TAGS:

ISO 9001 document control and Clause 7.5 requirements — TLM audit-ready QMS

Most guides to ISO 9001 document control open with a clause number and lose you by the second paragraph. Let’s start somewhere better — with a contractor that made its quality system audit-ready in twelve weeks, and got mistaken for a company that had been certified for years.

The quality system an auditor assumed was years old

A small contracting company — Morning Star — got the kind of letter that raises everyone’s pulse: one of their largest clients was exercising a clause in their contract and sending auditors to verify their quality system against ISO 9001. In three months.

Morning Star wasn’t starting from nothing. They ran a real quality system — one that had kept a demanding client happy for years. It just lived the way a lot of small companies’ systems do: in spreadsheets, shared files, and the know-how in their team’s heads. It worked. But as they looked at the audit date on the calendar, they did the math on what it would take to pull all that scattered evidence together, keep it current, and prove it on demand — and the sheer manual labor of doing it by hand was daunting.

So they made a smart call. Rather than spend the next twelve weeks assembling binders by hand, they’d move their quality system into software — a faster, far less stressful route to being audit-ready — and find a partner willing to help them implement it on a small-company budget.

Here’s what those weeks looked like:

  • The system was set up and their existing documents and templates were loaded — so they built on what they already had, not a blank page.
  • Process owners were interviewed so the procedures captured how the company actually works.
  • Their existing records — corrective actions and customer feedback sitting in email history — were organized into the system.
  • A management review was held before the external auditors arrived.

Then the audit began. On the second day, one of the auditors turned to Morning Star’s acting Management Representative and asked, almost in passing:

“The TLM system was easy to use, clear and met all the requirements we were seeking. It allowed us to utilize existing documents and create new documents at the same time with helpful templates and clear instructions. It made formalizing our quality processes into a stronger, more robust plan. Anytime we needed help, TLM staff was there to support us — they were very responsive, helpful and professional in every aspect. We have recommended TLM to several of our partners and we would not hesitate to use them again on any project.”

— Kelly, Management Representative, Morning Star

That story is the whole point of Clause 7.5. ISO 9001 document control isn’t about owning a thick binder — it’s about control being real, current, and provable on demand. A well-run system doesn’t look new; it looks trustworthy. Here is exactly what the clause asks for, and how to deliver it without drowning in paper. (New to this and still choosing a system? Start with our guide to the best document control software for ISO-certified firms.)

What Clause 7.5 actually requires (in plain English)

Clause 7.5 of ISO 9001:2015 is titled Documented Information — the 2015 standard’s umbrella term that replaced the old split between “documents” and “records.” It has three parts.

7.5.1 — What you actually have to document

Two things: the documented information ISO 9001 explicitly requires, plus whatever information you determine is necessary for your quality system to work. Crucially, the standard says the extent scales to your organization — your size, the complexity of your processes, and the competence of your people. Translation: there is no mandated page count. A 40-person contractor does not need a pharma company’s documentation. Right-sizing is not cutting corners; it’s compliance.

7.5.2 — Creating and updating documents

When you create or change a document, three things must be in place:

  • Identification and description — a title, a date, an author, and a unique reference or number.
  • Appropriate format and media — the right file type, language, and whether it’s electronic or hard copy.
  • Review and approval — someone with authority signs off that the document is suitable and adequate before it’s used.

7.5.3 — Controlling documented information

This is the heart of document control, and it has two halves.

7.5.3.1 — the information must be available and suitable for use, where and when it’s needed, and adequately protected (from loss of integrity, improper changes, or loss of confidentiality).

7.5.3.2 — you must control, as applicable:

  • Distribution, access, retrieval, and use — the right people can get the current version.
  • Storage and preservation, including keeping it legible.
  • Control of changes — i.e., version and revision control.
  • Retention and disposition — you keep what you must, and you remove obsolete documents from use.
  • External documents (customer specs, standards, regulations) — identified and controlled like your own.

Read 7.5.3.2 again and notice how little of it a filing cabinet actually satisfies.

Why the binder — and the shared drive — quietly fail

Most small firms meet Clause 7.5 with a binder, or a shared drive that behaves like one. Both store documents. Neither controls them. Here’s where they break under an auditor’s questions:

  • “Show me this is the current version.” A drive can hold five versions of a procedure; nothing stops someone opening last year’s.
  • “Prove the people who use this are trained on it.” A folder can’t tell you who’s read the current revision.
  • “Where’s the obsolete copy?” If old revisions aren’t actively pulled from circulation, someone will work from one — the single most common document-control finding in small firms.
  • “Walk me through this change.” “We edited the file and saved it” is not controlled change.

