Document Control ISO — 6 Critical Steps to Master It Before Your ISO Audit

Document control ISO failures are the number one source of non-conformances in ISO 9001 certification and surveillance audits worldwide. An operator using an obsolete Rev A procedure when Rev C is current. A document without an approval signature. A master document list that does not match the documents in actual use.

These are not complex failures. They are preventable failures — caused by document control systems that were set up for certification and never properly maintained.

This guide gives you 6 critical steps to master document control ISO Clause 7.5 — before your next auditor finds the gaps you have not noticed yet.

⚠️ The #1 audit finding globally in document control: an auditor walks to a workstation, picks up a work instruction, checks the revision — and it does not match the master list. Major non-conformance issued in under 60 seconds.

WHAT IS DOCUMENT CONTROL AND WHY DOES ISO 9001 CLAUSE 7.5 REQUIRE IT?

Document control ISO 9001 requirements sit in Clause 7.5 — Documented Information. This clause requires your organisation to maintain documented information that supports your Quality Management System, and to control that information so it remains appropriate, adequate, and available when needed.

ISO 9001:2015 — and the upcoming ISO 9001:2026 — uses the term “documented information” to cover both what older versions called “documents” (instructions, procedures, plans) and “records” (evidence that activities were performed).

Your document control system must ensure six things, which form the basis of this guide:
✅ Documents are properly identified and have current version information
✅ Documents are reviewed and approved before use
✅ Version changes are controlled and documented
✅ Current versions are available at the point of use
✅ Obsolete versions are removed or clearly marked
✅ Records are retained, protected, and retrievable

DOCUMENT CONTROL ISO — STEP 1: ESTABLISH YOUR DOCUMENT IDENTIFICATION SYSTEM

Every controlled document must be uniquely identifiable. This means every document must have:

→ A unique document reference number or code
→ A descriptive title
→ A revision number (Rev A, Rev B, Rev C — or v1.0, v1.1, v2.0)
→ A date of issue or effective date
→ The name of who prepared it and who approved it

A Master Document List (MDL) — sometimes called a Document Register — is a single index listing every controlled document, its current revision, and its location. This is the first document your auditor will ask for. It tells them immediately whether your document control system is under control.

The MDL must match reality. If a document exists at Rev C, the MDL must show Rev C. If a document has been withdrawn, it must be removed from the MDL. Discrepancies between the MDL and documents in circulation are instant non-conformances.

DOCUMENT CONTROL ISO — STEP 2: CREATE A ROBUST APPROVAL PROCESS

No document enters use without being reviewed and approved. This is a non-negotiable requirement of document control ISO Clause 7.5.

Your approval process must define:
→ Who has authority to prepare documents — typically the process owner or SME
→ Who reviews documents for technical accuracy — typically a subject matter expert
→ Who approves documents for release — typically the Quality Manager or department head
→ How approval is evidenced — signature, electronic approval, or dated acknowledgement

Common failure: a document is updated informally, saved to the shared drive, and distributed without formal review or approval. No approval evidence. No revision record. Instant non-conformance.

For electronic documents — your system must prevent unauthorised modification. Read-only access for users, controlled write access for document owners, and a clear audit trail of who changed what and when.

DOCUMENT CONTROL ISO — STEP 3: CONTROL EVERY VERSION CHANGE

Every revision to a controlled document must follow your approval process — not just new documents. The same rigour applies to every change, no matter how minor.

For every revised document, your document control system must capture:
→ What changed — a revision history or change log
→ When it changed — the effective date of the new version
→ Who approved the change — named individual with signature or electronic approval
→ Whether affected personnel were notified and trained

The revision history does not need to be complex. A simple table at the back of the document showing “Rev B: Section 3.2 updated to reflect new equipment — approved by [Name] on [Date]” is entirely adequate for auditors.

DOCUMENT CONTROL ISO — STEP 4: MAKE CURRENT VERSIONS AVAILABLE AT POINT OF USE

Current versions of documents must be available wherever the work is performed. For a manufacturing site, this means work instructions, procedures, and control plans must be accessible on the production floor — not locked in an office.

For paper-based systems: a controlled copy with a watermark or stamp identifying it as a controlled document. Uncontrolled copies should be clearly marked as such and not used for operations.

For electronic systems: shared drives, SharePoint, Google Drive, or QMS software — any system works provided access controls prevent outdated versions from remaining in circulation. Folder structure and naming conventions must make it immediately clear which version is current.

External documents — including ISO standards, customer specifications, and regulatory requirements — must also be controlled. Your master list must show the current edition of every external document you rely on.

DOCUMENT CONTROL ISO — STEP 5: REMOVE OR MARK ALL OBSOLETE DOCUMENTS

This is the single most important step in document control ISO compliance — and the most commonly failed.

When a document is revised, the previous version must be:
→ Removed from all points of use immediately — every workstation, shared drive folder, and printed copy
→ Either destroyed, or clearly marked OBSOLETE if retained for reference or legal reasons

Obsolete documents in circulation are the most common document control finding globally. An operator working from an outdated procedure may be performing an activity incorrectly — with genuine quality or safety consequences.

For paper systems: maintain a controlled copy distribution list so you know where every printed copy is and can retrieve them when a revision is issued.

For electronic systems: archive obsolete versions in a separate folder with a clear naming convention indicating their obsolete status. Ensure the live document location only ever contains the current version.

DOCUMENT CONTROL ISO — STEP 6: CONTROL RECORDS — RETENTION, PROTECTION, AND RETRIEVAL

Records are different from documents — they are the evidence that activities have been performed. Your document control system must manage both.

For records, your system must ensure:
→ Retention periods are defined for each record type — how long must it be kept?
→ Records are protected from damage, loss, or deterioration — secure storage, backup, environmental controls
→ Records are legible — handwritten records must be readable and completed at the time of the activity
→ Records are retrievable — you can find and present any record an auditor requests within a reasonable time

A retention policy does not need to be complex. A simple register showing record type, retention period, storage location, and disposal method is entirely sufficient.

COMMON DOCUMENT CONTROL ISO AUDIT FAILURES

❌ FAILURE 1 — Obsolete document found at workstation
The most common finding. Fix: retrieval system for all controlled copies when a revision is issued.

❌ FAILURE 2 — Master document list does not match documents in use
MDL shows Rev B, workstation has Rev A. Fix: update MDL immediately when documents are revised.

❌ FAILURE 3 — Documents without approval evidence
Updated informally, no signature or approval record. Fix: enforce approval process for every change.

❌ FAILURE 4 — No revision history on changed documents
Cannot demonstrate what changed or when. Fix: add a revision history table to every controlled document.

❌ FAILURE 5 — External documents not controlled
Using an old edition of an ISO standard or customer specification. Fix: include external documents in your MDL.

THE BOTTOM LINE

Document control ISO Clause 7.5 compliance is not complicated — but it requires discipline. The right document. The right version. At the right location. Used by the right people. Updated through the right process. Obsolete versions removed immediately. Build your Master Document List. Set up a controlled approval process. Institute a rigorous obsolete document removal procedure. Audit your own document control quarterly. Those four actions alone will eliminate the most common document control ISO findings before your auditor finds them.

👉 Download your free document control checklist at standardsunlimited.com/free

#DocumentControl #ISO9001 #ISO9001Clause75 #DocumentedInformation #QMS #QualityManagement #VersionControl #ISOAudit #AuditReady #Compliance #InternalAudit

Leave a Comment