What this is
What is document control?
What is document control?
The arrangements ensuring that documented information is identified, reviewed and approved before use, available where needed, controlled through changes, and that obsolete versions are prevented from unintended use.
What makes a copy uncontrolled?
Any copy that will not be updated when the source changes: a printout on a noticeboard, a laminated sheet at a machine, a file saved to a local drive, or a version emailed to a contractor. Each is accurate on the day it is made and becomes wrong silently at the next revision.
Scope
When is a document control record required?
This covers the control of documented information. The documents themselves sit elsewhere.
Use this template when
- Controlling creation, review, approval, revision and withdrawal of procedures and records
- Managing distribution and ensuring the current version is available at the point of use
- Communicating changes to the people whose work they affect
- Controlling external documents including standards, specifications and safety data sheets
- Setting and applying retention periods, including the extended ones
Do not use it for
- The documents being controlled, which are the subject rather than the record
- Training records, which evidence that a change was communicated and understood
- Records retention scheduling for statutory categories with their own long periods
- Data protection and privacy controls, which govern personal data separately
- Change management for engineering and process changes, which is broader
Compliance mapping
Which ISO 9001 cl.7.5 requirements does this satisfy?
Documented information requirements are consistent across management system standards.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 9001 cl.7.5.2 | Identification, description, format and review and approval for suitability and adequacy | Version control |
| ISO 9001 cl.7.5.3.1 | Documented information available and suitable for use where and when needed, and adequately protected | Distribution |
| ISO 9001 cl.7.5.3.2 | Distribution, access, retrieval, storage, version control, retention and disposition | Retention |
| ISO 9001 cl.7.5.3.2 | Obsolete documented information prevented from unintended use, and identified if retained | Version control |
| ISO 45001 cl.7.5.3 | External documented information determined necessary and controlled appropriately | Distribution |
| ISO 45001 cl.7.4 | Internal communication of relevant information, including changes to the system | Communication and competence |
| ISO 9001 cl.7.2 | Competence, where a change to a procedure may require retraining before it takes effect | Communication and competence |
| 21 CFR 1910.1020 / 117 | Statutory retention periods, some extending decades beyond employment | Retention |
What it does not cover
- The documents themselves, which this system controls.
- Training records, evidencing that a change was communicated and understood.
- Statutory retention scheduling, for categories with their own long periods.
- Data protection controls, governing personal data separately.
- Engineering and process change management, which is broader than document revision.
How to complete it
How to complete a document control record, step by step
Control the copies, communicate the change, and check the floor rather than the register.
Printouts, laminated sheets and local files become wrong at the next revision and nobody notices. Where a document must be physically present, either control that copy explicitly with a recall route, or replace it with access to the live version at the point of work. Marking a copy uncontrolled acknowledges the problem without solving it.
Approving a revision and telling the affected people are different actions. A procedure updated correctly, with a full change history and no communication, produces a compliant document and identical behaviour on the floor. Record who was told and how, because that is the step that changes anything.
Where a revision changes how work is performed, does anyone need retraining before it takes effect. Building that question into the approval step catches the case where a new method is issued and people continue doing what they have always done because nobody flagged that it had changed.
Standards, supplier specifications, safety data sheets, manufacturer manuals and customer requirements are all external documented information requiring control. They are usually the least controlled category, and a superseded standard or an old safety data sheet is exactly as misleading as an internal document out of date.
What auditors find
Most common document control record findings
Document control findings concentrate on what is in use rather than on the register.
| Finding | Clause | What fixes it |
|---|---|---|
| Uncontrolled printouts and laminated copies in use at the point of work. | ISO 9001 cl.7.5.3.2 | Remove them or control them explicitly; marking does not prevent use. |
| Superseded versions retained without being prevented from unintended use. | ISO 9001 cl.7.5.3.2 | Removal is the control; identification alone still leaves a readable copy. |
| Changes approved but not communicated to affected workers. | ISO 45001 cl.7.4 | Communication is a separate step and the one that changes behaviour. |
| No competence check when a revision changes the method. | ISO 9001 cl.7.2 | Ask at approval whether retraining is needed before it takes effect. |
| External documents not controlled. | ISO 45001 cl.7.5.3 | Standards, specifications and data sheets go out of date silently. |
| Retention periods not differentiated for statutory categories. | 1910.1020 | Some records require decades; a general period will lose them. |
| Documents available only through a system inaccessible at the point of work. | ISO 9001 cl.7.5.3.1 | Available where needed means where the work happens, on the shift it happens. |
| Change history incomplete, so what changed cannot be established. | ISO 9001 cl.7.5.2 | Record what changed and why; a version number alone answers neither. |
| Contractor copies issued and never recalled at revision. | ISO 45001 cl.8.1.4 | Issued copies need a recall route or they persist indefinitely. |
| Audit performed from the register rather than from the floor. | ISO 9001 cl.7.5.3 | Walk the areas and check what is displayed against current versions. |
Case in point
Case in point: the laminated sheet
A site with a well-run electronic document system passed successive audits on document control. Versions were numbered, approvals recorded, change histories complete, and the register was accurate.
An auditor asked to see the procedure for a specific process and was directed to a laminated sheet beside the machine, which was how the operators actually worked. It carried a revision number three versions behind the current one, and the intervening changes included a revised sequence for clearing a jam.
The sheet had been laminated because it was in a wash-down area and paper did not survive. The lamination had solved a practical problem and created a document that could never be updated, and nobody had connected the two.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- CMP-022
- Archetype
- Record
- Record ID
- DCR-2026-000
- Scoring
- Not scored
- Direction
- n/a
- Singleton
- No
- Basis
- ISO 9001 cl.7.5
- Links
- Links Document Register
- Tags
- Governance, Documentation
- Sections
- 5
- Fields
- 44
- Follow up fields
- 3
- Repeating sections
- 0
- Links out
- 6
Header
12 fieldsRecord ID*
Auto sequence. Format DCR-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Governing Document
Document ID
Format DOC-0000.
