Text banner with words Food Safety coming soon in bold white and blue letters on black background.
Interviewing Sigma Foods FSQA Leader — Jan 27, 3:00 PM ET
13 min read
Last Updated
August 5, 2026

Document Control Procedure for Food Manufacturers

Document Control Procedure for Food Manufacturers

An auditor walks your line, picks up the laminated SOP hanging at a station, and checks the revision number against your master list. It is two revisions out of date. That single finding tends to cascade, because if the document control system failed here, the auditor now has a reason to check everywhere else.

A document control procedure is the written process that prevents exactly this. Most of what has been published about it is framed around ISO 9001 and generic quality management. This is the food manufacturing version, grounded in what FSMA actually requires of your records and what SQF, BRCGS, and FSSC auditors actually check.

What is a document control procedure?

A document control procedure is the written procedure governing how documents in your food safety and quality management system are created, reviewed, approved, issued, revised, withdrawn, and retained, so that only current approved versions are in use.

It is the procedure auditors examine first, because every other claim in your system depends on it being real. If you cannot demonstrate that the HACCP plan on the wall is the current approved revision, the auditor has no basis for accepting anything built on it.

The scope is wider than most people assume. It covers not only the documents you author but the records those documents generate, and the external documents you rely on but did not write. Where document control sits inside the wider system is covered in our guide to food safety management systems.

Documents vs. records: the distinction that decides everything

This distinction gets blurred constantly, and it determines how a piece of paper is versioned, who signs it, how it is corrected, and how long you keep it.

A document says what you will do. A record proves what you did.

Document Record
Purpose Instructs future work Evidences completed work
Examples SOP, SSOP, HACCP plan, specification, blank form Completed form, monitoring log, calibration record, training record
Versioning Revised and version-controlled Never revised; a new record is created
Correction Issue a new revision through approval Single-line strike-through, initial, date, reason
Signed by Author, reviewer, approver The person performing the activity
Retention basis Superseded versions retained per policy Retained per regulatory requirement

The rule that trips people up: a blank form is a document and gets version control. The same form once filled in is a record and never gets edited. Backdating or rewriting a record is a data integrity issue, not a document control one, and it is treated far more seriously.

FDA sets out what a compliant record must contain in 21 CFR 117.305: actual values and observations obtained during monitoring, information adequate to identify the plant, the date and time of the activity, the signature or initials of the person performing it, and where appropriate the product identity and lot code.

The food document hierarchy

Organising documents into levels makes numbering, approval authority, and review frequency fall out naturally rather than being decided document by document.

Level Document type Food examples Typical approver
1 Policy and manual Food safety policy, quality manual Senior management
2 Programs and plans HACCP plan, food safety plan, allergen control program, environmental monitoring program, master sanitation schedule Food safety team leader or PCQI
3 Procedures SOPs and SSOPs Department manager plus QA
4 Work instructions and forms Line-level instructions, blank forms, specifications Supervisor plus QA
n/a Records Completed forms and logs The person performing the activity

Level 2 is where most of your food safety system lives. The HACCP plan, the FSMA food safety plan, the allergen control program, and the master sanitation schedule all sit at this level, and all require senior technical approval. Your SSOPs sit at Level 3.

A numbering convention that reflects the hierarchy makes the system self-documenting. Something like QA-2-004 for the fourth Level 2 document owned by QA is enough. What matters is that the number is unique, permanent, and never reused when a document is withdrawn.

The written food safety plan is a required document in its own right under 21 CFR 117.126, which lists everything it must contain.

What goes in your document control procedure

Work through this list and you have a complete procedure. Each item should be a short section rather than a paragraph of prose.

  • Scope, stating which documents and records the procedure covers and which it does not
  • Roles and authorities, defining author, reviewer, approver, and document controller
  • Numbering and identification, including the convention and how numbers are allocated
  • Version and revision conventions, including how revision numbers increment
  • The approval workflow, from draft through review, approval, and publication
  • Issue and controlled distribution, covering who receives what and how
  • Withdrawal of obsolete copies, including the retrieval record
  • Change history and reason for change, captured on every revision
  • Scheduled review cycles, by document type
  • External document control, for documents you did not author
  • Retention and archiving, by record type
  • Emergency or temporary changes, and how they are subsequently formalised

That last one is frequently missing and frequently needed. When a line change has to happen at 2am, people will write on the SOP. The procedure should say how that is handled and how it gets formalised within a defined window, rather than pretending it never happens.

