CTM buyer resource
Laboratory systems audit checklist
Use this printable decision tool to prepare a bounded conversation about a laboratory workflow or system. It is not a technical audit, does not establish compliance, and does not authorize access or production changes.
Print this checklist
- Write the workflow in plain language from intake through final delivery.
- Name the operational owner, technical owner, administrators, vendors, and people who approve changes.
- List systems, spreadsheets, documents, reports, labels, exports, and repeated manual handoffs.
- Mark the steps where work waits, gets re-keyed, is corrected, or depends on one person.
- Record the business decision the review must support: clarify, repair, automate, integrate, stabilize, replace, or defer.
- Identify outputs and daily paths that cannot be interrupted.
Evidence to gather
Gather existing workflow notes, diagrams, inventories, owner lists, vendor contacts, support agreements, runbooks, backup documentation, incident notes, and sanitized examples of important outputs. Record what is known, who supplied it, and when it was last verified. Unknown is an acceptable answer; do not turn an assumption into a fact just to complete the sheet.
For each system, note its purpose, legitimate owner, hosting location if known, dependencies, users, interfaces, and support path. For each document or handoff, note the source, destination, reviewer, frequency, exception path, and business consequence when it fails.
Red flags
- No named owner or no legitimate administrator can be identified.
- A critical workflow depends on one undocumented person, spreadsheet, workstation, or manual correction.
- Backup existence is assumed but restore evidence, ownership, or retention is unknown.
- Reports or exports are changed without version control, review, or acceptance checks.
- A proposed integration has no confirmed interface, reconciliation owner, or failure visibility.
- The requested solution is fixed before the current workflow and decision are understood.
Do not change production
Preparation is observational. Do not restart services, edit data, rotate credentials, test a restore, install software, alter a report, or “clean up” a workflow for the audit. If a serious risk appears, record it and route it to the authorized owner. Later change work needs a separate scope, current backup and rollback evidence, acceptance checks, and explicit authority.
Use the result
Bring the completed checklist to a fit conversation. The useful outcome is a smaller next decision: additional discovery, a bounded systems audit, document automation, an integration feasibility review, stabilization work, managed-product fit, or no project yet. Keep sensitive records and credentials out of initial intake.
Describe your systems need