ISO 9001 records control: procedure and template

ISO 9001 records control is the part of a quality management system nobody enjoys and no auditor lets slide. It is not about keeping paper: it is about being able to prove, at the moment you are asked, that something happened the way you say it happened.

Most companies that reach this point already have the records. The problem is different: they are spread across a shared folder, three people’s inboxes and a couple of spreadsheets only their author understands. When the auditor asks for last August’s calibration record, the hunt begins. And in an audit, the hunt is already half the answer.

This guide covers what clause 7.5.3 actually requires, how to build the retention table the whole procedure rests on, and the four questions an auditor uses to work out in five minutes whether your records control is real or just a well-named folder.

Free resource by QualityWeb 360

A record is not a document (and the confusion costs you a finding)

ISO 9001:2015 grouped both under documented information, and ever since a lot of people treat them the same way. They are not the same, and the procedure changes depending on which one you are holding.

A document states how something should be done: a procedure, a work instruction, a blank form, a policy. It faces forward, gets reviewed, approved and updated. It has versions.

A record is the evidence that something was already done: the completed form, the audit report, the management review minutes, the calibration certificate. It faces backwards and is not updated. Fixing a record so it “looks better” is not an improvement: it is altering evidence.

The practical consequence is simple. Documents need version control and approval before use. Records need identification, protection, a defined retention period and a clear rule for what happens when that period ends. Apply document control to records and you end up versioning evidence, which is exactly what must not happen.

What ISO 9001 clause 7.5.3 actually requires

Without transcribing the standard, clause 7.5.3 comes down to two requirements.

First: documented information must be available and suitable for use, where and when it is needed. Translated: if the record exists but sits on the laptop of someone who is out today, it is not available.

Second: it must be protected against loss of integrity, improper use and loss of confidentiality. To get there, the standard asks you to address five things: distribution and access, storage and preservation, control of changes, retention, and disposition.

That is where the trap sits: the last two — how long you keep it and what you do afterwards — are the ones almost no system documents, and the easiest to audit. An auditor does not need to review a thousand records to find the gap. Asking how long you keep training records and watching the owner’s face is enough.

The retention table: the artefact your auditor will ask for

The entire records control procedure rests on a single deliverable: a table stating, by record type, what happens to it. If you have that table and it is followed, the procedure is real. If you don’t, you have a nicely worded text.

These are the columns it needs:

  • Record type — the name people actually use, not the form code.
  • Owning process — purchasing, production, HR, audit.
  • Owner — a role, not a person. People leave; roles stay.
  • Where it lives — the real, single location. Two locations means zero.
  • Retention period — with its reason: legal requirement, customer requirement, or your own decision.
  • Who can read it and who can change it — two different permissions.
  • What happens when the period ends — destroyed, archived, anonymised.

Here is what it looks like filled in. Copy it into your spreadsheet and adjust every row to your case: the periods below are examples, not a regulatory reference.

Record typeProcessOwner (role)Where it livesRetentionRead / Change accessAt expiry
Calibration certificateMaintenance and metrologyMaintenance supervisorEquipment fileEquipment service life + 1 certification cycleQuality and production / NobodyArchived with equipment decommissioning
Training recordHuman resourcesHR managerEmployee fileEmployment period + whatever your regulation setsHR and department heads / HRAnonymised
Internal audit reportInternal auditQuality managerManagement system3 certification cyclesTop management and quality / NobodyArchived
Customer complaintCustomer serviceCustomer service managerManagement systemWhatever the customer contract setsQuality and sales / NobodyDestroyed, with a record of it

Two warnings about periods. First, do not copy another company’s timeframes: they depend on your regulation, your contracts and your product’s life cycle. Second, when there is no legal or contractual requirement, the right answer is not “forever”. Keeping everything indefinitely is as hard to defend as keeping nothing, and it multiplies the risk of holding information you should no longer have.

Six steps to build the procedure

1. Inventory what you already generate. Before designing anything, walk the processes and list the records operations already produce. There are almost always more than the QMS declares, and several are duplicated in two different places.

2. Prune and consolidate. Drop the forms nobody fills in and merge the ones capturing the same thing under another name. A records control procedure built on an inflated inventory collapses on its own within three months.

