ISO 22716 is the GMP standard for cosmetics, and for a testing lab it comes down to one question: can you prove, in writing, that every result came from a controlled process? The standard doesn't ask for exotic instrumentation. It asks for documented methods, trained analysts, traceable materials, and records that still make sense two years from now.
Short answer: ISO 22716 requires a cosmetic testing lab to document its methods, personnel training, equipment calibration, sample handling, and results review, then keep those records retrievable and tamper-evident. Certification isn't legally mandated in the US, but brand clients working under MoCRA increasingly ask their labs for proof of GMP-aligned practice before they'll send samples.
What ISO 22716 asks of a testing lab
The standard was written for cosmetic manufacturing, so parts of it read like a plant document. Testing labs still fall inside its scope through Clause 11 (subcontracting) and the quality-control sections that manufacturers must satisfy through their labs.
In practice, an auditor reviewing your lab wants five things: a written method for every test you report, evidence the analyst was trained on it, calibration and maintenance history for the instrument that produced the number, a sample record that connects the container on the bench to the batch on the certificate, and a documented second-person review before release.
That's it. No clause requires software. Every clause requires evidence.
The records auditors open first
- Method documents with version history. Not the current version - the version that was in force on the day the sample ran.
- Training records tied to specific methods. A general onboarding checklist won't cover it.
- Equipment logs. Calibration dates, maintenance events, and any out-of-tolerance findings with the investigation that followed.
- Chain of custody. Chain of custody is the unbroken record of who held a sample, when, and under what conditions - from receipt through disposal.
- Review and release signatures. Who checked the data, what they checked, and when they signed.
Every one of those is easy to produce for a single sample. The failure mode is scale. Ask a paper-based lab for the training record, method version, and calibration status behind one result from fourteen months ago, and you'll watch three people open four binders.
Where cosmetic labs actually lose control
The common failure isn't a missing record. It's a record that exists somewhere and can't be tied back to the result.
Stability testing makes this concrete. A single shelf-life study generates pull points across months, each with its own analyst, instrument state, and storage condition. When those pull points live in a spreadsheet and the storage log lives on a clipboard by the chamber, nothing links them. An auditor asks how you know the 12-month pull ran on a calibrated balance, and the honest answer becomes "we'd have to check."
Preservative efficacy testing has the same shape. USP <51> challenge tests run over 28 days with intermediate counts. Miss the documentation on one interval and the whole study gets questioned.
Building the documentation into the workflow
The labs that pass ISO 22716 audits without a scramble share one habit: the record gets created by the work, not after it.
That's the practical argument for running cosmetic testing in a LIMS rather than around one. In Confident, a method is a configurable workflow template, and configuration changes are versioned, so a result reads against the configuration recorded for its test date, in conjunction with the lab's validated SOPs.
The audit trail records who did what and when, without anyone remembering to log it. That's the difference between a lab that documents its work and a lab whose work documents itself.
Instrument data helps here too. When balance and HPLC results land in the sample record directly, the calibration status of that instrument is already attached to the result. No one is reconciling a printout against a logbook at audit time.
A starting sequence that works
- Inventory every test you report, and confirm each one has a current written method. Gaps here are the most common finding.
- Map each method to the analysts qualified to run it. Fix the mismatches before you automate anything.
- Move stability and challenge-test schedules into a system that owns the pull dates. Calendar reminders aren't records.
- Connect instruments to the sample record so calibration state travels with the result.
- Run a mock audit on one product line. Pull three results at random and reconstruct them end to end.
Labs moving onto Confident generally finish configuration and data migration inside the 2-6 week onboarding window - shorter than most audit-preparation cycles, which is why teams often start the switch after a client questionnaire lands rather than before.
Frequently asked questions
Is ISO 22716 certification mandatory for cosmetic testing labs?
No. ISO 22716 is a voluntary guideline, not a legal requirement in the US. It carries real weight anyway, because cosmetic brands under MoCRA obligations often require GMP-aligned evidence from the labs they contract with.
How is ISO 22716 different from ISO 17025?
ISO 17025 addresses the technical competence of a testing laboratory - method validation, measurement uncertainty, and accreditation. ISO 22716 addresses GMP for cosmetic products across production, storage, and control. Labs serving cosmetic clients often work against both: ISO 17025 for how they test, ISO 22716 for how their client's product is controlled.
How long should a cosmetic testing lab keep its records?
ISO 22716 doesn't set one universal retention period. It expects your lab to define a period, justify it, and follow it. Most testing labs align retention with their clients' batch-record policies plus the product's shelf life, which in cosmetics often means several years past the last pull point of a stability study.
Does MoCRA replace ISO 22716?
No. MoCRA is US law covering facility registration, product listing, safety substantiation, and adverse event reporting. ISO 22716 is a GMP framework. MoCRA's safety substantiation requirements are easier to meet when your testing data already sits in a GMP-aligned record system.
Cosmetic testing volume is rising faster than most labs' documentation habits, and the questionnaires arriving from brand clients are getting more specific every quarter. The labs that answer them in an afternoon aren't working harder - their records simply assemble themselves.
Confident supports cosmetics and personal care, nutraceuticals, and food and beverage labs that need configuration versioning, chain-of-custody records, and review sign-off captured as part of the daily workflow - the building blocks GMP environments rely on, in conjunction with the lab's validated SOPs. To see how it handles your documentation requirements, Get Demo.