Controlling management system documents: an ISO/IEC 17025:2017 clause 8.3 checklist for labs

Controlling management system documents

Quick Summary

Clause 8.3 of ISO/IEC 17025:2017 consists of two parts. Clause 8.3.1 requires you to control all the documents that relate to meeting the standard, internal and external. Clause 8.3.2 then sets out six specific controls, listed as items a) to f).

Together, they give you seven things to check, and assessors look at all of them closely. Document control tends to generate more nonconformities than it probably should, usually because of small gaps rather than missing controls.

Use these seven questions to check whether your current setup meets what the standard requires:

  • Are all your documents, internal and external, brought under control? (8.3.1)
  • Are documents approved before use by someone with the authority to do so? (8.3.2 a)
  • Are documents reviewed and updated at appropriate intervals? (8.3.2 b)
  • Are changes and the current revision status clearly identified? (8.3.2 c)
  • Is the current version available at the point of use, with distribution controlled? (8.3.2 d)
  • Does every document have a unique identifier? (8.3.2 e)
  • Are obsolete documents withdrawn and clearly marked? (8.3.2 f)

The document control problem most labs already know about

Ask any quality manager who has been through an ISO/IEC 17025 assessment what came up in the findings, and document control will almost always feature somewhere.

It’s rarely because labs are careless. It’s usually because the gap between how document control is supposed to work and how it actually works in a busy laboratory tends to be wider than anyone realises until an assessor starts asking questions.

An old procedure still sitting in a binder on the bench. A technician who has been working from a version they printed out during induction. A form that was updated six months ago, but where nobody quite got round to withdrawing the old one.

These aren’t disasters, but they are nonconformities. And they are almost always avoidable.

What is ISO/IEC 17025:2017 clause 8.3?

Clause 8.3 sets out how to control the documents your laboratory relies on to run its management system. Clause 8.3.1 makes the scope broad. It covers all documents that relate to meeting the standard, whether your lab produced them or not. That includes internal documents such as procedures, policies, SOPs, work instructions, forms and methods, and external documents such as manufacturer’s instructions, reference standards, calibration tables and charts.

Understanding what each requirement actually means, and honestly checking whether your current processes meet it, gives you the best chance of getting through an assessment without document control findings.

Documents versus records

Before working through the clause, it’s worth being clear about what clause 8.3 does and doesn’t cover. Documents describe how work should be done. Records prove it was done. Clause 8.3 governs documents: the living instructions and procedures your team refers to, updates and works from.

Records, including calibration worksheets, certificates and training sign-offs, are addressed separately under clause 8.4, with technical records covered in clause 7.5.

If an assessor raises a concern about a completed worksheet or an equipment history record, that finding sits under different clauses. Clause 8.3 is about the instructions that guided the work in the first place.

The clause 8.3 checklist

8.3.1 Are all your documents, internal and external, under control?

Clause 8.3.1 is the scoping requirement, and it is easy to read past. It requires you to control all the documents that relate to fulfilling the standard, not only the ones your lab writes. Internal documents such as procedures, methods and forms are the obvious part. External documents are the part labs most often miss: manufacturer’s operating and maintenance instructions, reference standards, calibration tables, conversion charts, and the normative or regulatory documents your methods depend on.

The gap assessors find here is a lab that controls its own SOPs well but has no real control over external documents. A superseded edition of a standard, an out-of-date manufacturer’s manual at the bench, or a calibration table that nobody is sure is current are all common. Bringing external documents into your register, identifying them, and confirming they are the current versions is what 8.3.1 is asking for.

8.3.2 a) Are all your documents approved before use?

Every document issued to laboratory personnel as part of the management system must be reviewed and approved by someone with the authority to do so before it goes into use. This applies to new documents and to any revised version.

This means having a clear approval process, knowing who has the authority to approve which types of documents, and having a record of that approval visible on or alongside the document itself. A named approver, a date and a signature, electronic or physical, are the basics.

Where this tends to go wrong is informal approval. Managers reviewing things by email. Verbal sign-offs that nobody wrote down. Drafts that quietly became the working version because the formal release process never quite happened.

8.3.2 b) Are your documents reviewed and updated at appropriate intervals?

