Blog

2026.08.31

Electronic Work Instructions: Revision Control and a 90-Day Plan

Electronic Work Instructions: Revision Control and a 90-Day Plan

An electronic work instruction project is not complete when a PDF appears on a tablet. The control objective is to deliver the one correct, approved revision to the right order, lot, operation, machine and operator role, then retain evidence of what was shown, acknowledged and handled as an exception. This guide turns that objective into requirements for a Thai factory: data identity, change control, offline behavior, multilingual approval, integration, FAT/SAT and a 90-day pilot.

Electronic work instructions control application—not just display

Paper remains practical: it is familiar, writable and independent of power. Its weaknesses appear when revisions accelerate. An obsolete copy may remain at a station; supervisors must distribute and retrieve pages; operators spend unpredictable time searching; and acknowledgements become detached from deviations and production results. A shared PDF folder improves access but does not automatically resolve applicability or prove use.

The control objective can be stated simply: use order, lot, operation, asset and operator role to resolve exactly one effective approved instruction, while recording presentation, acknowledgement and exceptions. Once that objective is fixed, tablets, fixed terminals, barcodes and QR codes become delivery choices. None of them—and no electronic signature by itself—guarantees controlled work.

Thailand’s Office of Industrial Economics reported a July 2026 manufacturing production index of 94.80, down 0.94% month on month and up 0.46% year on year. Electronics/components rose 2.36% year on year, rubber/plastics 4.55%, and food 1.47%. These figures are macro context only; they do not show that work instructions caused any change. They do underline that plants differ in product mix, regulation, languages and revision cadence, so applicability rules must be designed for the actual operation.

Thailand BOI reported 132 Smart and Sustainable Industry applications worth about THB 17.2 billion in H1 2026, covering machinery upgrades, digital technology, automation and robotics. Across H1 it reported 1,300 applications worth about THB 1.31 trillion and said approved projects would use about THB 386 billion of domestic raw materials annually. These are application and approval aggregates—not TOMAS TECH outcomes and not proof that a specific digital-instruction project qualifies for incentives. Eligibility requires project-specific confirmation.

A digital work instruction system differs from a PDF repository

Control pointShared PDFsControlled electronic instructions
Authoritative recordFile in a folderRecord with ID, revision and approval state
ApplicabilityOften selected by the operatorResolved from order, lot, operation, asset and role
RevisionFilename or modified dateEffective dates, supersession and approval history
OfflineDownload may remain indefinitelyCache scope, expiry, revocation and sync are governed
EvidenceViewing is uncertainRevision shown, acknowledgement and exception recorded
LanguagesIndependent files driftOne controlled source with per-language approval

Do not make the operator responsible for choosing among plausible documents. A station should read the manufacturing context and return one effective instruction. Zero matches or multiple matches must trigger a defined stop, supervisor decision or controlled deviation—not a best guess.

For broader WIP visibility, exception management and replanning, see our guide to a manufacturing process management system. For device UX and implementation choices, see shop-floor mobile app development. A mobile app is a channel; governance, identity, revision control, offline policy and audit evidence define the system.

Eight data elements to define first

A filename is not a sufficient instruction identity. Separate at least:

  1. instruction_id, an immutable identifier;
  2. revision;
  3. effective_from and effective_to;
  4. approval_state such as draft, review, approved or retired;
  5. supersedes, linking the replaced revision;
  6. product, route and operation applicability;
  7. machine, line or tooling applicability; and
  8. operator role or qualification applicability.

Revision alone is insufficient. Revision 4 might apply to Line A on 1 August but to Line B only after a machine modification on 15 August. Put those rules in machine-readable data, not prose buried inside the document. Conceptually, the distribution rule is “order/lot/operation/asset/operator role → one effective approved instruction.”

Electronic Work Instructions: Revision Control and a 90-Day Plan - figure 1

“Always show the latest” is also unsafe. A formally released old route may remain valid for existing WIP while new lots adopt a new process. The system must preserve the revision that was effective for the manufacturing event, not merely the newest file. Define boundaries with item revision, BOM, routing and machine state.

