Knowella

Document Control Record Template

Document control is judged by one question: is the version at the point of work the current one. Everything else, the numbering, the approval matrix, the change history, exists to make that true, and a system can be immaculate on all of it while a laminated copy of the 2019 procedure hangs next to the machine.

KnowComplyRecordCMP-022Full guide
Test
What is at the point of work
Fails at
Uncontrolled copies

Summary

In short

  • The only test that matters is what is physically at the point of work. A controlled system with uncontrolled printouts in the plant is an uncontrolled system.
  • Obsolete documents must be prevented from unintended use, which requires removal rather than marking, because a marked superseded copy still gets read.
  • Change communication is a separate obligation from change control. Updating a procedure that nobody is told about produces a compliant document and unchanged behaviour.
  • Where a change affects how work is performed, it should trigger a competence question: does anyone need retraining before this takes effect.
  • External documents such as standards, supplier specifications and safety data sheets need control too, and are usually the least controlled category.
  • Retention periods vary widely and some are very long. Exposure and medical records commonly require decades, which outlasts most document systems.

What it is

What it is

What is document control?

The arrangements ensuring that documented information is identified, reviewed and approved before use, available where needed, controlled through changes, and that obsolete versions are prevented from unintended use.

What makes a copy uncontrolled?

Any copy that will not be updated when the source changes: a printout on a noticeboard, a laminated sheet at a machine, a file saved to a local drive, or a version emailed to a contractor. Each is accurate on the day it is made and becomes wrong silently at the next revision.

When to use it

When to use it, and when not to

This covers the control of documented information. The documents themselves sit elsewhere.

Use it for

  • Controlling creation, review, approval, revision and withdrawal of procedures and records
  • Managing distribution and ensuring the current version is available at the point of use
  • Communicating changes to the people whose work they affect
  • Controlling external documents including standards, specifications and safety data sheets
  • Setting and applying retention periods, including the extended ones

Not for

  • The documents being controlled, which are the subject rather than the record
  • Training records, which evidence that a change was communicated and understood
  • Records retention scheduling for statutory categories with their own long periods
  • Data protection and privacy controls, which govern personal data separately
  • Change management for engineering and process changes, which is broader

Standards

What it is built against

Documented information requirements are consistent across management system standards.

ClauseRequirementWhere it lands
ISO 9001 cl.7.5.2Identification, description, format and review and approval for suitability and adequacyVersion control
ISO 9001 cl.7.5.3.1Documented information available and suitable for use where and when needed, and adequately protectedDistribution
ISO 9001 cl.7.5.3.2Distribution, access, retrieval, storage, version control, retention and dispositionRetention
ISO 9001 cl.7.5.3.2Obsolete documented information prevented from unintended use, and identified if retainedVersion control
ISO 45001 cl.7.5.3External documented information determined necessary and controlled appropriatelyDistribution
ISO 45001 cl.7.4Internal communication of relevant information, including changes to the systemCommunication and competence
ISO 9001 cl.7.2Competence, where a change to a procedure may require retraining before it takes effectCommunication and competence
21 CFR 1910.1020 / 117Statutory retention periods, some extending decades beyond employmentRetention

What it does not cover

  • The documents themselves, which this system controls.
  • Training records, evidencing that a change was communicated and understood.
  • Statutory retention scheduling, for categories with their own long periods.
  • Data protection controls, governing personal data separately.
  • Engineering and process change management, which is broader than document revision.

Filling it in

Filling it in well

Control the copies, communicate the change, and check the floor rather than the register.

Eliminate the uncontrolled copy rather than managing it

Printouts, laminated sheets and local files become wrong at the next revision and nobody notices. Where a document must be physically present, either control that copy explicitly with a recall route, or replace it with access to the live version at the point of work. Marking a copy uncontrolled acknowledges the problem without solving it.

Treat communication as a separate step

Approving a revision and telling the affected people are different actions. A procedure updated correctly, with a full change history and no communication, produces a compliant document and identical behaviour on the floor. Record who was told and how, because that is the step that changes anything.

Ask the competence question at each change

Where a revision changes how work is performed, does anyone need retraining before it takes effect. Building that question into the approval step catches the case where a new method is issued and people continue doing what they have always done because nobody flagged that it had changed.

Control external documents too

Standards, supplier specifications, safety data sheets, manufacturer manuals and customer requirements are all external documented information requiring control. They are usually the least controlled category, and a superseded standard or an old safety data sheet is exactly as misleading as an internal document out of date.

Audit findings

Common audit findings

Document control findings concentrate on what is in use rather than on the register.

