Ask any auditor where they find the most nonconformities and the answer is almost always the same: documented information. The 2025 pattern across FDA audit observations was overwhelmingly document-related — missing, incomplete, outdated or inconsistently followed procedures and records. Deloitte has reported that 56% of companies have run into compliance issues because of poor document control. None of this is exotic. It is the boring, fixable stuff: two versions of the same work instruction on the floor, an SOP nobody can find, a drawing that was superseded six months ago and is still being built to.
The good news is that document control is one of the few parts of a quality system you can get genuinely right with a weekend of structured work. This guide walks through the four decisions that matter — a numbering scheme, version control, an approval workflow, and obsolete-document handling — and shows what clause 7.5 actually expects from each.
What clause 7.5 actually requires
It helps to separate what the standard demands from what people assume it demands. Clause 7.5 of ISO 9001 covers "documented information", and it asks for three things. First, that documents are properly identified and described — a title, a date, an author or reference, and a suitable format (7.5.2). Second, that they are reviewed and approved for suitability before use. Third, that they are controlled: available where they are needed, protected, version-managed, and kept from being used once obsolete (7.5.3).
Notice what is not there. The standard does not mandate a particular numbering format, a specific piece of software, electronic signatures, or a paper-free system. Those are your choices. What it requires is that whatever you choose, you can always answer four questions on demand: What is the current version? Who approved it, and when? Where is it in use? And how do we stop the old one being used by mistake? Build your system to answer those four questions cleanly and you are most of the way to compliance.
Decision one: a numbering scheme you won't outgrow
A document number is just a unique, stable handle for a document. Its job is to make every document findable, referenceable and impossible to confuse with another. The mistake most organisations make is either having no scheme at all (files named "Quality Procedure FINAL v3 (2) revised.docx") or over-engineering one so baroque that nobody can remember it.
A workable scheme mirrors your documentation hierarchy. ISO 9001 systems generally stack documents in tiers — the quality manual or policy at the top, then procedures, then SOPs and work instructions, then the forms and records they generate. A prefix per tier keeps that visible at a glance:
- QM — quality manual / policy (e.g. QM-001)
- QP — quality procedure (e.g. QP-004)
- SOP — standard operating procedure (e.g. SOP-012)
- WI — work instruction (e.g. WI-07-02)
- FM — form / template (e.g. FM-031)
You then have two ways to allocate the numbers. The simplest is sequential: the eighth SOP is SOP-008, full stop. It is easy to administer and never runs out. The alternative is significant numbering, where digits carry meaning — for example tying a document to the process it serves, so if "proposal development" is process 07, the procedure is QP-07 and its work instructions are WI-07-01, WI-07-02, and so on. Significant numbering makes relationships visible but becomes brittle when processes are reorganised.
A practical rule: use sequential numbering unless you have a clear, stable reason to encode meaning. Significant numbering looks elegant on day one and fights you on the day you merge two departments.
Whatever you pick, write the rule down in a one-page document-control procedure, keep a master list (often called a master document register) of every controlled document and its current revision, and — critically — keep the document number out of the revision. The number identifies the document for its whole life; the revision tells you which version of it you are holding. Conflating the two is how organisations end up renumbering everything every time they make an edit. ISO 10013, the guidance standard for documented information, is worth a read if you want a fuller reference for structuring this.
Decision two: version control that survives contact with reality
Version control is where document systems quietly fail, because the failure mode is invisible until it bites. Research on knowledge workers found that 83% lose time every day to versioning issues, and IDC has put document-related inefficiency at nearly $20,000 per information worker per year. In a plant the cost is sharper than lost minutes: build to a superseded drawing or an old SOP and you get scrap, rework and material waste — the National Association of Manufacturers has linked document errors to production-cost increases of up to 20%.
Good version control rests on a few habits:
- One source of truth. There is exactly one official, current copy of each document, in one place everyone trusts. The moment a controlled document can be downloaded, edited locally and re-uploaded as a "new" file, you have lost control — this is the central weakness of using a plain shared drive or an unconfigured SharePoint library, where different people end up reading different versions of the same procedure.
- A clear revision identifier. A simple incrementing revision — Rev 1, Rev 2, or A, B, C — shown on every page, usually in the footer with the document number and approval date. Drafts can carry a separate convention (e.g. Rev 2 Draft) so an unapproved version is never mistaken for the live one.
