ISO/IEC 17020 Software for NDT Inspection Bodies: A Clause-to-Record Map

ISO/IEC 17020:2026 replaced the 2012 edition on 27 March 2026, with accreditation transition ending 27 March 2029. Software for an NDT inspection body has to hold eight record sets: impartiality threat monitoring, independence type, personnel competence, equipment calibration traceability, versioned procedures, controlled inspection data under new clause 7.5, versioned reports, and separated appeals and complaints cases.

ISO/IEC 17020:2026, the third edition, was published 2026-03 and, in the words of its own Foreword, cancels and replaces the second edition, ISO/IEC 17020:2012, which has been technically revised. The Foreword names the main changes: the categorization of the inspection body's independence type has been changed to type A and type non-A; definitions of item and client have been included; a new subclause on the control of data and information and actions to address risks and opportunities has been added; the common elements in CASCO standards have been incorporated; risk-based thinking has enabled some reduction in prescriptive requirements and their replacement by performance-based requirements; and there is greater flexibility in the requirements for processes, procedures, documented information and organizational responsibilities. For an NDT inspection body those changes move work out of the quality manual and into the system of record. Clause 7.5 has no 2012 equivalent, and it governs the digital evidence chain that A-scans, radiographic images, encoder positions and thickness readings already live in.

Source: ISO/IEC 17020:2026, Conformity assessment — Requirements for bodies performing inspection, third edition 2026-03 (cancels and replaces ISO/IEC 17020:2012), published by ISO/CASCO in collaboration with CEN/CLC/JTC 1.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
ISO/IEC 17020:2026 clauses mapped to the record objects NDT inspection body software has to hold
Clause (2026, third edition)What the clause governsRecord object the software must holdEvidence an assessor opens
4.1 ImpartialityOngoing monitoring of the body's activities and relationships to identify threats to impartiality, including the relationships of its personnelDated threat register with relationship type, owner, assessment and mitigation; personnel declarations with review datesThe log of identified threats and the demonstration of how each was eliminated or minimized
5.1 IndependenceCategorisation as type A or type non-A, and the safeguards that follow from that categorisationClient and item records flagged against parent-organisation, group-company and conflicting-activity relationshipsA job where the body inspected an item its own group supplied, and the control that was applied
6.1 PersonnelCompetence criteria, qualification, training, authorisation and ongoing monitoring of inspectorsPer-person, per-method certification matrix carrying level, scope, training and experience hours, examination results, vision test, expiry and written authorisationOne inspector's complete file, then a report they signed on a named date
6.2 Facilities and equipmentSuitability, maintenance and calibration of equipment used in inspection activitiesAsset register keyed to serial number with calibration certificate, due date, traceability chain and out-of-service stateThe calibration certificate that was valid on the date of a specific UT thickness survey
7.2 Inspection methods and proceduresUse of appropriate methods and documented procedures, including the handling of deviationsVersioned procedure library bound to each job, with recorded and authorised deviationsWhich procedure revision governed a job run fourteen months ago
7.5 Control of data and informationNew in the 2026 edition: integrity, security and control of inspection data and informationAppend-only audit trail on result-bearing fields, role-based access, tested restore evidence, software change controlWho altered a flaw sizing value, when, and what the value was before
7.6 Inspection report or inspection certificateAccurate, clear and unambiguous reporting of results, and the handling of amendments to issued reportsReport versions with issue and amendment history, authoriser identity, and the data snapshot behind each versionAn amended report alongside the superseded original and the recorded reason for amendment
7.7 and 7.8 Handling of appeals and complaintsSeparate processes in the 2026 edition for appeals against conformity decisions and for complaintsCase objects with intake date, category, independence check on the decision-maker, outcome and client notificationThe full trail of one appeal, including who decided it and their independence from the original decision
Clause 6.3 covers externally provided products and services, so subcontracted NDT and external calibration suppliers need approval and monitoring records in the same system. Clause 8.3 Documented information and clause 8.4 Actions to address risks and opportunities apply across every row above, and Annex A on independence is normative while Annex B on optional report elements is informative.

