Pending approval — not yet published
This document is in the review and approval workflow and is not yet available to staff. It will appear in the WMS library once it has been approved.
← Back to Document LibraryDocument Management Standard
Contents & downloads
Nomenclature
| Term | Definition |
|---|---|
| ASD | Australian Signals Directorate |
| DISP | Defence Industry Security Program |
| DLM | Dissemination Limitation Marker |
| DSPF | Defence Security Principles Framework |
| IMS | Integrated Management System |
| IRAP | Information Security Registered Assessors Program |
| ISM | Information Security Manual (Australian Government) |
| ISO | International Organization for Standardization |
| PSPF | Protective Security Policy Framework |
| WMS | Westlink Management System |
Purpose
This standard establishes the requirements for creating, identifying, classifying, controlling, storing, retaining, and disposing of documented information within the Westlink Management System (WMS).
It provides the rules and conventions that ensure documented information is consistently named, version-controlled, appropriately classified, and available at the point of use. The standard supports compliance with ISO 9001:2015, ISO 45001:2018, and ISO 14001:2026 clause 7.5 requirements, the Protective Security Policy Framework (PSPF) 2025, and Defence Industry Security Program (DISP) obligations.
Scope
This standard applies to all documented information within the WMS, including:
-
Maintained documented information — policies, procedures, standards, manuals, plans, guidelines, work instructions, and templates
-
Retained documented information — records, registers, forms, checklists, reports, and evidence of conformity
-
External-origin documents determined necessary for the planning and operation of the management system
The standard applies to all Westlink workers, contractors, and subcontractors who create, review, approve, distribute, or dispose of WMS documented information. It covers documents in all formats and media, whether electronic or physical.
Exclusions
Project and proposal documents prepared before the effective date of this standard are excluded from the naming convention requirements. All projects and proposals commencing after the effective date shall apply the naming protocols in Section 5.2. Client-mandated document formats and naming conventions take precedence where contractually required.
Normative References
The following documents are essential for the application of this standard. Where dated references are given, only the edition cited applies. Where undated references are given, the latest edition applies.
-
ISO 9001:2015 Quality Management Systems — Requirements — cl. 5.2 (policy), cl. 7.5 (documented information), cl. 10.2 (nonconformity and corrective action)
-
ISO 45001:2018 Occupational Health and Safety Management Systems — Requirements — cl. 5.2 (policy), cl. 6.1 (hazard identification), cl. 8.2 (emergency preparedness), cl. 10.2 (incident investigation)
-
ISO 14001:2026 Environmental Management Systems — Requirements — cl. 5.2 (policy), cl. 6.1.2 (environmental aspects), cl. 8.1 (operational controls and life cycle perspective), cl. 9.1.1 (monitoring, measurement and calibrated equipment), cl. 10.1 (continual improvement)
-
AS ISO 15489-1:2017 Records Management — Concepts and Principles — Retention scheduling, evidence integrity
-
Protective Security Policy Framework (PSPF) — Policy 8 (sensitive information handling), Policy 17 (security incident reporting)
-
Australian Government Information Security Manual (ISM) — ACSC — Controls 0120–0143 (cyber security incident response), Control 0123 (ACSC reporting)
-
Defence Industry Security Program (DISP) — Security Governance Framework — Membership obligations, security incident reporting
-
Electronic Transactions Act 1999 (Cth) — Electronic signatures and records equivalence
-
Privacy Act 1988 (Cth) — APPs 1–13, Part IIIC (NDB scheme), s.26WK–WR
Definitions
| Term | Definition |
|---|---|
| Documented information | Information required to be controlled and maintained by the organisation and the medium on which it is contained (ISO 9000:2015 cl.3.8.6). |
| Maintained documented information | Documents that describe the management system and how it operates — policies, procedures, standards, plans. Updated as the system evolves. |
| Retained documented information | Records that provide evidence of activities performed or results achieved — forms, registers, reports, checklists. Preserved as evidence of conformity. |
| Document Controller | The person responsible for administering the WMS library, managing document workflows, and maintaining the document register. Currently assigned to the Operations Manager. |
| Process Owner | The person accountable for a business process and its associated documented information. Responsible for content accuracy and initiating reviews. |
| Security classification | A designation applied under the PSPF that reflects the potential damage from unauthorised disclosure. Determines handling, storage, and disposal requirements. |
| WMS library | The SharePoint document library that serves as the single source of truth for all controlled WMS documents. |
Requirements
Document Hierarchy and Types
The WMS uses a structured document hierarchy. The IMS Manual (QHSE-MAN-001) is the top-level system document. Policies state organisational commitments. Standards define mandatory requirements. Procedures, plans, and work instructions provide operational detail. Forms, templates, checklists, and registers capture evidence.
