AW-03 — Policy, SOP and Controlled Document Management
| Workflow ID | AW-03 |
| Pack owner | IoL Administrative Affairs (decision of 2 September 2026; see Architecture/04_Ownership_Model.md) |
| Family | H — Governance and documented information |
| Ownership | IoL. MBRU's institutional policy framework governs which documents
IoL may issue; IoL owns the departmental repository and the lifecycle of
every document in it [IoL to confirm] |
| Governing policy | MBRU policy on policies, or equivalent document-control policy
[IoL to confirm]; ISO 9001:2015 clause 7.5; ISO 21001:2018
clause 7.5 |
| Interfaces | Every AW and WF; AW-04 records; AW-24 internal audit; AW-25 management review |
| OBEF touchpoint | None directly. This procedure controls the OBEF pack itself, so a failure here is a failure of every OBEF claim's provenance |
| Process owner | ______________ |
| Version | 0.1 draft |
| Effective | |
| Next review |
This is the procedure that makes every other procedure real. An uncontrolled SOP is an opinion. A controlled one has an owner, a version, an approval, a review date and a retrievable history. ISO auditors test this clause first because it is the cheapest way to find out whether a management system exists or merely a folder of documents.
1. Purpose
To ensure that every policy, procedure, work instruction, template and form used by IoL is identified, approved by the right authority, current, available where it is needed, protected from unintended change, and retired when obsolete, so that staff work from one authoritative version and an assessor can trace any practice to its documented basis.
2. Scope
Scope statement. This procedure manages IoL documented information from the proposal of a new or changed document through drafting, review, approval, publication and periodic review, to withdrawal and archiving.
Applies to. Departmental policies where IoL has
authority to issue them; all IoL procedures, work instructions,
templates, forms, checklists and controlled registers; both the academic
pack (IoL Pilot/) and this administrative pack; any
external document of origin (standards, regulator guidance, MBRU policy)
that IoL relies on and must hold at the current version.
Does not apply to. Institutional policy owned by MBRU or Dubai Health, which IoL adopts but does not control; records, which are the outputs of procedures and are governed by AW-04; working drafts that have not entered the control process; teaching materials, which are curriculum content governed by WF-02 and WF-03.
Applicable requirements. ISO 9001:2015 clause 7.5.2
(creating and updating: identification, format, review and approval) and
7.5.3 (control: availability, protection, distribution, access, storage,
change control, retention, disposition); ISO 21001:2018 clause 7.5; MBRU
document-control requirements [IoL to confirm].
3. Trigger, boundary and endpoint
| Trigger | A request to create, change, review or withdraw a controlled document; a scheduled review date; an audit finding, regulatory change or incident that requires a documented change |
| First activity | Logging the request in the document register with a unique ID |
| Last activity | Publication of the approved version and withdrawal of the superseded one, or archiving on withdrawal |
| Endpoint | The register shows the document's current version, approver, effective date and next review date, and only that version is retrievable from the published location |
| Upstream | Any procedure owner; AW-24 audit findings; AW-25 management review decisions; WF-26 methodological decisions requiring register change |
| Downstream | Every AW and WF that operates from a controlled document; AW-04 archiving of superseded versions |
4. SIPOC
| Element | Content |
|---|---|
| Suppliers | Process owners; Quality and IQA; MBRU policy office; regulators and standards bodies; audit and management review |
| Inputs | Change request with rationale; draft content; the current version; the approval matrix; the review calendar; external documents of origin |
| Process | Request → assign ID and owner → draft → review by affected roles → approve at the required level → publish and communicate → withdraw superseded → schedule review → periodic review → withdraw or archive |
| Outputs | Approved controlled document; register entry; communication of change; archived superseded version |
| Customers | IoL staff; learners where documents are learner-facing; assessors and auditors; MBRU quality function |
| Success criteria | One authoritative version per document; no document past its review date; every version traceable to an approver; superseded versions unavailable at the point of use but retrievable from archive |
5. Accountability
Process owner. IoL Quality Lead or equivalent
[IoL to confirm], with authority to refuse publication of a
document that has not passed approval.
| Step | Requester | Document Owner | Reviewer(s) | Approver (per matrix) | Document Controller | Quality Lead |
|---|---|---|---|---|---|---|
| Log request and assign ID | R | C | I | I | A/R | I |
| Assign or confirm owner | I | C | I | I | R | A |
| Draft or revise | C | A/R | I | I | I | I |
| Review by affected roles | I | R | R | I | C | A |
| Approve | I | C | I | A/R | I | C |
| Publish and withdraw superseded | I | I | I | I | A/R | I |
| Communicate change | I | A/R | I | I | R | I |
| Schedule and trigger periodic review | I | R | I | I | A/R | I |
| Withdraw and archive | I | C | I | A | R | I |
Approval matrix
[IoL to confirm against MBRU delegations]
| Document type | Approver |
|---|---|
| Departmental policy | Senior Director, IoL, after MBRU policy office confirmation that IoL holds the authority |
| Procedure (AW or WF) | Process owner's line manager, or IoL management committee where cross-functional |
| Work instruction, template, form, checklist | Document owner |
| Controlled register structure | Quality Lead |
| Adoption of an external document at a new version | Quality Lead, with impact assessment |
Escalation.
