How to control documents and records

Control current instructions through review and issue; protect completed records through identification, retention, retrieval and authorized disposition.

Control documents as current instructions that can be revised, and control records as evidence of work that must remain retrievable and protected.

The short version

  • Use review, approval, revision and withdrawal for live instructions and blank forms.
  • Use identification, protection, retrieval and retention rules for completed records.
  • Keep the source document revision with the record when that context matters later.

Two kinds of information need different controls

A blank inspection form is a controlled document: its layout can be revised and a superseded blank should leave use. A completed inspection form is a record: editing it to match a new form revision would damage the evidence. Both need an owner and access rules, but only the former has a current issue to publish.

Place the distinction at the point where a controlled form becomes a completed record. The document register identifies which form revision was effective; the record index says where a completed instance is held, how long it is kept and who may correct or dispose of it. Link the two identifiers so a reviewer can reconstruct which instruction governed the work.

Follow a controlled form into use

The chart controls the blank form through issue; its use creates records governed by a separate retention rule.

  1. Approve the blank form

    Author, reviewer and approver determine the form fields and authorize an identified issue before anyone records work on it.

  2. Publish and withdraw

    The controller enters the new issue in the register, publishes it and removes superseded blank copies from points of use.

  3. Preserve completed instances

    After users complete the form, retain those dated records under the record schedule even when the blank form later changes.

How it works

  1. Classify the item

    Ask whether it directs future work or proves completed work. A blank form is the former; each completed instance is the latter.

  2. Write separate control rules

    For documents, define approval, current-copy access and withdrawal. For records, define owner, location, access, retention period and authorized disposition.

  3. Link the evidence

    Where needed, put the effective document ID and revision on the completed record so later reviewers can connect the evidence to the instruction in force.

Mistakes to avoid

  • Replacing evidence when a form changes

    Reissue the blank form, but preserve completed instances under the retention rule that applied to the records.

Related QueryChart feature

Explore version history and change tracking

Map the document handoff

Adapt the control chart and add the point where a blank form becomes a retained record.

Map the document handoff

Frequently asked questions

Is a completed checklist still a controlled document?

Its blank template is a controlled document; the completed checklist is a record of an activity and needs record controls.

Can a record be corrected?

Follow the applicable correction rule so the original entry, correction, person and date remain traceable.

Should records appear in the document register?

The controlled form can. Use a record schedule or index for completed instances, linked by ID where reconstruction matters.

The template behind this guide

Document control process flowchart — A document control process flowchart with Author, Reviewer, Approver, Document controller and End user lanes: drafting, approval, issue and periodic review.

More in Process Governance, Compliance, Audit & Version Control Guides

More in Process mapping guides

Browse all Process Governance, Compliance, Audit & Version Control Guides