
ISO 35001
ISO 35001 biorisk management for laboratories and related organizations
ISO 35001 consulting helps laboratories and related organisations manage biorisks when they handle, store, transport or dispose of hazardous biological materials. Vosurein reviews the scope, existing processes and evidence, then helps define responsibilities, implementation steps and internal reviews.
For Your Business
Who this service is for and when to start
For laboratories and related organisations handling, storing, transporting or disposing of hazardous biological materials. Start by identifying gaps and priorities when change management, material access, training and incident records cannot be checked against each other.
The Challenge
Common challenges faced by businesses
Outdated risk assessments or access rights retained after staff leave or change roles can separate documented controls from actual responsibilities. Biorisk management must address both accidental events and unauthorised access; training attendance alone is not enough.
Our Approach
Methods and applicable requirements
The adopted version is ISO 35001:2019, including Amd 1:2024. Version history: first edition; revision plans do not constitute a formal new edition.
This standard deals with the identification, assessment, control, and monitoring of risks associated with hazardous biological materials. Microbiological and toxin testing laboratories in food or feed, as well as risks related to agricultural GMO crops, are not within its intended scope; mixed activities must be clarified first.
The following consulting tasks can be arranged to suit your needs.
Review current practices and scope
Confirm organization, site, activities, applicable requirements, and system gaps.
Risk assessment and change management
Organize assessment criteria, review responsibilities, control plans, and change reviews.
Biosafety and biosecurity management
Organize responsibilities for managing accidental exposure or release, as well as unauthorized acquisition, loss, or misuse.
Personnel and competency management
Review roles, authorizations, competencies, training, and supervision records.
Material and operational management
Organize responsibilities and evidence management for material registration, access, handover, and disposal.
Facility equipment and outsourcing management
Plan maintenance, professional inspection, supplier, and outsourced service management processes.
Incident and response collaboration
Establish reporting and contact procedures, drills, investigation responsibilities and improvement follow-up.
Internal review and improvement
Support system pilots, internal audits, management reviews and certification preparation.
Process
Consulting scope and process
Scope of activities and biological risks
Use activity summaries to confirm the applicable scope, facilities, and management roles, take stock of existing risk assessments and authorization procedures, and first distinguish issues that require professional review.
Biosafety, biosecurity and authorisation responsibilities
Connect biosafety and biosecurity responsibilities with staff authorisation, change management and reporting. Qualified professionals check whether all control responsibilities are covered.
Personnel, materials, and maintenance procedure trial
Review management records of personnel changes, material handovers, and equipment maintenance to ensure that responsible personnel can execute and report according to procedures.
Reporting drills and management review
Confirm reporting collaboration through appropriate drills or record reviews, track improvements and unresolved issues, and have management arrange subsequent resources.
Preparation
What documents do companies need to prepare?
- Activity summary: facilities, purposes, and applicable management responsibilities.
- System documents: risk assessment processes, authorization, and changes.
- Capabilities and equipment: training, maintenance, and professional inspection summaries.
- Incident review: de-identified reporting, drills, and improvements.
For the initial discussion, you can provide a summary. Handle customer, personal and confidential business information within the necessary scope and agreed access permissions.
Project Planning
Estimating time and cost
The activity type, facilities, and existing risk management maturity determine the scope of work. On-site inspections and drills must first coordinate authorization, competent personnel, and safety arrangements.
Consulting focuses on management arrangements and responsibilities. Qualified specialists handle biological materials, design, construction, testing and disposal. Management system assessment, laboratory accreditation, facility levels and permits must each be confirmed separately.
FAQ
Frequently asked questions
Does ISO 35001 apply to every laboratory?
No. The scope excludes laboratories intended for testing microorganisms or toxins in food or feed, and does not apply to agricultural GMO crop risk management; mixed operations should be confirmed separately.
Can existing systems and records be reused?
You can first review existing activity and responsibility summaries, management procedures, training, and de-identified incident records to confirm the applicable period, scope, and quality of evidence, then fill in gaps; rewriting all documents is not a prerequisite for implementation.
What needs to be checked when personnel leave or transfer?
The authorized contact verifies whether responsibilities, authorities, and handovers are updated, confirming that necessary tasks have been assigned to competent personnel to avoid discrepancies between the roster and actual activities.
How are consulting and third-party certification responsibilities divided?
Vosurein supports system implementation and preparation but does not issue third-party certificates. Confirm the applicable certification scheme, accreditation scope, fees and schedule separately. A certificate does not constitute product approval or proof of compliance with every regulation.
Will it require providing the complete material inventory?
Initial consultation uses summaries of activities and management arrangements. Authorised staff provide sensitive information about materials, locations or access rights only as needed for the project, using agreed channels.
Which version should be confirmed before implementation?
The edition covered is ISO 35001:2019 with Amd 1:2024. This is the first edition; a revision project is not a published replacement. Confirm the edition used by the customer and assessment scheme and any transition arrangements. Publication of a standard does not itself set a company’s transition deadline.
Related
Related services and enquiries
Please provide the industry, activities, locations, main requirements, and expected completion time.Contact Vosurein
Content checked: . Applicable versions and requirements depend on the company’s circumstances.
Let's Talk
Start a conversation about your needs.
Tell us how the work is done today and when you hope to finish,
so we can agree the scope and way of working together.
Blog
Sustainability and AI insights
Start with understanding,
and see where change can lead.

