Document control is one of those Quality Management processes that looks simple until you try to make it work across a real organisation.
Create a document. Review it. Approve it. Give it a revision number. Put it somewhere people can find it.
What could possibly go wrong?
Quite a lot, unfortunately.
People save uncontrolled copies on their desktops. Managers approve procedures by email without updating the master copy. Employees continue using old forms. Customer specifications change without the relevant department knowing. Records are altered without traceability. Nobody knows which version is current, and obsolete documents somehow return from the dead.
I have seen organisations with beautifully written procedures that nobody follows and shared drives containing several files with names such as:
- Final
- Final revised
- Final approved
- Final approved latest
- Final approved latest 2
- Final approved latest USE THIS ONE
That is not document control.
ISO 9001 document control is the process used to make sure that the right information is available to the right people, in the correct version, when and where it is needed.
It should also protect important documents and records against unintended change, loss, misuse or deterioration.
This guide explains:
- What ISO 9001 requires for document control
- The meaning of documented information
- The difference between documents and records
- Whether a document-control procedure is mandatory
- How to create a practical document-control procedure
- What to include in a master document register
- How documents should be reviewed and approved
- How to control external documents
- How to manage obsolete documents and records
- How electronic document-control systems should work
- Common document-control mistakes
- What auditors look for
- Practical examples for different types of organisations
If you are building a Quality Management System from the beginning, use this guide alongside my step-by-step guide to implementing ISO 9001.
What is document control in ISO 9001?
ISO 9001 document control is the process used to create, identify, review, approve, distribute, revise, store, protect, retrieve, retain and dispose of documented information.

Its purpose is to ensure that information remains:
- Suitable for its intended use
- Available where and when it is needed
- Appropriately protected
- Correctly identified
- Properly reviewed and approved
- Controlled when changed
- Stored and preserved
- Accessible only to authorised people where necessary
- Retained for an appropriate period
- Disposed of in a controlled way
Document control is not simply a Quality Department filing activity.
Every process depends on reliable information.
Sales teams need current customer requirements. Purchasing teams need approved supplier information. Production teams need current work instructions. Engineers need approved specifications. Internal auditors need reliable records. Management needs accurate performance information.
If those people are using incomplete, incorrect or obsolete information, the process is already out of control.
My guide to ISO 9001 requirements and Clauses 4 to 10 explains how documented information fits within the wider Quality Management System.
What is documented information?
ISO 9001 uses the term documented information.
This term covers both:
- Information the organisation needs to maintain
- Information the organisation needs to retain as evidence
Documented information can exist in many formats.
Examples include:
- Policies
- Procedures
- Process maps
- Work instructions
- Forms
- Registers
- Checklists
- Specifications
- Drawings
- Customer requirements
- Contracts
- Reports
- Meeting minutes
- Training material
- Photographs
- Videos
- Electronic records
- Software data
- Emails containing important approvals or decisions
- Inspection and testing results
- Audit reports
- Certificates
- Databases
- Cloud-based workflows
A document does not need to be a Word or PDF file.
Information stored in business software, an electronic form, a mobile application or a controlled database can also be documented information.
The important question is not:
Is this a document?
The better question is:
Does this information need to be controlled so that the process works properly or so that the organisation can demonstrate what happened?
Maintained and retained documented information
There is a useful practical distinction between documented information that is maintained and documented information that is retained.
Maintained documented information
Maintained information helps the organisation operate its processes.
It normally describes:
- What needs to happen
- Which requirements apply
- Who is responsible
- How an activity should be completed
- Which criteria should be followed
Examples include:
- Policies
- Procedures
- Process maps
- Work instructions
- Specifications
- Approved drawings
- Blank forms
- Inspection plans
- Checklists
- Organisation charts
- Quality plans
Maintained documents may need to be reviewed, revised and reissued when requirements or processes change.
Retained documented information
Retained information provides evidence of what happened.