Version control that holds up

Revision numbering only has to be consistent. Sequential integers work. Major and minor decimals work. What matters is that the current revision is unambiguous and that history is retrievable.

Reason for change is the field auditors read. A change history that says "Rev 4, updated" is worthless. "Rev 4, cook step critical limit changed from 74°C to 76°C following revalidation, ref. validation study VS-2026-03" tells the auditor what happened and why, and it links to the evidence.

The author cannot be the sole approver. Someone independent of the drafting has to approve, and for Level 1 and 2 documents that person should have the technical standing to challenge the content.

Separate the approval date from the effective date. These are different, and the gap between them is where training happens. A revised SOP approved today and effective in two weeks gives you time to train the people who will follow it. Making a document effective the moment it is approved guarantees that somebody works to a revision they have never seen.

Training on the change is part of the change. If a revision alters what an operator does, the revision is not complete until affected staff have acknowledged it.

Allera's Document Control module handles this workflow directly. Revisions move through Draft, Pending Approval, and then Approved or Denied, before Publishing, with the revision and approval history retained and exportable. Training Management can require assigned users to acknowledge that they have read a document, with inheritance from parent folders, so the acknowledgment trail sits alongside the revision trail.

Getting obsolete copies off the floor

This is the problem document control exists to solve, and it is a physical problem before it is a systems problem.

Obsolete copies hide in predictable places. Laminated station copies. The QA binder nobody has opened in a year. A printout taped inside a cabinet door. A PDF on a supervisor's desktop. A copy in someone's locker because it was easier than walking to the terminal.

The traditional control is the controlled copy register: numbered copies, a distribution list, and a retrieval record proving the old version came back. It works, and it only works if someone actually walks around and collects them. Most facilities maintain the register and skip the walk.

"Uncontrolled copy" stamps are the other conventional answer. They are honest, and they are also an admission that a document is circulating outside your control.

Moving to a single digital source removes the problem rather than managing it. If the current published revision is what people see when they open the document, there is no obsolete copy to retrieve. Allera's Document Control uses four access levels, Read-Only, Limited Edit, Full Edit, and Owner, with inheritance from parent folders, so operators see the published revision and cannot reach drafts or superseded versions.

Printing does not disappear entirely. What changes is that the printed copy becomes a convenience item with a visible print date, not the authoritative version.

Scheduled reviews, and what happens when one lapses

Every controlled document should have a defined review frequency. Annual is the common default. Higher-risk documents and anything tied to a validated process usually warrant more frequent review.

A review that concludes "no change required" still has to be recorded. The reviewer, the date, and the outcome go in the change history exactly as a revision would. An auditor cannot distinguish a document that was reviewed and confirmed from one that was forgotten unless you write it down.

Overdue reviews compound. One overdue SOP is a minor finding. A pattern of overdue reviews across the system suggests the document control procedure is not being followed, which is a systemic finding and much harder to close. Your internal audit program should be checking review currency as a matter of course.

Scheduled Review in Allera's Document Control sets the policy per document or folder and flags documents approaching or past their review date, so the overdue list is something you look at rather than something an auditor finds.

Controlling documents you didn't write

External documents are the most commonly overlooked part of a document control system, and a routine source of findings.

These include supplier specifications, certificates of analysis, allergen statements, third-party certificates, equipment manuals, chemical safety data sheets, and regulatory guidance documents. You cannot revise them, and you still have to control them.

What control means for an external document: it is on a register, it has a named owner, the current version is identified, and someone checks whether a newer version exists. For certificates specifically, expiry tracking is the whole game. A supplier's GFSI certificate that lapsed four months ago is a document control failure and a supplier approval failure at the same time.