3. Fill in the retention table. Row by row, with the columns above. This is the step that takes time and the only one you cannot skip.

4. Define permissions by role. Who reads, who uploads, who can retire a record. The rule that works: broad read access, narrow write access, near-zero delete access.

5. Define disposition. What happens when the period ends, who authorises it and where the proof lives. Destroying a record also leaves a record.

6. Train and let go. A procedure only the quality manager understands is not a procedure: it is a dependency. The proof that it landed is that someone from another department can find a record without asking you.

Protection and access: who reads, who edits, who deletes

Protecting a record is not hiding it. It is guaranteeing that it will still be the same record in three years, that the people who need it can find it, and that the people who shouldn’t touch it can’t.

With shared folders this gets hard for one concrete reason: edit permission and delete permission are usually the same permission. Whoever can upload a file can overwrite it, and nothing is left showing what was there before or who changed it. When an auditor asks how you guarantee a record’s integrity and the answer is “we trust the team”, the finding is already written.

The minimum that must exist, whatever the tool: unique identification for every record, a single place where it lives, separate read and write permissions, and traceability of who did what and when. The first three can be improvised. The fourth cannot.

How it is tested in an audit: the same four questions

An experienced auditor does not review your records one by one. They ask four questions and know whether the system is alive:

  1. “Show me this specific record from eight months ago.” Measures real availability. If it takes more than a couple of minutes, they already have their answer.
  2. “How long do you keep this type of record, and why?” Measures whether the retention table exists and whether anyone knows it.
  3. “Who can modify this?” Measures protection and integrity. The right answer is almost always “nobody”.
  4. “What did you do with the records that expired?” Measures disposition. It generates the most findings, because it is almost never documented.

If all four have an answer and evidence behind them, records control is solved. It doesn’t matter whether it lives in software or a filing cabinet, although the cabinet makes all four a lot slower.

Common mistakes that cost findings

  • Versioning records. If a record has a “version 2”, it is either a disguised document or evidence that was altered. Neither is good news.
  • A copied retention table. Periods that match neither your regulation nor your contracts. The auditor asks why a number is what it is, and there is no why.
  • Owners named as people, not roles. The person leaves, the record is orphaned and nobody knows who answers for it.
  • Two official locations. “It’s on the server and also on Drive” means there are two truths and neither is reliable.
  • Keeping everything forever. Comfortable today, indefensible when someone asks why you still hold a customer’s data from a decade ago.
  • A procedure written for the audit, not for operations. It shows in thirty seconds: nobody outside quality knows it exists.

From the shared folder to a real system

There is a point where the problem stops being the procedure and becomes the tool. The signs are concrete: somebody has to remember manually when a retention period expires, nobody knows for certain who changed the last record, and preparing audit evidence turns into a full week of one person’s work.

That is what QualityWeb 360 is for. It is not a consultant and it won’t tell you what your QMS should look like: it is the orderly place where your system lives, with every record in a single location, permissions by role, traceability of who did what, and retention periods controlled by the system instead of by somebody’s memory.

Frequently asked questions about ISO 9001 records control

What is the difference between document control and records control?
Document control manages what tells you how to do things (procedures, blank forms) and needs versions and approval. Records control manages the evidence of what was already done, which is not versioned: it is identified, protected, retained for a defined period and disposed of at the end.

Does ISO 9001:2015 require a documented records control procedure?
It does not require the document itself, as the 2008 version did. It requires the control to happen and to be demonstrable. In practice, writing the procedure is the simplest way to demonstrate it, and the retention table is its essential part.

How long must quality records be kept?
The standard sets no periods. They are set by your applicable regulation, your customer contracts and your product or service life cycle. What the standard does require is that the period is defined, has a reason and is honoured.

Are electronic records valid for ISO 9001?
Yes, and in practice they make compliance easier: they handle identification, role-based access and change traceability better than paper. The standard asks for protection and integrity, not a specific medium.

Can a record with an error be corrected?
It is not overwritten. The correction is documented so the original value stays visible and it is clear who made the change and when. Deleting the previous value is altering evidence.

Which records does an auditor always ask for?
It varies by industry, but there is a core that shows up almost every time: internal audits, management review, corrective actions, training and competence, supplier evaluation, and calibration or verification of measuring equipment.