Document control process flowchart
A document control process flowchart with Author, Reviewer, Approver, Document controller and End user lanes: drafting, approval, issue and periodic review.
How it works
Rename the lanes to your real roles
Replace Author, Reviewer, Approver, Document controller and End users with the roles you actually have, and name them by role rather than by person so the chart survives leavers and reorganisations. If your quality manager is both reviewer and document controller, merge those lanes instead of pretending they are separate. If technical and regulatory review are genuinely different people, split the Reviewer lane.
Define what counts as a controlled document
Write the scope next to the start of the process. Policies, procedures, work instructions, forms and templates are normally controlled; completed forms are records, which are retained and protected from alteration rather than revised. Decide how you handle documents of external origin, such as standards and supplier manuals, since those are identified and controlled but not authored by you.
Set your version and effective date rules
At the 'Assign version and effective date' step, fix a numbering scheme and stick to it, for example whole numbers for issued versions and decimals for drafts. Decide how much lead time the effective date needs so training can run and old copies can be pulled, and state what must appear on every page: document number, version, effective date and approver role.
Name the controlled location and the withdrawal points
Document control only works if there is one place a current version can live. Record where that is, then list every place an old version could survive: noticeboards, machine stations, shared drives, intranet pages, induction packs, supplier and customer copies. That list is what makes the 'Withdraw superseded copies from use' step executable rather than aspirational.
Decide when training is required, and what evidence you keep
Set the rule behind the training decision. A typographical fix usually needs nothing; a change to a safety-critical or regulated step usually needs training with attendance recorded. Everything in between is normally a read-and-acknowledge. Decide where that acknowledgement is stored, because it is the evidence that people are working to the current revision.
Set review intervals by risk and give each document an owner
One blanket interval either overloads the document controller or leaves critical documents stale. Set the interval by risk, for example annually for safety-critical work instructions and every two or three years for supporting policies, and add event-driven triggers for incidents, audit findings and process changes. Record the outcome even when nothing changes; a reviewed and unchanged document is controlled, an unreviewed one is not.
Frequently asked questions
What is a document control process?
It is the procedure that governs the lifecycle of documents that direct how work is done: how a new document or a change is requested, who drafts it, who reviews it, who approves it for use, how it is issued with a version number and effective date, how superseded copies are removed from circulation, and how it is reviewed at intervals until it is either revised or retired. The point is not paperwork; it is that anyone doing the work can find the current version and nobody can accidentally follow an old one.
Does this flowchart make us ISO 9001 compliant?
No diagram does that on its own, but it maps onto what clause 7.5 asks for. ISO 9001:2015 requires documented information to be reviewed and approved for suitability and adequacy before issue, identified and described, available and suitable for use where it is needed, controlled for distribution and access, version controlled, and covered by rules for retention and disposition. This chart puts a step or a decision against each of those. Note that the 2015 standard removed the 2008 requirement for a documented procedure for control of documents, so a written procedure is not mandatory in itself; you do still have to demonstrate the control. What an auditor tests is the evidence at each step, not the flowchart.
How often should controlled documents be reviewed?
ISO 9001 does not set an interval, so this is your decision to justify. Set it by risk: annually for documents covering safety-critical, regulated or high-turnover activities, and every two or three years for supporting policies that rarely change. Some frameworks are stricter, for example ISO/IEC 27001 expects policies to be reviewed at planned intervals and after significant change. Add event-driven triggers alongside the calendar, since an incident, an audit finding or a process change is a better reason to review than a date.
What is the difference between a controlled document and a record?
A controlled document tells people what to do and is expected to change: it is revised, reissued at a new version, and the old version is withdrawn. A record is evidence that something happened at a point in time, such as a completed checklist, a training log or a signed approval, and it is retained and protected from alteration rather than revised. They are managed differently, and mixing them is a common cause of confusion: version control belongs to documents, retention schedules belong to records. This process produces both, since the register entries and acknowledgements it generates are themselves records.