Control of monitoring and measuring equipment fails, in most organizations, in a drawer. There is a steel rule in a drawer on your production floor. It cost eleven dollars. Nobody knows when it arrived, nobody has ever calibrated it, and it is not on any register anywhere in your organization. It is also the thing your most experienced operator reaches for when the gauge is out being serviced, because it is right there and it has always been right there.
That rule is the whole problem with control of monitoring and measuring equipment in one object. Not negligence, not incompetence — a register that describes an intended system and a floor that runs a real one. Control of monitoring and measuring equipment is the ISO requirement that most organizations believe they have discharged because they hold a folder of calibration certificates, and it is the requirement that certification auditors keep writing up anyway.
Direct Answer
Control of monitoring and measuring equipment is the set of decisions an organization makes to ensure that any measurement used to judge conformity is fit for the judgement being made: determining what has to be monitored or measured, selecting equipment capable of the required resolution and accuracy, calibrating or verifying it against traceable references at defined intervals, identifying its status, safeguarding it from adjustment or damage, and determining the validity of previous results when equipment is later found to be out of tolerance. It sits at Clause 7.1.5 in ISO 9001:2015 and Clause 7.6 in ISO 13485:2016.

Determine. Demonstrate. Defend. Those three obligations, in that order, are what separates control of monitoring and measuring equipment that holds up from a drawer of certificates that does not.
Across 200+ audits attended in 28 years, MSI consistently sees monitoring and measuring equipment among the three most frequently cited areas — alongside internal audit and corrective action. That is a first-party observation from MSI's own audit-attended history rather than an industry statistic, and it is worth stating plainly because the pattern is so stable. The findings are rarely dramatic. They are almost never a laboratory failure. They are a device on the floor that is not on the list, a certificate that says less than the organization thinks it says, or an instrument that was correct while the decision it fed was wrong.
This article covers where control of monitoring and measuring equipment lives across five ISO standards, the requirement almost nobody implements, two worked examples that show how competent organizations miss it, what changes now that ISO 10012:2026 has been published, and the eight elements a working procedure needs. If you would rather score your own process before reading further, the free Control of Monitoring and Measuring Equipment Maturity Check takes about six minutes, gives you a band and a priority order, and asks for nothing first.
Section 1 · Where the requirement lives
Where control of monitoring and measuring equipment sits in each standard
Locate. Compare. Reconcile.
The first practical difficulty is that this requirement does not sit in the same place twice, and it is not called the same thing twice. An organization running more than one management system cannot copy a clause reference across, and a procedure for control of monitoring and measuring equipment written to one standard will silently miss obligations in another.
| Standard | Where it sits, and what it is called |
|---|---|
| ISO 9001:2015 | Clause 7.1.5, Monitoring and measuring resources, in two parts — 7.1.5.1 general suitability and maintenance, 7.1.5.2 measurement traceability. Traceability is conditional, not universal. |
| ISO 13485:2016 | Clause 7.6, Control of monitoring and measuring equipment — the only one of the five that uses the phrase as the clause title. Numbering does not align with ISO 9001 because ISO 13485 predates the harmonized ten-clause structure. Adds documented procedures and software validation. |
| ISO 14001:2026 | No dedicated clause. The obligation is carried inside Clause 9.1.1, which requires that calibrated or verified monitoring and measurement equipment is used and maintained as appropriate. |
| ISO 45001:2018 | Clause 9.1.1, in the same position as ISO 14001 — equipment calibrated or verified as applicable, and used and maintained as appropriate. Exposure monitoring instrumentation is the practical centre of gravity. |
| ISO 7101:2023 | Clause 9.1, supported by the resources and infrastructure requirements in Clause 7.1 — reaching clinical measurement devices, which are frequently owned by biomedical engineering rather than quality. |
The two rows that catch people are ISO 14001 and ISO 45001. Because neither carries a clause titled control of monitoring and measuring equipment, organizations transitioning into an environmental or safety system routinely conclude that the requirement is a quality-only concern. It is not. A stack sampling train, a sound level meter, a personal dosimeter and a flue gas analyser are all monitoring and measuring equipment producing results that a management system relies on, and Clause 9.1.1 in both standards says so in one clause almost everyone reads as boilerplate.
The other change worth knowing about is that the dedicated standard on this subject has just been rewritten. ISO 10012, Quality management — Requirements for measurement management systems, published its second edition on 12 February 2026, replacing an edition that had stood since 2003. It has been restructured onto the harmonized management system structure and extensively revised. ISO 10012 is not a clause of ISO 9001 and conformity to it is not required by any of the five standards above, but it is now the most current consensus description of what good control of monitoring and measuring equipment looks like — and it is the document a well-prepared auditor will have read.
Direct Answer
Which clause governs control of monitoring and measuring equipment depends entirely on the standard: 7.1.5 in ISO 9001:2015, 7.6 in ISO 13485:2016, 9.1.1 in both ISO 14001:2026 and ISO 45001:2018, and 9.1 supported by 7.1 in ISO 7101:2023. Only ISO 13485 uses the phrase as a clause title, which is why organizations certified to the other four frequently do not recognize that they hold the obligation at all.
Section 2 · The requirement almost nobody implements
Control of monitoring and measuring equipment fails at the register, not the laboratory
Reconcile. Walk. Prove.