Documents can’t simply be issued and left indefinitely. Your lab needs a process for reviewing them at appropriate intervals, or sooner when something changes, and any updates must go through the same approval process as the first issue.

Assessors will want to see that review cycles are defined and that there’s evidence they have been followed. A scheduled review date on each document, a reminder system, a review log, any of these can work. They will also check that changes have been formally approved rather than quietly edited.

Documents with review dates long past, and informal changes that didn’t follow a revision and re-approval process, can quickly escalate into a corrective action request if picked up during an assessment. Our guide to building a robust corrective action process covers what that looks like in practice.

8.3.2 c) Are changes and the current revision status clearly identified?

Clause 8.3.2 c) requires that changes to a document and its current revision status can be identified. Anyone picking up a document should be able to tell which version they are holding, whether it is the current one, and what changed at the last revision.

In practice, this is carried by a revision indicator and a revision date on the document, supported by a change history that records what changed, who approved it and when it took effect. Many labs also include page numbering, a total page count or end-of-document marker, and the issuing authority. Those fields were spelt out explicitly in the 2005 edition of the standard, and while the 2017 edition no longer lists them, they remain good practice, and assessors still expect a document’s identity and status to be unambiguous.

The gap here is that changes are made without updating the revision status, so two copies of a document carry the same identifier but different content, or a reader cannot tell whether what they are holding is current.

8.3.2 d) Can staff access the current version where they work, and does it stay controlled when shared?

The standard requires that the current version of any relevant document is available at the point where the work is actually carried out, and that its distribution is controlled where necessary. A procedure that lives in the quality manager’s office but can’t be reached from the lab bench doesn’t meet that requirement.

Assessors often test this by asking staff directly where they would find the current version of a procedure. The answer is revealing. If it is a personal copy someone printed at induction, or a folder on a shared drive nobody has opened since last year, that points to a gap. Physical binders not updated after revisions, shared drives reachable from office desks but not lab workstations, and staff keeping their own local copies are all common problems.

Controlled distribution also means a document keeps its identity when it moves between people, teams or sites. In a well-configured electronic system this is automatic. In email-based or manual setups, documents lose their identity easily: files renamed when saved locally, revision status not visible on an attachment, or a version sent out that no longer matches the current one.

8.3.2 e) Does every document have a unique identifier?

Every controlled document needs a stable, unique identifier that distinguishes it from every other document in your system, including earlier versions of itself.

The format is not prescribed. Most labs use a combination of a document type code, a sequential number and a revision indicator. Something like CAL-SOP-014-R02 tells you at a glance what kind of document it is, which one within that family, and that you are looking at revision 2. What matters is that the convention is consistent across all document types and that no identifier is ever reused.

The gap assessors find most often here is inconsistency, particularly where different teams have developed their own naming conventions independently. Another is documents identified only by title, with nothing to indicate which version they are.

8.3.2 f) Are obsolete documents withdrawn and clearly marked?

When a revised version of a document is released, the previous version needs to be removed from active use. If obsolete versions are kept for any reason, such as historical reference or traceability, they must be clearly identified as obsolete to prevent inadvertent use.

This is one of the most reliably tested requirements during assessments, precisely because it is so easy to check. An assessor can simply walk through the lab and see what is accessible. Old versions sitting in shared folders alongside current ones, unlabelled superseded SOPs in binders, and archived documents reachable from the same location as current ones are all nonconformities waiting to happen.

Quick reference summary

Clause

Checklist question

Evidence to have ready

8.3.1

Are all documents, internal and external, under control?

Document register that includes external documents, with evidence they are current

8.3.2 a)

Are documents approved before use?

Approval records: approver name, date, authority

8.3.2 b)

Are documents reviewed and updated at appropriate intervals?

Review schedule and completed review records

8.3.2 c)

Are changes and the current revision status identified?

Revision indicator, revision date and change history

8.3.2 d)

Is the current version available at the point of use and controlled when shared?

Access demonstration or distribution records

8.3.2 e)

Does every document have a unique identifier?

Naming convention and document register

8.3.2 f)

Are obsolete documents withdrawn and clearly marked?

Archiving process with obsolete labelling

Where does a document management system help?

Shared drives, email-based approvals and physical binders can satisfy the requirements of clause 8.3 in principle. The difficulty is keeping them consistent as your document set grows, your team changes and revisions pile up. That is where manual systems tend to come apart.

