An ISO document control system handles obsolescence by treating cancellation as a triggered event, not a cleanup task: the moment a human marks a document obsolete, the system updates its status everywhere it's referenced — the register, the master list, the controlled-copy record — so no one downstream is left working from a superseded version. It doesn't decide a document is obsolete on its own; a person still makes that call.
ISO 9001 clause 7.5.3 requires that obsolete documented information be prevented from unintended use, and if it's retained for any reason — legal, historical, reference — it has to be suitably identified as such. That's a simple sentence to write into a procedure and a genuinely hard thing to guarantee by hand, because obsolescence isn't a single event. It's a status that has to propagate correctly across every place a document's identity appears, at the exact moment a human decides it's no longer current.
Why obsolete documents survive longer than they should
Ask any document controller how an obsolete document ends up still circulating six months after cancellation, and the answer is almost always the same: it wasn't malice or carelessness, it was simply too many places to update by hand, at the same moment, without missing one.
A single cancellation event, done correctly, touches several things at once:
- The master document list, which has to show the document as cancelled, not just silently removed
- The change register, which needs an entry recording when and why it was cancelled
- Every controlled copy in circulation, which technically needs to be recalled or clearly marked
- Any uncontrolled copies retained for reference, which need identification that they're no longer current
- The retention and disposal clock, which starts (or resets) based on the cancellation date
When a document controller is doing all of this by hand, on top of everything else on their desk, it's routine for one of these to lag behind the others. A superseded procedure keeps living on a shop-floor binder because nobody physically walked over and swapped the page. That's not a training failure — it's what happens when a multi-step, multi-location update depends entirely on one person's memory and time.
How an ISO document control system closes the gap
The fix isn't smarter people — it's removing the gap between the decision and the record. Once the person with authority marks a document cancelled — the same decision gate that already exists in your SOP — the clerical consequences fire immediately and consistently, instead of arriving in whatever order the document controller gets to them.
This is the same lifecycle logic behind the reference system we built for a Thai manufacturer: the workflow covers the full document lifecycle — new document, revision, cancellation, controlled copy, and uncontrolled copy — as one connected state machine rather than five separate manual processes. Cancellation isn't a special case bolted on afterward; it's one of the five states the system was built to handle from day one.
When cancellation happens, the system writes the same kind of field-level updates it writes for any other lifecycle event — but for obsolescence specifically, three matter most:
- The document's status flips in the master document list and the change register, with the cancellation logged as its own entry, not just an overwritten row
- The retention and disposal-due date is calculated from the cancellation date, so the clock on how long the obsolete version must be kept — and when it must be destroyed — starts automatically instead of depending on someone doing the math
- The event is logged individually to the activity log, so there's a timestamped record of exactly when a document stopped being current, tied to who made that call
Controlled copies vs. uncontrolled copies after cancellation
This is where a lot of document control procedures get vague in practice, even when they're precise on paper. A controlled copy is one the organization is actively responsible for keeping current — it has to be recalled or updated the moment its source is cancelled. An uncontrolled copy, often kept for reference or historical purposes, doesn't carry that obligation, but it does have to be clearly identifiable as not current if it's retained at all.
| Controlled copy | Uncontrolled copy | |
|---|---|---|
| Obligation after cancellation | Recall or overwrite immediately | May be retained if identified |
| Marking required | Removed from circulation | Marked "obsolete" or equivalent |
| Who tracks it | Document control, via distribution matrix | Whoever retained it, per procedure |
| Automation's role | Flags every distributed location the moment cancellation is recorded | Marks the record obsolete in the register |
The distinction matters at audit time. An auditor checking obsolescence control isn't just asking "is the current version correct" — they're asking whether you can show that a superseded version couldn't have been mistaken for a current one, anywhere it existed. A Google Drive folder structure mirroring the document lifecycle makes this demonstrable: moving a document into a cancelled-state folder is the human decision, and everything downstream — register status, retention timer, activity log entry — follows from that single, visible action.
What stays a human decision
Nothing about obsolescence handling changes who decides a document is no longer current. That judgment — is this procedure outdated, does it conflict with a newer version, should it be superseded now or next quarter — stays exactly where your SOP puts it. Automation doesn't scan document content and decide relevance on its own, and it doesn't guess that a document is probably obsolete because it hasn't been touched in a while. It waits for the recorded decision and then makes sure that decision is reflected everywhere it needs to be, immediately and without a gap.
FAQ
Does automation decide when a document becomes obsolete?
No. A person with the authority defined in your SOP makes that call. Automation executes the clerical consequences — status updates, register entries, retention dates — only after that decision is recorded.
What's the difference between cancelling and deleting a document?
Cancellation keeps the document's history intact — it's marked obsolete, logged, and retained per your retention schedule. Deleting removes the record entirely, which is rarely what ISO 9001 document control actually requires; most procedures need obsolete versions identifiable, not erased.
How does the retention/disposal date get calculated?
It's derived from the cancellation date according to whatever retention period your procedure specifies. Once cancellation is recorded, the system calculates and stores that date automatically rather than requiring someone to track it separately.
Can an uncontrolled copy stay in circulation after cancellation?
Only if it's clearly identified as obsolete and retained for a defined reason — reference, legal, historical. The obligation is identification, not necessarily removal, and that's a distinction your procedure should already draw.
What does an auditor actually check for obsolescence control?
Typically whether a superseded document could plausibly be mistaken for current — anywhere it exists, in any format. A logged cancellation event tied to distribution records is generally stronger evidence than a verbal assurance that "we collect the old copies."
If your obsolete-document trail currently depends on someone remembering every location a cancelled document lives, that's worth walking through directly rather than describing in the abstract. Book a free consultation with 1% EVO. Bring your current master document list; we open a running system and walk it through, live.