| Condition | Escalates to | Within |
|---|---|---|
| Document past review date by more than 30 days | Quality Lead → process owner's line manager | Immediately on the monthly register check |
| Approver unavailable and the change is urgent (safety, legal, regulator) | Senior Director, IoL, for interim approval with 30-day ratification | Same day |
| Two documents conflict | Quality Lead decides which is authoritative and opens a change on the other | 5 working days |
| Uncontrolled document found in use | Document Controller withdraws it and logs a non-conformity via AW-24 | Same day |
6. Procedure
Receive and log the request. Any staff member may request a new document or a change. The Document Controller logs it in the document register with a unique ID in the form
AW-NN,WF-NN,WI-NN,FRM-NNorREG-NN, a title, the requester and the reason. [CONTROL] No document exists in the system without a register entry.Assess the request. The Quality Lead confirms the document type, that IoL has authority to issue it (departmental policy requires MBRU confirmation), whether it duplicates or conflicts with an existing document, and which template applies. Decision point. Reject with reasons, redirect to an existing document, or proceed.
Assign the owner. One named role, not a person, accountable for content and for future reviews.
Draft. The owner drafts in the applicable template, in the working area of the repository, marked DRAFT with no version number. Drafts are never distributed for use.
Review. The owner circulates to every role named in the document's RACI and to any interfacing process owner. Reviewers respond within the service standard. Substantive objections are resolved or recorded as dissent in the register. [CONTROL] A document affecting another procedure is not approved without that procedure owner's review.
Impact assessment for changes. For a revised document, the owner records what changed, why, which records or systems are affected, whether training is needed, and whether historical records remain valid. For documents in the academic pack, the owner records the effect on any OBEF time series (a definition change breaks three-year and five-year comparability). [CONTROL] The change log in section 14 of the document is updated before approval, never after.
Approve. The approver per the matrix signs, dates and records the effective date. Approval is recorded in the register and in the document's control block. [CONTROL] Segregation: the drafter of a procedure does not approve it. [CONTROL] An approver does not approve a document they have not read; the approval record includes the version hash or page count reviewed.
Publish. The Document Controller assigns the version number (major for scope or control changes, minor for editorial), converts to the published format, places it in the published location, and removes the superseded version from that location in the same action. [CONTROL] No period exists in which two versions are both retrievable from the point of use.
Communicate. The owner notifies affected staff, states what changed and from when, and arranges training or briefing where the impact assessment requires it. Acknowledgement is recorded for documents with safety, legal or data-protection content.
Archive the superseded version. Handed to AW-04 with its full control history. Superseded versions are retrievable on request for as long as records made under them are retained.
Schedule the review. Default review interval: policies three years, procedures two years, work instructions and forms annually, or sooner on any trigger in section 3. The register holds the date and the Document Controller runs a monthly check.
Conduct the periodic review. The owner confirms the document is still needed, still accurate, still consistent with governing policy and interfacing procedures, and still used in practice. Outcome is one of: reconfirm unchanged (new review date), revise (return to step 4), or withdraw (step 13). [CONTROL] A reconfirmation without evidence that the document was checked against current practice is not a review.
Withdraw. On withdrawal, the register is updated, the document is removed from the point of use, affected staff are told, and the final version is archived via AW-04 with the withdrawal reason.
Control external documents of origin. Standards, regulator guidance and MBRU policies that IoL relies on are listed in the register with the version held and the date last checked. The Quality Lead checks for new versions at least annually and on any notification, and opens a change request where a new version affects an IoL document. [CONTROL] The OBEF guide is an external document of origin; version 11.5 is the one this pack is built on, and a new version triggers review of the academic pack.
7. Information handled and interfaces
| Flow | Content | Classification | To or from |
|---|---|---|---|
| In | Change requests, audit findings, regulatory changes | Internal | Any staff; AW-24; AW-25; regulators |
| In | Draft content | Internal, may contain process detail affecting security | Document owners |
| Out | Approved documents | Internal; learner-facing documents are public within MBRU | All AW and WF; learners via AW-18 |
| Out | Superseded versions with history | Internal, archival | AW-04 |
| Register | Document ID, title, type, owner, version, approver, effective date, review date, status, external documents held | Internal | Maintained here; read by AW-24, AW-25 |
Two packs sit under this procedure. The academic pack's 26 workflows and this pack's 25 are controlled documents from the moment this procedure is approved. Until then they are drafts, which is what their control blocks say.
