Controlled document management: approvals, revisions, distribution and keeping people on the current version

Procedures, work instructions, forms and specifications only help if people use the right version. How to control documents through approval, revision, distribution, training and review.

An auditor walks onto the factory floor and finds three versions of the same work instruction: a laminated copy at the machine from four years ago, a printout in the team leader’s folder from last year and the current version on the shared drive that nobody on the floor can reach. The operator follows the laminated copy, which still specifies a setting that was changed after a customer complaint. The procedure had been fixed; the fix never reached the person doing the work.

Controlled documents, such as procedures, work instructions, forms, policies, specifications, inspection plans and safe work method statements, are how a business captures and shares the right way to do things. Their value depends entirely on people using the current, approved version. Document control is the set of practices that makes that happen: identifying documents, approving them before use, managing revisions, distributing them to where work is done, withdrawing old versions, training people on changes and reviewing documents so they stay accurate.

This article explains what controlled documents are and how they differ from records, what document control requires, the life cycle of a document, how to number, approve, distribute and review documents, how to communicate changes, how to manage documents from outside the business, how to choose a document management system and how to write documents people actually use. It is general information for quality, operations and safety managers.

Documents and records

Quality management distinguishes two kinds of information:

DocumentsRecords
PurposeDescribe how things should be doneProvide evidence of what was done
ExamplesProcedures, work instructions, forms, specifications, policiesCompleted forms, inspection results, training records, audit reports
ChangeRevised and re-approved over timeNot changed after completion, except by controlled correction
Control focusCurrent version in use, old versions withdrawnAccuracy, protection, retention and retrieval

A blank inspection form is a document; a completed inspection form is a record. Both need control, but in different ways.

What document control requires

Quality management standards such as ISO 9001 require organisations to control the documented information their management system needs. In practical terms, control means that documents are:

  • Identified, with a title, number, revision and owner.
  • Reviewed and approved for suitability before issue.
  • Available where and when they are needed.
  • Protected from unintended changes, loss and inappropriate access.
  • Distributed in a controlled way, so the current version reaches users.
  • Changed through a controlled process, with revisions identified.
  • Withdrawn when superseded, so obsolete versions are not used by mistake.
  • Retained or disposed of according to defined rules.

These principles apply whether or not a business is certified to a standard. They are simply what it takes for documents to be trusted.

The document life cycle

  1. Draft: the owner prepares or revises the document, ideally with input from the people who do the work.
  2. Review: subject experts and users check accuracy and practicality.
  3. Approve: an authorised person approves it for use.
  4. Issue: the approved version is published to its controlled location, and the previous revision is withdrawn.
  5. Communicate and train: affected people are told what changed and trained where necessary.
  6. Use: the document is available at the point of work.
  7. Review periodically: the owner confirms it remains accurate, at set intervals or when triggered.
  8. Revise or withdraw: changes go back through the cycle; documents no longer needed are withdrawn and archived.

Identification and revisions

Each controlled document needs:

  • A unique number, issued from a register, never reused.
  • A clear title describing its subject.
  • A revision identifier, such as a letter or number, and the date of issue.
  • An owner responsible for its content.
  • A document type, such as procedure, work instruction, form or policy.

A change history within the document or system records what changed in each revision and why. The designing identifiers and check digits article discusses principles for numbering schemes that also apply to documents.

Keep the document set lean

Many businesses accumulate far more controlled documents than they can maintain: procedures nobody follows, forms no longer used and instructions for equipment long since sold. Every document carries a maintenance cost, so withdraw what is no longer needed and combine overlapping documents. A smaller set of accurate, used documents is worth more than a large library of outdated ones.

Approval and review

Decide who may approve each type of document, typically the process owner for work instructions, a manager for procedures and senior management for policies. Approval should confirm both technical accuracy and practicality.

Documents also need periodic review, commonly every one to three years depending on risk, and triggered review when:

  • Processes, equipment, materials or products change.
  • An incident, complaint, nonconformity or audit finding shows the document is inadequate.
  • Regulations, standards or customer requirements change.
  • Users report that the document is unclear or wrong.

A review that confirms a document is still correct should be recorded too, so the review date is visible.

Distribution and access

The most reliable approach is a single controlled source: one location, usually electronic, holding the current approved version of each document, with read-only access for users. Practical measures include:

  • Access at the point of work, such as tablets or terminals on the shop floor, or codes on equipment that open the relevant instruction on a phone.
  • Printed copies marked as uncontrolled, with a print date and a statement that the user must check the current version, when printing is unavoidable.
  • Controlled printed copies, numbered and registered, where electronic access is impractical, with a process to replace them on revision.
  • Prompt withdrawal of superseded versions from all locations.

Communicating changes and training

A revised document changes nothing until people know about it. For each revision:

  • Summarise what changed, not just that a new version exists.
  • Identify who is affected, using roles or a training matrix.
  • Decide what is needed: awareness only, a briefing or formal retraining.
  • Record acknowledgement or training, where the change is significant.
  • Check in practice, for example through supervision or audits, that the new method is used.

Forms, drawings and safety documents

Forms

Forms are controlled documents too. A checklist or inspection form that changes revision but remains in circulation in its old version produces records that miss new checks. Print the form number and revision on every form, withdraw old stocks of printed forms when a revision is issued, and prefer electronic forms where practical, because they can only be completed in their current version and produce records that are easier to search.

Drawings and specifications

Engineering drawings and specifications are usually controlled through engineering or product data systems, with their own revision rules. On the shop floor, the same principles apply: production should work only from released drawings at the current revision, superseded drawings should be withdrawn or clearly stamped, and drawings sent to suppliers should be tracked so they can be replaced when revised. Mismatched drawing revisions between engineering, production and suppliers are a common cause of nonconforming parts.