The following WMS document types are recognised. Each type has a three-letter code used in the naming convention.
| Code | Type | Description |
|---|---|---|
| CHK | Checklist | Standardised list to verify that required steps or items are addressed. |
| FRM | Form | Structured format for collecting information in a controlled and consistent manner. |
| GDL | Guideline | Recommendations or best practices to inform and guide actions. Advisory, not mandatory. |
| MAN | Manual | Comprehensive document describing a management system or operational framework. |
| PLN | Plan | Outline of steps, resources, and responsibilities to achieve a specific objective. |
| POL | Policy | Formal statement by senior management defining organisational intent and expected conduct. |
| PRE | Presentation | Visual material for training, awareness, or stakeholder briefings. |
| PRO | Procedure | Defined activities, responsibilities, and interfaces for delivering a service or managing a process. |
| SCH | Schedule | Time-based register or timetable for planned activities. |
| STD | Standard | Mandatory requirements and rules applicable across all business activities. |
| TPL | Template | Preset format for reuse in creating consistent documents or records. |
Naming Convention
All WMS documents shall be named using the following convention:
{Department}-{DocType}-{Sequence}
Where:
-
Department — the business function code from Table 7 (e.g. GOV, QHSE, OPS)
-
DocType — the three-letter document type code from Table 5 (e.g. POL, PRO, STD)
-
Sequence — a three-digit sequential number commencing at 001, unique within each department-type combination
Example: GOV-STD-001, QHSE-PRO-007, OPS-MAN-002.
| Code | Business Function |
|---|---|
| BD | Business Development |
| CHT | Chartering |
| COM | Commercial |
| DEF | Defence |
| FIN | Finance |
| GOV | Governance |
| HR | Human Resources |
| OPS | Operations |
| QHSE | Quality, Health, Safety and Environment |
| TEC | Technology |
Do not include the revision number in the document filename. Embedding revision numbers in filenames breaks cross-document links and version tracking in SharePoint.
If a required code combination is not available, contact the Document Controller. New codes shall not be created without change management approval.
Legacy Naming Convention
Documents created under the previous naming convention used the format {Entity}-{Scope}-{Function}-{DocType}-{Sequence} (e.g. WLK-GBL-DMS-STD-001). These codes are mapped to the current convention and shall not be used for new documents. The migration map is maintained by the Document Controller.
Project-Specific Documents
When the WMS does not fulfil specific contract requirements, project-specific procedures may be developed. Project documents shall use the project number as a prefix (e.g. PRJXXXXX-PRO-001). The Process Owner and Document Controller shall be consulted before creating project-specific documents to avoid unnecessary duplication of WMS content.