Ask to see how an organization discharges control of monitoring and measuring equipment and you will be handed a register and a folder of certificates. The register will be tidy. The certificates will be current, issued by an accredited laboratory, and filed in date order. Every device on the list will be in calibration.
Then walk the floor and count.
Here is the requirement almost nobody implements, and it is worth being precise about why: no standard in the family requires you to reconcile the register against the floor. ISO 9001 Clause 7.1.5.2 b) requires measuring equipment to be identified in order to determine its calibration status. ISO 13485 Clause 7.6 requires the same. Both requirements operate on equipment that is in the system. Neither asks the prior question — whether the system contains everything it should contain — because a standard cannot require you to control a thing it has no way to know exists.
The register proves that what you listed is calibrated. It proves nothing whatever about what you did not list. Control of monitoring and measuring equipment that has never been reconciled against the physical floor is a claim about a document, not about the organization.
The reconciliation that closes this in control of monitoring and measuring equipment is a physical walk. Two people, a printed register, and a defined area. Every device capable of producing a number that anyone acts on gets touched: benches, drawers, toolboxes, vehicles, quality labs, maintenance cages, the shipping desk, the receiving dock, and the drawer in the supervisor's office. Each item is either on the register, added to it, or formally excluded with a written reason. The output is not a tidy list. The output is a count of what was found that nobody knew about.
What organizations find when they reconcile control of monitoring and measuring equipment against reality, consistently, falls into five categories:
- Personal equipment. A tradesperson's own micrometer, caliper or multimeter, brought from home or from a previous employer, used because it is better than the company one and trusted because it always has been.
- Equipment that came with the machine. Integrated pressure gauges, temperature displays, load readouts and torque indicators built into production equipment. They are part of the asset register and absent from the calibration register, because purchasing bought a machine and quality never saw an instrument.
- Reference and setting devices. Gauge blocks, setting rings, weights, check standards and reference thermometers used to verify other instruments. They sit one layer up the traceability chain and are frequently the least controlled objects in the building.
- Retired-but-present equipment. Devices withdrawn from service, never labelled, never removed, sitting in the same drawer as the live ones. Nothing physically prevents their use, and the standard's safeguarding requirement is not met by intention.
- Software-based measurement. A vision system, a data logger, a spreadsheet applying a correction factor, a PLC comparing a signal against a limit. A number is produced and acted on, so it is measurement, and it is almost never on the register.
MSI client experience suggests that a first reconciliation in a mid-sized manufacturing operation surfaces devices in every one of those five categories, and that the personal-equipment category is the one that produces the most uncomfortable conversation. The instrument is usually good. The operator is usually right that it is better than the company alternative. None of that is the point. Control of monitoring and measuring equipment is a claim the organization makes about the validity of its own measurements, and it cannot make that claim about an object it does not know it has.
The fix in control of monitoring and measuring equipment is not to confiscate anything. It is to bring the device into the system: register it, calibrate or verify it, label it, and let the operator keep using it. Organizations that handle the first reconciliation as an amnesty rather than an audit get a complete register. Organizations that handle it as an enforcement action get a register that is complete on paper and a second drawer nobody mentions.
Direct Answer
The requirement almost nobody implements in control of monitoring and measuring equipment is physical reconciliation of the calibration register against the equipment actually present on the floor. No standard in the ISO 9001, 13485, 14001, 45001 or 7101 family requires it, because a standard cannot mandate control of items it has no way to know exist. The register proves that listed equipment is calibrated; it says nothing about unlisted equipment. A two-person walk with a printed register, treating found devices as an amnesty rather than an enforcement action, is the only mechanism that closes it.
Section 3 · The decision that comes first
Control of monitoring and measuring equipment starts before any equipment is chosen
Determine. Specify. Then select.
ISO 9001 Clause 7.1.5.1 opens by requiring the organization to determine and provide the resources needed to ensure valid and reliable results when monitoring or measuring is used to verify the conformity of products and services to requirements. The determination comes first. Almost every procedure for control of monitoring and measuring equipment that MSI reviews starts at the second step — here is our equipment, here is how we calibrate it — and never records the determination that produced the list.
That omission has a practical cost in control of monitoring and measuring equipment, and it shows up as the wrong instrument rather than an uncalibrated one. The chain runs in one direction:
- A requirement exists — a specification, a legal limit, a clinical parameter, a customer tolerance.
- A decision has to be made about whether that requirement is met.
- That decision needs a measurement of a stated quantity, to a stated resolution, with a stated confidence.
- Only then does an instrument get selected, and it is selected because it is capable of that measurement.
- Calibration follows, because the instrument's capability has to be demonstrated rather than assumed.
Skip step three in control of monitoring and measuring equipment and you buy an instrument that resolves to the same decimal place as the tolerance you are judging. The classic version is a caliper reading to 0.01 mm used to accept a feature with a ±0.02 mm tolerance. Nothing is out of calibration. The certificate is genuine. The instrument is simply not capable of supporting the decision, and every acceptance made with it is a coin toss dressed as a measurement.
