Home / Resources / Provable QC

Quality & governance · Inspection readiness

Your QC evidence, independently verifiable.

At inspection, "trust me, the QC was fine" is not evidence. This guide explains how tamper-evident QC receipts let an assessor confirm your quality trail is intact, offline, with no login and no need to trust us.

Published 20 July 2026 · Last reviewed: July 2026 · 7 min read

An assessor's job is to distrust your word and check the evidence. If your quality-control history is a spreadsheet you maintain and a system you control, then "the QC passed" is an assertion, not proof. The problem is not bad faith. It is that a record which can be edited without a trace cannot, on its own, show that it was not edited. Provable QC closes that gap: it lets an independent person confirm that the QC evidence you present is exactly the evidence that was captured, unchanged.

This guide covers the ordinary QC work first (capturing controls, charting them, checking the rules, locking out a device that fails), then the part that makes the evidence stand up to scrutiny: a tamper-evident receipt on every record that anyone can verify for themselves.

The problem

Why "the QC was fine" is not enough.

Three things an assessor asks that a hand-kept QC log struggles to answer.

Can I trust the record?

A spreadsheet can be corrected after the fact, and often is, for good reasons. But that also means a failed control could be quietly softened, and nothing in the file shows it. The record cannot vouch for itself.

Who ran it, and when?

Accreditation expects each control result tied to a named operator, a device and a timestamp. Typed logs lose that chain: a row of numbers rarely proves who entered them or whether the date is the date the control was actually run.

What rule was applied?

"It was in range" begs the question: which range, which rules, decided when? Evidence that the correct evaluation ran at the time of the control, not reconstructed for the visit, is what turns a number into a defensible decision.

First, the ordinary QC work, done automatically

Before any of the verification story matters, the routine has to be right. Catenix captures quality control the same way it captures patient results: electronically, from the analyser, at the moment the control is run. There is no separate spreadsheet to keep and nothing to re-type, which removes the most common source of a missing or mistyped QC entry. Our guide to QC software for point-of-care devices covers the day-to-day workflow in depth; here is what sits underneath the receipts.

  • Capture. Control results arrive from the device automatically and are kept separate from patient results, so quality data never mixes with the clinical record. Each control carries its lot, level, operator, device and timestamp.
  • Chart. Every control plots onto a Levey-Jennings chart against your mean and limits, with a CUSUM overlay to surface slow drift that individual points can hide. Trends are visible before they become failures.
  • Rule-check. Each run is evaluated against Westgard multi-rules (the 1-2s warning, and rejection rules such as 1-3s, 2-2s, R-4s, 4-1s and 10-x), so a warning is distinguished from a genuine rejection rather than every deviation reading as an alarm.
  • Lock out. When a control fails a rejection rule, a lockout engine can hold the device until the failure is investigated and resolved. The principle is simple: no cert, no QC, no test. The block, and its release, both leave a record.

This is statistical data-quality monitoring and process control. It is not interpretation of any patient result, which stays with the clinician and the analyser's instructions for use. For the statistics behind the rules, see our field guide to Levey-Jennings charts and Westgard rules.

The idea

A receipt an outsider can check.

The step that turns a QC log into evidence: every record carries proof that it has not changed since it was written.

When Catenix records a QC run, it also writes a small tamper-evident receipt alongside it, using standard public-key cryptography. Think of the receipt as a seal over the record: the control values, the operator, the device, the timestamp and the rule outcome. If any of those change later, even by a single digit, the seal no longer matches, and an independent check will say so.

The important word is independent. The receipt can be verified by a tool that has nothing to do with Catenix and never contacts us, so the maths, not the vendor, does the vouching. That is what separates it from an audit log inside a system, which an assessor still has to trust the vendor about.

There are two ways an assessor or a lab manager can check a record, and both work without a Catenix account:

  • Drag the file into a web page. Export the QC record, open the verification page, and drop the file in. The page re-computes the receipt in the browser and reports, in plain language, whether the record is intact and unchanged. Nothing is uploaded anywhere.
  • Run an offline checker. For assessors who prefer to work off the network entirely, a small command-line checker performs the same verification on a laptop with no internet connection at all.

