Document control and records management compared by lifecycle and retention

Content authorBy Toomas PihlPublished onReading time8 min read
Businesswoman standing in an office with a workflow diagram, illustrating document control and records management by lifecycle and retention.

This article compares document control and records management by lifecycle stage and retention rule. It uses ISO 9001 and ISO 15489 to locate the moment a working document stops being editable and becomes fixed evidence, then follows an inspection form and a set of signed agreements through that point.

Why the distinction matters

Most compliance failures begin quietly. A work instruction gets printed. Document control issues revision 4 a week later, and the printed copy stays taped to the machine until an auditor finds it. The same confusion runs in the other direction when a completed form sits in an editable folder where anyone can correct a reading after the fact.

Regulators notice. Between 2008 and 2025, medical device companies received 1,556 citations under §820.40 covering document approval and change control, based on an export of the FDA Data Dashboard. The pattern behind those findings is the same: nobody decided who owns operational instructions and who owns finished evidence.

Documents and records defined

ISO 9001 splits documented information into two categories with different verbs. Information you maintain documented information for exists to direct work, while information you retain exists to prove results were achieved. Procedures and forms belong to the first group. Completed forms and calibration certificates belong to the second.

The retained side is where ISO 15489 takes over. According to ISO 15489-1:2016, clause 5.2.2, records are authoritative evidence of business only when they carry four characteristics:

  • Authentic, which means the record is what it claims to be and was created by the person or process it names

  • Reliable, so it can be trusted as a full and accurate account of the transaction

  • Complete and unaltered, which is integrity

  • Usable, so it can be found and interpreted for as long as it's needed

The standard also names what separates a record from any other file. Records "can be distinguished from other information assets by their role as evidence in the transaction of business and by their reliance on metadata," and that metadata preserves context and applies the rules for managing the record. ISO 23081-1:2017 sets the principles for that metadata across records and the systems holding them. So the document control vs document management question is narrower than it sounds. Control governs what people are allowed to do next. Records preserve what people already did.

Documents shouldn't be manual work.

Standardize how your business creates, manages, and signs recurring documents - without complex enterprise software.

Document control compared

Nine dimensions separate the two disciplines in daily practice. Read the table as a handoff, because each column describes the same information at a different stage of its life.

DimensionDocument controlRecords management
PurposeDirects how future work is performedProves a specific activity happened
Lifecycle stageDraft through active use and withdrawalCapture through retention and disposition
Permitted changesRevisions through a controlled change processNo content changes after capture
ApprovalRequired before issue and after every revisionAuthorization at release or signature only
Version controlNumbered revisions with an effective dateNot versioned, fixed at a point in time
AccessCurrent version available at every point of useRestricted to those with a business need
OwnershipProcess owner or the issuing functionRecords owner or the compliance function
Retention triggerWithdrawal of the revisionCompletion, signature or transaction close
Final dispositionRemoved from use, history retained as neededAuthorized destruction or permanent preservation

Notice how the change rows behave. Anyone weighing document control vs document management for the first time finds the difference in whether editing the content is legitimate work or evidence tampering. That single distinction drives everything else in the table and determines who holds the keys.

Follow an inspection form

Take a receiving inspection form used on an assembly line. As a blank template with fields and a revision number in the footer, it's a controlled document that tells inspectors what to measure. The moment an inspector signs it and releases the lot, the same file becomes the only proof that the lot was checked at all.

One file, two regimes. The template keeps changing as tolerances tighten, while the completed copy from last Tuesday can never change again. The rest of this comparison follows that form through both halves of its life, because the document control process and the records process each own a different piece of it.

Document control process

The document control process starts with drafting against a defined need and ends with approval by a designated authority before issue. Under 21 CFR 820.40, the approval must be documented with the date and signature of the approving individual, and the document has to be available at every location where it's designated or used. Release and distribution are part of the control.

Revision follows the same route. FDA training material on document controls requires change records to include a description of the change and identification of the affected documents. The same records carry the approving signature and the approval date, with the date the change becomes effective. The regulation is blunt about what happens to the previous version: all obsolete documents must be promptly removed from all points of use or otherwise prevented from unintended use.

Removed from use is not the same as deleted. The change history of revision 3 explains why revision 4 exists, and that reasoning belongs in your retained evidence when an auditor asks how a tolerance moved. In a document control process worth the name, withdrawal ends availability while the change record survives on the records side of the wall.

Documents shouldn't be manual work.

Standardize how your business creates, manages, and signs recurring documents - without complex enterprise software.

Records management process

Now follow the completed form. Capture fixes the content together with the metadata that identifies who inspected, when, against which revision and for which lot. Active use is brief: a release decision or a customer query, after which access narrows to the people with a reason to see it.

From there the sequence is mechanical:

  1. Inactive storage in a repository that blocks content edits and logs access

  2. Retention for the period set by regulation or contract, counted from a defined trigger

  3. Authorized destruction on schedule, or transfer to permanent preservation for records with lasting value

Retention periods come from outside the quality system. 29 CFR 1904.33 requires the OSHA 300 Log and the annual summary to be kept for five years after the calendar year they cover, along with the 301 Incident Report forms. OSHA kept that period because the longer window lets employers, employees and researchers "obtain sufficient data to discover patterns and trends of illnesses and injuries." Disposition itself is a documented process under ISO/TS 7538:2024, which covers reviewing whether disposal is permitted and recording that it happened.

