA submissions, operator activity, device faults, stock levels. If those arrive by email and spreadsheet, the committee pack is a month out of date before it is written. The practical options are described in our guide to managing POCT across multiple sites.

Standardisation

One device model per test wherever possible, one procedure, one QC schedule, one training package. Every additional model adds verification, training, QC and lot-management work, so the estate should be standardised where it can be. The committee's procurement authority is the tool for holding this line, and the policy should say that a site wanting a different device must make the case to the committee.

Lot management

Strips, cartridges, reagents and QC material arrive in lots with expiry dates. Across many sites you need to know which lot is in use where, when it was verified, when it expires, and, if the manufacturer issues a field safety notice, which patients' results were produced with it. ISO 15189:2022 clause 6.6 (reagents and consumables) expects lot acceptance and records. Lot-level traceability is what turns a recall from a week of phone calls into a query.

Device inventory

A live register: every device by serial number, model, location, owner, software version, connectivity status, last service, next calibration and committee approval date. The inventory is the first document an assessor asks for, and on a multi-site service it is the one most often wrong, because devices move without anyone updating it. Tie the register to the connectivity: a device that has sent no result or QC run for a month is unused, moved or broken, and all three matter.

One further pressure comes with scale: people turn over faster than one coordinator can retrain them, which is why local link nurses and operator lockout matter.

Metrics for the committee pack

ISO 15189:2022 clause 8.8.2 asks the laboratory to establish quality indicators and review them. For POCT the committee pack should be short, consistent from one meeting to the next, and broken down by site, because a service-wide average hides the site that is failing. A workable set:

  • Test volume by site and device, as context, not as a quality measure.
  • Percentage of results transmitted electronically into the patient record, and the count that could not be matched to a patient.
  • QC pass rate and QC lockout events, by device type and site.
  • EQA returns submitted on time, and returns outside the scheme's acceptable limits with the status of the investigation.
  • Percentage of active operators with in-date competency, and any tests run outside that.
  • Devices overdue for maintenance or calibration; devices with expired lots detected in use.
  • Incidents and near misses by type, with open corrective actions and their age.
  • Documents overdue for review.

Each metric needs a definition, a source and an owner, or the numbers will be argued over instead of acted on. Trend them over at least four quarters. The point of the pack is the question it provokes: why is one site's QC pass rate lower than the others.

What the assessor asks for: element to evidence

UKAS assessors, internal auditors and CAP inspectors all work the same way: pick an element of the framework, ask for the evidence that it operates, then sample. The table maps each element to what they will want to see.

Governance elementEvidence an assessor asks forWhere it usually lives
POCT committeeTerms of reference, membership, minutes with decisions and actions, evidence a device was approved before useQuality management system, committee folder
Accountability and rolesPOCT policy naming roles, job descriptions, the coordinator's authorisation, the accreditation scope listing POCTPOCT policy, HR records, UKAS schedule
Device procurement and verificationBusiness case, committee approval, verification file with acceptance criteria set in advance and sign-offDevice file per model
Device inventory and maintenanceRegister by serial number and location, service and calibration records, decommissioning recordsAsset register, device management software
Training and competencyPer person, per device, per test records with assessor and expiry; the assessment checklist; the lockout ruleCompetency matrix or operator management software
Internal quality controlQC schedule, acceptance rules, QC results with failures and actions, Levey-Jennings reviewDevice or middleware QC records
External quality assessmentScheme enrolment per test and site, submission records, returns, investigations of poor performance and their closureEQA folder or EQA module
Reagent and lot controlLot acceptance records, lot in use by site, expiry checks, recall handlingInventory records
Results into the recordEvidence results reach the patient record, unmatched result handling, critical result procedureMiddleware and clinical system records
Incidents and nonconformitiesIncident log, investigations, corrective actions, Yellow Card reports where made, trend reviewIncident system, CAPA log
Document controlControlled procedure list with versions and review dates, evidence sites hold the current versionDocument management system
Management reviewAnnual review covering POCT with quality indicators, audit results, EQA, incidents and resourcing decisionsManagement review minutes

Two findings recur: a gap between what the policy says and what a site does, found by asking a nurse to describe the procedure; and evidence that exists but cannot be produced in the room because it is on a laptop at another site.

