Document control basics for quality systems come down to one promise: the right version of the right document reaches the person doing the work, and there is objective evidence that it did. In practice that means every controlled document has a unique identifier, a named owner, a recorded approval, a current revision, defined access rules, and a defined end of life. ISO 9001:2015 clause 7.5 is where auditors look for it.
I have watched enough certification audits to know where the findings come from. It is almost never a missing quality manual. It is a Rev C work instruction sitting in a drawer at a molding machine while the machine runs Rev D settings, or a calibration record that proves nothing because nobody recorded which gauge was used.
This guide covers what to control, how to control it, and how to prove it, with the boring details that turn a document control procedure into something an auditor accepts. The focus is manufacturing and plastics production, because that is where weak document control tends to surface first.
Table of Contents
- What Is Document Control in a Quality System?
- Document Control Basics for Quality Systems at a Glance
- Which Documents Should Be Controlled?
- How Do You Set Up a Controlled Document System?
- How Are Documents Approved and Released?
- How Do You Manage Revisions and Obsolete Documents?
- Where Should Controlled Documents Be Stored?
- How Do You Make Sure Employees Use the Current Version?
- What Should a Document Control Review Include?
- Common Document Control Mistakes and How to Fix Them
- Frequently Asked Questions
- What does ISO 9001 say about document control?
- What are the different levels of documents in a quality management system?
- What are the mandatory documents required by ISO 9001?
- What are the five W’s and four C’s of documentation?
- How do you control obsolete documents in a QMS?
- What is the difference between a document and a record?
- Conclusion
What Is Document Control in a Quality System?
Document control is the set of managed activities that keeps quality-related documents and records identifiable, approved, current, available at the point of use, and traceable. The standard wording is control of documented information, which is what ISO 9001:2015 calls the whole requirement.
Six activities do nearly all the work:
- Identification – every document gets a unique number or code and a title that describes what it governs.
- Approval – a named person with authority signs it off before anyone is allowed to use it.
- Revision control – changes produce a new revision status, a change summary, and re-approval.
- Access and availability – the current version is reachable at the point of use, by the people who need it, without being reachable by people who must not change it.
- Protection – against loss of confidentiality, unintended alteration, and loss of legibility.
- Retention and disposition – records are kept for a defined period; obsolete documents are withdrawn and destroyed or archived so they cannot be mistaken for current.
That last one is where most systems leak. A controlled document is something you manage. A reference document — a supplier brochure, a general industry guideline, a textbook excerpt — is not controlled at all, and pretending otherwise just adds noise to your register.
Two terms you will see defined in every serious procedure. Obsolete document: a document that is no longer valid, whether superseded, withdrawn, or expired. Objective evidence: the record that proves something actually happened, as opposed to a statement that it should.
Document Control Basics for Quality Systems at a Glance

Eight elements cover most of what an auditor will ask about on any given document.
| Element | What it answers | Typical practice |
|---|---|---|
| Document type | How is it controlled? | Policy, procedure, work instruction, specification, form, drawing, record, external document |
| Owner | Who maintains it? | One named person per document, not a department mailbox |
| Approval authority | Who signs it off? | Defined in the document control procedure, matched to document level |
| Revision status | Is this current? | Rev code plus issue date on every page |
| Access | Who may read or edit it? | Read for operators, edit for owners and document control only |
| Storage | Where does the master live? | One controlled repository, with a read-only published copy |
| Retention | How long do we keep it? | Defined per document type, driven by customer and regulatory need |
| Review frequency | When is it checked? | Scheduled cycle, plus review triggered by a change or an audit finding |
Note what is missing from that table. There is no row for how many procedures you have. ISO 9001:2015 does not require a quality manual and does not set a minimum number of procedures. It requires that whatever you have is current, approved, and available. More documentation is not better documentation.
Which Documents Should Be Controlled?
