IoL Workflows
Administrative   Family H · Governance and documented information  ·  IoL Administrative Affairs

AW-03 · Policy, SOP and Controlled Document Management

Primary KPIsnone
Contributes to
TriggerA request to create, change, review or withdraw a controlled document; a scheduled review date; an audit finding, regulatory change or incident that requires a documented change
EndpointThe register shows the document's current version, approver, effective date and next review date, and only that version is retrievable from the published location
OBEF touchpointNone directly. This procedure controls the OBEF pack itself, so a failure here is a failure of every OBEF claim's provenance

BPMN 2.0 (ISO/IEC 19510), generated from the procedure section of this document. Lanes are the roles in the RACI; a cylinder marks a capture point and the KPI it feeds; a diamond is a decision point. Click a task to jump to its step. Scroll to zoom, drag to pan.

AW-03 — Policy, SOP and Controlled Document Management

Workflow ID AW-03
Pack owner IoL Administrative Affairs (decision of 2 September 2026; see Architecture/04_Ownership_Model.md)
Family H — Governance and documented information
Ownership IoL. MBRU's institutional policy framework governs which documents IoL may issue; IoL owns the departmental repository and the lifecycle of every document in it [IoL to confirm]
Governing policy MBRU policy on policies, or equivalent document-control policy [IoL to confirm]; ISO 9001:2015 clause 7.5; ISO 21001:2018 clause 7.5
Interfaces Every AW and WF; AW-04 records; AW-24 internal audit; AW-25 management review
OBEF touchpoint None directly. This procedure controls the OBEF pack itself, so a failure here is a failure of every OBEF claim's provenance
Process owner ______________
Version 0.1 draft
Effective
Next review

This is the procedure that makes every other procedure real. An uncontrolled SOP is an opinion. A controlled one has an owner, a version, an approval, a review date and a retrievable history. ISO auditors test this clause first because it is the cheapest way to find out whether a management system exists or merely a folder of documents.


1. Purpose

To ensure that every policy, procedure, work instruction, template and form used by IoL is identified, approved by the right authority, current, available where it is needed, protected from unintended change, and retired when obsolete, so that staff work from one authoritative version and an assessor can trace any practice to its documented basis.

2. Scope

Scope statement. This procedure manages IoL documented information from the proposal of a new or changed document through drafting, review, approval, publication and periodic review, to withdrawal and archiving.

Applies to. Departmental policies where IoL has authority to issue them; all IoL procedures, work instructions, templates, forms, checklists and controlled registers; both the academic pack (IoL Pilot/) and this administrative pack; any external document of origin (standards, regulator guidance, MBRU policy) that IoL relies on and must hold at the current version.

Does not apply to. Institutional policy owned by MBRU or Dubai Health, which IoL adopts but does not control; records, which are the outputs of procedures and are governed by AW-04; working drafts that have not entered the control process; teaching materials, which are curriculum content governed by WF-02 and WF-03.

Applicable requirements. ISO 9001:2015 clause 7.5.2 (creating and updating: identification, format, review and approval) and 7.5.3 (control: availability, protection, distribution, access, storage, change control, retention, disposition); ISO 21001:2018 clause 7.5; MBRU document-control requirements [IoL to confirm].

3. Trigger, boundary and endpoint

Trigger A request to create, change, review or withdraw a controlled document; a scheduled review date; an audit finding, regulatory change or incident that requires a documented change
First activity Logging the request in the document register with a unique ID
Last activity Publication of the approved version and withdrawal of the superseded one, or archiving on withdrawal
Endpoint The register shows the document's current version, approver, effective date and next review date, and only that version is retrievable from the published location
Upstream Any procedure owner; AW-24 audit findings; AW-25 management review decisions; WF-26 methodological decisions requiring register change
Downstream Every AW and WF that operates from a controlled document; AW-04 archiving of superseded versions

4. SIPOC

Element Content
Suppliers Process owners; Quality and IQA; MBRU policy office; regulators and standards bodies; audit and management review
Inputs Change request with rationale; draft content; the current version; the approval matrix; the review calendar; external documents of origin
Process Request → assign ID and owner → draft → review by affected roles → approve at the required level → publish and communicate → withdraw superseded → schedule review → periodic review → withdraw or archive
Outputs Approved controlled document; register entry; communication of change; archived superseded version
Customers IoL staff; learners where documents are learner-facing; assessors and auditors; MBRU quality function
Success criteria One authoritative version per document; no document past its review date; every version traceable to an approver; superseded versions unavailable at the point of use but retrievable from archive

5. Accountability

Process owner. IoL Quality Lead or equivalent [IoL to confirm], with authority to refuse publication of a document that has not passed approval.

