ISO9001 System Document Package (3) | Document Control Procedure (7.5.3)

By: QTank Published: 8/12/2026 Views: 97
Current rating: ★★★☆☆ Rate this Equivalent to 8 ratings

The Document Control Procedure is one of the most fundamental and essential secondary procedure documents in the ISO 9001:2015 system, corresponding to clause 7.5.3 "Control of Documented Information." Its position in the system: it follows the "Document Structure" requirements of the Quality Manual and governs the controlled management of tertiary work instructions and quaternary record forms. It serves as the carrier to ensure that "what is written is done, what is done is written, and what is done is recorded." Purpose: to ensure that system documents are available where needed, protected, have a single version, and are controlled for obsolescence, preventing the unintended use of obsolete documents. Applicable organizations: all organizations that have established an ISO 9001:2015 system, especially small and medium-sized manufacturing and service enterprises with chaotic document management, multiple versions coexisting, and inconsistencies between on-site documents and controlled versions. This article provides a template for the procedure text that can be directly replaced and filled in, including document numbering rules, approval authority tables, distribution and recovery processes, and references to all record forms.

1. Purpose

1.1 To implement full-process control over the preparation, approval, distribution, use, modification, review, obsolescence, and recovery of quality management system documents, ensuring that the current effective versions of applicable documents are available at all usage locations.

1.2 To prevent the unintended use of obsolete documents, maintain the integrity and traceability of system documents, and meet the requirements of clause 7.5.3 of the ISO 9001:2015 standard.

1.3 To clarify the responsibilities and work processes for document control, ensuring that document management is "regulated, traceable, with a single version, and controlled distribution."

2. Scope of Application

2.1 Applicable to the control of all system documents within the scope of the company's quality management system (including the Quality Manual, procedure documents, work instructions, record forms, and management systems) and external documents (laws and regulations, standards, customer-provided technical data, etc.).

2.2 Applicable to the management of document preparation, approval, distribution, use, modification, recovery, obsolescence, and archiving activities by all departments and positions related to the operation of the quality management system.

2.3 Not applicable to the records themselves generated during the operation of the system (control of records is executed according to the Record Control Procedure), but blank record forms are included in the control scope of this procedure.

3. Responsibilities

3.1 General Manager: Approves the Quality Manual and major system documents; approves the issuance of system documents; is responsible for the overall effectiveness of the document control system.

3.2 Management Representative (Quality Manager): Reviews the Quality Manual and procedure documents; approves tertiary work instructions and general documents; organizes document reviews and maintains the system document structure.

3.3 Department Heads: Responsible for the preparation, initial review, and modification requests of documents within their department's scope of responsibility; ensures that personnel in their department follow controlled documents; responsible for the daily management of documents in use within their department.

3.4 Document Control Center (Document Administrator, who can be a designated person from the Office/General Department or Quality Department): Responsible for the unified numbering, controlled distribution, registration, recovery, obsolescence, and archiving of system documents; maintains the "Controlled Document List" and "Document Distribution and Recovery Record"; responsible for the collection, registration, and distribution of external documents.

3.5 All Employees: Follow the requirements of controlled documents in their work; promptly report any issues with the documents; do not duplicate, alter, or lend controlled documents without authorization.

4. Work Procedures

4.1 Document Classification and Numbering

4.1.1 The company's system documents are classified into four levels:

  1. Level One: Quality Manual, numbering rule QM-XX (XX is the version number, e.g., QM-A/0).
  2. Level Two: Procedure documents, numbering rule QP-XX, e.g., QP-03 Document Control Procedure.
  3. Level Three: Work instructions/management methods, numbering rule WI-XX or WI-Department-Number.
  4. Level Four: Record forms, numbering rule QR-XX-XX (corresponding procedure document number + sequence number), e.g., QR-03-01 Document Distribution and Recovery Record.

4.1.2 Each document should be labeled with: document name, document number, version number (e.g., A/0, A/1, B/0), control status (controlled/uncontrolled), preparer/reviewer/approver and dates, issuance date, and implementation date. Version number rule: the first issuance is A/0; content modifications are upgraded to A/1; structural or significant changes are upgraded to B/0, and so on.

4.1.3 The document number and version number should be uniformly labeled in the header/footer of the document to prevent version confusion. For electronic documents, the number and version should be labeled in the file name, e.g., "QP-03 Document Control Procedure A/1.docx."

4.2 Document Preparation and Approval

4.2.1 Document preparation: The responsible department should designate personnel with the appropriate capabilities to draft the document. Drafting should be based on relevant clauses of ISO 9001:2015, the system document structure, and actual business processes, ensuring that the document is "consistent with reality, coordinated with upper and lower level documents, and operational and checkable."

4.2.2 Document approval authority follows Table 1; documents that have not been approved shall not be distributed or used.

