Introduction
An ISO 9001 document control procedure defines how your organization creates, approves, distributes, revises, and retires the documented information your quality management system depends on. It sounds administrative, but it is one of the highest-leverage procedures in the entire QMS: with more than one million valid ISO 9001 certificates worldwide according to the annual ISO Survey, certification bodies consistently report control of documented information among the most frequently cited sources of audit nonconformities.
The reason is simple. Document control touches every other process. An operator working from a superseded work instruction, an uncontrolled drawing on a shop-floor clipboard, or a customer specification nobody updated — each one is a finding waiting to happen, and each one is a real quality risk long before an auditor sees it.
This guide explains what clause 7.5 actually requires, walks through the full document lifecycle, and gives you a practical template for an SME manufacturer.
Why Your ISO 9001 Document Control Procedure Matters
Clause 7.5 of ISO 9001:2015 covers documented information — the standard's umbrella term for both documents (things you work from) and records (evidence of what happened). The clause requires that documented information is identified, formatted, reviewed, and approved appropriately (7.5.2), and that it is available where needed, adequately protected, and controlled for distribution, access, storage, changes, retention, and disposition (7.5.3).
Notice what the clause does not require: a specific numbering scheme, a specific software tool, or paper sign-off sheets. ISO 9001:2015 deliberately reduced prescriptive documentation demands compared to earlier revisions. What auditors check is whether your stated controls exist, whether they are followed, and whether the documents people actually use match the documents your system says are current. Your procedure defines the rules; the audit tests whether reality matches them.
For a quality manager at a small or mid-size manufacturer, this is good news. You do not need an enterprise document management suite. You need a clear lifecycle, consistent identification, and discipline about the point of use.
Key Elements of a Document Control Procedure
1. What Clause 7.5 Actually Requires
Break the requirements into three groups. Creation and updating: every controlled document needs identification (title, number, date, author), an appropriate format, and review and approval for suitability before release. Control: documents must be available at the point of use, protected from loss of confidentiality or integrity, and managed through their lifecycle. Records: evidence of conformity must be retained, legible, retrievable, and protected from unintended alteration. Your procedure should map each requirement to a specific mechanism so an auditor can trace requirement to control.
2. The Document Lifecycle
Define the full lifecycle explicitly: create, review and approve, distribute, use, revise, and obsolete. Name who can perform each step. A common SME model: the process owner drafts, a technical reviewer checks content, the quality manager approves for release, and the quality function controls distribution and archives obsolete versions. Every stage transition should leave evidence — an approval signature, a system timestamp, or a change record.
3. Document Numbering and Metadata Conventions
Adopt a numbering convention and apply it without exception. A workable scheme for manufacturers: a type prefix (QM for quality manual, PR for procedure, WI for work instruction, FM for form), a department or process code, and a sequence number — for example PR-QA-004. Required metadata on every document: unique number, title, revision, effective date, approver, and page numbering (page X of Y). Resist over-engineering: a numbering scheme that encodes too much meaning breaks the first time you reorganize departments.
4. Revision Control and Change History
Every controlled document carries a revision identifier and a change history table summarizing what changed, why, who approved it, and when. Require that changes are reviewed by the same function that approved the original — or a defined equivalent. Highlight or summarize the nature of the change so users can see what is different without a line-by-line comparison. Auditors routinely sample a revised document and ask an operator what changed in the latest revision; the change history is how your team answers.
5. Controlled Copies vs Uncontrolled Copies
A controlled copy is one your system updates when the master changes; an uncontrolled copy is a snapshot with no update obligation. Define both. If you issue printed controlled copies, keep a distribution register recording copy number, location, and holder, and retrieve or destroy superseded copies at every revision. Mark uncontrolled prints clearly — a footer stating that printed copies are uncontrolled and the electronic system holds the current version is standard practice and eliminates an entire category of findings.
