In-Depth Interpretation of ISO9001 Clause (16) | 7.5 Documented Information: A Comprehensive Explanation of Document Requirements and Record Control
1. Key Points of the Clause
ISO 9001:2015, Clause 7.5 "Documented Information" is divided into three sub-clauses. 7.5.1 General Requirements: The organization's quality management system (QMS) should include the documented information required by this standard, as well as the documented information determined by the organization as necessary for the effectiveness of the system. 7.5.2 Creation and Update Requirements: When creating and updating documented information, appropriate identification and description (such as title, date, author, or index number), format and medium (such as language, software version, diagrams), and review and approval (such as suitability and adequacy) should be ensured. 7.5.3 Control Requirements: Ensure that documented information is available and applicable where and when needed, manage its distribution, access, retrieval, and use, store and protect it (including maintaining clarity and readability), implement change control (such as version control), and specify retention and disposal.
Three aspects of the wording are worth emphasizing. First, "the documented information required by this standard" sets the baseline. The documents and records explicitly mentioned in clauses such as 4.3, 4.4, 5.2, 6.2, 7.1.5.2, 7.2, 8.4, 8.6, 8.7, 9.1.3, 9.2, 9.3, and 10.2 must all be included. Second, "determined by the organization as necessary" means that beyond the baseline, the organization decides how much to document and record, but it must be justified and explainable. Third, "available and applicable where and when needed" emphasizes the importance of location, timing, and applicability. If any of these aspects are lacking, the control loses its meaning. Additionally, the 2008 version separated "documents" and "records" into 4.2.3 and 4.2.4, respectively, while the 2015 version consolidates them into "documented information," only implying the record attribute when it is required to "retain... as evidence." This is not just a play on words; it shifts the focus from "what the medium looks like" to "whether the information is effectively controlled."
2. Interpretation of Intent
Why does the standard make this consolidation? There are at least three layers of logic.
First, medium neutrality. Whether it is a paper document, electronic document, image, system data, or a kanban photo, as long as it carries the information needed for the system's operation, it is considered documented information. The consolidation of terms acknowledges that the management logic should be unified around "reliable and usable information" rather than whether it is printed on paper or stored on a server. It also closes the loophole in the old version where electronic forms were called "system data" to avoid document control.
Second, responsibility returns to the organization. In the old version, many companies relied on "the standard requires procedure documents" to decide what to document. The 2015 version returns the discretion to the organization and also the burden of proof. Reducing the number of mandatory documents does not mean lowering the requirements: the organization cannot shirk necessary controls by claiming "the standard does not require it," nor can it create a pile of unused documents by citing "the standard requires it."
Third, the management focus of the two types of documented information is different. One type is directive, pointing to future execution—policies, objectives, procedures, work instructions, drawings, inspection specifications. The key is "correct version, available on-site." The other type is evidentiary, pointing to past events—calibration records, training records, supplier evaluations, release records, nonconforming product handling, internal audit and management review records. The key is "authentic, complete, traceable, and retained for a specified period." Managing both types in the same distribution process often results in neither being strictly controlled nor effectively managed.
3. Implementation Practices
Step 1: Create two lists to transform the two sentences of 7.5.1 into verifiable tables. "Documented information that must be maintained" should list out the documents explicitly required by the standard, annotated with clause numbers, responsible positions, and review cycles. "Documented information that must be retained" should list out the evidence records required by the standard, annotated with retention periods and their bases (standard, regulations, contracts, or customer requirements). Together, these two lists form the document map of the system.
Step 2: Design a hierarchical structure and naming rules. Layer the documents as "quality manual—procedure documents—work files and specifications—record forms—external documents," with each layer having clear creation authority and approval levels. Uniform naming should be "document name + version number + effective date" to avoid names like "inspection specification (final version) (2)" that cannot be sorted. Customer drawings, national standards, and regulations should have a separate layer, with a registration and update tracking system in place.
Step 3: Integrate the three requirements of 7.5.2 into the approval process. Identification and description: the title, number, version, preparer, approver, and effective date must all be present before publication. Format and medium: specify templates, systems, and language versions. Review and approval: differentiate between technical reviews (who verifies the content) and authorized approvals (who is responsible for publication), and leave a trail. All three requirements should be embedded in the process nodes to ensure that creation and updates are not just "publish after modification."
Step 4: Define rules for each of the six control elements of 7.5.3. Availability: define distribution ranges and on-site placement methods. Access permissions: allocate viewing, downloading, and editing permissions for electronic documents based on job roles. Retrieval: standardize numbering and directories to ensure quick location. Storage and protection: specify backup cycles, media requirements, fire and moisture protection, encryption, and anti-tampering measures. Change control: establish version rules, effective and obsolete dates, and procedures for recovering and locking old versions. Retention and disposal: create a retention schedule and records of expired disposal, with disposal requiring approval.
Step 5: Connect the control of documented information to change management and awareness, and reconcile regularly. Document version changes must synchronize three actions:回收旧版 (recover old versions), 宣贯到受影响岗位 (communicate to affected positions), and 确认现场实物与系统版本一致 (verify that on-site documents match the system versions). Additionally, conduct an annual documented information check: reconcile the list with the actual on-site versions, randomly check records for timely completion and genuine signatures, and check external documents for up-to-date tracking. The results should be included in the management review input.
4. Auditor's Perspective
Common Finding 1: Documented information and actual operations are disconnected. The procedures are written one way, but the operations on-site are another, or the processes are running without any documented information to support them, making it impossible to prove control.
Common Finding 2: Missing mandatory records. High-frequency areas for missing records include evaluations and re-evaluations of external suppliers (8.4), conclusions of analysis and evaluation (9.1.3), nature and results of corrective actions (10.2), calibration traceability results (7.1.5.2), and internal audit plans and results (9.2). Auditors typically check each item on the "documented information that must be retained" list, and an incomplete list makes it difficult to prove no omissions.
Common Finding 3: Doubts about the authenticity and timeliness of records. Inspection records filled out all at once for a week, the same pen signing off on all shifts at the same time, dates conflicting with production reports, and modifications without change signatures can often lead to the need to redo all records if caught.
Common Finding 4: Incomplete recovery of obsolete documents. Old versions are still found in on-site cabinets, team toolboxes, and personal computers, and although the system has been discontinued, they remain in shared directories. Paper printouts do not match the current system versions—document control only applies to the system, not the printer.
Common Finding 5: Missing retention and disposal rules. Records are retained indefinitely or destroyed at expiration without approval records; traceable records required by regulations and contracts for long-term retention are treated as ordinary records and cleared out.
Common Misconceptions: One is equating more documented information with a better system, leading to bloated documents that no one reads. Another is assuming that an electronic system automatically means control, with permissions that anyone can change, no approval trails, and no modification records.
5. Self-Inspection Checklist
- Is there a list of "documented information that must be maintained/retained" corresponding to each clause number of the standard, with no missing items?
- Are the documents used at on-site workstations all current and valid versions, and is there evidence of the recovery or locking of obsolete versions?
- Are the access permissions, approval trails, and modification records of electronic documents clearly defined and verifiable during audits?
- Is there a written basis for the retention period of each type of record, and is the disposal at expiration approved and recorded?
- Are customer drawings, standards, regulations, and other external documents included in the controlled list and have a system for receiving and tracking updates?
The system manages the single effective version and credible evidence, not the thickness of paper.
Knowledge code: 2.1.1
Version: v20260914
Author: QTank QTank is dedicated to providing systematic professional knowledge, methodologies, and practical tools for quality management practitioners, helping companies continuously improve their quality capabilities.