Direct Answer
Document and records control is the set of decisions an organization makes about how its documented information will be created, approved, found, changed, retained and disposed of — and those decisions belong at the beginning of an implementation, not the end. Documents state what the organization intends to do. Records are the evidence it actually did. Deciding how both are governed before the first procedure is written is the cheapest structural decision available, because every process built afterwards inherits it.
Most management systems are not built. They accumulate — and document and records control is where the accumulation starts.
The document and records control decisions get made by default. Somebody writes a procedure. Somebody else writes one in a different template, because the first one was on a laptop that went home for the weekend. A third process gets documented in a spreadsheet because a spreadsheet was what was open. Two years later the organization has ninety documents, four naming conventions, three ideas about who approves what, and a shared drive nobody trusts. Nothing went wrong at any single point. The system simply grew without anyone deciding how it would be held together.
That is what document and records control is for, and it is why the decisions belong first. Not because a clause requires them — though every standard in this family does require them — but because they are the decisions every other process is going to inherit whether they were made deliberately or not. An organization that has not decided how documents are identified has still decided: it has decided that each author will choose. An organization that has not decided how long records are kept has decided that too, and the decision is being made by whoever runs out of storage first.
Every management system rests on a handful of decisions about documents and records. The only question is whether you made them, or inherited them.
This article is about making the document and records control decisions deliberately, and about the half of the subject that gets least attention. Documents get the procedures, the templates and the approval workflows. Records get an afterthought — and records are the only part of a management system that proves it exists. If you want to know whether an organization has implemented anything, you do not read its procedures. You look at what its work left behind.
If you are diagnosing a system that has already drifted — the shared drive, the competing versions, the file called FINAL_final — the companion piece on document control covers the symptoms and the requirements that address them. This one is about the decisions you make before there is anything to diagnose.
WHERE IMPLEMENTATIONS ACTUALLY BEGIN
Why does document and records control come first?
Decide. Do. Demonstrate.
Ask most organizations where their implementation started and they will name a standard, a consultant, a certification target, or a customer requirement. Ask what they did first and the answer is usually that they began writing procedures — quality policy, scope, then whichever process felt most urgent.
That sequence has a structural problem. Every procedure written before the document and records control decisions are made embeds a set of assumptions about how documents work, and those assumptions will not match each other. The first procedure assumes the author approves it. The fourth assumes a manager does. The seventh introduces a revision letter where the others used numbers. None of it is wrong at the time. All of it has to be reconciled later, and reconciling ninety documents costs several orders of magnitude more than deciding once.
There is a second reason, and it is the one that matters more commercially. The document and records control decisions determine what evidence the system will produce. A process whose record is created at the point of the work produces evidence automatically. A process whose record is written up afterwards produces a recollection, and recollections are what organizations end up defending. That difference is designed in at the start or retrofitted expensively later.
What exactly is being decided?
Fewer things than people expect. The document and records control decisions are answerable in an afternoon by people who already know the organization. The difficulty is not that the questions are hard. It is that they are invisible until someone names them.
- How is a controlled item identified? Numbering, titling, revision marking, effective dating, page counts.
- Who approves what, and when does it take effect? Two separate questions that most systems merge into one.
- Where does the work happen, and how does the current version get there? Including the places nobody counts — vehicles, contractors, temporary sites.
- How does something change? One route, or as many routes as there are people who want changes.
- What is a record here, and what is a document? The decision that drives approval, retention and access all at once.
- How long is anything kept, and on whose authority? Almost never the standard’s authority. Usually a law.
- Which external documents does the system depend on, and how would you learn one had changed?
Those seven questions are the whole of document and records control at the decision level. Everything else — the procedure, the register, the change notice, the software — is machinery for carrying out answers that have already been given. Organizations that buy the machinery first and answer the questions afterwards end up configuring a system around decisions they have not made.
THE PATTERN MSI SEES MOST OFTEN
An organization arrives with a document management system already purchased and partially configured, and asks for help making it comply. The software is rarely the problem. What has usually happened is that the configuration encoded a set of implicit answers — a default retention period, a default approval route, a default folder structure — and those defaults are now the organization’s policy by accident. Undoing that is harder than deciding first, because by then there is data in it.
This is also why document and records control sits so close to the leadership decisions in an implementation rather than in the administrative tail. MSI’s ISO 9001 implementation planning guide treats the sequencing question directly, and the same logic runs through the seven marks of an effective ISO procedure — a procedure cannot produce records as a byproduct of the work unless somebody decided, beforehand, what the record would be.
