Skip to content
SharePoint Solutions & Products

ISO 9001 document control with SharePoint

What ISO 9001 clause 7.5 requires for the control of documented information, what SharePoint covers and where controlled documents need more.

Updated
Table: requirements from ISO 9001 clause 7.5 and how they are implemented, from review and approval to retention and disposition

Anyone who operates a quality management system in accordance with ISO 9001 must control its documented information. The standard does not prescribe any software for this. It describes what must be ensured. How you achieve that is up to you.

This post translates the requirements of clause 7.5 into concrete functions and shows which of them SharePoint brings with it. It replaces neither the text of the standard nor the advice of your certification body.

Governing documents and records are two different things

Since its 2015 edition, the standard has spoken uniformly of “documented information”. In practice, the old distinction is still helpful:

  • Governing documents say how work is done: process descriptions, procedures, work instructions, form templates. They change, and exactly one version is valid at any time.
  • Records (evidence documents) show what has happened: inspection reports, completed checklists, training records. They are no longer changed and are retained for a defined period.

Document control in the narrower sense concerns the governing documents. They are the subject here. Records mainly need orderly filing and retention.

What clause 7.5 requires

In essence, and without any claim to completeness:

When creating and updating (7.5.2)

  • appropriate identification and description, such as title, date, author or number
  • a suitable format and medium
  • review and approval for suitability and adequacy

In the control of documented information (7.5.3)

  • available and suitable for use, where and when it is needed
  • adequately protected, for example against loss of confidentiality, improper use or loss of integrity
  • regulated distribution, access, retrieval and use
  • storage and preservation, including legibility
  • control of changes, for example through version control
  • retention and disposition
  • identification and control of documents of external origin

Requirement by requirement

RequirementStandard SharePointWhere it gets tight
IdentificationMetadata columns, content types, Document IDYou have to ensure a business number that follows your own scheme, and its uniqueness, yourself.
Review and approvalContent approval, approvalsseveral stages, roles per organisational unit, a record per version
AvailabilityLibrary, search, mobile useReaders must be certain that they have the valid version in front of them, even if the next one has already been approved.
ProtectionPermissions, check-outReaders should not be able to change the source. A fixed reader version as a PDF does not come about by itself.
DistributionAlerts, sharingno distribution list per document, no proof of acknowledgement
ChangesVersion historyThe history shows that something has changed, but not at a glance what. A change comment is optional.
Retention and dispositionRetention labels in Microsoft PurviewVersions that are no longer valid must disappear from the readers’ view but remain traceable.
External documentsStored as a file or linkidentification as external and a check that they are up to date

The left half of the table is no small thing. Small organisations pass audits with it if they live by their rules with discipline.

What auditors ask

The requirements become tangible when you read them as questions:

“Show me the valid version of this work instruction.” The answer has to come without thinking, at the workplace and not only in the quality department’s office. A library that contains only valid versions makes this easy.

“Who reviewed and approved it, and when?” The version history shows who published. Who reviewed the content and who approved it is only stated there if the workflow records it. An approval record per version answers the question. If it also appears on the document’s cover sheet, there is no need to search.

“How do your employees find out about changes?” An email to everyone is one answer; a documented acknowledgement per person and version is a better one. More on this in the post on read confirmation in SharePoint.

“What has changed compared with the previous version?” A mandatory comment with every approval helps. A change comparison that sets the old and new versions side by side helps more.

“How do you prevent old versions from being used?” Superseded versions disappear from the reader view. Printouts carry the version and approval date in the footer and a note that they are not subject to change control.

“How do you ensure that documents stay up to date?” A valid-until date with a reminder to those responsible, or a periodic review whose result is recorded.

The document list lives in the metadata

Many systems keep a list of controlled documents in Excel: number, title, version, approval date, person responsible. It reliably goes out of date because it is maintained alongside the documents.

If the same details are held as metadata on the document, the list is a view of the library and always up to date. The prerequisite is that version and approval date are set by the workflow and not by hand.

Where a DMS core comes in

The gaps in the table show what is needed beyond standard SharePoint:

  • approval with your roles and a record per version
  • separate areas for editing and for valid documents
  • a station for approved versions that only apply from an effective date, described in the post Valid from
  • distribution lists and acknowledgement
  • a reader version as a PDF with cover sheet and footer
  • valid until, periodic review and archive

That is the scope of Smarter DMS. The same building blocks also support other standards with the same structure, such as ISO 14001, ISO 45001 or ISO 27001. There, too, the control of documented information is found in clause 7.5.

Conclusion

ISO 9001 does not require software; it requires reliability: the right version is in the right place, its approval is documented, changes are traceable. SharePoint provides a good foundation for this. Whether it is enough is decided by a few questions: are there effective dates, several approval stages, an obligation to prove acknowledgement?

Are you preparing for an audit or rebuilding your document control? Let’s go through your requirements together.

All parts of the series:

  1. SharePoint as a DMS: where major and minor versions end
  2. Valid from: distributing documents before the effective date
  3. SharePoint document approval workflow: five real-world examples
  4. Read confirmation in SharePoint: proving acknowledgement
  5. ISO 9001 document control with SharePoint (this article)
  6. Building an integrated management system in Microsoft 365
  7. Controlled digital work instructions: from Word to the valid PDF
  8. Is SharePoint audit-proof? What a DMS must prove
  • Smarter DMS
  • Document control
  • SharePoint Online
  • ISO 9001
  • Quality management

Related articles

Is SharePoint audit-proof? What a DMS must prove
Approval record of a work instruction: for each version the reviewer, approver, validity period and number of acknowledgements

Is SharePoint audit-proof? What a DMS must prove

Audit-proof storage is not a switch in SharePoint. What the term requires, what version history and Purview do and what a DMS proves for controlled documents.

Read more
Controlled digital work instructions: from Word to the
Diagram: on the left the Word file being edited, on the right the generated PDF with cover sheet, version, validity and footer

Controlled digital work instructions: from Word to the valid PDF

How a Word file becomes a controlled work instruction: number, approval, PDF with cover sheet, a stable link at the workplace and periodic review.

Read more
Building an integrated management system in Microsoft
Diagram: process map with management, core and support processes, next to it a work instruction assigned to a process, management systems and scope

Building an integrated management system in Microsoft 365

One rulebook for quality, environment, occupational safety and information security: how process map, metadata and roles carry an IMS in SharePoint.

Read more

Questions about this topic?

We are happy to help you put this into practice in your environment.