Creation, Review, and Approval
All WMS documents shall be created using the approved templates:
-
Policy template (policy.docx) — for all policy documents (POL)
-
Document Template with Cover (Document Template with Cover.docx) — for all other WMS document types
The following review and approval requirements apply:
| Activity | Responsibility | Requirement |
|---|---|---|
| Document creation | Author (Process Owner or delegate) | Use approved template. Complete all metadata fields. Assign document code per naming convention. |
| Technical review | Subject matter expert | Verify content accuracy, completeness, and alignment with applicable standards and legislation. |
| Approval — policies | Chief Executive Officer | All policies require CEO approval before issue. |
| Approval — standards, procedures, plans, manuals | Operations Manager or delegated Process Owner | Approve for suitability and adequacy before issue. |
| Approval — forms, templates, checklists | Process Owner | Approve for fitness for purpose. |
| Periodic review | Process Owner | Review at the cadence specified in the document metadata (Annual default; Biennial for forms and templates). |
Security Classification
All WMS documents shall be classified in accordance with the Australian Government Protective Security Policy Framework (PSPF) 2025. Westlink uses the following classification tiers:
| Classification | Potential Damage | Handling Summary |
|---|---|---|
| UNOFFICIAL | No damage to government, individuals, or organisations | No special marking or handling required. Default for non-Defence WMS documents. |
| OFFICIAL | Low or no damage to government | Mark ‘OFFICIAL’ in header and footer. Standard business handling. May be shared externally with Document Controller approval. |
| OFFICIAL:Sensitive | Low to medium damage to government, individuals, or organisations | Mark ‘OFFICIAL: Sensitive’ in header and footer (red, bold). Encrypt in transit. Need-to-know access only. Do not share externally without Security Officer approval. |
| PROTECTED | Significant damage to government, individuals, or organisations | Mark ‘PROTECTED’ in header and footer (red, bold). IRAP-assessed systems only. Secure storage. Transmission encryption mandatory. Security Officer shall authorise access. |
The document author shall assess the classification at creation and before each review. The originator controls reclassification. Where aggregation of multiple OFFICIAL:Sensitive documents may create a PROTECTED aggregate, the Security Officer shall assess the combined sensitivity.
Westlink Security Levels
In addition to PSPF classification, Westlink applies an internal security level to control access within the organisation:
| Level | Access |
|---|---|
| General | Available to all Westlink workers and authorised external parties. |
| Internal | Westlink workers only. Must not be distributed externally without CEO approval. |
| Restricted | Access limited to specified authorised user groups. The document security table shall identify the authorised groups. |
| Confidential | Senior management and Board members only. |
Marking and Handling
Documents classified OFFICIAL and above shall display the classification centred in the header and footer of every page. OFFICIAL:Sensitive and above shall be displayed in red, bold text.
All documents shall display ‘Uncontrolled when printed’ in the footer. Printed copies are uncontrolled unless physically stamped ‘CONTROLLED COPY’ by the Document Controller.
Dissemination limitation markers (DLMs) may be applied within the OFFICIAL tier where additional handling caveats are required: LEGAL-PRIVILEGE, PERSONAL-PRIVACY, COMMERCIAL-IN-CONFIDENCE.
Distribution and Access Control
The WMS SharePoint library is the single source of truth for all controlled documents. Workers shall access the current version from the library. Distribution of documents by email or other means creates uncontrolled copies and shall be avoided.
Access permissions in SharePoint shall be configured to reflect the security level assigned to each document. Restricted and Confidential documents shall have explicit access controls. The Document Controller maintains access permissions.
Storage and Preservation
All WMS documents shall be stored electronically in the SharePoint WMS library. The library provides version history, metadata indexing, search capability, and automated backup.
Documents classified OFFICIAL:Sensitive and above shall be stored on systems that meet PSPF handling requirements. Physical copies of classified documents shall be stored in approved security containers appropriate to the classification level.
The Document Controller shall maintain legibility of all stored documents, including conversion from obsolete formats where necessary to preserve readability.
Version Control
Documents shall be version-controlled from initial draft through to retirement:
| Stage | Version Format | Rule |
|---|---|---|
| Draft | Alpha (A, B, C) | Sequential alpha indicator until the document is approved. |
| Approved and issued | Numeric (1, 2, 3) | Revision 1 on first approval. Sequential numeric thereafter. |
| Client-specific override | Per contract | Different sequencing permitted if contractually required and approved by the Operations Manager. |
Each revision shall include a revision history entry describing what changed, who authored the change, and who approved it. The revision table is maintained in the document front matter.
