Biobanking LIMS Software: 6 Questions That Actually Separate Vendors

Six questions to ask biobanking LIMS vendors, what a good answer sounds like, and the red flags to watch for.

August 10, 2026
()
min read
A laboratory

Download Whitepaper

By submitting this form, you agree with our Privacy Policy.
Thank you! Download the file by clicking below:
Download
Oops! Something went wrong while submitting the form.

Table of Contents

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Table of Contents

TL;DR

The questions that separate biobanking LIMS vendors are about sample lineage, consent handling, chain of custody, and audit evidence, not about interface polish or support hours.

  • Lineage over inventory.
    A biobank does not store samples, it stores families of samples. Ask how the system models parent specimens, aliquots, and derivatives across multiple generations, and whether that relationship survives a bulk import. Systems built as freezer inventory tools tend to flatten lineage into a text field, which shows up years later when you cannot reconstruct where a vial came from.
  • Consent is a data problem.
    Donor consent, withdrawal, and permitted-use restrictions have to live with the specimen record and travel with it. Ask whether consent is a configurable field, a dedicated module, or something you are expected to track elsewhere. Ask where that data is physically hosted, because GDPR and HIPAA answers depend on it.
  • Audit evidence beats feature lists.
    ISO 20387 and CAP accreditation assessors want records, not screenshots. Ask what the system produces on demand: full audit trails, custody history, and equipment records. SciSure logs sample-level changes with user and timestamp, though accreditation always remains the biobank's responsibility, not the software's.
  • Migration is the real cost.
    Most biobanks are not buying a first system, they are leaving one. Ask for a test import with your own messy data before signing, not a demo dataset. The vendors who agree to that are telling you something.


Originally published February 2023, this post has been rewritten for 2026, including accreditation and consent guidance, the main categories of system on the market, and states plainly where SciSure fits and where it doesn't.

Biobanks are the least forgiving buyers of laboratory software, and most software buying guides do not reflect that.

The generic advice applies to any system: Is the interface intuitive? Does the vendor offer training? Is there 24/7 support? All reasonable, all things you will find out during a trial anyway. None of them tell you whether a system will still make sense in year seven, when someone asks you to trace a derivative back through four generations to a donor who withdrew consent in 2027.

I have sat on both sides of these evaluations. The questions below are the ones where vendor answers actually diverge. For each one, I have written what a good answer sounds like and what should worry you.

A note on bias before you read further: SciSure sells a LIMS used by biobanks, so I do have a stake in this. I have tried to write questions that are useful regardless of what you buy, and I have been specific later on about where SciSure is a poor fit.

Question 1: How does the system model lineage, not just location?

A freezer inventory tool answers "Where is vial 4471?", while a biobanking LIMS answers "What was vial 4471 derived from, what else came from the same primary specimen, and what has happened to all of it since?"

Those are different data models. The first needs a location field. The second needs parent-child relationships that hold across generations, survive bulk operations, and stay intact when samples move between studies.

A good answer sounds like: the vendor shows you a multi-generation lineage view built from actual relationships in the data model, not from a naming convention. They can tell you what happens to lineage during a bulk import and during a batch update.

Red flag: lineage is described as a report, or the demo relies on sample IDs like BLOOD-001-A1-DNA to imply relationships. Naming conventions are not a data model. They break the first time someone types a hyphen wrong.

With SciSure, samples carry parent and child relationships as structured data, with additional lineage visualisation available through Marketplace add-ons. Sample types are configurable, so a whole blood specimen and an extracted DNA aliquot can hold different required fields while staying linked.

SciSure
See how your specimens actually connect
SciSure holds parent and child relationships as structured data, so derivative chains stay intact through bulk imports and batch updates.
Talk to a specialist

Question 2: Where does consent live, and where does the data physically sit?

Human biobanks need consent status, permitted uses, and withdrawal handling attached to the specimen record itself. If consent lives in a separate spreadsheet or a clinical system with no link to the sample, then answering "Can this vial be released for a commercial study?" becomes a manual reconciliation every single time.

The second half of the question matters just as much. Donor data has a jurisdiction. A European biobank with data in a US region has a GDPR conversation to have with its data protection officer, whatever the vendor's certifications say.