This connects tightly to your supplier approval program, and the certificate of analysis is the external document you handle most often.

How long do you have to keep everything?

Retention is governed by regulation, not preference, and the answer varies by record type and product category.

Record type Governing framework Practical guidance
Records subject to the preventive controls rule 21 CFR 117.315 Follow the section's stated retention period for your record type
The written food safety plan 21 CFR 117 Subpart F Retained as a record; superseded versions kept
Meat and poultry records USDA FSIS Retention varies by product type; consult the FSIS recordkeeping guidance
Certification scheme records SQF, BRCGS, FSSC 22000 Generally the audit cycle plus history; often longer in practice than the legal minimum

Two practical rules beyond the minimums. Keep records at least as long as the product's shelf life plus a margin, because a complaint can arrive at the end of shelf life and you will want the production record. And keep superseded revisions of controlled documents, since reconstructing what an operator was instructed to do at the time of an incident requires the revision that was current then, not the one current now.

21 CFR 117 Subpart F sets out which records are subject to the requirements and the general obligations that apply to them, and 117.301 defines the scope.

Records also have to be retrievable, not merely retained. A box in a storage unit off site satisfies retention and fails the practical test when an investigator asks for a specific record during a visit.

Sharing documents with auditors without losing control

The usual approach is emailing a PDF, and the usual outcome is that the document now exists somewhere you cannot see, at a revision that will eventually be superseded, with no record of who has it.

Controlled external sharing should be scoped to specific documents rather than a folder, time-limited so access expires, revocable per recipient, and logged so you know who opened what.

Allera's Document Vault is built for this. You share specific documents with an external recipient who authenticates with a one-time passcode sent to their email, without needing an Allera account. Access is revocable per recipient and vaults can be set to expire automatically. For an auditor requesting a document pack, or a customer asking for your certifications, that is a materially better answer than an email attachment.

The full audit trail for a document, covering revision history, approval history, access control changes, and training acknowledgments, is exportable when an auditor wants the complete picture.

What the schemes require

Document control appears in every GFSI-recognised scheme and in the federal records requirements. The language differs; the substance is consistent.

Framework What it expects What an auditor asks to see
FSMA 21 CFR 117 Subpart F Records with required content, retention, and availability A named record, produced on request, meeting the content requirements
21 CFR 117.126 A written food safety plan with defined contents The plan, current, approved, complete
SQF Edition 9 Document control and records management within the FSMS Master document list, revision history, evidence current versions are in use
BRCGS Issue 9 Document control, record completion and maintenance Version control, completed records, obsolete document control
FSSC 22000 v6 and ISO 22000 Control of documented information Creation, approval, distribution, and retention controls
Codex Documentation and record-keeping as a general principle Records appropriate to the nature and size of the operation

The primary scheme documents are the SQF Food Safety Code for Food Manufacturing (Edition 9), the BRCGS Global Standard Food Safety (Issue 9), and the FSSC 22000 Scheme Version 6, all benchmarked under the GFSI Benchmarking Requirements. ISO 22000:2018 underpins FSSC 22000.

Preparation guidance for individual schemes sits in our SQF audit checklist, BRCGS certification, and FSSC 22000 Version 6 guides.

When paper document control stops scaling

Paper works at a single site with a small document set and one diligent document controller. It breaks at three predictable points.

Multiple sites. Site A revises an SOP, Site B does not hear about it, and two plants now run different procedures under one certificate.

Multiple shifts. Night shift cannot reach the document controller, so somebody photocopies what is available.

The single point of failure. The document controller goes on leave and the system pauses. When that person leaves the company, knowledge of which document is where leaves with them.

What to look for: an enforced approval workflow rather than an honour system, scheduled review that fires before the due date, access control that prevents operators reaching drafts, a full exportable audit trail, and in-browser editing so people work on the live document instead of a downloaded copy that immediately diverges.

Allera's Document Control covers those, including editing Word and Excel documents and annotating PDFs in the browser. Our roundup of document control software for food manufacturers compares the wider market. Document control living in a separate tool from your forms and records creates two systems to reconcile at audit time, which is why it sits inside the broader food quality management system.