What changed on 27 March 2026, and why it lands on your software

ISO/IEC 17020:2026 is the third edition of the conformity assessment standard for bodies performing inspection. Its Foreword states plainly that this third edition cancels and replaces the second edition, ISO/IEC 17020:2012, which has been technically revised. Accreditation bodies including UKAS, NATA and ANAB have set a transition window ending 27 March 2029, after which accreditation held against the 2012 edition ceases to be valid. For an NDT inspection body that means roughly one accreditation cycle, not three, in which to close the gaps.

The Foreword lists the main changes explicitly rather than leaving them to interpretation: the categorization of the inspection body's independence type has been changed to type A and type non-A; a definition of item and a definition of client have been included; a new subclause on the control of data and information and actions to address risks and opportunities has been added; the common elements in CASCO standards have been incorporated; risk-based thinking has enabled some reduction in prescriptive requirements and their replacement by performance-based ones; and there is greater flexibility in the requirements for processes, procedures, documented information and organizational responsibilities.

Read that list as a software specification rather than as a documentation exercise. Greater flexibility in documented information does not mean less evidence. It means the assessor stops checking whether you have written a procedure and starts checking whether your records demonstrate the outcome the clause requires. Records live in systems. An NDT body whose evidence is a shared drive of Word procedures and an Excel certification tracker has considerably more work before 2029 than one whose evidence is queryable on demand.

Impartiality (4.1) is a monitoring record now, not a policy PDF

Clause 4.1.3 requires the inspection body to monitor its activities and its relationships to identify threats to its impartiality on an ongoing basis, and states that this monitoring shall include the relationships of its personnel. The accompanying Note enumerates the relationship types that can create a threat: ownership, governance, management, personnel, shared resources, finances, contracts or marketing — including branding and sponsoring — and the payment of sales commissions or other inducements for the referral of new clients. The Note is careful to add that such relationships do not necessarily present a threat.

Ongoing is the operative word, and it is what breaks the common approach. A signed impartiality policy dated three years ago evidences a policy, not monitoring. What evidences monitoring is a dated register: each identified threat, the relationship type it arises from, the person or client it attaches to, the assessment made, and the action taken. Clause 4.1.4 requires that where a threat is identified its effect shall be eliminated or minimized so that impartiality is not compromised, and that the body shall demonstrate how it does so. Demonstration is a record.

NDT bodies generate these threats routinely and quietly. A Level III who also consults for the fabricator whose welds the body inspects. A technician whose relative manages the client's maintenance contract. A commission component in a business development salary — clause 4.1.7 states that personnel involved in inspection activities shall not be remunerated in a way that influences the results of inspections. The software's job is to turn each of those into a dated, owned, closed record rather than a corridor conversation nobody wrote down.

Type A and type non-A: the independence flag your system carries per job

The 2012 edition's three-way split into types A, B and C is gone. The 2026 Introduction states that the categorization of inspection bodies as type A and type non-A reflects the level of their independence, and that the impartiality requirements are equally applicable to both. This cleanly separates two concepts that were previously entangled. Independence is structural, sits in clause 5.1, and is governed by the normative Annex A. Impartiality is behavioural, sits in clause 4.1, and applies to every body regardless of type.

The practical consequence for an NDT company is that "we are type A" stops being a sentence in the quality manual and becomes a constraint the system has to enforce on every job. A type A body cannot inspect items its own legal entity has designed, manufactured, supplied, installed, purchased, owned, used or maintained. Job intake therefore has to test each new client and each item against that list and record the result of the test, so that the determination is deliberate and reviewable rather than assumed.

This is exactly where in-house inspection departments and hybrid service companies get caught. A company that sells NDT services and also sells refurbishment work, or that has a sister company performing welding repair, is effectively making an independence determination every time it accepts a job. If the CRM record and the job record do not carry the relationship flag, nobody makes that determination consciously — and the assessor samples until they find the one job where it went the wrong way.

