Glossary
Document control
Also called: controlled documents, documented information
Document control is the discipline of ensuring only approved documents are in use, superseded ones cannot be mistaken for current, and every change is authorised and recorded. It is the requirement behind ISO 9001 clause 7.5 and the equivalent clauses in most management system standards.
Document control explained
What the standard asks for
ISO 9001 clause 7.5.3 requires documented information to be available where needed, adequately protected, and controlled for distribution, access, retrieval, version and retention. It also requires something most systems fail: preventing the unintended use of obsolete documents.
That last clause is the test. A shared drive satisfies availability and fails prevention, because nothing stops an operator opening last year's file and working from it.
The four mechanisms
Approval before issue. A document is not in force until an authorised person has approved that specific version, and the approval is recorded against it.
Unambiguous current marking. A reader can tell at a glance which version applies.
Retained supersession. Old versions are labelled and kept, because the question in any investigation is which version was in force at the time.
Controlled distribution. You know who received each issue, which is what makes a recall possible.
Where printed copies break it
On a production floor, a construction site or a laboratory, the copy in use is often paper. Watermarking a download with its status is the practical mechanism — it does not stop someone keeping an old printout, but it makes the printout identify itself. The better answer is reducing the need to print by making the current version easy to reach at the point of work.
FAQ
Document control: common questions
Is document control the same as version control?
Version control is one component of it. Document control adds approval before issue, controlled distribution, periodic review and prevention of obsolete use — the governance around the versions rather than the versions themselves.
What does 'documented information' mean?
The term ISO standards adopted in 2015 to cover both documents and records in one phrase, replacing the earlier distinction. In practice it means anything the standard requires you to maintain or retain.
Related terms
- Audit trailAn audit trail is an append-only record of every action taken on a document — views, downloads, edits, approvals, permission changes and deletions — with the acting user, timestamp and affected version.
- Chain of custodyChain of custody is the documented, unbroken record of who has held, accessed or altered an item of evidence, and when.
- DispositionDisposition is what happens to a record when its retention period expires: destruction, transfer to an archive, or a decision to extend.
- Information governanceInformation governance is the framework of accountability, policies and controls determining how an organisation creates, uses, retains and disposes of its information.
- Legal holdA legal hold suspends the routine destruction of records that may be relevant to litigation, an investigation or an audit.
- Records managementRecords management governs how long a document is kept and what happens at the end of that period.
Zuletzt geprüft: 28. August 2026. Browse the full glossary.