QMS document control software should establish which document revision is authorized for a particular use, preserve the decisions behind that status and prevent superseded instructions from being mistaken for current instructions. Drafting and approval are only part of the job. Release, distribution, revision, historical retrieval and retirement need equally clear rules.
An approved SOP may have a future effective date or unresolved release prerequisites. A superseded SOP may still be essential evidence of how work was performed last month. Treating either as simply “approved” can give the reader the wrong answer.
This guide helps quality and document-control teams define those distinctions before configuring or evaluating an eQMS. It includes a lifecycle model, a reusable control matrix and a worked example. The controls are planning recommendations to adapt to your intended use; the regulatory sources below retain their specific scope.
Define the lifecycle around use, not just approval
Choose status names that fit your procedures, but define what each state permits. The following model is an example, not a mandatory set of software labels.
| State | Meaning in this example | Permitted use and next decision |
|---|---|---|
| Draft | Content is being prepared | Authoring and designated review; not routine operational instruction |
| In review | Identified revision is under formal assessment | Reviewers assess that revision; changes follow the defined return/review route |
| Approved, pending effectiveness | Required content approvals are complete | Release owner checks effective date and other applicable prerequisites |
| Effective | Authorized for the defined scope of use | Users follow this revision within its site/process applicability |
| Under periodic review | Continued suitability is being assessed | Existing authorization continues only as defined by the procedure; review alone does not create a new revision |
| Superseded or obsolete | No longer authorized for its former routine use | Clearly identified historical access; controlled withdrawal from points of use |
| Retained archive | Preserved according to record obligations | Authorized retrieval without silently restoring operational status |
Approval and effectiveness can occur together when your process allows it. Separate them when a date, implementation step or other condition lies between the two. The system should make that condition visible and should not imply release merely because the last reviewer signed.
Define scope alongside state. A global procedure, a site-specific instruction and a product-specific method can all be effective without being interchangeable. If a user asks for “the current method,” the system needs enough context to identify the intended document family, site and activity.
Distinguish instructions, templates and completed records
An SOP tells someone what to do. A blank controlled form structures how they record the work. A completed record provides evidence of what occurred. These objects can share a repository, but a new form revision should not rewrite previously completed records.
Identify the document types in scope: SOPs, policies, work instructions, specifications, methods, protocols, reports, forms and relevant external references. Quality-event records such as investigations or CAPA may be managed in another module; link their authoritative records rather than assuming that every object is an ordinary editable document.
For each type, define its owner, approvers, lifecycle, required metadata, retention basis and relationship to dependent records. The document controller administers the process; the technical owner is responsible for content within the assigned role. Quality and other functions exercise the approvals required by the applicable process. A software administrator does not acquire content-approval authority merely by having configuration access.
EU GMP Chapter 4 distinguishes instructions from records/reports. Its January 2011 revision also addresses controls over templates and copies, identification, approval, effective dates and regular review. These expectations support designing the relationships between objects, rather than applying one file workflow to everything. EU GMP Chapter 4, revision 1, sections 4.1–4.5.
Establish the applicable regulatory basis
For US finished-pharmaceutical production and process controls, 21 CFR 211.100 requires written procedures and changes to be reviewed and approved by the appropriate organizational units and quality control unit. It also requires following the procedures and recording and justifying deviations. The regulation establishes responsibilities and required behavior; it does not select an eQMS vendor. 21 CFR 211.100.
For medical devices, FDA's QMSR became effective February 2, 2026 and incorporates ISO 13485:2016. Manufacturers subject to Part 820 must document a QMS meeting applicable ISO and additional FDA requirements. Section 820.35 adds specified record requirements to ISO 13485 clause 4.2.5; it is not a substitute for the complete applicable standard. FDA QMSR overview, 21 CFR 820.10 and 21 CFR 820.35.
For relevant electronic records and signatures, determine Part 11 applicability from record use and underlying requirements. The regulation addresses closed-system controls and electronic-signature requirements, including signature meaning and linkage. FDA's scope-and-application guidance describes enforcement discretion for specified provisions while preserving applicable predicate-rule obligations. A generic “Part 11” product label cannot resolve that analysis for your implementation. 21 CFR Part 11, FDA scope-and-application guidance.
Keep the applicability assessment with the requirements. Include relevant document populations and electronic/paper boundaries, the authoritative record and the controls you rely on. This avoids both under-controlling required evidence and imposing an identical signature workflow on every administrative file.
Configure release as an explicit decision
Start with the identified revision. Review comments and approval records must relate to the content actually assessed. If substantive content changes after approval, route it through the applicable change and approval process; do not retain an earlier approval as though it covered the changed text.
Define who can approve, reject, withdraw and release. Distinguish review, approval and acknowledgement where they serve different purposes. Include delegated roles, absence coverage and administrator actions in the authority model. Record decisions and reasons through the approved mechanism rather than relying on an email that is disconnected from the document.
