Are Files That Haven't Been Touched for Five Years Still "Currently Valid"? —— A Five-Step Method for Regular Review and Obsolescence Management of Documented Information

By: QTank Published: 10/5/2026 Views: 17
Current rating: ★★★☆☆ Rate this Equivalent to 8 ratings

In the final stage of a customer process audit, the auditor walked to the oldest machine at the back of the workshop, reached out, and took down the "Operating Procedures" hanging on the machine. The cover had turned yellow, and the version number was from 2019. He flipped through a couple of pages and looked up to ask the workshop director who was accompanying him, "Is this document still valid?" The director was taken aback and replied, "It should be valid, it has always been here." The auditor didn't press further but wrote a line in his notebook. Three days later, the nonconformity report came in: there were uncontrolled expired documents on-site, and it could not be proven that the documents had been reviewed for validity before use.

This document was indeed "truly" valid—there was no record of its obsolescence in the database, and it was still listed as "currently valid" on the controlled document list. However, since its release in 2019, no one had ever opened it again. The person who wrote it had left the company, and the machine had undergone two rounds of renovation. Three parameters in the operating procedures no longer matched the current setup. The document had neither been revised nor declared obsolete; it simply hung there quietly, becoming a "zombie document" in the system.

This is the real shortcoming in documented information management for the vast majority of companies: there are processes for release and revision, but no mechanisms for "review" and "obsolescence." Documents only enter but never leave, only increase but never decrease. Over time, the quantity piles up, but the validity drops.

1. Why Do Files Become "Zombified": Three Structural Gaps

First, let's understand the problem. Document obsolescence is not due to someone's carelessness but to three missing elements in the structure.

First, the lack of a "time trigger." In most companies' document control procedures, only two actions are defined: release and revision. This means that documents are only reviewed when "someone thinks of revising them." In reality, what often makes a document obsolete is not someone's oversight but time itself—equipment aging, personnel turnover, process optimization, and upgraded customer requirements. These changes do not actively seek out the document, so the document remains in place.

Second, the lack of a "content owner." Document administrators are typically responsible for numbering, distribution, recovery, and archiving, managing the "flow" rather than the "content." The ones who can truly judge whether "these process parameters are still correct" are professionals like process engineers and quality engineers. However, in many companies, the task of reviewing is not included in the job descriptions or performance evaluations of these positions, so no one does it proactively.

Third, the lack of an "obsolescence path." Compared to reviewing, obsolescence is even more challenging. Many quality managers think: if I declare a document obsolete, what if the auditor asks for evidence? So, they prefer not to declare it obsolete and let the old version hang alongside the "obsolete" status. As a result, obsolete documents lack identification, recovery, and archiving, and multiple versions exist simultaneously in the workshop and production system, leaving no one knowing which one to follow.

The standard has already clearly stated this requirement. ISO 9001's 7.5.3 Control of Documented Information, besides ensuring that documents are "available and suitable for use," specifically states: to prevent the use of obsolete and obsolescent documented information—note, it is "to prevent misuse," not simply to delete the document. Obsolescence and deletion are two different things. For the automotive industry, the requirement is even stricter: IATF 16949 explicitly requires that upon receiving a customer engineering standard change notification, a review must be completed within a certain period (usually 10 working days) to confirm whether the changed document affects work-in-progress, inventory, and delivered products. The logic behind this requirement is that "the validity of documents must be actively confirmed, not assumed."

Closing these three gaps transforms the fundamental issue of documents into a manageable rhythm issue: every document must have a clear "next review date" and a clear "what to do when it expires."

2. How to Determine the Review Cycle: Grade by Failure Risk, Not a One-Size-Fits-All Approach

Many companies, when thinking about reviews, immediately react with "review all documents once a year." This approach has two inefficiencies: low-risk documents waste a lot of time, and high-risk documents may not be reviewed frequently enough. A reasonable approach is to grade—determine the cycle based on the potential consequences if the document fails.

First, distinguish the three driving sources:

Driving Type Trigger Condition Typical Application Responsible Position Output
Time-Driven Reaching the preset review date All controlled documents Document owner Review conclusion
Event-Driven Changes, anomalies, audit findings, updates in regulations/customer requirements Affected documents and their referenced documents Initiating department Linked revisions
Performance-Driven Increase in related nonconformities, deviations in on-site execution Documents deemed "not read" Quality/Process Review or merge

The review cycle for time-driven documents is recommended to be tiered and risk-graded:

  • Quality Manual, policy and objective documents: every 2-3 years, or confirmed synchronously with management review;
  • Procedure documents (cross-department processes): every 1-2 years;
  • Work instructions, inspection standards, operating procedures: every year; for those involving safety characteristics or key characteristics, shorten to every six months;
  • Record form templates: reviewed synchronously with the corresponding process documents, no separate cycle;
  • External documents (customer drawings, regulations, standards): routinely every year, but immediately triggered if the upstream updates, without waiting for the cycle.

For event-driven and performance-driven reviews, they should be integrated into the company's existing rhythms—reviewing the documents of the audited process during internal audits, confirming whether related work instructions need to be revised when closing 8D cases, and listing a "reference impact list" during change reviews. This way, reviews are not an additional task but are embedded into meetings and processes that are already in place.

3. Five-Step Method: Making Reviews Executable and Traceable

Step One: Create a "Document Health Ledger"

Don't settle for a controlled document list. The list only answers "which documents are there," while the ledger answers "what is the current status of these documents." The ledger should at least include the following fields: document number, name, current version, effective date, last review date, next review date, content owner, using department, associated processes and standard clauses, format (paper/electronic), confidentiality level, and current status (valid/pending review/obsolete).

