Back to Blog

Compliance

Document Control That Holds Up Under Audit

Jess Wright
Jess WrightProduct Experience and Growth Specialist
8 min read
Document Control That Holds Up Under Audit

Document control gives every site team the right version, clear ownership and a complete audit trail - without chasing folders or expired files on site.

A policy found in a shared drive is not controlled simply because it has a date in its filename. If a site manager cannot tell whether it is current, who approved it, which teams received it, or what changed from the previous version, it is a risk waiting to surface during an audit, incident or enforcement visit.

Document control turns policies, procedures, risk assessments, certificates and records into governed operational evidence. Done properly, it gives every person the right information at the right point of work - and gives the organisation a clear record of how that information was approved, issued, reviewed and replaced.

For facilities, compliance and health and safety teams, that distinction matters. A document may look organised in a folder structure while still leaving the business unable to prove control.

What document control means in practice

Document control is the process of managing a document throughout its working life. It covers creation, review, approval, publication, access, acknowledgement, revision, retention and withdrawal. The aim is not to create more administration. It is to prevent people acting on outdated instructions and to make evidence available when it is needed.

Consider a fire evacuation procedure. A controlled process identifies the document owner, approval date, version number and review deadline. It makes the current version available to relevant sites and staff. When the procedure changes, the previous version is archived or withdrawn, affected colleagues are notified, and their acknowledgement can be recorded. At any point, an auditor can see the chain of control.

Learn MoreDocuments & PoliciesA single controlled record for each policy, so the published copy is the one that counts.

Without that process, the same procedure can exist as several attachments in email inboxes, printed copies at reception and files with names such as “Fire Procedure FINAL v4”. Nobody can confidently say which one governs the site.

This is why document control belongs within daily operations, not in a separate administrative corner of the business. Policies direct work. Risk assessments shape controls. Inspection records demonstrate that checks happened. Training materials support competence. Each document is connected to people, places, tasks and legal duties.

Why shared drives stop short of document control

Shared drives are useful storage locations. They are rarely sufficient control systems for regulated operations. They rely on individuals to follow naming rules, replace old files correctly, remember review dates and distribute changes manually. That can work for a small, stable team. It becomes unreliable as sites, contractors, document volumes and regulatory obligations grow.

The pressure points are familiar. A revised asbestos register is saved centrally, but the contractor attending site receives an old copy. A risk assessment has passed its review date, yet no owner has been alerted. A policy is reissued after an incident, but there is no evidence that the affected team read it. During an audit, the compliance manager spends hours reconciling folders, emails and spreadsheets.

These failures are usually not caused by careless people. They are caused by fragmented workflows. The information exists, but ownership, status and proof are spread across systems.

A controlled environment reduces that dependence on memory. It uses defined statuses, permissions, automated reminders and a history that cannot be confused with the current document. The result is not merely cleaner filing. It is a defensible record of governance.

Build document control around accountability

Every controlled document needs an accountable owner. That person does not have to write every revision, but they are responsible for ensuring the document remains accurate, appropriate and reviewed on time. In multi-site organisations, ownership may sit centrally while local managers are responsible for implementation and acknowledgement.

The key is to separate roles clearly. Authors prepare content. Reviewers check technical or operational accuracy. Approvers authorise publication. Document owners manage the review cycle. Readers use the published version. If one person performs several roles in a small organisation, that is acceptable, provided the approval trail remains clear and proportionate to the risk.

Documents should also have a defined status. Drafts are not operational instructions. Documents under review should not be treated as approved. Superseded versions must be visibly withdrawn from normal use while retained where record-keeping rules require them.

This matters most for high-risk material: emergency arrangements, safe systems of work, contractor controls, permits, equipment procedures and site-specific risk assessments. A typo in a low-risk internal guide may be inconvenient. An obsolete control measure can contribute directly to harm.

Set review dates that reflect risk

An annual review date is common, but it should not become a substitute for judgement. Some documents need review after a change in legislation, a significant incident, a building alteration, new equipment, a change of contractor or a revised work activity. Others may require less frequent formal review if the underlying process is stable.