The conventional engineering rule of thumb is that the accuracy of the measuring equipment should be a defined fraction of the tolerance being judged — ratios of 4:1 or 10:1 are the ones most commonly written into procedures. None of the five standards specifies a ratio. That is precisely why it belongs in your procedure for control of monitoring and measuring equipment: it is a decision the standard leaves to you, which means an auditor is entitled to ask what you decided and to see it applied. An organization that has never written a ratio down has not made the decision; it has deferred it to whoever was holding the purchase order.
The same determination governs the opposite error in control of monitoring and measuring equipment, which is over-controlling. A tape measure used to check whether a pallet fits through a door does not need traceable calibration, because no conformity decision depends on its accuracy at that resolution. Writing that exclusion down — with the reason — is part of control of monitoring and measuring equipment, and it is what keeps the register to a size the organization can actually maintain. A register that includes every ruler in the building will be abandoned within two years. A register built from recorded determinations will not.
Direct Answer
Control of monitoring and measuring equipment begins with a determination, not with equipment. ISO 9001 Clause 7.1.5.1 requires the organization to determine what monitoring and measurement is needed to verify conformity before it provides resources to perform it. The chain is requirement, decision, required measurement and resolution, then instrument selection, then calibration. Organizations that start at the equipment end acquire instruments that are fully calibrated and not capable of supporting the decision they are used for — and they have no recorded basis for excluding the instruments that genuinely do not need control.
Section 4 · Traceability
The word in control of monitoring and measuring equipment that is most often misused
Trace. Verify. Read the certificate.
Traceability is where control of monitoring and measuring equipment most often turns out to rest on an assumption. ISO 9001 Clause 7.1.5.2 requires that, where measurement traceability is a requirement or where the organization considers it an essential part of providing confidence in the validity of measurement results, measuring equipment shall be calibrated or verified at specified intervals or prior to use against measurement standards traceable to international or national measurement standards — and that where no such standards exist, the basis used shall be retained as documented information.
Three things in that sentence get skipped, and each one weakens control of monitoring and measuring equipment.
Traceability is conditional, and the condition is a decision you record
The clause does not say all measuring equipment must be traceably calibrated. It says traceable calibration applies where traceability is a requirement or where the organization decides it is essential to confidence. That is a determination the organization makes and should record, instrument class by instrument class. In practice most procedures for control of monitoring and measuring equipment treat traceability as universal, which is defensible but expensive, or treat it as automatic, which is not defensible at all. Neither records a decision.
“NIST traceable” is a claim made by a supplier, not a certification issued by NIST
This is the single most common misunderstanding MSI encounters in control of monitoring and measuring equipment, and it is worth quoting the source. The NIST Policy on Metrological Traceability states that NIST establishes traceability for the measurement results NIST itself provides, and that other organizations are responsible for establishing the traceability of their own results. NIST's supporting material is blunter still: merely using an instrument that was calibrated at NIST is not enough to make your measurement result traceable. Traceability is a property of a documented, unbroken chain of calibrations with stated uncertainties — and supporting the claim is the responsibility of whoever makes it.
A certificate that says “NIST traceable” and nothing else is a marketing phrase. A certificate that names the reference standards used, gives their identities, and states the measurement uncertainty is evidence. Control of monitoring and measuring equipment means being able to tell the difference, and it means someone in your organization reading the certificate rather than filing it.
The practical control here is simple and almost never implemented in control of monitoring and measuring equipment: when a calibration certificate arrives, someone competent reads it before it is filed. They check that the certificate identifies the instrument by serial number, that the reference standards are identified, that the measurement uncertainty is stated, that the points calibrated cover the range you actually use, and that any as-found data is present. Certificates arriving from an accredited laboratory generally carry all of this. Certificates arriving from an equipment supplier's service department frequently carry none of it, and the organization has no idea because nobody read it.
Accreditation is the mechanism, and its governance changed in 2026
ISO/IEC 17025:2017 is the standard against which calibration and testing laboratories are accredited, and an accredited certificate is the ordinary route by which a chain of traceability is made credible. In the United States, ANAB is a principal accreditation body for that scope. Two points matter for control of monitoring and measuring equipment: accreditation is granted for a defined scope, so a laboratory accredited for dimensional work is not thereby accredited for pressure; and international recognition of accredited certificates now sits under Global Accreditation Cooperation Incorporated, which replaced IAF and ILAC on 1 January 2026. Procedures still citing IAF or ILAC as the governing arrangement are referencing bodies that no longer exist.
There is one more line in Clause 7.1.5.2 that procedures for control of monitoring and measuring equipment routinely omit, and it is the escape hatch the standard deliberately provides: where no international or national measurement standard exists, the basis used for calibration or verification is retained as documented information. Colour, gloss, tactile feel, odour, subjective clinical assessment and certain functional checks all fall here. The requirement is not to invent traceability. It is to write down what you compared against and why that comparison is adequate — a retained master sample, a boundary set, a documented visual standard. Organizations that do not know this clause exists either fake a traceable calibration or leave the check entirely uncontrolled.
Direct Answer
Traceability within control of monitoring and measuring equipment is conditional, not automatic: ISO 9001 Clause 7.1.5.2 applies it where traceability is a requirement or where the organization determines it is essential to confidence in results, and that determination should be recorded. “NIST traceable” is a claim made by the provider of a measurement result, not a certification issued by NIST — NIST's own policy places responsibility for supporting the claim on whoever makes it. Where no national or international standard exists, the standard requires the basis used for calibration or verification to be retained as documented information instead.