Personnel competence (6.1): the certification matrix an assessor actually opens

Clause 6.1 covers competence criteria, qualification, training, authorisation and ongoing monitoring of inspection personnel. ISO/IEC 17020 does not name an NDT personnel scheme, and accreditation bodies accept internationally recognised ones. In North America that is usually an employer-based programme written to ASNT Recommended Practice No. SNT-TC-1A (2024 edition), or certification to ANSI/ASNT CP-189 (2024). ISO 9712:2021 governs most work outside the United States, and NAS 410 governs aerospace. Whichever applies, the standard requires the body to define and evidence competence, not merely to hold certificates.

The record set has the same shape under every scheme and is considerably larger than a scanned certificate. Per person, per method, per level: documented initial training hours, documented experience hours, general, specific and practical examination results recorded by part, the annual vision examination including near-vision acuity and colour contrast differentiation, the identity of the certifying Level III, the certification and expiry dates, and the written authorisation defining precisely what that individual is permitted to perform and sign. Recertification intervals and interrupted-service rules sit on top of all of it.

The failure mode is the expired certification that signed a report. It is trivially findable by an assessor — select a report, identify the signer, compare the signature date against the certification file — and it is trivially preventable in software by gating authorisation on live certification scope. A spreadsheet cannot gate anything; it can only be consulted by someone who remembers to consult it. That single automated control is the highest-value thing an ISO/IEC 17020 NDT body can implement.

Facilities and equipment (6.2): calibration traceability down to the wedge

Clause 6.2 requires suitable facilities and properly maintained, calibrated equipment. In an NDT context the object under control is not the instrument alone. A phased array inspection result depends on the flaw detector, the probe, the wedge, the cable, the encoder and the reference or calibration block, and each of those carries its own identity and its own calibration or verification state. Each has to be traceable to the specific inspection it contributed to, not merely present somewhere in an equipment list.

The traceability chain matters as much as the certificate itself. An assessor will ask where a reference block's dimensional verification traces to and expect a route through to a national metrology institute. For ultrasonic thickness measurement they will ask how the velocity calibration was performed on the day, on which block, by whom, and what the recorded values were. These are data captured at inspection time and bound to the result, not PDF attachments filed into a folder the following week.

Out-of-service and out-of-tolerance handling is the part most systems miss entirely. When an instrument is found out of tolerance at its next calibration, the body has to determine which inspections performed since its last valid calibration are affected and take action on them. That is a database query — list every result produced with serial number X between two dates, with the reports and clients they went to — and it is either instantaneous or it is a week of file archaeology performed under time pressure with a client waiting.

Control of data and information (7.5): the clause with no 2012 equivalent

Clause 7.5 is new. The Foreword names it among the main changes: a new subclause on the control of data and information and actions to address risks and opportunities has been added. There was no equivalent in the 2012 edition, which acknowledged that records could be electronic without meaningfully governing them. NDT is a data-heavy discipline — A-scans, C-scan volumes, radiographic images, encoder positions, thickness grids, corrosion rates, remaining-life calculations — and until 2026 the integrity of all of that was largely left to the body's own discretion.

The requirement set that follows will be familiar to anyone who has worked under a data-integrity regime in another sector. Inspection data has to be protected from unauthorised access and from alteration that cannot be detected. Systems have to be shown fit for their purpose before use and after change. Failures have to be logged and acted upon. If an inspector can open a stored thickness reading, change it, save it, and leave no trace, the body cannot demonstrate that it controls that record — and the report built on it inherits the problem.

Three capabilities carry most of clause 7.5 in practice. An append-only audit trail on every result-bearing field, recording prior value, new value, actor and timestamp. Role-based access that genuinely separates capture, review, approval and administration rather than granting everyone an admin login because it is simpler. And restore evidence, meaning a dated test in which data was actually restored and verified against source, not a backup policy document. Ask any prospective vendor to produce all three on screen.

