8 August 2026
Controlled Documents vs Working Copies
Controlled documents vs working copies: what each means in document control, why unofficial copies create risk, and how labs stay aligned.
Enterprise Knowledge · Education
Controlled documents vs working copies is a core document-control distinction: a controlled document is the approved, effective version managed under your quality system (unique identity, revision, approval, distribution, and obsolescence rules), while a working copy is any additional copy—printout, local file, email attachment, or marked-up draft—used for convenience or editing. Working copies are not automatically wrong; they become a problem when people treat them as authoritative after the controlled version has moved on.
FDA’s pharmaceutical quality resources (see the agency’s pharmaceutical quality resources hub) sit in a broader expectation that firms follow current approved procedures. Unofficial copies are one of the fastest ways current procedures stop matching actual work.
What makes a document “controlled”?
A controlled document typically has:
- A unique document ID and title
- A revision or version identifier
- Defined authors, reviewers, and approvers
- An effective date (and sometimes a review-by date)
- A home in the official repository (eQMS, validated DMS, or equivalent)
- Rules for who may print, download, or distribute copies
- A path to obsolete prior revisions and retrieve them from use
Policies, SOPs, work instructions, specifications, and many forms fall under this umbrella. The point of control is not bureaucracy for its own sake—it is so everyone can answer: Which version was effective when this batch was made?
What counts as a working copy?
Working copies include:
- Desk printouts of an SOP
- “My Downloads” PDFs saved last quarter
- Draft Word files in personal folders during revision
- Annotated slides used in training dry-runs
- Email forwards of procedures to contractors
- Screenshots pasted into chat tools
Some of these are necessary for work. Document-control SOPs should say how long printed copies may be used, whether they must be stamped “controlled copy” with a retrieval date, and how users verify they still match the effective revision before use.
Hybrid labs often keep laminated WI cards at benches. Those cards are working copies unless your system treats each as a controlled distributed copy with update-and-retrieve discipline.
Why do unofficial copies create quality risk?
The failure mode is simple: the controlled SOP is revised after a regulatory or process change; the bench still uses last year’s printout. Training records may show completion on the new revision while practice follows the old sheet. Deviations then look like “human error” when the system allowed obsolete instructions to remain in view.
Related risks:
- Marked-up working copies that silently become the real procedure
- Contractors working from emailed PDFs with no revision check
- Multiple “final” files in SharePoint with no effective flag
SharePoint-style search without document control semantics makes this worse; see why SharePoint search fails regulated labs. Integrity expectations such as ALCOA+ also suffer when the “original” or accurate procedure source is ambiguous—see what is ALCOA+ data integrity.
How should change control treat working copies?
When a controlled document is revised:
- Approve and effective-date the new revision in the official system.
- Quarantine or clearly mark the prior revision as obsolete.
- Retrieve or destroy distributed controlled copies per procedure.
- Remind users that personal working copies are invalid after the effective date.
- Assign training on the new revision before or by effectiveness, as required.
Impact assessments should ask where working copies live: binders, equipment drawers, contractor portals, and local shared drives. If you cannot list distribution points, you cannot complete retrieval.
Regulatory-driven revisions follow the same retrieval logic; process context is in regulatory change control in a QMS.
How do drafts differ from working copies of effective documents?
Drafts are pre-approval. They should be clearly labeled as draft, stored in a revision workspace, and barred from use in GxP production activities. A working copy of an effective document is a copy of something already approved—often the riskier case because it looks official.
Good practice:
- Draft watermark on all pre-approval exports
- Separate draft library or status in the eQMS
- No draft use in batch release, validated methods, or official training completion (training on drafts only when your SOP explicitly allows pre-effective familiarization)
What should mid-market teams put in the document-control SOP?
Keep instructions concrete:
- Definition of controlled document vs working copy vs draft
- Where the official effective set lives
- Print/download rules and any “day stamp” requirements
- Retrieval steps at revision
- Prohibition on uncontrolled editing of PDFs as the master
- How contractors receive current copies
- Periodic walk-throughs to find unofficial binders
Pair the SOP with a short floor check: once a quarter, spot-check two labs for printouts and compare revision numbers to the eQMS. Small samples catch drift early.
When staff look up procedures digitally, require that links open the controlled effective version—and that any AI or search answer cites document ID and revision (citations and provenance in enterprise knowledge agents).
FAQ
Are printed SOPs always non-controlled?
No. Printed copies can be controlled distributed copies if your procedure issues them, tracks them, and retrieves them on revision. Untracked printouts are the problem.
Can we keep a “working copy” Word file as the master?
The editable master should still sit under document control with check-in/out or equivalent. A personal Word file on a laptop is not an acceptable sole master for GxP procedures.
What is the fastest way to reduce working-copy risk?
Shorten print retention, require revision checks before use, eliminate duplicate SharePoint “final” folders, and run retrieval as a mandatory step in every document change record—not an optional reminder.