What Is the Difference Between Document Control and Record Control?

What Is the Difference Between Document Control and Record Control?

Document control manages information that tells people what to do, while record control manages evidence that shows what was done. A procedure, work instruction, blank form, or specification is normally a document. A completed form, inspection result, training log, or approval record is normally a record.

ISO 9001:2015 groups both under the term documented information. The practical distinction still matters because working documents must stay current, while records must preserve trustworthy evidence. Clauses 7.5.2 and 7.5.3 address how documented information is created, updated, available, protected, changed, retained, and disposed of.

What Is the Difference Between a Document and a Record?

Documents and records may sound alike, especially when both are electronic files, but there is a big difference between the two. Documents are created by planning what needs to be done. Records are created when something is done and record the event. The easiest test is to ask whether the information directs future work or proves that past work occurred.

Document Definition

Document: Information used to support an effective and efficient organizational operation.

A controlled document communicates an approved plan, requirement, or method. Common quality management system documents include the quality policy, quality objectives, QMS scope, organization chart, process maps, business plans, control plans, internal audit schedules, procedures and work instructions, approved supplier lists, purchasing criteria, and customer requirements.

Documents can be revised as the organization learns. Document control makes that change deliberate: the appropriate people review and approve the revision, identify its status, distribute the current version, and prevent unintended use of an obsolete version.

Users need legible, up-to-date, and readily available documents to do their jobs. Review, approval, revision status, communication, and access controls help ensure that anyone following a document can find the accurate, approved version.

Record Definition

Record: Evidence about a past event or a result achieved.

A record is generated during the operation of the QMS. Records consist of data collected while work is performed, such as a completed inspection form, calibration result, audit report, supplier evaluation, training record, or management review output. Record control protects the integrity and traceability of that evidence.

Records are protected against unauthorized or unintended alteration, but that does not mean an error can never be corrected. A controlled correction should keep the initial entry or audit trail traceable, identify the change, and follow applicable legal, customer, and organizational rules.

How Does PDCA Help Explain the Difference?

A simple way to understand the difference is through the Plan, Do, Check, Act cycle. Documents often originate in the planning phase of the process approach and define the intended process. Doing and checking often produce records that show what happened and what results were obtained. Acting on those results may lead to a controlled document revision. This is a practical analogy, not a rule that every document belongs only to Plan or every record belongs only to Do. ISO’s process approach guidance describes PDCA as a method that can manage processes and systems.

Control questionDocumentRecord
PurposeDirect or support workProvide evidence of work or results
Typical timingCreated before or while defining the activityCreated when the activity or decision occurs
Change behaviorRevised through review, approval, version control, and releasePreserved as evidence; corrections remain traceable
ExamplesPolicy, procedure, work instruction, blank form, specificationCompleted form, audit result, training log, approval, inspection result
Primary control emphasisAdequacy, approval, current version, access, and change communicationIdentification, integrity, protection, retrieval, retention, and disposition
Comparison of controlled documents with completed quality records

How Do Document Control and Record Control Differ?

With a better understanding of what documents and records are, the different control requirements become clearer.

What Does Document Control Require?

ISO 9001:2015 clause 7.5.2 addresses creating and updating documented information. It covers appropriate identification and description, suitable format and media, and review and approval for suitability and adequacy. Clause 7.5.3 then applies availability, protection, access, storage, change control, retention, and disposition requirements to documented information. The ISO/TC 176 guidance on documented information explains how organizations apply these requirements.

  • Identify the document, owner, revision, and approval status.
  • Review and approve it before use.
  • Make the correct version legible and readily available where needed.
  • Control distribution, access, retrieval, and use.
  • Review and update it when requirements or processes change.
  • Identify changes and prevent unintended use of obsolete versions.

What Does Record Control Require?

Records need to remain identifiable, stored, protected, retrievable, retained, and disposed of under control. In practical terms, they should be labeled, protected from corruption, and available when users need the data. The retention period and disposition method should reflect legal, regulatory, contractual, customer, and operational needs. Backup can support protection and recovery, but backed-up data alone is not a retention policy.

  • Identify the record and connect it to the relevant activity, product, person, or decision.
  • Protect it from loss, damage, unauthorized access, and unintended alteration.
  • Keep it readable and retrievable for the required retention period.
  • Control any correction so the original information and change history remain traceable.
  • Dispose of it securely when the approved retention rule permits.

Which Controls Apply to Both?

Both documents and records are documented information, so both need appropriate identification, access, protection, storage, and preservation. The difference is emphasis. A working document must reliably communicate the current approved direction. A record must reliably preserve evidence. Reviewing common document-control audit findings can help identify where these controls break down in practice.

What Documented Information Does ISO 9001:2015 Require?