The practical requirement is visibility. Teams need to see what is due, what is overdue and who owns the next action. Review reminders should escalate before a document lapses, rather than appearing only after the deadline has passed.

Connect documents to the work they govern

The strongest document control systems do not treat documents as isolated files. They connect them to the physical estate, compliance requirements and people who carry out the work.

A legionella risk assessment, for example, should relate to the relevant building or water system, planned monitoring tasks, corrective actions, contractor evidence and responsible persons. If a finding changes the control scheme, the associated tasks and staff instructions should be reviewed as part of the same workflow.

That connection changes the quality of evidence. Instead of proving only that a risk assessment was stored, the organisation can show how its controls were put into practice. Inspections were completed. Defects were assigned. Training was delivered. The revised procedure was issued. The audit trail follows the work.

For frontline teams, access matters as much as governance. A document locked in a desktop filing system is of little use to a manager standing in a plant room or a contractor arriving at a remote site. Browser-based mobile access and QR codes can give authorised users a direct route to current site information, without creating uncontrolled copies.

Learn MorePremises & Asset ManagementHow sites and assets are structured so a scan opens the current information for that place.

There is a trade-off. Not every document should be accessible to every user. Personnel records, commercially sensitive information and investigation files need tighter permissions. Good control means making the right evidence easy to find while restricting material that should not be widely shared.

Make acknowledgement meaningful

Sending a policy by email does not prove understanding. It only proves that an email was sent. Where a change affects how people work, organisations need a proportionate way to demonstrate that the information reached the relevant audience.

For straightforward updates, recorded acknowledgement may be enough. For changes to a safety-critical procedure, teams may need a briefing, a competency check or refreshed training. The document control record should show what was issued, to whom, when, and what action was completed.

This is particularly valuable for multi-site operations. Central teams can publish a revised procedure once, assign it to the right roles or locations, and monitor completion without chasing separate site managers for screenshots or email confirmations. Exceptions become visible early: the people who have not acknowledged, the site that has not completed a briefing, or the contractor whose documentation has expired.

Learn MoreDistribution & ReviewsHow a revised procedure is issued to the right groups, with a record of who acknowledged it.

Prepare for the questions an auditor will ask

Auditors and investigators tend to ask simple questions that are difficult to answer when records are scattered: What was the approved procedure at the time? Who authorised it? When was it last reviewed? Who was told about the change? Can you show that the required checks followed it?

A sound document control process should answer those questions quickly. That means retaining version history, approval records, distribution details and linked operational evidence. It also means being able to retrieve information by site, document type, owner, standard or date range, rather than relying on one person who knows where everything is stored.

CalmCompliance supports this approach by bringing controlled documents together with risk assessments, inspections, training, assets, actions and audit trails. The value is practical: the evidence is assembled through normal work, rather than reconstructed under pressure.

Start with the documents that create the greatest exposure

A full clean-up of every historic folder can be tempting, but it often delays progress. Start with the documents that most directly affect safe operation and legal compliance. Prioritise those that guide frontline activity, support recurring inspections, govern contractor work or are likely to be requested during an audit.

Establish a simple document register with owners, status, review dates, locations, permissions and related obligations. Remove duplicates from active use. Set a clear rule that published documents are accessed from one controlled source, not circulated as unmanaged attachments. Then bring review, approval and acknowledgement into a repeatable workflow.

The objective is not perfect paperwork. It is controlled information that helps people do the right thing, gives managers live oversight and stands up when someone asks for proof. When a document changes, the organisation should be able to see exactly what changed in the work around it - before that change becomes a compliance gap.

Health and SafetyComplianceFacilities ManagementRisk ManagementCalmCompliancefacilitiescaremanufacturingleisureconstructionofficeseducation

Keep reading

Get the next article before everyone else

Join the weekly brief for new posts, product updates, and guides you can use on site straight away.

  • New posts
  • Product Updates
  • Practical guides
Weekly in your inbox

We care about your data. Read our privacy policy.