Inspection reports and certificates (7.6): reproducible, amendable, attributable

Clause 7.6 governs the report or certificate, which is the output the client, the owner-operator and sometimes the regulator rely upon. Annex B remains informative and lists optional elements a body may choose to include. The requirements that actually bite are that results are reported accurately, clearly and unambiguously, that the report identifies who authorised it, and that amendments to a report which has already been issued are handled in a way that makes the change visible rather than silent.

Reproducibility is the software test that separates a system of record from a document store. Take a report issued eighteen months ago and regenerate it from the stored data. If the regenerated output does not match the document the client received, the body cannot demonstrate that the PDF reflects its records — the PDF has become the record, and everything behind it is decoration. Systems that store only rendered documents fail this quietly, because nobody checks until an assessor samples or a dispute reaches a lawyer.

Amendment handling is the second test and the one that generates findings. A corroded-area re-evaluation after further analysis, a client-requested clarification, a transcription error found during review after issue — each produces a new revision of a document that has already left the building. The record has to show the superseded version, the new version, the reason for the change, the person who authorised it and the date the client was notified. Overwriting the original is the failure, and it is common.

Appeals (7.7) and complaints (7.8) became separate processes

The 2012 edition handled complaints and appeals together. The 2026 edition separates them into clause 7.7, Handling of appeals, and clause 7.8, Handling of complaints. The definitions in clause 3 make the separation meaningful rather than cosmetic. An appeal, defined at 3.5, is a request by the client to an inspection body for reconsideration by that body of a decision it has made relating to the conformity of the item inspected, with a Note stating that an appeal is only possible if a statement of conformity has been issued.

A complaint, defined at 3.6, is an expression of dissatisfaction other than an appeal, by any person or organization, relating to the activities of the body, where a response is expected. Different definitions, different populations, different remedies. An appeal can overturn an accept or reject call on a weld and therefore has direct technical and commercial consequences. A complaint might concern a technician's conduct on site, a missed mobilisation, or a late report. Categorising each correctly at intake is the first control the software has to support.

The independence requirement is what the system has to enforce rather than merely record. The person deciding an appeal must not have been involved in the original decision being appealed. In a small NDT body with two Level IIIs and a heavy workload that is a genuine operational constraint, and the case record has to show it was met: who investigated, who decided, and their documented relationship to the original inspection and inspector. A shared mailbox and a folder of email threads cannot evidence any of that.

Risks and opportunities (8.4) and what a gap analysis should produce

Clause 8.4, Actions to address risks and opportunities, arrives alongside clause 7.5 as part of the same documented change. Risk-based thinking is precisely why the 2026 edition was able to reduce prescription: rather than instructing every inspection body to perform the same fixed set of actions, it requires each body to identify what can go wrong in its own context and to act on it. That is more flexible and considerably harder to fake, because the evidence is a live register with movement in it rather than a completed template.

For an NDT inspection body the risk set is specific and largely predictable: dependency on a single Level III for a whole method, technician certification lapsing unnoticed, an instrument found out of tolerance long after the affected inspections shipped, a subcontractor performing work outside its approved scope, loss of raw acquisition data, offline field data captured but never synced, and commercial pressure applied to a reject call during a turnaround. Each maps to a control, and most of those controls are software controls rather than policy statements.

A useful gap analysis produces three artefacts and nothing else: a clause-by-clause statement of the evidence you hold today, a list of gaps expressed as the record object that is missing, and an owner with a date against each gap. Bodies that instead begin by rewriting the quality manual have usually done the least valuable part of the work first. The manual describes the system; the assessment examines the records the system produced.

Why generic LIMS platforms do not fit NDT inspection bodies

Search results for inspection body software are dominated by laboratory information management systems built for analytical laboratories. Their underlying data model is a sample: something physically arrives, is logged in, is tested, produces a numeric result compared against a specification limit, and is eventually disposed of. That model is a reasonable fit for an ISO/IEC 17025 testing laboratory and a poor fit for inspection performed under ISO/IEC 17020, which is why generic vendors ranking for this query cannot answer the questions an NDT body actually has.