Couple revision control with accountable workflow

A practical flow is draft → technical review → quality/safety review → approval → effective date → controlled release → acknowledgement → supersede/archive. Record who evaluated what evidence and why each transition was allowed. Decide whether authors and approvers must differ, who can authorize an emergency revision, and whether language approval is simultaneous or follows source approval.

A change request should include its reason, affected products/operations/assets, training impact, effective condition and rollback method. An approval button without impact analysis is weak control. NIST SP 800-53 Rev. 5.1 CM-3 is a useful design reference for controlled change; AU-2 and AU-12 help structure deliberate event selection and logging. This does not imply a legal requirement for Thai factories to comply with that publication.

Treat emergency changes as time-bound exceptions, not skipped governance. Require scope, affected lots, expiry, authorizer and post-review date. Rollback is more than restoring an old PDF: it includes approval to reactivate a revision, WIP disposition, cache invalidation and any renewed acknowledgement.

Evidence should be sufficient, not invasive

For each instruction event, retain the user or station, timestamp, revision shown, acknowledgement, optional training state and reference to an exception or deviation. More data is not automatically better. Photos, location, fine-grained interaction time or continuous camera feeds create privacy and labor risks unless purpose, retention, access and employee notice are defined.

Opening a screen is not the same as understanding it. A safety-critical change may require a knowledge check or retraining; punctuation may need only a notice. If every page always requires a signature, operators may click mechanically and evidence quality falls. Match acknowledgement to change severity, process risk and qualification.

Logs should not silently become worker surveillance. Where a personal identity is unnecessary, a role or station identifier may suffice. Where personal data is needed, agree purpose limitation, minimization, retention, access and investigation procedures with HR, legal and information security.

Shop-floor tablet instructions need explicit offline rules

Temporary loss of connectivity is realistic in factories because of building structure, maintenance and radio interference. “Works offline” is too vague. Define that:

  • only the required approved set is encrypted and cached;
  • offline state and last-sync time are visible;
  • cache expiry and stop/degraded-operation rules vary by process risk;
  • a revoked revision cannot be selected even if its file remains on the device;
  • queued evidence uses an idempotency key so retries do not duplicate records; and
  • central/device conflicts have a declared priority and human resolution path.
Electronic Work Instructions: Revision Control and a 90-Day Plan - figure 2

A dangerous failure is a device that appears synchronized while only some documents failed. Track sync by instruction ID and revision. Decide whether failed revocation blocks the affected operation. Monitor clock drift because a wrong device clock can expose a not-yet-effective or expired revision. Shared devices also require shift-change logout, lost-badge handling, glove usability, lock-screen recovery and prevention of the previous operator’s privileges carrying forward.

One controlled source, separate approval for every language

Independent Japanese, English, Thai and Vietnamese folders drift. Use one controlled source with language variants and explicit translation states. Source Revision 6 may be approved while Thai Revision 6 is approved and Vietnamese Revision 6 remains under review; that difference must be visible.

Never silently fall back to another language or an older revision. A language the operator cannot understand is not a safe instruction, while an old translation breaks revision control. Policy options include stopping the operation, using a qualified interpreter, or formally approving a temporary bilingual version.

Validate units, decimal conventions, dates, warning terms, text inside diagrams, left/right orientation and equipment tags. Test Thai combining characters and Vietnamese diacritics on the actual tablet, export and search path. Assign distinct accountability to translator, technical checker, native shop-floor reviewer and final approver.

Define ERP, MES, QMS and identity boundaries

ERP or MES typically supplies order, item, lot, routing and operation context. A document repository or QMS supplies approved content. An identity provider supplies users and roles; barcode/QR identifies the object; acknowledgements, exceptions and production events may return to MES or a data platform.

For every boundary, define data owner, identifier, update timing and failure responsibility. If ERP routing changes but the applicability table does not, which system blocks work? When QMS retires a revision, how quickly must every cache reject it? When an employee changes roles, when must access change? Capture these as business service levels, not only API fields.

QR is a useful carrier but not a control system. If the plant already uses GS1 identifiers, GS1 Digital Link URI Syntax 1.7.0, ratified in August 2026, may be an interoperability option for expressing keys such as GTIN with batch/lot or serial in a web URI. It is not mandatory for work instructions. Adopt it only when it fits the existing identification and security model.