Start with the document types you would be embarrassed to have wrong on the floor. For a plastics or injection molding operation that is a manageable list.
- Policy and quality manual – top-level commitments. The manual is optional under ISO 9001:2015; a scope statement and a policy are not.
- Procedures – who does what, when, and how the process steps connect. Your document control procedure, purchase control, corrective action, internal audit.
- Work instructions – the step-by-step at the machine: setup sheet for a molding cell, purging sequence, changeover sequence, inspection method.
- Specifications and drawings – material grades, tolerances, cavity drawings, and the customer drawings you build to.
- Forms – the blank templates, including first article inspection reports, nonconformance reports, and calibration labels.
- Records – the completed evidence: first article reports signed off, gauge calibration certificates, training acknowledgments, internal audit reports, CAPA records, management review minutes.
- External documents – customer drawings, material datasheets, and standards you have decided to adopt. These are documents of external origin and they need the same control as your own, because an out-of-date customer print circulating uncontrolled will fail you just as badly.
Documents and records are treated differently, and getting this distinction right saves you a lot of wasted effort. Documents describe what should happen and get revised. Records describe what did happen and are protected from alteration.
| Attribute | Document | Record |
|---|---|---|
| Purpose | Tell people what to do | Prove what was done |
| Changes | Revised and re-approved through change control | Never revised; a correction is made under the correction procedure |
| Point-of-use status | Current revision must be available | Archived once complete |
| Retention | Kept while current, plus one superseded revision | Kept for a defined retention period, then dispositioned |
| Editing rights | Owner and document control | Nobody, after the fact |
ISO 9001:2015 is direct about the two halves. Clause 7.5.1 is about maintaining documented information: the quality manual, objectives, process maps, and the evidence of what the organization determined and who decided it. Clause 7.5.2 is about retaining documented information: the results of monitoring, measurement, traceability, conformity, nonconformity, corrective action, internal audit, external audit, management review, and competence. Clause 7.5.3 is the control itself, and it applies to both documented information and external documents.
How Do You Set Up a Controlled Document System?
Here is the sequence that works, in the order that keeps you from rebuilding twice.
- Run a gap analysis against clause 7.5. List what you actually have today, in email attachments, on a shared drive nobody can navigate, and in a filing cabinet. Most shops find roughly a third of their documents are active and two thirds are orphans.
- Define the hierarchy and the rules. Write a short document control procedure that states which types exist, who owns each, who approves each, and how long each is retained. Keep it to a few pages.
- Adopt a numbering convention. One scheme, applied consistently, applied before you migrate anything.
- Build the register and set permissions. One row per document with the metadata fields below.
- Set the approval workflow. Route by document type, not by whoever happens to remember.
- Train and publish. Everyone who uses a document confirms they have seen the current version.
- Review and audit. A scheduled cycle plus internal audit checks on a defined sample.
A document numbering convention you can copy
The most useful scheme I have seen comes from a practitioner discussion on the Elsmar quality forum: five positions. Position one is the letter of the system process. Position two is a consecutive letter A to Z. Positions three to five are digits 001 to 999. That yields roughly 24,000 numbers per process area, which sounds absurd for most plants until you look at a large manufacturer running more than 10,000 documents in a single process area.
Worked examples from that scheme:
- PA001 – Purchasing process, first document.
- PA002 – Purchasing process, second document.
- QA014 – Quality Assurance process, fourteenth document.
- MOP003 – Moulding Operations process, third document.
The letters matter more than the digits. A reader who sees MOP knows before opening the file that this is a moulding operations document, and the number only has to be unique. One caution from the same thread: document levels such as procedure, instruction, and checklist matter enormously to whoever built the numbering system and barely at all to the operator at the machine. Keep the taxonomy simple enough to explain in a training session.
