
Document control is the part of ISO 9001 that generates the most unnecessary paperwork, because it’s the part most often implemented from fear rather than from the standard. Read clause 7.5 closely and it asks for less than most quality manuals deliver, but it asks for it consistently, which is where systems fail.
Here’s what the clause actually says, what auditors actually check, and where manual systems typically break.
What counts as “documented information”
ISO 9001:2015 dropped the old vocabulary of “documents” and “records” in favor of one term: documented information. It covers both:
- Information you maintain: procedures, work instructions, specifications, the quality policy. Things that describe how work should happen and get revised over time.
- Information you retain: records. Inspection results, training sign-offs, calibration certificates, management review minutes. Evidence that work did happen, which shouldn’t change after the fact.
The distinction matters because the control requirements differ. Maintained documents need revision control and approval. Retained records need protection from alteration and loss, plus defined retention.
The actual requirements of clause 7.5
Boiled down, 7.5.2 and 7.5.3 require that documented information is:
- Identified and described: a title, date, author, or reference number. The standard doesn’t mandate a numbering scheme; it mandates that you can tell documents apart.
- Reviewed and approved for suitability and adequacy before use.
- Available where and when it’s needed: the released version at the point of use.
- Protected from loss of confidentiality, improper use, and loss of integrity.
- Controlled through its lifecycle: distribution, access, retrieval, storage, change control, retention, and disposition.
- Guarded against unintended use of obsolete versions: the retired revision can’t quietly keep circulating.
Notice what’s not there: no requirement for wet signatures, no mandated master list format, no rule that every document needs a three-letter prefix and a form number. Those are conventions, not requirements.
What auditors actually look for
An experienced auditor rarely starts with your document control procedure. They start on the floor. The classic move: pick up whatever instruction is at a workstation and ask three questions.
- Is this the current revision? Then they check it against your register or system.
- Who approved it? Then they ask for the approval evidence.
- When it changed, who was told? Then they look at training records for the affected people.
Each question crosses a boundary between systems: the floor copy, the register, the approval trail, the training matrix. In a manual QMS those are four different artifacts maintained by hand, and every handoff between them is a place for the answers to disagree. Most document control findings aren’t “no procedure exists”; they’re “the procedure exists and reality has drifted from it.”
Where manual document control breaks
The failure modes are predictable enough to list:
- The uncontrolled copy. Someone prints a work instruction or saves a local copy “for convenience.” It’s correct for exactly as long as the document never changes again.
- The stale register. The master list is a spreadsheet updated after the fact; sometimes days after, sometimes never.
- Approval by folder location. The document is “approved” because it’s in the Approved folder. Who moved it there, and when, is anyone’s guess.
- The silent revision. A document changes, the version number ticks up, and nobody who uses the document finds out until something goes wrong.
- Retention roulette. Records are retained “forever, probably” because nobody defined disposition, and the shared drive slowly becomes a liability instead of an archive.
None of these come from carelessness. They come from a control system where every rule depends on a human remembering to follow it under time pressure.
Meeting 7.5 without the paperwork factory
Whether you run document control in software or on paper, the same principles keep it lean:
Control the minimum that needs controlling. Not every scrap of information is QMS documented information. Over-controlling reference material buries the documents that matter and trains people to ignore the stamps.
Make the released version the easy one to find. If the controlled copy takes four clicks and the desktop copy takes zero, the desktop copy wins. Availability at point of use is a usability requirement wearing compliance clothing.
Tie change to notification. A revision that nobody hears about is a nonconformance in incubation. Whatever your system, releasing a change should trigger who needs to know automatically, ideally straight into training requirements.
Let approval leave a trail by itself. If approving a document and recording the approval are two separate actions, the record will eventually be skipped. In good QMS software they’re the same action: the approval workflow is the evidence.
Define retention once, then stop thinking about it. A simple retention schedule beats a sophisticated one nobody follows.
The register, reconsidered
The document register (the master list of what’s controlled, at what revision, owned by whom) is the heart of clause 7.5 compliance. In a spreadsheet-based QMS it’s also the single most fragile artifact you own: manually maintained, always slightly behind, and load-bearing for every audit.
The register shouldn’t be a document someone maintains. It should be a view of the system, generated from the documents themselves, current by construction. That’s the quiet, structural difference between running document control in software and running it by hand: the evidence stops being something you produce and becomes something you already have.