Contact us
Illustration for ISO management-system services

ISO 35001

ISO 35001 biorisk management for laboratories and related organizations

ISO 35001 consulting helps laboratories and related organisations manage biorisks when they handle, store, transport or dispose of hazardous biological materials. Vosurein reviews the scope, existing processes and evidence, then helps define responsibilities, implementation steps and internal reviews.

Discuss ISO 35001 biorisk management consulting

For Your Business

Who this service is for and when to start

For laboratories and related organisations handling, storing, transporting or disposing of hazardous biological materials. Start by identifying gaps and priorities when change management, material access, training and incident records cannot be checked against each other.

The Challenge

Common challenges faced by businesses

Outdated risk assessments or access rights retained after staff leave or change roles can separate documented controls from actual responsibilities. Biorisk management must address both accidental events and unauthorised access; training attendance alone is not enough.

Our Approach

Methods and applicable requirements

The adopted version is ISO 35001:2019, including Amd 1:2024. Version history: first edition; revision plans do not constitute a formal new edition.

This standard deals with the identification, assessment, control, and monitoring of risks associated with hazardous biological materials. Microbiological and toxin testing laboratories in food or feed, as well as risks related to agricultural GMO crops, are not within its intended scope; mixed activities must be clarified first.

The following consulting tasks can be arranged to suit your needs.

Review current practices and scope

Confirm organization, site, activities, applicable requirements, and system gaps.

Risk assessment and change management

Organize assessment criteria, review responsibilities, control plans, and change reviews.

Biosafety and biosecurity management

Organize responsibilities for managing accidental exposure or release, as well as unauthorized acquisition, loss, or misuse.

Personnel and competency management

Review roles, authorizations, competencies, training, and supervision records.

Material and operational management

Organize responsibilities and evidence management for material registration, access, handover, and disposal.

Facility equipment and outsourcing management

Plan maintenance, professional inspection, supplier, and outsourced service management processes.

Incident and response collaboration

Establish reporting and contact procedures, drills, investigation responsibilities and improvement follow-up.

Internal review and improvement

Support system pilots, internal audits, management reviews and certification preparation.

Process

Consulting scope and process

  1. Scope of activities and biological risks

    Use activity summaries to confirm the applicable scope, facilities, and management roles, take stock of existing risk assessments and authorization procedures, and first distinguish issues that require professional review.

  2. Biosafety, biosecurity and authorisation responsibilities

    Connect biosafety and biosecurity responsibilities with staff authorisation, change management and reporting. Qualified professionals check whether all control responsibilities are covered.

  3. Personnel, materials, and maintenance procedure trial

    Review management records of personnel changes, material handovers, and equipment maintenance to ensure that responsible personnel can execute and report according to procedures.

  4. Reporting drills and management review

    Confirm reporting collaboration through appropriate drills or record reviews, track improvements and unresolved issues, and have management arrange subsequent resources.

Preparation

What documents do companies need to prepare?

  • Activity summary: facilities, purposes, and applicable management responsibilities.
  • System documents: risk assessment processes, authorization, and changes.
  • Capabilities and equipment: training, maintenance, and professional inspection summaries.
  • Incident review: de-identified reporting, drills, and improvements.

For the initial discussion, you can provide a summary. Handle customer, personal and confidential business information within the necessary scope and agreed access permissions.

Project Planning

Estimating time and cost

The activity type, facilities, and existing risk management maturity determine the scope of work. On-site inspections and drills must first coordinate authorization, competent personnel, and safety arrangements.

Consulting focuses on management arrangements and responsibilities. Qualified specialists handle biological materials, design, construction, testing and disposal. Management system assessment, laboratory accreditation, facility levels and permits must each be confirmed separately.

FAQ

Frequently asked questions

Does ISO 35001 apply to every laboratory?

No. The scope excludes laboratories intended for testing microorganisms or toxins in food or feed, and does not apply to agricultural GMO crop risk management; mixed operations should be confirmed separately.

Can existing systems and records be reused?

You can first review existing activity and responsibility summaries, management procedures, training, and de-identified incident records to confirm the applicable period, scope, and quality of evidence, then fill in gaps; rewriting all documents is not a prerequisite for implementation.

What needs to be checked when personnel leave or transfer?

The authorized contact verifies whether responsibilities, authorities, and handovers are updated, confirming that necessary tasks have been assigned to competent personnel to avoid discrepancies between the roster and actual activities.

How are consulting and third-party certification responsibilities divided?

Vosurein supports system implementation and preparation but does not issue third-party certificates. Confirm the applicable certification scheme, accreditation scope, fees and schedule separately. A certificate does not constitute product approval or proof of compliance with every regulation.

Will it require providing the complete material inventory?

Initial consultation uses summaries of activities and management arrangements. Authorised staff provide sensitive information about materials, locations or access rights only as needed for the project, using agreed channels.

Which version should be confirmed before implementation?

The edition covered is ISO 35001:2019 with Amd 1:2024. This is the first edition; a revision project is not a published replacement. Confirm the edition used by the customer and assessment scheme and any transition arrangements. Publication of a standard does not itself set a company’s transition deadline.

Related

Related services and enquiries

Please provide the industry, activities, locations, main requirements, and expected completion time.Contact Vosurein

Content checked: . Applicable versions and requirements depend on the company’s circumstances.

Let's Talk

Start a conversation about your needs.

Tell us how the work is done today and when you hope to finish,
so we can agree the scope and way of working together.

Discuss your service needsBack to ISO management-system contents