Metadata fields worth putting in the register for every controlled document:
- Document number and title
- Type and hierarchy level
- Process area and owner
- Current revision and issue date
- Effective date
- Approver name and approval date
- Next review date
- Storage location and access level
- Supersedes and superseded by
- Retention period and disposition method
Ownership is where most argument happens, so be decisive. A moderator on that same Elsmar thread pushed back on strict single ownership: when HR and Operations both touch a document, forced co-ownership can break departmental silos and reflect how the work really runs, but the borrowed management principle is blunt – two owners of one process means the job does not get done. A workable rule of thumb: one accountable owner, several named contributors, and a single backup owner written down.
How Are Documents Approved and Released?
Approval means someone with defined authority confirms the content is correct and fit for use, and that confirmation is recorded. Two separate roles, not one. The author writes, the reviewer checks technical accuracy, the approver accepts accountability for release.
For manufacturing documents the review is cross-functional by nature. A work instruction for a molding cell gets read by the process engineer who wrote it, the operator who runs it, the maintenance lead who will do the changeover, and quality who will audit against it. A review that skips the operator produces exactly the finding everyone dreads: the procedure describes a process nobody follows.
Release criteria worth writing into your procedure:
- All reviewers have signed within the defined timeframe
- Effective date is set and shown on the document
- Training impact is assessed and acknowledged before the effective date
- Superseded copies are withdrawn on the same day the new revision is released
- The document is published to the controlled location, not emailed
That last point matters more than it looks. Approval that depends on somebody remembering to send the right email is not auditable, and every practitioner forum on this topic reaches the same conclusion independently.
How Do You Manage Revisions and Obsolete Documents?
Revisions are simple if you follow three rules. Never reissue a document without a revision status change. Never change content without a change summary. Never reissue without re-approval at the same level as the original.
Trigger re-approval on: a process change, an equipment or tooling change, a material or supplier change, a new regulation or customer requirement, an audit finding, a CAPA action, or a periodic review that confirms no change is needed but the document is reissued anyway. That last one is worth doing on purpose. A document nobody has reviewed in three years is a weak witness in an audit even if it happens to be correct.
Withdrawal of obsolete documents is the activity auditors check first, because it is where failures are visible. The control has three parts: physically remove the obsolete copy from every point of use, mark the master as superseded so nobody re-uses it by accident, and record what you removed, from where, and when. If you keep paper at the machine, your register needs a printed-copy log with the location, the holder, the issue, and the date withdrawn.
Retention periods come from three places: law, your customer, and your own risk. Where none of those specify, set a defensible period and write down the reasoning.
| Framework | Typical expectation | Note |
|---|---|---|
| ISO 9001:2015 | No fixed period stated | Set your own, proportionate to product and process risk |
| ISO 13485 | Commonly the lifetime of the device plus two years | Wider than ISO 9001, and the main reason medical device firms cannot copy a generic rule |
| FDA 21 CFR Part 820 | Follows the underlying regulation | Check the applicable regulation rather than a summary of it |
| IATF 16949 | Driven by customer and PPAP requirements, often vehicle lifetime plus a calendar period | Customer terms usually dominate |
| AS9100 | Long, product-lifetime-driven | Aerospace configuration records go back further than most people expect |
Retention figures are the area to verify against your own applicable regulation. Treat the table as a starting point for a conversation with your customer and your compliance lead, not as legal advice.
Where Should Controlled Documents Be Stored?

Every option works at small scale and breaks at a specific size. The honest question is which limit you are about to hit.