Examples include:
- Completed forms
- Inspection records
- Test reports
- Training records
- Calibration certificates
- Audit reports
- Management-review minutes
- Supplier evaluations
- Customer-complaint records
- Nonconformity reports
- Corrective-action evidence
- Product-release records
Records should normally be protected as evidence.
They should not be revised in the same way as a working procedure.
If a correction is necessary, the change should be authorised and traceable. The original information should not simply disappear without explanation.
This distinction helps organisations establish the correct controls.
A procedure may be revised and replaced.
A completed audit report should normally be preserved as evidence of the audit conducted at that time.
Documents versus records
The terms document and record are still widely used, even though ISO 9001 groups both under documented information.

The practical difference is:
| Document | Record |
|---|---|
| Describes what should happen | Provides evidence of what happened |
| May be revised | Should be preserved |
| Used to control an activity | Used to demonstrate the result |
| Examples include procedures and instructions | Examples include completed forms and reports |
| Usually has an approval and revision status | Usually has a completion date and responsible person |
| Superseded versions may be replaced | Historical records should normally remain retrievable |
Consider an internal-audit checklist.
The blank approved checklist is a controlled document.
Once the checklist has been completed during an audit, it becomes a record.
The same principle applies to forms, inspection checklists, training assessments and evaluation templates.
Does ISO 9001 require a document-control procedure?
ISO 9001:2015 does not automatically require every organisation to maintain a separate written document-control procedure.
This is an important difference from older versions of the Standard, which were more prescriptive about documented procedures.
However, the organisation still has to control its documented information effectively.
A procedure can therefore be extremely useful—particularly where:
- Many documents are used
- Several departments create and approve information
- Documents change frequently
- Customer or regulatory requirements apply
- Multiple locations are involved
- Employees need controlled access
- Records must be retained for long periods
- External documents affect operations
- Document responsibilities are unclear
- Electronic approval workflows are used
A small consultancy with five employees may not need a ten-page document-control procedure.
A multinational engineering company probably does.
The level of documentation should reflect the organisation’s size, complexity, risks, competence and operating environment.
ISO 9001 does not reward organisations for creating unnecessary procedures.
The objective is control—not paperwork.
Why document control matters
Poor document control can create much more than administrative inconvenience.
It can result in:
- Products made to obsolete specifications
- Services delivered against outdated requirements
- Incorrect materials being purchased
- Employees following superseded procedures
- Missed customer requirements
- Unapproved process changes
- Incorrect inspection criteria
- Regulatory noncompliance
- Lost evidence
- Repeated errors
- Customer complaints
- Rework
- Delays
- Failed audits
- Legal and contractual disputes
In construction, outdated drawings or specifications can result in work being installed incorrectly and then covered before the problem is discovered.
I have covered the construction-specific risks, workflows, drawing registers, transmittals, RFIs and handover records in my separate guide to creating a construction document-control procedure and register.
That article is specifically for construction projects.
This guide has a wider purpose: establishing document control as part of an ISO 9001 Quality Management System in any industry.
What documents should be controlled?
The organisation should identify documented information that affects:
- Customer requirements
- Product or service conformity
- Process effectiveness
- Legal and regulatory compliance
- Employee competence
- Operational consistency
- Inspection and acceptance
- Traceability
- Business continuity
- Quality Management System performance
Typical controlled documents include:
Management-system documents
- Quality Policy
- Quality objectives
- QMS scope
- Process maps
- Procedures
- Work instructions
- Organisation charts
- Responsibility matrices
- Risk registers
- Audit programmes
Operational documents
- Specifications
- Technical drawings
- Production instructions
- Service-delivery instructions
- Inspection plans
- Testing methods
- Acceptance criteria
- Maintenance instructions
- Method statements
- Job sheets
- Approved forms
Customer documents
- Contracts
- Purchase orders
- Drawings
- Specifications
- Technical requirements
- Service-level agreements
- Customer standards
- Approved changes
- Correspondence affecting requirements
External documents
- Legislation
- Regulations
- Industry standards
- Codes of practice
- Manufacturer instructions
- Product data sheets
- Material safety information
- Customer portals
- Supplier manuals
- Equipment manuals
Quality records
- Internal-audit reports
- Inspection results
- Test reports
- Calibration records
- Training and competence records
- Supplier evaluations
- Customer complaints
- Management-review records
- Nonconformity reports
- Corrective-action records
- Product or service release evidence
Not every email, note or draft needs formal document control.
