ISO 9001 Document Control: The Complete Implementation Guide

Document control is the set of rules that guarantees everyone in your organization is working from the current, approved version of the information that matters — and that you can prove it. ISO 9001:2015 clause 7.5 calls this "documented information" and requires that it be identified, reviewed and approved before use, available where the work happens, protected from loss or improper use, version-controlled when it changes, and retained or disposed of on a defined schedule. Nothing in the standard requires a specific tool, a document control manual, or a four-digit numbering scheme. It requires control that is proportionate to your size, your risk and your processes, and evidence that the control actually operates.

What does ISO 9001 clause 7.5 actually require?

Clause 7.5.2 requires that when creating and updating documented information, the organization ensures appropriate identification and description (for example a title, date, author or reference number), format and media, and review and approval for suitability and adequacy. Clause 7.5.3.1 requires that documented information be available and suitable for use where and when it is needed, and adequately protected from loss of confidentiality, improper use or loss of integrity. Clause 7.5.3.2 requires that you address distribution, access, retrieval and use; storage and preservation including preservation of legibility; control of changes such as version control; and retention and disposition.

That is the whole requirement. Six controls, stated plainly. Most of the complexity organizations add on top of it — approval matrices nobody follows, numbering schemes only the quality manager can decode, a document control procedure that runs eleven pages — is self-inflicted and is itself an audit risk, because a control you do not follow is worse than a control you never wrote.

What is the difference between a document and a record?

A document tells people what to do and is maintained: procedures, work instructions, drawings, specifications, blank forms, the quality policy. A record proves what happened and is retained: a completed inspection sheet, a signed training log, a calibration certificate, a material test report, an audit report. Both fall under clause 7.5, but they are controlled differently. Documents get revision control and re-approval. Records get retention periods, protection from alteration, and legibility over time. A control plan is a document; the measurements taken against it are records.

How should a QMS document structure be organized?

The conventional structure is four tiers, and it still works because it matches how questions get answered on a shop floor.

Two rules keep the structure honest. Put each fact in exactly one place and reference it everywhere else, because duplicated text is how two approved documents end up contradicting each other. And keep external documents — customer specifications, supplier manuals, industry standards such as ASME or ASTM, regulations — inside the same register with an owner and a currency check, because clause 7.5.3 does not exempt information just because you did not write it.

What is the document control lifecycle?

  1. Draft. The process owner writes it, not the quality department. Identification is assigned here (clause 7.5.2(a)).
  2. Review. Technical review by someone who does the work, plus quality review for adequacy. Substance before format.
  3. Approve. A named authority approves for suitability and adequacy before release (clause 7.5.2(c)). Approval before use is the control auditors test first.
  4. Issue. The approved revision becomes available at the point of use and the previous revision stops being available in the same moment (clauses 7.5.3.1(a) and 7.5.3.2(a)).
  5. Use. People work from it. If they cannot find it in under a minute, the control has failed regardless of what the procedure says.
  6. Change. A revision is raised, reviewed, re-approved, and the change itself is identifiable — what changed, when, why, and by whose authority (clause 7.5.3.2(c)).
  7. Retain or dispose. Superseded revisions are archived for traceability or destroyed per the retention schedule (clause 7.5.3.2(d)).

What are controlled and uncontrolled copies?

A controlled copy is one the system keeps current: when the revision changes, that copy is replaced. An uncontrolled copy is a snapshot with no such promise. The risk lives entirely in printed paper. A laminated setup sheet at a machine, a PDF a supervisor emailed himself, a binder in a truck — each is a document at the point of use with no mechanism to update it.

Three practices that hold up in an audit: keep a distribution list so you know which copies exist and where, stamp or watermark anything printed as either a controlled copy with a distribution number or "UNCONTROLLED COPY — verify current revision before use" with the print date, and make the digital current revision easier to reach than the printed one. If a tablet at the station shows the approved revision in two taps, printed shadow copies stop appearing on their own.

Is a spreadsheet-based document control system enough?

For a genuinely small system it can pass. A master document list with document ID, title, owner, current revision, approval date and next review date, a locked-down folder structure where only the document controller can write, and approval evidence captured somewhere durable will satisfy clause 7.5 if — and only if — one person maintains it with discipline.

It stops working at predictable points: when the master list, the shared drive and the paper on the floor disagree about the current revision; when approval evidence lives in an inbox that belongs to someone who has left; when the same procedure is used at two sites; when revisions happen weekly; when a customer or registrar asks for the change history of one work instruction over three years and reconstructing it takes a day. The honest test is not "does it comply" but "how many hours does audit preparation cost, and would a finding survive the answer."

What features should ISO 9001 document control software have?

The last item is the one buyers under-weight and auditors probe hardest. A repository that stores approved PDFs still leaves you to answer by hand which procedures a revised specification affects, who needs retraining, and which open corrective actions reference it.

Frequently asked questions about document control

How do I implement ISO document control effectively?

Inventory what already governs work, decide what genuinely needs control based on risk, assign each item an owner and an ID, define one review and approval route per document type, put the current revision where the work happens, and set a periodic review cadence. Write the document control procedure last, describing what you actually do.

Does ISO 9001:2015 still require a document control procedure?

No. The 2015 revision removed the six mandatory documented procedures, including document control. You must control documented information; you are not obliged to write a procedure about controlling it. Most organizations still keep a short one because it makes the rules teachable.

What are common document control nonconformities?

Obsolete revisions in use at the point of work, missing approval evidence, external documents such as customer specifications outside the system, records without a defined retention period, uncontrolled printed copies, and periodic reviews scheduled but never performed.

How is document control different from a document management system?

A document management system stores and finds files. Document control adds approval before use, single-current-revision enforcement, change history as evidence, controlled distribution and retention rules. Storage plus search is a filing cabinet with a better index; control is what an auditor accepts.

How long do quality records have to be kept?

ISO 9001 sets no universal number. Retention comes from customer contracts, regulatory and statutory requirements, product life and liability exposure, and sector schemes. Define it per record type, write it down, and apply it consistently.

Who approves documents in a small company?

A named role with the competence to judge suitability and adequacy — often the process owner for technical accuracy plus one management approver. One reviewer and one approver is a legitimate route. What matters is that the authority is defined in advance and the evidence exists.

Related resources

ISO 9001 document control system guide · QMS document hierarchy · ISO 9001 software as an audit-ready operating system · QMS software buyer’s guide for manufacturers · Lean principles in action · Podcast: a leader’s blueprint for a robust QMS · Podcast: the strategic power of QMS software · QMS software for manufacturers · All QMS2GO features · Learning hub · Authors and editorial team · Schedule a demo