THE FIRST HALF OF THE DECISION
What do you decide about documents before writing anything?
Name. Approve. Deliver.
Direct Answer
Before writing a single procedure, decide four things about documents: how a controlled item is identified on its face, who approves it and separately when it takes effect, how the current version reaches the place the work happens, and what route a change travels. These four decisions are the document half of document and records control, and every procedure written afterwards inherits them.
How will a controlled item identify itself?
The first document and records control decision is identification. A person holding a document should be able to establish, without asking anyone, that it is the current version and that they have all of it. That means the identity travels on the document rather than in the system that stores it — because the moment a document is printed, emailed or opened offline, the system is no longer present to vouch for it.
Under document and records control the identity is a short list: a unique number, a title, the revision, the date it took effect, and the page count. The last of those is the one most often skipped and the cheapest to add. Page 1 of 1 tells the reader nothing is missing. Page 1 of 3 tells them something is.
An electronic system can tell you a document is current. It cannot tell the person holding a printout of it.
Who approves it, and when does it take effect?
These are two document and records control decisions and most systems merge them into one, which is where documents get lost. Approval is a judgment that the content is adequate. Release is the act that makes it the version directing work. An organization that has only defined approval will eventually find a revision that everybody signed and nobody issued — complete on every dashboard, absent from the wall where the work happens.
Deciding this early costs one sentence: the document becomes controlled at the moment a named role records its release, and directs work from the effective date on that release. Deciding it late costs an investigation into why people were working to a superseded revision that the system said had been approved four months earlier.
How does the current version reach the point of use?
This document and records control decision is usually made on the assumption that everyone works at a desk. The organizations that discover otherwise discover it through a list, and the list is always longer than expected: vehicles, temporary sites, home workers, contract staff, a supplier operating under your procedure, anyone working somewhere you do not control.
ISO 45001:2018 raises this further than the others by pairing availability with suitability — its Clause 7.4 requires language, culture, literacy and disability to be taken into account. A safe system of work issued in one language to a workforce that reads three is available and is not suitable. That is a design decision about how documents are produced, and it is far cheaper made before ninety of them exist.
What route does a change travel?
One route or many. That is the entire decision, and it is the last of the four document-side document and records control decisions. Organizations that choose many did not choose — they allowed separate forms for request, approval, training and distribution to accumulate. MSI client experience suggests those systems lose the thread between the four within about eighteen months, and the symptom is consistent: an approved revision that nobody was trained on.
The decision worth making at the start is that one instrument carries impact assessment, approval, awareness, training and distribution, and that it cannot be closed until the last two are confirmed. A change notice that can be closed without the training confirmation will be closed without it, every time, by someone under pressure who means well.
THE HALF THAT GETS LESS ATTENTION
Why can records not be managed the same way?
Capture. Protect. Keep.
Direct Answer
Records are governed differently from documents at every point. A document is authored, approved before use, revised through versions, and made available where work happens. A record is generated by the work, never approved in advance, never revised — only corrected in a way that leaves the original readable — and retained on a clock usually set by law rather than by the standard. Treating the two alike is the most common structural error in document and records control.
The word “documented information” in the harmonized standards covers both halves of document and records control, and the convenience of the single term hides how differently the two behave. It is worth setting them side by side, because the differences are not nuances — they run in opposite directions.
| Question | Documents | Records |
|---|---|---|
| Who creates it | An author, deliberately | The work itself, as a byproduct |
| Approved before use | Yes — that is the control | No — approval in advance is meaningless |
| Can it be revised | Yes, through controlled versions | No. Corrected only, with the original left readable |
| What “current” means | One version directs work; the rest are superseded | Every record stays true for the moment it captured |
| How long it is kept | Until superseded, plus a defined period | A period usually set by law, sometimes for decades |
| What it proves | What the organization intends to do | That the organization actually did it |
What decisions do records need that documents do not?
Three document and records control decisions apply to records alone, and none has a document equivalent.
- Where is the record created? At the point of the activity, by the person who performed it — or afterwards, from memory. This is a design decision about the form, not a discipline expectation about the person. A record that can only be completed at the end of a shift will be completed at the end of a shift.
- How is a correction made? Single line through, initialled, dated, original still readable. Never obliteration, never overwriting. Decide it once and train it once, because the alternative is discovering three different conventions during an investigation.
