ISO 9001 · Clause 7 · 7.5, 7.5.1, 7.5.2, 7.5.3
Documented information
In plain words
“Documented information” is the standard’s collective term for both: documents (which are maintained — procedures, policy, plans) and records (which are retained — inspection protocols, evidence). The clause has three parts. 7.5.1 — what belongs: what the standard demands plus what you yourselves deem necessary; the extent is explicitly your decision, lean as in 4.4. 7.5.2 — when creating and updating: identification (title, date, version), a suitable format — and review and approval before anything takes effect. 7.5.3 — control: available where needed; protected against loss, breach of confidentiality and unintended alteration; distribution, access, archiving and retention settled; external documents (customer drawings, standards) identified and controlled; and records protected against subsequent change — the audit-proof part.
The spirit of the clause in one sentence: there is exactly one valid version, everyone finds it, and what has become evidence stays unfalsifiable.
Why this requirement exists
Documented information is the memory of the QMS — and a memory with two truths is more dangerous than none. The outdated drawing at the workstation is probably the most common audit finding in the world, and it is never harmless: somewhere, someone is machining to the old state right now. Every uncontrolled copy is a ticking nonconformity.
The second half of the purpose is records as evidence: the inspection protocol, the release, the calibration certificate are what you present in a complaint, in the audit and in a liability case (product liability). A record anyone can alter afterwards proves exactly nothing — which is why the standard demands protection against change, and why German retention rules (the GoBD way of thinking) demand the same of commercial records.
What good looks like
In a company of 12 people: one place of truth — not three server folders and a USB stick. Every controlled document carries ID, version and status; there is a defined release path (who reviews, who approves — 5.3 supplies the answer); old versions leave circulation but stay archived and findable. Paper at the workstation is allowed — but recognisable as a copy of a state (“uncontrolled when printed”) and consistently swapped on change.
Plus the two gladly forgotten edges: external documents — the customer drawing with its revision index, the standard with its year — are kept with their state like your own. And retention periods are determined: what is kept how long (customer requirements, law, own caution), and what may go afterwards?
What changes as you grow: From around 50 people, role-based access and a control overview join (which document kind, which release path, which period); from 100–250 people, real records management with running periods and legally safe archiving. The core stays the same sentence at every size: one valid version, everyone finds it, evidence unfalsifiable.
The minimum to pass
- The current version is findable — and cannot be confused with old states (identification!).
- Review and approval before validity are evidenced — who approved, when?
- Records are protected against subsequent change — traceable, not overwritable.
- External documents are controlled with their state — the customer drawing has a known index.
- Retention is settled — periods determined, the archive accessible.
What an auditor asks for
- The spot check of spot checks, in every audit: pick up a document at the workstation — is it the current version? This one grab decides the impression of the whole clause.
- The release evidence of any controlled document: who reviewed, who approved, when?
- How a record is protected: “Show me last week’s inspection protocol — and explain why I can believe it.”
- The state of a customer drawing in production against the customer’s latest revision index.
- The reach into the archive: retrieve an old version on purpose — archiving that works instead of being claimed.
Common traps
- The outdated copy at the workstation. The world champion among audit findings — almost always a paper copy nobody swapped at the last update. Whoever distributes paper takes on the swapping with it.
- Explorer chaos.
procedure_final_v2_NEW_really.docxnext to four siblings — nobody knows which one counts. Not an isolated finding but a system finding: the one place of truth is missing. - Approval as a formality. The signature under a document nobody read — or documents quietly circulating before anyone approved. 7.5.2 is not a courtesy; the unreviewed instruction is tomorrow’s nonconformity.
- Editable records. The inspection spreadsheet where anyone can change any cell is worthless as evidence — awkward in the audit, fatal in a liability case.
- External documents in the fog. Production holds index C, the customer is at index E — the most expensive special case of the outdated copy, because in the end the part does not fit at the customer.
- Over-control. Every note, every internal memo through the full release procedure — that smothers the work and devalues control where it counts. 7.5.1 leaves you the extent: control what has effect.
Worked example
Honesty first: before easo, Berger Präzisionsteile GmbH was average here. Server folders with copies, paper at the machines, inspection results in a free spreadsheet. And the world classic actually happened — the outdated setup sheets at the 5-axis machine that the internal audit found (9.2): the same story that in 6.3 showed the missing change routine and in 7.1.6 the flip side of documented knowledge is, through the 7.5 lens, simply uncontrolled documented information at the workstation. One thread, three lessons.
Then Berger drew the conclusion: one place of truth for all controlled documents; paper at the machines only as same-day controlled printouts with visible state and the note that printouts are uncontrolled; customer drawings kept with their revision index in the order folder and swapped on customer updates; inspection records no longer in a free spreadsheet but as closed, versioned evidence. In the next certification audit, the auditor grabbed — of course — the setup sheet at the 5-axis: current state, version visible, release traceable. The former favourite finding had become structurally impossible.
How easo covers it
This is easo’s home clause — the control of documented information is literally what easo builds:
- 7.5.2 with proof instead of a signature folder: every release is a personal, cryptographic signature after a defined review path; who approved what and when is part of the document — not of a folder beside it.
- One valid version, technically enforced: released content is unalterable (any subsequent change breaks the signature — visibly); changes run as a new version through the same review path; predecessor versions stay archived and retrievable via the history; superseded and retired content is marked, not deleted.
- Records audit-proof in the literal sense: versioned, signed, traceable — the protection against subsequent change that 7.5.3 (and the GoBD way of thinking) demands is a construction principle, not a discipline question.
- Available where needed: the handbook with full-text search for everyone in the house; the PDF export carries the note that printouts are uncontrolled — the paper trap is labelled.
- External documents: pinned byte-exact as controlled attachments (hash-named) — whether the drawing is still the one that was released is checkable, not a matter of trust.
- And honest about readiness: 7.5 has no row of its own in easo’s denominator — control is not a single document one could tick off, but a property of all of them. easo fulfils it systemically, the same for every document.
Stay in the loop
easo is available for macOS — the Windows version is coming soon. Leave us a note and we'll reach out the moment it lands.