Where software helps

None of the framework above requires software, and an assessor will accept paper if it is complete and current. What software changes is the cost of keeping it that way across many sites, and the speed with which evidence can be produced.

The useful functions replace collection with capture. Devices connected to middleware report QC, results, operators and faults as they happen, so the committee pack is generated rather than assembled. One device register, operator register and lot register shared across sites means the coordinator and the link nurse see the same truth. An audit trail of who did what, when, on which device is the evidence an assessor samples from. Per-site views with a service-wide roll-up let the committee compare sites without a spreadsheet.

Catenix provides multi-site administration with a shared device inventory, operator register, QC and EQA records, lot traceability and dashboards per site and across the network, and our resource on managing POCT across multiple sites sets out the operating model in more detail. Whatever you use, apply the assessor's test: pick a device at a distant site and produce its approval, verification, operators, QC and lot in use without leaving the room.

Questions people ask

What is a POCT governance framework?

A POCT governance framework is the structure an organisation uses to control point-of-care testing: a named accountable laboratory, a multidisciplinary POCT committee with authority to approve and withdraw devices, a POCT coordinator, a policy set covering procurement, training, QC, EQA, incidents and document control, and a set of quality indicators reviewed regularly. MHRA guidance and ISO 15189:2022 Annex A describe the same elements.

Who should sit on a POCT committee?

A chair with authority, usually the laboratory director or a consultant responsible for POCT; the POCT coordinator; the quality manager; a clinical lead from each service using POCT; a senior nurse; representatives from informatics and procurement or finance; and, for a multi-site service, a lead for each site or group of sites. Define roles rather than individuals in the terms of reference so membership survives staff changes.

What does the POCT coordinator do?

The POCT coordinator runs the programme day to day: maintains the device inventory, writes and controls procedures, organises training and competency assessment, monitors QC and EQA, investigates incidents and poor performance, visits sites, prepares the committee pack and is the first contact for device users. In large or multi-site services the role is a small team with local link nurses as deputies.

Does ISO 15189:2022 cover point-of-care testing?

Yes. ISO 15189:2022 includes Annex A, additional requirements for point-of-care testing, which replaced the separate standard ISO 22870:2016. It places POCT under the laboratory's responsibility and asks for a governance structure, a group with authority over POCT, a quality assurance programme and a training and competence programme. UKAS assesses POCT as part of the laboratory's accreditation scope.

What policies does a POCT service need?

Six controlled documents cover most services: an overarching POCT policy setting out scope, governance and roles; device procurement and verification; training and competency; quality control and external quality assessment; incident reporting, including when to report to the MHRA; and document control. Each needs an owner, a version and a review date, and every site must be working to the current version.

How is POCT governance different across multiple sites?

The elements are the same, but the coordinator loses direct sight of the testing. Multi-site services therefore depend on standardised devices and procedures, lot-level control of reagents and QC material, a live device inventory by serial number and location, local link nurses at each site, and data that arrives from devices automatically rather than being collected by hand for each committee meeting.

Sources and further reading

Take it with you

The buyer's guide, in your inbox.

Nine pages on what POCT connectivity is, the standards in plain English, the cost of doing it by hand and eight questions to ask any supplier.

Get the POCT connectivity buyer's guide

Nine pages, vendor-neutral: what connectivity is, the standards in plain English, the cost of doing it by hand and eight questions to ask any supplier. The PDF also opens directly from the downloads page; leave an email only if you want it in your inbox.

We use your email only to send the guide and, if you ask, to follow up once. No newsletter unless you tick the box. See our privacy notice.

Thank you. The guide is on its way. You can also open it now.
That did not send. Open the guide directly or email contact@catenix.com.

See it done in software.

A 30-minute walkthrough on a live tenant, with your analysers and your allowable-error limits.