- What is the retention period and what is its basis? Not how long feels right. What legal requirement, contractual commitment or recorded decision sets it. A period with no basis behind it cannot be defended, cannot be reviewed, and cannot safely be changed.
That last one deserves emphasis, because it is where document and records control stops being a quality-system topic and becomes a legal exposure. Almost no retention period in a management system comes from the standard. ISO 9001:2015 requires you to determine retention and disposition; it does not tell you how long. The number comes from somewhere else — and if nobody went looking, it came from a default.
THE FAILURE THIS PRODUCES
Records destroyed on schedule, in good order, with an authorised disposal record proving the destruction was deliberate — years before the statutory period they were actually subject to had expired. The disposal record, which exists to demonstrate control, becomes the evidence that the destruction was systematic rather than accidental. This is not a hypothetical risk. It is what a single default retention period produces when the organization is subject to a clock it never looked up.
Records management has its own body of standards for exactly this reason. ISO 15489-1 sets out the principles and ISO 30301 defines a management system for records specifically — neither is required for ISO 9001 certification, and both are worth knowing exist when the retention question turns out to be larger than the quality manual can answer. For US public-sector context, the US National Archives records management guidance is the reference point.
THE DECISION MOST IMPLEMENTATIONS SKIP
Is this item a document or a record?
Ask. Decide. Route.
Direct Answer
Decide whether an item is a document or a record at the moment it is created, not when it is filed. The classification drives three separate controls — whether it needs approval before use, how long it is retained, and who may access it. Making the decision late in document and records control means all three have to be redone, and usually means one of them is already wrong.
Most items are obvious, and document and records control handles them without anyone thinking about it. A procedure is a document. A completed inspection sheet is a record. The interesting cases are the ones that are both, and every management system has more of them than anyone expects.
- A register — of external documents, of legal requirements, of training — is a document in its current version and a record in every superseded version.
- A blank form is a document. The same form completed is a record. They have different owners, different retention and different approval requirements, and they are usually stored together.
- A plan — audit plan, project plan, maintenance schedule — is a document while it directs work and a record of what was planned once the period closes.
- A report is almost always a record, but a report template that dictates content is a document.
- An approved supplier list is the current version people work to and the historical evidence of who was approved when a given batch was purchased.
ISO 45001:2018 makes this unusually visible: six of its clauses require documented information to be both maintained and retained, which is the standard’s way of saying the current version is a document and every superseded version is a record. The register of legal requirements is the one that matters most. After an incident, the only version relevant to the question of what applied at the time is the superseded one — and an organization that treated the register purely as a document has been overwriting its own evidence.
If your system cannot produce the version of the legal register that was current eighteen months ago, it has been treating a record as a document.
The document and records control test worth writing down is short. Does the item tell people what to do in future, or does it capture what happened at a point in time? If it does both, it is both, and it needs the controls of both — approval and version control on the live copy, retention and integrity on the superseded ones.
WHAT IMPLEMENTATION ACTUALLY LOOKS LIKE
Why do good records prove a management system has been implemented?
Evidence. Not. Intent.
Direct Answer
Records are the only part of a management system that demonstrates implementation, which is why document and records control treats them as a design problem. Documents describe what an organization intends to do and can be written by anyone in an afternoon. Records can only be produced by the work actually happening. This is why document and records control decisions determine whether a system can show it operates — an organization with excellent procedures and thin records has built something that cannot demonstrate it exists.
You can read an organization’s entire documented system and learn almost nothing about whether it operates. The procedures may be excellent. They may have been bought, adapted from a template, or written by a consultant who left in March. Documents are statements of intent, and intent is cheap.
Records are different in kind, and this is why document and records control treats them separately. A completed calibration record exists because somebody calibrated something. A change notice with a training confirmation on it exists because somebody trained somebody. A management review minute exists because the review happened. None of these can be produced by good intentions, and none of them can be produced retrospectively without the organization knowing it is doing something it should not.
This is the argument for treating records as a design problem rather than an administrative one. The question at the start of an implementation is not “what records does the standard require” — that list is short and easy to satisfy badly. The question is “what will this process leave behind that proves it ran,” and then designing the process so that it leaves it behind automatically. That is the fourth of the seven marks: records produced as a byproduct of the work rather than reported about it afterwards.
