Documents the quality management system requires are controlled, and a documented procedure sets the controls needed to: review and approve documents as adequate before they are issued; review them, bring them up to date where needed and approve them again; identify changes and the current revision status; make the relevant versions of applicable documents available where they are used; keep documents legible and easy to identify; identify the external documents the organization has decided it needs for planning and running the system, and control how they are distributed; prevent documents deteriorating or being lost; and prevent obsolete documents being used by mistake, identifying them suitably. Any change to a document gets its review and approval from the function that first approved it, or from another function designated for the purpose that has access to the relevant background information. The organization sets how long at least one copy of each obsolete controlled document is kept. That period must be at least as long as the device lifetime the organization has defined, must be no shorter than the retention of any record produced from the document, and must satisfy the regulatory requirements that apply.
This control maps to 3 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.