Table 1 Document Approval Authority

Document Category Preparation Review Approval
Quality Manual Organized by Management Representative Signed by all departments General Manager
Procedure Documents Responsible department Management Representative General Manager
Work Instructions/Management Methods Using department Department head Management Representative
Record Forms Using department Department head Management Representative
External Documents Collected by Document Control Center Reviewed for applicability by relevant departments Management Representative

4.2.3 During approval, the document's sufficiency (whether it covers the requirements), suitability (whether it fits the actual situation), and operability (whether it is easy to execute) should be reviewed. After approval, the Document Control Center registers and numbers the document, and includes it in the "Controlled Document List."

4.3 Document Distribution (Controlled)

4.3.1 Document distribution forms are divided into controlled distribution and uncontrolled distribution:

  1. Controlled distribution: Stamped with a "controlled" seal (electronic documents set to read-only or watermark), distributed to locations and positions essential for system operation, recorded in the "Document Distribution and Recovery Record," and old versions must be recovered or marked as obsolete when the document is modified.
  2. Uncontrolled distribution: For reference, publicity, bidding, etc., stamped with an "uncontrolled" seal, not tracked for modifications, and not used as a basis for work.

4.3.2 Distribution process: The Document Control Center registers the document name, number, version, distribution department/position, quantity, distribution date, and recipient's signature in the "Document Distribution and Recovery Record." When distributing, ensure that the old version is simultaneously recovered or marked as obsolete in the receiving department.

4.3.3 After receiving the document, each department should include it in their "Controlled Document List" and organize learning and dissemination to ensure that relevant personnel are aware of the document requirements.

4.4 Document Use and Storage

4.4.1 Users of controlled documents should keep the documents clear and complete, and must not arbitrarily alter, damage, lose, or lend them. If duplication is necessary, it must be approved by the Document Control Center, and the copies should be stamped with a "controlled" seal and registered.

4.4.2 Electronic documents should have access control set according to permissions to prevent unauthorized modifications, deletions, and dissemination; important electronic documents should be regularly backed up.

4.4.3 Document storage should be "assigned to a person, cabinet, and location" to facilitate retrieval; confidential documents should be managed according to confidentiality regulations.

4.5 Document Modification

4.5.1 Proposal for document modification: Any position that discovers discrepancies between the document and reality, changes in standard requirements, or the need for process optimization can fill out the "Document Modification Request Form" and submit it to the responsible department, explaining the reasons for modification, the content of the modification, and the scope of impact.

4.5.2 Approval of modifications: Follow the corresponding authority in Table 1; modifications involving cross-departmental interfaces should be co-signed by relevant departments; major modifications to the Quality Manual and procedure documents must be reviewed by the Management Representative.

4.5.3 Implementation of modifications: After approval, the Document Control Center uniformly updates the version, recovers the old version, and distributes the new version, recording the changes in the "Document Distribution and Recovery Record." If there are many modifications or significant structural changes, the document should be version-upgraded, and a modification history page should be retained.

4.5.4 After document modification, the consistency of related training, work instructions, and record forms should be reviewed to prevent situations where "the document is modified but the site is not" or "the record form does not match the new document."

4.6 Document Review and Update

4.6.1 The Document Control Center should organize at least one annual review of the applicability of system documents (which can be combined with internal audits and management reviews). The review content includes: the consistency of documents with actual processes, the coordination between documents, and issues and improvement suggestions during use.

4.6.2 Review output: A list of documents requiring modification and the modification schedule; a list of documents to be discontinued; a list of new documents to be added. The review results should be recorded and tracked for implementation.

4.7 Control of External Documents

4.7.1 Scope of external documents: laws and regulations, national/industry standards, customer-provided drawings and technical requirements, regulatory agency documents, etc.

4.7.2 The Document Control Center and relevant departments are responsible for collecting, identifying, and registering external documents, reviewing their applicability, and including them in the "External Document List." They should be distributed to the usage locations as needed and learning organized.

4.7.3 The Document Control Center should regularly (e.g., every six months) verify the effectiveness of external documents (e.g., whether standards have been replaced or regulations revised), promptly update versions, and recover obsolete external documents to prevent the unintended use of invalid versions.

4.8 Disposal of Obsolete Documents

4.8.1 Obsolete documents (including old versions recovered after modification) should be uniformly recovered by the Document Control Center, stamped with an "obsolete" seal, and destroyed or stored separately with a "retained as obsolete" label. Obsolete documents retained for legal or knowledge preservation purposes must be clearly labeled to prevent misuse.

4.8.2 The Document Control Center should note the status (in use/obsolete) and handling method of documents in the "Controlled Document List" to ensure that no unmarked obsolete documents exist on-site.