| Approach | Control capability | Where it breaks |
|---|---|---|
| Paper binders | Visible, hard to lose physically, easy to audit by flipping pages | Withdrawal of obsolete copies, point-of-use availability across shifts, revision confusion, no search |
| Shared drive with a folder structure | Free, searchable, version history in most setups | No approvals, no permissions worth the name, no link between a document and the training record for it |
| Spreadsheet register | A usable index, often the first real step | Cannot manage attachments, reminders, or audit trail; becomes a second uncontrolled copy |
| General-purpose wiki or collaboration tool | Familiar to staff, quick to roll out | Retrofitting traceability is hard; page history is not a revision record. Practitioners on the Atlassian community forum hit exactly this friction. |
| Dedicated eQMS or EDMS | Workflow, reminders, permissions, audit trail, training links, obsolete handling | Cost and the migration effort to get legacy documents in |
| Hybrid | Electronic master with controlled printed copies at machines | Needs a printed-copy log, which is the part most plants skip |
Whichever you pick, four things have to be true. There is one authoritative location, backed up on a schedule you have tested. Access is role-based, so an operator can read a work instruction but cannot edit it. Every change produces a timestamped audit trail. And the whole thing has a continuity plan, because a document control system that dies with one laptop is not audit-ready.
How Do You Make Sure Employees Use the Current Version?
This is the most common practical complaint on quality forums, and the cause is almost always the same: people save local copies because they do not trust that the central copy is current. Once a person has a PDF in their downloads folder, the system has already failed.
What works, roughly in order of impact:
- Kill the attachment habit. Publish to a controlled location and say plainly that emailed copies are uncontrolled.
- Train on the how, not just the what. Show operators how to open the current work instruction at the machine in under thirty seconds.
- Record acknowledgment. A training record naming the person, the document number, the revision, the date, and the trainer. This is also your objective evidence.
- Control printed copies deliberately. Stamp them, number them, log who holds them, and withdraw them when superseded. A watermark is not a substitute for the log, and the ability to print at all is a permanent problem you manage rather than solve.
- Audit the floor, not the cabinet. Ask an operator to show you the current version of a work instruction they use. If they pull up a saved file, you have your finding and you already know the corrective action.
- Handle remote and contract sites explicitly. Define how a contract molder receives the current list, confirms receipt, and returns obsolete copies.
One more control that closes the loop nobody connects: document control, change control, CAPA, and training are one cycle, not four systems. A CAPA action that changes a process must produce a revised document, a training record, and a verification that the revised process held. If those three are not linked in your register, an auditor will find the gap between what you fixed and what you now tell people to do.
What Should a Document Control Review Include?
A scheduled document review and an internal audit of document control are different activities that answer the same question from different angles. The review asks whether a document is still right. The audit asks whether your document control system works.
For a scheduled review, work through: is the document still needed, is it still accurate, does it match how the work is actually done, has anything changed in process, equipment, material, regulation, or customer requirement, and is a re-issue warranted.
For an internal audit sample, check: identification and numbering are unique and applied, approval is present and by an authorized person, the revision status is current, superseded revisions are withdrawn, printed copies in the area match the register, the document is legible and available at the point of use, retention and disposition are defined, external documents are identified as such, and the document matches the process it describes. Then ask someone who actually does the work to describe the process, and compare. The mismatch is the finding.
Two community frameworks are useful as a review lens, with the caveat that neither is defined by ISO. Both are widely used practice shorthand, not requirements. The five W’s of documentation ask what, why, who, when, and where. The four C’s ask whether a document is correct, current, complete, and consistent. A work instruction that fails the first W – what is this actually for – is usually a work instruction that should not exist.
Common Document Control Mistakes and How to Fix Them
Obsolete revisions still in circulation. The universal number one failure, and it usually shows up as a printed copy or a local saved file. Fix: a withdrawal log, a point-of-use check, and a periodic floor sweep.
Uncontrolled drafts circulating. Someone works on a procedure in a personal folder while the approved version stays in use, and the draft is better than the approved copy. Fix: a single working copy in the system, marked draft, editable only by the owner.
No named owner. The procedure exists, nobody is accountable for it, and it drifts. Fix: one owner per document in the register, with a named backup.
Missing approval evidence. The document says approved but there is no record of who approved it or when. Fix: approval is captured in the system, not inferred from an email thread.
