Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
SOP Plug-and-play starting point Quality Assurance

SOP: Document Control System

A plug-and-play master procedure for the GxP document control system: the document hierarchy, numbering, the SOP lifecycle from draft to retirement, effective dates and training linkage, controlled copies, the master list, and retention, with a filled specimen and the regulatory basis.

Document type: SOP

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use SOP, the foundational one a document control system hangs off. Replace every <<FILL: ...>> placeholder with your own specifics and route it through your normal review and approval. A worked filled specimen follows the template. It is an educational aid to adapt and verify against your own quality system, not a compliance guarantee.

Document control header

FieldEntry
Document titleDocument Control System
Document number<<FILL: SOP-ID, e.g. SOP-QA-001>>
Version<<FILL: version>>
Effective date<<FILL: date>>
Supersedes<<FILL: prior version or "New">>
Document owner<<FILL: role, e.g. Head of Quality Assurance>>
Applies to<<FILL: sites / departments in scope>>

1. Purpose

Define how controlled documents are created, numbered, reviewed, approved, made effective, trained, revised, and retired, so that at any moment the current version of every document is known, available where the work is done, and followed. Document control is the skeleton of the quality system; every other element attaches to it.

2. Scope

This procedure covers all controlled documents that direct or record a GxP activity, regardless of format, including policies, SOPs, work instructions, methods, specifications, protocols, and forms. The test is function, not format: if a document governs or records a GxP activity, it is controlled. Authoring of SOP content is detailed in <<FILL: SOP-ID for SOP authoring>>; this procedure governs the control system itself.

3. Responsibilities

RoleResponsibility
Document owner / authorDrafts content, keeps it accurate, initiates periodic review and revisions on time.
Functional reviewers (SMEs)Confirm the document is correct and executable for their function and record what they checked.
Quality AssuranceApproves all GxP documents, owns this SOP, enforces the lifecycle, is the final authority on fitness for use.
Document control administratorAssigns numbers, routes workflows, retires versions, reconciles controlled copies, maintains the master list.
Training coordinatorMaps documents to roles and tracks training tied to effective dates.
Line managersEnsure people are trained before working to a new version and that only current versions are in use at the point of use.

4. Definitions

  • Controlled document: a document subject to formal approval, version management, and access control because it directs or records a GxP activity.
  • Effective date: the date from which a version must be followed, on or after approval.
  • Master list: the current index of every effective controlled document and its version.
  • Controlled copy: a live, tracked copy of a document, distinct from an uncontrolled printout.

5. Procedure

5.1 Document hierarchy

Maintain a defined hierarchy so a lower level adds detail but never contradicts the level above it:

LevelDocument typeAnswers
1Policy / Quality ManualWhy and at what commitment
2SOPHow the process works
3Work instruction / methodExactly how a task is done
4Form / template / logbookWhat data is captured

5.2 Numbering and version

  1. Assign each document a unique, stable identifier that does not change across revisions.
  2. Use a defined revision scheme (alphabetical or numeric). Where a major/minor scheme is used, define what counts as major versus minor in section 5.6.
  3. Every page carries the document number, version, effective date, and page X of Y, so a single loose page identifies itself.

5.3 Draft, review, approve

  1. The owner drafts the content.
  2. Functional reviewers review and record what they checked.
  3. QA approves all GxP documents; the same person is not the sole reviewer and sole approver of a document they wrote.

5.4 Effective date and training

  1. Set the effective date on or after approval, with a defined window (commonly two to four weeks) to complete training first.
  2. Affected roles are trained before the effective date; working to a new version before training is recorded is a violation.
  3. The prior version is retired the moment the new version becomes effective, so two live versions never coexist.

5.5 Periodic review

  1. Review each document on a defined schedule (commonly every two years, shorter for higher-risk documents).
  2. Confirm it is still accurate, current, needed, and consistent with the levels above and below. A review is a real evaluation, not a signature.
  3. Document the outcome (revise or no change) and reset the clock.

5.6 Revision and change control

  1. Any content change goes through change control; there is no in-place edit.
  2. Classify the change as major or minor per the defined rule (see the paired change-request form) and tie re-training to a major change.
  3. Record the revision history entry naming the section changed and the reason, and link the change control record.

5.7 Retirement and retention

  1. Retire a document formally when the process or system it governs ends; removal from use and archival are recorded actions, not something that happens by neglect.
  2. Retain the retired document and its records for the defined retention period; destruction is a controlled, approved, documented event.

5.8 Master list and controlled copies

  1. Maintain a current master list of all effective controlled documents and versions.
  2. Track every controlled paper copy so the firm can state, at any moment, how many exist and where; reconcile and destroy superseded copies at each revision.

6. Acceptance criteria

  • Every controlled document is uniquely numbered, approved before use, versioned, dated, and identifies itself on every page.
  • Training is complete before each effective date, and only current versions are at the point of use.
  • Changes go through change control with a revision history that names what changed and why.
  • A current master list exists, and controlled copies are fully reconciled.
  • Retired documents are archived for the retention period, and destruction is controlled.

7. References

21 CFR 211.100(b) (procedures followed and documented at the time of performance), 211.22(c) and (d) (quality unit approval of procedures), 211.180 (record retention). EU GMP EudraLex Volume 4, Chapter 4, Documentation. A revision of Chapter 4 went to consultation on 7 July 2025 (closed 7 October 2025) and remains a draft as of mid-2026; the 2011 text is in force. ISO 13485:2016 clause 4.2.4 (control of documents) and 4.2.5 (control of records), incorporated by reference under FDA’s QMSR (effective 2 February 2026) for combination products and operations following that standard. ICH Q10, Pharmaceutical Quality System.

Confirm the current version and clause numbers of each reference before issue.

8. Record generated: document control record (per document)

FieldEntry
Document number and title<<FILL>>
Version and effective date<<FILL>>
Change control reference<<FILL>>
Training completion vs effective date<<FILL: all complete before effective date Y/N>>
Prior version retired<<FILL: version, date>>
Next periodic review due<<FILL: date>>

9. Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

10. Approvals

RoleNameSignatureDate
Author<<FILL>>
Reviewer (QA)<<FILL>>
Approver (Quality Head)<<FILL>>

Filled specimen

One document’s control record, worked:

FieldEntry
Document number and titleSOP-QC-058, 100% Visual Inspection and AQL Re-Inspection
Version and effective dateRev C, effective 04 Apr 2026
Change control referenceCC-2026-0231
Training completion vs effective date14 of 14 affected analysts trained by 03 Apr 2026 (Y)
Prior version retiredRev B, obsolete 04 Apr 2026
Next periodic review due04 Apr 2028

Read as an inspector would: the effective date is after approval, training finished before the effective date, the change ties to a change control record, and the prior version went obsolete the moment the new one took effect, so no window of two live versions existed. Each of those is a control the record makes testable.

Common inspection findings this SOP prevents

  • Obsolete documents at the point of use because the prior version was not retired on the effective date.
  • People working to a new version before training is recorded, or training dated before the document existed.
  • Content changed in place without a formal revision or change control record.
  • No current master list, so the firm cannot prove which version is current.

How to adapt this SOP

  1. Set your hierarchy levels, numbering scheme, review periods, and the major/minor rule.
  2. Point the cross-references to your SOP authoring, change control, training, and retention procedures.
  3. Decide your controlled-copy mechanism (stamped copies with a register, or an EDMS watermark and reconciliation).
  4. Confirm every reference in section 7 against its current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.