Release prerequisites might include an approved implementation plan, affected-site readiness, necessary training or a future effective timestamp. Specify which apply to the document and how the responsible person establishes completion. Training design and qualification belong in their own process; this workflow needs the correct prerequisite result and its source, not a copied summary with unclear meaning.
Avoid a universal “everyone must acknowledge every change” rule. Determine the affected roles and appropriate action through the training-impact process. Likewise, a complete acknowledgement list should not override a separate implementation restriction. The release decision needs all applicable conditions, not whichever dashboard turns green first.
For urgent changes, use the authorized procedure with explicit scope, approval, communication and follow-up. Urgency should not silently transform an unapproved draft into an effective instruction or justify backdating a decision. If the ordinary route cannot be followed, the responsible quality/process owners need to determine and document the appropriate handling.
Use this document-control matrix
Copy the matrix for one document family and add the requirement ID, system/configuration, responsible person, evidence reference and disposition. Mark each row Pass, Fail, Unresolved or Not applicable with rationale. A supplier statement can identify a proposed capability; it is not the same as evidence that your configuration performs it.
| Control area | Required behavior to define | Evidence or boundary exercise |
|---|---|---|
| Identity and applicability | One identifiable document/revision with site, product or process scope as needed | Two similar titles do not cause the wrong instruction to be selected |
| Draft separation | Working content cannot masquerade as an effective instruction | Ordinary user sees correct state through search, direct link and export |
| Review and approval | Authorized decisions bind to the assessed revision | Rejected or subsequently changed content does not inherit an invalid approval |
| Effective release | Defined prerequisites and timing control operational availability | One unresolved prerequisite prevents unsupported release |
| Permissions | Roles permit only their assigned actions | Unauthorized user cannot approve, release or alter controlled history |
| Change/history | Relevant changes and decisions remain reconstructable | Content revision and metadata-only change are distinguishable |
| Distribution and copies | Current-use access and permitted copies follow the release rule | Superseded print/local copy has an assigned withdrawal or reconciliation action |
| Template lineage | Completed record identifies the form/template basis where needed | New template revision does not rewrite old completed evidence |
| Periodic review | Assigned owner assesses continued suitability | Overdue review produces an owned disposition, not invented approval |
| Retention and retrieval | Required history remains readable and accessible | Historic revision is retrieved without making it current |
| Export and exit | Required content and context survive an agreed export | Receiving reviewer can identify revision, state and relevant approval evidence |
Treat mandatory unresolved controls as open work with an owner and next evidence step. Do not average a missing release control against attractive search or reporting features. If assessing an unimplemented system, clearly label the outcome as design or procurement readiness rather than production acceptance.
The matrix can also expose a boundary between applications. If the document module gets prerequisites from a training or change-control system, specify which record and status it consumes, how failures appear and who resolves discrepancies. A failed connection should not convert “unknown” into “complete.”
Work through an effective-date and obsolete-copy failure
Assume a fictional laboratory uses SOP-LAB-012 revision 3. Revision 4 is approved for a planned release at 09:00 UTC on an agreed implementation date, after the required site-readiness review. A controlled printed copy of revision 3 is issued at the laboratory workstation. These are example conditions, not regulatory deadlines.
Before release: The readiness decision remains unresolved. The matrix's effective-release row therefore cannot pass. Revision 4 stays approved but pending effectiveness under the example procedure. Whether work can continue under revision 3 depends on its existing authorization and any separate operational restrictions; a pending revision is not itself permission to continue or stop work.
At the planned time: Advancing the clock does not complete the missing readiness decision. If the software releases revision 4 solely because the scheduled timestamp arrived, the observed defect is at the release condition. Correcting a status afterward is insufficient without addressing why an unmet prerequisite was ignored.
After authorized release: Assume the responsible owners resolve the prerequisite and authorize the recorded transition. Current-use access now points to revision 4 for the intended scope. Revision 3 remains available as history. The printed-copy register identifies the workstation copy and its required replacement or withdrawal action.
Keep planned and actual release times separate in the evidence. Under this example's procedure, the following observations lead to different decisions:
| Observation | Expected disposition | Evidence to retain |
|---|---|---|
| At 08:59, readiness is complete but the agreed effective time is still 09:00 | Revision 4 remains pending until its authorized effective time | Readiness decision and scheduled transition |
| At 09:00, readiness is still unresolved | Hold revision 4; the scheduled time does not supply the missing authorization | Unresolved prerequisite, owner and release hold |
| At 09:15, the prerequisite is resolved and release is authorized | Record the actual authorized transition at 09:15 | Decision, identified revision and actual timestamp; do not backdate release to 09:00 |
These are three test conditions, not three observations from a customer system. A supplier demonstration passes this example only if the retained record and ordinary user's access agree with the applicable condition. An untested scheduled transition remains unresolved even if an administrator can change the status manually.
