Quality Operations Guide 12 min read

ISO 9001 document control — managing controlled documents without chaos

Clause 7.5 in practice — how to version, approve, distribute and withdraw controlled documents so the floor always works to the current revision, drawings and FMEAs stay attached to the item, and you survive a surveillance audit without a full-time document officer.

12 min read By Vidya Kathare · July 18, 2026 Operations guide
The document lifecycle
01
Draft
Author against the item record
Created
02
Review & approve
Right authority signs off
Approved
03
Release
Current revision available to the floor
In force
04
Change
New revision via change control
Revised
05
Withdraw
Obsolete revision removed from use
Retired

What document control means

Document control is the discipline of making sure that everyone in the plant is working from the right version of the right document, that changes to those documents are authorised, and that superseded versions cannot be used by mistake. In a quality context the “documents” are the ones that define how a part is made and checked: drawings, specifications, control plans, work instructions, FMEAs, inspection standards and the PPAP package.

It sounds administrative, but it is one of the highest-leverage controls in a quality system. An out-of-date control plan means parts checked against the wrong limits; a superseded drawing means parts made to superseded dimensions; an unapproved work instruction means a process nobody signed off. Document control is what stands between a well-run process and a plant quietly making the wrong thing correctly. ISO 9001 devotes clause 7.5 to it precisely because uncontrolled documents are one of the most common — and most damaging — quality failures.

A simple way to think about it
Document control is the answer to one question an auditor will always ask: “how do you know the operator is working to the current revision — and how do you know the old one can’t still be used?”
If the answer is “we photocopied it and told everyone,” you do not have document control. If it is “the current revision is the one attached to the item, and the obsolete one is withdrawn,” you do.

What clause 7.5 actually requires

ISO 9001 clause 7.5 (“Documented information”) — carried into IATF 16949 with additional automotive requirements — asks for a handful of concrete controls. Stripped of the standardese, it requires that documented information be:

  • Identified and described — a title, a number, a revision and a date, so any copy can be pinned to an exact version.
  • Reviewed and approved for suitability before release, by an authority with the competence to sign it off.
  • Available where needed — the current version accessible at the point of use, and legible.
  • Version-controlled through change — changes made under control, with the revision history retained.
  • Protected from loss and misuse — including preventing the unintended use of obsolete versions.

Notice that none of this demands a particular tool or a dedicated officer. It demands a system in which those five properties are true by default. A stack of Word files in shared folders can technically satisfy the letter of the clause, but it makes every one of the five a matter of human vigilance — which is exactly where document control breaks down.

Which documents must be controlled

A frequent confusion is scope: which documents actually need control, and which are just files. The test is impact — if using the wrong version could produce a non-conforming part or an invalid record, the document is controlled. In a manufacturing quality system that typically means:

Product definition

Drawings, specifications and engineering standards that define what the part must be — the top of the chain every check derives from.

Drawings & specs

Process control

Control plans, work instructions, process sheets and inspection standards that define how the part is made and checked.

Control plans & WIs

Quality records & PPAP

FMEAs, MSA studies, the PPAP package and the quality manual — the risk and approval evidence an audit follows.

FMEA & PPAP

The automotive angle sharpens the point. Every element of a PPAP package — drawing, FMEA, control plan, MSA study, dimensional results, the PSW — is a controlled document, which is why a document-backed PPAP (rather than a loose folder of files) is the only version that stays audit-ready. In Fast Quality, PPAP elements and quality documents live in the same shared document-control subsystem, so the same lifecycle that governs a drawing governs a PPAP element.

The controlled-document lifecycle

A controlled document is not a static file; it moves through a lifecycle, and the control is in the transitions. Getting the lifecycle explicit — with an approval gate before release and a change gate before revision — is what turns “a folder of files” into document control.