Links to FDN-008 Document ID
One Current Version, Findable
Almost every document control failure is the same thing: an old version still in use somewhere because nobody knew where the copies were.
Document Type*
Owner*
Approver*
Version control
7 fieldsVersion*
Issue Date*
Supersedes Version
Change Summary*
Reason For Change*
Scheduled review, incident, audit finding, regulatory change, process change or improvement.
Change Reviewed And Approved*
- Yes3 pts
- No0 pts
MOC ID
Links to FDN-020 MOC ID
Distribution
7 fieldsWhere Copies Exist*
Every location, including laminated copies on the wall and in the office folder.
Controlled Copies Numbered
- Yes3 pts
- No1 pt
Superseded Copies Withdrawn*
- Yes3 pts
- Partly1 pt
- No0 pts
Withdrawal Verified*
- Yes3 pts
- No0 pts
Available At Point Of Use*
- Yes3 pts
- Partly1 pt
- No0 pts
Available In Required Languages*
- Yes3 pts
- Partly1 pt
- No0 pts
Format Suitable For The Environment*
Paper in a wash down area lasts a shift. Laminated or digital is the only workable answer.
- Yes3 pts
- Marginal1 pt
- No0 pts
Communication and competence
6 fieldsAffected People Identified*
- Yes3 pts
- Partly1 pt
- No0 pts
Change Briefed*
- Yes3 pts
- Partly1 pt
- No0 pts
Briefing Record ID
Links to TRN-064 Record ID
Training Required*
Training Delivered Before Use
- Yes3 pts
- No0 pts
Acknowledgement Recorded*
- Yes3 pts
- Partly1 pt
- No0 pts
Retention
12 fieldsRetention Period*
Retention Schedule ID
Links to CMP-024 Schedule ID
Archive Location
Next Review Due*
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Owner*
Signature*
Approver*
Second Signature*
CMP-022 · record IDs look like DCR-2026-000 · Links Document Register
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The system controls versions. What fails is the copy on the wall and the change nobody communicated.
Holds versions, approvals and change history, and tracks issued physical copies with a recall route rather than assuming there are none.

Raises the competence question at approval where a revision changes method, so retraining precedes the change taking effect.
Makes current procedures accessible at the point of work in the conditions where the work happens, which is why uncontrolled copies exist.
Controls external documents including specifications and safety data sheets, where currency is owned by nobody by default.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Document Control Record definitions and key terms
- Documented information
- The ISO term covering both documents and records, subject to control requirements.
- Uncontrolled copy
- Any reproduction that will not be updated when the source changes, however accurate when made.
- Obsolete document
- A superseded version, which must be prevented from unintended use rather than merely marked.
- Change communication
- Telling the affected people, a step separate from approving and issuing the revision.
- External documented information
- Standards, specifications, data sheets and manuals originating outside the organisation, requiring control.
- Point of use availability
- Whether the current version is accessible where and when the work happens, including on night shifts.
- Retention period
- How long a record must be kept, which varies widely and extends decades for some statutory categories.
- Change history
- The record of what changed and why, distinct from the version number.
FAQ
Frequently asked questions about document control record
What is the real test of document control?+
What is physically at the point of work. Walk the areas, collect every printed procedure, chart and laminated sheet, and check each against the current version. A system with immaculate version control and superseded printouts on the floor is an uncontrolled system, and the register cannot reveal that because the register does not know the printouts exist.
Is marking a copy uncontrolled sufficient?+
No. The requirement is to prevent obsolete information from unintended use, and a marked copy remains readable and gets read. Where a physical copy is genuinely needed, it needs a controlled recall route. Where it is not, it should be removed and replaced with access to the live version.
Why do uncontrolled copies keep appearing?+
Because they solve real problems: paper does not survive a wash-down area, the system needs a login nobody has on nights, the network is slow at the machine. Removing them without addressing the underlying access problem produces new ones within weeks. The durable fix is making the current version usable in the conditions where the work happens.
Is issuing a revision enough?+
No. Approving and issuing a change is separate from telling the people whose work it affects, and a revision nobody is told about produces a compliant document and unchanged behaviour. Where the change alters how work is performed, it should also raise the question of whether anyone needs retraining before it takes effect.
What about external documents?+
They require control too, and they are usually the least controlled category. Standards get revised, supplier specifications change, safety data sheets are reissued after reclassification, and manufacturer manuals are superseded. An out-of-date external document is exactly as misleading as an internal one, and nobody in the organisation owns its currency by default.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Management System Governance
Legal and Other Requirements Register
Lists every law, regulation, permit and commitment that applies to your operation
Compliance Obligation Assessment
Assesses how each legal requirement applies to you and what you do to meet it
Compliance Evaluation Record
Records the periodic evaluation of whether you actually comply with each obligation
Regulatory Change Record
Records a change in law or regulation and what it means for you
Regulatory Inspection Record
Records a visit by a regulator, including what was inspected, what was said and any orders issued
Management Review Record
Records the periodic review of the management system by senior leadership, covering performance, risks, resources and improvement

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 9001:2015 clause 7.5, documented information
- ISO 45001:2018 clauses 7.4 and 7.5
- ISO 14001:2015 clause 7.5, documented information
- 29 CFR 1910.1020, access to employee exposure and medical records, OSHA
- ISO 9001:2015 clause 7.2, competence
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.