RFP questions that expose real capability

Ask vendors to demonstrate failure scenarios, not only attractive screens:

  1. How is one revision resolved from order, lot, operation, asset and role?
  2. What happens with zero or multiple matches?
  3. How are approved caches, revocation and resynchronization controlled?
  4. How is unapproved translation prevented from silent fallback?
  5. Which audit events are retained, protected, searched and exported?
  6. How are ERP/MES/QMS/identity integration failures detected and replayed?
  7. Can all data be exported in a documented standard form at contract end?
  8. What are the vulnerability disclosure, update, end-of-support and incident-notification terms?

The CISA/FBI Secure by Demand Guide encourages buyers to ask security questions before procurement, include suitable requirements in contracts and continue assessment afterward. NIST SP 1326, final on 8 July 2026, describes ICT-supplier due-diligence components including FOCI, provenance, resilience, foundational cyber practices and supply-chain tiers. Its scope is ICT suppliers; it should not be presented as a method for evaluating raw-material suppliers.

Request live demonstrations of a revoked revision on an offline device, duplicate scan replay and interruption during approval. Separate license, migration, translation, devices, wireless remediation, integration, testing, training, support and exit costs in commercial proposals.

Minimum FAT/SAT acceptance cases

Acceptance must go beyond “the page opens.” Test at least:

  • revoked revision is blocked for new work;
  • wrong product, operation or machine is blocked;
  • expired offline cache stops or enters explicitly approved degraded mode;
  • repeated synchronization does not duplicate evidence;
  • clock drift is detected and governed;
  • duplicate scans do not create duplicate starts/results;
  • shared-device logout clears the prior user’s context;
  • Thai combining characters and Vietnamese diacritics display, search and export correctly;
  • interrupted approval cannot leave a half-approved record;
  • rollback aligns the intended lots and all relevant devices; and
  • an authorized user can export reconstructable audit evidence.

Attach prerequisite data, action, expected result, evidence and approver to each case. Retain screens, logs, API responses and device state—not a sentence saying “no problem.” Include shift-change load, daily synchronization, large diagrams and constrained bandwidth in performance tests.

Regulated operations may require more. FDA Part 11 scope guidance concerns certain electronic records created, maintained or submitted under FDA record requirements; it is not a universal factory requirement. Quality and legal teams should determine applicability by product, market and record before adding electronic-signature, audit-trail and retention controls.

Connecting manufacturing execution data capture

Linking acknowledgement with manufacturing execution data capture can show which instruction revision accompanied a lot. A view event, however, is not proof of output or quality. Quantity, disposition, downtime and measurements must come from their authoritative systems and defined measurement rules.

Use a common event ID when sending an event to MES, the instruction service and a data platform, and make replay idempotent. Define rework, split/merged lots, proxy entry and late entry. Decide whether production before acknowledgement triggers a warning or interlock based on risk and existing safety controls; a software screen must not replace machine-safety functions.

Dashboards should emphasize exceptions—zero/multiple matches, expired caches, unapproved translations, overdue acknowledgement and failed replay—rather than rank workers by clicks. The purpose is to expose defects in documents, master data and integration.

Read the financial model as an illustration only

Every number in this section is an illustrative planning assumption, not observed performance, a market benchmark, price, quotation or guarantee. Assume 3 lines, 2 shifts, 120 operators and 240 controlled work instructions. Baseline instruction-related wrong-revision, search or clarification events are assumed at 18 per month and 25 minutes each, or 7.5 hours per month. Supervisor distribution and acknowledgement administration is assumed at 40 hours per month.

Set pilot targets—not benchmarks—of 50% lower distribution/admin time and 60% fewer wrong-revision events after stable operation. Assuming loaded rates of THB 450/hour for supervisors and THB 300/hour for operators/quality, illustrative annual direct labor saving is:

(40h × 50% × THB 450 + 7.5h × 60% × THB 300) × 12 = THB 124,200/year

No scrap, downtime or audit saving is added because that would need a separate, non-overlapping verified baseline. THB 124,200 alone is too small to justify a broad platform; combine it with verified local loss data without double counting. Costs should include software, implementation, devices, protection/charging, Wi-Fi, document cleanup, translation, integration, testing, training, support, upgrades and exit migration.