Safety documents

Work health and safety documents need particular care because people rely on them to stay safe. Under work health and safety laws, high-risk construction work generally requires a safe work method statement, which must be kept available on site and reviewed when the work or its risks change. Emergency procedures, permits to work, isolation procedures and chemical safety information must also be current and accessible to the people who need them. Treat these as controlled documents with owners, review triggers and clear withdrawal of old versions.

Documents from outside the business

Businesses also rely on external documents: standards, regulations, customer specifications, supplier instructions, safety data sheets and manufacturers’ manuals. These need control too:

  • A register of external documents, with the edition or revision in use and its source.
  • A process to check for updates, such as subscriptions to standards notifications or regular checks of supplier information.
  • Current safety data sheets for hazardous chemicals, accessible to workers who use them, as work health and safety laws require.
  • Clarity about which edition applies when contracts or regulations reference a particular version. The which edition of a standard applies article explains why that question matters.

Records and retention

Records produced from controlled forms must be protected, retrievable and kept for defined periods, set by legal requirements, customer contracts and business needs. Obsolete documents may also need to be retained for a period, marked clearly, to show what instructions applied at a given time, for example in an investigation or claim. The keeping business records for the long term article covers retention schedules and archiving.

Choosing a document management system

ApproachSuitsStrengthsLimitations
Structured shared drive with a registerVery small businessesSimple, low costManual control; easy to bypass; weak audit trail
Collaboration platform with document librariesSmall and medium businessesVersion history, permissions, approval workflowsNeeds configuration and discipline
Quality management softwareBusinesses with formal quality systemsIntegrated approvals, training links, review reminders, audit trailsSubscription cost; setup effort
Product data managementEngineering drawings and modelsRevision control linked to CAD and bills of materialsSpecialised; usually engineering-focused

Useful features include approval workflows, automatic revision numbering, review reminders, read-only publishing, links to training records, audit trails, search, and access from mobile devices on the floor. Whatever the tool, the discipline of owners, approvals and withdrawal matters more than the software.

Writing documents people use

Control is wasted on documents nobody reads. Usable documents are:

  • Short and specific, focused on one task or process.
  • Written for the user, in plain language and the terms used on the floor.
  • Visual, with photos, diagrams and examples of acceptable and unacceptable results.
  • Structured as steps, with key points and reasons for critical steps.
  • Tested with users before approval.
  • Located where the work happens.

Measuring document control

A few simple measures show whether document control is working:

  • Documents overdue for review, as a share of the total.
  • Obsolete documents found in use during audits or walk-throughs.
  • Time from approval to availability at the point of work.
  • Acknowledgements outstanding for significant changes.
  • Nonconformities or incidents where a document was a contributing cause.

Short floor walks, in which a supervisor or quality officer checks a sample of documents at workstations against the controlled source, are one of the quickest and most revealing checks.

Common mistakes

  • Multiple uncontrolled copies in folders, on walls and on desktops.
  • Revisions that never reach the floor.
  • No summary of changes, so users cannot see what is different.
  • Documents without owners, never reviewed.
  • External documents not tracked, so outdated standards or data sheets remain in use.
  • Long, text-heavy procedures nobody reads.
  • Treating completed records like documents, editing them after the fact.

A worked example

This is an illustrative example. A food manufacturer with 90 staff and a certified food safety system keeps procedures and work instructions on a shared drive, with printed copies in folders at each production area. An internal audit finds that about a quarter of the printed work instructions on the floor are out of date, and that two safety data sheets for cleaning chemicals are more than five years old.

Changes. The business moves controlled documents into a document library with approval workflows, automatic revision numbering and review reminders. Each document has an owner and a review interval based on risk. Tablets mounted at each production area display current work instructions, and laminated copies are withdrawn. Remaining printed copies are marked uncontrolled with a print date. Every revision includes a short summary of changes, and affected staff acknowledge significant changes on the tablets, with training records updated automatically. A register of external documents, including safety data sheets, is set up, with the purchasing officer responsible for requesting current versions from suppliers.

Clean-up. Before migrating, owners review every document. About 30% are withdrawn as obsolete or duplicated, and several long procedures are rewritten as short, illustrated work instructions tested with operators.

Result. The next audit finds no obsolete instructions in use. Supervisors report that operators look up instructions more often because they are easier to find, and changes after incidents reach the floor within a day rather than weeks.

Applying this in an Australian business

  • List controlled documents with numbers, revisions and owners.
  • Approve before use and record approvals.
  • Publish from a single controlled source, read-only to users.
  • Make documents available at the point of work.
  • Withdraw superseded versions everywhere.
  • Summarise changes and train affected people.
  • Track external documents, including standards and safety data sheets.
  • Review documents periodically and after incidents or changes.

Questions worth considering

  • How many versions of our key work instructions exist on the floor today?
  • How does a revised procedure reach the people who use it?
  • Which documents have not been reviewed in years?
  • Are our safety data sheets and referenced standards current?
  • Would our operators find our procedures useful, or just long?

Bringing it together

Controlled documents capture the right way to do things, but only when people use the current approved version. Identify each document, approve it before use, publish it from a single controlled source at the point of work, withdraw old versions, communicate changes and train people, track external documents, review regularly and write documents that users find helpful. Good document control turns hard-won improvements into everyday practice.


Source: KEVOS editorial notes, drawing on general quality management, work health and safety and document control practice. Standards and legal requirements are summarised for orientation. The worked example is illustrative. This article is general information.

Need practical engineering, manufacturing or process support? KEVOS can help move the work forward.