After the ledger is created, use the "next review date" to generate a reminder list, aggregated monthly. After completing this step, you will find that "when documents expire" becomes a certain matter for the first time.

Step Two: Attach a "Review Card" to Each Document

The core of the review card is not to increase the amount of records but to前置 the judgment criteria. It is recommended to have three mandatory items: whether the document is consistent with the on-site reality; whether the upstream and downstream documents it references are still valid; and whether the applicable regulations or customer special requirements have changed. Print these three questions on the review form, and whoever reviews the document checks the boxes and signs the date, which is the review date.

Step Three: Review with "Three Checks and One Question"

Checking boxes on paper is not enough; you must really go to the site.

Check Consistency: Compare the document with the on-site reality, records, and upstream and downstream documents. Focus on parameter values, responsibility divisions, and reference numbers. A common issue is that one procedure document has been revised, but the three work instructions that reference it still have the old reference numbers—documents have "broken the chain."

Check Applicability: Is this document still relevant? Is anyone actually following it? If a "Manual Soldering Work Instruction" corresponds to a process that has been fully automated, the correct action is likely to "declare it obsolete" rather than "review it and keep hanging."

Check Compliance: Compare with the latest standard clauses, customer special requirements, and industry regulations. Has the special requirement added by the customer last year been incorporated into the document?

Ask the Users: Directly ask the operators and inspectors—can you understand this document? Which steps do you not follow in practice? Why? The places where steps are "skipped" on-site are often where the document needs to be revised.

After completing these four actions, the conclusion must be one of four options, and "temporarily put aside" is not allowed: continue valid / revise / merge / declare obsolete.

Step Four: Obsolescence and Failure Control, Focus on "Preventing Misuse" Rather Than "Deleting Completely"

The easiest thing to get wrong about declaring a document obsolete is the process. The correct obsolescence loop has five actions:

  1. Approval: Initiated by the original document writing department, confirmed by the quality department, specifying the reason for obsolescence and the effective date;
  2. Identification: Stamp the obsolete document with an "obsolete" mark, noting the obsolescence date, and physically isolate it from controlled documents;
  3. Recovery and Reconciliation: Recover each document according to the distribution record, check each item, and do not leave any "approximately collected";
  4. Electronic Channel Cleanup: Set the versions in shared drives and systems to obsolete and remove them from the active directory; withdraw all paper versions from the on-site areas;
  5. Archiving: Retain a sample of each obsolete document. Archiving is not for continued use but for future product history tracing to determine "which version of the document was used for that batch of products."

A common misconception to highlight: obsolescence does not equal deletion. Thoroughly deleting a document from the system and shared drives may seem "clean," but it actually destroys the traceability of the product. Several years later, if a customer inquires about the production basis for a certain batch of products, you won't be able to produce the document from that time.

Step Five: Use Four Indicators for a Closed-Loop Dashboard

Reviewing is not just about completing the review; it must also reflect the overall health status. It is recommended to focus on four numbers:

  • Review completion rate (the proportion of documents that should have been reviewed in this period and have been completed);
  • Number of overdue documents (including the distribution of overdue days);
  • Obsolete document recovery rate (number recovered / number to be recovered);
  • Number of deviations or nonconformities directly caused by document obsolescence.

The first two indicators reflect whether the rhythm is running, and the last two reflect whether the risks have been truly mitigated. Incorporate these four numbers into the input for management review, and reviewing will transform from a "document administrator's task" into a "management concern."

4. Five Common Pitfalls to Avoid

Pitfall One: Reviewing Equals Revising. The review conclusion can be "continue valid," but it must be traceable. The method of traceability can be light—signing the review form once or confirming in the system once. The key is that "this confirmation has occurred" and is verifiable.

Pitfall Two: Leaving Reviewing to the Document Administrator Alone. Document administrators can confirm versions, distribution, and recovery, but the judgment of "whether the parameters are still correct" must be made by the content owner. The correct division of labor is: the document administrator manages the rhythm and ledger, and the content owner manages the content judgment.

Pitfall Three: One-Size-Fits-All Cycle. Reviewing all documents annually means high-risk documents are not reviewed frequently enough, and low-risk documents waste time; reviewing all documents every three years means process documents are already obsolete. Grading is the prerequisite for efficiency.

Pitfall Four: "It's Okay to Reference Obsolete Documents." This is the easiest to compromise on-site. Hanging an obsolete old parameter table next to a machine "for reference" can lead to batch nonconformities if new employees follow it. Either completely remove it from the on-site area or stamp it with a prominent non-controlled mark and clearly state "not to be used as a work reference."

Pitfall Five: Reviewing Only This Document, Not the Referencing Relationships. Declaring a document obsolete or revising it often affects a batch of documents that reference it. When reviewing, it is essential to simultaneously confirm the referencing documents; otherwise, a document reviewed today may "resurrect" in another document tomorrow.

An automotive parts company conducted a comprehensive document health inventory: a total of 380 controlled documents were reviewed, with 222 deemed "continue valid," 73 revised, 24 merged, and 61 declared obsolete. At the same time, 9 obsolete documents still in circulation were identified on-site, two of which did not match the current process parameters. After the inventory, the total number of documents decreased by about 18%, but the more important change was that each document now had a next review date, and the question of "which document to follow" had a unique answer for the first time. Six months later, the number of customer nonconformities related to document control dropped from 3 to 0.

5. One Sentence Summary

The maturity of document management is not reflected in how many documents you have, but in whether each document has someone regularly signing off on its "validity."


Document validity is not a default state but one that is regularly confirmed.

Knowledge code: 2.3.1

Version: v20261005

Author: QTank QTank is dedicated to providing systematic professional knowledge, methodologies, and practical tools for quality management practitioners, helping companies continuously improve their quality capabilities.