SharePoint Document Control for ISO 13485 Explained (Audit-Ready Setup Guide)
SharePoint Document Control for ISO 13485 Explained
ISO 13485 document control requires that documents are reviewed, approved, version-controlled, accessible at point of use, and protected from unintended changes or obsolete use. In SharePoint, this is achieved through structured document libraries, versioning, controlled permissions, and automated approval workflows.
If your SharePoint setup allows uncontrolled editing, unclear versions, or missing approvals, your system is not compliant—regardless of how many documents you have.
This guide shows how to build document control that actually passes audits.
What ISO 13485 Document Control Actually Requires
ISO 13485 is very explicit about document control under Clause 4.2.4.
Documents must be:
- Reviewed and approved before release
- Updated and re-approved when changed
- Identifiable with revision status
- Available at point of use
- Protected from unintended use
These are not “nice to have” — they are audit-critical controls :contentReference[oaicite:0]{index=0}.
In practice, document control is one of the top 3 audit failure areas because companies underestimate how strict these requirements are.
How SharePoint Supports ISO 13485 Document Control
SharePoint can fully support ISO 13485—but only if configured correctly.
What SharePoint Does Well
- Version history tracking
- Access control (permissions)
- Workflow automation (Power Automate)
- Centralized document storage
Where Most Implementations Fail
- No enforced approval workflows
- Everyone has edit access
- Documents downloaded and shared offline
- No clear “controlled vs uncontrolled” distinction
SharePoint is not the problem. Poor configuration is.
Version Control Setup (Non-Negotiable)
Version control is the backbone of document control.
What You Must Configure
- Major versioning (e.g. v1.0, v2.0)
- Minor versioning for drafts (optional but recommended)
- Mandatory check-in/check-out
- Version comments for every change
How This Maps to ISO 13485
You must be able to demonstrate:
- What changed
- Who changed it
- When it changed
- Who approved it
If you cannot show this within seconds during an audit, you will get a finding.
Practical Rule
If your team is emailing documents or saving local copies, your version control is already broken.
Approval Workflows (Where Compliance Lives or Dies)
This is the biggest gap in most SharePoint QMS systems.
ISO Requirement
Documents must be approved before release and re-approved after changes.
SharePoint Implementation
- Use Power Automate for approval workflows
- Assign defined approvers (QA/RA or management)
- Lock document after approval
- Automatically update status (Draft → Approved)
Minimum Workflow Design
- Document created (Draft)
- Submitted for review
- Reviewer feedback (optional loop)
- Final approval
- Published as controlled document
This workflow must be enforced—not optional.
For deeper integration with CAPA and audits, see: CAPA Hub and Internal Audit Hub.
Controlled vs Uncontrolled Documents
This distinction is critical—and often ignored.
Controlled Documents
- SOPs
- Procedures
- Templates
- Forms
These must be:
- Approved
- Version-controlled
- Access-controlled
Uncontrolled Documents
- Exports (PDF copies)
- Training handouts
- External sharing copies
These must be clearly marked as “Uncontrolled if printed or downloaded.”
Audit reality: If someone is working from an outdated printed SOP, your system has failed.
How to Implement This in Practice
Here is a practical implementation framework that works in real companies:
Step 1: Define Document Types
- SOPs
- Forms
- Records
- Policies
Step 2: Build SharePoint Library
- Enable versioning
- Require approvals
- Add metadata fields (owner, version, status)
Step 3: Configure Permissions
- Read access: All users
- Edit access: Document owners
- Approval access: QA/RA
Step 4: Build Workflow
- Draft → Review → Approval → Release
Step 5: Train Users
- No offline copies
- No bypassing workflows
- Always use SharePoint as source of truth
Step 6: Validate System
ISO 13485 requires validation of software used in the QMS where applicable :contentReference[oaicite:1]{index=1}.
This means:
- Test workflows
- Test permissions
- Verify document lifecycle
Audit Expectations (What Auditors Actually Check)
Auditors do not review your system—they test it.
Expect them to:
- Pick a document and check approval history
- Check version traceability
- Verify latest version at point of use
- Look for obsolete document control
- Check if users follow the process
If your system relies on “people doing the right thing” instead of enforced controls, it will fail.
Common Mistakes to Avoid
- No approval workflow
- Too many people with edit access
- Documents shared outside SharePoint
- No clear version naming
- No distinction between draft and approved
- Obsolete documents still accessible
Most audit findings are not complex—they come from these basic failures.
Quick Document Control Checklist
- ✔ Version control enabled
- ✔ Approval workflow enforced
- ✔ Permissions defined
- ✔ Documents clearly labelled
- ✔ Obsolete documents controlled
- ✔ Users trained
Mid-Article CTA
If your document control system feels manual, inconsistent, or audit-risky, it’s usually a design issue—not a SharePoint issue.
See how we build audit-ready systems here: ISO 13485 Consulting
Final Thoughts
Document control is not about storing files—it is about controlling risk.
Weak document control leads directly to:
- Audit findings
- Process breakdowns
- Regulatory exposure
Strong document control creates:
- Consistency
- Traceability
- Audit confidence
If your SharePoint system cannot clearly demonstrate control, it is not compliant—no matter how clean it looks.
Strong CTA
If you're serious about passing ISO 13485 audits and scaling your QMS properly, your document control system needs to be built correctly from the start.
We help medical device companies design and implement SharePoint-based document control systems that actually hold up under audit pressure.
Get expert help building your document control system →
For more insights, visit SharePoint QMS Blog Hub or explore Document Control ISO 13485.