FindingClauseWhat fixes it
Uncontrolled printouts and laminated copies in use at the point of work.ISO 9001 cl.7.5.3.2Remove them or control them explicitly; marking does not prevent use.
Superseded versions retained without being prevented from unintended use.ISO 9001 cl.7.5.3.2Removal is the control; identification alone still leaves a readable copy.
Changes approved but not communicated to affected workers.ISO 45001 cl.7.4Communication is a separate step and the one that changes behaviour.
No competence check when a revision changes the method.ISO 9001 cl.7.2Ask at approval whether retraining is needed before it takes effect.
External documents not controlled.ISO 45001 cl.7.5.3Standards, specifications and data sheets go out of date silently.
Retention periods not differentiated for statutory categories.1910.1020Some records require decades; a general period will lose them.
Documents available only through a system inaccessible at the point of work.ISO 9001 cl.7.5.3.1Available where needed means where the work happens, on the shift it happens.
Change history incomplete, so what changed cannot be established.ISO 9001 cl.7.5.2Record what changed and why; a version number alone answers neither.
Contractor copies issued and never recalled at revision.ISO 45001 cl.8.1.4Issued copies need a recall route or they persist indefinitely.
Audit performed from the register rather than from the floor.ISO 9001 cl.7.5.3Walk the areas and check what is displayed against current versions.

Worked case

Case in point: the laminated sheet

A site with a well-run electronic document system passed successive audits on document control. Versions were numbered, approvals recorded, change histories complete, and the register was accurate.

An auditor asked to see the procedure for a specific process and was directed to a laminated sheet beside the machine, which was how the operators actually worked. It carried a revision number three versions behind the current one, and the intervening changes included a revised sequence for clearing a jam.

The sheet had been laminated because it was in a wash-down area and paper did not survive. The lamination had solved a practical problem and created a document that could never be updated, and nobody had connected the two.

Definitions

Definitions and key terms

Documented information
The ISO term covering both documents and records, subject to control requirements.
Uncontrolled copy
Any reproduction that will not be updated when the source changes, however accurate when made.
Obsolete document
A superseded version, which must be prevented from unintended use rather than merely marked.
Change communication
Telling the affected people, a step separate from approving and issuing the revision.
External documented information
Standards, specifications, data sheets and manuals originating outside the organisation, requiring control.
Point of use availability
Whether the current version is accessible where and when the work happens, including on night shifts.
Retention period
How long a record must be kept, which varies widely and extends decades for some statutory categories.
Change history
The record of what changed and why, distinct from the version number.

FAQ

Frequently asked questions

What is the real test of document control?+

What is physically at the point of work. Walk the areas, collect every printed procedure, chart and laminated sheet, and check each against the current version. A system with immaculate version control and superseded printouts on the floor is an uncontrolled system, and the register cannot reveal that because the register does not know the printouts exist.

Is marking a copy uncontrolled sufficient?+

No. The requirement is to prevent obsolete information from unintended use, and a marked copy remains readable and gets read. Where a physical copy is genuinely needed, it needs a controlled recall route. Where it is not, it should be removed and replaced with access to the live version.

Why do uncontrolled copies keep appearing?+

Because they solve real problems: paper does not survive a wash-down area, the system needs a login nobody has on nights, the network is slow at the machine. Removing them without addressing the underlying access problem produces new ones within weeks. The durable fix is making the current version usable in the conditions where the work happens.

Is issuing a revision enough?+

No. Approving and issuing a change is separate from telling the people whose work it affects, and a revision nobody is told about produces a compliant document and unchanged behaviour. Where the change alters how work is performed, it should also raise the question of whether anyone needs retraining before it takes effect.

What about external documents?+

They require control too, and they are usually the least controlled category. Standards get revised, supplier specifications change, safety data sheets are reissued after reclassification, and manufacturer manuals are superseded. An out-of-date external document is exactly as misleading as an internal one, and nobody in the organisation owns its currency by default.

The agents

What the agents do with it

The system controls versions. What fails is the copy on the wall and the change nobody communicated.

KnowComply

Holds versions, approvals and change history, and tracks issued physical copies with a recall route rather than assuming there are none.

Ella

Raises the competence question at approval where a revision changes method, so retraining precedes the change taking effect.

KnowSafe

Makes current procedures accessible at the point of work in the conditions where the work happens, which is why uncontrolled copies exist.

KnowQuality

Controls external documents including specifications and safety data sheets, where currency is owned by nobody by default.

This template lives in KnowComplyaudit and governance. Audit programmes, legal register, management review, risk and certification.

Sources

Sources

  • ISO 9001:2015 clause 7.5, documented information
  • ISO 45001:2018 clauses 7.4 and 7.5
  • ISO 14001:2015 clause 7.5, documented information
  • 29 CFR 1910.1020, access to employee exposure and medical records, OSHA
  • ISO 9001:2015 clause 7.2, competence
Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.