A good answer sounds like: consent fields are part of the specimen record, restrictions can be enforced through permissions or flags rather than convention, and the vendor can tell you exactly which region or facility holds the data.

Red flag: "We're fully GDPR compliant" with no follow-up about where data is stored. Compliance is a property of your whole operation, not a badge the software carries.

SciSure supports public cloud in EU or US regions, private cloud, on-premises, and hybrid deployment, so you can put donor data where your legal team needs it. Our hosting options page cover these in greater detail. Keep in mind that consent in SciSure is handled through configurable sample fields rather than a dedicated consent module. For many research biobanks that is sufficient. For a large clinical biobank with complex withdrawal workflows, ask hard about it.

Question 3: What happens to chain of custody when a sample leaves the building?

Most systems track samples well while they sit in a freezer. Custody gets thin at the edges, during distribution to a requesting researcher, transfer to a collaborator, or temporary removal for processing. Those edges are where samples go missing and where audits find gaps.

A good answer sounds like: check-out and check-in are recorded actions with a user and timestamp, not a status field someone remembers to update. Distribution creates a record on both the sample and the request. The vendor can show you the custody history of a single vial without running a report.

Red flag: custody is handled by "adding a note." Notes are not records.

SciSure supports sample check-in and check-out with audit history, and every sample record carries a log of who changed what and when.

Inventory management with SciSure LIMS
Inventory management with SciSure LIMS

Question 4: What does this system hand an accreditation assessor?

If you hold or are pursuing ISO 20387:2018 accreditation, or CAP Biorepository Accreditation, this question separates vendors faster than anything else on this list.

ISO 20387 requires third-party assessment by an accreditation body, which is a different thing from internal conformance to a guidance document like the ISBER Best Practices or the NCI Best Practices for Biospecimen Resources. The standard is structured to align with ISO/IEC 17025 and ISO 9001, which is why bodies that already accredit testing laboratories, such as UKAS in the UK or ANAB in the US, tend to be the ones offering it. A recent comparison in Archives of Pathology and Laboratory Medicine found that the CAP programme and ISO 20387 launched in 2012 and 2018 respectively, and 99 biorepositories held CAP accreditation at time of writing.

Software cannot make you accredited. It can make the evidence retrievable, or it can make you rebuild it by hand every cycle.

A good answer sounds like: the vendor talks about audit trails, retention, controlled access, and what the system can export. They are comfortable saying that accreditation is your responsibility.

Red flag: any vendor claiming their software makes you ISO 20387 compliant. It cannot. Compliance requires your SOPs, training, quality oversight, and a third-party assessment.

SciSure
Have your records ready before the assessor asks
SciSure supports audit trails, role-based permissions, and electronic signatures where configured and validated. The validation and governance remain yours.
Request a demo

Question 5: What does migrating off our current system actually involve?

Most biobanks reading this are not buying their first system. They are leaving Freezerworks, a homegrown Access database, an ageing enterprise LIMS, or a set of spreadsheets that grew legs. The migration is the project. The software is the easy part.

A good answer sounds like: the vendor offers a test import using a sample of your real data, including the messy parts. They can tell you what happens to records with invalid storage locations, duplicate barcodes, or references to staff who left in 2019.

Red flag: migration is quoted as a fixed-price line item before anyone has looked at your data. That number will change.

SciSure separates initial system migration from ongoing batch imports and batch updates, and documents the field mapping and validation rules for each. Ask for a test import with your own export before you commit. I would say that about any vendor on this list, including us.

Question 6: What happens when the collection doubles?

Scale in biobanking is rarely about raw sample count. It is about retrieval time, request throughput, and how much manual coordination each new specimen adds.

A good answer sounds like: the vendor can describe automation in specific terms. What triggers an alert. What happens when a quantity crosses a threshold. Whether barcode scanning drives actions or just lookups. Whether there is an API you can build against.

Red flag: scalability answered purely in infrastructure terms. Server capacity was not your problem. Twelve people manually updating statuses was.

SciSure uses a trigger, condition, action automation model, supports API and SDK access, and connects to rack scanners and label printers through Marketplace add-ons.