ISO 9001:2015 does not specifically require a quality manual or the earlier minimum set of six documented procedures. It requires certain documented information and also requires each organization to determine what additional documentation is necessary for an effective QMS. The amount and form can vary with the organization’s size, activities, process complexity, and employee competence, as described in the official documented-information guidance.

Information Maintained to Support the QMS

The guidance identifies the QMS scope, documented information needed to support process operation, the quality policy, and quality objectives as information the organization maintains. Other useful QMS documents can include organization charts, process maps, process descriptions, procedures, work instructions, specifications, production schedules, approved supplier lists, purchasing criteria, customer requirements, test and inspection plans, quality plans, forms, and a quality manual when the organization chooses to use one. A Control Plan used in Advanced Product Quality Planning, or APQP, is another industry-specific example.

These planning and support materials are still subject to document control. For example, a blank inspection form is a document because its fields and instructions direct how an inspection should be recorded. Once an employee completes and approves that form, the completed instance becomes a record.

Information Retained as Evidence

The standard also requires organizations to retain evidence in several areas, where applicable. These are clause-specific obligations, and the records needed depend on the organization’s processes and circumstances.

  • Clause 4: documented information needed to have confidence that the processes have been carried out as planned.
  • Clause 7 Resources: evidence of fitness for purpose of monitoring and measurement resources, the basis used for calibration or verification where measurement traceability is required and standards do not exist, and evidence of competence.
  • Clause 8 Operation: results of the review of requirements related to products and services; design and development inputs, controls, process outputs, and changes; results of external-provider evaluations, performance, and re-evaluations; unique identification of process outputs where traceability is a requirement; notice of customer property damage; results of the review of production changes and the personnel authorizing the change; the person or authority authorizing release for delivery; and actions taken on nonconforming process outputs, products, and services, including any concessions obtained.
  • Clause 9 Performance Evaluation: results that demonstrate monitoring and measurement activities were implemented in accordance with determined requirements, evidence of the audit program and audit results, and evidence of the results of management reviews.
  • Clause 10 Improvement: nonconformities, subsequent actions taken, and results of corrective action.

What Happened to the Old Six Procedures?

ISO 9001:2008 guidance separately called for documented procedures covering 4.2.3 Document Control, 4.2.4 Record Control, 8.2.2 Internal Audit, 8.3 Nonconforming Product Control, 8.5.2 Corrective Action, and 8.5.3 Preventive Action. ISO 9001:2015 consolidated the first two concepts under clause 7.5 and removed the prescribed six-procedure structure. The separate preventive-action clause was also removed, with preventive intent addressed through risk-based thinking across the QMS.

How Can You Apply Document and Record Control in Practice?

Consider an inspection procedure. First, the process owner drafts the procedure and blank form. The appropriate reviewers approve them, document control releases the current version, and employees use it at the point of work. When an employee performs an inspection, the completed form becomes a record. Record control identifies it, protects it, makes it retrievable, retains it for the approved period, and disposes of it securely when permitted.

  1. Draft and identify the procedure and blank form.
  2. Review and approve them for suitability and adequacy.
  3. Release the current version and control access.
  4. Perform the work and capture the completed record.
  5. Protect, retrieve, and retain the record according to the retention schedule.
  6. Revise the working document when the process changes, while preserving the prior record history.
Document and record control lifecycles shown as separate workflows

The distinction is simple: documents tell people what should happen, and records show what did happen. Strong control keeps the instruction current and the evidence trustworthy. You can also review how to create QMS procedures and download free ISO 9001 policy and procedure samples as a starting point.

Frequently Asked Questions

What Is the Simplest Difference Between a Document and a Record?

A document tells people what to do or what requirement to follow. A record provides evidence that an activity, decision, approval, or result occurred.

Can the Same File Be a Document in One Context and a Record in Another?

Yes. A blank inspection form is a controlled document because it directs data collection. A completed copy of that form is a record because it preserves evidence of the inspection.

Can an ISO 9001 Record Ever Be Corrected?

A record can be corrected under a controlled method that protects its integrity. The original entry or audit trail should remain traceable, and the change should follow applicable legal, customer, and organizational rules.

What Controls Apply to Both Documents and Records?

Both need appropriate identification, access, protection, storage, and preservation. Documents place more emphasis on review, approval, current versions, and change communication, while records place more emphasis on integrity, retrieval, retention, and disposition.

Does ISO 9001:2015 Require Separate Document-Control and Record-Control Procedures?

No. ISO 9001:2015 uses clause 7.5 for documented information and does not prescribe the old six-procedure structure. An organization may still use separate procedures when that approach supports an effective QMS.

Discover Dash

Best Manual Deals