Is the Document on the Workshop Wall a Controlled Document? — A Five-Step Method for Managing and Reconciling Document Copies
A customer came for a process audit and stopped at an assembly station, pointing to a page of paper stuck on the side of a machine and asking the operator, "Is this work instruction a controlled document?" The operator said they didn't know; the workshop supervisor said it was provided by the quality department; the quality department said it was printed by the workshop itself. The auditor took the paper down and took a photo: there was no version number in the footer, no controlled stamp, and one parameter had been altered with a pencil. Four hours later, the same auditor found an even more troublesome item—a drawing sent to a supplier, still the version from two and a half years ago. The last time the version was changed, the company had replaced all the documents in its possession but forgot about the one the supplier still had.
These two incidents may seem unrelated, but they share the same root cause: the company only cares about whether the documents are written and reviewed, not about how many copies are issued, who receives them, what version they are, and whether old versions are recovered. No matter how well the original documents are managed, if the copies are out of control, the old rules will still be followed on the shop floor.
1. The Original Document is Only One, but the Problems Lie in the Copies
ISO 9001:2015, clause 7.5.3.2, lists seven requirements for controlling documented information. Two of these are often glossed over: "Ensure that documented information is available and suitable for use where and when it is needed" and "Ensure that documented information is adequately protected against loss, misuse, and unauthorized access." The key phrase is "suitable for use"—it's not enough to have the document; it must be the current effective version at the workstation where it is most needed.
According to this standard, a company's documented information can be categorized into three different types:
- Original Document: The archived copy or the main file in the system. Each document has only one original, which goes through approval, stamping, and numbering.
- Copy: Each copy replicated from the original for use. There can be many copies, but each should be traceable.
- Record: The completed results, which serve as evidence rather than documents, and are managed through archiving and retention periods.
Most document management incidents occur with the second type. The cost of losing control over copies typically falls into three categories, appearing in the order they are discovered:
First Category: Audit and Trust Costs. Auditors randomly select documents from the shop floor, not from the file cabinets. These include posted documents, workstation cards, and drawings hung on machines. These are the parts of the copies that are managed the least strictly. A single version mismatch is a nonconformity; when customers see a disconnect between the shop floor and the documents, their first reaction is, "This company's system is just for audits."
Second Category: Execution Deviation Costs. Operators follow the old version of the work instructions, with parameters, inspection frequencies, and judgment criteria all lagging behind by one version. The products are "made according to the documents," but the documents are incorrect. Such deviations often only come to light when customer complaints are traced back.
Third Category: Traceability Costs. When a problem arises and you need to trace which version was in use at the time, you find that no one can answer: when was this copy issued, how many were issued, who signed for them, and who recovered them during the version change? Without a record in the ledger, responsibility can only be "shared by everyone."
Many companies focus on making the original documents look good but assume that copies are "no longer my concern once they are issued." However, the essence of control is: one original, each copy is named and traceable, with a clear issuance and recovery process.
2. First, Categorize Copies into Five Types to Target Identification
Different types of copies have different risks of losing control and require different management intensities. Without categorization, questions like "Is the diagram posted by the workshop also a controlled document?" will remain unanswered. It is recommended to categorize copies into five types in the document control procedure and clearly define the identification methods, distribution targets, and responsibilities for updates and recovery:
| Copy Type | Identification Method | Distribution Target | Update and Recovery Responsibility | Typical Risk |
|---|---|---|---|---|
| Controlled Copy | Controlled stamp + copy serial number + version | Fixed workstations, machines, inspection points | Document administrator exchanges old for new, one in and one out | Old version hanging on the workstation for a long time |
| Uncontrolled Copy | Uncontrolled stamp + purpose statement (reference/training/display) | Temporary borrowing, external consultation | Registered for distribution, not mandatory for recovery, must clearly state it cannot be used as an execution reference | Used as an effective execution reference |
| Display Copy | "For display only, no copying" + version + effective date | Workshop boards, posted items, workstation cards | Document administrator prints and stamps uniformly, replaces on the day of the new version's effectiveness | No version, parameters altered by hand |
| External Copy | External distribution stamp + recipient unit number | Suppliers, collaborating factories, customers | Issuing party registers, confirms recovery or written obsolescence after version change | Supply chain still produces according to the old version |
| Electronic Controlled Copy | System permissions + watermark + account binding | Position accounts, terminals | System automatically synchronizes versions | Free dissemination after downloading or screenshotting |
The value of this table lies not in the categorization itself, but in turning two vague questions into determinable ones: which category does this copy belong to? According to the requirements of this category, what should it look like, where should it be placed, and who is responsible for updating it?
