Document control for a quality system that survives the audit.
A certified management system (ISO 9001 and the like) lives on controlled documents: procedures, work instructions, forms, with signed revisions and tracked read-acknowledgement. Shared folders hold up until the audit arrives. Here is what it takes so you are not caught out.
What a controlled document really requires
- An identifiable current edition: the reader must know they are looking at the latest, not an old copy.
- Read-acknowledgement tied to the person and the specific revision: a signature that holds in audit, not a generic «seen».
- Version history intact: who approved what, when and with what meaning.
- An explicit lifecycle (draft, review, in force, withdrawn), not the implicit «it is in the right folder».
The leap that matters: from folder to linkage
The value is not storing documents, it is linking them to the requirements they must satisfy.
- Link each document to the standard requirements it covers, so the compliance matrix is read, not rebuilt.
- See the gaps: which requirements have no document covering them, before the auditor finds them.
- Handle standard editions as entities: when ISO 9001:2026 lands, 2015 stays valid for those who have not transitioned.
- On a new edition, put people back into read-acknowledgement: they re-read and re-sign what changed.
Fit it to your sector without rebuilding
Pharma quality, an engineering firm and a generic DMS do not share the same states or metadata.
- Declarative domain profiles: metadata, states and lifecycle change per sector without duplicating code.
- On-premise when documents must not leave: healthcare, defence, public tenders.
- Built on open standards (Alfresco), data in your database: no lock-in, clear exit.
Preparing for a certification or audit and the documentation is still in shared folders? Let us look at how to bring it under control before the visit.
Let’s talkPage updated 23 August 2026.