Draft to obsolete, under control
1
Draft
The document is authored and identified — number, title, revision, date — and attached to the item or quality record it governs.
2
Review & approve
The right authority reviews for suitability and approves it. Until approved, it is not in force — the approval gate is the heart of the control.
3
Release
The approved revision becomes the current version, available at the point of use. There is exactly one current revision at any time.
4
Change
A revision is made through change control — impact assessed, the new version approved — and the revision history is retained, not overwritten.
5
Withdraw
The superseded revision is marked obsolete and removed from use, so it cannot be picked up by mistake while remaining on record for traceability.

The approval and change gates are where a real system pays off. When a document can only reach “in force” through an approval step, and can only change through a controlled revision, the two hardest requirements of clause 7.5 — approval before use and controlled change — happen automatically rather than by discipline. In Fast Quality, documents move through the platform’s approval lifecycle (draft, verify, released/approved), and revisions run through change management.

The whole of document control lives in two gates: nothing is in force until it is approved, and nothing changes except through a controlled revision. Get those two right and clause 7.5 mostly takes care of itself.

Obsolete-document withdrawal — the audit favourite

If an auditor is going to catch a document-control failure, it will almost always be here. It is easy to release a new revision; it is easy to forget to remove the old one. And the moment an obsolete revision is still reachable at the point of use, you have failed the clause’s requirement to prevent unintended use — regardless of how neat your approval records are.

The classic finding is the photocopy: a controlled drawing revised in the system while a printed copy of the previous revision still hangs at the machine. This is why best practice minimises uncontrolled paper copies and drives operators to the current revision from the system, so the version on the item record and the version in use are the same by construction. When a document is superseded, the previous revision is marked obsolete and withdrawn — retained on record for traceability, but no longer reachable as a working document. In Fast Quality, releasing a new revision supersedes the prior one in the shared document store, so the current attached version is the one in force.

Attaching documents to the item record

The structural best practice that makes everything above easier is to attach controlled documents to the item record rather than filing them by folder. When the drawing, control plan, FMEA, work instruction and PPAP package all hang off the part they govern, finding “the current control plan for this part” is one lookup, not a hunt through shared drives. It also makes completeness visible: you can see at a glance which documents a part is missing.

This item-centric model is what powers a document-status dashboard — a view of document and PPAP completeness per item that answers, in one place, “is this part fully documented and approved?” It is the same data that feeds PPAP completeness reporting (see quality reports and KPIs). In Fast Quality, documents attach to the item and quality records, and an item document-status dashboard shows completeness per part, with upload and controlled download through the shared document engine.

Is the drawing on the floor the same as the one in the system?

See versioned control plans and FMEAs attached to the item, an approval lifecycle, and obsolete revisions withdrawn automatically — in 30 minutes, on your own documents.

Get a demo

Surviving an audit without a document officer

Large organisations can afford a full-time document controller whose job is to keep the paperwork straight. Most Indian SMEs cannot — and should not have to. The answer is not to hire the vigilance; it is to build a system where control is the default so the vigilance is not needed. Three moves make document control largely self-maintaining:

  • Make the system the single source. If the current revision is always the one attached to the item, no one has to remember which copy is right — the system knows.
  • Make approval and change gates mandatory. When a document can only go live through approval and only change through revision, the two hardest clauses enforce themselves.
  • Let the dashboard find the gaps. A document-status view per item surfaces missing or unapproved documents before the auditor does.

Done this way, the pre-audit scramble disappears — not because someone worked harder, but because the records were controlled as a by-product of daily work. That is the same principle behind the whole quality system, laid out in the pillar guide on what quality management software is, and the antidote to the mistakes covered in 7 quality management mistakes.

Illustrative — an engineering change, controlled

From a customer change to a withdrawn revision

A customer issues an engineering change to a machined part — a tightened tolerance on one feature. The change is raised, its impact assessed (which drawing, control plan, FMEA and inspection standard are affected), and each affected document is revised and re-approved. The new control-plan revision goes in force and is attached to the item; the previous revision is marked obsolete and withdrawn; the FMEA is re-scored; and because the change is significant, a PPAP re-submission is triggered. An operator pulls the control plan for that part and gets, necessarily, the new revision — because it is the one attached to the item. When the auditor asks to see change control and current revisions, the trail is complete and the obsolete revision is provably out of use.

