ISO9001 System Document Package (4) | Record Control Procedure (7.5.3)
Document Description: This procedure is the implementation document for clause 7.5.3 "Control of documented information" of ISO 9001:2015 at the record level. It is a second-level document of the quality management system (QMS) and is complementary to the "Document Control Procedure" — the latter manages "current effective versions," while this procedure manages "evidence of results already formed." Records serve as "legal evidence" for the operation of the system: internal audits, external audits, customer factory inspections, product traceability, and the closure of nonconforming product handling all depend on records to provide evidence. This procedure is applicable to all manufacturing, service, and trading enterprises, especially small and medium-sized enterprises that need to obtain ISO 9001 certification or are frequently subject to customer audits. Enterprises can directly apply the clauses of this procedure, only needing to adjust the department names and record numbering rules according to their organizational structure before publishing and implementing it.
1. Purpose
To implement full-process control over the design, filling, collection, archiving, storage, retrieval, preservation, and disposal of various records generated during the operation of the quality management system, ensuring that records are authentic, accurate, complete, clear, and traceable. This provides objective evidence for product conformity, process effectiveness, and system continuous improvement, meeting the requirements of clause 7.5.3 of ISO 9001:2015 and the needs of customers and laws and regulations.
2. Scope of Application
This procedure applies to the identification, storage, protection, retrieval, retention period, and disposal control of all quality records in the operation of the company's quality management system, including:
- System operation records: management review, internal audit, corrective action, training, target assessment, etc.;
- Product realization records: contract review, design and development, procurement, production, inspection, identification, protection, release, etc.;
- Resource management records: personnel capability, equipment and facilities, monitoring and measurement resources, knowledge management, etc.;
- External records: customer property lists, supplier inspection reports, etc., related to the system.
This procedure does not apply to the control of document versions (including external documents), which should be managed according to the "Document Control Procedure."
3. Responsibilities
3.1 Management Representative
- Approve the "Record List" and record destruction applications;
- Supervise the execution of this procedure and organize inspections and evaluations of record management work.
3.2 Administrative Department (Document Control Center) — Record Management Department
- Responsible for the unified numbering, registration, and filing of record forms throughout the company;
- Responsible for the archiving, cataloging, storage, and destruction of records transferred from various departments;
- Responsible for establishing and maintaining the "Record List" and organizing an annual record management inspection.
3.3 Department Heads
- Responsible for the design, review, and daily management of record forms in their respective departments;
- Ensure that department personnel fill out records in a timely, authentic, and complete manner as required;
- Responsible for the classification and sorting of records in their departments and transferring them for archiving on schedule.
3.4 All Employees
- Fill out various records truthfully, promptly, and in accordance with work instructions;
- Properly store records to prevent loss, damage, or alteration;
- Follow the procedures for borrowing records and do not lend, copy, or destroy them without authorization.
4. Work Procedures
4.1 Design and Approval of Record Forms
- Each department proposes record form requirements based on the needs of system operation and business activities, fills out the "Record Form Design Approval Form," and attaches a sample form;
- The form design should include the following essential elements: record name, record number, filling date, filling person/signature section, review section (if required), header/footer identification;
- Record forms are reviewed by the department head and approved by the management representative or their authorized person before taking effect;
- Approved record form samples are submitted to the Document Control Center for unified numbering and filing, and are included in the "Record List";
- If modifications are needed, follow the "Document Control Procedure." After the revision, all old blank forms should be recalled and invalidated to prevent misuse.
4.2 Filling of Records
- Records should be filled out timely, in synchronization with the activities, and not be backfilled or pre-filled;
- Records should be authentic, reflecting objective facts without fabrication, concealment, or alteration;
- Records should be complete, with each item filled out. If there is no content, mark it with a "/" or note "none," and do not leave it blank;
- Records should be clear, with neat handwriting and filled out using blue-black or black ink pens. Pencils or erasable pens are not allowed;
- Records should be standardized, using legal units of measurement, and terms and symbols should comply with regulations;
- Correction Requirements: If a record needs to be corrected, draw a line through the error (keeping the original writing legible), write the correct content next to it, and sign the name and date of the person making the correction. Do not use correction fluid, knives, or covering stickers to modify;
- Electronic records (such as inspection data systems, OA processes) should have input permissions and modification traceability functions, with important data regularly backed up.
4.3 Collection and Organization of Records
- Each department should designate a specific person (who can also have other responsibilities) to collect, organize, and store records;
- Daily-generated records should be sorted by date, batch, or product model, and bound into volumes (or stored in electronic folders);
- Records that need to be transferred for archiving should be organized monthly (or according to the specified cycle) and the "Record Archiving Registration Form" should be filled out before transferring to the Document Control Center;
- Both parties should verify the record name, quantity, and completeness, and sign to confirm. The Document Control Center will then register and store the records.
