Doxis Blog  ECM & Archive

Stay compliant with ISO 9001 document control software from Doxis

| Marc Volquardsen

A woman smiling while using a laptop, with a document and certification visible.

 

Effective document control ensures that quality-related documents are versioned, reviewed, approved, and archived in a revision-proof manner. It is the information foundation that compliance, audits, and a working Quality Management System (QMS) all depend on.

Without a structured process, outdated work instructions stay in circulation, approvals become impossible to trace, and audit findings pile up.

A Document Management System (DMS) closes those gaps with standardized workflows, role-based access, and automatic versioning.

Doxis Quality Management builds that control directly into a digital QM manual preconfigured for ISO 9001:2015 and ISO 13485:2016, so the standard's requirements are enforced by the system itself.

Key takeaways

  • Maintain version control: Keep only approved document versions in circulation
  • Control approvals: Document roles, responsibilities, and review steps clearly
  • Meet ISO 9001 requirements: Clause 7.5 requires documented information to be controlled and traceable
  • Reduce audit risks: Keep changes, storage, and archiving transparent and verifiable
  • Run it on Doxis: A preconfigured ISO 9001 QM manual automates the workflows, versioning, and archiving this article covers

What is document control?

Document control is the systematic management and governance of documents throughout their entire lifecycle—from creation and review to legally compliant retention and disposal. In DIN EN ISO 9001:2015, this process is referred to as the control of documented information and is defined in Clause 7.5 (Sections 7.5.1–7.5.3). It is one of the core principles of quality management.

A controlled document is:

  • Clearly identified and easy to read.
  • Available in its latest approved version.
  • Authorized through a defined approval workflow.
  • Protected against unauthorized changes through appropriate access controls.

Documents vs. records: what’s the difference?

While ISO 9001:2015 groups both documents and records under the umbrella term documented information, ISO 13485, the quality management standard for medical devices, distinguishes between them.

Documents are controlled, editable files that define requirements, instructions, or procedures. Records, by contrast, provide permanent evidence that a process or activity has been completed and cannot be altered once created.

Aspect Document Record
Purpose Provides instructions or requirements Serves as evidence of completed activities
Content Policies, procedures, and work instructions Results of activities or processes
Can it be changed? Yes, through controlled version revisions No, once created it must remain unchanged
Examples Standard operating procedures (SOPs), work instructions, process descriptions, forms, quality manuals Inspection reports, meeting minutes, audit records

A blank audit questionnaire is a document, once someone fills it in and files the results, it becomes a record.

Doxis draws the same line automatically: a QM document under active editing carries a workflow status, while a finalized record is locked and moved into audit-proof archiving, where it can no longer be edited, only retrieved.

What are the stages of the document control process?

Hey Doxi, can you explain the document control process?

The document control process consists of seven sequential stages that together represent the complete lifecycle of a document:

  1. Create: Draft the document with a unique identifier, author, version, and date. Doxis creates Version 1 on save and records that metadata automatically.
  2. Review: A designated reviewer checks accuracy and compliance. Doxis routes this through an approval workflow that assigns the reviewer and logs every comment.
  3. Register: Add the document to the DMS register. With Doxis, this step disappears: documents are already centrally stored and searchable.
  4. Update: Increment the version and restrict access to obsolete copies. Doxis keeps full version history, visible to employees and traceable for auditors.
  5. Approve: The QMR signs off before release. Doxis logs every approval, rejection, and condition automatically.
  6. Archive: Store the document in a revision-proof archive. Doxis is IDW PS 880-certified, which also verifies GoBD conformance.
  7. Dispose: Delete the document once retention expires, per GoBD and GDPR. Doxis applies the right schedule and flags disposition automatically.

What are the objectives of document control?

Fast, reliable retrieval: Every document has a defined storage location and a unique identifier, so the correct version turns up in seconds instead of a shared drive search.

A service representative fielding a product question can pull up the current operating manual before the customer finishes explaining the issue, because Doxis indexes documents centrally.

Constant availability: Employees reach the documents relevant to their work without waiting on a manual handoff or a disconnected system.

Protection against unauthorized change or deletion: Revision-proof archiving and role-based access stop unauthorized edits before they happen. Every change is logged with its author, date, and type, building the audit trail an ISO assessor will ask to see.

Run ISO 9001 document control without the manual work

See how a preconfigured QM manual handles versioning, approvals, and audit-proof archiving for you.

Why is document control important?

