A document control procedure is the document that controls all your other documents. It’s the one an auditor tends to open first — because it defines how your quality system keeps every procedure current, approved, and provable. ISO 9001 (Clause 7.5) and ISO 13485 (Clause 4.2.4) require you to control your documented information; the document control procedure is where you write down exactly how you do it. Get it right and it quietly runs your document lifecycle. Copy a generic template you don’t actually follow, and it becomes the first finding of your audit.
This is a practical guide to what your document control procedure has to cover, how to write one that fits your company, and the mistakes that turn a good intention into an audit finding.
On this page
What a document control procedure is (and why auditors open it first)
Think of it as the rulebook for your documents. It answers a simple set of questions for every controlled document in your system: How is it created and identified? Who reviews and approves it before it’s used? How is a change made? How does the current version stay unmistakable and obsolete ones get pulled? How long are records kept?
Auditors start here because it’s the fastest way to test whether your control is real or aspirational. If the procedure says one thing and your actual documents tell a different story, that gap is exactly what they’re looking for. So the golden rule is: write what you actually do, and do what you write.
What your document control procedure must cover
A complete document control procedure addresses each of these — mapped to what ISO 9001’s Clause 7.5 and ISO 13485’s 4.2.4 require:
- Purpose and scope. What the procedure governs (which documents, which sites).
- Responsibilities. Who owns document control, who is authorized to review, approve, and release.
- Document identification. How documents are numbered, titled, and revision-labeled so each one is uniquely identifiable.
- Creation and format. Templates, required fields (title, author, date, revision), and the media used.
- Review and approval. Documents are reviewed and approved for suitability before use — by whom, and how the approval is recorded (increasingly, electronic signatures).
- Distribution and access. How the right people get the current controlled version, and who has access.
- Change control. How a change is proposed, reviewed, and approved — as a controlled event, not an in-place edit.
- Version and revision control. How the current revision stays unmistakable and prior versions are archived, not presented as current.
- Obsolete-document control. How superseded documents are removed from use so no one works from an old copy.
- Records and retention. What records are kept and for how long (in medical devices, tied to the lifetime of the device).
- Control of external documents. How standards, regulations, and customer specifications are identified and kept current.
If your procedure covers those eleven areas clearly, it will stand up to an audit. If it’s missing obsolete-document control or change control, those are the gaps auditors find most often.
How to write a document control procedure, step by step
- Start from how you actually work — not a generic template. Downloaded templates are a fine skeleton, but a procedure that describes an idealized process you don’t follow is worse than a simple one you do. Map your real flow first.
- Interview your process owners. The people who create and use documents know where control actually breaks. Their reality belongs in the procedure.
- Keep it as simple as your risk allows. ISO scales expectations to your size and complexity. A small firm needs a lean, clear procedure — not a 40-page epic no one reads.
- Write one document control procedure, not ten. One authoritative procedure that covers the eleven areas above beats scattered rules across multiple documents.
- Define roles by function, not by name. “The Quality Manager approves,” not “Jane approves” — so the procedure survives staff changes.
- Make the current version obvious and obsolete control explicit. These are the two areas that fail most audits; spell them out.
- Review and approve the procedure itself under its own rules. It’s a controlled document too — practice what it preaches.
Common document control procedure mistakes
- The copy-paste template. A procedure describing a process you don’t follow is an instant credibility gap in an audit.
- Over-engineering. Complexity you can’t sustain becomes non-compliance the moment reality diverges from the paperwork.
- No real obsolete control. “We keep old versions” isn’t the same as removing them from use.
- Training disconnected from releases. If your procedure requires training on the current revision but you track it on a spreadsheet, expect a finding.
- A procedure no one can find or follow. If it lives in a folder nobody opens, it isn’t controlling anything.
From a written procedure to a system that enforces it
Here’s the honest limitation of any document control procedure: it describes control, but it can’t enforce it. A procedure can say “obsolete documents are removed from use,” but on a shared drive or in a binder, that still depends on a person remembering to do it. This is exactly where a written procedure meets its ceiling — and where software takes over.
Document control software turns the rules in your procedure into behavior the system enforces automatically: version control, approval workflows, obsolete-document handling, training tied to each release, and an audit trail that generates your evidence as you work. If you’re at the point of writing (or rewriting) your procedure, it’s worth understanding what document control software does and, if you’re evaluating options, how to choose the right one for a small or mid-sized firm.
See a document control system that enforces your procedure automatically →
Frequently asked questions
What is a document control procedure?
A document control procedure is a controlled document that defines how an organization creates, identifies, reviews, approves, distributes, changes, and retires all of its other controlled documents — meeting the document-control requirements of standards like ISO 9001 (Clause 7.5) and ISO 13485 (Clause 4.2.4).
What should a document control procedure include?
Purpose and scope; responsibilities; document identification; creation and format; review and approval before use; distribution and access; change control; version and revision control; obsolete-document control; records and retention; and control of external documents.
Does ISO 9001 require a document control procedure?
ISO 9001:2015 requires you to control documented information (Clause 7.5) but doesn’t mandate a specific written procedure. ISO 13485, however, explicitly requires a documented procedure for document control. Most organizations keep one regardless, because it’s the simplest way to demonstrate consistent control to an auditor.
How do you write a document control procedure?
Start from how your team actually works, interview process owners, keep it as simple as your risk allows, define roles by function, and be explicit about the two areas auditors probe most — obsolete-document control and change control. Then approve and control the procedure under its own rules.
Do you need software for document control?
Not to write the procedure — but a procedure only describes control; it can’t enforce it. For anything beyond a handful of documents, software is how you make the rules in your procedure automatic and provable, rather than dependent on everyone remembering them.
Ready to turn your document control procedure into a system that runs itself? Book a short walkthrough — bring your procedure and we’ll show you how the rules on paper become automatic in practice.