The binder isn’t wrong because it’s paper. It’s wrong because control depends on everyone remembering the rules — and that dependency is exactly what an audit is designed to expose.

The twelve-week playbook: how to make Clause 7.5 audit-ready fast

The Morning Star build is a repeatable sequence. It’s how you turn “we do good work” into “here is the controlled evidence” — whether you have three months or you’re finally getting serious after years.

  1. Start from templates, not a blank page. A skeleton of controlled documents mapped to the ISO 9001 clauses saves weeks and guarantees you don’t miss a required procedure.
  2. Interview your process owners. Document how the work actually happens, not an idealized version. Procedures your team recognizes are procedures your team follows — and auditors can tell the difference in five minutes.
  3. Review and release under control. Every document gets an approver and a version before it goes live. This alone satisfies most of 7.5.2 and 7.5.3.
  4. Tie training to the release. When a procedure is released, assign the people who use it to read and acknowledge it — against that specific revision. That’s your answer to “prove they’re trained on the current version.”
  5. Turn on obsolete-document control. Superseded revisions get pulled from circulation automatically. Close the most common finding before it happens.
  6. Reconstruct the records you already have. Most companies have more evidence than they think — corrective actions and customer feedback are often sitting in email history. Organize it into CAPA and feedback records; you’re not inventing, you’re capturing.
  7. Hold a management review before the audit. It’s a required input and a dress rehearsal. Walking in with review minutes signals a system that’s actually running.

Facing a surprise audit date, or finally formalizing a system you’ve run informally for years? Talk to us about a fast, audit-ready build →

Why the auditor couldn’t tell it was new

Here’s the insight worth keeping: control isn’t age. An auditor can’t see how long your system has existed — only whether it’s controlled today. Are current versions the ones in use? Are changes approved? Is training current? Are records retrievable in under a minute? Get Clause 7.5 right and a twelve-week-old system reads exactly like a ten-year-old one. Get it wrong, and a ten-year-old system throws findings on day one.

That’s the reframe every small firm needs: document control isn’t a tax you pay to be compliant. It’s the thing that makes your real competence visible to the one person — the auditor, the client, the regulator — who wasn’t there to watch you earn it.

How TLM makes Clause 7.5 the default

We built TLM so that the twelve-week playbook above isn’t a heroic sprint — it’s just how the system works:

  • Controlled review and release, version control, and obsolete handling are built in, not bolted on.
  • Training is tied to each release, so the “prove they’re trained” question answers itself.
  • CAPA, customer feedback, audits, and management review live alongside your documents, so your evidence is connected, not scattered across folders and spreadsheets.
  • It flexes to how you actually work — there’s only one quality system worth running: yours — and we onboard your team directly instead of handing you a manual.

The result is what the Morning Star auditor saw: a system that looks like it’s been running for years, because everything is controlled, current, and one click from proof.

See an audit-ready ISO 9001 system on your own processes →

Frequently asked questions

What does ISO 9001 Clause 7.5 require?
Clause 7.5 (Documented Information) requires you to maintain the documents ISO 9001 mandates plus any others your quality system needs; to identify, format, and formally approve documents when creating or updating them (7.5.2); and to control them (7.5.3) — ensuring the current version is available where needed, changes and versions are controlled, obsolete copies are removed, records are retained, and external documents are managed.

Does ISO 9001 require a documented document-control procedure?
Not explicitly — ISO 9001:2015 dropped the old requirement for six mandatory procedures. You must control documented information (Clause 7.5.3), but you choose how. Most organizations still keep a short document-control procedure because it’s the simplest way to demonstrate consistent control to an auditor.

What counts as “documented information” in ISO 9001?
It’s the 2015 standard’s unified term for both documents (procedures, work instructions, policies, forms) and records (evidence of results — audit reports, CAPA records, training records, management review minutes). The same clause, 7.5, governs both.

How many documents does ISO 9001 require?
There’s no fixed number. Clause 7.5.1 ties the extent of documentation to your organization’s size, the complexity of its processes, and the competence of its people. A small contractor can be fully compliant with a lean set of well-controlled documents.

Can you really get ISO 9001 document control ready in three months?
Yes — with the right approach. Starting from templates, documenting how work actually happens, releasing documents under control, tying training to releases, and organizing the records you already have can produce an audit-ready system in about twelve weeks, as long as leadership is engaged and the tooling doesn’t fight you.


Want to see what an audit-ready ISO 9001 document control system looks like on your own procedures? Book a short walkthrough — bring one real process and we’ll show you controlled review, release, and training assignment live.

Simplify Compliance with Easy, Robust and AI-Powered QMS Software

Your business runs on a vast web of interrelated information, so your software systems should be able to do the same.