A 90-day pilot with evidence gates

The 90-day sequence below is an editorial recommendation, not a standard.

Days 1–30: baseline and document map

Map product, lot, route, operation, machine, role and document relationships. Select a representative subset rather than migrating all 240 assumed instructions. Define current search time, distribution work and wrong-revision/clarification events. Assign source owner, translator and emergency-change authority. At Day 30, do not build unless scope, IDs, applicability, baseline and exclusions can be explained.

Days 31–60: one-line build and failure tests

Connect minimum order context, approved documents, language state and identities. Test loss of network, revocation, clock drift, duplicate scans and shared-device logout early. Have operators test gloves, lighting, posture, route and warning comprehension. At Day 60, require proof that dangerous misapplication is blocked, offline policy is reproducible and evidence returns once.

Days 61–90: controlled trial and go/no-go

Run a limited production trial, release at least one revision, and exercise shift changes, connectivity loss, exceptions, resync and audit export. Measure side effects; fewer questions do not count as savings if supervisor master-data work rises by the same amount. At Day 90 choose scale, correct and continue, remain limited, or stop. Stopping must include data export, cache removal and safe return to paper or the prior system.

Electronic Work Instructions: Revision Control and a 90-Day Plan - figure 3

Pre-procurement checklist

  • Are inputs and ownership for resolving one instruction defined?
  • Are revision, effectiveness, supersession and approval separate fields?
  • Are zero match, multiple match and unapproved language policies explicit?
  • Can offline expiry, revocation, resync and deduplication be tested?
  • Are logging purpose, personal-data minimization, retention and access agreed?
  • Are ERP/MES/QMS/identity owners and failure responsibilities assigned?
  • Will Thai and Vietnamese be tested on real devices?
  • Are rollback and exit-data export acceptance criteria?
  • Is there a plan to replace every financial assumption with local baseline data?

Summary

Electronic work instructions should be judged by controlled applicability, not by paper removed or tablets purchased. The system must resolve one approved revision for the actual manufacturing context, govern expiry offline, protect language-specific approval and reproduce proportionate evidence. RFPs should expose exception behavior; FAT/SAT should test revocation, wrong context, retry, clock drift, complex scripts and rollback. A 90-day pilot exists to replace assumptions with local decision evidence.

TOMAS TECH can support document mapping, pre-RFP requirements and a one-line pilot before a platform commitment. If you want to translate the current paper/PDF process and system boundaries into testable acceptance criteria, contact us.

FAQ

Are electronic work instructions simply PDFs on tablets?

No. PDF display is a channel. Controlled instructions also require identity, revision, effectiveness, approval, applicability and evidence, plus defined behavior when no valid match exists.

What should a digital work instruction system cost estimate include?

Include licenses, content cleanup, translation, devices, charging/protection, wireless work, ERP/MES/QMS integration, identity, migration, testing, training, support and exit. The THB 124,200/year figure above is only an illustrative planning assumption, not a quotation or promised outcome.

Is shop-floor tablet instruction possible offline?

Yes, if the approved cache, visible offline state, expiry, revocation, conflict policy and idempotent replay are specified and tested by disconnecting the real site network.

How does work instruction version control handle multilingual content?

Use one controlled source and per-language approval. Show translation status and owner. Never silently substitute an older revision or a language the operator cannot understand.

Should manufacturing execution data capture start at the same time?

Not necessarily. You can stabilize instruction applicability first while preserving shared order, lot, operation and event IDs. If deployed together, keep view events separate from authoritative output and quality records.

Does QR ensure compliance?

No. QR identifies a context or object; server-side applicability, approval, expiry and cache controls determine the valid revision. GS1 Digital Link is an optional interoperability approach where GS1 identifiers already fit the plant.

Does every factory need FDA Part 11 controls?

No. Applicability depends on specific FDA-regulated electronic records. Quality and legal review must define scope; adding an electronic signature alone is not compliance.

Sources