Document control provides a structured way to identify, review, approve, distribute, update, retain, and retire important organisational documents.
It is particularly useful where multiple people work with the same information and where using an outdated document could create operational, quality, contractual, financial, safety, compliance, or customer-service problems.
Use this template as a framework for establishing control over individual documents or as part of a broader document management system.
The level of control should match the importance and risk associated with the information being managed.
Start by establishing a unique identity for the document.
Document Title:
[Insert document title]
Document Number:
[Insert unique document number]
Document Type:
[Policy / Procedure / Manual / Work Instruction / Report / Specification / Form / Template / Other]
Department or Function:
[Insert responsible department]
Business Area:
[Insert business area]
Document Owner:
[Insert responsible person or role]
Document Controller:
[Insert responsible person or role]
Current Version:
[Insert version]
Document Status:
[Draft / Under Review / Approved / Superseded / Obsolete]
State why the document exists.
A useful purpose statement should explain:
Purpose:
[Insert purpose statement]
Define the boundaries of the document.
Explain:
Scope:
[Insert scope]
Identify the people expected to use the document.
Primary Users:
[Insert users]
Secondary Users:
[Insert users]
Approvers:
[Insert roles]
Reviewers:
[Insert roles]
Other Stakeholders:
[Insert stakeholders]
Assign an appropriate classification to the document.
Possible categories include:
Classification:
[Insert classification]
Reason for Classification:
[Explain why this classification applies]
Identify who is accountable for the document’s content.
Document Owner:
[Insert name or role]
Owner’s Responsibilities:
Clearly assign responsibilities.
Responsible for the accuracy, relevance, and continued suitability of the document.
Responsible for administrative control, version management, distribution records, and document status.
Responsible for evaluating technical, operational, legal, quality, or business accuracy as appropriate.
Responsible for authorising the document for official use.
Responsible for using the current authorised version and reporting errors or required changes.
Maintain a record of significant changes.
| Version | Date | Description of Change | Prepared By | Reviewed By | Approved By |
|---|---|---|---|---|---|
| 0.1 | [Date] | Initial draft | [Name] | [Name] | [Name] |
| 0.2 | [Date] | [Change] | [Name] | [Name] | [Name] |
| 1.0 | [Date] | Initial approved version | [Name] | [Name] | [Name] |
The revision history should allow a reader to understand how the document has developed.
Establish a consistent versioning method.
For example:
Major Version:
Use when substantial changes affect the purpose, scope, requirements, or use of the document.
Minor Version:
Use for limited changes that do not fundamentally alter the document.
Draft Version:
Use a clearly identifiable draft numbering convention before approval.
The organisation should select one numbering method and apply it consistently.
Every controlled document should have a clear status.
Possible statuses include:
Draft
The document is being developed and has not been authorised for official use.
Under Review
The document is undergoing formal review.
Approved
The document has completed the required approval process.
Superseded
A newer approved version has replaced the document.
Obsolete
The document is no longer required for operational use.
Withdrawn
The document has been deliberately removed from circulation.
Identify who prepares the document and how source information is obtained.
Author:
[Insert name or role]
Subject-Matter Contributors:
[Insert names or roles]
Source Information:
[Identify source documents, data, standards, requirements, interviews, records, or other inputs]
Preparation Method:
[Describe preparation approach]
Define who must review the document before approval.
Potential review areas include:
Review Area:
[Insert area]
Reviewer:
[Insert role]
Review Date:
[Insert date]
Review Result:
[Accepted / Accepted with Changes / Rejected / Further Review Required]
Comments:
[Insert comments]
Identify the person or authority authorised to approve the document.
Approving Authority:
[Insert role]
Approval Criteria:
[Describe criteria]
Approval Date:
[Insert date]
Approval Method:
[Electronic / Written / System-Based / Other]
Approval Evidence:
[Insert reference]
Record when the approved document becomes applicable.
Effective Date:
[Insert date]
Implementation Deadline:
[Insert date if applicable]
Transition Requirements:
[Describe transition arrangements]
Identify where the controlled document is made available.