SciSure's Marketplace Add-Ons and Integrations

Where SciSure fits, and where it does not

SciSure LIMS is built around configurable sample types, lineage, and flexible storage modelling rather than a fixed biorepository workflow, which suits biotech R&D biobanks, academic collections, and biobanks embedded in a wider research programme.

Where I would point you elsewhere: if you are a large clinical biobank whose primary requirement is a dedicated consent and withdrawal module with complex donor workflows, a purpose-built clinical biobanking system will fit better out of the box. If you need validated GMP manufacturing workflows around your repository, an enterprise LIMS is the more direct answer.

If you want to work through this properly, talk to our team and bring your current data export. That conversation is more useful than a feature demo.

For the operational side of running a biobank rather than buying software for one, our post on 5 operational challenges for biobanks covers sample integrity, disaster preparedness, and capacity planning in more depth. SciSure is also not a LIS, which we cover in our guide to figuring out the difference.

FAQ

What is a biobanking LIMS?

A biobanking LIMS is software for tracking biological specimens across their full lifecycle, from collection through storage, aliquoting, distribution, and disposal. It differs from a general LIMS mainly in how it handles specimen lineage, donor consent data, and long-term storage in freezers and liquid nitrogen.

Is a LIMS enough, or do biobanks need an ELN too?

It depends on what happens to the samples. A repository that only receives, stores, and distributes specimens needs a LIMS. If your team also runs experiments on those samples, an ELN covers the experimental record that a LIMS does not.

Can biobanking LIMS software make us ISO 20387 accredited?

No. ISO 20387 accreditation requires assessment by an accreditation body against your whole operation, including quality management, personnel, facilities, and processes. Software can hold the records an assessor asks for, which shortens the preparation considerably, but the accreditation is yours to earn.

How long does migrating to a new biobanking LIMS take?

It depends far more on your data quality than on the software. Cleaning identifiers, resolving duplicate barcodes, and mapping historical staff records typically takes longer than the technical import. Ask any vendor for a test import with your real data before agreeing a timeline.

What should we ask about data residency?

Ask which country or region physically holds the data, whether on-premises or private cloud deployment is available, and what happens to donor data in backups. If you handle EU donor material, involve your data protection officer before shortlisting.

SciSure
Bring your data export, not a feature wishlist
SciSure supports configurable sample models, flexible hosting, and audit trails, and we'll tell you plainly where a purpose-built biobank system would suit you better.
Request a demo

Check out our guide to the best sample management and tracking platforms of 2026 to figure out which might best fit your lab.

Ready to see SciSure in action?

Get a personalized demo and see how SciSure fits your lab's workflows.
Request demo

No commitment · Free consultation

Biobanks are the least forgiving buyers of laboratory software, and most software buying guides do not reflect that.

The generic advice applies to any system: Is the interface intuitive? Does the vendor offer training? Is there 24/7 support? All reasonable, all things you will find out during a trial anyway. None of them tell you whether a system will still make sense in year seven, when someone asks you to trace a derivative back through four generations to a donor who withdrew consent in 2027.

I have sat on both sides of these evaluations. The questions below are the ones where vendor answers actually diverge. For each one, I have written what a good answer sounds like and what should worry you.

A note on bias before you read further: SciSure sells a LIMS used by biobanks, so I do have a stake in this. I have tried to write questions that are useful regardless of what you buy, and I have been specific later on about where SciSure is a poor fit.

Question 1: How does the system model lineage, not just location?

A freezer inventory tool answers "Where is vial 4471?", while a biobanking LIMS answers "What was vial 4471 derived from, what else came from the same primary specimen, and what has happened to all of it since?"

Those are different data models. The first needs a location field. The second needs parent-child relationships that hold across generations, survive bulk operations, and stay intact when samples move between studies.

A good answer sounds like: the vendor shows you a multi-generation lineage view built from actual relationships in the data model, not from a naming convention. They can tell you what happens to lineage during a bulk import and during a batch update.

Red flag: lineage is described as a report, or the demo relies on sample IDs like BLOOD-001-A1-DNA to imply relationships. Naming conventions are not a data model. They break the first time someone types a hyphen wrong.