Change Control
Changes to approved documents shall follow the document control procedure (GOV-PRO-002). The Process Owner initiates the change. Changes shall be reviewed and approved before the revised document is published to the WMS library.
When a document is superseded, the Document Controller shall:
-
Archive the previous approved revision in the SharePoint version history.
-
Retain a marked-up copy (track changes) identifying the changes made.
-
Communicate the update to affected workers where the change affects operational practice.
When a document is retired, append the final revision number to the filename for archival reference. Links from other documents will continue to point to the latest approved version in SharePoint.
Retention and Disposition
Retention periods for WMS documented information are defined in the Document Retention Schedule (GOV-SCH-001). The following legislative minimums apply and shall not be overridden by shorter organisational retention periods:
| Record Category | Minimum Retention | Legislative Source |
|---|---|---|
| Health monitoring records | 30 years | WHS Regs 2022 (WA) r.368, r.381 |
| Atmospheric monitoring | 30 years | WHS Regs 2022 (WA) r.361 |
| Safety data sheets (long-latency chemicals) | 30 years | WHS Regs 2022 (WA) r.344 |
| WHS incident records | 5 years | WHS Regs 2022 (WA) r.12 |
| Employee records | 7 years post-termination | Fair Work Act 2009 (Cth) s.535 |
| Pay slips | 7 years | Fair Work Act 2009 (Cth) s.536 |
| Financial records | 7 years | Corporations Act 2001 (Cth) s.286 |
| Workers’ compensation claims | 7 years post-settlement | WC&IM Act 2023 (WA) |
| Environmental harm reports | Permanent | EP Act 1986 (WA) s.72 |
| Heavy vehicle fatigue and maintenance records | 3 years | RT(V) Regs 2014 (WA) |
| Plant registration records | Life of plant + 5 years | WHS Regs 2022 (WA) Part 5.1 |
Disposal methods shall be proportionate to the document’s security classification:
| Classification | Disposal Method | Evidence |
|---|---|---|
| UNOFFICIAL / OFFICIAL | Cross-cut shred (physical) or standard deletion (electronic) | Disposal log entry |
| OFFICIAL:Sensitive | ASD-approved media sanitisation (electronic) or cross-cut shred (physical) | Disposal log entry |
| PROTECTED | ASD-approved destruction, witnessed | Destruction certificate retained |
External-Origin Document Control
External documents determined necessary for the planning and operation of the management system shall be identified and their distribution controlled. This includes Australian Standards, codes of practice, client specifications, and regulatory guidance.
The Document Controller shall maintain a register of external documents, verify currency at each periodic review, and restrict reproduction in accordance with copyright and licence terms.
Classified Document Register
Documents classified OFFICIAL:Sensitive and above shall be recorded in the classified document register maintained by the Security Officer. The register shall track:
-
Receipt — date, source, and classification of incoming documents
-
Custody — current holder and storage location
-
Transfer — date, recipient, and method of transfer
-
Disposal — date, method, and evidence of destruction (per the disposal methods in Section 5.11)
This requirement derives from DISP obligations and DSPF Principle 16, Control 16.1 for classified material handling.