4.8.3 Electronic obsolete documents should be deleted or moved to an "obsolete area" in the shared directory/system permissions and set to read-only.

4.9 Flowchart (Text Version)

The document control process is as follows:

  1. Document preparation/modification request → 2. Responsible department drafts/fills out the "Document Modification Request Form" → 3. Approval according to authority (major modifications require co-signature) → 4. Document Control Center numbers, registers, and stamps with control status → 5. Controlled distribution and recording in the "Document Distribution and Recovery Record" → 6. Using department learns and disseminates, follows the document → 7. Old versions are simultaneously recovered, marked as obsolete/destroyed → 8. Regular review of document applicability → 9. Update of the "Controlled Document List" and "External Document List."

Key control points: approval authority (Table 1), closed-loop distribution and recovery records, prevention of misuse of obsolete documents, and verification of the effectiveness of external documents.

5. Related Records

5.1 QR-03-01 "Controlled Document List": Records the number, name, version, status (in use/obsolete), and storage department of all controlled documents, maintained and dynamically updated by the Document Control Center.

5.2 QR-03-02 "Document Distribution and Recovery Record": Records the distribution and recovery dates, departments/positions, versions, quantities, and signatures of documents, ensuring that the destination of each controlled document is traceable.

5.3 QR-03-03 "Document Modification Request Form": Records the proposing department, reasons for modification, content of modification, scope of impact, approval opinions, and implementation status.

5.4 QR-03-04 "External Document List": Registers the name, number, source, effective date, applicable department, and effectiveness verification records of external documents.

5.5 QR-03-05 "Document Review Record": Records the time, participants, review conclusions, and follow-up tracking of annual document reviews.

Records are archived and preserved by the Document Control Center according to the Record Control Procedure, with a retention period of no less than 3 years.

6. Related Documents

6.1 Quality Manual (QM-A/0) Chapter 7.5 "Documented Information."

6.2 Record Control Procedure (QP-04).

6.3 Document Preparation and Approval Work Instruction (WI-38, corresponding to document number 38 in the package).

6.4 Record Filling and Archiving Work Instruction (WI-39, corresponding to document number 39 in the package).

6.5 ISO 9001:2015 Standard Clause 7.5.3.

Usage Instructions

1. How to Modify According to Actual Company Conditions

  1. Organizational structure adaptation: Replace the "Document Control Center" with the actual responsible department of the company (e.g., Administration Department, General Office, or a designated person from the Quality Department), and adjust the approval authority table according to the company's authorization system. In small enterprises, the Management Representative can take on both review and approval responsibilities.
  2. Simplify numbering rules: Small enterprises with few documents can use a simple "category-number" numbering system (e.g., CX-01, SC-01), but must ensure that the numbering is unique and the version is clear.
  3. Adapt to the degree of digitalization: Enterprises using OA/document management systems (e.g., DingTalk Documents, PanWei, SharePoint) can replace the "controlled seal" with system permission control, and supplement the procedure with explanations of electronic document approval flows, version tracking, and access permissions to avoid a disconnect between the written procedure and actual electronic processes.
  4. Adapt to product type: Service enterprises can reduce the emphasis on controlling drawing-type external documents and focus more on controlling contracts, regulations, and customer requirements. Manufacturing enterprises should focus on controlling the version consistency of technical drawings and inspection standards.

2. Audit Focus Points (Typically Checked by Certification Auditors)

  1. On-site spot checks: Check in workshops, inspection rooms, and warehouses to ensure that in-use documents are the current effective versions, and that there are no obsolete documents or handwritten alterations.
  2. Closed-loop distribution and recovery: Select a document to check its distribution records, modification records, and recovery records to ensure that "what is distributed is recovered."
  3. External documents: Check whether the list of standards/regulations is up-to-date and whether any outdated standards are still in use on-site.
  4. Electronic documents: Check whether multiple versions coexist in shared directories and whether permission settings are effective.

3. Common Errors

  1. Only distribution, no recovery: After document modification, only the new version is distributed without recovering the old version, leading to mixed use of new and old versions on-site.
  2. Lagging lists: The "Controlled Document List" does not match the actual situation, and the list is not updated when documents are modified.
  3. Misuse of the controlled seal: All documents are stamped with a controlled seal, or controlled documents are not stamped, losing the meaning of control.
  4. Loss of control over external documents: Standards and regulations are kept by individuals, and the Document Control Center is unaware, leading to version uncertainty.
  5. No version tracking: Direct alterations to documents replace the formal modification process, making version tracking impossible.

Document control, single version, and mandatory recovery of obsolete documents.

Knowledge code: 2.3.1

Version: v20260809

Author: Quality Think Tank Quality Think Tank is dedicated to providing systematic professional knowledge, methodologies, and practical tools for quality management practitioners, helping enterprises continuously improve their quality capabilities.