WHAT THIN RECORDS ACTUALLY SIGNAL
An organization with a full procedure set and sparse records is usually not a careless organization. It is an organization whose processes were documented after the fact rather than designed — so the records were never part of the work, and completing them is an extra task competing with the real one. The fix is not to insist harder. It is to move record creation into the work, which is a design decision, and one that belongs at the start.
There is a document and records control diagnostic in this, and it is worth applying to any process in your system. Ask what that process would leave behind if everybody stopped talking about it. If the answer is “nothing,” the process is not implemented regardless of how well it is written. If the answer is “a form somebody fills in at the end of the week,” it is partially implemented and the record is a recollection. If the answer is “the thing the work itself produces,” it is implemented, and the evidence takes care of itself.
Continual improvement runs on the same fuel. MSI’s piece on continual improvement makes the point that improvement requires knowing what actually happened, and knowing what actually happened requires records that were true when they were made. A system whose records are reconstructed cannot improve, because it has nothing reliable to improve from.
Where does your document and records control actually sit?
Eight elements, four levels, about six minutes. The Document and Records Control Maturity Check scores your process as it behaves on a busy week — not as your procedure describes it. You get your score, your band and the element most organizations score lowest on straight away, with no email required. It covers ISO 9001, ISO 14001, ISO 13485, ISO 45001 and ISO 7101, whether or not you are certified.
Enter your details afterwards and you also get the element-by-element breakdown and the full Maturity Framework, with a blank scoring worksheet to take into your next management review.
WHAT CHANGES BY STANDARD
What does document and records control require across the five standards?
One. Clause. Five. Answers.
Direct Answer
The core requirements of document and records control are almost identical across ISO 9001, ISO 14001, ISO 13485, ISO 45001 and ISO 7101 — identification, approval, availability, change control, protection, retention and external documents. What differs is where the obligations come from. Three of the five carry requirements that have no equivalent elsewhere, and in two of those the obligation comes from regulation rather than from the standard.
The harmonized standards — ISO 9001, ISO 14001, ISO 45001 and ISO 7101 — all place document and records control at Clause 7.5 and say substantially the same things. The exception is ISO 13485. Documented information at Clause 7.5 and say substantially the same things. ISO 13485 does not: it predates the harmonized ten-clause structure and puts documents at 4.2.4 and records at 4.2.5, as two separate clauses with separate requirements. An organization adapting a quality procedure for device use by renumbering it has already missed the point.
| Standard | Where it lives | What is distinctive |
|---|---|---|
| ISO 9001:2015 | 7.5.2, 7.5.3 | The baseline. More retained documented information than any other standard here, spread across the whole of Clause 8 rather than concentrated in one place. |
| ISO 14001:2026 | 7.5.2, 7.5.3 | Substantively the same as ISO 9001. The 2026 edition adds a dedicated Clause 6.3 for planning of changes, which did not exist in 2015. |
| ISO 13485:2016 | 4.2.4, 4.2.5 | Two clauses, not one. Two separate retention clocks. Record content specified by regulation rather than by the standard. Since February 2026 the records are inspectable. |
| ISO 45001:2018 | 7.5.2, 7.5.3 | States no retention period for any record it requires. Every period comes from law, and the periods run to decades. Adds suitability of documents alongside availability. |
| ISO 7101:2023 | 7.5.2 to 7.5.6 | Six subclauses where the others have three. Requires records to be audited, and requires the information management system itself to be validated. |
Where the obligation is not in the standard at all
Two of the five carry their heaviest document and records control requirements from outside the standard, which is exactly why they get missed — no clause checklist points at them.
For medical devices, the QMSR final rule brought ISO 13485:2016 into 21 CFR Part 820 by reference with effect from 2 February 2026. Document and record controls for US-marketed devices are now the operative form of a federal requirement rather than only a certification matter, and the records they govern are inspectable. The regulation also specifies the content of certain records — complaints, servicing, unique device identification, labelling release — where the standard does not. FDA guidance sets out the transition. Build the required data elements into named fields on the form; a reminder to include them is not a control.
For occupational health and safety, the retention periods come from 29 CFR Part 1904 and 29 CFR 1910.1020 rather than from ISO 45001. The second of those requires employee exposure and medical records to be kept for durations measured in decades, because occupational disease takes decades to appear. Part 1904 goes further and requires one record type to be corrected after the fact — stored injury and illness records are updated when a case outcome changes, sometimes years later. An organization that has trained its people to never alter a record has trained them into a recordkeeping violation.