The organisation should apply controls proportionately according to the information’s importance and risk.
The seven principles of effective ISO 9001 document control

1. Identification
Every important document should be identifiable.
Depending on the organisation, identification may include:
- Document title
- Reference number
- Department or process
- Document owner
- Revision number
- Issue date
- Approval status
- Page number
- Confidentiality classification
A document number can be useful, but numbering everything does not automatically create control.
A clear title, responsible owner, revision status and approval may be more important than a complicated reference code nobody understands.
Avoid document-numbering systems that require employees to consult another procedure before they can create a file.
2. Review and approval
Documents should be reviewed and approved for suitability and adequacy before use.
The reviewer should consider whether the document is:
- Technically correct
- Complete
- Consistent with requirements
- Practical
- Clear to the intended user
- Compatible with related processes
- Suitable for the organisation
The approver should have appropriate authority.
A Quality Manager should not automatically approve every document in the company.
A technical work instruction may require approval from the relevant technical manager. A commercial process may require approval from the Commercial Director. A health-and-safety instruction may require competent specialist review.
The Quality Department may check that the document-control process has been followed without taking responsibility for every document’s technical content.
3. Availability and access
The current approved document must be available where and when it is needed.
This may involve:
- Shared drives
- Intranets
- Document-management platforms
- Controlled printed copies
- Mobile applications
- Production terminals
- Customer portals
- Business-management software
Access should be appropriate.
Employees need access to information required for their work, but that does not mean everyone needs permission to change it.
Good systems distinguish between:
- Viewing
- Editing
- Reviewing
- Approving
- Publishing
- Archiving
- Deleting
Access restrictions should protect information without making the system so difficult that employees create uncontrolled alternatives.
4. Version and change control
When a document changes, users should be able to identify:
- What changed
- Why it changed
- Who reviewed the change
- Who approved it
- When the change became effective
- Which version is current
- Whether affected people were informed
Revision control can use:
- Sequential numbers
- Letters
- Dates
- Software version histories
- Automated workflow records
There is no universal ISO 9001 revision format.
Revision 1 is not inherently better than Revision A.
The system needs to be consistent, understandable and traceable.
Minor formatting corrections may not require the same level of control as a change to a technical requirement.
The procedure should explain how different types of changes are handled.
5. Distribution and communication
Approving a document is not enough.
The people affected by it need to know:
- That it exists
- That it has changed
- When the new version applies
- Whether training or briefing is required
- What should happen to previous copies
Methods of communication may include:
- Automated notifications
- Email alerts
- Team briefings
- Toolbox talks
- Training sessions
- Department meetings
- Software tasks
- Controlled distribution lists
Not every revision requires formal training.
However, significant changes affecting responsibilities, technical requirements or operational controls should be communicated appropriately.
A person cannot follow a revised process if nobody tells them that the process has changed.
6. Storage and protection
Documented information should be protected against:
- Unauthorised access
- Unintended alteration
- Loss
- Damage
- Corruption
- Deterioration
- Accidental deletion
- Cybersecurity threats
- Inappropriate disclosure
Controls may include:
- Permissions
- Passwords
- Backups
- Encryption
- Access logs
- Locked storage
- Fire-resistant storage
- Disaster-recovery arrangements
- Controlled correction processes
- Data-validation rules
Protection should reflect risk.
Confidential employee records need stronger restrictions than a publicly available Quality Policy.
A calibration certificate may need reliable backup and retention but not the same confidentiality controls as commercially sensitive customer information.
7. Retention and disposal
Records should be retained for a defined period.