When the old print is discovered: A supervisor finds revision 3 still at the workstation. The team follows the applicable procedure to prevent unintended use, reconciles the issued copy and assesses whether work was affected. The system's correct online version does not erase the distribution failure. Retain the finding and decisions; do not delete revision 3's history or change past records to suggest revision 4 was used earlier.
Now change one condition: the procedure permits approval and effectiveness together, with no deferred prerequisites. A combined transition can be valid if the defined requirements are met. The necessary control is accurate authorization and use context, not forcing every company to adopt an extra lifecycle state.
Control copies beyond the main repository
Search results are only one route to a document. Review links in equipment screens, bookmarks, work instructions, exports, downloaded PDFs and paper copies. Determine where the organization relies on a copy for controlled work and what keeps that use aligned with the authoritative revision.
For issued controlled copies, record the copy identifier or other tracking method, version, location or recipient, purpose and reconciliation responsibility. Define how replacement, withdrawal, loss and destruction are handled. For reference-only exports, make their limitations clear and establish how users obtain the effective instruction when required.
A watermark can communicate state but does not prove that every obsolete copy was removed. Revoking a link does not recall a previously downloaded file. These technical and procedural boundaries should appear in the acceptance evidence and operating procedure, rather than being hidden behind an “obsolete” label in the database.
If the project replaces paper-based distribution, use the paperless QMS software guide to assess the operating change alongside repository features. Include the workstation, offline and issued-copy paths in the rollout scope.
Keep historical retrieval intentional. An investigator may need the exact procedure applicable to an earlier event. The reader should see its identity, period or scope of use and retired status without accidentally promoting it into today's operational path. Separate access to history from authority to reactivate it.
Preserve records through revision, review and retirement
Periodic review is a decision about continued suitability. Define the owner, trigger or interval, evidence and outcome. An overdue review needs assessment and escalation under your procedure; do not assume it always causes automatic expiry or that the system can silently renew approval. Different document classes can justify different rules.
A revision should identify why the change was made and what dependent documents or processes require assessment. Where relevant, link the initiating quality event and regulatory impact decision. The pharmaceutical change-control guide covers that wider process; document control needs its resulting conditions and traceable evidence.
Retiring a form template should not erase the completed records created from it. Preserve the version relationship and the actual entries. If historical data need correction, use the applicable record-correction process rather than rebuilding the old record with today's blank form and implying it existed that way originally.
Set retention by record type and applicable obligations. For records within its scope, 21 CFR 211.180 addresses retention and inspection availability, including immediately retrievable records held elsewhere and original records or true copies. It is not a universal retention period for every SOP or QMS file. 21 CFR 211.180.
Before migration or platform exit, define the required content and context: versions, metadata, decisions, applicable signature/audit evidence and relationships. Check retrieval in the proposed retained environment. A current-PDF export can be useful without being sufficient for all historical-record obligations.
Evaluate software with your actual lifecycle
Ask a supplier or implementation team to configure one representative document family and explain the ownership of each control. Request the exact product/module scope, configuration dependencies and customer work. A broader eQMS package may include document control, but its name does not establish that training, quality events or integration services are included in your proposal.
Exercise the matrix with representative roles and evidence. Include a rejected draft, changed content after approval, an unresolved release condition, a superseded direct link, a retained historical revision and an export. Record what was observed, what remains untested and which behavior depends on a procedure outside the software.
For an existing system, use a permitted test environment or other approved verification approach. Do not create misleading production approvals merely to demonstrate a feature. Assess supplier releases and configuration changes against the controls your organization relies on, and keep operating responsibilities assigned after go-live.
This is a lifecycle evaluation, not a vendor ranking. The computerized system validation guide provides wider planning context. The right result is evidence for your defined use, with open issues visible and owned.
Keep regulatory summaries tied to the source actually used
A specification, method or validation report may later support a regulatory narrative. Preserve the source document ID and exact revision behind that statement. When the source changes, assess the affected narrative; do not silently replace its link with the newest revision and imply that the earlier text was based on it.
Document approval, a quality decision and a regulatory filing decision remain distinct. Use the quality-to-regulatory traceability guide to define their handoff. Controlled source evidence supports that work, but an effective SOP alone does not establish submission readiness.
Assyro publishes this guide. If your next task concerns regulatory document preparation or review, evaluate Assyro's document-management offering against that bounded workflow. Confirm the actual controls, interfaces and evidence needed; do not infer a full eQMS, training platform or device-submission capability from this article. Discuss a representative document lifecycle with Assyro, including the authoritative source and the decision the output must support.
About the author
Assyro Team
Expert regulatory operations consultants helping pharmaceutical companies navigate complex compliance challenges.