Section 5 · Worked example one
The eleven-dollar instrument that carried the whole exposure
Cheap. Critical. Uncontrolled.
A contract manufacturer produced a bracket assembly with a bolted joint. The joint was safety-relevant: the customer specification named a torque range, and the assembly drawing carried a note requiring torque to be recorded.
The organization's register for control of monitoring and measuring equipment was in good order. It held forty-one entries. Coordinate measuring machine, height gauges, micrometers, calipers, surface plates, a hardness tester, two pressure gauges, a set of gauge blocks and a torque analyser in the quality laboratory. Every one of them was in calibration, calibrated by an accredited laboratory, with certificates on file.
The bolts were tightened on the line with a preset click-type torque wrench. It had been bought years earlier for about eleven dollars more than a standard ratchet. It was not on the register. Nobody had ever decided it should not be on the register — nobody had ever considered it at all, because it lived in a toolbox and looked like a tool rather than like an instrument.
Consider what that wrench actually did. It was the only device in the entire process that determined whether a safety-relevant joint met its specification. The torque analyser in the laboratory was calibrated to a fraction of a percent and was never used on this product. The forty-one controlled instruments measured features that were dimensionally verified again by the customer on receipt. The one uncontrolled device made the only judgement nobody downstream could re-make.
Preset click wrenches drift. They drift with cycle count, with storage under load, with being dropped, and with age. There is no visual indication and no failure mode that announces itself. The operator hears a click and the joint is recorded as torqued. It is the perfect uncontrolled instrument: confident, silent and wrong.
This is the structural point, and it is the same point that makes control of monitoring and measuring equipment hard in every organization MSI has worked with. The register was built from the quality department's inventory. The quality department owned instruments. The line owned tools. No document in the organization asked the question that would have caught it — which devices produce a number that somebody acts on? — because the register was built by walking the laboratory rather than by walking the process.
The correction to its control of monitoring and measuring equipment cost very little. Three wrenches went onto the register, went out for calibration, came back with certificates and identification labels, and went into a six-month interval with a documented basis. Total annual cost, less than the price of one of the forty-one existing certificates. The exposure that closed was categorically larger than anything on the original list.
Two diagnostic questions surface this class of finding faster than any checklist. First: which of our decisions cannot be re-made downstream? Those are the measurements that carry the exposure. Second: which devices producing numbers live outside the quality department? That is where the uncontrolled ones are. A procedure for control of monitoring and measuring equipment that asks both questions during register construction will not produce this finding. One built from a laboratory inventory will produce it every time.
Section 6 · Worked example two
The correctly calibrated instrument feeding the wrong decision
Accurate. Traceable. Wrong.
A device manufacturer performed a tensile pull test on a bonded joint as a routine release check. The test rig used a load cell. The load cell was calibrated annually by an accredited laboratory, the certificate named its reference standards, stated the uncertainty and covered the full working range. The instrument was, in every sense the standard uses, under control.
The rig's control software applied a pass/fail limit. An operator ran the test, the software compared the peak load against the limit, and the screen displayed a result. Nobody read a number; they read a word.
The limit in the software had been entered when the rig was commissioned, taken from the design specification current at that time. The design specification was subsequently revised upward following a design change. The drawing was revised, the design history file was updated, the change was reviewed and approved, and every quality record correctly reflected the new figure. The number inside the test rig was never touched, because the change control process routed to documents and to production tooling and had no branch that reached instrument configuration.
For fourteen months the rig measured accurately and judged wrongly. Every measurement was valid. Every conformity decision made from it was against a superseded requirement. The calibration certificate would have been produced in an audit as evidence of control, and it was evidence of control — of the measurement. It was evidence of nothing at all about the decision.
This is the failure mode most procedures for control of monitoring and measuring equipment have no defence against: the instrument is right and the limit is wrong. Calibration verifies that the device reports the quantity correctly. It says nothing about whether the criterion the device is compared against is the current one.
ISO 13485 Clause 7.6 is the only one of the five standards that names the mechanism directly. It requires that software used in the monitoring and measurement of requirements be validated for its intended use prior to initial use, and revalidated as necessary, with records retained. The clause is written about software, and its practical reach is exactly this: the configuration the software carries is part of the measurement system, and a change to a requirement is a change to that configuration.
Under the FDA Quality Management System Regulation, effective 2 February 2026 by the final rule published on 2 February 2024, ISO 13485:2016 is incorporated by reference into 21 CFR Part 820. For device manufacturers that means Clause 7.6 is not merely a certification requirement; the records it demands are inspectable. Organizations that have carried a monitoring and measuring equipment procedure across from a general quality system should be reading Clause 7.6 line by line against it, because the documented-procedure and software-validation obligations have no ISO 9001 counterpart.
The control that closes this in control of monitoring and measuring equipment is a single line in the change process. When a specification, tolerance, limit or acceptance criterion changes, the impact assessment must ask whether that value exists inside any instrument, fixture, program, gauge, spreadsheet or system, and the answer must be recorded — including when the answer is no. Organizations running ISO compliance automation platforms often assume the tool handles this. It handles the calibration schedule. Whether it reaches instrument configuration depends entirely on how the procedure beneath it was written.