4.4 Identification and Numbering of Records
- Record form numbering rule: QR-Department Code-Sequence Number, for example:
- QR-XZ-01 (Administrative Department record), QR-ZJ-01 (Quality Inspection Department record), QR-SC-01 (Production Department record);
- Department codes are uniformly compiled by the Document Control Center and published in the "Record List";
- Archived records are cataloged by "year-category-sequence number," such as NJ-2026-01 for internal audit records in 2026;
- Each archived record should be labeled with the record name, number, archiving date, and retention period, ensuring "one label per volume, one label per box."
4.5 Archiving of Records
- Archiving scope: All records that can prove product conformity, process effectiveness, and system operation status are within the archiving scope, as specified in the "Record List";
- Archiving time: Daily records should be archived by the 10th of the following month; project records (such as internal audits, management reviews, design and development) should be archived within 10 working days after the activity ends;
- Archiving requirements: Archiving records should be complete, neatly bound, scientifically classified, and clearly cataloged for easy retrieval;
- Archiving of electronic records: Export to a non-modifiable format (such as PDF), burn to a disk or store in a dedicated server directory, and maintain dual backups.
4.6 Storage and Custody of Records
- Paper records should be stored in dedicated file cabinets or archives, ensuring fireproof, theft-proof, moisture-proof, pest-proof, dust-proof, and light-proof;
- The archive room should be well-ventilated and dry, equipped with fire extinguishers, and the storage environment should have suitable temperature and humidity, with regular inspections;
- Electronic records should be stored on dedicated computers or servers, with access permissions set and regular (weekly or monthly) backups. Backup media should be stored in a different location;
- Record custody follows the principle of "who archives, who is responsible." The Document Control Center should inspect the custody of records throughout the company at least once a year and fill out the "Record Management Inspection Record";
- Confidential records (such as customer technical data, quotation information) should be stored separately and have restricted borrowing permissions.
4.7 Retrieval and Borrowing of Records
- The Document Control Center should establish a "Record List" and an archiving ledger to enable quick retrieval by "record name, number, date, department";
- Internal borrowing: Fill out the "Record Borrowing Registration Form" and obtain approval from the department head before borrowing. The borrowing period generally does not exceed 7 working days, and the records should be returned and the account cleared upon expiration;
- Copying: Confidential records should not be copied in principle. For ordinary records, the purpose of copying should be registered, and copies should be marked with "copy";
- External review (by customers, certification bodies, regulatory authorities): Approval from the management representative is required, and the review should take place in a designated location. Originals should not be taken away;
- If borrowed records are damaged or lost, the borrower should provide a written explanation, and the records should be handled according to the "Nonconforming and Corrective Action Procedure."
4.8 Retention Period of Records
The retention period of records is determined based on laws and regulations, customer requirements, and the purpose of the records. The general provisions are as follows (adjustments can be made based on the company's actual situation and clearly stated in the "Record List"):
| Record Category | Typical Record | Retention Period |
|---|---|---|
| System Operation | Management review, internal audit, corrective action records | 3-5 years |
| Product Realization | Contract review, procurement, production process records | 3-5 years |
| Inspection | Incoming/process/final inspection records | Product life cycle + 1 year |
| Measurement Equipment | Calibration certificates, inspection records | Equipment service life + 2 years |
| Personnel | Training, capability evaluation records | During employment |
| Regulatory Mandatory | Special equipment, safety and hygiene records | As required by regulations (e.g., 10 years) |
| Customer Special Requirements | As agreed in contracts/protocols | Follow the agreement |
- After the retention period, the Document Control Center should list the records and fill out the "Record Destruction Application Approval Form" for approval by the management representative;
- If laws and regulations or customer contracts have specific retention requirements, these must be followed, and records should not be destroyed prematurely.
4.9 Disposal of Records
- Records that have exceeded their retention period and have no further value should be destroyed after approval;
- Disposal methods: Shredding by a paper shredder, incineration (in compliance with environmental requirements), or destruction by a qualified institution;
- At least two people should supervise the destruction, and sign the "Record Destruction Application Approval Form" after the destruction is completed;
- Records that may be needed for litigation, disputes, or customer complaint handling should be retained even if they have reached their retention period, and disposed of after the matter is resolved;
- The Document Control Center should deregister the destroyed records in the "Record List."
4.10 Special Control of Electronic Records
- Electronic record systems (such as ERP, LIMS, OA) should set user permissions to prevent unauthorized modifications or deletions;
- Key electronic records (inspection data, measurement data) should have modification traceability, retaining logs of the modifier, time, and content of the modification;
- Electronic records should be regularly backed up, with at least two copies of the backup media (such as external hard drives, CDs, cloud storage) and the readability of backups verified monthly;
- During system upgrades or replacements, data migration and verification should be completed in advance to ensure the continuity and traceability of records.
