ISO 35001: How Laboratories Manage Biorisk Safely and Securely
Any organization that works with dangerous biological materials carries a dual responsibility: to protect its own people from accidental exposure, and to protect the wider world from the deliberate misuse of those materials. ISO 35001 is the international standard that brings both responsibilities under one disciplined management system. This guide explains what ISO 35001 requires, which organizations it applies to, and how it helps laboratories and facilities identify, control and monitor biorisk. It is written for laboratory directors, biosafety officers, biorisk managers, technical staff and those charged with oversight and governance.
What is ISO 35001?
ISO 35001 specifies requirements and provides guidance for a biorisk management system for laboratories and other organizations that work with biological agents and toxins. Its purpose is to enable those organizations to identify, assess, control and monitor the risks associated with hazardous biological materials.
The standard deliberately unites two disciplines that are often treated separately:
- Biosafety — the containment principles and practices that prevent unintentional exposure or accidental release.
- Biosecurity — the protection, control and accountability measures that prevent the loss, theft, misuse or intentional release of biological materials.
By combining them, ISO 35001 recognizes that a laboratory cannot be truly safe unless it is also secure, and vice versa. A missing vial is both a safety and a security failure.
Who needs it and where it applies
ISO 35001 applies to any organization that handles, stores, transports or disposes of biological agents. That reach is wide:
- Clinical and diagnostic laboratories.
- Research and academic institutions.
- Veterinary and agricultural facilities.
- Industrial and production laboratories.
- Public health laboratories.
Within these settings, the standard speaks directly to laboratory directors, biosafety officers, biorisk managers, technical and bench staff, and the governance functions responsible for oversight. Wherever biological hazards are present, the framework offers a consistent way to manage them.
Key benefits of implementation
Implementing a biorisk management system aligned to ISO 35001 delivers protection that is both practical and reputational. It reduces the chance of harm while demonstrating that the organization takes its responsibilities seriously.
Principal benefits include:
- Reduced likelihood of laboratory-acquired infections and accidental releases.
- Improved regulatory and stakeholder confidence in the facility's controls.
- A stronger safety and security culture among staff.
- Demonstrable due diligence — evidence that risks were identified and managed responsibly.
What's inside the management system
Following the ISO harmonized high-level structure, ISO 35001 addresses organizational context, leadership and worker engagement, planning, support, operation, performance evaluation and improvement, all driven by the Plan-Do-Check-Act cycle. Its operational heart, however, lies in a set of biorisk-specific requirements:
- A documented biorisk management policy setting direction and commitment.
- Biorisk assessments that systematically evaluate the hazards of the biological materials and activities involved.
- Implementation of a hierarchy of controls — elimination, substitution, engineering controls, administrative measures and personal protective equipment — applied in order of effectiveness.
- Competence and training so that every worker understands the risks and the controls.
- Inventory management and accountability of biological materials, so that what is held is always known and traceable.
- Emergency and incident planning for when things go wrong.
- Continual improvement of biorisk performance over time.
Worker engagement is emphasized strongly: those who handle the materials must be actively involved, because they are the first line of both safety and security.
The structure of the standard
ISO 35001's requirements progress through the familiar Annex SL clauses. It begins by establishing the context of the organization and the expectations of interested parties, then sets out the role of leadership and worker engagement in owning biorisk. Planning translates risk assessment into objectives and controls. Support covers resources, competence and communication. Operation is where the hierarchy of controls, inventory accountability and emergency preparedness live. Performance evaluation and improvement close the loop, ensuring the system stays effective as agents, methods and threats evolve.
The standard does not exist in isolation. It draws on and complements respected international guidance such as the World Health Organization Laboratory Biosafety Manual, and it aligns with other management system standards — ISO 9001 for quality, ISO 45001 for occupational health and safety, and ISO 31000 for risk management — allowing biorisk to be integrated into a broader management framework rather than bolted on.
The road to conformity
Although ISO 35001 contains auditable requirements, it is frequently implemented as a robust management framework, and organizations may seek independent assessment to demonstrate conformity where that is required by regulators, funders or partners. A typical path looks like this:
- Gap analysis — measure existing biosafety and biosecurity practices against the standard's requirements.
- Implementation — establish the biorisk policy, conduct biorisk assessments, deploy the hierarchy of controls, and build inventory, training and emergency arrangements.
- Operation — run the system, engage workers, and generate the records that show controls are effective.
- Internal audit and management review — verify performance and correct weaknesses.
- Independent assessment — where required, an external body evaluates conformity with the standard.
- Ongoing improvement — periodic review keeps controls current against new agents and emerging threats.
How AGS can help
Standing up a full biorisk management system is a substantial undertaking, especially for laboratories already stretched by day-to-day operations. The AGS ISO 35001 Biorisk Management System toolkit, part of our Standard tier, gives you a comprehensive head start. It contains editable manuals, procedures, biorisk assessment templates, inventory and accountability records, training materials, emergency plans and compliance matrices — all structured around the standard's requirements.
Rather than drafting biosafety and biosecurity documentation from a blank page, your team adapts proven, well-organized templates to your specific agents, facilities and activities. The kit streamlines implementation, strengthens your safety and security culture, and puts you in a strong position for internal audit or independent assessment. Reach out to the AGS Compliance Team to make your laboratory demonstrably safer and more secure.