Document control governs how documents get created, reviewed, distributed, and disposed of, in a way that can be traced later. It also protects something harder to rebuild than a missing file: institutional knowledge. When a long-tenured employee leaves, a well-documented process survives them. A folder full of undated Word files does not.

The gap shows up fastest in day-to-day operations, not in the audit itself.

Without document control With document control
Multiple document versions circulate, creating confusion. Clear version control ensures everyone works with the latest approved version.
No defined approval process. Clearly defined roles and workflows govern document review and approval.
No secure, compliant archiving. Legally compliant, revision-proof archiving reduces audit findings and the risk of penalties.
No systematic knowledge repository. Comprehensive documentation preserves organizational knowledge during staff turnover.

 

The most common ISO 9001 document control audit findings

During ISO 9001 audits, nonconformities often arise not because documents are missing, but because their control cannot be clearly demonstrated. Common audit findings include outdated document versions, missing approvals, unclear responsibilities, or undocumented changes.

Common audit finding Cause How a DMS helps
Outdated document version in circulation No clear version control The latest approved version is made centrally available.
Missing approval No defined approval workflow Automated review and approval workflows ensure proper authorization.
Changes cannot be traced No revision history Every modification is automatically logged in an audit trail.
External documents are outdated No assigned ownership Responsible users and review intervals are clearly defined and monitored.
Unclear retention period Missing or incomplete metadata Retention periods are documented, managed, and automatically monitored.

With an effective Document Management System (DMS), document control becomes an integral part of daily operations rather than a last-minute task before an audit. This continuous approach helps organizations maintain compliance, improve traceability, and stay audit-ready at all times.

ISO 9001 document control requirements

ISO 9001:2015 sets out the requirements for controlling documented information in Clause 7.5, one of the most frequently cited clauses in audit findings because organizations rarely define versions, approvals, or storage locations clearly enough to defend them.

The clause has three parts:

  1. Clause 7.5.1 – General: The Quality Management System (QMS) requires documented information in more than 20 sections of the standard. Unlike previous versions, the 2015 revision no longer requires a quality manual.
  2. Clause 7.5.2 – Creating and Updating: Every document must have a unique identifier, including its title, date, author, and version number. Before a document is issued—or after it has been updated—it must be reviewed and approved by an authorized person.
  3. Clause 7.5.3 – Control of Documented Information: This subclause defines the core requirements for document control. It covers document availability, protection, distribution, access, storage, retention, and disposal throughout the entire document lifecycle. It also applies to external documents, such as industry standards and customer specifications.

Relevant documents:

ISO 9001 does not name specific document types. It applies to whatever documented information matters to the QMS: process descriptions, SOPs, work instructions, forms, reports, audit records, meeting minutes, and management review documents.

An appropriate format:

Documents must be clear, legible, and uniquely identified, with title, date, author, and version number attached so they can be tracked through their lifecycle.

Availability:

The right people need access at the right time, for both internal documentation and external documents like legal regulations and customer requirements.

Protection:

Organizations have to guard documented information against unauthorized access, alteration, or loss, while keeping it usable for the people who need it.

Review and approval:

Every document is reviewed and formally approved before release and after each update, with the outcome documented as evidence.

Traceability:

This is where most audit findings originate. Organizations need to track who changed what and when, keep version control intact, run defined approval workflows, and archive in a revision-proof way.

ISO 9001 does not dictate who reviews or approves documents, or how often, but defining that internally, and letting the system enforce it, is what separates a QMS that survives an audit from one that only looks good on paper.

Document control template: a checklist to get started

A document control template captures the fields ISO 9001:2015 Clause 7.5 expects to see. Get these consistently filled in and you have covered the fundamentals.

Field Description
Document name and ID A unique identifier for the document within the system.
Version number and date Indicates the current revision status of the document.
Author, reviewer, and approver The responsible individuals or roles, identified by name or initials.
Scope of applicability Specifies the relevant department, process, or location.
Retention period Defines the required legal and internal retention period.
Storage location and access rights Specifies the document's location in the Document Management System (DMS) and the authorized user groups.

A spreadsheet can hold these fields. It cannot enforce them. Doxis attaches them as metadata to every document automatically and keeps them consistent for the life of the document, so the template stops being a manual checklist and becomes how the system already works.

ISO-compliant document control with Doxis

Every requirement in Clause 7.5 maps directly onto a Doxis Quality Management document: unique identifiers, review and approval, traceability, revision-proof archiving.