Retention requirements may come from:
- Legislation
- Regulations
- Contracts
- Customers
- Certification requirements
- Insurance
- Warranty obligations
- Product life
- Industry practice
- Organisational needs
The organisation should determine:
- Which records are retained
- Where they are stored
- Who owns them
- How long they are kept
- How they remain readable
- How they can be retrieved
- How they are disposed of
- Whether disposal requires approval
Keeping everything forever is not necessarily good control.
It increases storage, privacy, security and retrieval problems.
Deleting records too early can be even worse.
A document-retention schedule can provide a practical solution.
How to create an ISO 9001 document-control procedure
A useful document-control procedure should reflect how the organisation genuinely works.
Do not copy a complicated procedure from a multinational company if your business has twelve employees and one office.
The procedure should answer the following questions.
Purpose
Why does the procedure exist?
For example:
This procedure establishes the controls for creating, reviewing, approving, issuing, revising, distributing, storing, retaining and disposing of documented information required by the Quality Management System.
Scope
Which information and parts of the organisation are covered?
The scope may include:
- All QMS documents and records
- Particular locations
- Electronic and hard-copy information
- Customer and external documents
- Particular software systems
Responsibilities
Define who is responsible for:
- Creating documents
- Reviewing technical content
- Approving documents
- Maintaining the master register
- Publishing approved versions
- Communicating changes
- Managing access
- Archiving records
- Establishing retention periods
- Disposing of expired information
- Auditing the process
Document creation
Explain any requirements for:
- Templates
- Titles
- References
- Revision numbers
- Owners
- Approvers
- Formatting
- Confidentiality
- Effective dates
Standard templates can improve consistency, but visual consistency should not become more important than useful content.
Review and approval
Define:
- Who reviews documents
- Who approves them
- How approval is recorded
- Whether electronic approval is acceptable
- When documents require reapproval
- What happens when approval is rejected
Issue and distribution
Explain:
- Where approved documents are published
- How users are notified
- How printed copies are controlled
- How external parties receive documents
- How distribution evidence is maintained where necessary
Revision and change control
Define:
- How changes are requested
- How changes are reviewed
- How revision status is updated
- Whether change descriptions are recorded
- How effective dates are established
- How previous versions are removed
- Whether users require briefing or training
External documents
Explain:
- How external documents are identified
- Who monitors them
- How updates are detected
- Where approved copies are stored
- How affected employees are informed
- How obsolete external documents are controlled
Records
Define:
- How completed records are identified
- Where they are stored
- How they are protected
- How corrections are made
- How long they are retained
- Who can access them
- How they are disposed of
Obsolete documents
Explain:
- How previous versions are removed from normal use
- Whether they are archived
- Why they may be retained
- How they are marked
- Who can access them
- How unintended use is prevented
The ISO 9001 master document register
A master document register is a practical way to identify controlled documents and their current status.
It is not specifically mandatory, but it is often extremely useful.
A document register may include:
- Document reference
- Document title
- Process or department
- Document owner
- Document type
- Current revision
- Issue date
- Effective date
- Reviewer
- Approver
- Approval status
- Storage location
- Access classification
- Review date
- Retention period
- Obsolete-document location
- Comments
A simple example might look like this:
| Reference | Document title | Owner | Revision | Issue date | Approver | Status |
| QMS-PRO-001 | Document Control Procedure | Quality Manager | 03 | 15 July 2026 | Managing Director | Approved |
| OPS-WI-004 | Equipment Start-Up Instruction | Operations Manager | 05 | 10 July 2026 | Operations Director | Approved |
| HR-FRM-002 | Competence Assessment Form | HR Manager | 02 | 4 July 2026 | HR Director | Approved |
| PUR-PRO-003 | Supplier Evaluation Procedure | Procurement Manager | 04 | 28 June 2026 | Commercial Director | Approved |
The register should help people identify the current document.
It should not become another record that is always out of date.
