ISO 9001 Document Control Requirements: A Practical Guide for 2026

ISO 9001 Document Control Requirements: A Practical Guide for 2026

Document control is still where many ISO 9001 audits find their first nonconformity. The good news is that clause 7.5 of ISO 9001:2026 is almost the same as in the previous edition, so if your system worked before, it needs tuning rather than rebuilding. This guide sets out the ISO 9001 document control requirements as they stand in the 2026 edition, what auditors actually look for, and how to run a system your team will use.

What ISO 9001:2026 means by documented information

ISO 9001:2026 now defines a short list of core terms in clause 3 itself, including documented information (3.10). It covers three things: information about the management system and its processes, information you need to operate (what most people call documents, such as procedures and work instructions), and evidence of results achieved (records).

The standard keeps two phrasings with different meanings, and Annex A of the 2026 edition spells the difference out:

  • "Available as documented information" means the information must exist and be usable, for example your quality policy (5.2.2) or QMS scope (4.3).
  • "Documented information available as evidence of" means you retain objective evidence, for example competence records (7.2), audit results (9.2.2) or nonconformity records (10.2.2). That is a record requirement, not a legal evidence standard.

ISO 9001 document control requirements, clause by clause

7.5.1 What you must document

Your QMS must include the documented information the standard requires and whatever else you decide is necessary for the QMS to be effective. How much you need depends on your size, the complexity of your processes and how competent your people are. A ten-person machine shop with experienced operators does not need the same volume of procedures as a 500-person multi-site manufacturer.

7.5.2 Creating and updating documents

When you create or update documented information, make sure it has:

  • Identification and description: a title, date, author or owner, and a reference number.
  • Suitable format and media: language, software version, graphics, paper or electronic.
  • Review and approval: someone with authority checks it is suitable and adequate before release.

7.5.3 Controlling documents and records

Controlled information must be available and suitable for use where and when it is needed, and adequately protected against loss of confidentiality, improper use or loss of integrity. To achieve that you address, as applicable:

  • distribution, access, retrieval and use;
  • storage and preservation, including keeping it legible;
  • control of changes, such as version control;
  • retention and disposition.

Two further points auditors test often. Documents of external origin that you need for planning and operating the QMS (customer drawings, supplier specifications, regulations, standards) must be identified and controlled. And records kept as evidence of conformity must be protected from unintended changes. Annex A of the 2026 edition adds that this protection covers unauthorised alteration or deletion, and that obsolete documents you choose to keep must be controlled to prevent unintended use.

What changed for document control in the 2026 edition

Clause 7.5 itself is essentially unchanged. The practical changes come from elsewhere in the standard, because new requirements generate new documented information you will need to control:

  • 4.1: your determination of whether climate change is relevant, with its reasoning.
  • 4.2 c): which interested party requirements your QMS will address.
  • 6.1.2 and 6.1.3: separate records for risk actions and opportunity actions and how their effectiveness is evaluated.
  • 6.3: plans for QMS changes, including how they are communicated and how their results are reviewed.
  • 7.3 e): evidence that people are aware of your quality culture and expected ethical behaviour, typically through acknowledged communications or training.

See our ISO 9001:2026 clause by clause guide for the full list of revisions.

Documents vs records: a working example

TypeExampleKey control
Document (changes over time)SOP-PRD-04 Final inspection, rev. 6Approval before release, version history, obsolete revisions withdrawn
Record (evidence, should not change)Inspection report for batch 26-118Locked after completion, retention period, protected from alteration and deletion
External documentCustomer drawing DWG-4471 rev. CIdentified as external, current revision checked, distribution controlled

How to run document control that people actually use

One controlled location

A "controlled" procedure saved on a supervisor's desktop is the classic audit finding. Keep one source of truth that shop floor and remote staff can reach from a tablet or phone. Modern ISO document control software handles access rights, so people see the current version and only authorised users can change it.

Versioning and approval workflows

Increment revisions automatically on approval, archive the superseded version and record who approved what and when. Route documents to reviewers instead of chasing signatures by email. Electronic approvals are acceptable as long as each signature is attributable to one person and the document cannot be changed after approval without a new revision.

Link changes to their cause

Most procedure changes come from somewhere: a corrective action, an audit finding, a customer complaint or a planned QMS change under 6.3. Linking the revision to its source shows an auditor a closed loop. When a corrective action changes how work is done, your CAPA management software should point straight to the revised procedure.

Tell people what changed

Updating a document is only half the job. Clause 7.3 requires people to be aware of what affects their work, and 7.2 requires competence. Notify affected staff when a revision is released and keep a record that they read it, especially for safety-critical or customer-critical procedures.

Set retention periods on purpose

Decide retention per record type based on legal requirements, customer contracts and product life. Calibration certificates, training records, inspection reports and complaint files usually need different periods. Write them into one retention schedule rather than keeping everything forever.

Common pitfalls

  • Over-documenting: writing a procedure for every task buries the ones that matter. Focus on processes where inconsistency causes nonconformities.
  • Uncontrolled printouts: mark printed copies as uncontrolled or date-limited.
  • Editable records: completed inspection or audit records that anyone can still edit fail the protection requirement.
  • Forgotten external documents: superseded customer drawings at the point of use are a frequent major finding.

What auditors will ask to see

  • How you make sure only the current version is available where work is done.
  • How documents of external origin are identified and kept current.
  • Who can change controlled documents, and how completed records are protected from change or deletion.
  • The revision history of a document, including why it changed and who approved it.
  • The new 2026 records: climate change determination, interested party decisions, risk and opportunity actions, and planned QMS changes.

An ISO management software platform makes these demonstrations quick because the history, approvals and links already sit together. In ISO audit software, the same evidence can be pulled into the audit trail.

Frequently asked questions

What are the ISO 9001 document control requirements?

Clause 7.5 of ISO 9001:2026 requires you to identify, format, review and approve documented information, and to control its distribution, access, storage, changes, retention and disposal. External documents you rely on must be controlled, and records kept as evidence must be protected from unintended alteration.

Do we still need a quality manual?

No. The standard does not require one. Many organizations keep a short one because it helps new staff and auditors understand the system, but it is your choice.

How often should documents be reviewed?

The standard sets no frequency. Annual or two-yearly reviews are common, but review a document whenever the process changes, after a related nonconformity or audit finding, and when a planned QMS change affects it.

Are electronic signatures acceptable?

Yes. ISO 9001 is technology-neutral. An electronic approval works if it is attributable to a specific person, secure, and part of a controlled process that prevents changes after approval.

Did document control change in ISO 9001:2026?

Clause 7.5 barely changed. What changed is the set of things you now need to document and control, such as the climate change determination in 4.1, interested party decisions in 4.2 c) and separate risk and opportunity actions in 6.1.2 and 6.1.3.