Section 7 · The clause auditors sample first
What control of monitoring and measuring equipment requires when equipment is found out of tolerance
Contain. Reconstruct. Decide.
Both ISO 9001 Clause 7.1.5.2 and ISO 13485 Clause 7.6 close with the same obligation, phrased slightly differently: when measuring equipment is found to be unfit for its intended purpose, the organization shall determine whether the validity of previous measurement results has been adversely affected, and take appropriate action.
In MSI's experience of attending audits, this is the sub-requirement of control of monitoring and measuring equipment that auditors sample first when they want to know whether a system is real. It is a good probe, because it cannot be satisfied by a document. It requires the organization to have retained enough information to answer a backward-looking question, and most do not.
The question, put plainly, is this: an instrument came back from calibration with an as-found reading outside tolerance. What did it measure since it was last confirmed good, and are any of those results still relied upon?
Answering it inside control of monitoring and measuring equipment requires four things that have to exist in advance:
- As-found data on the certificate. A certificate that reports only the as-left condition makes the question unanswerable. As-found readings must be requested; many laboratories omit them by default and will supply them if the purchase order asks.
- A usage link. Some record connecting the instrument to what it measured — the device identity on inspection records, batch records, test reports or the electronic equivalent. Without it the affected population cannot be bounded.
- A bounded period. The interval between the last confirmed-good calibration and the discovery. The conservative default is the whole interval.
- A recorded impact decision. Made by someone competent, considering the magnitude of the deviation against the tolerances being judged, and recorded whether the conclusion is that product is affected or that it is not.
The most common failure in control of monitoring and measuring equipment here is not a wrong decision. It is no decision. The instrument is recalibrated, adjusted or replaced, the register is updated, and the file closes. Nobody ever asked the backward question, so no record exists showing it was considered — and an auditor cannot distinguish between an organization that considered it and concluded no impact, and one that never thought about it. The record of a negative conclusion is worth as much as the record of a positive one.
An out-of-tolerance finding is also a corrective action trigger, not merely a calibration event. It should enter the same system that handles every other nonconformity, with a root cause analysis that asks why the interval was inadequate, whether the device was damaged, whether handling and storage contributed, and whether the same conclusion applies to similar devices. Organizations that keep out-of-tolerance events inside the calibration process learn nothing from them; those that route them into corrective action adjust their intervals on evidence rather than on habit.
Calibration intervals inside control of monitoring and measuring equipment are an organizational decision, and they are the one number in this process that should move. An instrument that has passed at twelve months for six consecutive cycles is telling you something. So is one that has failed twice. A procedure that sets every interval at twelve months and never revisits it has replaced a determination with a default.
Direct Answer
When equipment is found out of tolerance, control of monitoring and measuring equipment requires the organization to determine whether the validity of previous measurement results was adversely affected and to take appropriate action — ISO 9001 Clause 7.1.5.2 and ISO 13485 Clause 7.6 both say so. Answering it requires as-found calibration data, a record linking the instrument to what it measured, a bounded period since the last confirmed-good calibration, and a recorded impact decision. The most common finding is not a wrong conclusion but no recorded conclusion at all.
Section 8 · Standard by standard
What each standard asks of control of monitoring and measuring equipment that the others do not
Compare. Differentiate. Cover.
A procedure for control of monitoring and measuring equipment written to one standard will not transfer cleanly to another. Each of the five carries at least one obligation the others do not, and these are consistently the requirements organizations have not discharged — for a structural reason. A procedure carried across from another standard will not contain them, and no clause checklist from that other standard points at them, so no internal audit ever samples them.
ISO 9001:2015 — suitability, and the conditional traceability determination
Clause 7.1.5.1 requires resources to be suitable for the specific type of monitoring and measurement being undertaken, and to be maintained to ensure continued fitness. Suitability is a capability judgement against the decision being made, and it is the requirement most often satisfied by assertion. Clause 7.1.5.2 then makes traceability conditional and requires the basis to be retained where no measurement standard exists. ISO 9001 does not require a documented procedure for this process — which is exactly why so few organizations have one, and why the determinations that should sit inside it are nowhere.
ISO 13485:2016 — a documented procedure, software validation, and inspectable records
Clause 7.6 is the most demanding treatment of control of monitoring and measuring equipment of the five. It requires documented procedures to ensure that monitoring and measurement can be and is carried out consistently. It requires software validation prior to initial use, with revalidation as necessary and records retained. It requires calibration or verification at specified intervals or prior to use, against standards traceable to international or national measurement standards, with the basis recorded where none exist. And since the QMSR took effect on 2 February 2026, those records are inspectable rather than merely auditable. Device organizations working through the transition should read Clause 7.6 alongside the {a(‘https://msi-international.com/fdas-voluntary-improvement-program-transforming-medical-device-quality-through-continuous-improvement/','FDA Voluntary Improvement Program')} maturity model, which probes the same machinery from a different direction.
ISO 14001:2026 — the equipment nobody thinks of as equipment
Clause 9.1.1 requires that calibrated or verified monitoring and measurement equipment is used and maintained as appropriate. The word doing the work is appropriate, and it is appropriate to whatever your significant environmental aspects are. In practice this reaches flow meters on discharge lines, continuous emissions monitors, energy sub-meters feeding an objective, weighbridges feeding a waste return, and gas detection. These devices are frequently owned by facilities or engineering and appear on no quality register at all. An organization working through the ISO 9001 and ISO 14001 transition usually discovers this when it maps its monitoring plan against its calibration register for the first time and finds the two documents share almost no entries.
