Skip to main content
DocumentMS

Manufacturing

Manufacturing document management and change control

Manufacturing document management centres on controlled work instructions and engineering change. The line must only ever hold the current revision, each change needs a recorded approval chain, and IATF 16949 or ISO 9001 audits sample whether the issued document matches what operators actually used.

Why documents are difficult in manufacturing

Manufacturing document management turns on a single question that an auditor will ask in some form on every visit: was the document the operator used the current approved one? Everything else — change control, training records, supplier documentation — exists to make the answer to that question reliably yes. A repository that stores documents well but cannot evidence which revision was in use on a given shift has not solved the problem.

The second characteristic is that documents live at the point of work, not at a desk. A work instruction is consulted at a machine, often on a shared terminal or a printout, sometimes with gloves on. That physical reality is why controlled printing and watermarking matter more here than in an office setting, and why a system that assumes everyone has their own screen will be circumvented.

Regulatory pressure

Three pressures that shape the configuration

Two are certification requirements and one is customer-imposed, which in automotive and aerospace is often the stricter of the two.
  1. ISO 9001:2015 control of documented information (clause 7.5)

    What it requires. Documented information must be available where and when needed, adequately protected, and controlled for distribution, access, retrieval, version and retention — including preventing the unintended use of obsolete documents.

    What it means for a document system. "Preventing unintended use of obsolete documented information" is the clause that a shared drive cannot satisfy, because nothing stops an operator opening last year’s file. Marking the current revision, labelling superseded ones and watermarking printed copies is the direct answer to it.

  2. IATF 16949 record retention (automotive)

    What it requires. Production part approval, tooling records, purchase orders and amendments retained for the length of time the part is active for production and service, plus one calendar year — unless the customer or a regulator specifies otherwise.

    What it means for a document system. Retention is expressed relative to the end of production and service, which is a date not known when the document is created. That requires a retention trigger that can be set later, and a review step rather than an automatic timer.

  3. Engineering change control and customer-specific requirements

    What it requires. Changes affecting product, process or tooling must be assessed, approved and communicated before implementation, with customer approval where the contract requires it.

    What it means for a document system. A change is a workflow with a mandatory reason and an approval chain that can include an external party. The evidence that matters is not that the change was approved but that it was approved before implementation, which needs dated approval against a specific revision.

Capability mapping

Five capabilities mapped to manufacturing requirements

What each module does in a production configuration.
  • Obsolete document prevention

    The current revision is marked unambiguously, superseded revisions are labelled and cannot be presented as current, and downloads and prints carry a watermark showing status. This is the direct implementation of ISO 9001 clause 7.5.3.

  • Engineering change as a controlled workflow

    A change control captures the reason and impact assessment as mandatory fields, routes for technical and quality approval, and can include a customer approval step. Approval is dated against the specific revision, so "approved before implementation" is evidenced rather than assumed.

  • Training and competency tied to revisions

    When a work instruction changes materially, the operators who use it need retraining, and an attestation against the previous revision proves nothing about the new one. Acknowledgement is recorded per named user against a specific version and reissued on supersession.

  • Retention triggered by end of production

    Retention rules can be triggered by an event set later — the end of production and service — rather than by creation date. Disposition raises a review, which is what IATF retention needs because the trigger date is a business decision, not a calendar fact.

  • Supplier documentation with expiry tracking

    Material certificates, supplier approvals and calibration certificates expire. Enforced metadata with expiry dates turns an audit finding waiting to happen into a report of what lapses next month.

Taxonomy

A starting folder taxonomy

Organised so that everything an operator or auditor needs at the point of work sits in one predictable place.