6. External Documents
Clause 7.5.3.2 requires that documents of external origin necessary for the QMS are identified and controlled. For a manufacturer that means standards (ISO, ASTM, customer-referenced specs), customer drawings and specifications, regulatory documents, and supplier data sheets. Maintain an external document register listing each document, its version, its owner, and how you learn about updates. Customer specification revisions are a classic failure point: define who receives customer engineering changes and how the register and shop-floor copies get updated.
7. Documents vs Records: Know the Difference
Documents tell people what to do and are revised over time; records are evidence of what was done and must never be revised. A work instruction is a document; the completed inspection sheet made from it is a record. The distinction drives different controls: documents need revision management, records need protection from alteration and defined retention. Blank forms sit in the middle — the form template is a controlled document, while the filled-in form is a record.
8. Retention Schedules and Disposition
Publish a retention schedule listing each record type, its retention period, its storage location, and its disposition method. Retention periods come from customer contracts, regulatory requirements, product liability exposure, and business need — not from guesswork. Typical SME manufacturing retentions run from three years for training records to the product lifetime plus a margin for critical inspection and traceability records. Define disposition: who authorizes destruction, how confidential records are destroyed, and what evidence of destruction you keep.
9. Electronic Document Control vs Paper
Electronic control is now the default for most SMEs, and for good reason: a single master, automatic timestamps, access control, and no copy retrieval problem. Your procedure should define access permissions (who can edit vs read), backup arrangements, and how the point of use is served — shop-floor terminals, tablets, or posted controlled prints. If you run a hybrid system, be explicit about which is master. The most common hybrid failure: the PDF on the server is revision D while the laminated card at the workstation is revision B.
10. Common Audit Nonconformities in Document Control
Registrars see the same findings year after year: obsolete documents at the point of use; documents in use that were never formally approved; external documents (especially customer specs) at the wrong revision; missing or inconsistent document identification; records stored where they can be edited; and retention schedules that exist on paper but are not followed. Build your internal audit checklist directly from this list — it is exactly what your certification auditor will sample.
Step-by-Step: Building Your Document Control Procedure
- Inventory what exists. List every document type in use — procedures, work instructions, forms, drawings, external specs — and where each physically lives.
- Define the lifecycle and authorities. Write the create-review-approve-distribute-revise-obsolete flow and name the roles at each step.
- Set the numbering and metadata standard. Pick a simple convention and retrofit it to existing documents during their next scheduled review rather than in one big-bang renumbering.
- Build the master document register. One list of every controlled document with number, title, current revision, owner, and next review date.
- Control the point of use. Walk the floor, find every printed copy, and either register it as a controlled copy or mark it uncontrolled.
- Publish the retention schedule. Cover every record type with a period and a disposition rule.
- Audit it within 90 days. Sample five documents from the register and trace each from master to point of use before your certification body does.
Common Mistakes to Avoid
Writing the procedure for the auditor instead of the user. A 15-page document control procedure nobody reads is itself a document control failure. Two to four pages plus a register is enough for most SMEs.
Uncontrolled point-of-use copies. The master can be perfect; the finding happens at the workstation. Control the last metre.
Treating records like documents. Records must be protected from change, not revised. Storing inspection records in an editable shared folder is a standing nonconformity.
Forgetting external documents. Customer specifications and referenced standards change without your involvement. If nobody owns the external document register, it is out of date.
No obsolete document handling. Superseded documents retained for knowledge or legal reasons must be clearly marked as obsolete and segregated from current documents.
How AI Accelerates SOP Creation
WorkProcedures generates a complete ISO 9001 document control procedure from a plain-language description of how your organization works, and its compliance projects map your documented procedures against ISO 9001 requirements. Branded PDF export and acknowledgement tracking give you controlled distribution with evidence built in.
Conclusion
A strong ISO 9001 document control procedure is the backbone of your QMS: a clear lifecycle, consistent identification, disciplined revision control, and honest attention to the point of use. Get clause 7.5 right and every other clause becomes easier to demonstrate. Visit WorkProcedures to build your document control SOPs today.