With SciSure, samples carry parent and child relationships as structured data, with additional lineage visualisation available through Marketplace add-ons. Sample types are configurable, so a whole blood specimen and an extracted DNA aliquot can hold different required fields while staying linked.

SciSure
See how your specimens actually connect
SciSure holds parent and child relationships as structured data, so derivative chains stay intact through bulk imports and batch updates.
Talk to a specialist

Question 2: Where does consent live, and where does the data physically sit?

Human biobanks need consent status, permitted uses, and withdrawal handling attached to the specimen record itself. If consent lives in a separate spreadsheet or a clinical system with no link to the sample, then answering "Can this vial be released for a commercial study?" becomes a manual reconciliation every single time.

The second half of the question matters just as much. Donor data has a jurisdiction. A European biobank with data in a US region has a GDPR conversation to have with its data protection officer, whatever the vendor's certifications say.

A good answer sounds like: consent fields are part of the specimen record, restrictions can be enforced through permissions or flags rather than convention, and the vendor can tell you exactly which region or facility holds the data.

Red flag: "We're fully GDPR compliant" with no follow-up about where data is stored. Compliance is a property of your whole operation, not a badge the software carries.

SciSure supports public cloud in EU or US regions, private cloud, on-premises, and hybrid deployment, so you can put donor data where your legal team needs it. Our hosting options page cover these in greater detail. Keep in mind that consent in SciSure is handled through configurable sample fields rather than a dedicated consent module. For many research biobanks that is sufficient. For a large clinical biobank with complex withdrawal workflows, ask hard about it.

Question 3: What happens to chain of custody when a sample leaves the building?

Most systems track samples well while they sit in a freezer. Custody gets thin at the edges, during distribution to a requesting researcher, transfer to a collaborator, or temporary removal for processing. Those edges are where samples go missing and where audits find gaps.

A good answer sounds like: check-out and check-in are recorded actions with a user and timestamp, not a status field someone remembers to update. Distribution creates a record on both the sample and the request. The vendor can show you the custody history of a single vial without running a report.

Red flag: custody is handled by "adding a note." Notes are not records.

SciSure supports sample check-in and check-out with audit history, and every sample record carries a log of who changed what and when.

Inventory management with SciSure LIMS
Inventory management with SciSure LIMS

Question 4: What does this system hand an accreditation assessor?

If you hold or are pursuing ISO 20387:2018 accreditation, or CAP Biorepository Accreditation, this question separates vendors faster than anything else on this list.

ISO 20387 requires third-party assessment by an accreditation body, which is a different thing from internal conformance to a guidance document like the ISBER Best Practices or the NCI Best Practices for Biospecimen Resources. The standard is structured to align with ISO/IEC 17025 and ISO 9001, which is why bodies that already accredit testing laboratories, such as UKAS in the UK or ANAB in the US, tend to be the ones offering it. A recent comparison in Archives of Pathology and Laboratory Medicine found that the CAP programme and ISO 20387 launched in 2012 and 2018 respectively, and 99 biorepositories held CAP accreditation at time of writing.

Software cannot make you accredited. It can make the evidence retrievable, or it can make you rebuild it by hand every cycle.

A good answer sounds like: the vendor talks about audit trails, retention, controlled access, and what the system can export. They are comfortable saying that accreditation is your responsibility.

Red flag: any vendor claiming their software makes you ISO 20387 compliant. It cannot. Compliance requires your SOPs, training, quality oversight, and a third-party assessment.

SciSure
Have your records ready before the assessor asks
SciSure supports audit trails, role-based permissions, and electronic signatures where configured and validated. The validation and governance remain yours.
Request a demo

Question 5: What does migrating off our current system actually involve?

Most biobanks reading this are not buying their first system. They are leaving Freezerworks, a homegrown Access database, an ageing enterprise LIMS, or a set of spreadsheets that grew legs. The migration is the project. The software is the easy part.

A good answer sounds like: the vendor offers a test import using a sample of your real data, including the messy parts. They can tell you what happens to records with invalid storage locations, duplicate barcodes, or references to staff who left in 2019.

Red flag: migration is quoted as a fixed-price line item before anyone has looked at your data. That number will change.

SciSure separates initial system migration from ongoing batch imports and batch updates, and documents the field mapping and validation rules for each. Ask for a test import with your own export before you commit. I would say that about any vendor on this list, including us.

