Document version control for ISO 9001 quality management systems
What ISO 9001 clause 7.5 actually requires for document version control (identification, approval before issue, distribution control and retention) and how a document control chart proves it to an auditor.
A worked example, stage by stage
Identify, then approve before issue
Rows 1 to 8 are clause 7.5's “identify” and “approve before use”: “Raise a document change request” comes before anyone drafts, “Carry out technical review” and “Comments to resolve?” loop through “Update the draft against comments,” and “Approve for issue?” is the approval clause 7.5 requires before a document reaches anyone else.
The version number, the register, the withdrawal
Row 9, “Assign version and effective date,” is the identifier clause 7.5 names. Row 10 writes it to the master document register as a File row. Row 11 publishes to the controlled location. Row 12, “Withdraw superseded copies from use,” is the disposition control most document control processes leave out entirely.
Distribution and access, named as rows
Rows 13 to 16 are the distribution and access half of clause 7.5: “Training required for this change?” splits into “Complete training on the change” or “Read and acknowledge the new version,” and both converge on “Use the current controlled version,” the row that makes using anything else a nonconformity.
Retention and disposition close the loop
“Trigger the scheduled periodic review” and “Document still valid?” are the review interval clause 7.5 implies. “Valid” records the outcome and next date at row 19; “Revise” loops back to row 2 to open a new version; “Retire” reaches “Document withdrawn and retired”: disposition, the control most registers never actually exercise.
How it works
Give every document a unique identifier and a revision
Fix a numbering scheme (whole numbers for issued revisions, decimals for drafts) and print the identifier, revision, effective date and approver in the header of every page. This is the “identify” half of clause 7.5's documented-information requirement, and it's the first thing an auditor checks against the register.
Record approval before issue, not after
Route every new or revised document through a named reviewer and approver before it reaches its controlled location, and keep a record of who approved which revision and when. Clause 7.5 asks for approval for suitability and adequacy before use: a document already in circulation being approved retroactively is the finding, not the fix.
Publish to one authoritative location and register it
Every copy outside that one location is a control gap waiting to be found. Write the new revision to a master document register at the same step you publish it, so the register and the controlled copy can never drift apart.
Withdraw the superseded revision at the same step
Give withdrawal its own step immediately after publishing, and list every point of use the old revision reached: noticeboards, shared drives, supplier packs. A register that says revision 4 is current while revision 3 is still on the wall is the gap most audits actually find.
Set a review interval and record its outcome
Attach a review date to every controlled document and log the outcome (keep, revise or retire) rather than only refreshing the date. Clause 7.5's disposition requirement expects an ending, so “retire” has to be a reachable outcome on the chart, not an assumption off it.
Let QueryChart's version history stand as your evidence
Every edit to a chart or document built in QueryChart is a dated, attributed revision automatically. Open the Change Log to show a reviewer exactly what changed, use Compare Versions to put two revisions side by side for an auditor, and restore an earlier one if a revision needs reverting. See /features/version-control.
Frequently asked questions
What does ISO 9001 clause 7.5 actually require for document version control?
It requires documented information to be identified (a title, date, author and reference, the version), reviewed and approved for suitability before it is issued, and controlled for distribution, access, retrieval, storage, protection from unintended change, and retention and disposition. Version control is the identification, approval-before-issue and disposition parts of that list; distribution and access are a related but separate control clause 7.5 states next to it.
Is a written procedure still required for document control under ISO 9001:2015?
No. The 2015 revision dropped the six mandatory documented procedures the 2008 edition required, including the one titled “control of documents.” What clause 7.5 asks for now is the control itself, demonstrated through documented information (a register, a version scheme, an approval record) whether or not a procedure describes how you run it. See /guides/how-to-create-a-document-control-process for the fuller process a procedure would otherwise describe.
How is version control different from revision control, change control and document control?
Version control and revision control are the same idea under two names: knowing which iteration of a document is current. Change control is the decision that approves a change before it's made: the gate, not the record. Document control is the whole system clause 7.5 names, of which version control is one part; document management is the broader discipline of storing, finding and securing documents, version or no version. This page covers the version-control slice; /guides/how-to-create-a-change-control-process covers the change-control mechanics.
Is document version control for ISO 9001 the same as clause 4.4?
No. Clause 4.4 asks you to determine a process's inputs, outputs, sequence, interaction with other processes, criteria, resources, responsibilities and risks: process design, not documents. Clause 7.5 governs the documented information a process produces, including its version. A process map can satisfy part of 4.4 and still fail 7.5 if the map itself has no revision, no approval record and no register entry. See /guides/how-to-create-a-process-for-iso-9001 for the clause 4.4 side.
Does QueryChart's version history satisfy the ISO 9001 version control requirement?
For the identification, approval-before-issue and history side, yes: every save is a dated, attributed revision, the Change Log records who changed what, and Compare Versions and restore give you the evidence an auditor samples for, all in the free tier. See /features/version-control. What it does not do by default is enforce a hash-chained, tamper-evident audit trail against a named compliance framework: that's a separate, opt-in capability for organizations that need it, not something switched on for every chart.