Building a Regulatory Document Control System That Survives an Audit
Core principles of document control for regulated companies, version control, approval workflows, distribution control, obsolete document management, what audit
Every regulatory audit begins with documents. Before an inspector examines your stability data or reviews your pharmacovigilance files, they will ask to see your document control system. How quickly can you retrieve the current version of your Site Master File? Can you prove who approved your latest SOP revision, and when? If these questions make you uncomfortable, your document control system needs attention - and it needs it before the auditor arrives.
Document control is not glamorous work, but it is foundational. Whether you operate under SAHPRA's requirements, ISO 13485, or ICH Q10, the expectation is the same: you must demonstrate that the right people are working from the right documents at the right time, and that you can prove it.
The core principles that auditors expect
A defensible document control system rests on five pillars: version control, approval workflows, distribution control, obsolete document management, and retrieval. Each of these must be not only functional but demonstrable. An auditor does not care that you "usually" follow the process - they care that you can show evidence of it every single time.
Version control means every document carries a unique identifier and version number, with a clear revision history. When SOP-QA-012 moves from version 3 to version 4, the system must record what changed, who made the change, and the effective date. Auditors routinely pull a document at random and ask to see its full revision trail. If you cannot produce that trail in minutes, you have a finding waiting to happen.
Approval workflows require documented evidence that the right people reviewed and authorised each document before it became effective. "The right people" is context-dependent - a manufacturing SOP might require sign-off from production, QA, and the Responsible Pharmacist, while a regulatory submission document might need the RA manager and the Qualified Person. What matters is that your system enforces these approvals consistently and records them with timestamps and signatures (electronic or wet ink).
Distribution control: knowing who has what
One of the most common audit observations relates to uncontrolled copies. If a printed SOP sits on a production floor and it is two versions behind the current approved document, you have a serious compliance gap. Distribution control means you know exactly where every controlled copy resides, and you have a mechanism to replace outdated copies when new versions take effect.
For small-to-medium regulatory teams, this is where electronic document management systems (eDMS) earn their value. Even a well-structured SharePoint environment with restricted permissions and version tracking is vastly superior to a filing cabinet and a distribution log maintained in Excel. The key is that your chosen tool enforces read-only access for end users, prevents unauthorised editing, and logs every access event.
If you do maintain paper-based controlled copies - and many manufacturing sites still do - your distribution log must capture the copy number, the holder, the issue date, and confirmation that the previous version was retrieved and destroyed.
Managing obsolete documents without creating risk
Retiring a document is not the same as deleting it. Regulatory frameworks universally require that you retain obsolete documents for a defined period, typically aligned with your record retention policy. The critical control is ensuring obsolete documents are clearly marked and physically or electronically separated from current documents so that no one accidentally works from a superseded version.
A practical approach is to maintain an "obsolete" archive - a locked folder in your eDMS or a sealed filing section - with restricted access. The document index, which should be a living register of every controlled document in your system, must reflect the current status of each item: active, under review, or obsolete.
What auditors look for first
Experienced auditors have a short list of early indicators that signal whether a document control system is trustworthy. They will ask for your master document index and check whether it is current. They will select two or three documents at random and ask to see the approved originals alongside any distributed copies. They will look at your last three or four document revisions and check whether the approval records are complete and the effective dates are logical.
They also look for gaps between your SOP on document control and your actual practice. If your SOP says documents must be reviewed every two years, but your register shows documents that have not been reviewed in four, that discrepancy becomes a finding - often a major one.
Practical steps for smaller teams
You do not need a six-figure eDMS to run effective document control. What you need is discipline and consistency. Start with a clean master index. Define your numbering convention and never deviate from it. Build simple but enforced approval templates. Conduct periodic self-audits of your document system - quarterly reviews of your index against actual documents will catch drift before an inspector does.
Train every person who touches a controlled document, not just QA staff. Document control failures most often occur at the edges, where someone in production prints "just a quick copy" or a regulatory associate saves a draft to their desktop.
How Avidara can help
Avidara's Document Review service helps regulated companies identify gaps in their controlled documents - from SOPs and quality manuals to regulatory dossiers - before auditors do. If you want a structured, expert assessment of your documentation against current SAHPRA and international standards, book a review.
Book a review
Ready to close your compliance gaps?
Two ways to engage - pick the one that fits your situation, or tell us what you need and we will recommend the right approach.
No commitment required. We will confirm scope and turnaround before any work begins.