A single default retention period is either non-compliant for the long clocks or absurd for everything else. Usually both at once.
If you run more than one of these standards, the document and records control decisions are still made once. That is the practical argument for an integrated approach and the reason MSI’s work on the ISO 9001 and 14001 transition treats documented information as a single design problem rather than two parallel ones. Accreditation and certification context has shifted as well — IAF and ILAC merged into the Global Accreditation Cooperation with effect from January 2026 — and ASQ and ANAB remain useful orientation points for organizations mapping who does what in the certification landscape.
TURNING DECISIONS INTO A PROCEDURE
What must a document and records control procedure contain?
Trigger. Owner. Record.
Direct Answer
A working document and records control procedure contains a real trigger covering every way a document can be initiated, one accountable owner with named alternates, stated decision criteria rather than intentions, records produced as a byproduct of the work, a defined exception path for the urgent case, and an event-based review trigger. A procedure that restates the clause without answering these has documented the requirement without controlling anything.
Once the document and records control decisions are made, the procedure is largely transcription. The trap is writing a procedure that restates the standard — “documented information shall be reviewed and approved for suitability and adequacy” — which is an assertion, not a mechanism. ISO 10013:2021 is the guidance standard for documented information specifically and is worth reading precisely because so few organizations cite it.
- A trigger that fires however the need arises. Including the request made verbally to a supervisor, which is the route that never enters the system.
- One accountable owner, with named alternates for every gating role. Roles persist; people change jobs and take holidays.
- Criteria, not judgment. Which tier a document falls into, who approves that tier, and how long before it is reviewed again — stated, so nobody has to decide under pressure.
- An emergency route that is written down and bounded. A named authoriser, a stated reason, an expiry date, and a log. An unwritten emergency route still exists; it is simply unbounded.
- A records section with no blanks. Every record with a named location, an owning role, a retention period and the basis for that period.
- Event-based review triggers. A calendar review is the weakest option available. The procedure should be re-examined when the system changes, not when the year turns.
That structure is not specific to document control — it is what separates procedures that survive contact with a busy week from procedures that are quietly worked around. The full test is set out here, and it applies equally to purchasing, corrective action and internal audit planning.
A complete procedure, written as a worked example
The Document and Records Control Procedure Template and Guide is a full, editable procedure — not an outline with blanks. It arrives as a Word file with the decisions already made and explained, bracketed placeholders wherever a value is genuinely yours to set, a change notice, a register, a desk-level work instruction with a worked example, and the same eight-element maturity ladder the Maturity Check scores you against. Choose your standard: ISO 9001, ISO 14001:2026, ISO 13485, ISO 45001 or ISO 7101.
Editable Word format. Adapt it, rebrand it, adopt it into your own document control system.
IF YOU ARE STARTING NOW
How do you make these decisions in the right order?
Decide. Do. Demonstrate.
The order matters less than making all the document and records control decisions, but there is a sequence that reduces rework. Identification first, because everything else refers to it. Then the document-or-record test, because it routes each item to the right set of controls. Then approval and release, then availability, then change. Retention last, because it requires someone to go and look up the legal clocks, and that is the one task in this list that cannot be done from a desk in an afternoon.
| Order | Decision | Who needs to be in the room |
|---|---|---|
| 1 | How a controlled item identifies itself on its face | Whoever will maintain the register, plus one person who works at the sharp end |
| 2 | The document-or-record test, written down | Process owners — they know the awkward cases |
| 3 | Approval tiers and the release point | Whoever holds the authority being delegated |
| 4 | Points of use, including the ones nobody counts | Supervisors, and anyone managing contractors or remote work |
| 5 | The change route and the bounded emergency route | Process owners plus whoever will be blamed when it is urgent |
| 6 | Retention periods and the basis for each | Someone who will go and read the regulation, not recall it |
| 7 | External documents, owners, and detection arrangements | Whoever currently assumes somebody else is watching |
That last row is the one almost every organization gets wrong in document and records control, and it is worth naming plainly. Most systems hold a list of external documents — standards, regulations, customer specifications, safety data sheets. Very few can answer the next question: how would you find out that one of them had changed? A list with no detection arrangement behind it produces an internal procedure that carries the organization’s authority while pointing at a requirement that was superseded eighteen months ago. Internal audit does not catch it, because the register exists and the entries have owners.
