Documentation & Change Control
Controlled records and a change process that keeps a validated state validated.
What a domain score is not
A domain is one of the axes SPEQ’s assessment scores, on SPEQ’s own five-stage progression. It is a labelled synthesis, not the FDA’s Quality Management Maturity rating, and a score here is a self-assessment — nobody but you has rated your organization.
Records are the evidence a regulated operation ran as intended, and change control is how a validated state survives change. When either fails, an inspector cannot trust anything downstream — which is why uncontrolled documents and unassessed changes are among the most frequently cited GMP deficiencies. This domain is the connective tissue of the whole quality system.
What changes with maturity is not how many documents exist but what a change is allowed to touch before anyone notices. A reactive operation controls documents and reacts to change; a mature one assesses a proposed change against everything downstream of it — validation status, registered details, supplier qualification, training, the equipment’s qualified state — before it is approved, and can show the assessment. The visible tell is direction: in a weak system, changes are recorded after they are implemented and documents are corrected after they are found wrong.
- Make the change-impact assessment a real question with a real answer. A form that asks "regulatory impact? Y/N" and is always answered N is not an assessment; ask what registered detail, validated state or qualified system this touches, and require the answer to name them.
- Close the loop between change and validation. Most uncontrolled drift is a change that was approved correctly and never triggered the revalidation it implied.
- Put version control where the work happens, not where the documents are stored. An obsolete copy at the line is a document-control failure regardless of how good the repository is.
- Add an effectiveness check to changes, not only to CAPAs — and let it be capable of failing.
Watch the lag between a change being decided and being recorded — if records are consistently created after implementation, the system is documenting rather than governing. Watch the proportion of changes whose impact assessment names a downstream object rather than asserting none. And watch how often a document is found wrong at the point of use rather than at review: that ratio says whether control reaches the floor.
The observable behaviours that place a site at each level — what a practitioner or inspector would actually see — and the concrete move that carries it to the next.
- ·Uncontrolled copies and unofficial "working" documents circulate
- ·Changes are made first and documented later, or not at all
- ·No single owner can say which version is current
TO ADVANCE →Stand up a document register with version control and a basic change-request form approved before any change is made.
- ·Controlled SOPs exist but staff still use memory or shortcuts
- ·Change requests are raised but impact assessment is a checkbox
- ·Linked updates (training, validation) are missed or lag the change
TO ADVANCE →Make impact assessment substantive — force each change to identify and close its downstream actions before closure.
- ·Every change carries a risk-rated impact assessment and pre-approval
- ·Downstream actions (training, validation, regulatory) are tracked to closure
- ·The effective version is unambiguous and retrieval is fast
TO ADVANCE →Instrument the system — trend change volume, lead time, and overdue actions so management review acts on data.
- ·Change lead time, backlog, and recurrence are trended and reviewed
- ·Overdue linked actions trigger escalation, not just a reminder
- ·Effectiveness of significant changes is verified, not assumed
TO ADVANCE →Close the loop — use trends to prevent the next change problem and manage document knowledge across the lifecycle.
- ·Change data feeds proactive risk decisions, not just reporting
- ·Knowledge from changes is captured and reused across sites and transfers
- ·Documentation and change control run as one connected, self-improving system
- A change-control log with impact assessments, approvals dated before implementation, and closure evidence
- The current, effective version of a named SOP and its revision history
- Evidence that a recent change drove the linked updates (training, validation, filings) it should have
Want the specific artifacts that move your score up? The Comprehensive assessment turns your domain scores into a prioritised, personalised remediation plan.
The observable evidence a practitioner — or an inspector — would expect at each maturity level. Drawn from the assessment questions themselves.
How are your quality documents controlled and version-managed?
No formal system — printed copies, email distribution
Documented SOPs exist but reviews are ad hoc
Formal DMS with scheduled review cycles and training records
Validated electronic DMS with metrics, trending, and periodic effectiveness review
Predictive, self-service DMS: automated review scheduling, real-time control metrics, and continuous-improvement feedback across the network
How is change control managed across your site?
Changes tracked informally — no formal review board
Change control SOP exists; review is inconsistent
Formal change control with cross-functional review and regulatory impact assessment
Integrated change management linked to risk register, CAPA, and regulatory intelligence
Predictive change management: automated risk-based routing, live regulatory-impact intelligence, and network-wide effectiveness benchmarking
- ›Obsolete or uncontrolled documents in use at the point of work — no effective version control.
- ›Changes implemented without a documented impact / risk assessment or a regulatory-impact evaluation.
- ›Records not completed contemporaneously; entries missing, backdated, or lacking a second-person review.
- ›Change controls closed without an effectiveness check, or with implementation actions left overdue.
Recent FDA recalls whose reason SPEQ maps to this domain — a SPEQ editorial interpretation of the recall reason, not an official FDA classification.