3. Five Steps to Manage Copies with "In and Out" Control
Step One: Define Identification Rules, Simple Enough for Long-Term Execution
Identification should cover three elements: status wording (controlled/uncontrolled/external/display), copy serial number (numbered sequentially as 001, 002, etc., for the same original document), and version and effective date. Without any of these, the copy cannot be traced back to the original.
The rules should be designed to be simple: a single stamp plus a handwritten serial number is more sustainable than five different colored labels and seven different stickers. At the same time, the criteria for what counts as a copy should be clearly defined—any duplicate that leaves the system or file cabinet, including printouts, photocopies, photos, screen projections, and entire pages pasted into training PPTs. Without clear criteria, audits will rely on arguments.
Step Two: Create a Copy Ledger, Record by "Distribution Point" Rather Than "Quantity"
The copy ledger and the controlled master list are two separate ledgers and should not be merged. The master list answers "how many types of documents we have and which version is effective"; the copy ledger answers "how many copies of each document have been issued and where they are now, and what their status is." Merging them results in: the list showing "20 copies in the workshop," but never matching during inventory.
Essential fields in the ledger: copy number, corresponding document number and version, receiving unit or workstation machine number, quantity, issue date, signatures of the issuer and receiver, planned recovery date, recovery status, and recovery date. The minimum viable approach is a single table, with one row added for each issuance—don't rush to implement a system until the rules are clear. Moving chaos into a database is not a solution.
Step Three: Bind Recovery to Issuance, Replace Old with New Instead of Post-Event Recovery
Most old version recovery failures occur because recovery is designed as a "post-event action": new versions are issued, and then each person is notified to "return the old version." The correct approach is to bind recovery to the issuance action:
- Issuance is an Agreement. Each controlled copy issued should clearly state, "This copy will become invalid from the effective date of the new version. During version change, old copies will be exchanged for new ones, one in and one out," and this should be reflected in the sign-off form.
- Set a Central Version Change Day (T+0). The day the new version becomes effective is the central version change day. Old versions are recovered on the spot. The number of recovered copies should match the number of issued copies in the ledger, and any discrepancies should be traced on the same day, with no outstanding accounts.
- Leave a Trace for Old Versions. All recovered old versions should be stamped "obsolete," with one copy retained for archiving and traceability (retention period should align with the record retention period). The rest should be destroyed according to regulations and documented.
- Recall Copies When Personnel or Equipment Changes. When personnel leave or change positions, equipment is scrapped, workstations are canceled, or orders are completed, the corresponding copies should be recalled simultaneously and documented in the departure handover and equipment scrapping process.
- Set Metrics. Include the "controlled copy recovery rate" in the document administrator's monthly metrics. The recovery rate should be part of the management review input to ensure there is motivation for recovery.
Step Four: Manage Display Copies Separately, They Are the First Things Auditors See
Posted items, boards, workstation cards, and files on electronic screens are the first "documents" auditors encounter when entering the workshop, and they are also the parts most easily overlooked by the company. Four requirements:
- Unified Outlet. All posted items should be printed and stamped by the document administrator, and the workshop should not print them independently. Any page printed by the workshop is an uncontrolled copy from the moment it is created.
- Version Clearly Indicated. Posted items should have the version and effective date in the bottom right corner, with a font size visible from a normal operating distance.
- Complete Version Change. Maintain a "posting point list" and register all posting points with numbers. On the day the new version becomes effective, replace and sign off at each point. The version change is not for the "workshop," but for each point on the list.
- Prioritize System for Electronic Screens. If electronic boards can be directly retrieved from the system, do not export images. If export is necessary, the file name should include the version, and old files should be deleted simultaneously. Also, prohibit hand-altering parameters on posted items—any temporary adjustments should follow a temporary process change or deviation authorization form.
