Every business runs on documents. Policies, procedures, forms and records guide the work and prove it happened. Yet without IMS document control, those documents drift. Versions multiply, the wrong form gets used, and the record you need at audit has quietly vanished.
Document control is not bureaucracy for its own sake. It is how you make sure people work from the current instruction. It is also how you show a regulator that your system is real. Get it right, and your integrated management system stays trustworthy. Get it wrong, and every other control sits on sand.
What IMS document control means under ISO Clause 7.5
Clause 7.5 Documented information appears in ISO 9001, ISO 14001 and ISO 45001. It sets three plain duties. First, create and identify each document properly, with a title, date, author and reference. Second, keep it in a suitable format and review it for adequacy. Third, control it, so the right version is available where it is needed and protected from loss or misuse.
So IMS document control covers the full life of a document. You create it, approve it, issue it, revise it, and eventually retire it. Each step needs a simple rule and a place to record it. The master register is where those rules live and stay visible.
Documents and records are not the same thing
People blur the two, but ISO keeps them apart. A document tells you what to do. A policy, a procedure or a blank form is a document, and it changes over time as you improve it. A record shows what happened. A signed permit, a completed checklist or a training certificate is a record, and you do not edit it after the fact.
The difference drives how you control each one. Documents need version control, so everyone works from the current one. Records need protection and retention, so they stay legible and available for as long as the law or the contract demands. Mix them up, and you either edit history or lose the live instruction.
Version control and the master document register
Version control is the heart of IMS document control. Give every document an ID, a version number and an issue date. Raise the decimal for a minor edit, and the whole number for a major change. Then record who approved it and when. When a new version issues, the old one leaves circulation at the same moment.
A master document register makes all of this visible. It lists every controlled document, its current version, its owner and its next review date. One glance shows what is current, what is due, and what is overdue. Without that register, control lives in people’s heads, and it fails the day someone leaves.
Control access, distribution and obsolete documents
A current document only helps if the right people can reach it and the wrong version cannot. Store the master copy in one controlled location. Give workers read access to the current version, and limit editing to the owner. When you issue a change, pull every superseded copy, whether it sits on a noticeboard, a laptop or a ute glovebox.
Obsolete documents cause real harm. A worker following last year’s method does not know the control changed. So mark retired documents clearly, archive them out of the live system, and keep just enough history to trace what applied and when. That trace is exactly what an incident investigation leans on later.
How long to keep your QHSE records
Retention is where document control meets the law. The WHS Act requires you to keep a record of a notifiable incident for at least five years. Health monitoring reports for workers exposed to hazardous chemicals must be kept for thirty years under the WHS Regulations. Tax and general business records run to five years under ATO rules.
So set a retention period for every record type, and note where it lives. AS ISO 15489.1, the Australian standard on records management, gives a solid guide. When the period ends, dispose of records in a controlled way, and log that you did. Keeping everything forever is its own risk, not a safe default.
Practical Application
Picture an Australian civil contractor with 25 staff across several sites. The QHSE manager builds one master register. Every policy, procedure, SWMS, form and key record gets an ID, a version, an owner and a review date. The register sits in a single controlled folder, and each site copy links back to it.
Now control is simple. A monthly check flags anything due for review within thirty days. When a SWMS changes, the supervisor swaps every site copy that day and records the sign-off. Incident records are locked and retained for five years. At the next audit, the contractor opens one file and shows the whole document system at a glance.
Conclusion
Strong IMS document control is quiet, but it holds everything else up. Identify your documents, version them, and keep the current one in reach. Separate your records, protect them, and retain them for as long as the law says. Do all of that in one master register, and your system tells the truth every time someone opens it.
The MiSAFE All-in-One QHSE subscription runs your document register inside DS Site, with version history, review reminders and controlled access held in one place.
Ready to act? Contact us today or book a free 45-minute consultation.
Download the Free Template
Download the free QHSE Document and Records Control Register (.xlsx) and put every QHSE document, version and record in one controlled place.
Recent Comments