For organizations that would rather work through this with someone who has done it before, that is what ISO consulting is for — and MSI’s SurePath program covers the full path for organizations building a system from the ground up, with SureResults for keeping it running afterwards. For those already certified and wanting an independent read on how the system actually behaves, The Portrait is the operational assessment.
COMMON QUESTIONS
Document and records control: frequently asked questions
Ask. Answer. Act.
Is document and records control the same as documented information?
Broadly yes. “Documented information” is the term the harmonized standards use to cover both documents and records in a single phrase, introduced so the standards would not have to keep saying “documents and records.” Document and records control is the process that governs it. The single term is convenient and slightly misleading, because the two behave very differently — documents are authored and approved before use, records are generated by the work and never approved in advance.
Do we need a documented procedure for document and records control?
Under ISO 9001, ISO 14001 and ISO 45001, no — the standard requires document and records control, not a procedure describing it. Under ISO 13485 a documented procedure is explicitly required for both document control and record control. In practice most organizations write one regardless, because the decisions have to be recorded somewhere and a procedure is the natural place. The question worth asking is not whether you need one but whether the one you have states mechanisms or restates the clause.
How long do we have to keep records?
The standard almost never tells you. ISO 9001 requires you to determine retention and disposition without specifying periods. ISO 13485 sets two separate clocks tied to the lifetime of the device as you define it. ISO 45001 states no period at all, and the operative periods come from occupational health and safety regulation — some running to decades. Every period in your schedule should carry the basis it derives from, because a period with no basis cannot be defended or safely changed.
Can an electronic system handle document and records control for us?
Software can carry out the document and records control decisions. It cannot make them. A document management system configured before the organization has decided its identification convention, approval tiers and retention basis will encode a set of defaults, and those defaults become policy by accident. Configure after deciding, not before. Also verify one thing specifically: whether the audit trail can be disabled by the person making the entry. If it can, records are not protected against loss of integrity whatever else the system does well.
What is the difference between maintaining and retaining documented information?
Maintained means kept current — it is a document, and there is one live version. Retained means kept as evidence — it is a record, and it is never revised. Some items require both, which means the current version is controlled as a document and every superseded version is kept as a record. Registers of legal requirements are the clearest example, and ISO 45001 requires it in six separate clauses.
Our records are thin but our procedures are good. Is that a problem?
It is the most useful diagnostic signal in document and records control. Documents state intent and can be written by anyone; records can only be produced by the work actually happening. Thin records usually mean the processes were documented after the fact rather than designed, so completing the record is an extra task competing with the real one. The fix is to move record creation into the work rather than to insist harder that people complete forms.
We are not certified. Does any of this apply to us?
All of it. Nothing in document and records control depends on holding a certificate. An organization running a management system because a customer requires it, because a supply chain demands it, or because it is a sensible way to work faces exactly the same decisions and gets exactly the same benefit from making them deliberately. Certification changes who examines the evidence, not whether the evidence is worth having.
Where should an organization start?
With identification and the document-or-record test, in that order. Those two document and records control decisions cost an afternoon and everything else refers to them. Retention comes last because it requires someone to look up the legal clocks that apply to your industry and jurisdiction, which is the one task in this sequence that cannot be done from memory.
WHERE THIS LEAVES YOU
Decide. Do. Demonstrate.
The three that carry everything else.
Document and records control is not the interesting part of a management system, and it is the part that determines what everything else costs. Decide how documents are identified, approved, released, delivered and changed. Decide what is a record and what is a document, before the question is academic. Decide retention on a basis you can point at. Then design the processes so that the evidence appears without anyone being asked for it.
Get the document and records control decisions right at the start and the system produces its own proof. Get them wrong and you spend three years reconciling ninety documents that never agreed with each other, and defending records that were written from memory.
Not sure which of the eight elements is costing you most?
Call MSI and talk it through. Across 28 years and 200+ audits attended, the patterns repeat — and the element that turns out to be expensive is rarely the one an organization expects. A planning session works out where your system actually stands and what to do first.
Prefer to start on your own? Score your process free, or watch the ISO Executive Decision Briefs — short leadership-level videos on what a management system is supposed to produce.
References and further reading
About Management Systems International (MSI)
Diana Lynn is President and Principal ISO Consultant at Management Systems International (MSI), a consulting firm she co-founded in 1998. With 28 years of experience including extensive AS9100 work in MSI’s early years, MSI’s track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.
MSI is veteran-owned and female-owned. · msi-international.com · 760-434-9141