ISO 45001:2018 — the measurements that produce legal exposure
Clause 9.1.1 carries the same wording, applied to occupational health and safety monitoring. The devices are personal sampling pumps, sound level meters and dosimeters, gas detectors, air velocity meters for local exhaust ventilation, and lux meters. Two features distinguish them. Many are subject to statutory or regulatory calibration expectations independent of the standard, so the obligation arrives from more than one direction. And the results are frequently reported to workers, to regulators, or in the context of a claim — which means an uncontrolled instrument produces a number the organization may later have to defend outside its own walls.
ISO 7101:2023 — measurement the quality function does not own
Healthcare organizations hold the largest population of devices subject to control of monitoring and measuring equipment of any sector MSI works in, and quality owns almost none of them. Infusion pumps, patient monitors, sphygmomanometers, thermometers, weighing scales used for dosing, pipettes, centrifuges and refrigerator temperature monitors are typically managed by biomedical engineering under a maintenance system with its own conventions. Clause 9.1, supported by the resource and infrastructure requirements in Clause 7.1, does not care which department holds the register. It cares that measurements the management system relies on are made with equipment fit for the purpose. The practical first step is not a new register; it is a reconciliation between the biomedical inventory and the measurements the quality system claims. The same interface problem appears in {a(‘https://msi-international.com/remote-patient-monitoring-compliance/','remote patient monitoring compliance')}, where the measuring device is outside the organization entirely.
Section 9 · The eight elements
Eight elements every control of monitoring and measuring equipment procedure needs
Score. Prioritize. Fix.
In MSI's client experience across manufacturing, technology, medical device, government, healthcare and other regulated industries, a procedure for control of monitoring and measuring equipment that works in practice tends to be strong on the same eight elements, and organizations that struggle tend to be weak on the same ones.
- Determination of monitoring and measurement needed — what has to be measured, to what resolution, to support which decision, recorded before any instrument is selected, with documented exclusions.
- Register completeness — every device producing a number anyone acts on, including software-based measurement, integrated instrumentation and reference standards, reconciled physically against the floor at a stated frequency.
- Capability and suitability — a written basis for accepting an instrument as capable of the decision, including the accuracy-to-tolerance ratio the organization has adopted.
- Calibration, verification and traceability — intervals with a documented basis, the traceability determination recorded, certificates read on arrival against defined acceptance criteria, and the retained basis where no measurement standard exists.
- Identification and status — every device identifiable and its calibration status determinable at the point of use, including devices that cannot carry a label.
- Safeguarding — protection from adjustment, damage and deterioration, extending to configuration, limits and software settings as well as to physical seals and storage.
- Out-of-tolerance and retrospective validity — as-found data obtained, affected period bounded, impact decision recorded whether positive or negative, and the event routed into corrective action.
- Interfaces — named links to change control, purchasing, maintenance, internal audit and management review, with an owner on both sides of each one.
Scoring control of monitoring and measuring equipment element by element is more useful than reaching a single verdict, because most organizations are not uniformly weak. They are strong on calibration scheduling and weak on register completeness, or strong on traceability and weak on retrospective validity, and knowing which one changes what you do on Monday. The free Control of Monitoring and Measuring Equipment Maturity Check scores all eight, adds questions specific to your standard, and returns a band and a priority order immediately without asking for anything first.
Section 10 · Interfaces
Where control of monitoring and measuring equipment connects to the rest of the system
Connect. Feed. Close.
Control of monitoring and measuring equipment does not operate alone, and the interfaces are where implementations thin out. Five connections carry most of the weight, and a procedure for control of monitoring and measuring equipment should name each of them.
- Change control. Every specification, tolerance or acceptance criterion change must be assessed against instrument configuration. This is the interface that failed in the second worked example, and it is the one most systems do not have.
- Purchasing. Calibration laboratories are external providers, and their selection belongs inside purchasing and supplier control, evaluated on accreditation scope and uncertainty rather than on price. An accredited laboratory outside its scope for your measurement is not providing what you think you bought.
- Records. Certificates, as-found data, impact decisions and register revisions are all documented information with a location, an owner and a retention period. Those decisions belong in document and records control, and a monitoring and measuring equipment procedure written without them will produce evidence nobody can retrieve.
- Internal audit. This process is audited by walking, not by reading. Internal audit planning should schedule it as a floor activity, and ISO 19011:2026, published on 27 May 2026, is the current guidance — the 2018 edition was withdrawn on the same date. Findings then need to survive internal audit follow-up rather than closing on a promise.
- Management review. Out-of-tolerance rate, interval performance and register growth are inputs a leadership team can act on. Presented as data they drive interval decisions; presented as impressions they drive nothing.
The reach extends further than most organizations expect. ISO for university research turns on Clause 7.1.5 because reproducibility fails at uncalibrated instruments before it fails anywhere else. ISO for additive manufacturing depends on it because in-process monitoring is the only verification available for features that cannot be inspected afterwards. And an organization assessing its overall management system maturity will usually find that its score here predicts its score everywhere else, because this is the process that is hardest to fake.
