GeoBusinessIQGeoBusinessIQ

Documentation control: being able to produce the right version of the right record

What this answers

If an inspector asked for a specific record from a past production run, how long would it take us to produce it and could we prove it was unchanged?

Plenty of manufacturers do the right things and cannot prove it. Regulated environments judge a business partly on whether the current version of a procedure is the one in use, whether a record can be located when someone asks, and whether the file has been altered since approval. Document control is the unglamorous system that answers those questions. It separates controlled documents that tell people what to do from records that evidence what happened, and it treats the two differently in almost every respect.

Written for: quality systems managers, document controllers, regulatory affairs teams.

Documents instruct, records evidence, and they need different rules

A work instruction, specification, drawing or procedure is living: it has versions, an approver, an effective date and a distribution. A batch record, calibration certificate, training log or inspection result is fixed at the moment it was created and should never be edited afterwards. Systems that treat both the same way produce the two classic failures: instructions that keep circulating after they were superseded, and records that somebody corrected quietly. Draw the distinction explicitly in the system design, because everything downstream — approval routes, retention, access rights — follows from which category a file belongs to.

Version control fails at the printer, not in the system

Most sites have a controlled repository and a shop floor covered in printouts, laminated sheets, photographs on phones and a copy taped inside a machine cabinet. The repository can be immaculate while the operator follows a sheet from two revisions ago. Effective control means knowing where copies exist, having a defined route for withdrawing them when a revision is issued, and making the current version genuinely easier to reach than the pinned copy. Screens at the workstation solve part of this and create their own problem when the network is down and nobody planned for it.

Retention, retrieval and the file nobody can find

Retention periods are set by regulators, contracts and product life, and they differ across the same site: employment records, calibration history, batch documentation and technical files can each be governed by a different clock. The harder requirement is retrieval. An inspector asking for a specific record expects it within a reasonable interval, and an archive of unindexed boxes in a mezzanine does not meet it. Test retrieval periodically with a real request, including for a period covered by a system you have since replaced, which is where most searches actually collapse.

Electronic records raise questions paper never did

Once records live in software, regulators become interested in who can create, amend and delete them, whether changes are logged with author and time, how signatures are attributed to individuals, and whether the data can still be read when the system is retired. Shared logins destroy attribution and are still common on production terminals. Spreadsheets used as record systems are difficult to control because anything can be changed without trace. These are not reasons to stay on paper, but they are reasons to specify the controls before selecting a system rather than after.

Where the expectations come from and how far they vary

Management system standards describe control of documented information in general terms; sector regulators go considerably further for records affecting product safety, and their published inspection findings are the most informative reading available on what falls short in practice. Because the applicable expectations depend on your sector, your markets and the systems you use, this description is orientation rather than instruction. Confirm retention periods and record integrity requirements with the authority that regulates your products, and with counsel where employment or personal data records are involved. Whatever the sector, a retention rule somebody can actually recite beats one filed in a policy nobody opens.

Frequently asked questions

Can we keep production records only in electronic form?
Many regulators accept electronic records provided the system controls who can change what, logs changes with attribution, protects against loss, and allows records to be retrieved and read for their full retention period. The practical barriers are usually shared accounts, uncontrolled spreadsheets and systems that will not be readable after migration. Check the position for your sector and market, and plan for how data will survive the eventual replacement of the software holding it.
How should a correction to a completed record be made?
The general principle is that the original entry stays visible: the error is struck through rather than erased, the correction is added with who made it and when, and a reason is given where the change is substantive. In electronic systems the equivalent is an audit trail that preserves the prior value. What causes real damage is overwriting, backdating or rewriting a record neatly, because it converts an honest mistake into a question about the integrity of everything else you hold.
Who should own document control in a mid-sized plant?
It needs someone with authority to refuse to release a document that has not been approved, which usually means the quality function rather than an administrator reporting to production. The role is part librarian and part gatekeeper: maintaining the register, running the approval route, controlling distribution and withdrawal, and managing the archive. Splitting ownership between departments tends to produce parallel systems with different versions of the same procedure.

Data limitations

  • Worker safety, machinery safety, chemical handling and hazardous-materials duties are set by the law of the jurisdiction and by the risk assessment for the specific workplace. Material here explains the mechanism only and is not a safety determination, a risk assessment, or legal advice.
  • Standards are referenced, never reproduced. Pages describe what a standard governs and point to the issuing body; they do not restate its requirements, and conformity is determined by the standard itself and by an accredited assessment, not by anything here.
  • Manufacturing figures are operator-supplied inputs, not market data. GeoBusinessIQ holds no factory costs, production volumes, yields, cycle times, tooling prices or capacity data and does not estimate them — every result reflects only the figures you enter.

Explore the graph

Sources

  • International Organization for Standardization ISO (accessed )
    Covers: International standards for quality management, environmental management, occupational health and safety, and industrial processes.
    Does not cover: The content of any standard, conformity decisions, or certification status of any organisation.
    Why it matters: Cited so a reader can reach the issuing body's own public description of a standard. Standard text is never reproduced here.
    Review cadence: annual
  • United States Food and Drug Administration FDA (accessed )
    Covers: United States regulation of medical devices, pharmaceuticals, food and cosmetics, including manufacturing practice requirements.
    Does not cover: Product approvals for your product, inspection outcomes, or requirements outside United States jurisdiction.
    Why it matters: Cited only for the regulated sectors it actually governs, where manufacturing practice is set by the regulator.
    Review cadence: annual

Educational and operational information only — not legal, engineering, safety, customs, tax, or financial advice. Requirements vary by jurisdiction, product, process, and contract; confirm with the relevant authority or a qualified professional before acting.

Last updated: