Select a non-conformance from the register, or add findings from an audit report under Add non-conformances.
From an audit report or NC register
Claude extracts each findingReview before adding
| Ref | Category | Clause | Finding | Evidence the auditor cited |
|---|
Single non-conformance
Type it in directlyGap audit against ISO/IEC 17025:2017
Not yet runAbout the standard itself. The clause-by-clause requirements built into this audit are our own plain-language statement of what each clause obliges a laboratory to demonstrate — the text of ISO/IEC 17025:2017 is copyrighted and is not distributed with this tool. If your laboratory holds a licensed copy you may upload it under Quality system as Standard (your licensed copy); it stays in your laboratory's own library, is never shared with any other laboratory, and is used only to make your findings more precise. Check your licence terms first — many are issued to a single named user.
Risk assessment matrix
Generic defaultSelect a risk or opportunity, add one, or raise entries from the root causes already in the NC register.
Assessment scores the entry on the matrix above, proposes treatment, re-scores the residual risk, and repeats until the residual falls to the acceptance criterion — or reports that it cannot, for a documented management decision.
Laboratory profile
Shared with everyone using this registerQuality manual, procedures & policies
Claude cites these when clearing an NCHow a non-conformance is cleared here
Capture the finding
Type a single NC, or upload the audit report or register. Claude splits it into individual findings, each with clause, category and objective evidence, for you to review before anything enters the register.
Ground it in your system
The clearance reads the laboratory profile and searches the uploaded quality manual, procedures and policies for the passages that govern the finding, so root causes point at real documents.
Analyse
Claude maps the finding to ISO/IEC 17025:2017, restates it as requirement, evidence and gap, proposes the immediate correction, runs the 5 Whys to a root cause, and drafts corrective actions with an effectiveness check.
Own it and close it
Every field is editable. Fill owners and dates (they arrive as TBC), record the evidence of implementation, mark the NC cleared, and export the record for the auditor.
Carry it into the risk register
A cleared root cause becomes a risk entry. It is scored on your own matrix, treated, re-scored, and treated again until the residual risk reaches your acceptance criterion — with every round kept as the evidence trail for clause 8.5.
What the analysis follows
The corrective-action structure mirrors clause 8.7 of the standard: react to the nonconformity and correct it, evaluate whether similar nonconformities exist or could occur, determine the cause, implement action proportionate to the effect, review its effectiveness, update risks and opportunities (clause 8.5), and change the management system where needed. Nonconforming work itself is handled under 7.10.
Claude does not quote the standard verbatim; it works from the clause structure and your own documents. Treat every draft as a proposal to be checked by the quality manager, especially owners, dates and anything marked TBC.
How the risk cycle terminates
Assessment is an actual loop, not a single answer. The entry is scored for likelihood and consequence on the laboratory's own matrix, treatment is proposed, and the residual is re-scored. If that residual still sits above the acceptance criterion the loop runs again, adding treatment on top of what is already there, up to four rounds. It stops when the residual is acceptable, or when two consecutive rounds fail to reduce the score — in which case the entry is marked for a documented management decision rather than being quietly declared safe. Every round is kept, so the register shows how the risk came down, which is what an assessor asks for.
Privacy and cost
Documents are stored with this register and visible to everyone in your organisation who can open the page. Each analysis runs on the account of the person who clicks the button; the first click asks for permission.