NDT inspections do not have samples. They have items in place — a piping circuit, a tank floor, a weld seam on a vessel that will still be in service in fifteen years. Clause 3.8 defines item broadly enough to encompass a product, process, service, material, location, facility, premises or installation, or parts of these. The record is positional and longitudinal: this thickness at this measurement location on this date, compared against the reading from the previous outage, producing a corrosion rate and a remaining-life estimate. Clause 3.1 defines inspection as determination of conformity with detailed requirements or, on the basis of professional judgement, with general requirements — a numeric limit is often not the answer at all.

The practical consequences are concrete rather than philosophical. A LIMS has no concept of a weld map, an encoder position, a probe wedge, a calibration block, or a technician's method-and-level certification scope. It cannot gate report sign-off on NDT certification because it does not model NDT certification. Configuring one to do so is a multi-year custom development effort, and the resulting system sits outside the vendor's product roadmap and support boundary. Starting from an inspection data model is materially cheaper than bending a laboratory one.

Atlantis NDT builds the ISO/IEC 17020 record set on an Odoo 18 core configured around inspection objects rather than samples: certification-gated sign-off, serial-level calibration traceability with out-of-tolerance recall queries, versioned procedures bound to jobs, audit-trailed results, and separated appeals and complaints cases. Affordable, accessible and fully customizable. Request a demonstration or a scoped quote at /contact, or send your clause-to-record gap list to info@atlantisndt.com.

When does ISO/IEC 17020:2026 become mandatory for accredited inspection bodies?

The third edition was published on 27 March 2026 and cancels and replaces ISO/IEC 17020:2012 from that date. Accreditation bodies have set a three-year transition ending 27 March 2029, after which accreditation granted against the 2012 edition ceases to be valid. Individual accreditation bodies apply earlier internal cut-offs for new applicants and for scheduled reassessments, so confirm the dates with yours.

Does ISO/IEC 17020 require the inspection body to use validated software?

The 2026 edition introduces clause 7.5, Control of data and information, which has no equivalent in the 2012 edition and brings the integrity, security and control of inspection data explicitly into scope. Where inspection data is created, stored or processed electronically — which describes nearly all modern NDT — the body has to demonstrate that its systems protect that data from unauthorised access and from undetectable alteration.

What is the difference between type A and type non-A under the 2026 edition?

The 2026 edition replaces the 2012 three-way A, B and C categorisation with two types. Type A is the fully independent third party whose legal entity is not involved in the design, manufacture, supply, installation, purchase, ownership, use or maintenance of the inspected item. Type non-A absorbs the former types B and C and relies on internal safeguards. The Introduction states impartiality requirements apply equally to both.

Can ISO 9001 software satisfy ISO/IEC 17020 clause 8?

The 2012 edition offered two routes at clause 8.1: a standalone management system, or one established in accordance with ISO 9001. The 2026 edition keeps 8.1 as General and adds 8.2 Policies and responsibilities, 8.3 Documented information and 8.4 Actions to address risks and opportunities. Either route leaves clauses 4 through 7 uncovered, and that is exactly where the inspection record objects live.

What personnel records must an NDT inspection body hold under clause 6.1?

Clause 6.1 requires competence criteria, qualification, training, authorisation and ongoing monitoring without naming an NDT scheme. In practice the file is per person and per method: documented training and experience hours, general, specific and practical examination results, the annual vision examination, the certifying Level III, certification and expiry dates, and a written authorisation defining exactly what that individual is permitted to sign.

Does ISO/IEC 17020 accreditation replace ISO/IEC 17025 for an NDT company?

No, because they cover different activities. ISO/IEC 17020 applies to inspection, which involves professional judgement in determining the conformity of an item. ISO/IEC 17025 applies to testing and calibration laboratories producing test results. Many NDT organisations hold both — 17020 for field inspection and 17025 for a materials or metallurgical laboratory. The scope statement on the certificate, not the standard number, determines what clients can accept.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.