Guide to Documented Information Architecture Design — Ensuring Proper Placement of Documents, Records, and Knowledge
Abstract: The number of system documents is increasing, but employees are finding it harder to locate "which version to use." Records are scattered everywhere, and materials are hastily compiled during audits. The root cause is often not "insufficient documentation," but the lack of a clear documented information architecture—how documents, records, external documents, and knowledge assets are layered, numbered, controlled, distributed, and obsolete. This article systematically explains the four-tier structure of documented information, numbering and versioning rules, and key points for controlled distribution and external document management.
1. A Common Dilemma: Many Documents, Chaotic System
A quality department in a manufacturing company maintains over 800 system documents, with folders named by year and department, and version numbers written in various formats such as "V1.0," "Rev.B," and "2024 Edition." Production line employees report: "I followed the old version of the SOP given by my supervisor, but the auditor had the new version—so who is right?"
Reviewing the situation reveals three issues:
- Documents and records are mixed together—original inspection data is archived as "work instructions"
- Lack of a unified numbering system—documents with the same name exist in different directories
- External documents (customer CSR, regulations, supplier specifications) are not included in the controlled list, leading to uncertainty about whether they are the latest versions
This is not an issue of execution but a lack of documented information architecture—the organization has not defined "which information should be in what form, where it should be placed, and how it should be controlled."
2. Documented Information Architecture: Four Levels
ISO 9001's "documented information" (Documented Information) includes documents (Documents) and records (Records). In practice, it is recommended to further divide these into four levels:
| Level | Type | Typical Content | Control Focus |
|---|---|---|---|
| L1 | Manuals/Policies | Quality Manual, Management Policies | Few and stable, approved by senior management |
| L2 | Procedures/Processes | Procedure, Process Descriptions | Cross-departmental interfaces, responsibilities |
| L3 | Work Instructions/Standards | SOP, Inspection Specifications, Drawings | On-site execution, version control |
| L4 | Records/Evidence | Inspection Records, Training Sign-Offs, Audit Reports | Objective, traceable, retention period |
Principles of Architecture Design:
- Stability at the top, flexibility at the bottom—L1/L2 have low change frequencies, while L3/L4 adjust according to process and customer requirements
- One document, one purpose—do not combine procedures, SOPs, and record templates into a single Word document
- Reference rather than duplicate—write general requirements in the upper layers and reference them in the lower layers rather than copy-pasting
3. Numbering Rules: Giving Each Document an "ID"
Unified numbering is the backbone of the documented information architecture. The recommended structure is:
[System Code]-[Type Code]-[Sequence Number]-[Version Number]
Examples:
| Number | Meaning |
|---|---|
| QMS-P-001 | Quality Management Procedure No. 001 |
| QMS-WI-012 Rev.3 | Work Instruction No. 012, Version 3 |
| QMS-F-205 | Form/Record Template No. 205 |
| QMS-EXT-008 | External Document No. 008 |
Type Code Suggestions (can be tailored to the company):
- M — Manual (手册)
- P — Procedure (程序)
- WI — Work Instruction (作业指导书)
- F — Form (表单/记录模板)
- EXT — External (外来文件)
- SPEC — Specification (产品/检验规范)
Version Number Rules:
- Procedures/SOPs: Major version number change = substantial content change; minor version = format/typo corrections
- Records: No version control; use "record number + date + batch" for traceability; version control applies only to record templates
4. Version Control and Controlled Distribution
1. Version Lifecycle
Drafting → Review → Approval → Release → Training/Notification → Implementation → Periodic Review → Revision or Obsolescence
Each stage should have records: who reviewed, who approved, when it became effective, and when the old version was obsoleted.
2. Controlled Distribution List
Core Requirement: Only the latest valid version can be used at controlled points.
It is recommended to maintain a Controlled Document Distribution List with fields including:
- Document number, name, version
- Distribution target (department/position/production line station)
- Distribution method (paper/electronic/system)
- Confirmation of old version回收 (especially important for paper documents)
Electronic Systems (QMS/PLM/SharePoint) should implement:
- Unauthorized users cannot edit released documents
- Automatic watermark or header showing version and effective date
- Obsolete documents are read-only archived and cannot be used as current references
3. Management of "Uncontrolled Copies"
Printed paper documents and exported PDFs should be labeled "Uncontrolled Copy, for Reference Only" or have print permissions restricted. One of the most common nonconformities in audits is the use of unmarked copies of documents on-site.
5. Record Control: Managed Separately from Documents
Records are "evidence of facts that have occurred," and their management logic differs from documents:
| Dimension | Document | Record |
|---|---|---|
| Purpose | Specifies how to do it | Proves it was done |
| Change | Has versions, requires approval | Generally no alterations allowed |
| Retention | Long-term validity | Defined retention period |
| Filling | Not applicable | Clear, traceable, searchable |
Key Points for Record Control:
- Record templates (blank forms) should be included in document control
- Filled records should be categorized and stored according to the Record Retention Policy (paper/electronic)
- Crossing out is allowed, but must be signed and dated, keeping the original content readable
- Electronic records must meet audit trail requirements (who, when, what was changed)—see 12.1.2
6. Management of External Documents
External documents are the most easily overlooked part of the documented information architecture, including:
- Laws, regulations, national standards, industry standards
- Customer drawings, CSR, inspection specifications
- Supplier specifications, Material Safety Data Sheets (MSDS)
- Certification body requirements, audit criteria
Management Steps:
- Identification — Departments report applicable external documents in their respective fields
- Registration — Include in the External Document List, assign an EXT number
- Review — Assess the impact on the company's products/processes
- Conversion — Convert to internal documents (procedures/SOPs) when necessary, rather than directly referencing untranslated customer PDFs
- Update Monitoring — Subscribe to standard updates and customer engineering change notifications to trigger reviews
Common Pitfall: Directly placing customer email attachments into the shared drive without version and applicability confirmation.
7. Relationship Between Documented Information and Knowledge Base
Documented Information (controlled) ≠ Knowledge Base (referable):
- Documented Information: "Regulations" that must be followed—non-compliance is a nonconformity
- Knowledge Base/Lessons Learned: Best practices, cases, training materials—referable but do not replace controlled documents
Architecturally, it is suggested:
- Controlled documents are in the QMS/document control system
- Knowledge base is in the Wiki/knowledge repository/SharePoint non-controlled area
- Practices matured from the knowledge base should enter the controlled process when elevated to SOPs
8. Implementation Checklist
| Check Item | Compliance Standard |
|---|---|
| Document Layering | Clear responsibilities for manuals, procedures, SOPs, and record templates |
| Unique Numbering | No duplicate numbers, unified type codes |
| Current Version | No outdated versions on-site |
| Traceable Distribution | Ability to check who holds which version |
| Record Retention | Defined retention periods, easy to retrieve |
| External Documents | List, review, and update mechanisms in place |
| Obsolescence Management | Old versions cannot be used as execution references |
9. Conclusion
A documented information architecture is not about "writing more documents," but about building a functional directory system for the organization's knowledge—documents specify how to do it, records prove it was done, external documents ensure compliance with inputs, and the knowledge base supports continual improvement.
Designing the architecture upfront provides a foundation for internal audits, audit preparation, and digital document control; otherwise, documents will only pile up, and "finding documents" itself will become a quality cost.
Knowledge Number: 2.3.1
Version: v20260521
Author: Quality Excellence Think Tank