Start with the hierarchy

If your document control needs work, the most useful first move is not writing a new procedure. It is listing every controlled document you have and assigning each one a level, an owner, a current revision, and a review date.

That exercise surfaces the real problems quickly: documents with no owner, revisions nobody approved, SOPs that have not been reviewed in four years, and external certificates that expired months ago. Fix those, then write the procedure that keeps them fixed.

To see how approval workflows, scheduled reviews, access control, and exportable audit trails work in one place, take a look at Allera's Document Control module or the wider food quality management software overview.

FAQs

Retention depends on the record type and product category. Records subject to the preventive controls rule follow 21 CFR 117.315, meat and poultry records follow USDA FSIS requirements, and certification schemes generally expect records across the audit cycle. As a practical rule, keep records at least as long as product shelf life plus a margin.

A document instructs future work and is revised through a controlled process. A record evidences completed work and is never revised, only corrected with a single-line strike-through, initials, date, and reason. A blank form is a document; the same form filled in is a record.

Yes. SOPs sit at Level 3 of the hierarchy and require a unique number, version control, defined approval, controlled distribution, and a scheduled review cycle. A completed record generated by an SOP is not a controlled document and is never revised.

Level 1 is policy and manual. Level 2 is programs and plans, such as the HACCP plan and allergen control program. Level 3 is procedures, including SOPs and SSOPs. Level 4 is work instructions and blank forms. Completed records sit outside the hierarchy because they are evidence rather than instruction.

Most facilities maintain document control as its own SOP, typically numbered near the top of the quality system. That SOP defines how every other document is created, approved, issued, revised, and retained, including itself.

Record a reason for change on every revision, since that is the field auditors read. Separate the approval date from the effective date so training can happen in between. Keep the author out of the sole approver role.

Control external documents such as supplier specifications and certificates, not just the ones you author, and track certificate expiry. Move to a single digital source where possible, which removes the obsolete-copy problem rather than managing it.

ISO 9001 addresses this under control of documented information, covering creation, approval, distribution, version control, and retention. ISO 22000 applies the same logic to food safety management systems.

For a US food manufacturer, ISO is not the governing requirement. Records are subject to 21 CFR 117 Subpart F, and your GFSI-recognised scheme, whether SQF, BRCGS, or FSSC 22000, adds its own document control clauses on top.

A document control procedure typically covers scope, roles and authorities, numbering conventions, version and revision rules, the approval workflow, controlled distribution, withdrawal of obsolete copies, change history, scheduled reviews, external document control, and retention.

In a food plant the documents being controlled include the HACCP plan and food safety plan at programme level, SOPs and SSOPs at procedure level, and blank forms at work-instruction level. Completed forms are records, which are never revised.

Define your document hierarchy, assign a unique number to every controlled document, route revisions through a defined draft, review, and approval workflow, and publish only approved versions.

Then withdraw obsolete copies and record the retrieval, set a review frequency per document type, and retain superseded versions according to your retention policy. The author should never be the sole approver.

author
Paddy McNamara
Co-Founder & CEO
Paddy McNamara, Author of the Allera Technologies blog.
Paddy McNamara is the Founder and CEO of Allera Technologies, helping food manufacturers modernize food safety and compliance. After nearly dying from a severe food allergy, he started Allera to reduce risk and simplify FSQA. He writes to demystify food safety regulations and shares insights on LinkedIn while connecting with FSQA professionals at conferences and Food Safety Night meetups.
Food Safety Leadership: 5 Lessons from Jill Stuber
Jill Stuber
Co-Founder, Catalyst Food Leaders
Logo with the text 'THIRTY FOOD SAFETY' in bold uppercase letters.
30-min Interviews with the Brightest Minds in FSQA
100% Free access to 20+ videos
Access now
Decorative
Enjoy free access forever!
Oops! Please enter a valid email address
Food industry leaders from Mars, Wendy’s, and Lyons Magnus featured in a food safety and quality management discussion — highlighting innovation and compliance in global food manufacturing.