Controlled vs Uncontrolled Documents

Every GMP activity depends on personnel using the correct instructions, forms, and procedures.

Document control helps ensure that the information being used is current, approved, and appropriate for its intended purpose.

Understanding the difference between controlled and uncontrolled documents is therefore essential because document status influences how GMP activities are performed, documented, and evaluated during inspections.

This article explains what regulators mean by controlled and uncontrolled documents, how inspectors assess document status during inspections, and why uncontrolled documents are a frequent source of data integrity and compliance risk.

 

Why Controlled vs Uncontrolled Documents Matter in GMP

Controlled documents establish approved GMP requirements. Uncontrolled documents may support GMP activities, but they are not managed through the organization’s formal document control process unless defined otherwise.

Document status matters because:

  • SOPs define how work must be performed

  • forms generate GMP records

  • reference documents support technical and quality decisions

If document status cannot be demonstrated clearly, inspectors cannot trust that activities are being executed under approved conditions. This concern often escalates beyond documentation into broader data integrity questions.

The foundational role of documentation in system credibility is discussed further in GMP Documentation & Data Integrity.

 

What Regulators Mean by a Controlled Document

A controlled document is one that is formally governed by the quality system. While exact implementations vary, regulators expect controlled documents to demonstrate certain characteristics.

A controlled document typically has:

  • documented approval before use

  • version control and revision history

  • defined distribution or access control

  • clear status indicating the current effective version

What “controlled” does not automatically mean:

  • that the document is perfect or error-free

  • that it never changes

  • that it must be electronic

Inspectors assess whether a document is controlled by examining how it is managed, not by relying on labels alone.

 

What Regulators Mean by an Uncontrolled Document

An uncontrolled document is any document that is not governed by formal document control processes. This includes documents that were once controlled but are no longer current or properly managed.

Documents become uncontrolled when:

  • they are copied or printed without version control

  • they are stored outside approved systems

  • they are shared informally without status indication

  • their use is not defined or restricted

Uncontrolled does not necessarily mean prohibited. Some documents may be intentionally uncontrolled, such as general reference materials.

The regulatory concern arises when uncontrolled documents are used to perform GMP activities without defined controls to ensure that the information remains current and appropriate.

 

Common Misconceptions About Document Control

Several misconceptions contribute to document control failures.

Common examples include:

  • “Controlled means approved once and never revisited”.

  • “Uncontrolled means not important”.

  • “Electronic documents are automatically controlled”.

  • “Printed copies are always uncontrolled”.

Inspectors routinely test these assumptions by asking personnel how they know a document is current, approved, and applicable. Inconsistent answers indicate weak understanding of document status rather than isolated procedural gaps.

 

Controlled vs Uncontrolled Documents

Inspectors rarely ask whether a document is controlled in isolation. They assess document status through use and behavior.

Typical inspection approaches include:

  • observing which documents are used during operations

  • asking how personnel verify that the document is current

  • reviewing document headers, revision history, and access controls

  • comparing SOPs, forms, and records for version alignment

When inspectors find uncontrolled documents influencing GMP decisions, they question whether document control is functioning as intended.

The differences between controlled and uncontrolled documents can be summarized as follows:

Feature Controlled Document Uncontrolled Document
Approval Approved under document control Not governed by document control
Revision Current version maintained May not reflect latest version
Distribution Managed Not formally managed
GMP use Used to perform regulated activities Generally not used unless procedures define appropriate use
Inspection expectation Traceable and current Clearly identified and appropriately managed
 

Impact on SOPs, Forms, and Records

The distinction between controlled and uncontrolled documents directly affects execution and record reliability.

Key impacts include:

  • SOPs: Use of outdated or uncontrolled SOPs undermines procedural compliance

  • Forms: Mismatched form versions lead to inconsistent records

  • Records: Records generated using uncontrolled documents may be considered unreliable

These issues often surface as data integrity concerns rather than documentation issues alone. When records cannot be traced clearly to controlled source documents, inspectors question their validity.

How forms should be designed to support control is addressed in Designing GMP-Compliant Forms.

 

What Does “Uncontrolled When Printed” Mean?

Many electronic document management systems display the statement “Uncontrolled When Printed”. This does not mean the printed document is automatically incorrect or prohibited.

Instead, it means that:

  • the printed copy is no longer linked to the electronic document control system

  • future revisions will not automatically update the printed copy

  • users must have a defined process for verifying that the printed version remains current

For example:

Is a printed SOP always an uncontrolled document?

No.

Printed SOPs may be:

  • controlled copies

  • uncontrolled reference copies

  • temporary working copies

depending on the organization’s document control procedure.

 

What Are the Risks of Using Uncontrolled Documents?

Risks include:

  • performing work to obsolete instructions

  • generating records on outdated forms

  • inconsistent manufacturing practices

  • training against superseded procedures

  • inability to demonstrate compliance during inspection

These risks arise because personnel may unknowingly rely on information that no longer reflects the organization’s approved requirements.

 

How Long Is an Uncontrolled Copy Valid?

There is no universal time limit.

Validity depends on:

  • company procedures

  • whether the document has been revised or updated

  • whether verification of current status is required before use

An uncontrolled copy may become outdated immediately after a revision is approved.

For this reason, organizations should define how uncontrolled copies are verified before use whenever they may influence GMP activities.

 

Common Inspection Findings

Uncontrolled documents frequently contribute to inspection findings.

Example:

An inspector notices a printed SOP at a manufacturing workstation.

Rather than asking whether it is controlled, the inspector may ask:

  • “How do you know this is the current version?”

  • “Who issued this copy?”

  • “What happens when the SOP is revised?”

  • “How are obsolete copies removed?”

The objective is not to prohibit printed documents but to determine whether document status is effectively controlled.

 

How Document Status Fits Within Document Control Systems

Controlled vs uncontrolled status represent one component of a broader document control system.

Document status is linked to:

  • document lifecycle management

  • training and competency documentation

  • retrieval and inspection readiness

  • data integrity controls

Understanding document status in isolation is insufficient. It must be supported by processes that ensure documents remain current, accessible, and appropriately restricted throughout their lifecycle.

The end-to-end management of documents is explored further in Document Lifecycle: Creation to Archival, while inspection-ready access is addressed in Documentation Retrieval Protocols.

 

Regulatory Perspective

Regulators do not expect organizations to eliminate all uncontrolled documents.

They expect organizations to clearly define which documents are controlled, how that control is maintained, and how personnel recognize document status.

The distinction between controlled and uncontrolled documents defines the boundary of trust in a GMP system.

Inspectors rely on controlled documents to understand approved requirements and assess execution against them.

Clear control boundaries demonstrate that documentation is governed through defined processes rather than informal practice.

 

Explore more on Documentation & Data Integrity

Browse VerethiQ resources on documentation control, data integrity expectations, ALCOA+ principles, record review, SOP governance, and inspection readiness.

 
Previous
Previous

Choosing an eDMS

Next
Next

Document Lifecycle: Creation to Archival