8. Controls
Stated as assertions an auditor can test.
| # | Control | Evidence |
|---|---|---|
| C1 | Every document in use appears in the register with a current status | Register versus a sample of documents at the point of use |
| C2 | No published document is past its review date by more than 30 days | Monthly register check, escalation log |
| C3 | Every published version carries an approver, a date and a version number in its control block | Sample of documents |
| C4 | The drafter and the approver of a procedure are different people | Register |
| C5 | Only one version of any document is retrievable from the point of use | Repository check |
| C6 | Every superseded version is retrievable from archive with its control history | AW-04 archive sample |
| C7 | Every change carries an impact assessment and a change-log entry made before approval | Document section 14 versus register |
| C8 | External documents of origin are listed with version held and last check date | Register |
| C9 | Any uncontrolled document found in use generates a non-conformity | AW-24 log |
9. Exceptions and escalation
| Exception | Authorised by | Rationale required | Recorded where |
|---|---|---|---|
| Interim approval where the approver is unavailable and the change is urgent | Senior Director, IoL | The urgency and the risk of waiting; ratification within 30 days | Register |
| Temporary work instruction pending a full procedure | Quality Lead | Scope, expiry date not exceeding 90 days | Register, marked TEMPORARY |
| Deviation from a controlled document in a specific case | Process owner, with the document owner informed | The reason, the case, the date; not a precedent | Deviation log, reviewed at AW-25 |
| Adoption of an external document at a version MBRU has not yet adopted | Quality Lead with MBRU policy office | Why IoL needs the newer version | Register |
This procedure must never: allow a document into use without a register entry; allow the drafter to approve their own procedure; leave two versions retrievable at the point of use; record a review that did not check the document against practice; backdate an effective date; or alter a change log after approval.
10. Service standards
| Service | Standard |
|---|---|
| Request logged and assessed | 5 working days |
| Reviewer response | 10 working days |
| Approval decision after review complete | 10 working days |
| Publication after approval | 3 working days |
| Communication of change | Before the effective date |
| Monthly register check | By the 5th working day of each month |
| Periodic review completed | Within 30 days of the review date |
| Retrieval of a superseded version on request | 5 working days |
11. Records and retention
| Record | System | Retention | Owner |
|---|---|---|---|
| Document register | Controlled repository [IoL to confirm] |
Permanent | Document Controller |
| Change requests and impact assessments | Repository | Life of document plus 7 years | Document Controller |
| Review and approval records | Repository | Life of document plus 7 years | Document Controller |
| Published versions | Repository, published location | Until superseded, then archive | Document Controller |
| Superseded and withdrawn versions | Archive via AW-04 | As long as records made under them are retained | AW-04 |
| Communication and acknowledgement records | Repository | 7 years | Document owner |
| Deviation log | Repository | 7 years | Quality Lead |
12. Risks and controls
| # | Risk | Consequence | Control | Owner |
|---|---|---|---|---|
| 1 | Staff work from an old version held locally | Inconsistent practice, audit finding | Single published location; C5; periodic communication that local copies are uncontrolled | Document Controller |
| 2 | Documents drift past review dates | Management system decays silently | Monthly register check; C2; escalation | Quality Lead |
| 3 | Academic pack definition changed without impact on OBEF time series assessed | Incoherent three-year or five-year series, indefensible under review | Step 6 impact assessment names the OBEF effect | Document owner |
| 4 | Conflicting documents from IoL and MBRU | Staff choose, and choose differently | Institutional policy always prevails; register flags the conflict; change opened | Quality Lead |
| 5 | Repository access allows uncontrolled editing of published versions | Integrity failure | Write access to the published location limited to the Document Controller; AW-15 access review | AW-15 |
| 6 | New OBEF guide version issued and not noticed | Academic pack built on a superseded framework | External documents of origin register; annual check; MoHESR notifications routed here | Quality Lead |
| 7 | Volume of documents exceeds capacity to review | Backlog, then abandonment | Review intervals set by document type; merge rather than multiply | Quality Lead |
13. Performance measures
| Dimension | Measure | Target |
|---|---|---|
| Compliance | Documents in use with a register entry | 100% |
| Compliance | Documents past review date at the monthly check | 0 |
| Timeliness | Publication within 3 working days of approval | 95% |
| Timeliness | Periodic reviews completed within 30 days of due date | 90% |
| Accuracy | Control-block defects found on sample | 0 |
| Experience | Staff able to locate the current version of a named document at first attempt, on periodic test | 95% |
| Integrity | Uncontrolled documents found in use per audit cycle | 0, with trend reported |
14. Change control
| Date | Version | Change | Reason | Approved by |
|---|---|---|---|---|
| 2026-09-02 | 0.1 | Initial draft | IoL administrative pack | draft, unapproved |