Skip to main content
v2026.11,610 entries · CC-BY 4.0

Document Control Procedure: The Six-Stage Lifecycle

How a document control procedure governs draft, review, approval, distribution, revision, and withdrawal for controlled documents in a GxP quality system — and the exact record each stage has to leave for an audit.

Ask about Document Control Procedure: The Six-Stage Lifecycle

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Written and maintained by CASRAI Editorial Board

Last updated

A document control procedure is the process that governs every other controlled document on site — SOPs, work instructions, specifications, forms, the quality manual itself. That creates an obvious trap: the procedure describing how documents get drafted, reviewed, approved, distributed, revised, and withdrawn has to survive the same discipline it imposes on everything else. An auditor who finds the document-control SOP itself running on an unreviewed draft, or without its own version history, has found the fastest possible way to distrust every other controlled document in the building.

This guide treats document control as its own lifecycle with six discrete stages — draft, review, approval, distribution, revision, and obsolescence/withdrawal — and, separately, as the source of a specific set of records an auditor will actually go looking for.

What a Document Control Procedure Governs

Document control governs controlled documents: the instructions that tell people what to do — policies, standard operating procedures (SOPs), work instructions, specifications, drawings, forms and templates, and the quality manual that sits above them. It is a distinct discipline from record control, which governs the completed evidence that those instructions were followed — a filled-in batch record, a signed training log, a calibration certificate.

ISO 13485:2016 keeps the two separate on purpose: clause 4.2.4, “Control of documents,” and clause 4.2.5, “Control of records,” are adjacent but distinct requirements — see CASRAI’s quality manual guide for how clause 4.2.2 requires the manual to describe the document structure this procedure then has to actually deliver. ISO 9001:2015 folds the same discipline into clause 7.5.3, “Control of documented information,” under the Annex SL high-level structure, and ISO/IEC 17025:2017 requires it of a testing or calibration laboratory’s management-system documents at clause 8.3. Under the US medical device Quality Management System Regulation (QMSR), the legacy 21 CFR 820.40 “Document Controls” requirement is now reserved, with ISO 13485:2016’s clause carrying the obligation directly by reference as of February 2, 2026.

Where This Procedure Sits in the Document Hierarchy

A document control procedure doesn’t stand alone; it governs a hierarchy, and it needs to say explicitly which tier a given document belongs to and who is authorized to approve at each tier:

  • Policy / quality manual — the top-level statement of scope and process interaction (see the quality manual guide).
  • Procedures / SOPs — the controlled documents this guide is centrally about.
  • Work instructions and forms/templates — the detail layer beneath a procedure, often revised more frequently than the procedure that references them.
  • Records — the executed evidence, governed separately (record control, not document control).

The same layered logic shows up in narrower form elsewhere in a quality system — CASRAI’s validation master plan guide walks the analogous policy → VMP → validation plan → protocol → summary report chain for validation documentation specifically.

Draft

Every controlled document starts with a unique identifier — a document number that never gets reused, even after the document is withdrawn — and a draft version marker (commonly 0.1, distinct from the 1.0 a first approval produces). The draft stage should record: the assigned owner/author, the tier the document belongs to, which upstream policy or procedure it implements, and, for a revision rather than a new document, what triggered the change and a reference back to the prior approved version.

Review

Review is a distinct step from approval, not a formality folded into it. A technical or subject-matter review confirms the content is correct and workable; a quality/QA review confirms it meets the document-control procedure’s own formatting, hierarchy, and cross-reference requirements. Where a document affects more than one function — a change to a sampling SOP that also touches QC release criteria, for example — review should be cross-functional, and review comments need to exist as a record, not as a verbal exchange the document owner incorporated from memory.

Approval

Approval is restricted to a named, authorized role — typically defined in an authorization matrix, not left to whichever manager happens to be available. A document’s status changes from draft to approved-and-effective only at the point of formal, dated approval; nothing changes status by being “basically done.” Where approval is captured electronically rather than on paper, the electronic signature has to meet 21 CFR Part 11’s requirements for FDA-regulated records — permanently linked to the record it signs, and carrying the identity, meaning, and date/time of the signing action.

Effective Date and Controlled Distribution

The effective date is not the same as the approval date, and treating them as identical is a common finding. The gap between the two exists specifically so that the people expected to follow the document can be trained on it first — a procedure cannot reasonably be “in effect” for staff who haven’t yet been told it changed. Setting the effective date to allow training to complete beforehand, and confirming that training actually happened before that date, is itself part of the control.

Distribution then has to distinguish controlled copies — tracked against a distribution list, replaced (not just supplemented) on every revision — from uncontrolled or reference copies, which should be visibly marked (e.g. “UNCONTROLLED IF PRINTED”) precisely because a printed copy stops tracking revisions the moment it leaves the printer.

Revision

A revision is triggered by a defined event — commonly a separate change-control process, a periodic review finding, a deviation or CAPA, or a regulatory update — not an ad hoc edit to the working file. Each revision gets a new version number; the prior version is superseded, not silently overwritten, and the document itself should carry a revision history section summarizing what changed and why. A revision restarts the same draft → review → approval → distribution cycle in full — there is no shortcut version of the lifecycle for a “minor” change, even a single-word correction, because the record of who reviewed and approved that specific change is what an auditor is actually checking for.

