Sendabrief logoSendabrief
Free template

Document control procedure for ISO 9001

Document control is the procedure auditors test first, because it is the one that proves every other procedure can be trusted. The common failures are mundane: two versions in circulation, no evidence of who approved a change, and an obsolete document still being followed on the floor.

Download as Word (.docx) 11 stepsNo email, no signup. 11 steps, editable in Word or Google Docs.
Trigger

When any controlled document is created, revised, or withdrawn.

Roles involved
Document OwnerQuality ManagerProcess User
Review cadence

Annually, and before any external audit or recertification. Also review immediately after any finding related to documentation.

  1. 1

    Document Owner drafts or revises the document and records what changed and why in the revision history.

    Document Owner

    The reason for the change matters as much as the change. A revision history of "updated" answers nothing at audit.

  2. 2

    Document Owner confirms the document carries its unique identifier, revision number, and issue date.

    Document Owner

    Identifier plus revision on every page, not just the cover. Pages get printed and separated.

  3. 3

    Quality Manager reviews the document for adequacy and confirms it does not contradict another controlled document.

    Quality Manager

    The contradiction check is the step most often skipped and the one that causes the worst findings, because two valid procedures disagreeing means neither can be followed.

    Adequate: go to step 4

    Changes required: go to step 1

  4. 4

    Quality Manager records approval with the approver's name and the approval date before the document is issued.

    Quality Manager

    Approval before issue, recorded durably. The author cannot approve their own document.

  5. 5

    Document Owner checks whether a previous revision is in circulation.

    Document Owner

    Previous revision exists: go to step 6

    New document: go to step 7

  6. 6

    Document Owner withdraws every copy of the superseded revision from use and marks any retained copy as obsolete.

    Document Owner

    Retained obsolete copies must be visibly marked and separated. An unmarked old revision on a noticeboard is the single most common document control finding.

    Withdrawn: go to step 7

  7. 7

    Document Owner issues the approved revision to everyone who needs it and records the distribution.

    Document Owner

    Record who received it. "It is on the shared drive" is not distribution and does not evidence access.

  8. 8

    Process User confirms they have read the current revision where the change affects how they work.

    Process User

    Read confirmation only where the change is material. Requiring it for every typo trains people to click through without reading.

  9. 9

    Quality Manager records the document in the master list with its current revision, owner, and next review date.

    Quality Manager

    The master list is the artefact an auditor asks for first. If it does not match reality, nothing else you show them carries weight.

  10. 10

    Quality Manager reviews each controlled document on or before its review date and records the outcome even when nothing changes.

    Quality Manager

    "Reviewed, no change required" with a date and a name is a valid and necessary record. A blank review field reads as a document nobody has looked at in three years.

    No change required: the procedure ends

    Revision needed: go to step 1

  11. 11

    Document Owner identifies externally originated documents that the quality system depends on and brings them under control.

    Document Owner

    Standards, supplier specifications, statutory guidance, and equipment manuals. These are routinely missed because nobody wrote them, and an out-of-date external standard invalidates the procedures built on it.

    Under control: go to step 9

Change these before you use it

  • Map these steps onto your own numbering if you reference ISO 9001 clauses directly, and confirm the mapping with whoever runs your audits.
  • Define your retention periods explicitly. This template states none because they depend on your sector and contracts.
  • Name your actual document management system. "The shared drive" and "the QMS" are not followable instructions.
  • Decide and write down which changes are material enough to require the read confirmation in step 8.
  • This is a starting point, not certification advice. It is written to be adapted and reviewed by someone accountable for your quality system.

This is a starting point, not compliance advice. It is written to be adapted, and a procedure that touches access, money, or customer data needs to match how your business actually operates and whatever rules apply to you. Use it as a first draft to edit, not a policy to adopt.

Make it yours in a couple of minutes

Rather than retyping this and editing it, describe your own version of the process out loud or click through it once, and get a first draft with your actual steps, roles, and systems in it. No account needed to see the result.

No account neededNo credit cardSee the whole SOP before you sign up