Quality management system

  • Quality manual and policies
  • Procedures (controlled)
  • Work instructions by cell or line
  • Forms and checklists
  • Internal audit records

Product and process

  • Engineering drawings by revision
  • Bills of material
  • Control plans and FMEAs
  • Production part approval packages
  • Engineering change records

Production records

  • Inspection and test records
  • Non-conformance reports
  • Corrective and preventive actions
  • Traceability records

Equipment and tooling

  • Machine manuals
  • Maintenance and calibration records with due dates
  • Tooling records and ownership

Supply chain

  • Supplier approvals and audits
  • Material and conformity certificates with expiry
  • Purchase orders and amendments
  • Customer-specific requirements

Keeping customer-specific requirements as a distinct folder rather than filing them inside contracts is deliberate: in automotive and aerospace they frequently impose stricter retention and approval rules than the standard does, and they need to be findable when a rule is being configured.

Worked example

A worked workflow: engineering change to a work instruction

The workflow that ISO 9001 and IATF audits sample most often, and where the evidence usually turns out to be the weak point.
  1. Step 1: Raise the change

    A change record captures the reason, the affected part and process, and an impact assessment. Both the reason and the assessment are mandatory fields — an optional field here becomes an audit observation.

  2. Step 2: Assess and approve

    The change routes to engineering and quality in parallel, and to the customer where the contract requires it. Each approval is recorded against the specific revision being approved.

  3. Step 3: Train before effective date

    On approval an effective date is set and affected operators receive a training acknowledgement task. The revision does not become effective on the line until training is recorded.

  4. Step 4: Issue, supersede, retain

    The new revision is marked current, the previous one superseded and watermarked, and the retention rule attaches with its trigger set to end of production and service.

Retention

Retention expectations

Manufacturing retention is driven by product life and customer requirements more than by statute, which makes the trigger event unusually important.
Manufacturing retention expectations — starting points, not a schedule
Record classCommonly applied periodWhat starts the clockSource
Production part approval, tooling records, purchase ordersLength of active production and service, plus one calendar yearEnd of production and service for the partIATF 16949 §7.5.3.2.1
Records of conformity and inspectionCommonly matched to product life; minimum set by customer requirementsManufacture date or end of productionISO 9001 §7.5 and customer-specific requirements
Superseded controlled documentsRetained as long as the records produced under themDate the revision ceased to be effectiveAudit practice — the question is always which revision applied
Calibration and maintenance recordsCommonly 3 years, longer where product liability is a factorDate of the recordISO 9001 §7.1.5 and organisational policy
Occupational exposure recordsUp to 40 years depending on the substanceDate of last exposureOccupational health regulations — jurisdiction dependent
Product liability supporting recordsAligned to the applicable liability limitation periodDate product placed on the marketProduct liability statutes — often 10 years or more

These periods are indicative and must be confirmed against your certifications, customer-specific requirements and product liability exposure before you rely on them. Customer requirements frequently exceed the standard, and exposure records carry very long periods. Nothing here is legal advice.

FAQ

Manufacturing document management: common questions

What compliance, IT and operations teams in this sector ask us first.
How do we stop operators using a superseded work instruction?

The current revision is marked unambiguously, superseded revisions are labelled and cannot be presented as current, and any download or print carries a watermark showing its status. The watermark is the part that matters in practice, because on a production floor the copy in use is often paper.

Can retention be triggered by end of production rather than creation?

Yes, and for IATF configurations it has to be. Retention rules take an explicit trigger event that can be set later, which is what "active for production and service plus one calendar year" requires — the date is a business decision made years after the document was created.

Does it handle customer approval steps in a change workflow?

A workflow step can go to an external party through a secure link scoped to that document and that request, without provisioning them an account. The approval is recorded against the specific revision, which is what a customer audit will want to see.

How do we track certificates that expire?

Expiry is an enforced metadata field on the document type, so material certificates, supplier approvals and calibration records can be reported by what lapses next. An expired certificate discovered by an auditor is a finding; one discovered by a report is a task.

Do we need to retrain operators every time a document changes?

Only for material changes, and that judgement is yours — but the system should support it either way. Acknowledgement is recorded against a specific revision, so a change that requires retraining can reissue the requirement while a typographical correction does not.

A 30-minute session using the taxonomy, workflow and retention rules on this page, adapted to how your organisation actually works.