· QUALITY CAPABILITY

Document & Record Control

GMPGDocPQMS

Document and record control is the organisation's ability to ensure that the instruction a person follows is the current, approved one, and that the record they produce is a faithful, enduring account of what was done. It is two obligations in one capability: controlling the say (procedures, specifications, forms — versioned, approved, and withdrawn when superseded) and controlling the do (the completed records that become objective evidence). Neither is useful without the other. A perfect SOP followed against an obsolete form still produces an untrustworthy record.

All 16 capabilities →

What this page does not claim

A capability is something an organization must be able to do; it is not a maturity score and not an assessment domain. The scored domains measure how consistently capabilities are performed, they do not map one-to-one, and nothing on this page rates your organization.

What this capability is

Document and record control is the organisation's ability to ensure that the instruction a person follows is the current, approved one, and that the record they produce is a faithful, enduring account of what was done. It is two obligations in one capability: controlling the say (procedures, specifications, forms — versioned, approved, and withdrawn when superseded) and controlling the do (the completed records that become objective evidence). Neither is useful without the other. A perfect SOP followed against an obsolete form still produces an untrustworthy record.

What distinguishes it from mere filing is control at the point of use. An organisation with this capability can prove that no one could have worked to a withdrawn version, that a blank form cannot be created outside the system, that a completed record cannot be quietly altered, and that everything is retrievable for its full retention period. The capability spans paper and electronic equally — the obligations are identical, only the mechanisms differ.

WHY IT MATTERS

  • Almost every other capability produces or consumes controlled documents and records. When document control is weak, the weakness propagates: a deviation investigated against the wrong procedure, a batch made to a superseded master record, a validation run whose raw data cannot be found. It is the substrate the quality system is written on.
  • It is the single most common thing an inspector tests first, because it is cheap to check and diagnostic of everything else. Obsolete documents in use, uncontrolled blank forms, or records that cannot be produced on request are early, reliable signals that the quality system is documented but not operating.
  • Retention and retrievability are where good organisations quietly fail. A record that exists but cannot be found within the retention period, or an electronic record reduced to a static PDF that lost its metadata, is functionally a missing record — and the gap only surfaces when something is contested, years later.

[ POSITION IN THE FRAMEWORK ]

7 DIMENSIONS · 28 LINKS

Document and record control governs the say and the do wherever work is instructed and evidenced: the current approved version at every point of use, and completed records that stay trustworthy and retrievable for their retention period.

06 · QUALITY MATURITY — DOCUMENT & RECORD CONTROL, REACTIVE TO ADAPTIVE

L1
Reactive

Documents live in shared drives and inboxes; versions proliferate and no one is certain which is current. Records are completed and filed, but retrieval is a search-and-hope exercise and obsolete instructions are found in use.

L2
Defined

A controlled-document procedure defines approval, distribution, and periodic review, and records have defined retention. Control depends on people following the process — the right version is usually in use, but nothing structurally prevents the wrong one.

L3
Controlled

Point-of-use control is enforced: the system serves only the current version, blank forms cannot be created outside it, and completed records cannot be altered without an attributable, reasoned, audit-trailed change. Periodic review happens on schedule with evidence.

L4
Predictive

Document and record health is measured and trended — overdue reviews, change-request cycle times, retrieval failures — and the data drives where effort goes. Retention is managed as a lifecycle, with restore and readability tested rather than assumed.

L5
Adaptive

The document system is a live knowledge asset, not an archive: content is structured, reused, and connected to the processes it governs, changes to a requirement propagate to every document that depends on it, and the organisation can reconstruct the exact controlled state that applied at any past moment.

SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →

07 · REGULATORY & EVIDENCE

GOVERNING STANDARDS · 6

Derived from the 6 standards SPEQ maps to this subject, across 5 regulatory bodies: FDA, EMA, ICH, ISO, MHRA.

RECORDS & OBJECTIVE EVIDENCE

  • A controlled-document register showing current, superseded, and withdrawn status
  • Distribution and point-of-use control records for every issued document
  • Periodic review records with evidenced re-approval, not batch re-dating
  • Blank-form issuance and reconciliation logs for GMP-critical records
  • Retention schedules with tested retrieval across the full retention period

COMMON INSPECTION FINDINGS

  • Obsolete procedure versions found in use at the point of work
  • Uncontrolled photocopied blank forms circulating outside the system
  • Records not producible on request during the inspection
  • Periodic review overdue, or a year of documents re-approved on one date
  • Superseded documents never withdrawn from workstations and binders
EVERY CHIP IS A DOOR · WALK THE FRAMEWORK FROM ANY SUBJECTHow SPEQ maps the framework →

HOW YOU’D SEE WHERE YOU SIT

  • Ask a floor operator to produce the procedure they are working to, and check its version against the system of record — the gap, if any, tells you whether control reaches the point of use.
  • How a blank form comes into existence: printed on demand from the controlled system, or photocopied from a desk drawer.
  • How long it takes to retrieve a named record from three years ago, and whether the retrieved copy carries its full metadata or is a flattened print.
  • Whether periodic document review is evidenced with real re-approval, or a batch of documents is rubber-stamped current on the same date every year.
  • What happens to the superseded version when a document is revised — actively withdrawn from every point of use, or left to linger.

Observable behaviours, not a self-rating — what a capability looks like from the outside, the same way SPEQ’s Quality Culture assessment reads behaviour rather than felt safety.

FREQUENTLY ASKED

What is the difference between document control and record control?

Document control governs the instructions — procedures, specifications, forms — making sure the approved, current version is the one in use and that superseded versions are withdrawn. Record control governs the evidence — the completed batch records, logbooks, and results that prove what was actually done. A document is a template that should always be current; a record is a historical fact that must never change after the event. The same capability owns both because a trustworthy record depends on having been made against the correct document.

Does document control apply the same way to electronic and paper records?

The obligations are identical; only the mechanisms differ. Whether paper or electronic, you must ensure the current version is in use, prevent unauthorised change, attribute every entry to a person, and retain records retrievably for their full period. Electronic systems bring 21 CFR Part 11 and EU GMP Annex 11 controls — secure audit trails, access control, electronic signatures — but they do not change the underlying requirement. A hybrid system, where an electronic original is printed and the paper is treated as the record, is where the two worlds collide and integrity is most often lost.

How does document control relate to the maturity assessment?

It is measured through the Documentation & Change Control domain of the maturity assessment, which scores how consistently an organisation keeps its documents current and its records trustworthy. The capability page describes what the function is and what good looks like across the reactive-to-adaptive ladder; the assessment domain places your organisation on that ladder with scored questions. Use the two together — read the capability to understand the target, then score yourself to find the gap.

MEASURED THROUGH THE MATURITY ASSESSMENT

This capability is about what you must be able to do. How consistently you do it is what the maturity assessment scores — through the domain below.

Contributes to the FDA QMM practice area Advanced Pharmaceutical Quality System (a SPEQ mapping).

Score your quality system →