Step Requester Document Owner Reviewer(s) Approver (per matrix) Document Controller Quality Lead
Log request and assign ID R C I I A/R I
Assign or confirm owner I C I I R A
Draft or revise C A/R I I I I
Review by affected roles I R R I C A
Approve I C I A/R I C
Publish and withdraw superseded I I I I A/R I
Communicate change I A/R I I R I
Schedule and trigger periodic review I R I I A/R I
Withdraw and archive I C I A R I

Approval matrix [IoL to confirm against MBRU delegations]

Document type Approver
Departmental policy Senior Director, IoL, after MBRU policy office confirmation that IoL holds the authority
Procedure (AW or WF) Process owner's line manager, or IoL management committee where cross-functional
Work instruction, template, form, checklist Document owner
Controlled register structure Quality Lead
Adoption of an external document at a new version Quality Lead, with impact assessment

Escalation.

Condition Escalates to Within
Document past review date by more than 30 days Quality Lead → process owner's line manager Immediately on the monthly register check
Approver unavailable and the change is urgent (safety, legal, regulator) Senior Director, IoL, for interim approval with 30-day ratification Same day
Two documents conflict Quality Lead decides which is authoritative and opens a change on the other 5 working days
Uncontrolled document found in use Document Controller withdraws it and logs a non-conformity via AW-24 Same day

6. Procedure

  1. Receive and log the request. Any staff member may request a new document or a change. The Document Controller logs it in the document register with a unique ID in the form AW-NN, WF-NN, WI-NN, FRM-NN or REG-NN, a title, the requester and the reason. [CONTROL] No document exists in the system without a register entry.

  2. Assess the request. The Quality Lead confirms the document type, that IoL has authority to issue it (departmental policy requires MBRU confirmation), whether it duplicates or conflicts with an existing document, and which template applies. Decision point. Reject with reasons, redirect to an existing document, or proceed.

  3. Assign the owner. One named role, not a person, accountable for content and for future reviews.

  4. Draft. The owner drafts in the applicable template, in the working area of the repository, marked DRAFT with no version number. Drafts are never distributed for use.

  5. Review. The owner circulates to every role named in the document's RACI and to any interfacing process owner. Reviewers respond within the service standard. Substantive objections are resolved or recorded as dissent in the register. [CONTROL] A document affecting another procedure is not approved without that procedure owner's review.

  6. Impact assessment for changes. For a revised document, the owner records what changed, why, which records or systems are affected, whether training is needed, and whether historical records remain valid. For documents in the academic pack, the owner records the effect on any OBEF time series (a definition change breaks three-year and five-year comparability). [CONTROL] The change log in section 14 of the document is updated before approval, never after.

  7. Approve. The approver per the matrix signs, dates and records the effective date. Approval is recorded in the register and in the document's control block. [CONTROL] Segregation: the drafter of a procedure does not approve it. [CONTROL] An approver does not approve a document they have not read; the approval record includes the version hash or page count reviewed.

  8. Publish. The Document Controller assigns the version number (major for scope or control changes, minor for editorial), converts to the published format, places it in the published location, and removes the superseded version from that location in the same action. [CONTROL] No period exists in which two versions are both retrievable from the point of use.

  9. Communicate. The owner notifies affected staff, states what changed and from when, and arranges training or briefing where the impact assessment requires it. Acknowledgement is recorded for documents with safety, legal or data-protection content.

  10. Archive the superseded version. Handed to AW-04 with its full control history. Superseded versions are retrievable on request for as long as records made under them are retained.

  11. Schedule the review. Default review interval: policies three years, procedures two years, work instructions and forms annually, or sooner on any trigger in section 3. The register holds the date and the Document Controller runs a monthly check.

  12. Conduct the periodic review. The owner confirms the document is still needed, still accurate, still consistent with governing policy and interfacing procedures, and still used in practice. Outcome is one of: reconfirm unchanged (new review date), revise (return to step 4), or withdraw (step 13). [CONTROL] A reconfirmation without evidence that the document was checked against current practice is not a review.

  13. Withdraw. On withdrawal, the register is updated, the document is removed from the point of use, affected staff are told, and the final version is archived via AW-04 with the withdrawal reason.

  14. Control external documents of origin. Standards, regulator guidance and MBRU policies that IoL relies on are listed in the register with the version held and the date last checked. The Quality Lead checks for new versions at least annually and on any notification, and opens a change request where a new version affects an IoL document. [CONTROL] The OBEF guide is an external document of origin; version 11.5 is the one this pack is built on, and a new version triggers review of the academic pack.