In both cases the answer is a straightforward yes or no: this record is the record that was captured, or it has been altered. No login, no trust in us required.

Two honest limits. First, this is tamper-evident, not tamper-proof: it makes any change to a stored record detectable, rather than making change impossible, and we do not claim that fraud is impossible. Second, it proves the integrity of the QC record and the rule evaluation that ran, not the clinical correctness of any patient result. It shows that your process trail is intact, which is precisely what an assessor needs to see.

How verification runs

Export, open, drop, read.

01
Export
Pull the QC record, or a run of them, out of Catenix as a file. The receipt travels inside the file, so the evidence stays with the data.
02
Open the checker
Open the verification page in any browser, or launch the offline checker on a laptop. Neither needs a Catenix login, and neither contacts our servers.
03
Drop the file
Drag the exported file in. The tool re-computes the receipt locally, on the assessor's own device, using the published verification key.
04
Read the result
Plain-language verdict: the record is intact and unchanged, or it has been altered. The assessor draws their own conclusion, on their own terms.

How this maps to ISO 15189-aligned evidence

ISO 15189:2022, the standard for medical laboratory quality and competence, expects a laboratory to run quality control appropriate to its methods, to keep records of that control, and to be able to show those records are reliable and traceable. Provable QC is built to sit comfortably against those expectations, without claiming to grant accreditation, which no software can do.

  • Control is charted and evaluated. Levey-Jennings charting and Westgard multi-rule evaluation are applied at the time of each run, aligning with the standard's expectation of statistical quality control appropriate to the examination.
  • Records are complete and traceable. Each control ties to its operator, device, lot, level and timestamp, and the whole quality trail sits in a wider tamper-evident audit trail. See our plain-English guide to ISO 15189 and POCT for how the clauses map to point-of-care practice.
  • Evidence is defensible to a third party. The independently verifiable receipt gives an assessor a way to confirm reliability without taking the laboratory's or the vendor's word for it, which is the essence of what they are there to establish.

Catenix produces and preserves this evidence. It does not interpret clinical results and provides no clinical decision support: it does not re-calculate values, re-classify results, derive estimated quantities, or auto-flag. Interpretation, validation and authorisation stay with your clinicians, exactly where accreditation expects them.

Where the receipts fit the wider record

Verifiable QC receipts are one instance of a pattern that runs through the platform. The same tamper-evident approach underpins the audit trail (every login, edit, review and report release recorded against the authenticated actor) and the signed completeness manifest that ships with released reports. The result is a quality story an assessor can follow from a single control run all the way to a signed report, with each link checkable. To see how the quality and governance layer holds together, read the quality and governance overview or the security and trust approach behind it.

← Back to resources

Questions, answered

The questions buyers ask first.

What does provable QC mean?

Provable QC means your quality-control evidence can be checked by someone who does not trust the system that produced it. Each QC record carries a tamper-evident receipt: an assessor or lab manager can confirm the record has not been altered since it was written, without logging in and without taking Catenix's word for it. It is a way to show your QC held, rather than simply asserting that it did.

How does an inspector verify a Catenix QC receipt?

They drag the exported file into a verification page in a web browser, or run a small offline checker. Either tool re-computes the receipt using standard public-key cryptography and reports whether the record is intact and unchanged. No account, no connection to Catenix and no trust in Catenix is required, because the check runs entirely on the assessor's own device.

Does provable QC prove my results are clinically correct?

No. It proves that the QC record you present is the record that was captured, unaltered, and shows the rule evaluation that was applied at the time. It is evidence of an intact process trail, not a judgement about any patient result. Interpretation, validation and authorisation of clinical results stay with your clinicians.

Is this the same as a tamper-proof or fraud-proof system?

We describe it as tamper-evident and independently verifiable, not tamper-proof. The point is that any change to a stored QC record is detectable by an independent check, so an altered record cannot quietly pass as genuine. It is designed to make quality evidence trustworthy to an outsider, not to make change impossible.

See your QC evidence stand up.

Bring your analyser list. We'll show a control run, rule-checked and independently verifiable, live.