Where a document-management system automatically records document metadata, approval and revision history, a separate manual register may duplicate information unnecessarily.
Use the register where it adds control.
Do not maintain it merely because an auditor expects to see a spreadsheet.
Who should own a document?
Every controlled document should have a responsible owner.
The owner is normally the person accountable for the process described by the document.
The document owner may be responsible for:
- Confirming that the document remains necessary
- Reviewing its content
- Coordinating updates
- Consulting affected departments
- Obtaining approval
- Ensuring related documents remain consistent
- Confirming that users are informed
The Quality Manager should coordinate the management system, but process owners should take responsibility for their own documents.
Otherwise, the Quality Department becomes responsible for maintaining procedures it does not operate and cannot fully understand.
That is how QMS documents gradually become disconnected from reality.
How often should documents be reviewed?
ISO 9001 does not require every document to be reviewed annually.
The organisation should establish a review approach appropriate to risk.
Documents may be reviewed:
- At a defined interval
- When requirements change
- When processes change
- After an audit finding
- Following a nonconformity
- After a customer complaint
- When equipment or software changes
- When responsibilities change
- When legislation or standards change
- When users identify that the document is unclear or ineffective
A mandatory annual review of every document can create a large administrative exercise with little value.
People may simply change the review date without examining whether the document remains useful.
High-risk operational instructions may justify scheduled reviews.
Stable low-risk documents may only need review when something changes.
The procedure should describe the organisation’s approach.
How to control document changes
A practical document-change process may follow these steps:
- A change is requested.
- The document owner evaluates the need.
- A revised draft is prepared.
- Affected departments are consulted.
- Technical and process implications are reviewed.
- Related documents are identified.
- The revised document is approved.
- The revision and effective date are updated.
- The new version is published.
- Affected people are notified or trained.
- Superseded versions are removed from normal use.
- Evidence of the change and approval is retained.
Related documents are easily overlooked.
A change to a purchasing procedure may affect:
- Supplier evaluation forms
- Approved-supplier registers
- Purchase-order templates
- Receiving instructions
- Inspection requirements
- Software workflows
- Training material
Document change should therefore be treated as a process change—not only a file replacement.
Controlling external documents
External documents are created outside the organisation but are necessary for planning or operating its processes.
Examples include:
- Customer specifications
- Legislation
- Regulations
- International and national standards
- Industry codes
- Manufacturer instructions
- Equipment manuals
- Supplier data sheets
- Approved customer drawings
- External licences and permits
External documents present a common weakness because nobody inside the organisation feels responsible for maintaining them.
The organisation should determine:
- Which external documents are important
- Who owns each document
- Where the controlled version is stored
- How changes are monitored
- How access is provided
- What happens when a new version is issued
- Whether the change affects existing work
Buying a copy of a standard and placing it in a folder does not complete the process.
Someone needs to monitor whether the standard remains current and assess what a revision means for the organisation.
Controlling printed copies
Electronic systems have reduced the number of printed documents, but hard copies are still used in many workplaces.
Printed copies may be controlled by:
- A controlled-copy stamp
- A unique copy number
- A distribution register
- Named copy holders
- Expiry dates
- Regular replacement
- Colour coding
- A statement that printed copies are uncontrolled
Simply writing “uncontrolled when printed” does not solve every problem.
If employees need paper instructions at the point of use, the organisation should establish a reliable way to replace them when the master document changes.
Otherwise, the disclaimer merely transfers responsibility to the user without providing a practical control.
How should obsolete documents be controlled?
When a document is replaced, previous versions should be protected against unintended use.
Possible controls include:
- Removing them from the active folder
- Restricting access
- Moving them to a controlled archive
- Adding an obsolete or superseded watermark
- Disabling links
- Replacing printed copies
- Maintaining revision history
- Preventing normal users from downloading archived copies
Obsolete documents may need to be retained for:
- Legal reasons
- Contractual evidence
- Historical traceability
- Product support
- Investigations
- Audit evidence
- Demonstrating which requirement applied at a particular time
An obsolete document is not necessarily a document that should be destroyed.