7. Information handled and interfaces

Flow Content Classification To or from
In Change requests, audit findings, regulatory changes Internal Any staff; AW-24; AW-25; regulators
In Draft content Internal, may contain process detail affecting security Document owners
Out Approved documents Internal; learner-facing documents are public within MBRU All AW and WF; learners via AW-18
Out Superseded versions with history Internal, archival AW-04
Register Document ID, title, type, owner, version, approver, effective date, review date, status, external documents held Internal Maintained here; read by AW-24, AW-25

Two packs sit under this procedure. The academic pack's 26 workflows and this pack's 25 are controlled documents from the moment this procedure is approved. Until then they are drafts, which is what their control blocks say.

8. Controls

Stated as assertions an auditor can test.

# Control Evidence
C1 Every document in use appears in the register with a current status Register versus a sample of documents at the point of use
C2 No published document is past its review date by more than 30 days Monthly register check, escalation log
C3 Every published version carries an approver, a date and a version number in its control block Sample of documents
C4 The drafter and the approver of a procedure are different people Register
C5 Only one version of any document is retrievable from the point of use Repository check
C6 Every superseded version is retrievable from archive with its control history AW-04 archive sample
C7 Every change carries an impact assessment and a change-log entry made before approval Document section 14 versus register
C8 External documents of origin are listed with version held and last check date Register
C9 Any uncontrolled document found in use generates a non-conformity AW-24 log

9. Exceptions and escalation

Exception Authorised by Rationale required Recorded where
Interim approval where the approver is unavailable and the change is urgent Senior Director, IoL The urgency and the risk of waiting; ratification within 30 days Register
Temporary work instruction pending a full procedure Quality Lead Scope, expiry date not exceeding 90 days Register, marked TEMPORARY
Deviation from a controlled document in a specific case Process owner, with the document owner informed The reason, the case, the date; not a precedent Deviation log, reviewed at AW-25
Adoption of an external document at a version MBRU has not yet adopted Quality Lead with MBRU policy office Why IoL needs the newer version Register

This procedure must never: allow a document into use without a register entry; allow the drafter to approve their own procedure; leave two versions retrievable at the point of use; record a review that did not check the document against practice; backdate an effective date; or alter a change log after approval.

10. Service standards

Service Standard
Request logged and assessed 5 working days
Reviewer response 10 working days
Approval decision after review complete 10 working days
Publication after approval 3 working days
Communication of change Before the effective date
Monthly register check By the 5th working day of each month
Periodic review completed Within 30 days of the review date
Retrieval of a superseded version on request 5 working days

11. Records and retention

Record System Retention Owner
Document register Controlled repository [IoL to confirm] Permanent Document Controller
Change requests and impact assessments Repository Life of document plus 7 years Document Controller
Review and approval records Repository Life of document plus 7 years Document Controller
Published versions Repository, published location Until superseded, then archive Document Controller
Superseded and withdrawn versions Archive via AW-04 As long as records made under them are retained AW-04
Communication and acknowledgement records Repository 7 years Document owner
Deviation log Repository 7 years Quality Lead

12. Risks and controls

# Risk Consequence Control Owner
1 Staff work from an old version held locally Inconsistent practice, audit finding Single published location; C5; periodic communication that local copies are uncontrolled Document Controller
2 Documents drift past review dates Management system decays silently Monthly register check; C2; escalation Quality Lead
3 Academic pack definition changed without impact on OBEF time series assessed Incoherent three-year or five-year series, indefensible under review Step 6 impact assessment names the OBEF effect Document owner
4 Conflicting documents from IoL and MBRU Staff choose, and choose differently Institutional policy always prevails; register flags the conflict; change opened Quality Lead
5 Repository access allows uncontrolled editing of published versions Integrity failure Write access to the published location limited to the Document Controller; AW-15 access review AW-15
6 New OBEF guide version issued and not noticed Academic pack built on a superseded framework External documents of origin register; annual check; MoHESR notifications routed here Quality Lead
7 Volume of documents exceeds capacity to review Backlog, then abandonment Review intervals set by document type; merge rather than multiply Quality Lead

13. Performance measures

Dimension Measure Target
Compliance Documents in use with a register entry 100%
Compliance Documents past review date at the monthly check 0
Timeliness Publication within 3 working days of approval 95%
Timeliness Periodic reviews completed within 30 days of due date 90%
Accuracy Control-block defects found on sample 0
Experience Staff able to locate the current version of a named document at first attempt, on periodic test 95%
Integrity Uncontrolled documents found in use per audit cycle 0, with trend reported

14. Change control

Date Version Change Reason Approved by
2026-09-02 0.1 Initial draft IoL administrative pack draft, unapproved