Document control is the infrastructure of the QMS. Without it, no other process can be audited seriously: an audit report with no tracked version proves nothing. Two failings recur in audits. Documentation that is too light, with no version control or approval. And documentation that is too heavy, where two hundred procedures slow everyone down without reducing a single risk. The standard calls for neither.
Documents or records: don’t confuse the two regimes
ISO 13485:2016 separates two objects under distinct clauses. Documents fall under clause 4.2.4. Records fall under clause 4.2.5. The most common confusion stems from the old numbering of ISO 13485:2003, where control of documents was 4.2.3 and records were 4.2.4. The 2016 revision inserted the Medical Device File at 4.2.3, shifting the two clauses by one notch. Citing the wrong numbers in a quality manual gets noticed in an audit.
Documents (clause 4.2.4) are supports for action: procedures, work instructions, blank forms, quality policy. They are approved before distribution, versioned, and kept available at the point of use. Obsolete versions are removed or clearly identified as such.
Records (clause 4.2.5) are evidence: audit reports, non-conformity reports, calibration results, training records, management review minutes. They remain legible, identifiable, accessible, and are retained for defined periods.
Confusing the two is costly in both directions. Applying the document approval circuit to a non-conformity report creates an absurd burden: no one approves an NC before issuing it. Conversely, treating an audit report as a mere document, with no retention rule, opens a traceability gap that an auditor will find.
What clause 4.2.4 requires, concretely
Each controlled document carries a unique identifier, a title, a version number, an approval date, and the name of the approver. The clause also requires control of documents of external origin deemed necessary — standards, regulatory texts, supplier instructions — and defining the period during which at least one copy of obsolete versions is retained. Obsolete versions disappear from the points of use. Kept for the record, they carry an unambiguous marking that blocks any accidental use.
How long to retain records
Clause 4.2.5 sets a floor: retain records at least until the end of the device lifetime as defined by the organisation, or for the period imposed by applicable regulatory requirements, never dropping below two years from the date the device was made available. This is not a device lifetime plus two years. It is a minimum of two years when the lifetime is shorter.
The MDR adds a distinct, longer obligation, which targets the technical documentation and the declaration of conformity, not the entire set of quality records. Article 10(8) requires them to be kept available to the authorities for at least ten years after the last device is placed on the market, fifteen years for implantable devices. Aligning your retention policy on the ISO floor alone therefore exposes you to an MDR non-conformity on technical files.
Avoiding the bureaucratic machine: when a procedure is justified
Documenting everything is counterproductive. A procedure is justified in three cases. The standard explicitly requires it, as a mandatory documented procedure. The risk of failure without it is real: complex activity, several operators, significant consequences for the product or the patient. Or several people perform the same task and consistency must be guaranteed.
Outside these cases, the procedure adds weight without protecting. A simple activity, carried out by a single person, whose result is immediately visible, calls for no written procedure. Neither does a common-sense decision.
Calibrating the level of detail to the risk
A procedure that describes every gesture is often worth less than a procedure that frames the key steps, the decisions to be made, and the records to be produced. The cursor is set on the risk. A sterilisation procedure justifies a high level of detail, because a deviation is paid for in patient safety. A supply ordering procedure does not need the same weight. A QMS of thirty procedures that are kept up and applied passes the audit. A catalogue of two hundred that no one opens fails it.
A well-calibrated documentation system is recognised by a simple sign: teams use it instead of working around it. If your internal audits reveal mostly version discrepancies, ignored procedures, or records that cannot be found, the problem is not the volume, it is the calibration.