Section 11 · Building it
How to build a control of monitoring and measuring equipment procedure that holds
Walk. Write. Verify.
If you are writing a procedure for control of monitoring and measuring equipment from scratch, the order that works is: determination first, then register completeness, then everything else. Those two are load-bearing. Improvements to intervals, certificates or labelling do not hold if the register is incomplete or the determinations were never made.
- Walk the floor with two people and a blank sheet before you look at any existing register. Write down every device that produces a number.
- For each one, record the decision it supports and whether that decision can be re-made downstream. That gives you your risk order.
- Write the determination: what is measured, to what resolution, with what accuracy-to-tolerance ratio, and what is deliberately excluded and why.
- Set intervals with a stated basis, then commit to reviewing them against out-of-tolerance history rather than leaving them at the manufacturer's default forever.
- Define what a certificate must contain to be accepted, and name who reads it.
- Write the out-of-tolerance route end to end, including the record of a no-impact conclusion.
- Name the change-control interface explicitly, in both procedures.
If you would rather start from a complete one, MSI's Control of Monitoring and Measuring Equipment Procedure Template and Guide is a working procedure written as a filled-in worked example rather than an outline, in editable Microsoft Word, built to the sixteen-section architecture used across the MSI procedure template library. It carries the equipment register, the calibration and verification record designed to function as the release gate, a desk-level work instruction for the person doing the work, the out-of-tolerance impact assessment form, and the same eight-element maturity ladder the free check scores you against. Choose your standard: ISO 9001, ISO 13485, ISO 14001:2026, ISO 45001 or ISO 7101.
Start free · No email required
Find out which of the eight elements is holding your score down
Score. Diagnose. Decide.
Twenty questions, about six minutes, five standard paths. You get your score, your band, and the element most organizations score lowest on — immediately, without entering anything. Enter your details afterwards and the element-by-element breakdown and full maturity framework open, with a blank scoring worksheet you can take into your next management review.
If the result surprises you, or the priority order does not match what you expected, a conversation is usually quicker than a rewrite. MSI's ISO consulting practice has supported 80+ certifications and attended 200+ audits across 28 years, and a planning session on 760-434-9141 will tell you in half an hour whether your process needs repair or replacement. If you are building a system from the ground up, SurePath is the turnkey route; if you are certified and holding, SureResults covers surveillance and internal audit support year-round. You can also watch the ISO Executive Decision Briefs — short leadership-level videos on what a management system is supposed to produce — or read about The Portrait, MSI's independent operational assessment, which is the right instrument when the documented process and the observed process have drifted apart.
Frequently asked questions
Frequently asked questions
Ask. Answer. Apply.
What is control of monitoring and measuring equipment?
It is the controlled process by which an organization ensures that any measurement used to judge conformity is fit for the judgement being made. It covers determining what monitoring and measurement is needed, selecting equipment capable of the required resolution and accuracy, calibrating or verifying that equipment against traceable references at defined intervals, identifying it and its status, safeguarding it from adjustment or damage, and determining the validity of previous results when equipment is later found unfit. ISO 13485:2016 uses the phrase as the title of Clause 7.6; ISO 9001:2015 addresses the same ground at Clause 7.1.5 under the heading monitoring and measuring resources.
Which ISO clause covers control of monitoring and measuring equipment?
It depends on the standard. ISO 9001:2015 places it at Clause 7.1.5, split into 7.1.5.1 general and 7.1.5.2 measurement traceability. ISO 13485:2016 places it at Clause 7.6. ISO 14001:2026 and ISO 45001:2018 both carry it inside Clause 9.1.1 rather than giving it a dedicated clause. ISO 7101:2023 addresses it at Clause 9.1, supported by the resource and infrastructure requirements at Clause 7.1. ISO 10012:2026 is the dedicated standard on measurement management systems and is not required by any of them.
Does ISO 9001 require a documented calibration procedure?
ISO 9001:2015 does not require a documented procedure for this process by name. It requires documented information to be retained as evidence of fitness for purpose of monitoring and measuring resources, and it requires several determinations to be made. In practice a documented procedure is the most straightforward way to satisfy those requirements coherently, because the determinations — what is measured, what capability is required, what interval basis applies, what traceability decision was made — have nowhere else to live. ISO 13485:2016 Clause 7.6 does explicitly require documented procedures.
Does every instrument need traceable calibration?
No. ISO 9001 Clause 7.1.5.2 applies traceable calibration where measurement traceability is a requirement, or where the organization considers it an essential part of providing confidence in the validity of measurement results. That is a determination the organization makes and should record. Instruments used for indication only, where no conformity decision depends on their accuracy, can be excluded — provided the exclusion is written down with its reason. Where no international or national measurement standard exists, the standard requires the basis used for calibration or verification to be retained as documented information instead.
What does “NIST traceable” actually mean?
Less than most organizations assume. NIST's published policy on metrological traceability states that NIST establishes traceability for the measurement results NIST itself provides, and that other organizations are responsible for establishing traceability for their own results. Supporting a traceability claim is the responsibility of whoever makes it, and using an instrument that was calibrated at NIST is not by itself sufficient. A useful certificate identifies the instrument by serial number, identifies the reference standards used, states the measurement uncertainty, and covers the range actually in use. A certificate carrying the phrase and none of that detail is a marketing statement.