Possible distribution channels include:
Distribution Location:
[Insert location]
Authorised Users:
[Insert user groups]
Distribution Method:
[Insert method]
Where physical or specifically controlled copies are used, record them.
| Copy Number | Location | Custodian | Issue Date | Status |
|---|---|---|---|---|
| [001] | [Location] | [Name/Role] | [Date] | Current |
| [002] | [Location] | [Name/Role] | [Date] | Current |
Define how controlled physical copies are identified.
Determine how unofficial copies are treated.
An uncontrolled copy may be:
Uncontrolled Copy Statement:
[Insert applicable statement]
Users should understand that an uncontrolled copy may not reflect the latest approved version.
Define who can view, edit, approve, distribute, or delete the document.
| Role | View | Edit | Review | Approve | Distribute | Retire |
|---|---|---|---|---|---|---|
| Document Owner | Yes | Yes | Yes | [Yes/No] | [Yes/No] | [Yes/No] |
| Document Controller | Yes | [Yes/No] | [Yes/No] | No | Yes | Yes |
| Reviewer | Yes | [Yes/No] | Yes | No | No | No |
| Approver | Yes | No | Yes | Yes | No | No |
| General User | Yes | No | No | No | No | No |
Adjust permissions to match the organisation’s actual control system.
Identify the authoritative storage location.
Primary Repository:
[Insert location]
Backup Repository:
[Insert location]
Owner of Repository:
[Insert role]
Access Restrictions:
[Describe restrictions]
Backup Frequency:
[Insert frequency if applicable]
Identify the authoritative version.
Master Document Location:
[Insert location]
Master Document Owner:
[Insert role]
Master Version:
[Insert version]
System of Record:
[Insert system]
Users should know where the authoritative version is maintained.
All material changes should be documented.
Change Request Number:
[Insert number]
Requested By:
[Insert name]
Request Date:
[Insert date]
Requested Change:
[Describe proposed change]
Reason for Change:
[Explain reason]
Impact of Change:
[Describe expected impact]
Urgency:
[Low / Medium / High / Critical]
Before approving a change, consider its potential effect.
Evaluate:
Assessment:
[Insert assessment]
Risk Level:
[Insert risk level]
Additional Actions Required:
[Insert actions]
Record the decision regarding the proposed change.
Change Decision:
[Approved / Approved with Conditions / Rejected / Deferred]
Decision Maker:
[Insert name or role]
Decision Date:
[Insert date]
Conditions:
[Insert conditions]
A change to one document may affect other documents.
Review related:
Related Documents Reviewed:
[Insert list]
Changes Required:
[Insert changes]
Record important dependencies.
Related Process:
[Insert process]
Related System:
[Insert system]
Related Policy:
[Insert policy]
Related Procedure:
[Insert procedure]
Related Form:
[Insert form]
External Requirement:
[Insert requirement]
When a new version is released, the previous version should be controlled appropriately.
Actions may include:
Superseded Version:
[Insert version]
Replacement Version:
[Insert version]
Withdrawal Date:
[Insert date]
Define how long the document and relevant records should be retained.
Retention Period:
[Insert period]
Retention Basis:
[Legal / Regulatory / Contractual / Operational / Historical / Other]
Retention Owner:
[Insert role]
Disposal Method:
[Insert approved method]
Retention requirements should be consistent with applicable organisational and legal requirements.
When a document reaches the end of its retention period, document its disposal.
Document Identifier:
[Insert identifier]
Disposal Date:
[Insert date]
Disposal Method:
[Insert method]
Authorised By:
[Insert name or role]
Disposal Record:
[Insert reference]
Sensitive information should be disposed of using an appropriate method.
Define when the document must be reviewed.
Normal Review Interval:
[Insert period]
Next Scheduled Review:
[Insert date]
The review interval should reflect the document’s importance and rate of change.
