Aliquora Team

Sample Traceability: Why Chain of Custody Is a QC Issue

Sample traceability isn't just a regulatory checkbox — it's the backbone of defensible QC. Learn how chain of custody failures happen and how to close the gaps.

Sample traceability is the difference between a result you can defend and one you can only hope nobody questions. This post argues that chain of custody is fundamentally a quality control problem — not a paperwork problem — and that treating it as the latter is how labs end up in front of auditors with answers they don't have.

Chain of Custody Is Not a Logistical Formality

Most labs think of chain of custody as a handoff document. Sample arrives, someone signs it in, testing begins. That mental model is incomplete and quietly dangerous.

Chain of custody is evidence. It answers the question: At every point in this sample's life in my facility, do I know where it was, who touched it, what condition it was in, and what decisions were made about it? If you can't answer that question for any point in the timeline, you don't have a chain of custody — you have a partial record and a liability gap.

The distinction matters because regulators and accreditation bodies treat it that way. ISO 17025:2017 clause 8.4 requires laboratories to maintain records sufficient to enable identification of factors affecting measurement results. FDA 21 CFR Part 211 requires traceability of laboratory records back to specific samples. Neither regulation is asking for a sign-in sheet. They're asking for a defensible account of every sample decision.

Where Traceability Actually Breaks Down

When labs lose sample traceability, it rarely happens because someone maliciously discarded a record. It happens in the ordinary friction of lab work.

The Re-labeling Problem

A sample arrives with a client label. Someone assigns it an internal identifier. Later, an analyst prepares a sub-sample and writes a shorthand on the tube. A second analyst, running the instrument, uses a slightly different identifier in the data file. By the time the result is reported, there are four identifiers across three documents — and reconciling them is left to whoever generates the COA.

This is not hypothetical. It is how cannabis labs have failed state audits and how food safety labs have issued recalls under ambiguous sample attribution. The error isn't one catastrophic mistake; it's four small conveniences that accumulate into an unresolvable record.

The Verbal Handoff

Analysts talk to each other. "I left the extracts in the fridge on the second shelf." "The retest samples are in the rack by the GC." These verbal handoffs are efficient and they are invisible to any audit trail. When an OOS result comes back three days later and the question is whether the sample was stored correctly, "I think someone told me where it was" is not a defensible answer.

The Retroactive Record

Perhaps the most structurally risky practice: recording sample movements and observations after the fact, often at the end of a shift or at the end of a batch. Memory degrades. Timestamps get estimated. What was actually a 4-hour storage excursion gets recorded as 45 minutes because that's what felt right. Retroactive records aren't necessarily fraudulent — they're often well-intentioned — but they are unreliable and they are exactly what auditors probe.

The Argument That This Only Matters for Regulated Industries Is Wrong

Some lab directors, particularly in contract testing environments outside heavy regulatory frameworks, push back on rigorous chain of custody on the grounds that their clients don't require it and their accreditation body hasn't flagged it.

This is a reasonable short-term view and a poor long-term one.

First, client requirements expand. A food safety lab that lands a contract with a major retailer will face that retailer's supplier quality requirements — which frequently include ISO 17025 accreditation or equivalent chain of custody documentation — often on a 90-day timeline.

Second, litigation is a different auditor. If a product recall implicates your test results, the question is not whether your accreditation body was satisfied. The question is whether you can prove your result was associated with the right sample, tested under controlled conditions, by a qualified analyst, with a calibrated instrument. Without traceability, you cannot prove that. You can only assert it.

Third, internal quality depends on it. If you can't trace a sample, you can't perform a meaningful OOS investigation. You can't determine whether an anomalous result reflects a real sample characteristic or a handling error. Traceability is what makes your QC data interpretable.

What a Defensible Chain of Custody Actually Requires

There is no universal template, but defensible chain of custody has identifiable components regardless of industry.

A unique, persistent identifier assigned at receipt. One ID, used everywhere, from the moment the sample enters the facility to the moment it is disposed of or returned. Sub-samples and aliquots derive their IDs from the parent — they don't get renamed.

Time-stamped custody transfers. Every time a sample changes hands or location, that event is recorded with a timestamp and an actor. This includes movement to storage, retrieval for testing, return to storage, and transfer to disposal.

Environmental and condition records linked to the sample. Storage temperature logs aren't useful unless they can be associated with specific samples during specific time windows. A fridge log that shows an excursion on Tuesday is only actionable if you know which samples were in that fridge on Tuesday.

Instrument and method linkage. The record connecting a result to a sample should include which instrument produced it, which method version was in use, and which analyst ran it. This is not bureaucracy — it is what allows you to scope an OOS investigation correctly.

Disposal documentation. Chain of custody ends at disposal, not at reporting. If a sample is retained for a stability study, the retention period and final disposition need to be recorded. Samples don't just stop existing.

