Document control is the set of rules that guarantees everyone in your organization is working from the current, approved version of the information that matters — and that you can prove it. ISO 9001:2015 clause 7.5 calls this "documented information" and requires that it be identified, reviewed and approved before use, available where the work happens, protected from loss or improper use, version-controlled when it changes, and retained or disposed of on a defined schedule. Nothing in the standard requires a specific tool, a document control manual, or a four-digit numbering scheme. It requires control that is proportionate to your size, your risk and your processes, and evidence that the control actually operates.
Clause 7.5.2 requires that when creating and updating documented information, the organization ensures appropriate identification and description (for example a title, date, author or reference number), format and media, and review and approval for suitability and adequacy. Clause 7.5.3.1 requires that documented information be available and suitable for use where and when it is needed, and adequately protected from loss of confidentiality, improper use or loss of integrity. Clause 7.5.3.2 requires that you address distribution, access, retrieval and use; storage and preservation including preservation of legibility; control of changes such as version control; and retention and disposition.
That is the whole requirement. Six controls, stated plainly. Most of the complexity organizations add on top of it — approval matrices nobody follows, numbering schemes only the quality manager can decode, a document control procedure that runs eleven pages — is self-inflicted and is itself an audit risk, because a control you do not follow is worse than a control you never wrote.
A document tells people what to do and is maintained: procedures, work instructions, drawings, specifications, blank forms, the quality policy. A record proves what happened and is retained: a completed inspection sheet, a signed training log, a calibration certificate, a material test report, an audit report. Both fall under clause 7.5, but they are controlled differently. Documents get revision control and re-approval. Records get retention periods, protection from alteration, and legibility over time. A control plan is a document; the measurements taken against it are records.
The conventional structure is four tiers, and it still works because it matches how questions get answered on a shop floor.
Two rules keep the structure honest. Put each fact in exactly one place and reference it everywhere else, because duplicated text is how two approved documents end up contradicting each other. And keep external documents — customer specifications, supplier manuals, industry standards such as ASME or ASTM, regulations — inside the same register with an owner and a currency check, because clause 7.5.3 does not exempt information just because you did not write it.
A controlled copy is one the system keeps current: when the revision changes, that copy is replaced. An uncontrolled copy is a snapshot with no such promise. The risk lives entirely in printed paper. A laminated setup sheet at a machine, a PDF a supervisor emailed himself, a binder in a truck — each is a document at the point of use with no mechanism to update it.
Three practices that hold up in an audit: keep a distribution list so you know which copies exist and where, stamp or watermark anything printed as either a controlled copy with a distribution number or "UNCONTROLLED COPY — verify current revision before use" with the print date, and make the digital current revision easier to reach than the printed one. If a tablet at the station shows the approved revision in two taps, printed shadow copies stop appearing on their own.
For a genuinely small system it can pass. A master document list with document ID, title, owner, current revision, approval date and next review date, a locked-down folder structure where only the document controller can write, and approval evidence captured somewhere durable will satisfy clause 7.5 if — and only if — one person maintains it with discipline.
It stops working at predictable points: when the master list, the shared drive and the paper on the floor disagree about the current revision; when approval evidence lives in an inbox that belongs to someone who has left; when the same procedure is used at two sites; when revisions happen weekly; when a customer or registrar asks for the change history of one work instruction over three years and reconstructing it takes a day. The honest test is not "does it comply" but "how many hours does audit preparation cost, and would a finding survive the answer."
The last item is the one buyers under-weight and auditors probe hardest. A repository that stores approved PDFs still leaves you to answer by hand which procedures a revised specification affects, who needs retraining, and which open corrective actions reference it.
Inventory what already governs work, decide what genuinely needs control based on risk, assign each item an owner and an ID, define one review and approval route per document type, put the current revision where the work happens, and set a periodic review cadence. Write the document control procedure last, describing what you actually do.
No. The 2015 revision removed the six mandatory documented procedures, including document control. You must control documented information; you are not obliged to write a procedure about controlling it. Most organizations still keep a short one because it makes the rules teachable.
Obsolete revisions in use at the point of work, missing approval evidence, external documents such as customer specifications outside the system, records without a defined retention period, uncontrolled printed copies, and periodic reviews scheduled but never performed.
A document management system stores and finds files. Document control adds approval before use, single-current-revision enforcement, change history as evidence, controlled distribution and retention rules. Storage plus search is a filing cabinet with a better index; control is what an auditor accepts.
ISO 9001 sets no universal number. Retention comes from customer contracts, regulatory and statutory requirements, product life and liability exposure, and sector schemes. Define it per record type, write it down, and apply it consistently.
A named role with the competence to judge suitability and adequacy — often the process owner for technical accuracy plus one management approver. One reviewer and one approver is a legitimate route. What matters is that the authority is defined in advance and the evidence exists.
ISO 9001 document control system guide · QMS document hierarchy · ISO 9001 software as an audit-ready operating system · QMS software buyer’s guide for manufacturers · Lean principles in action · Podcast: a leader’s blueprint for a robust QMS · Podcast: the strategic power of QMS software · QMS software for manufacturers · All QMS2GO features · Learning hub · Authors and editorial team · Schedule a demo