What has to happen when an instrument is found out of calibration?
Both ISO 9001 Clause 7.1.5.2 and ISO 13485 Clause 7.6 require the organization to determine whether the validity of previous measurement results has been adversely affected, and to take appropriate action. That requires as-found calibration data, a record linking the instrument to what it measured, a bounded period since the last confirmed-good calibration, and a recorded impact decision made by someone competent. The decision must be recorded whether the conclusion is that product is affected or that it is not, because an auditor cannot otherwise distinguish a considered no-impact conclusion from a question nobody asked.
Does control of monitoring and measuring equipment apply to software?
Yes, and this is the part most often missed. ISO 13485 Clause 7.6 explicitly requires software used in the monitoring and measurement of requirements to be validated for its intended use prior to initial use, with revalidation as necessary and records retained. Beyond that explicit requirement, any software that applies a limit, a correction factor or a pass/fail criterion is part of the measurement system in every standard, because it determines the decision. A correctly calibrated instrument feeding a superseded limit produces a valid measurement and an invalid conformity judgement.
How often should equipment be calibrated?
None of the five standards specifies an interval. The interval is an organizational determination that should have a stated basis — manufacturer recommendation, usage rate, stability history, criticality of the decisions the instrument supports, and environmental conditions — and it should move on evidence. An instrument that has passed at twelve months for six consecutive cycles is a candidate for extension with a documented rationale; one that has failed twice is a candidate for shortening. A procedure that sets every interval at twelve months and never revisits it has substituted a default for a determination, and that substitution is visible to an experienced auditor within minutes.
What does ISO 10012:2026 change?
ISO 10012 published its second edition on 12 February 2026, replacing the 2003 edition. It has been restructured onto the harmonized management system structure and its clauses extensively revised. Conformity to ISO 10012 is not required by ISO 9001, ISO 13485, ISO 14001, ISO 45001 or ISO 7101, and certification to it is not a substitute for any of them. Its practical significance is that it is now the most current consensus statement of what a measurement management system should contain, which makes it a useful benchmark when writing or reviewing a procedure — and it is a document a well-prepared certification auditor is likely to have read.
References
References
Primary. Current. Verifiable.
View all references
- ISO 9001:2015 — Quality management systems — Clause 7.1.5, monitoring and measuring resources
- ISO 13485:2016 — Medical devices — Clause 7.6, control of monitoring and measuring equipment
- ISO 14001:2026 — Environmental management systems — Clause 9.1.1, published 15 April 2026
- ISO 45001:2018 — Occupational health and safety management systems — Clause 9.1.1
- ISO 7101:2023 — Healthcare organization management — quality management systems for healthcare organizations
- ISO 10012:2026 — Quality management — requirements for measurement management systems, second edition published 12 February 2026
- ISO 19011:2026 — Guidelines for auditing management systems, published 27 May 2026
- ISO/IEC 17025:2017 — General requirements for the competence of testing and calibration laboratories
- ISO/IEC 17025 overview — ISO summary of testing and calibration laboratory requirements
- NIST Policy on Metrological Traceability — National Institute of Standards and Technology
- NIST metrological traceability — frequently asked questions — NIST supporting material on traceability claims
- 21 CFR Part 820 — Quality Management System Regulation, eCFR
- 21 CFR 211.68 — Automatic, mechanical and electronic equipment, eCFR
- 21 CFR 211.160 — Laboratory controls, including calibration of instruments, eCFR
- FDA Quality Management System Regulation — Effective 2 February 2026
- Federal Register — Medical Devices; Quality System Regulation Amendments, final rule, 2 February 2024
- Global Accreditation Cooperation Incorporated — Replaced IAF and ILAC on 1 January 2026
- ANAB — ANSI National Accreditation Board — ISO/IEC 17025 accreditation
- ASQ Quality Glossary — Definitions of calibration, capability and traceability
Related reading
Related reading
Adjacent. Useful. Verified.
- Document and Records Control: The Proven Place to Start — where every calibration record has to live
- Your Purchasing and Supplier Control Procedure Misses This — how to select and control a calibration laboratory
- Effective ISO Procedure: The Proven Test That Matters — the seven marks of a procedure that works
- Internal Audits — auditing this process by walking rather than reading
- ISO Internal Auditor training — building the competence to sample it properly
- Risk Assessment Methodology Framework — prioritizing which measurements carry real exposure
- ISO 9001 · ISO 13485 · ISO 14001 · ISO 45001 · ISO 7101 — MSI standard pages
About Management Systems International (MSI)
Diana Lynn is President and Principal ISO Consultant at Management Systems International (MSI), a consulting firm she co-founded in 1998. With 28 years of experience including extensive AS9100 work in MSI's early years, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality. MSI is veteran-owned and female-owned.
To talk through your own process, call 760-434-9141 or visit msi-international.com.
This article is general guidance and does not replace ISO 9001:2015, ISO 13485:2016, ISO 14001:2026, ISO 45001:2018, ISO 7101:2023, ISO 10012:2026, any applicable regulation, or the judgement of a competent professional. Standards are revised, amended and withdrawn; confirm the current status of your standard at iso.org before relying on clause references. Clause references and publication dates were verified on 20 July 2026.