OMS Software

OMS Blog

Sample Management & Chain of Custody Software: From Field Collection to Lab Report

How testing laboratories register, track, store and dispose of samples — and why an unbroken chain of custody is the foundation of defensible test results.

·Jayant Chandavarkar

A test result is only as reliable as the sample it came from. If the sample was mislabelled at collection, mixed up at receipt, stored at the wrong temperature, or tested without a documented record of who handled it and when, the result — however technically precise — is legally and scientifically indefensible. Sample management is not a paperwork exercise. It is the foundation on which every test result stands.

For accredited testing laboratories, this foundation is formalised through ISO/IEC 17025 Clause 7.4 and through the chain of custody documentation that environmental, food, pharmaceutical, forensic, and construction labs are required to maintain. Getting it right manually — with paper log books, printed CoC forms, and spreadsheet storage registers — is possible at low volume. At scale, it breaks down. Here is what best-practice sample management looks like, and how software makes it reliable.

What Sample Management Covers in a Testing Laboratory

Sample management encompasses every stage of a sample's life inside — and immediately outside — the laboratory:

Each stage generates records that must be retained and linked. A break at any point creates a gap in the chain that an assessor — or a legal challenge — will find.

The practical consequence of poor sample management is significant. Results disputed by clients, samples that cannot be retrieved for re-testing, instruments used on compromised samples, and reports that cannot be connected back to a documented sample history all create real commercial and regulatory risk. For environmental monitoring labs providing data that informs regulatory decisions, or forensic labs providing evidence to courts, that risk is heightened further.

Chain of Custody — What It Is and Why It Matters

Chain of custody (CoC) is the documented, unbroken record of who held a sample, when, and what was done to it at each transfer of possession. The term has legal origins — in forensic and environmental testing, a CoC form is the mechanism that allows a test result to be admitted as evidence in legal proceedings. But its value is not limited to legal contexts. Any testing laboratory that wants its results to be defensible — commercially, technically, or under accreditation review — needs an intact chain of custody.

Industries where CoC is mandatory

Environmental testing labs are the most familiar with formal CoC requirements. Samples collected for regulatory monitoring — water quality, air quality, soil contamination — must have a complete CoC documenting field collection, transport conditions, and receipt. Regulatory bodies can and do reject non-conforming results if the CoC is incomplete.

Food testing labs receive samples from production lines, retail shelves, and border control. Chain of custody establishes that the sample tested was the sample collected, and that the testing result applies to the specific batch or lot described in the instructions.

Pharmaceutical testing labs operate under both ISO/IEC 17025 and GMP-adjacent requirements. Samples for release testing, stability testing, and method validation all require full traceability from receipt to result.

Forensic labs face the most demanding CoC requirements. Every transfer of a forensic sample — from crime scene to transport to receipt to analysis — must be individually documented and signed. A break in this chain can render a result inadmissible.

Construction material testing labs receive concrete, soil, steel, and aggregate samples for compliance testing. CoC documentation protects both the lab and the client if a result is disputed — it establishes that the sample tested was the one collected from the specified location, at the specified time, under specified conditions.

What a CoC form must contain

A properly completed chain of custody form should document: client name and project reference; sample description, type, and matrix; collection location and date/time; sampling method; collector identity; sample container type and preservation method; transport conditions (including temperature monitoring where required); number of containers; requested tests; any special instructions; and a transfer log showing each person who held the sample and the date/time of transfer. For samples sent from the field, the sampler completes the form, signs it, and the receiving person at the laboratory counter-signs on receipt. Any discrepancy between what was sent and what arrived must be documented.

Sample Registration and Login

Sample registration — the intake process at the laboratory — is the most critical moment in the sample lifecycle. This is where a physical object becomes a laboratory record, and where errors introduced are hardest to recover from.

Receipt inspection

Before any sample is logged into the system, the receiving technician should inspect and record: container integrity (no damage, no leakage), labelling (does it match the CoC form?), temperature on arrival (for temperature-sensitive samples, measured with a calibrated thermometer), preservation status (correct preservative used?), and completeness against the CoC form. Any deviation — a container that arrived damaged, a temperature excursion in transit, a preservative omitted — must be recorded immediately and communicated to the client before testing proceeds. ISO/IEC 17025 Clause 7.4.3 is explicit: the laboratory must record condition on receipt, including any deviation, and must notify the client when in doubt about suitability.