Obsolescence and Withdrawal

When a document is retired — the procedure it describes is discontinued, or fully replaced by a new one — it has to be formally withdrawn, not simply left to lapse. That means: the controlled document register status changes to obsolete with a recorded date, active controlled copies are retrieved, and the document is prevented from ordinary use going forward. ISO 13485:2016 clause 4.2.4 and ISO 9001:2015 clause 7.5.3 both require, in substance, the prevention of unintended use of obsolete documents, and suitable identification of any obsolete document that is deliberately retained for a defined purpose (commonly, historical traceability of what specification or SOP version was in effect for a given batch, run, or study). That means obsolete versions are archived, not destroyed — discarding them defeats the traceability the whole system exists to provide.

Periodic Review

A document control procedure should also require documents to be reviewed on a defined cycle even when nothing has triggered a revision — confirming the content is still accurate, the referenced roles/titles/systems still exist, and cross-references to other documents haven’t gone stale. Periodic review with no changes found should itself be recorded (a review date and outcome, even “no change required”), otherwise there is no evidence the review happened at all.

The Record This Process Itself Must Leave

An auditor testing document control isn’t reading the SOP’s prose — they’re tracing a specific document through the system and checking that every stage above left evidence. The minimum record set:

  • Master document list / controlled document register — document number, title, current version, status, effective date, and owner for every controlled document, in one place.
  • Revision history per document — what changed, when, and why, at each version.
  • Review and approval records — who reviewed, who approved, and on what date, distinct roles both evidenced.
  • Distribution log — which controlled copies exist, where, and confirmation superseded copies were retrieved on revision.
  • Training records tied to the specific document version — and dated before the document’s effective date, not after.
  • Obsolete-document archive — retained, clearly marked, for the organization’s defined retention period.

Where the system is electronic rather than paper, the register above is typically generated by the system itself, but the system then has to be validated as fit for that purpose (see CASRAI’s computer system validation guide) and, if it carries FDA-regulated electronic signatures, needs an audit trail meeting 21 CFR Part 11. EU GMP Annex 11 states the same expectation from the EU side: a record of all GMP-relevant changes and deletions, reviewed regularly and convertible to a generally intelligible form — see CASRAI’s Annex 11/15 guide for the full clause set.

What an Auditor Actually Checks

In practice, an auditor picks a document at random and works it end to end: is the copy physically in use at the bench the current approved version, or an earlier one someone kept out of habit? Does the register’s effective date match what training records show staff were trained on, and did training complete before that date rather than after? Is there a documented review and a separately documented approval, or does the file only show a single signature covering both? Are the copies marked obsolete actually retrieved, or still sitting in a binder next to the current version?

The findings that recur across regulated labs are rarely about the procedure’s content — they’re gaps in exactly this evidence trail: an uncontrolled personal copy still in active use, training dated after the effective date, an approval with no separate review record behind it, or a revision history with a version missing from the sequence.

Paper vs. Electronic Document Control

An electronic document management system (part of an eQMS, or a standalone module) can automate version control, route review and approval, capture electronic signatures, and trigger training assignments the moment a document goes effective — closing the training-before-effective gap almost mechanically. None of that is free of obligation, though: the system itself has to be validated for its intended use (see the CSV/GAMP 5 guide and, for a lab-notebook-specific example of the same validation logic, the ELN validation guide), and if it relies on electronic signatures to satisfy a regulatory approval requirement, Part 11’s audit-trail and signature-linkage requirements apply to it directly, not just to the documents it stores.

Frequently Asked Questions

What is a document control procedure?

It is the controlled procedure that governs how every other controlled document — policies, SOPs, work instructions, specifications, forms — is drafted, reviewed, approved, distributed, revised, and eventually withdrawn, and it defines what record each of those steps has to leave behind.

What’s the difference between document control and record control?

Document control governs the instructions (what people are told to do); record control governs the evidence that the instructions were followed (what people actually did). ISO 13485:2016 treats them as two adjacent but separate clauses — 4.2.4 for documents, 4.2.5 for records — precisely because the two need different handling: documents get superseded and withdrawn, while records get retained as a permanent, unaltered account of what happened.

Who should approve a controlled document?

Whoever is named for that document type in the organization’s authorization matrix — a defined role, not any available manager. The approver should be distinct from whoever performed the technical review, so approval isn’t the only evidence a document was actually checked.

How long should obsolete or superseded documents be retained?

There is no single retention period that applies universally — it depends on the organization’s records retention schedule and the regulatory framework in force (product lifecycle, study duration, or a specific regulatory minimum). What is universal is the requirement itself: obsolete versions are archived for traceability, not deleted, so that whoever is auditing a historical batch, run, or study can confirm which document version was actually in effect at the time.

Does a small lab need a formal document control procedure?

Yes, if it operates under any accreditation or regulatory framework that requires one — ISO/IEC 17025 accreditation, GLP/GCP/GMP compliance, or a medical-device quality system under ISO 13485/QMSR all require it regardless of headcount. The scale of the procedure can be proportionate to the lab’s size, but the six stages and the underlying record set don’t become optional because the organization is small.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 44,322 indexed passages, and every answer cites the ones it drew on.