1
current revision at any time
2
gates — approval & change
7.5
the clause it satisfies

How Fast Quality controls documents

Fast Quality Software, built by Improsys in Pune on the shared Fast Suite platform, implements clause 7.5 through the platform’s universal document-control subsystem:

1
One controlled store. Drawings, control plans, work instructions, FMEAs and PPAP elements live in the shared document subsystem, uploaded and served through the platform’s document engine.
2
An approval lifecycle. Each document moves through draft, verify and released/approved status, so nothing is in force until the right authority has signed it off.
3
Controlled change. Revisions run through change management — change request, impact assessment, document approval — with the prior revision superseded and withdrawn.
4
Attached to the item. Documents hang off the item and quality records, so the current revision is always the one on the part, and an item document-status dashboard shows completeness per part.
5
PPAP as controlled documents. Every PPAP element carries the same version and approval lifecycle, so the submission package stays audit-ready rather than becoming a loose folder — see PPAP completeness reporting.

Because document control is a shared platform service, the same subsystem serves quality, PPAP and the wider suite through native document-control integration — no separate document system to reconcile. For the connected quality loop this sits inside, see the pillar guide on what quality management software is.

Keep going — the quality operations library
Sibling guides on common mistakes, quality reporting and non-conformance, plus the product page behind document and change control.

Frequently asked questions

What is document control in ISO 9001?

Document control is the discipline of ensuring everyone works from the right version of the right document, that changes are authorised, and that superseded versions cannot be used by mistake. In a quality context the controlled documents are those that define how a part is made and checked — drawings, specifications, control plans, work instructions, FMEAs, inspection standards and the PPAP package. ISO 9001 clause 7.5 (“Documented information”) sets the requirements: documents must be identified, approved before use, available where needed, version-controlled through change, and protected from the unintended use of obsolete versions.

What does clause 7.5 actually require?

In plain terms, five things: documents must be identified and described (title, number, revision, date); reviewed and approved for suitability before release by a competent authority; available and legible where they are used; controlled through change with the revision history retained; and protected from loss and misuse, including preventing the unintended use of obsolete versions. Clause 7.5 does not mandate a particular tool or a dedicated document officer — it requires a system in which those five properties are true by default rather than by constant human vigilance.

Which documents need to be controlled?

The test is impact: if using the wrong version could produce a non-conforming part or an invalid record, the document is controlled. In manufacturing that typically means product-definition documents (drawings, specifications, engineering standards), process-control documents (control plans, work instructions, process sheets, inspection standards) and quality records including FMEAs, MSA studies and the whole PPAP package. Every PPAP element is a controlled document, which is why a document-backed PPAP stays audit-ready while a loose folder of files does not.

Why do auditors focus on obsolete documents?

Because it is the easiest control to fail and the most damaging when it fails. Releasing a new revision is easy; removing the old one is easy to forget. The moment an obsolete revision is still reachable at the point of use — the classic photocopy at the machine while the drawing was revised in the system — you have failed the requirement to prevent unintended use, no matter how tidy your approval records are. Best practice minimises uncontrolled paper copies and drives operators to the current revision from the system, so the version on the item record and the version in use are the same by construction.

Can an SME manage document control without a dedicated officer?

Yes — by building a system where control is the default rather than hiring the vigilance. Three moves make it largely self-maintaining: make the system the single source so the current revision is always the one attached to the item; make approval and change gates mandatory so documents only go live through approval and only change through controlled revision; and let a document-status dashboard surface missing or unapproved documents before the auditor does. Done this way, the pre-audit scramble disappears because the records were controlled as a by-product of daily work, not maintained by a full-time controller.

Controlled documents without the chaos

A 30-minute Fast Quality Software demo shows versioned drawings, control plans and FMEAs attached to the item, an approval lifecycle, controlled change and obsolete-revision withdrawal — clause 7.5 satisfied as a by-product of daily work, on your own documents.

Get a demo
No commitment. No slides. Your document control on screen. Cloud or on-premise.