Documented Information Architecture Design Guide — Ensuring Files, Records, and Knowledge Are in Their Right Places
Abstract: The number of system documents is increasing, but employees are finding it harder to determine "which version to use." Records are scattered everywhere, and materials are hastily prepared during audits. The root cause is often not "insufficient documentation," but the lack of a clear documented information architecture—how to layer, number, control, distribute, and obsolete documents, records, external documents, and knowledge assets. This article systematically explains the four-layer structure of documented information, numbering and versioning rules, and key points for controlled distribution and external document management.
1. A Common Dilemma: Many Files, Chaotic System
A quality department of a manufacturing company maintains over 800 system documents, with folders named by year and department, and version numbers written in various formats such as "V1.0," "Rev.B," and "2024 Edition." Production line employees report: "I operated according to the old SOP given by the team leader, but the auditor had the new version—so who is right?"
Reviewing the situation reveals three issues:
- Documents and records are mixed together—original inspection data is archived as "work instructions."
- No unified numbering rules—documents with the same name exist in different directories.
- External documents (customer CSR, regulations, supplier specifications) are not included in the controlled list, and it is unclear whether they are the latest versions when used.
This is not an issue of execution, but a lack of documented information architecture—the organization has not defined "which information should be in what form, where it should be stored, and how it should be controlled."
2. Documented Information Architecture: Four Levels
ISO 9001's "documented information" includes documents and records. In practice, it is recommended to further divide it into four levels:
| Level | Type | Typical Content | Control Focus |
|---|---|---|---|
| L1 | Manual/Policy Level | Quality Manual, Management Policy | Few and stable, approved by senior management |
| L2 | Procedure/Process Level | Procedure Documents, Process Descriptions | Cross-departmental interfaces, responsibilities |
| L3 | Work/Instruction Level | SOPs, Inspection Specifications, Drawings | On-site execution, version control |
| L4 | Record/Evidence Level | Inspection Records, Training Sign-in Sheets, Audit Reports | Objectively true, traceable, retention period |
Architecture Design Principles:
- Upper levels are stable, lower levels are flexible—L1/L2 have low change frequencies, while L3/L4 adjust according to processes and customer requirements.
- One document, one purpose—do not combine procedures, SOPs, and record templates into a single Word document.
- Reference instead of copy—write general requirements in the upper levels and reference them in the lower levels rather than duplicating and pasting.
3. Numbering Rules: Giving Each Document an "ID"
Unified numbering is the backbone of the documented information architecture. The recommended structure is:
[System Code]-[Type Code]-[Sequence Number]-[Version Number]
Examples:
| Number | Meaning |
|---|---|
| QMS-P-001 | Quality Management Procedure No. 001 |
| QMS-WI-012 Rev.3 | Work Instruction No. 012, Version 3 |
| QMS-F-205 | Form/Record Template No. 205 |
| QMS-EXT-008 | External Document No. 008 |
Type Code Suggestions (can be tailored to the company):
- M — Manual
- P — Procedure
- WI — Work Instruction
- F — Form
- EXT — External
- SPEC — Specification (Product/Inspection)
Version Number Rules:
- Procedures/SOPs: Major version number change = substantial content change; minor version = format/typographical errors.
- Records: No version control; use "record number + date + batch" for traceability; only record templates are version-controlled.
4. Version Control and Controlled Distribution
1. Version Lifecycle
Drafting → Review → Approval → Release → Training/Notification → Effective → Regular Review → Revision or Obsolescence
Each step should be recorded: who reviewed, who approved, when it became effective, and when the old version was obsoleted.
2. Controlled Distribution List
Core Requirement: Only the latest valid version can be used at controlled points.
It is recommended to maintain a Controlled Document Distribution List with the following fields:
- Document number, name, version
- Distribution target (department/position/production line station)
- Distribution form (paper/electronic/system)
- Confirmation of old version retrieval (especially important for paper documents)
Electronic Systems (QMS/PLM/SharePoint) should implement:
- Unauthorized users cannot edit released documents.
- Automatic watermark or header displaying version and effective date.
- Obsolete documents are read-only archived and cannot be used as current references.
3. Management of "Uncontrolled Copies"
Printed paper documents and exported PDFs should be labeled "Uncontrolled Copy, for Reference Only" or have print permissions restricted. One of the most common non-conformities during audits is the use of unmarked copies on-site.
5. Record Control: Managed Separately from Documents
Records are "evidence of what has happened," and their management logic differs from documents:
| Dimension | Document | Record |
|---|---|---|
| Purpose | Specifies how to do it | Proves it was done |
| Change | Has versions, requires approval | Generally no alterations allowed |
| Retention | Long-term validity | Defined retention period |
| Filling | Not applicable | Clear, traceable, searchable |
Key Points for Record Control:
- Record templates (blank forms) should be included in document control.
- Filled records should be classified and stored according to the Record Retention Policy (paper/electronic).
- Crossing out is allowed, but must be signed and dated, with the original content remaining readable.
- Electronic records must meet audit trail requirements (who, when, what was changed)—see 12.1.2.
6. Management of External Documents
External documents are the most easily overlooked part of the documented information architecture, including:
- Laws, regulations, national standards, industry standards
- Customer drawings, CSR, inspection specifications
- Supplier specification sheets, material safety data sheets (MSDS)
- Certification body requirements, audit criteria
Management Steps:
- Identification — Departments report applicable external documents in their respective fields.
- Registration — Include in the External Document List and assign an EXT number.
- Review — Assess the impact on the company's products/processes.
- Conversion — Convert to internal documents (procedures/SOPs) when necessary, rather than directly referencing untranslated customer PDFs.
- Update Monitoring — Subscribe to standard updates and customer engineering change notifications to trigger reviews.
Common Misunderstandings: Directly placing customer email attachments into the shared drive without version and applicability confirmation.
7. The Relationship Between Documented Information and Knowledge Base
Documented Information (controlled) ≠ Knowledge Base (for reference):
- Documented Information: "Regulations" that must be followed—non-compliance is a non-conformity.
- Knowledge Base/Best Practices: Best practices, case studies, training materials—referenced but do not replace controlled documents.
Architecturally, it is suggested:
- Controlled documents are stored in the QMS/document control system.
- The knowledge base is stored in the Wiki/think tank/SharePoint non-controlled area.
- Mature practices extracted from the knowledge base should only enter the controlled process when elevated to SOPs.
8. Implementation Checklist
| Check Item | Qualification Standard |
|---|---|
| Document Layering | Clear responsibilities for manuals/procedures/SOPs/record templates |
| Unique Numbering | No duplicate numbers, unified type codes |
| Current Version | No expired versions on-site |
| Traceable Distribution | Can check who holds which version |
| Record Retention | Defined retention periods, easy to search |
| External Documents | Have a list, reviewed, and updated mechanisms |
| Obsolescence Management | Old versions cannot be used as execution references |
9. Conclusion
A documented information architecture is not about "writing more documents," but about establishing a functional directory system for the organization's knowledge—documents specify how to do it, records prove it was done, external documents ensure compliance with inputs, and the knowledge base supports continuous improvement.
Designing the architecture first provides a foundation for internal audits, preparation for audits, and digital document control. Otherwise, documents will only pile up, and "finding the right document" itself will become a quality cost.
Knowledge Number: 2.3.1
Knowledge code: 2.3.1
Version: v20260521
Author: QTank