A document may also require an unscheduled review when:
Record the results of periodic reviews.
| Review Date | Reviewer | Findings | Changes Required | Result |
|---|---|---|---|---|
| [Date] | [Name] | [Findings] | [Changes] | [Result] |
| [Date] | [Name] | [Findings] | [Changes] | [Result] |
A review does not always require a new version. However, the review decision should be recorded where the control system requires evidence.
Before approval, verify:
For organisations managing multiple controlled documents, maintain a central register.
| Document Number | Document Title | Version | Owner | Status | Effective Date | Next Review | Location |
|---|---|---|---|---|---|---|---|
| [Number] | [Title] | [Version] | [Owner] | [Status] | [Date] | [Date] | [Location] |
| [Number] | [Title] | [Version] | [Owner] | [Status] | [Date] | [Date] | [Location] |
The register provides an overview of the organisation’s controlled documentation.
A change log can provide more detail than the revision history.
| Change ID | Date | Document | Section | Change | Reason | Requested By | Approved By |
|---|---|---|---|---|---|---|---|
| [ID] | [Date] | [Document] | [Section] | [Change] | [Reason] | [Name] | [Name] |
Use the change log where detailed traceability is required.
Some situations may require a document to be updated urgently.
Examples include:
Where emergency changes are permitted, establish a controlled process for:
Emergency Change Reference:
[Insert reference]
Reason:
[Insert reason]
Temporary Measures:
[Insert measures]
Follow-Up Review Date:
[Insert date]
For electronically controlled documents, consider:
The specific controls should reflect the organisation’s systems and risk profile.
Where physical documents are important, establish controls for:
Physical control may be particularly relevant where electronic systems are unavailable or where original documents have special evidentiary value.
For confidential or sensitive documents, consider additional safeguards.
Possible controls include:
Do not include sensitive credentials, passwords, security keys, or unnecessary personal information in the document control record.
Projects often generate large numbers of documents.
Project document control may cover:
Each document should have a clear relationship to the project and its relevant approval process.
Technical documentation may require additional controls for:
Technical changes should be evaluated for their impact on related procedures and operational activities.
Where documents form part of a quality management system, consider:
The control process should support traceability and consistent use of approved information.
Business documents that may benefit from control include:
The objective is to ensure employees use current and authorised information.
Where documentation is used by external service providers, define:
Clear control is especially important when different organisations work from shared procedures.
When a document changes, determine whether users require training or communication.
Training Required:
[Yes / No]
Affected Users:
[Insert users]
Training Method:
[Insert method]
Training Completion Date:
[Insert date]
A document change that materially alters how work is performed may require more than simply publishing a new version.
Define how important changes are communicated.
Possible methods include:
Communication Method:
[Insert method]
Responsible Person:
[Insert role]
Communication Date:
[Insert date]
Periodically verify whether the document control system is functioning as intended.
Audit areas may include:
Audit Date:
[Insert date]
Auditor:
[Insert name]
Findings:
[Insert findings]
Corrective Actions:
[Insert actions]
Watch for:
Create a consistent naming method.
A possible format is:
DocumentNumber_DocumentTitle_Version
Example:
OPS-001_Customer-Service-Procedure_V2.0
Another approach may use:
Department_DocumentType_Number_Title_Version
Example:
FIN_PROC_004_Expense-Approval_V1.2
Choose one naming convention and document it.
Where electronic systems support metadata, consider recording:
Consistent metadata can make large document collections easier to search and manage.
Before introducing a document control system, determine:
A document control system should make it possible to answer the following questions:
If these questions cannot be answered reliably, the document control process may need improvement.
For additional resources, explore:
This template provides a general framework for document control and should be adapted to the organisation’s document types, systems, risk profile, contractual obligations, and applicable requirements.
Not every document requires the same level of control. High-risk, regulated, safety-related, contractual, technical, or operational documents may require more formal controls than routine working documents.
The objective is to ensure that people can reliably identify, access, use, review, update, and retire the correct information at the appropriate time.
Effective document control ultimately supports accuracy, traceability, consistency, accountability, and reliable access to current information.