Regulatory
Document Control for ISO 9001 and 27001
Both standards require documented information to be approved before issue, available where needed, controlled for version and retention, and protected from unintended use when obsolete. One library with two policy branches satisfies both, and is considerably cheaper to operate than two.
Document Control for ISO 9001 and 27001
ISO 9001 and ISO 27001 ask for the same thing in different vocabulary. Both require documented information to be identified, approved for suitability before issue, available where it is needed, protected, and controlled for distribution, version and retention — and both require obsolete versions to be prevented from unintended use.
Organisations certified to both frequently run two document systems, which doubles the maintenance and halves the attention each receives. This guide sets out how to run one.
What the clauses actually require
ISO 9001 clause 7.5.3 and the corresponding ISO 27001 clause 7.5 overlap almost entirely. Between them they call for:
Approval before issue, by someone with authority, recorded against a specific version. Version identification, so a reader can tell which document applies. Availability at the point of use. Protection against loss and unauthorised change. Controlled distribution, so you know who received each issue. Retention and disposal on a defined basis. And prevention of the unintended use of obsolete documented information.
That last requirement is the one a shared drive cannot satisfy, and it is the one worth designing for first.
One library, two policy branches
The practical structure is a single controlled library organised by document tier, with the information security policy set as one branch and the quality management system as another. Procedures, work instructions, forms and records sit in the same tiers regardless of which standard they serve, because the control requirements are identical.
One document control procedure covers both. One approval workflow pattern covers both. One retention framework covers both. What differs is the content and the evidence.
What each standard adds
ISO 9001 emphasises the operational document set: procedures, work instructions and the records they produce. Its distinctive requirement is that documents at the point of work are current, which is why watermarking and unambiguous current-version marking matter more in a manufacturing or laboratory context than in an office one.
ISO 27001 adds a document set about the controls themselves. The statement of applicability lists which Annex A controls apply and why; the risk treatment plan justifies them; the policy set implements them. Those three must agree, and an inconsistency between them is the most common major non-conformity in a first certification audit.
It also adds evidence with a period attached. A surveillance audit asks whether a control operated throughout the year, not whether it operates today — so the evidence that a control ran is its own record class with its own retention, distinct from the policy describing the control.
The metadata that makes both auditable
Eight fields, and the last three are the ones organisations most often omit.
Document number and revision. Document tier, which determines approval authority. Process or document owner, by name. Approver and approval date, recorded by the system rather than typed into a footer. Effective date, which answers "which version was in force when this record was made". Next review date. Whether training or acknowledgement is required. And, for ISO 27001, the Annex A control reference plus the audit period the evidence belongs to.
Those last two turn "show me that this control operated during this period" from a hunt into a two-clause filter, which materially changes how a surveillance audit feels.
What auditors sample
In our experience, four questions, and all four are metadata questions when the system is configured properly.
Which version of this procedure was in force on a stated date? Who approved it, and when? Were the people it applies to trained on, or acknowledged, that specific version? Has its review date passed?
The fourth is the most commonly failed, and it fails systemically rather than individually: an auditor samples five documents, finds three past their review date, and raises a finding about the control rather than about the documents. That is a more expensive finding to close.
Approval before issue, in practice
The workflow that satisfies both standards has four stages. A change is raised with a recorded reason — Annex 11 requires the reason explicitly and ISO 9001 auditors increasingly expect it. Reviewers are determined by document tier. Approval locks the version, sets an effective date and marks the previous version superseded. And where training is required, the revision does not become effective until it is recorded.
That last step is what closes the gap between a document being approved and the people using it knowing about it, which is where most quality findings actually originate.
Retention of superseded versions
Retain them for at least as long as the records produced under them. The question in any investigation is which revision was effective at the time, and a superseded revision that has been deleted makes that question unanswerable.
This is worth stating explicitly in the document control procedure, because "we deleted old versions to reduce clutter" is a finding rather than an explanation.
Two practices that pay for themselves
Tag every ISO 27001 document and every piece of control evidence with the Annex A reference it supports. It takes seconds per document and turns the audit into filtering.
And build a report of documents past their review date. It is the single most effective preventive control available here, because it converts the most common non-conformity into a routine task.
FAQ
Questions this raises
Do we need separate systems for ISO 9001 and ISO 27001?
No, and separate systems make both harder. The control discipline is identical; only the document set differs. Organisations certified to both usually run one library with separate policy branches and one document control procedure.
What does an auditor actually sample?
Typically: which version was in force on a stated date, who approved it and when, whether the people it applies to were trained or acknowledged it, and whether its review date has passed. All four are metadata questions if the system is configured properly.
Is a document control procedure still required?
Yes. The system implements controls; the procedure describes them, names the roles and states review frequencies. An auditor will ask for both, and a procedure describing what the system actually does is far easier to sustain than an aspirational one.
What is the most common non-conformity?
Overdue review dates, followed by inconsistency between the statement of applicability, the risk treatment plan and the policy set. Both are findings about the control operating rather than about content.
About the author
Written and reviewed by the DocumentMS product and compliance team.
Last reviewed: 27 August 2026