Sample ID assignment

Every sample that enters the laboratory must receive a unique identifier at the point of login. This is not optional. The identifier must be: unique within the laboratory system, ideally globally unique (not re-used after disposal); assigned by the system, not manually chosen by the technician; physically applied to the sample container immediately upon assignment; and linked to all downstream records — test assignments, results, storage records, and the issued report.

In modern laboratory sample management software, the system generates a unique ID automatically when a new sample record is created. The ID is printed as a barcode or QR code label. The technician scans the sample at each stage of the workflow rather than writing or typing the ID, eliminating transcription errors. Barcode sample tracking means the physical location of a sample is known at all times because every movement is scanned.

Sub-sample creation and splitting records

Many samples require multiple tests performed under different conditions or by different methods. A soil sample might be split for particle size analysis, chemical testing, and moisture content. A water sample might be sub-sampled for microbiological analysis and heavy metals. Each sub-sample receives its own unique ID, linked to the parent sample ID. The splitting record documents: the parent sample ID, the number of sub-samples created, the volume or mass allocated to each, and the method assigned to each. This link is essential for traceability — if a question arises about a specific result, the record must show which sub-sample of which parent produced it.

Sample login for environmental labs

Environmental testing laboratories typically have high sample volumes with time-sensitive tests — some parameters (dissolved oxygen, pH, some microbiological tests) have maximum holding times from collection to analysis measured in hours. Sample login software for environmental labs must capture collection time (not just receipt time), calculate holding time expiry for each parameter, and alert the scheduler when a sample is at risk of exceeding the holding time before testing is complete. This is an area where manual systems — the traditional lab log book — consistently fail at volume.

ISO/IEC 17025 Requirements for Sample Management

ISO/IEC 17025:2017 Clause 7.4 sets out the requirements for handling test and calibration items. Understanding these requirements clause by clause is essential for labs preparing for initial accreditation or for their next surveillance assessment.

Clause 7.4.1 requires the laboratory to have a documented procedure for the transport, receipt, handling, protection, storage, retention, and disposal of test items. This includes provisions that protect the laboratory and the client from damage, deterioration, or loss. The procedure must address all phases of sample life, not just receipt.

Clause 7.4.2 requires that all items received for testing or calibration be uniquely identified throughout the laboratory. The identification system must avoid ambiguity — the same ID cannot refer to different physical samples at the same time. For sub-samples, the system must maintain the link to the parent item.

Clause 7.4.3 requires that on receipt, the condition of the item is recorded, including any abnormality or deviation from specified conditions. When there is doubt about suitability for testing, the client must be consulted before proceeding. Where testing proceeds despite a known deviation, the report must note this condition and state that results apply only to the item as received.

Clause 7.4.4 requires that when items need to be stored or conditioned under specific environmental conditions, those conditions must be maintained, monitored, and recorded. The storage requirements — temperature range, humidity, light exclusion — must be specified for each sample type.

Clause 7.5 (Technical Records) requires that all data relating to a test item — from the original entry through every test performed — form part of the technical record, and that every record be traceable to the person who made it. This is the audit trail requirement: the system must show who logged the sample, who assigned the tests, who entered the results, and who approved the report.

For laboratories seeking or maintaining NATA accreditation or NABL accreditation, assessors routinely trace a sample through the system from the CoC form to the issued certificate. Gaps in this trace — samples logged without an ID, results without a sample reference, storage records that don't match login records — are recorded as non-conformances.

Sample Storage and Retention

Many test parameters require retention of the sample after testing for a period that allows re-testing if the original result is disputed. The laboratory's storage system must be able to hold samples safely under appropriate conditions, track their location, and alert staff when retention periods are expiring.

Storage conditions by sample type

Storage requirements vary significantly by matrix and test type:

The storage register — whether physical or digital — must record where each sample is, its storage location within the facility (room, rack, shelf position), the date it was placed in storage, and any temperature monitoring logs for the storage area.

