Quality management
Quality management document control and QMS software
Quality management document control means only approved documents are in use and superseded ones cannot be mistaken for current. DocumentMS enforces approval before issue, keeps full revision history, marks the current version unambiguously, records who received each issue, and schedules the periodic review ISO 9001 expects.
What goes wrong without document control
ISO 9001 clause 7.5.3 asks for something very specific and easily failed: documented information must be controlled so that it is available where needed, adequately protected, and — the part that trips organisations up — obsolete versions must be prevented from unintended use. A shared drive satisfies availability and fails prevention, because nothing stops an operator opening last year’s file.
The second failure is that approval happened but cannot be evidenced. An auditor asks who approved revision 4 of a procedure and on what date, and the answer is an email from someone who has since left, or a signature on a printout in a folder. The approval was real; the evidence is not durable.
The third is periodic review. Procedures are written, approved and then left. When an auditor samples review dates and finds several overdue, the finding is not that a procedure is wrong — it is that the control over documented information is not operating. That is a systemic finding rather than a document one, and it is more expensive to close.
The symptoms you will recognise
- Controlled documents stored on a network drive with no mechanism preventing use of an old revision
- Approval evidenced by an email or a signature on paper filed separately from the document
- Printed procedures at workstations with no indication of whether they are current
- Periodic review dates passed without review, discovered during an audit
- A document control master list maintained by hand and out of step with the documents
- No record of which revision an operator was trained on
Configuration
Folder structure
Tier 1 — Policy
- Quality manual
- Quality policy
- Scope and exclusions
Tier 2 — Procedures
- Management procedures
- Operational procedures
- Support procedures
Tier 3 — Work instructions
- Work instructions by area or cell
- Setup and changeover instructions
- Inspection instructions
Tier 4 — Forms and records
- Controlled forms (blank)
- Completed records
- Registers and logs
Audit and improvement
- Internal audit programme and reports
- Non-conformances and CAPA
- Management review inputs and minutes
Configuration
Metadata a controlled document needs
| Field | Type | Mandatory | Why it exists |
|---|---|---|---|
| Document number | Text (auto-generated) | Mandatory | Referenceable in a procedure, an audit finding or a training record. Auto-generation removes duplicates and gaps. |
| Revision | Text or number | Mandatory | The identity of the version. Every approval, training record and audit finding attaches to a revision, not to a document. |
| Document tier | Single-select | Mandatory | Determines approval authority and review frequency without a separate rules document. |
| Process owner | User | Mandatory | A named accountable person. Ownerless procedures are the ones that go unreviewed. |
| Approved by / approval date | User / date | Mandatory | The evidence an auditor asks for first. Recorded by the system, not typed into a footer. |
| Effective date | Date | Mandatory | Answers "which revision applied when this record was made" — the question behind most investigations. |
| Next review date | Date | Mandatory | Raises a review task in advance. An overdue review is a systemic finding, not a document one. |
| Training required | Yes / no | Mandatory | Distinguishes revisions that require re-training from editorial corrections that do not. |
Configuration
Approval chain
Step 1: Draft with a recorded reason
The process owner drafts a new revision, recording the reason for change as a mandatory field. Free-text reasons that can be skipped produce the audit observation you were trying to avoid.
Step 2: Review by tier
Reviewers are determined by the document tier — a work instruction by the area supervisor, a procedure by the process owner and quality, the manual by top management. Each approves in their own authenticated session.
Step 3: Approve, set effective date, train
Approval locks the revision and sets its effective date. Where training is required, affected operators receive an acknowledgement task and the revision does not take effect until it is recorded.
Step 4: Issue and supersede
The revision becomes current, the previous one is marked superseded and watermarked on any download or print, and the retention rule attaches.
Configuration
Retention rule
What starts the clock
For a controlled document the trigger is the date the revision ceased to be effective, not the date it was created. For completed records it is usually the record date, except where product liability applies, in which case it is the date the product was placed on the market.
Outcomes
What changes
- An operator cannot open a superseded revision believing it to be current, because status is marked on screen and watermarked on print
- The master list is generated from the documents, so it cannot drift out of step with them
- Approval evidence is a system record attached to a revision, not an email held by an individual
- Overdue reviews appear on a report before an auditor samples them
- Training is recorded against a specific revision, so "trained on the current version" is a verifiable statement
- "Which revision applied on this date" is answered from the effective-date field
FAQ
Quality management (QMS): common questions
Does this satisfy ISO 9001 clause 7.5.3?
It provides the controls the clause calls for: controlled distribution and access, version identification, protection, retention, and — the part most systems miss — prevention of unintended use of obsolete documents through unambiguous status marking and watermarked printing. Whether your implementation satisfies your auditor depends on how you configure and operate it, which is true of any tool.
Do we still need a document control procedure?
Yes. The system implements controls; the procedure describes them, names the roles and states the review frequencies. An auditor will ask for both, and a procedure that describes what the system actually does is much easier to sustain than one written aspirationally.
How do we control printed copies at workstations?
Watermarking is the practical mechanism: a printed copy carries its status, so a superseded printout is identifiable as one. It is not a perfect control — nothing that leaves the system is — which is why the better answer is to reduce the number of printed copies by making the current revision easy to reach at the point of work.
Should completed records live in the same system as procedures?
In the same system, in a separate tier. They have different retention rules, different permissions and different review requirements. Keeping them in one branch means either over-controlling records or under-controlling procedures.
What is the difference between this and the ISO 27001 page?
The discipline is the same; the document set and the evidence differ. ISO 9001 is about the quality management system and its procedures; ISO 27001 is about the ISMS, its statement of applicability and the Annex A controls. Organisations certified to both usually run one document library with two policy branches.
Última revisão: 2026-09-01. See all seven use cases.