Step Five: Quarterly Copy Inventory, Reconciliation Asks Only Three Questions
The key to copy management is a reconciliation process that can be consistently executed. Conduct a copy inventory every quarter or before internal audits, and ask three questions:
- Ask the Ledger: How many copies are registered, and at which distribution points?
- Ask the Shop Floor: Randomly select 10 distribution points and check if the physical copy numbers, versions, and effective dates match the ledger and the master list.
- Ask External Recipients: Confirm that all copies issued to suppliers and collaborating factories in the previous year have been recovered or declared obsolete in writing.
The inventory should output three numbers: copy recovery rate, on-site version compliance rate, and external copy recovery confirmation rate. If any of these numbers are not up to standard, first identify the process gaps, not the individuals. Include "copy inventory" in the internal audit checklist to ensure it does not disappear due to the document administrator's workload.
4. An Example: Copy Reconciliation in an Automotive Parts Company
An automotive parts company with approximately 420 employees is a Tier 1 supplier to two vehicle manufacturers. Its original documents are managed very well: all procedure documents are controlled in the system with complete approval flows. However, the copy ledger only registers to the "department + quantity" level, without copy numbers.
During a quarterly self-inspection, 12 workstations were randomly checked, and 5 posted items were found without version information, 2 of which were from two years ago. Among the 68 drawings and specifications issued externally, 11 had been updated twice, but the suppliers still had the old versions. There were no download records for electronic copies.
Four corrective actions were taken: first, define three types of stamps (controlled, uncontrolled, external) plus copy serial numbers, and ensure all duplicates have identification; second, recreate the copy ledger, registering each distribution point, totaling 428 rows; third, implement an old-for-new exchange, designating the last working day of each month as the central version change day, with old versions recovered and matched on the spot; fourth, maintain a posting point list of 63 points, sign off on version changes at each point, and issue 11 obsolescence notices to external recipients, recovering the old versions.
Three months later, the data showed: a controlled copy recovery rate of 99%; an on-site posting item version compliance rate of 100% (30 points checked); and zero old versions externally. During the subsequent customer process audit, the auditor checked 6 posting items, all of which had complete version and effective date information, and no nonconformities were issued. The document administrator's daily workload actually decreased—previously, they had to call each person to recover old versions, but now they rely on a ledger and a fixed monthly version change day.
5. Five Common Misconceptions
Misconception One: Assuming That Documents in the System Are Not Copies. Any electronic version that is downloaded, printed, screenshot, or projected becomes a new copy, with the same risks as a paper version, but harder to detect.
Misconception Two: Assuming "Uncontrolled" Means Anything Goes. Uncontrolled copies still need to be registered, with their purpose clearly stated, and a declaration that they cannot be used as an execution reference. Without this declaration, reference documents can be mistaken for work instructions.
Misconception Three: Recording Copies by Quantity, Not by Distribution Point. Recording "20 copies in the workshop" will never balance the ledger and makes it impossible to recover old versions point by point. Recording to the workstation, machine, or inspection point is necessary to balance the ledger.
Misconception Four: Issuing New Versions Without Recovering Old Ones. This is the most frequent mistake. It results in a double effort: one for issuing and one for recovery, often missing the most easily overlooked posted items and copies in the hands of departed personnel.
Misconception Five: Allowing Workshops to Print Their Own Display Copies. Display copies are the most easily overlooked and the first to catch the auditor's eye. Controlling the "unified outlet" ensures that the majority of on-site version issues are managed.
The quality of copy management is not judged by how neat the file cabinets are, but by whether these two questions can be answered on the spot: where did this copy come from, and who has it? On the day of the version change, were all old versions recovered without exception? Managing the original document relies on systems, but managing copies depends on the ledger, version change day, and inventory—three very basic but essential practices.
Every copy issued must be traceable.
Knowledge code: 2.3.1
Version: v20261001
Author: QTank QTank is dedicated to providing systematic professional knowledge, methodologies, and practical tools to quality management practitioners, helping companies continuously improve their quality capabilities.