Compliance Criteria
Compliance with this standard shall be verified during internal audits and management reviews. The following criteria shall be assessed:
| # | Criterion | Evidence |
|---|---|---|
| 1 | All WMS documents use the approved naming convention. | WMS library — document reference codes. |
| 2 | All documents are created from approved templates. | Spot-check document formatting and metadata. |
| 3 | All documents have a current security classification. | Document metadata in SharePoint. |
| 4 | Review dates are current — no overdue reviews. | WMS library review date column; HTML library dashboard. |
| 5 | Version control is applied consistently (draft alpha, approved numeric). | Revision tables in front matter. |
| 6 | Changes follow the document control procedure (GOV-PRO-002). | Change request records; SharePoint version history. |
| 7 | Retained records meet legislative minimum retention periods. | GOV-SCH-001 retention schedule vs actual disposal records. |
| 8 | Classified documents (OFFICIAL:Sensitive+) are registered in the classified document register. | Classified document register entries. |
| 9 | External-origin documents are identified and current. | External document register. |
| 10 | Disposal methods match the classification tier. | Disposal logs and destruction certificates. |
Records
The following records provide evidence of compliance with this standard:
| Record | Location | Responsible | Retention |
|---|---|---|---|
| WMS document register | SharePoint WMS library | Document Controller | Life of organisation + 7 years |
| Document Retention Schedule | GOV-SCH-001 in WMS library | Document Controller | Current version + 2 prior versions |
| Document review and approval records | SharePoint version history and approval workflows | Document Controller | Life of document + 5 years |
| Classified document register | Security Officer’s records (restricted access) | Security Officer | Life of document + 7 years |
| Disposal logs and destruction certificates | Security Officer’s records | Document Controller / Security Officer | 7 years post-disposal |
| External document register | WMS library | Document Controller | Current version |
References
Related WMS documents:
-
QHSE-MAN-001 — Westlink Management System Manual
-
GOV-PRO-002 — Document Control Procedure
-
GOV-SCH-001 — Document Retention Schedule
-
GOV-POL-001 — Quality Policy
-
TEC-POL-001 — Information Security Policy
Compliance coverage — cited by 4 requirements across 3 frameworks
ISO 14001:2026(1)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| ISO14001-2026-7.5.1-01 | 7.5.1 | Full | Document Management Standard. |
ISO 45001:2018(1)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| ISO45001-2018-7.5.1-01 | 7.5.1 | Full | Document Management Standard. |
ISO 9001:2015(2)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| ISO9001-2015-7.5.2-01 | 7.5.2 | Full | Document Management Standard — identification and description. | |
| ISO9001-2015-7.5.3.1-01 | 7.5.3.1 | Full | Classification scheme. |
Declared compliance references (4)
ISO14001-2026-7.5.1-01ISO45001-2018-7.5.1-01ISO9001-2015-7.5.2-01ISO9001-2015-7.5.3.1-01
Document Revision Summary
| Rev | Issued | Document Ref | Document Title | Author | Approved |
|---|---|---|---|---|---|
| 2 | 13/03/2026 | GOV-STD-001 | Document Management Standard | Craig Foreman | CEO (JDG) |
| 1 | 07/10/2022 | WLK-GBL-DMS-STD-001 | Document Numbering & Security Classifications | Peter Wilkinson | CEO (JDG) |
Document Revision Details
| Rev | Purpose of revision and changes made |
|---|---|
| 2 | Major rewrite: restructured to §2.4 Standard format; aligned security classifications to PSPF 2025; updated naming convention to Dept-Type-Seq format; added ISO 7.5 document control requirements; added retention framework and compliance criteria.• Restructured from naming-convention reference to full §2.4 Standard format with normative references, definitions, requirements, compliance criteria, and records sections.• Aligned security classifications to PSPF 2025 — replaced legacy tiers (Confidential/Restricted/Internal/Unrestricted) with PSPF classifications (UNOFFICIAL/OFFICIAL/OFFICIAL:Sensitive/PROTECTED).• Updated naming convention from {Entity}-{Scope}-{Function}-{DocType}-{Seq} to {Department}-{DocType}-{Seq} format.• Added comprehensive document control requirements covering creation, review, approval, distribution, storage, version control, change control, retention, and disposition per ISO 7.5.• Added legislative minimum retention periods table (WHS Regs, Fair Work Act, Corporations Act, WC&IM Act, EP Act, RT(V) Regs).• Added disposal methods by classification tier per PSPF 2025 and ASD media sanitisation requirements.• Added DISP classified document register requirement for OFFICIAL:Sensitive and above (DSPF Principle 16, Control 16.1).• Added compliance criteria section with 10 audit checkpoints for document control verification. |
| 1 | Initial issue. Document naming conventions and security tiers. |