Ask any lead auditor which clause trips up the most companies, and document control comes up almost every time. Not because the requirement is complicated. It isn't. It fails because companies treat it as paperwork instead of infrastructure — something to tidy up before the audit rather than something the quality system actually runs on.
I've sat across the table from companies that had beautiful procedures and a document control system that couldn't tell you which revision was actually on the shop floor. That gap is where nonconformities live. Document control nonconformities under ISO 9001:2015 clause 7.5 consistently rank among the most frequently cited findings in third-party audits, and in my experience they're rarely the result of a missing procedure. They're the result of a procedure nobody follows consistently.
This guide covers what document control actually requires across the ISO family, where it breaks down, and the practices that hold up when an auditor starts pulling threads.
What Document Control Actually Means Under ISO
ISO defines two related but distinct categories: documented information that gives direction (procedures, policies, work instructions, forms) and documented information that provides evidence (records — the completed forms, the signed batch records, the training logs). ISO 9001:2015 folded both into a single term, "documented information," under clause 7.5, but the practical distinction still matters. You control documents by managing revisions. You control records by managing retention and integrity. Confusing the two is one of the most common root causes of a document control finding.
The clause itself asks for five things: documents are identified and described, they're reviewed and approved before use, changes are controlled and re-approved, current versions are available where they're needed, and obsolete versions are removed or clearly marked. That's the whole requirement. Everything else — your numbering scheme, your software, your approval matrix — is just the mechanism you build to satisfy those five points.
ISO 9001 is the most widely implemented management system standard in the world, with more than one million active certificates issued across over 190 countries according to the ISO Survey, which means the document control requirement in clause 7.5 is one of the most frequently assessed clauses on the planet. That scale is also why the requirement stays deliberately generic — it has to work for a five-person medical device startup and a multinational manufacturer using the same clause language.
Why Document Control Fails More Often Than It Should
Three patterns show up again and again in the audits and gap assessments I've run.
The first is version drift. Someone updates a work instruction, emails it around, and the master list never gets touched. Now three versions exist in three places, and nobody can say with confidence which one is authoritative. This is the single most common finding I encounter, and it's almost never malicious — it's just a system with no single source of truth.
The second is approval theater. A document gets an approval signature, but the approver never actually reviewed the technical content — they signed because the workflow required a signature to move forward. Auditors test this by asking approvers substantive questions about what they approved. If the approver can't explain the change, the finding writes itself.
The third is scope creep in what counts as "controlled." Companies either control too little — leaving critical work instructions as tribal knowledge or informal cheat sheets — or they control too much, dragging every internal memo and meeting note into a formal revision process that grinds the organization to a halt. Good document control finds the line and holds it.
A document control system's real test isn't whether it looks organized in a binder review. It's whether the person on the floor is working from the same revision the QA manager thinks is current.
The Core Requirements Across ISO Standards
Document control isn't unique to ISO 9001. Every major management system standard carries some version of the same requirement, though the clause numbers and emphasis shift.
| Standard | Clause | What It Specifically Requires |
|---|---|---|
| ISO 9001:2015 | 7.5.2 / 7.5.3 | Identification, review/approval, control of changes, availability at point of use, control of external documents |
| ISO 13485:2016 | 4.2.4 / 4.2.5 | Same core requirements plus a defined retention period tied to product lifetime and mandatory document/record retention for the device's useful life |
| ISO 14001:2015 | 7.5 | Documented information for environmental aspects, controls, and legal obligations, with the same five-point structure as 9001 |
| ISO 27001:2022 | Clause 7.5 / Annex A 5.37 | Control of documented information plus explicit information security controls over document access and classification |
| ISO 42001:2023 | 7.5 / 6.1.2 | Documented information for the AI management system, tied to risk assessments and impact assessments that must stay traceable to current AI system versions |
The pattern across all five: identify it, approve it, control changes to it, make the current version available, and keep the old version from causing confusion. ISO 13485 adds the sharpest teeth here, because a medical device company has to defend document and record retention for the entire useful life of the device, which can mean decades. ISO 42001 is the newest addition to this family, and I'd argue it's the one companies most often underestimate, because AI system documentation changes faster than a traditional QMS was ever built to track.
Ten Document Control Practices That Hold Up Under Audit
1. Maintain a single master document list, not a folder structure you hope stays organized. The master list — document number, title, current revision, approval date, owner — is the one artifact an auditor will ask for in the first ten minutes. If it doesn't match what's actually deployed, everything downstream is suspect.
2. Assign document owners, not just approvers. An owner is accountable for the document staying current, accurate, and reviewed on a defined cycle. An approver just signs off on a specific change. Companies that only have approvers end up with documents nobody actively maintains between audits.
3. Build a change control process with teeth, not a rubber stamp. Every revision needs a documented reason for the change, an assessment of downstream impact — training needs, form updates, related procedures — and an actual review by someone qualified to evaluate the content, not just the formatting.
4. Control your external documents just as tightly as your internal ones. Supplier specs, regulatory guidance documents, customer drawings — these go obsolete too, and auditors specifically test whether you're working from the current version of documents you didn't even write.
5. Remove obsolete documents from circulation, don't just relabel them. Marking something "obsolete" in a footer while it's still sitting on a shared drive where people can open and use it doesn't satisfy the requirement. Move it, restrict access, or use software that enforces this automatically.