Question 6: What happens when the collection doubles?

Scale in biobanking is rarely about raw sample count. It is about retrieval time, request throughput, and how much manual coordination each new specimen adds.

A good answer sounds like: the vendor can describe automation in specific terms. What triggers an alert. What happens when a quantity crosses a threshold. Whether barcode scanning drives actions or just lookups. Whether there is an API you can build against.

Red flag: scalability answered purely in infrastructure terms. Server capacity was not your problem. Twelve people manually updating statuses was.

SciSure uses a trigger, condition, action automation model, supports API and SDK access, and connects to rack scanners and label printers through Marketplace add-ons.

SciSure's Marketplace Add-Ons and Integrations

Where SciSure fits, and where it does not

SciSure LIMS is built around configurable sample types, lineage, and flexible storage modelling rather than a fixed biorepository workflow, which suits biotech R&D biobanks, academic collections, and biobanks embedded in a wider research programme.

Where I would point you elsewhere: if you are a large clinical biobank whose primary requirement is a dedicated consent and withdrawal module with complex donor workflows, a purpose-built clinical biobanking system will fit better out of the box. If you need validated GMP manufacturing workflows around your repository, an enterprise LIMS is the more direct answer.

If you want to work through this properly, talk to our team and bring your current data export. That conversation is more useful than a feature demo.

For the operational side of running a biobank rather than buying software for one, our post on 5 operational challenges for biobanks covers sample integrity, disaster preparedness, and capacity planning in more depth. SciSure is also not a LIS, which we cover in our guide to figuring out the difference.

FAQ

What is a biobanking LIMS?

A biobanking LIMS is software for tracking biological specimens across their full lifecycle, from collection through storage, aliquoting, distribution, and disposal. It differs from a general LIMS mainly in how it handles specimen lineage, donor consent data, and long-term storage in freezers and liquid nitrogen.

Is a LIMS enough, or do biobanks need an ELN too?

It depends on what happens to the samples. A repository that only receives, stores, and distributes specimens needs a LIMS. If your team also runs experiments on those samples, an ELN covers the experimental record that a LIMS does not.

Can biobanking LIMS software make us ISO 20387 accredited?

No. ISO 20387 accreditation requires assessment by an accreditation body against your whole operation, including quality management, personnel, facilities, and processes. Software can hold the records an assessor asks for, which shortens the preparation considerably, but the accreditation is yours to earn.

How long does migrating to a new biobanking LIMS take?

It depends far more on your data quality than on the software. Cleaning identifiers, resolving duplicate barcodes, and mapping historical staff records typically takes longer than the technical import. Ask any vendor for a test import with your real data before agreeing a timeline.

What should we ask about data residency?

Ask which country or region physically holds the data, whether on-premises or private cloud deployment is available, and what happens to donor data in backups. If you handle EU donor material, involve your data protection officer before shortlisting.

SciSure
Bring your data export, not a feature wishlist
SciSure supports configurable sample models, flexible hosting, and audit trails, and we'll tell you plainly where a purpose-built biobank system would suit you better.
Request a demo

Check out our guide to the best sample management and tracking platforms of 2026 to figure out which might best fit your lab.

About the author:

Zareh Zurabyan

Zareh Zurabyan is VP of GTM & Enterprise Solution Architecture at SciSure, and a biotech executive with extensive experience scaling digital platforms for research and life science organizations. His work sits at the intersection of lab operations, digital strategy, AI-Readiness and therapeutic development, helping institutions build technology stacks that support reproducibility, regulatory readiness, and long-term scientific productivity. Previously, he led growth efforts during the formation of SciSure from eLabNext (Eppendorf Group) and SciShield. He also advises early-stage biotech SaaS companies on market entry, post-acquisition strategy, and operational foundations.

See all posts from this author

Melde dich für unseren Newsletter an

Holen Sie sich die neuesten Tipps, Artikel und exklusiven Inhalte zum modernen Labormanagement in Ihren Posteingang.
Danke! Deine Einreichung ist eingegangen!
Please check your email to verify your submission.
Hoppla! Beim Absenden des Formulars ist etwas schief gelaufen.