The critical control is preventing it from being used as the current instruction.
Correcting completed records
Completed records occasionally contain errors.
The correction method should preserve traceability.
For paper records, a practical method may involve:
- Crossing out the incorrect entry with a single line.
- Entering the correct information.
- Adding the initials or signature of the person making the correction.
- Recording the date.
- Explaining the reason where it is not obvious.
Correction fluid or erasing the original entry should normally be avoided because it removes evidence of what was first recorded.
Electronic systems should ideally maintain:
- User identification
- Date and time
- Original value
- Revised value
- Reason for change
- Approval where required
- Audit trail
Not every record needs an advanced electronic signature system.
The strength of the control should reflect the risk and importance of the information.
Electronic document-control systems
ISO 9001 does not require organisations to purchase document-management software.
A small company may effectively control documents using:
- A structured shared drive
- Clear permissions
- A master document register
- Standard templates
- A defined approval process
- Reliable backups
Larger or more complex organisations may benefit from systems providing:
- Workflow approval
- Version history
- Automated notifications
- Permission management
- Search
- Audit trails
- Electronic signatures
- Retention controls
- Archive management
- Integration with training systems
- Mobile access
- Reporting
Software can strengthen document control, but it does not repair an unclear process.
If responsibilities, approval routes and document ownership are confused, the electronic system may simply automate the confusion.
Technology should support the process—not become the process.
Using email for document approval
Email approval can be acceptable if the organisation can demonstrate:
- Which document was approved
- Which revision was approved
- Who approved it
- When it was approved
- That the approval was authorised
- That the approved version was subsequently published
- That approval evidence is retained
Problems occur when documents continue circulating as attachments after approval.
Several recipients may then save separate copies, and the organisation loses control over which version is current.
Where possible, send links to the controlled document rather than attaching copies.
Document control in small businesses
A small business does not need a document-control bureaucracy.
A proportionate system could use:
- One controlled QMS folder
- Restricted editing permissions
- A simple document register
- Named document owners
- Approval recorded electronically
- Clear revision numbers
- A separate records folder
- Automated backups
- A basic retention schedule
The main requirements remain the same:
- Current information is available.
- Changes are authorised.
- Obsolete versions are prevented from unintended use.
- Records remain protected and retrievable.
A simple system that people follow is better than a sophisticated system they avoid.
Document control in construction
Construction projects create a particularly difficult document-control environment.
Information may come from:
- Clients
- Designers
- Consultants
- Main contractors
- Subcontractors
- Suppliers
- Laboratories
- Regulators
- Manufacturers
Project documents may include drawings, specifications, RFIs, technical submittals, method statements, Inspection and Test Plans, inspection records, NCRs and handover information.
A response to an RFI in construction may affect a drawing, method statement, material approval, ITP and completed work.
That information needs to reach the people performing and inspecting the activity.
Because construction requires its own detailed workflows, I have explained the complete process separately in my guide to construction document control.
Construction companies should also connect project document control with the organisation’s wider QMS. My guide to ISO 9001 for construction companies explains that relationship.
Document control and Quality Assurance
Document control is primarily a Quality Assurance activity because it establishes the information and controls needed to prevent mistakes.
However, document control also supports Quality Control.
An inspector cannot make a reliable acceptance decision without:
- The correct specification
- The current drawing
- Approved acceptance criteria
- A suitable inspection form
- The required test method
The relationship is explained further in my guide to Quality Assurance versus Quality Control.
A controlled procedure does not prove that people follow it.
That is why document control must be checked through monitoring, internal audits and operational verification.
Document control and internal audits
An ISO 9001 internal audit should evaluate whether documented information is controlled in practice.
The auditor may sample:
- Current procedures
- Document approvals
- Revision histories
- Employee access
- Printed copies
- External documents
- Completed records
- Retention arrangements
- Archived documents
- Software audit trails
- Previous document-related findings
A useful audit does not remain inside the master document register.