Protection from unauthorized alteration is the point of all of it. The European Commission's draft revision of GMP Annex 11 requires audit trail functionality to be enabled and locked at all times and states that it should not be possible for any user to edit audit trail data. A record that anyone can quietly correct proves nothing.

Define the lifecycle handoff

Teams that argue about document control vs document management have no written answer to one question: at what event does this file change hands? Write that event down for each document family, and most of the argument disappears. Specify six things:

  • The conversion event, which is completion, signature or transaction close in almost every case

  • The metadata captured at conversion, which covers the template revision in force, the responsible person and the timestamp

  • The named owner after conversion, who is rarely the same person who owned the template

  • Access permissions, which tighten once evidence is fixed

  • The retention trigger and the clock it starts

  • The repository that holds the fixed file and enforces the rule against editing

Signature deserves particular attention because it carries legal weight of its own. Under Article 25 of the eIDAS Regulation, an electronic signature cannot be denied legal effect or admissibility as evidence solely because it's electronic, and a qualified electronic signature has the equivalent legal effect of a handwritten one. Once that signature lands, what matters is whether the signed version and its signature evidence stay intact for as long as the retention rule says.

Where Agrello fits

Agrello is a document management and e-signing platform that collects signatures with a national e-ID or its own advanced electronic signature and stores the signed files digitally. For agreements specifically, that covers the part of the handoff most teams handle worst: keeping the signed file and the signature evidence together in one place with controlled access.

Be precise about the boundary. Agrello preserves completed agreements with their signing evidence. In a document control vs document management architecture, treat it as the repository for signed agreements and connect it to whatever holds your retention rules.

Apply document control rules

One test settles most cases. Ask whether the information directs future work or proves a completed activity. If it directs work, control the version and withdraw obsolete copies from use. If it proves activity, freeze the content and hold it to the retention schedule until authorized destruction or permanent preservation.

Agrello supports the evidence side of that split for signed agreements. Talk to our team about where your handoff sits, or start a free trial and test it against your own document control rules.

Documents shouldn't be manual work.

Standardize how your business creates, manages, and signs recurring documents - without complex enterprise software.

Capture the responsible person, completion or signature time, transaction or lot reference, and the template revision used. Add the record’s status, location, and retention trigger when your schedule requires them. This metadata supports document control by preserving context and helping users verify that the file is authentic, complete, and usable.

Store the record in a system that blocks content edits after capture and keeps an access history. Preserve the original file with its signature or approval evidence, then review audit trail entries during investigations. Access permissions should allow authorized viewing while preventing users from replacing or silently correcting the retained content.

Start the clock from the trigger defined for that record class, such as completion, signature, lot release, or transaction close. Use one written trigger for recurring inspections and apply it consistently. The retention schedule should also identify the responsible owner, required period, and approval needed before destruction.

Yes, but it must be unavailable for operational use. Keep the withdrawn revision and its change history in a controlled archive with restricted access, while clearly marking the current version for use. This preserves evidence of what people were instructed to do without allowing an obsolete procedure back into circulation.

Agrello is suited to completed agreements and their signing evidence, rather than managing active work instructions through revision and distribution. Keep controlled instructions in the system that governs approval, effective dates, and withdrawal. Connect the retained signed agreement to the applicable retention schedule and restrict changes after signing.

Schedule a Meeting

Book a time that works best for you and let's discuss your project needs.

You Might Also Like

Discover more insights and articles

Business professional standing in a modern office, representing collaboration and document controls for legal, sales, and operations teams.

Which Collaboration Controls Do Legal, Sales and Ops Need?

Seven controls matter. They include defined roles and clause-level comments. Version history and review handoffs with visible approval status also matter, as do least-privilege access and event-based notifications. A documented signing-readiness check completes the set. Together they let the three departments contribute to the same agreement while only one person holds decision authority at each stage.

Business professional in a modern office representing cloud-based document management and streamlined digital workflows

How to keep document workflows moving with a cloud based document management system

This article explains how to build an approval workflow that keeps moving when someone is out of office or when a reviewer forgets. It covers mapping the lifecycle and configuring routing and escalation rules in cloud document management software.

Businessman reviewing a contract approval workflow in an office

How Do You Ensure the Approved Contract Gets Signed?

You get the approved contract signed by locking the file under one identifier and one owner, and you send only that locked file to signature. Everything else stays a draft. The control is unglamorous and it holds, because wrong-file risk lives in the gap between someone saying "looks good" and someone clicking send.

Woman evaluating remote signing solutions for business documents during a professional team meeting

How to Evaluate Remote Signing for Business Documents

Evaluate remote signing by testing signer access without paid accounts and mobile usability against your real contracts. Platform features matter less than whether your specific employees and suppliers can finish signing.