4.11 Record Control Flowchart (Text Version)
Start → Design/Approval of Record Forms (4.1) → Filling according to standards (4.2) → Department collection and organization (4.3) → Identification and numbering (4.4) → Transfer for archiving (4.5) → Storage and custody (4.6) → Retrieval and borrowing (4.7) → Retention period management (4.8) → Expiration assessment → Approval for destruction (4.9) → End; Any abnormalities (loss, damage, forgery) in each step should be handled according to sections 4.7, 4.8, and the "Nonconforming and Corrective Action Procedure."
4.12 Referenced Forms
The forms involved in the operation of this procedure are listed in "5. Related Records." All form samples are uniformly filed by the Document Control Center, and departments can collect or print them as needed.
5. Related Records
| No. | Record Name | Number | Retention Period | Custody Department |
|---|---|---|---|---|
| 1 | Record List | QR-WK-01 | Long-term | Document Control Center |
| 2 | Record Form Design Approval Form | QR-WK-02 | 3 years | Document Control Center |
| 3 | Record Archiving Registration Form | QR-WK-03 | 3 years | Document Control Center |
| 4 | Record Borrowing Registration Form | QR-WK-04 | 3 years | Document Control Center |
| 5 | Record Destruction Application Approval Form | QR-WK-05 | 5 years | Document Control Center |
| 6 | Record Management Inspection Record | QR-WK-06 | 3 years | Document Control Center |
6. Related Documents
- ISO 9001:2015 "Quality Management System Requirements" clause 7.5.3;
- "Document Control Procedure" (Part 3 of the package);
- "Nonconforming and Corrective Action Procedure" (Part 27 of the package);
- "Record Filling and Archiving Work Instruction" (Part 39 of the package);
- Company "Archives Management System."
Usage Instructions
1. How to Modify According to the Company's Actual Situation
- Department and Number Adaptation: The "Administrative Department (Document Control Center)" in this document is a general setting. Small enterprises can designate a "General Office" or have the Quality Department take on the role of record management. The department codes in the record numbering rule QR-Department Code-Sequence Number should be recompiled according to the actual departments of the company and published in the "Record List" for effectiveness;
- Adjustment of Retention Periods: The retention period table in section 4.8 is a common practice in the industry. Each item should be verified based on the product life cycle, customer contracts, and regulatory requirements (such as in the medical device, food, and special equipment industries) to avoid a one-size-fits-all approach;
- Adaptation to the Degree of Digitalization: Enterprises that have implemented ERP/OA can rewrite sections 4.2, 4.6, and 4.10 to describe system operations, clearly defining the system administrator, approval flow, and backup strategy. Purely paper-based enterprises can delete section 4.10 or simplify it to "Requirements for Electronic Document Backups";
- Reduction of Form Quantity: Small enterprises can merge the six forms into two, the "Record Ledger" and the "Record Destruction Approval Form," as long as they cover the four key steps of "identification, archiving, borrowing, and destruction."
2. Audit Focus Points (Commonly Checked by External Auditors)
- On-site spot checks to verify if records are filled out timely and authentically, and if there are any instances of correction fluid, pencil writing, or proxy signatures;
- Check if the "Record List" matches the actual records, and if there are any cases of "records without a list" or "lists without records";
- Check if the retention period regulations cover regulatory and customer requirements, and if there are any approved destruction records;
- Check if borrowing and copying are registered, and if confidential records are controlled;
- Check if electronic record permissions and backups are implemented, and if historical data can be retrieved on-site.
3. Common Errors
- Confusion Between Records and Documents: Managing procedure documents and work instructions as records, or distributing blank forms as controlled documents without recalling old versions, leading to the mixed use of new and old forms on-site;
- Pre-filling and Proxy-filling: Concentrating on pre-filling records before audits, resulting in similar handwriting and conflicting dates, which can be identified as serious nonconformities;
- Improper Corrections: Using correction fluid to cover errors, making it impossible to verify the original information, which violates the traceability principle;
- Uniform Retention Period: All records are retained for 3 years, leading to the premature destruction of legally required records or the long-term occupation of storage space by ordinary records;
- Destruction Without Approval: Expired records are discarded at will, leading to leaks and the inability to provide evidence of disposal;
- Loss of Control Over Electronic Records: Lack of permission management, no backups, and data loss after system upgrades, which are the most common nonconformities in information-based enterprises.
Records Fully Controlled, Traceability Ensured
Knowledge code: 2.3.1
Version: v20260809
Author: Quality Think Tank Quality Think Tank is dedicated to providing systematic professional knowledge, methodologies, and practical tools for quality management practitioners, helping enterprises continuously improve their quality capabilities.