The auditor should visit the place where the work happens and confirm that people are actually using the current approved information.
In construction, this means checking the drawing or method statement being used on site.
In manufacturing, it may mean checking the instruction available at the workstation.
In a service business, it may mean checking which template or guidance employees use when delivering work to customers.
ISO 9001 document-control audit checklist
Use the following questions as a practical starting point.
Identification and approval
- Are controlled documents clearly identified?
- Is the current revision evident?
- Are document owners defined?
- Are documents reviewed before issue?
- Are approvers appropriately authorised?
- Is approval evidence retained?
Access and availability
- Can employees find the documents they need?
- Are current versions available at the point of use?
- Are editing permissions restricted appropriately?
- Can users distinguish drafts from approved documents?
- Are confidential documents protected?
Changes and revisions
- Are changes reviewed and approved?
- Is the nature of significant changes recorded?
- Are affected documents updated consistently?
- Are users informed about important revisions?
- Are training or briefings completed where necessary?
Obsolete documents
- Are superseded documents removed from normal use?
- Are archived versions clearly identified?
- Are old printed copies replaced?
- Can obsolete information be accessed accidentally?
External documents
- Have important external documents been identified?
- Is responsibility for monitoring them assigned?
- Can the organisation determine whether they remain current?
- Are changes assessed and communicated?
Records
- Are records legible and retrievable?
- Are electronic records protected?
- Are corrections traceable?
- Are retention periods defined?
- Are records disposed of securely?
- Are backups reliable and tested?
Effectiveness
- Have document-control failures caused errors?
- Are employees creating uncontrolled workarounds?
- Does the system help people perform their work?
- Are repeated audit findings occurring?
- Is the document register current?
- Are the controls proportionate to risk?
Common ISO 9001 document-control mistakes
Creating too many documents
Organisations sometimes assume that ISO 9001 requires a procedure for every clause.
It does not.
Excessive documentation becomes difficult to maintain and increases the chance that written procedures no longer reflect reality.
Letting the Quality Department own everything
Process owners should be responsible for the documents used within their processes.
The Quality Department can coordinate the system, but it should not become the technical owner of every company procedure.
Controlling formatting rather than content
A document may have the correct logo, footer, reference and revision while containing unclear or inaccurate instructions.
Document control should ensure suitability—not just visual consistency.
Using uncontrolled attachments
Employees distribute documents as email attachments and continue using downloaded copies after the master has changed.
Forgetting external documents
Customer specifications, legislation and standards change, but the organisation continues using old requirements.
Keeping an inaccurate document register
A register that does not reflect the documents actually in use gives false confidence.
Treating approval as implementation
A procedure has been approved and published, but affected employees have not been informed or trained.
Changing records without traceability
Completed records are overwritten or corrected without preserving the original information.
Retaining everything forever
The organisation has no retention rules and stores large volumes of duplicated, obsolete and confidential information indefinitely.
Deleting records too early
Important evidence disappears before warranty, legal, contractual or customer obligations have ended.
Assuming software guarantees compliance
The organisation purchases an expensive system but fails to define ownership, approval, access and change responsibilities.
Practical document-control example
Imagine that a company changes its supplier-evaluation process.
The previous procedure required an annual questionnaire for every supplier.
Management decides to adopt a risk-based approach:
- Critical suppliers will receive an annual evaluation.
- Medium-risk suppliers will be evaluated every two years.
- Low-risk suppliers will be reviewed based on performance.
- Poor performance can trigger an additional audit.
A properly controlled change would include:
- Revising the supplier-evaluation procedure.
- Updating the evaluation form.
- Updating the approved-supplier register.
- Reviewing related purchasing instructions.
- Checking whether software workflows need modification.
- Obtaining approval from the responsible process owner.
- Recording the change and new revision.
- Establishing an effective date.
- Communicating the revised process to purchasing personnel.
- Removing the previous form from normal use.
- Retaining the superseded procedure where necessary.