Weak naming conventions. Final_v3_USE_THIS_new.doc at the top of a folder, with no revision control and no date. Fix: adopt a numbering convention and let the title carry the meaning. Numbers first, titles second.
Records missing where the activity happened. Calibration was done, training happened, a deviation was handled, and nothing was captured. Fix: tie the record to the activity in the process itself, and audit for the gap rather than the volume.
Over-documentation. Exhaustive paperwork nobody can use, which creates its own inconsistency risk because nobody updates all of it. Fix: document the process as it actually runs, and delete what nobody reads.
Here is what the last three look like in a single audit. An auditor asks a molding operator how nonconforming product is handled. The operator describes a real, careful process: quarantine the parts, tag the boxes, raise a report, get quality disposition. The auditor then reads the written procedure and finds it describes a different quarantine location and a form that was retired eight months ago. The operator did nothing wrong. The finding is written against document control, it is a major nonconformity because the controlled information does not reflect actual practice, and it drags in containment, root cause, corrective action, and a re-audit visit. The whole thing traces back to a revision that was issued without withdrawing the previous one.
Frequently Asked Questions
What does ISO 9001 say about document control?
ISO 9001:2015 covers all of this in clause 7.5, titled control of documented information, split into three parts. Clause 7.5.1 covers maintaining documented information, such as the quality manual, process information, and evidence of decisions. Clause 7.5.2 covers retaining documented information, including results of monitoring, traceability, conformity, nonconformity, corrective action, audits, management review, and competence. Clause 7.5.3 covers controlling both, plus external documents of origin.
What are the different levels of documents in a quality management system?
Most quality systems use four levels. Level one is policy and quality manual, the top-level commitments. Level two is procedures, which describe who does what and when. Level three is work instructions, the step-by-step used at the machine or desk. Level four is forms and records, where completed evidence is captured and kept. The number of levels is a convention rather than an ISO requirement, but the clear separation between what people should do and proof of what happened is not negotiable.
What are the mandatory documents required by ISO 9001?
ISO 9001:2015 does not name a fixed list of documents and no longer requires a quality manual. It requires documented information to support the operation of the processes, the information needed to achieve product and service conformity, and evidence that the system achieves its results. In practice that means a scope statement, a quality policy, documented information for each process, and retained evidence for monitoring, nonconformity, corrective action, audits, and management review.
What are the five W’s and four C’s of documentation?
These are community frameworks used as review lenses, not ISO-defined requirements. The five W’s ask what, why, who, when, and where a document applies. The four C’s ask whether a document is correct, current, complete, and consistent. They are useful because a document that fails the first W often should not exist at all, and a document that fails the C’s is the usual root cause behind a documentation audit finding.
How do you control obsolete documents in a QMS?
Control obsolete documents in three steps. Remove every superseded copy from each point of use, including printed copies at machines. Mark the master as superseded so it cannot be re-issued or reused by mistake. Then record what was removed, from which location, on what date, and who confirmed it. If printed copies are permitted, maintain a printed-copy log listing the holder, location, revision, and withdrawal date for each one.
What is the difference between a document and a record?
A document describes what should happen and is revised when the process changes, with re-approval and a new revision status each time. A record describes what actually happened and is never revised once completed. A correction to a record is made under a defined correction procedure so the original entry remains visible. This distinction drives retention: documents are kept while current, records are kept for a defined period and then dispositioned.
Conclusion
Document control basics for quality systems are not complicated, they are just unglamorous and easy to postpone. Five things to do first, in order:
- List the documents that would hurt you most if they were wrong on the floor, and control those before anything else.
- Give every controlled document one named owner and one named backup.
- Adopt a numbering convention and a metadata list, then apply them to the new documents before you migrate the old ones.
- Move the master into one controlled location, and make the point-of-use path fast enough that nobody keeps a local copy.
- Put a review date on every document and audit the floor, not the cabinet.
Everything else — the software choice, the retention schedule, the clause 7.5 wording — gets easier once those five hold.