6. Set a periodic review cycle independent of the change control trigger. Some documents never get an urgent reason to change, and that's exactly how they go five years without anyone confirming they're still accurate. A scheduled review — annual is common — catches drift that no single change event would trigger.
7. Match your training records to your revision history. If a work instruction changes materially, the people using it need retraining, and that retraining needs to be documented and dated after the revision date, not before it. Auditors cross-reference these dates specifically to catch this gap.
8. Define retention periods before you need them, not after a record request. Retention should be documented per record type, tied to regulatory requirement where one exists, and actually enforced — both the keeping and the eventual disposal.
9. Separate document access from document editing. Everyone who needs a procedure should be able to read the current version. Very few people should be able to change it. Confusing "available" with "editable" is how uncontrolled versions get created in the first place.
10. Audit your own document control system before your certification body does. A quarterly internal spot-check — pull five documents at random, verify the master list matches the field copy, verify training is current — catches the drift that turns into a formal nonconformity.
Electronic vs. Paper-Based Systems
The honest answer to "should we go electronic" depends on document volume and site count more than company size alone.
| Factor | Paper/Manual System | Electronic Document Control (eDMS/QMS software) |
|---|---|---|
| Best fit | Single site, low document count, simple approval chains | Multi-site operations, regulated industries, high document volume |
| Version control | Manual — relies entirely on discipline | Enforced automatically; old versions locked from active use |
| Approval trail | Physical signatures, easy to lose or backdate | Timestamped e-signatures with full audit trail |
| Obsolete document control | Requires active removal by a person | Automatic upon new revision release |
| Upfront cost | Low | Moderate to significant, plus validation effort |
| Audit findings risk | Higher — version drift is the top failure mode | Lower, but only if the system itself is configured and validated correctly |
I've seen small, well-disciplined companies run a clean paper system for years, and I've seen companies drop six figures on an eDMS and still get a document control finding because they never validated the workflow rules or trained people to use it correctly. The software doesn't replace the discipline. It enforces the discipline you already have to build. If your organization operates across more than one site, or you're in a regulated industry where retention periods run long, electronic control stops being optional in any practical sense.
Common Nonconformities and How to Prevent Them
The findings I see most often break down into a short list, and each one has a specific, preventable cause. Obsolete documents in active use almost always trace back to a removal step that depends on someone remembering to act, rather than a system that enforces it. Missing or informal approval evidence traces back to a change process that never defined who has authority to approve which document type. Training gaps against revision dates trace back to change control that stops at "document released" instead of continuing through "everyone affected is trained." External document control gaps trace back to companies that built rigorous internal processes and simply forgot that a supplier drawing or regulatory standard needs the same discipline.
None of these require a bigger budget to fix. They require closing the loop between the document change and everything downstream of it — training, forms, related procedures, and the master list itself.
Where Document Control Overlaps With Record Control
Document control and record control get treated as the same activity, and that's a mistake worth correcting early. A document tells people what to do — it changes over time, and only the current revision should be in use. A record proves what was actually done — a completed form, a signed inspection report, a calibration certificate — and once created, a record should never change. Applying document-style revision control to a record (letting someone "correct" a signed record after the fact without a documented correction process) is its own category of finding, distinct from document control but often discovered during the same audit.
The distinction matters most in ISO 13485 environments, where device history records have to remain unaltered and traceable for the product's full useful life. Getting document control right and getting record control right are two separate disciplines that happen to share a clause number.
If your organization is preparing for initial certification or a recertification cycle, it's worth running a focused internal audit of your document control system before your certification body does it for you — the gap between what you think your master list says and what's actually deployed is almost always bigger than expected. For companies building out a management system from scratch, this is also a good moment to look at ISO 9001 certification consulting to make sure document control is designed into the QMS architecture from day one, rather than bolted on before an audit.
FAQ
What is the difference between a controlled document and an uncontrolled document?
A controlled document is tracked on a master list, has a defined revision history, and is issued through a formal approval process. An uncontrolled document — a printed copy, a personal reference sheet, a PDF someone saved to their desktop — falls outside that system and creates risk the moment it's used to make a decision or perform work, because there's no guarantee it reflects the current revision.
How long do we have to retain ISO 9001 documents and records?
ISO 9001:2015 doesn't specify a universal retention period — it requires your organization to define its own, based on legal, regulatory, and business need. Sector-specific standards are stricter: ISO 13485 ties retention to the device's useful life, often decades, and many regulatory frameworks layered on top of ISO 9001 add their own minimums.
Does ISO 9001 require a specific document control software?
No. ISO 9001 is deliberately software-agnostic — it specifies outcomes (identification, approval, revision control, availability, obsolescence control), not tools. A disciplined paper or spreadsheet-based system can satisfy the clause. What auditors actually check is whether the outcomes are met consistently, not which platform you used to get there.
What's the most common document control finding in ISO audits?
Obsolete document versions still in active use is the most frequent finding I encounter, typically traced back to a removal step that depended on someone remembering to act rather than a system that enforced it. The second most common is a mismatch between a document's revision date and the training records for people using it.
Do external documents like supplier specs need to be controlled the same way as internal procedures?
Yes. ISO 9001 clause 7.5.3.2 specifically requires control of externally-provided documents that the organization determines are necessary for the quality management system — supplier specifications, regulatory standards, customer drawings. Auditors routinely test this by asking whether the copy on file is the current published version.
Last updated: 2026-08-06
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.