A document management system (DMS) handles the controls that are hardest to maintain manually. Approval workflows enforce sign-off before a document is released, so nothing drifts into use without being authorised. Automatic versioning handles the identification and revision-status requirements. Scheduled review reminders mean overdue reviews do not quietly slip past. Role-based access means staff only ever see the current approved version. And when a new version is released, the old one is archived automatically with a clear audit trail. For a broader look at what this means in practice, see our guide to the key benefits of a DMS for regulated industries.

For calibration and metrology labs operating under ISO/IEC 17025, the Cognidox DMS provides this kind of control without adding unnecessary process overhead for your team. Rather than piecing together evidence the week before an assessment, you have it ready to show whenever you need it.

Learn more about Cognidox DMS

Key takeaways

Clause 8.3 has two parts. Clause 8.3.1 requires you to control all documents that relate to meeting the standard, internal and external. Clause 8.3.2 sets out six specific controls: approval before issue, periodic review and update, identification of changes and revision status, availability of current versions at the point of use with controlled distribution, unique identification, and prevention of the unintended use of obsolete documents.

Each one has a specific evidence trail that assessors will look for. The most common weaknesses are uncontrolled external documents, informal approval practices, review cycles that are defined but not followed, revision status that is not kept up to date, and superseded versions left accessible alongside current ones.

None of these is a difficult problem to solve individually. Maintaining them consistently as your lab evolves is where a structured approach and the right tools make a real difference.

Ready to see how Cognidox supports ISO/IEC 17025 labs? Book a demo, and we can walk you through how a DMS can be configured to meet your lab's specific document control needs, from approval workflows to archiving obsolete documents.

New call-to-action

FAQs

1. What is the difference between clause 8.3 and clause 8.4 in ISO/IEC 17025:2017?

In ISO/IEC 17025:2017, clause 8.3 covers management system documents: the procedures, policies, methods and instructions that describe how your lab operates. These are revised over time as your methods and processes change. Clause 8.4 covers records, which are the evidence generated by carrying out those activities, such as calibration results, completed worksheets and training sign-offs. Records are not altered without a traceable, authorised correction that preserves the original entry.

2. Does clause 8.3 apply to documents the lab did not write?

Yes. Clause 8.3.1 applies to internal and external documents alike. External documents such as manufacturer’s instructions, reference standards and calibration tables that your methods rely on need to be identified and kept current in the same way as your own procedures. Uncontrolled external documents are a common assessment finding.

3. Does ISO/IEC 17025:2017 specify how long management system documents must be retained?

ISO/IEC 17025:2017 clause 8.3 does not set retention periods for documents. Retention requirements for records are addressed under clause 8.4. When setting your own retention periods, it is worth also factoring in your accreditation body’s expectations, whether UKAS in the United Kingdom or A2LA, NVLAP or ANAB in the United States, along with any customer contracts and applicable regulatory requirements.

4. Are electronic approvals acceptable under clause 8.3?

Electronic approvals are acceptable under ISO/IEC 17025:2017 clause 8.3, provided the system is controlled, the approver’s identity is verifiable, and the approval record is traceable and protected from alteration. Your electronic approval setup should also align with the data integrity and information management requirements in clause 7.11. Most labs use a document management system to handle this in a way that is auditable and straightforward to demonstrate during an assessment.

 

Tags: Document Management and Control

Alexander Thomson

Written by Alexander Thomson

Alexander Thomson is CEO of Cognidox, a document control and quality management platform used by medical device, biotech and pharmaceutical organisations worldwide to stay audit-ready as they scale. His team works closely with quality and regulatory functions to replace manual and fragmented processes with controlled, compliant systems that support faster product development. He writes about eQMS, ISO 13485, FDA 21 CFR Part 11 and practical approaches to maintaining compliance without slowing innovation. See how Cognidox helps regulated teams stay audit-ready.

Related Posts

AI in Your Document Management System: What Works, What Doesn’t, and What You Need to Think About

Quick summary AI features in a document management system can speed up search, classification, ...

How a modern DMS supports M&A, scale, and due diligence

Growth changes the questions investors ask. It’s no longer just about what you’ve built, but how ...