Retention periods by industry

Retention periods should be defined in the laboratory's quality procedures, with reference to client requirements, regulatory requirements, and the laboratory's own policy:

The storage register in a sample management system allows the laboratory to see, at any point, every sample currently in storage, its retention period end date, and whether any samples are approaching or past their disposal date. Automated retention scheduling means disposal decisions are not missed under the pressure of daily operations.

Chain of custody within the lab

The CoC obligation does not end at laboratory intake. Within the laboratory, every transfer of a sample between storage areas, between technicians, or between testing areas should be logged. In a barcode-based system, this is a scan event — the technician who removes a sample from storage scans it out, and scans it back in on return. This internal CoC log is part of the technical record required under Clause 7.5 and is essential for demonstrating sample integrity if a result is later disputed.

Sample Disposal

When the retention period expires — or when the client instructs early disposal — the sample must be disposed of through a documented process. Disposal is not simply throwing a sample away. It is the final entry in the chain of custody record, and for many sample types, it carries significant regulatory obligations.

Disposal records

The disposal record for each sample must document: the sample ID, the disposal date, the disposal method used, the authorisation (who approved the disposal), and — for hazardous materials — the name of the licensed waste contractor, the consignment note number, and the destination facility. This record forms part of the technical record and must be retained for the same period as the other laboratory records, even though the sample itself has been destroyed.

Hazardous waste disposal

Chemical, biological, and radioactive samples require disposal through licensed channels:

Client consent for early disposal

If a client requests early disposal of their samples — before the standard retention period — the laboratory should obtain written consent from the client before proceeding and record that consent in the sample record. Similarly, if the laboratory needs to dispose of samples early for legitimate reasons (storage capacity, safety), the client should be notified in writing before disposal occurs. The sample receipt to report software should make it possible to record and retrieve this consent as part of the sample record.

Disposal logs and regulatory requirements

In Australia, laboratories disposing of chemical or biological waste are subject to state-based environmental protection legislation. The Environmental Protection Acts in each state set requirements for waste tracking, contractor licensing, and manifests. The laboratory's disposal log must be sufficient to demonstrate compliance with these requirements if inspected. Equivalent requirements apply under state or territory work health and safety legislation for hazardous materials in the workplace.

Managing Sample Management with Software

The workflow described above — receipt inspection, unique ID generation, barcode labelling, CoC recording, sub-sample creation, storage location assignment, retention scheduling, and disposal logging — can be managed manually. In a laboratory with low sample volumes and a small team, it often is. But as volume grows, the manual approach breaks down in predictable ways: samples are logged with IDs written on paper and entered into a spreadsheet later (creating a window for transcription errors), storage registers are not updated when samples are moved, retention periods are tracked in a shared calendar that nobody checks consistently, and disposal records are incomplete.

OMS handles the full sample management lifecycle in a single platform connected to the laboratory's test workflows:

Sample registration and login: When a new sample arrives, the technician creates a sample record in OMS. The system generates a unique sample ID and prints a barcode or QR code label. The CoC form details are recorded against the sample record — client, project, collection date/time, collection location, container details, requested tests, and any special instructions or deviations noted at receipt. All of this happens before the sample leaves the intake bench.

Barcode generation and scanning: Every sample in OMS carries a barcode or QR code that travels with it through the workflow. Technicians scan samples at each stage — when moving from intake to storage, when removing for testing, when returning to storage after testing. The scan log creates an automatic internal chain of custody record without requiring separate documentation.

CoC tracking: The full chain of custody — from field collection records through laboratory intake through testing through storage through disposal — is maintained in the sample record. Any user with appropriate permissions can see the complete history of a sample: who logged it, who accessed it, which tests were performed and by whom, where it was stored, and when it was disposed of.

Sub-sampling records: Sub-samples created from a parent sample are linked in the system. The parent-child relationship is preserved through the test record and through to the issued report, so a query about any result can be traced back through the sub-sample to the parent sample and the original CoC form.

Storage location management: OMS allows the laboratory to define its storage infrastructure — rooms, refrigerators, freezers, shelves, positions — and assign each sample to a specific location. The storage register is always current because it is updated at the point of sample movement. Temperature monitoring integrations allow continuous storage condition records to be associated with the sample record.

