Docordia
Document control under ISO 9001 clause 7.5: what you need
Published

General information, not legal advice. Always check the full text of the ISO 9001 edition your certification body audits against, and ask your registrar or consultant about your specific situation.
Ask a quality manager at a manufacturer in Rayong or Chonburi what takes up most of their week before a certification audit, and document control is usually near the top of the list. Not because the requirement is complicated, but because it touches every department: production, maintenance, purchasing, engineering, HR. A single outdated work instruction at one workstation is enough to raise a nonconformity.
This article explains what clause 7.5 of ISO 9001 actually asks for, how to tell documents from records, what to do with documents that come from outside the company, and the questions auditors tend to ask. It is written for QMRs, document control staff (often called DCC in Thai organisations) and managers who want a clear picture rather than a long consultant's manual.
What clause 7.5 "Documented information" covers
ISO 9001 uses one umbrella term, documented information, for anything the quality management system needs in written or digital form. Clause 7.5 has three parts:
- 7.5.1 General. The system must include the documented information the standard requires, plus whatever the organization decides it needs to work effectively. How much you need depends on your size, your processes and the competence of your people.
- 7.5.2 Creating and updating. Documents need proper identification and description (title, date, author or number), a suitable format and media (language, software version, paper or electronic), and review and approval for suitability and adequacy.
- 7.5.3 Control. Documented information must be available and suitable for use where and when it is needed, and adequately protected against loss of confidentiality, improper use or loss of integrity.
Under 7.5.3, the standard lists the activities you must address, as applicable:
- Distribution, access, retrieval and use
- Storage and preservation, including keeping it legible
- Control of changes (version control)
- Retention and disposition
- Documented information of external origin, identified and controlled
- Records protected from unintended alteration
Notice what is missing: there is no requirement for a quality manual, a specific numbering format, or a particular software tool. The standard tells you what outcome to achieve, not how to achieve it.
Documents vs records: why the difference still matters
In everyday shop-floor language, people separate the two:
| Documents | Records | |
|---|---|---|
| Purpose | Tell people what to do | Prove what was done |
| Examples | Procedures, work instructions, drawings, control plans, forms (blank) | Completed checksheets, calibration results, training logs, inspection reports |
| Changes | Revised through a controlled change process | Should not change after completion |
| Main risk | Someone uses an outdated version | Someone alters or loses the evidence |
The 2015 edition expressed this as "maintain" documented information (documents) and "retain" documented information (records). Even so, the practical distinction is still useful on the shop floor. A blank form is a document and goes through revision control; the same form once filled in is a record and must be protected from editing.
Documents of external origin
External documents are easy to forget because nobody inside the company writes them. Typical examples in a Thai organisation include:
- Customer drawings and specifications
- National standards such as TIS (มอก.) and international standards your products must meet
- Supplier data sheets and safety data sheets
- Equipment manuals from machine makers
- Thai laws and ministerial regulations that apply to your operations
The standard asks that these be identified as needed and controlled. In practice that means keeping a register of external documents, recording which edition you hold, assigning someone to check for updates, and making sure the current edition reaches the people who use it. A common audit finding is a customer drawing at the incoming inspection bench that is two revisions behind the one engineering received by email.
Questions auditors typically ask
Auditors rarely read your procedure from start to finish. They follow a trail and test whether the system works. Expect questions like these:
- "Show me the master list. How do you know this document is the current revision?"
- "Who approved this revision, and when? Where is the evidence?"
- "This work instruction changed last month. How did the operators find out? Were they trained?"
- "What happened to the old copies?"
- "How do you control the customer specifications you receive?"
- "How long do you keep inspection records, and where is that defined?"
- "Can someone edit this completed record after the fact?"
- "If the server failed tonight, how would you recover these files?"
They will then walk to the shop floor and compare what is posted at the workstation with what the register says. Printed copies are where most problems hide. If a copy at the line is not the current version and is not marked as uncontrolled, that is very likely a finding.
A practical checklist for clause 7.5
Use this list to test your own system before an internal audit:
- Master list exists and shows document number, title, current revision, effective date and owner for every controlled document.
- Approval is evidenced for every revision, with the approver's name and date.
- Change history explains what changed and why, not only that it changed.
- Old versions are withdrawn from points of use, or clearly marked if kept for reference.
- Printed copies are controlled: you know where controlled copies are, and uncontrolled copies are marked.
- Access matches roles: people can read what they need and edit only what they own.
- External documents have a register, an owner and a review routine.
- Retention periods for each record type are defined, along with how records are disposed of.
- Records cannot be quietly altered after completion.
- Backups are tested, not just scheduled.
- Training follows change: when a document is revised, affected people are informed or retrained, and you can show it.
If you can answer "yes, and here is the evidence" to each point, you are in good shape. The same discipline of approval, version control and traceability also underpins safety paperwork; see our article on what a permit to work is for an example outside quality.
When ISO 9001 is revised
This article follows the clause 7.5 structure of ISO 9001:2015, the edition most organisations have been audited against for years. ISO reviews every standard periodically, and when a new edition is published, the transition period is set through the accreditation system (IAF), and your certification body will tell you the dates that apply to you. The principles described above — identification, review and approval, distribution, version control, retention and handling of obsolete documents — are basic practice for any quality management system, whichever edition you are audited against.
To stay on top of it, ask your certification body which edition your next audit will use and what the transition dates are. When you have the full text of that edition, compare it clause by clause with your quality manual and document control procedure, and keep the comparison as evidence. Follow announcements from ISO (iso.org) and your own registrar rather than relying on general summaries. A sound document control system should need adjustment, not a rebuild.
Making clause 7.5 easier to live with
Most document control problems come from manual steps that depend on one person remembering: chasing signatures, updating a spreadsheet, collecting old copies, telling operators about a change. A system that ties approval, version status, distribution and training together removes much of that risk and makes audit evidence available in minutes.
Docordia is a document control and QMS system that runs in a web browser with a Thai interface, designed following ISO 9001 guidelines. It issues document numbers, keeps a register with status, and routes documents through approval paths you design and test-run before use. Every revision is kept and can be compared, issued files cannot be overwritten, and a new revision takes effect at final approval while the old one becomes obsolete automatically. An audit trail that cannot be edited or deleted records opening, downloading and printing, permissions go down to the document cabinet level, and read or training assignments are created when a new revision takes effect. On-premise installation is available.

Sources
Related articles
SAFEFLOW ·
What is a permit to work system?
How a permit to work system controls high-risk jobs in Thai workplaces: permit types, roles, lifecycle, handover, isolation, gas testing and SIMOPS.
Read more →