- Checking implementation during a future audit.
Changing only the procedure would leave the rest of the process inconsistent.
That is why document control needs to consider the complete system.
Document control and nonconformities
Document-control failures can produce nonconforming products and services.
Examples include:
- Manufacturing to an obsolete specification
- Using an expired inspection form
- Delivering a service against outdated customer instructions
- Purchasing an unapproved material
- Using an outdated drawing
- Applying superseded acceptance criteria
The immediate issue should be corrected and the affected work controlled.
Where the failure is significant or recurring, the organisation should investigate why the document-control process failed.
My guide to ISO 9001 nonconformity and corrective action explains how to distinguish correction, containment, root cause and corrective action.
If the underlying cause is unclear, the practical methods in my root-cause analysis guide can help.
Frequently asked questions
What is document control in ISO 9001?
Document control is the process used to ensure that documented information is appropriately created, reviewed, approved, distributed, revised, stored, protected, retained and disposed of.
Which ISO 9001 clause covers document control?
Documented information is primarily addressed in Clause 7.5. However, document and record requirements also appear throughout the Standard because every QMS process depends on reliable information and evidence.
Does ISO 9001 require a document-control procedure?
ISO 9001:2015 does not automatically require a separate documented procedure for document control. The organisation must nevertheless demonstrate that its documented information is effectively controlled.
Is a document register mandatory for ISO 9001?
No. A master document register is not specifically mandatory. It is a practical tool for identifying controlled documents, owners, revisions and approval status. An electronic document-management system may provide the same control without a separate spreadsheet.
What should a document register contain?
It may contain the document reference, title, owner, department, current revision, issue date, approver, status, storage location, review date and retention requirements.
What is the difference between a document and a record?
A document normally describes what should happen and may be revised. A record provides evidence of what happened and should normally be preserved with traceable corrections.
What is a controlled copy?
A controlled copy is a distributed copy whose location or recipient is known and which is replaced or updated when the master document changes.
Are printed documents automatically uncontrolled?
No. Printed documents can be controlled if the organisation records their distribution and ensures that they are replaced when revisions change. A statement such as “uncontrolled when printed” does not remove the organisation’s responsibility where employees rely on paper copies.
Can documents be approved by email?
Yes, provided the organisation can identify the document and revision approved, the authorised approver, the approval date and the approval evidence. The approved version should then be published in the controlled system.
How often should controlled documents be reviewed?
ISO 9001 does not require every document to be reviewed annually. Review frequency should reflect risk, process change, legal requirements, audit results and organisational needs.
How should obsolete documents be controlled?
Obsolete documents should be removed from normal use or clearly identified and restricted. They may be retained for legal, historical, contractual or traceability reasons.
How long should ISO 9001 records be retained?
ISO 9001 does not provide one universal retention period. The organisation should consider legal, regulatory, contractual, customer, warranty and business requirements.
Does ISO 9001 require document-management software?
No. Organisations can use shared drives, registers and manual controls if they are effective. Software may be useful where document volumes, approval workflows, locations or security requirements are more complex.
Final thoughts
ISO 9001 document control should make information easier to trust and use.
It should not create a bureaucratic obstacle between employees and the instructions they need.
A practical system ensures that:
- Important documents are clearly identified.
- Suitable people review and approve them.
- Current versions are available.
- Changes are controlled.
- External requirements are monitored.
- Obsolete information is prevented from unintended use.
- Records remain protected and retrievable.
- Retention and disposal are properly managed.
The best document-control system is not necessarily the one with the most procedures, the most expensive software or the most impressive numbering structure.
It is the one that consistently provides people with the right information and reliable evidence.
If your organisation is building its complete QMS, continue with my guide on how to implement ISO 9001 step by step.
For construction-specific document workflows, drawing registers, RFIs, transmittals and handover records, read my detailed guide to construction document control.
You can also explore the complete ISO 9001 resource hub for practical guidance on requirements, implementation, certification, audits, nonconformities and continual improvement.