Retention scheduling: When a sample is logged, OMS calculates the retention period end date based on the laboratory's defined retention policy for that sample type. As the expiry date approaches, the system generates alerts so disposal is actioned on time — not missed because the relevant person was on leave or the manual register was not checked.

Disposal records: When a sample is disposed of, the disposal is recorded in OMS — method, date, authorising person, and for hazardous waste, the contractor details and consignment reference. The record is retained in the system as part of the sample's permanent history, even after the physical sample no longer exists.

Links to test results and reports: Every test result entered in OMS is linked to the sample record from which it came. The issued test report references the sample ID, and the full traceability chain — from the field CoC form to the test result to the issued certificate — is available within the platform. An assessor asking to trace a specific result back to its sample can be shown the complete record in minutes rather than hours of cross-referencing paper files and spreadsheets.

For laboratories managing multiple industries — an environmental lab that also does food testing, or a geotechnical lab that handles construction material and soil samples — OMS supports different retention policies, storage requirements, and disposal workflows by sample type within the same platform.

The goal of sample management software is not to add administrative overhead. It is to make the required documentation happen automatically as part of the testing workflow, so the records that are needed for accreditation compliance, client disputes, and legal defensibility are always complete — without relying on individuals to remember to update a register or check a calendar.

Frequently Asked Questions

What is chain of custody in a laboratory context?
Chain of custody (CoC) in a laboratory is the documented, unbroken sequence of possession and control of a sample from the moment it is collected in the field through receipt, login, testing, storage, and final disposal. It records who handled the sample, when, under what conditions, and what was done to it at each stage. An unbroken CoC is essential for the legal admissibility of test results and is required by accreditation standards including ISO/IEC 17025 Clause 7.4.
What does ISO/IEC 17025 require for sample management?
ISO/IEC 17025 Clause 7.4 (Handling of Test or Calibration Items) requires laboratories to: transport, receive, handle, protect, store and dispose of test items in a way that prevents deterioration, contamination or loss; record the condition of items on receipt including any deviations from specified conditions; assign unique identifiers to all items throughout the laboratory; and maintain records of the receipt condition, storage conditions, and any preparation or pre-treatment applied. Clause 7.5 (Technical Records) requires that these records be traceable to the specific results produced.
How long should a testing laboratory retain samples?
Retention periods vary significantly by industry and regulatory context. Environmental laboratories typically retain samples for a minimum of 28 days to allow for re-testing disputes, with longer retention (up to 5 years) for regulatory monitoring samples. Food testing labs retain samples until after the product's best-before or use-by date has passed. Forensic samples are retained as directed by the instructing authority — often until legal proceedings are finalised. Pharmaceutical laboratories may retain samples for the product shelf life plus one year. The laboratory should establish retention periods by industry sector and document them in its quality management system.
What information must be on a laboratory sample label?
A laboratory sample label must carry, at minimum: a unique sample identifier (system-generated number, barcode, or QR code); the client and job reference; the sample description or matrix type; the date and time of receipt or collection; and any special storage or handling instructions. For sub-samples derived from a parent sample, the label must also reference the parent sample ID. ISO/IEC 17025 Clause 7.4.2 requires that the identification system avoids confusion between items. Labels must remain legible throughout the storage and testing lifecycle — chemical-resistant, waterproof labels are required for samples stored in refrigerators, freezers, or chemical environments.
How does sample management software improve lab efficiency?
Sample management software improves laboratory efficiency in five main ways: it eliminates paper-based sample log books and the double-entry transcription errors that come with them; it automates unique ID and barcode generation at sample receipt so samples cannot enter the workflow unlabelled; it provides real-time visibility of where every sample is in the workflow and who has it; it triggers automated alerts when storage conditions are due for checking or when retention periods are approaching expiry; and it links each sample record directly to its test results and issued reports, meaning any query about a result can be traced back to the original sample receipt record without manual searching.
OMS Software

This article is published by OMS Software — operational management software built for testing, inspection & calibration companies. Learn what OMS does →