Templates
Document Control Procedure Template
A document control procedure describes how documented information is approved, identified, distributed, reviewed and withdrawn. An auditor reads it to establish what your controls claim to do, then samples individual documents to confirm that each of those claims is true in practice.
Document Control Procedure Template
This is a section structure with notes on what each section has to establish. It is written so that what you produce describes controls a system can actually enforce, because the most common cause of findings here is a procedure that is more ambitious than the configuration.
1. Purpose and scope
State which documents are covered and, explicitly, which are not. Personal working notes, email and transitory material are normally out of scope, and saying so prevents an auditor sampling from material you never intended to control.
Name the standards the procedure is written to satisfy, if any.
2. Definitions
Keep it to terms used with a specific meaning in the procedure: controlled document, record, revision, superseded, effective date, document owner. Definitions that repeat a standard's glossary add length without adding clarity.
3. Document tiers and approval authority
The table an auditor turns to first. For each tier, state who reviews and who approves.
| Tier | Examples | Reviewed by | Approved by |
|---|---|---|---|
| 1 — Policy | Quality policy, information security policy | Management team | Chief executive |
| 2 — Procedure | Document control, change control | Process owner | Function head |
| 3 — Work instruction | Task-level instructions | Supervisor | Process owner |
| 4 — Form and template | Checklists, record forms | Process owner | Process owner |
Set the tiers to match how your organisation actually approves things. A table describing an approval chain nobody follows is worse than a simpler one that is true.
4. Identification and version numbering
State the document numbering scheme, the revision scheme, and where the identifiers appear. Say explicitly that the system of record holds the authoritative version, so a printed copy is uncontrolled unless marked otherwise.
Include the rule for what constitutes a new revision as opposed to an editorial correction, because this is the point where practice diverges from documentation fastest.
5. Approval before issue
Describe the workflow: how a change is raised, that a reason for change is recorded, who reviews by tier, how approval is captured, and that approval sets an effective date and marks the previous revision superseded.
The recorded reason for change is worth naming explicitly. Several regulated frameworks require it, and it is the field most often absent.
6. Distribution and availability
State how people access current documents, and how they are informed of a revision. Where training or acknowledgement is required, state that the revision does not take effect until it is recorded — that sentence closes the gap between a document being approved and the people using it knowing about it.
If controlled printed copies exist, state who holds the distribution list and how withdrawal works.
7. Review cycle
A review frequency per tier — commonly annual for policies, two-yearly for procedures — plus the rule that a review date is set on every approval and that a review is recorded even when it results in no change.
Overdue review dates are the most frequently raised non-conformity in this area, so name the report that monitors them and the role that owns it.
8. Obsolete and superseded documents
State that superseded revisions are retained but marked, that they are not accessible in the way current documents are, and how long they are kept. Retain them at least as long as the records produced under them — the question in any investigation is which revision was effective at the time.
9. External documents
Standards, regulations, supplier specifications and customer drawings are controlled documents you did not write. State who maintains the register, how currency is confirmed, and what happens when a new edition is issued.
This section is thin in most procedures and is sampled regularly, because working to a withdrawn edition of a standard is a substantive finding rather than a paperwork one.
10. Records and retention
Reference the retention schedule rather than duplicating it, so there is one place where periods are maintained.
11. Responsibilities and revision history
A short list of roles and what each is accountable for, then the procedure's own revision history — revision, date, reason for change, approver. Its own history being incomplete is an unhelpful place to be found wanting.
What to check before approving it
Walk the procedure against the system as configured, section by section, and mark anything the configuration does not currently do. Then either change the configuration or change the sentence.
That reconciliation is the whole value of the exercise. A procedure written from a template and approved without it will be internally coherent and externally wrong, and the mismatch is found by sampling rather than by reading — which means it is found by an auditor rather than by you.
It is also worth naming, in the procedure, the reports that monitor the controls: documents past their review date, documents awaiting approval beyond a threshold, and external documents whose currency has not been confirmed. Controls with a monitoring report attached tend to keep operating.
FAQ
Questions this raises
How long should a document control procedure be?
Short enough that it is accurate. A procedure describing what the system actually does is sustainable; one describing an aspiration produces findings at every audit, because the sampled documents will not match it.
Do we need one if the system enforces the controls?
Yes. The system implements the controls and the procedure documents them, names the accountable roles and states the review frequencies — none of which an auditor can read from a configuration screen.
Who approves the document control procedure itself?
It is a tier-one document and should be approved at the level its own table specifies for that tier. A procedure that exempts itself from its own controls is a finding waiting to happen.
About the author
Written and reviewed by the DocumentMS product and compliance team.
Last reviewed: September 2, 2026