The document control procedure is the strange one in the register: it is a procedure about procedures, and it has to apply to itself. It says how a document is created, reviewed, approved, published, revised and retired, and it is the document everything else in the register points at when somebody asks why things are done this way. It is also short, or should be. This page sets out the five rules it needs and the trap in writing it.
Rule one: every document has an owner and a version
Stated once, in the control procedure, so no other document has to repeat it. The owner is a named person and the version is visible on the face of the document, because that is where somebody following it looks. Everything else in document control depends on these two existing.
Rules two and three: how a change is made, and who approves it
Who may propose a change, who may approve one, and what happens between. The trap is writing a single approval route for every document type: a policy change and a typo correction on a procedure are not the same decision, and a control procedure that treats them alike guarantees typos survive for years.
Rules four and five: publication and retirement
Where the current version lives and how people are told it changed, then how a document is retired without being deleted. Retired-but-readable is the only safe form: the question of what the procedure said in March comes up, and a register that overwrote it cannot answer. The National Archives publishes retention schedules for exactly this reason.
The trap: writing it as an ISO artefact
Document control has a long association with certified quality systems, and control procedures written in that register tend to be six pages of formality that nobody outside the quality function reads. If the organisation is not certified, write the five rules in a page. If it is, the certification body's requirements are the ones to follow, and they are not this site's subject.
Questions people ask about document control procedure
How long should a document control procedure be?
About a page for an uncertified organisation. Five rules: owner and version, who proposes, who approves, how it is published, how it is retired.
Should retired documents be deleted?
No. Retired-but-readable is the only safe form, because the question of what a procedure said last March does get asked.
Do we need one if we are not ISO certified?
Yes, and a much shorter one. The formality in most published examples comes from certification requirements rather than from the job.