What this is
What counts as a controlled document?
What counts as a controlled document?
Anything that governs how work is done and must stay current for people to follow it correctly: policies, procedures, work instructions, specifications, plans, forms and drawings. A controlled document has an owner, a version number and a review cycle. An email or a one-off memo is not controlled — it has no lifecycle to manage.
What is the difference between a document register and a records retention schedule?
The document register tracks the documents that tell people what to do — procedures, policies, work instructions — and their current version. A records retention schedule tracks how long the evidence generated by doing that work must be kept. One governs instructions, the other governs proof, and they are maintained on different cycles for different reasons.
Why does Status matter more than the version number?
The Status field, not the version number, decides what Pick Lists across the library are allowed to show. A document can carry version 4 and still be wrong if Status was never flipped from Current to Superseded when version 5 was issued. Version number is a label; Status is the control.
Scope
When is a document register required?
The register exists so any template can point at the document that governs it and reach the current version automatically. Used for the wrong purpose it becomes a dumping ground that nobody trusts.
Use this template when
- A new policy, procedure, work instruction, specification, plan, register or drawing needs a controlled entry
- An existing document is revised, reissued, superseded or withdrawn
- A template elsewhere in the library needs to reference the document that governs it
- The compliance lead or document controller needs a single view of what is due for review
- An audit requires proof that only current versions are in circulation
Do not use it for
- Standards and Clause Register, which tracks the standard and clause a document satisfies, not the document itself.
- Vendor and Contractor Register, which holds supplier-facing paperwork, not internally controlled documents.
- Job and Task Register, which holds work activities, not the instructions that govern how they are performed.
- Records Retention Schedule, which governs how long generated evidence is kept, not the documents that produced it.
- Uncontrolled working files, drafts and personal notes — put those in ordinary storage, not the register
Compliance mapping
Which ISO 9001 cl.7.5 requirements does this satisfy?
ISO 9001 cl.7.5 (Documented Information) sets the control requirements this register exists to satisfy: identification, approval, availability and control of change. The clauses below map to the sections actually built into the form.
| Clause | Requirement | Where it lands |
|---|---|---|
| cl.7.5.2 Creating and updating | Appropriate identification and description (title, format, ID) | Identification |
| cl.7.5.2 Creating and updating | Review and approval for suitability and adequacy | Control |
| cl.7.5.3 Control of documented information | Available and suitable for use where and when needed | Identification |
| cl.7.5.3 Control of documented information | Adequately protected, with version and status controlled | Control |
| cl.7.5.3 Control of documented information | Control of changes, retaining a record of prior versions | Content |
| cl.9.3 Management review | Documents reviewed on a defined cycle, not left indefinitely current | Control |
| cl.7.2 Competence | Personnel retrained when a controlling document changes materially | Content |
What it does not cover
- A shared drive folder of procedures, which has no enforced Status field, so nothing stops two conflicting versions from being open at once.
- Version numbers alone, which describe sequence but not whether a document is still authorised for use.
- An email announcing a policy update, which is not itself a controlled record and has no review date attached to it.
- A signed-off procedure with no Next Review Due date, which will not surface itself as overdue and relies on someone remembering.
- A reissued document with Retraining Required left unticked, which leaves the people who must follow it working from the old version in practice.
Global
Document Register requirements by country
ISO 9001 is applied worldwide, but how document control is checked — and how heavily it is weighted — differs by certification scheme and by what a customer's own audit programme expects to see.
ISO 9001:2015 cl.7.5
A management-system requirement, verified at every surveillance and recertification audit.
An overdue Next Review Due date or a Current document that should have been Superseded is written up as a nonconformity, not a comment.
21 CFR Part 820 / DFARS document control clauses
Document control sits inside a broader quality-system regulation with its own inspection regime.
Registers feeding these sectors need traceability to the regulation, not just the ISO clause, in the Related Clause link.
Customer second-party audit protocols referencing ISO 9001
Buyers frequently audit supplier document control directly, using their own checklist against the same clause.
The register needs to survive a walk-through by someone who has never seen your workspace before, not just an internal reviewer.
How to complete it
How to complete a document register, step by step
Filling in the fields is mechanical. The judgement calls are what decide whether the register actually protects people from working off a stale version.
The moment a replacement is approved and issued, not when someone gets around to tidying the register. Treat the flip as part of the same approval action, never a separate housekeeping task.
A date set from the standard's own review cycle or the document's risk level, not a default twelve months applied to everything. High-consequence procedures often need a shorter interval than the certification cycle implies.
A wording clarification does not need it; a changed step, changed responsibility, or changed control does. Ticking it reflexively on every revision trains people to ignore the flag.
Link to the clause the document actually satisfies, sourced from the Standards and Clause Register, not the nearest-sounding clause number typed from memory. This is the link that lets certification readiness be shown without a separate audit.
What auditors find
Most common document register findings
The findings an auditor or internal reviewer raises against this register cluster around a small set of recurring gaps.
| Finding | Clause | What fixes it |
|---|---|---|
| Document shows Current but a newer version is already in circulation | cl.7.5.3 | Flip the superseded entry's Status immediately on approval of the replacement, in the same transaction. |
| Next Review Due date has passed with no action recorded | cl.7.5.2 / cl.9.3 | Run a standing report of overdue entries and assign each to its Document Owner before the next audit window. |
| No Approved By recorded for a document requiring sign-off | cl.7.5.2 | Make Approved By mandatory for policy and procedure document types before the entry can be marked Current. |
| Retraining Required ticked with no evidence a briefing happened | cl.7.2 | Link the training record generated by the briefing back to the document entry, not just the tick. |
| Related Clause left blank on documents that clearly satisfy a specific requirement | cl.7.5.3 | Require the link at the point of document approval, not as a retrospective clean-up exercise. |
| Summary of Change left blank across multiple revisions | cl.7.5.2 | Make the field mandatory whenever Version changes from the previous entry. |
Case in point
Case in point: two versions of the same procedure, both marked current
A site revised its permit-to-work procedure after a near-miss, uploaded the new version, and briefed the day shift. The register entry for the old version was never touched — its Status stayed Current because the person doing the reissue assumed a new entry automatically superseded the old one.