The LIMS Argument: Systems Close the Gaps Humans Create

The tracking components described above can be implemented on paper, in spreadsheets, or in a LIMS. Let's be direct about what each approach actually delivers.

Paper and spreadsheet systems depend on humans remembering to record events in real time, using consistent identifiers, with accurate timestamps. They are not self-enforcing. An analyst under pressure will skip a step. A spreadsheet won't object.

A purpose-built system enforces the record. It requires a barcode scan before a sample can be checked out for testing. It timestamps events automatically. It flags when a sample is retrieved from a storage location that doesn't match its logged location. It links sub-sample IDs to parent IDs without human transcription.

Consider a concrete example: Meridian Environmental Testing, a 12-person water quality lab, was running chain of custody on a hybrid spreadsheet and paper system. During an ISO 17025 surveillance audit, the auditor asked to trace a specific sample — a drinking water composite — from receipt through reporting for a routine nitrate analysis. The lab needed 40 minutes and two staff members to reconstruct the record, and the reconstruction had a 6-hour gap in storage documentation. The non-conformance wasn't the gap itself; it was that the gap existed and the lab had no way of knowing it existed until asked.

After implementing a LIMS with sample tracking and custody transfer logging — in Meridian's case, Aliquora — the same trace took under two minutes and required no staff involvement beyond pulling up the sample ID. The audit finding didn't recur.

The argument isn't that software eliminates human error. It's that software reduces the surface area where human error can go undetected.

Implementing Chain of Custody Without Disrupting the Lab

The practical objection to rigorous chain of custody is real: scanning a barcode and logging a transfer takes time, and labs operate under throughput pressure. This is a genuine tradeoff, not a false concern.

The answer is to implement incrementally and instrument the highest-risk transitions first.

  • Receipt and login is the highest leverage point. A sample that enters the system with a persistent ID and a clear condition record at intake is already more traceable than most labs achieve.
  • Refrigerator and freezer transfers are the second priority. Storage condition failures are a leading source of OOS investigations, and they're also the transfers analysts are most likely to skip documenting.
  • Instrument checkout and return is third. Knowing which instrument processed a sample is often the critical piece in an OOS root cause investigation.

You don't need perfect chain of custody on day one. You need a complete chain of custody at the transitions that matter most for your most regulated test categories. Build from there.

Traceability as a Competitive Differentiator

Here's the argument labs rarely make explicitly: demonstrable traceability is a selling point.

Contract labs compete on turnaround time, price, and method capability. Those are commodities. A lab that can hand a client a COA with a full chain of custody audit trail — showing every custody transfer, every storage condition, every instrument used — is offering something that most competitors aren't. For clients in pharmaceutical, food safety, or cannabis, that documentation has direct value. It is what they need to defend their own product release decisions.

Some clients are beginning to request custody documentation as part of their supplier qualification process. Labs that have it built into their workflow will satisfy those requests immediately. Labs that don't will either lose the business or scramble to reconstruct records they didn't design their systems to produce.

Treatability is no longer a back-office QC function. It is increasingly part of what clients are buying.

Frequently Asked Questions

What is the difference between sample traceability and chain of custody?

Sample traceability refers to the ability to reconstruct a sample's complete history — its origin, handling, testing, and disposition. Chain of custody is a specific documented record of who had possession of the sample at each point in that history. Chain of custody is the mechanism that makes traceability possible; traceability is the outcome.

Does ISO 17025 require a formal chain of custody procedure?

ISO 17025:2017 does not use the phrase "chain of custody," but clause 8.4 (handling of test or calibration items) requires laboratories to have procedures for receipt, handling, protection, retention, and disposal of items — including documentation of unusual conditions. In practice, a defensible chain of custody procedure satisfies these requirements directly.

How long should chain of custody records be retained?

Retention requirements vary by regulatory framework and accreditation body. ISO 17025 requires records to be retained for a minimum period defined by the laboratory or specified by regulations, contracts, or clients — commonly five to ten years for testing records. FDA-regulated labs should consult 21 CFR Part 211 for specific retention periods by record type. When in doubt, retain longer and document your retention policy.

What should I do if there is a gap in a sample's chain of custody?

Document the gap, assess its impact on result validity, and initiate an investigation using whatever records are available. A gap does not automatically invalidate a result, but it must be acknowledged and evaluated. If the gap cannot be explained and the sample was used for a critical test, retesting from a retained portion or re-sampling may be necessary. Pretending the gap doesn't exist is the worst possible response.

Can a spreadsheet-based system provide adequate sample traceability?

It can, but it requires exceptional discipline and carries structural risks that purpose-built systems eliminate. Spreadsheets don't enforce timestamps, don't alert when a step is skipped, and don't automatically link sub-sample records to parent records. For low-volume labs with highly trained staff and simple workflows, a spreadsheet may be sufficient. For labs handling moderate-to-high sample volumes across multiple analysts, the error accumulation risk is real and the audit exposure is significant.