- A revision history table. Inside the document, a short table listing each revision: version, date, author, approver, and a one-line summary of what changed. This is the cheapest possible way to satisfy the "identify changes and current revision status" requirement, and auditors love it.
- Review even when nothing changes. If you review a document and decide no change is needed, update the "last reviewed" date anyway. It demonstrates the document is live and under control, not abandoned.
The principle underneath all of this: a reader should be able to pick up any document and know, without asking anyone, whether it is current and what changed last time.
Decision three: an approval workflow with teeth
Clause 7.5.2 asks that documents are reviewed and approved for suitability before they are used. The intent is simple — a competent person, with the authority to do so, signed off before this procedure started controlling how work gets done.
In practice an approval workflow needs three roles, even if one person wears two hats in a small firm: an author who drafts, a reviewer who checks it is technically correct and workable, and an approver who authorises release. The evidence that this happened is the part that matters to an auditor. That can be a wet signature on a cover sheet, a signature block in the document, or — increasingly — an electronic approval with a name, date and timestamp captured by a system. What it cannot be is nothing: "we all just knew it was approved" is a finding waiting to happen.
The approval record is not bureaucracy for its own sake. It is the answer to the auditor's second question — who approved this, and when? If you can't produce it in seconds, the document isn't really controlled.
The same applies to changes. A revision to a controlled document is itself a change that should be reviewed and re-approved before the new version goes live, with the old version retired at the same moment. Where document control most often breaks is the handoff after approval — a revised SOP is released, but the people who follow it, and any related training, are never updated. If a revision affects how someone is trained to do a job, the re-approval and the re-training should travel together.
Decision four: getting obsolete documents out of circulation
The final requirement of 7.5.3 is the one people forget: preventing the unintended use of obsolete documents. Approving the new version is only half the job; the old version has to disappear from where work happens.
For an electronic, single-source system this is largely automatic — replace the current file and the previous version is no longer the one people open, while the system retains it in history for traceability. For any system with printed copies, you need a deliberate routine: a controlled-copy list so you know where hard copies live, a recall-and-destroy step when a revision is released, and a clear rule for any obsolete document that must be retained (for legal or historical reasons) — typically stamping or watermarking it "OBSOLETE — reference only" so it can never be mistaken for live. The test is blunt: walk the floor and try to find a single out-of-date document in active use. If you can, your control isn't working yet.
Where the tools fit — and where they don't
Most organisations run document control on whatever they already have, and that is a reasonable place to start. A shared drive or SharePoint can hold documents and, properly configured, manage versions — but "properly configured" is the catch. Out of the box these tools let users save local copies and reorder folders, and they have no native concept of an approval workflow, an obsolete-document state, or a link between a document and the training tied to it. LNS Research found that only 13% of companies using non-purpose-built tools rated their quality processes "excellent". Wiki-style tools like Notion, Confluence or ClickUp are excellent for writing and finding procedures, and they support draft/review/approved statuses — but the controlled record, the locked approval, and the audit-grade history are not really their job.
Dedicated electronic QMS platforms exist precisely to enforce all four of the decisions above automatically. They are also priced for it: most purpose-built systems start in the region of $1,200–$1,600 per month, which is the right investment for a regulated medical-device or pharma manufacturer and a hard sell for a 30-person workshop chasing its first ISO 9001 certificate. The honest answer for most small and mid-sized manufacturers sits in the middle: keep your documents where your team already works, but put a disciplined control layer — numbering, versioning, approvals, an obsolete-document state and a master register — on top of them. That is the gap most teams fall into, and it is entirely closable.
A weekend plan
If you want to fix this from a standing start, the order is: (1) write the one-page document-control procedure that states your numbering scheme and approval roles; (2) build the master document register listing every controlled document and its current revision; (3) standardise the footer and revision-history table across your templates; (4) run one pass to approve and re-baseline everything to a clean revision; and (5) sweep the floor for obsolete copies. Done deliberately, that is a weekend — and it closes the single most common category of audit finding for years.
Document control isn't the glamorous part of a quality system, but it is the part auditors reach for first and the part that quietly costs the most when it slips. Get the four decisions right and the rest of your system has something solid to stand on.
If you'd like a document-control procedure, numbering scheme and master register built to fit how your team already works — rather than a generic template — that's exactly the kind of work we do.