Three months later a night-shift supervisor pulled the procedure from a Pick List that still surfaced both entries, picked the older one by habit, and ran the permit process against a step that had already been corrected. Nothing failed on that shift, but the audit that followed treated it as exactly the nonconformity cl.7.5.3 exists to prevent, because the register — not the intent — is what actually controlled which version was in use.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
3 sections
- Reference
- FDN-008
- Archetype
- Register
- Record ID
- DOC-2026-000
- Scoring
- None
- Direction
- n/a
- Singleton
- Yes
- Basis
- ISO 9001 cl.7.5
- Links
- Referenced by all workspaces
- Tags
- Master data
- Sections
- 3
- Fields
- 19
- Follow up fields
- 0
- Repeating sections
- 0
- Links out
- 2
Identification
6 fieldsDocument ID*
Format DOC-0000.
The record's own ID. Other templates point at this value.
Status*
Only Current documents appear in Pick Lists.
Document Title*
This is what Pick Lists display.
Document Type*
Policy, procedure, work instruction, plan, form or record.
Version*
Language
Control
9 fieldsDocument Owner*
Approved By
Issue Date*
Last Review Date
Next Review Due*
Documents past review date are a standing audit finding.
Applies To Sites
Site ID
Links to FDN-001 Site ID
Related Clause
Clause ID
Links to FDN-009 Clause ID
Content
4 fieldsDocument File*
Summary of Change
What changed in this version, in one or two lines.
Retraining Required*
Tick to trigger a briefing for everyone in the affected roles.
Supersedes Version
FDN-008 · record IDs look like DOC-2026-000 · Referenced by all workspaces
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The register is easy to fill in once. Keeping every entry's Status correct, chasing overdue reviews and tying revisions to actual retraining is the part that erodes without something watching it continuously.
Rolls overdue Next Review Due dates and missing Approved By fields into a single readiness view ahead of certification audits.
Flags document entries referenced by nonconformities or corrective actions so a procedure gap and its fix stay linked.
Turns a ticked Retraining Required into an assigned briefing and closes the loop with a completion record, not just a checkbox.

Watches for entries where Status and circulation disagree, drafts the correction, and holds it for the document controller's approval before anything changes.
This template lives in General — control tower. The orchestration layer. Registries and engines every other workspace reads from.
Meet General→Glossary
Document Register definitions and key terms
- Document control
- The set of practices ensuring only current, approved versions of documents are available and used, and that changes are tracked.
- Controlled document
- A document with a defined owner, version and review cycle whose distribution and currency are actively managed.
- Documented information
- The ISO 9001 term covering both instructional documents (procedures) and the records that result from using them.
- Supersede
- To formally replace a document version with a newer one, retiring the old version from active use.
- Review cycle
- The defined interval at which a document is reassessed for continued suitability, independent of whether it changes.
FAQ
Frequently asked questions about document register
Does every document type need the same review interval?+
No. A safety-critical procedure typically needs a shorter cycle than a low-consequence work instruction. Set Next Review Due from risk, not from a single default applied library-wide.
Who should be able to change a document's Status?+
Ordinarily only the document controller or the Document Owner named on the entry. Widening that access is how registers drift out of control.
Does a form or template count as a controlled document?+
Yes if changing it changes how work is done or recorded — the Document Type list includes Form or template for exactly this reason.
What happens if Retraining Required is ticked but nobody runs the briefing?+
The register shows compliance intent, not compliance fact. Pair the tick with a linked training record so the briefing is evidenced, not assumed.
Can this register replace a document management system?+
It replaces the tracking layer — what is current, who owns it, when it is due — not necessarily the storage and workflow of a dedicated DMS for large document volumes.
Why is Applies To Sites optional rather than required?+
Some documents, such as a corporate policy, apply everywhere by default. Requiring a site link on every entry would force noise into records that are deliberately organisation-wide.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Master Data and Foundations
Site and Location Register
Holds every site, building, area and zone your organisation operates
Asset Register
Holds every piece of equipment, machine, vehicle and tool you track
Worker Profile
Holds a record for each worker, including role, department, site and start date
Job and Task Register
Lists the jobs and tasks people perform, so risk assessments and ergonomic assessments can be tied to real work rather than job titles
Vendor and Contractor Register
Holds every supplier, contractor and service provider you work with, including their status and approval level
Chemical and Substance Register
Lists every chemical and hazardous substance held on site, with quantity, location and hazard class
More in Registries
Site and Location Register
Holds every site, building, area and zone your organisation operates
Asset Register
Holds every piece of equipment, machine, vehicle and tool you track
Worker Profile
Holds a record for each worker, including role, department, site and start date
Job and Task Register
Lists the jobs and tasks people perform, so risk assessments and ergonomic assessments can be tied to real work rather than job titles
Vendor and Contractor Register
Holds every supplier, contractor and service provider you work with, including their status and approval level
Chemical and Substance Register
Lists every chemical and hazardous substance held on site, with quantity, location and hazard class

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 9001:2015 cl.7.5 — Documented information
- ISO 9001:2015 cl.9.3 — Management review
- ISO 9001:2015 cl.7.2 — Competence
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.