The platform ships preconfigured for ISO 9001:2015 and ISO 13485:2016, with a digital QM manual and built-in workflows for editing, review, approval, publication, and deviation management.

Version control, approvals, and retention stop being separate manual tasks. They become one system tracking the document from draft to disposal.

Document control is also one piece of a larger platform. The same Doxis platform that runs your QM manual automates inbound processes like supplier certificate intake and connects directly to SAP.

That means a nonconformance raised on the shop floor can trigger a document update without anyone re-keying it into a second system.

For US manufacturers running SAP, this is where a generic document control system falls short: Doxis is document control software for SAP specifically, not a bolt-on connector.

For US organizations, that same platform is built to hold up under SOX and FDA 21 CFR Part 11, alongside IDW PS 880 certification (which also verifies GoBD conformance) for European entities, so a single global company doesn't need separate archiving systems per region.

  • Preconfigured ISO 9001:2015 and ISO 13485:2016 structure, so you are not building a QM manual template from scratch
  • Automated review, approval, and publication workflows for every QM document
  • Full version history that keeps every superseded version restricted and available for audit
  • Audit trails that log every change, approval, and access event without manual entry
  • US-compliant retention covering SOX and FDA 21 CFR Part 11, plus IDW PS 880 certification (which also verifies GoBD conformance) for global operations
  • One platform across ECM, workflow automation, and AI-powered document processing, so QM documents connect to the same SAP and ERP processes

Doxis was named a Leader in the 2026 Gartner® Magic Quadrant™ for Document Management for the second consecutive time. If your last audit turned up a version nobody could explain, that is worth fixing before the next one. Request a free demo to see your QM manual running on Doxis.

Run ISO 9001 document control without the manual work

See how a preconfigured QM manual handles versioning, approvals, and audit-proof archiving for you.

Document control FAQs

What is document control?

Document control is the systematic management of documents throughout their entire lifecycle—from creation and approval to version control, compliant archiving, and secure disposal. ISO 9001:2015 defines this process as the control of documented information in Clause 7.5.

What is a controlled document?

A controlled document is clearly identified, easy to read, and available in its latest approved version. It has been authorized through a defined approval process and is protected against unauthorized changes through access controls. This ensures compliance with the requirements of ISO 9001:2015 Clause 7.5.

What is document control in quality management?

In quality management, document control ensures that all quality-related information remains accurate, traceable, and compliant with applicable standards. It is a core requirement of ISO 9001:2015 and forms the foundation for successful quality management system (QMS) audits and certifications.

What is the difference between document control and document management?

Document management focuses on storing, organizing, and retrieving documents throughout their lifecycle. Document control goes a step further by ensuring that documents are reviewed, approved, version-controlled, distributed, and archived according to defined procedures and compliance requirements. Effective document control requires clearly defined workflows, assigned roles, complete version histories, and secure, revision-proof archiving.

Which documents are subject to document control under ISO 9001?

ISO 9001 does not prescribe a fixed list of controlled documents. Instead, any document that is relevant to the effectiveness of the Quality Management System (QMS)—such as procedures, work instructions, forms, reports, or audit records—should be managed through a controlled process.

When is a document considered controlled?

A document is considered controlled when it is clearly identified, available in its latest approved version, and accessible to authorized users when needed. Version control, approval workflows, and access restrictions ensure that unauthorized changes cannot occur. The document must also be retained and archived in accordance with applicable legal and organizational requirements.

Does document control software support US compliance requirements like SOX or FDA 21 CFR Part 11?

Yes, a document control system built for US compliance needs to support these alongside ISO 9001. Doxis supports SOX recordkeeping requirements for public companies and FDA 21 CFR Part 11 for electronic records and signatures in regulated industries, in addition to ISO 9001:2015 and ISO 13485:2016.

What is the difference between a record and a document?

Documents are editable files that define requirements, procedures, or instructions and are updated through controlled revisions. Records, on the other hand, provide permanent evidence that an activity or process has been completed. While documents evolve through version control, records remain unchanged after creation to preserve their integrity and traceability.

Marc Volquardsen

I am a Product Manager & Solution Architect and have been with Doxis since 2004. After 15 years as a Solution Consultant for Sales, in 2020 I switched to Product Management, where I design solutions for customers based on Doxis, SAP and Salesforce. Please feel free to contact me to talk about solutions for you!

You might also be interested in

How can we help you?

+49 (0) 30 498582-0
What is the sum of 4 and 8?

Your message has reached us!

We appreciate your interest and will get back to you shortly.

Contact us

Table of contents