If your quality system runs on SharePoint document control, you’re in good company — it’s one of the most common ways small and mid-sized companies manage controlled documents, largely because it’s already bundled with Microsoft 365. SharePoint is a capable, familiar file platform. The trouble starts when you assume that storing controlled documents is the same as controlling them for ISO 9001 or ISO 13485. It isn’t — and it’s usually an auditor, not your team, who points out the difference.
This is a fair look at what SharePoint genuinely does well for document control, where it quietly falls short of what the standards require, exactly what auditors tend to flag, and how to tell when you’ve outgrown it.
On this page
What SharePoint does well
Let’s give credit where it’s due. For document management, SharePoint is legitimately good:
- Central storage and permissions. One place for your documents, with access control by user or group.
- Version history. It keeps prior versions and shows who changed what.
- Familiar and included. Your team already knows it, and it comes with your Microsoft 365 subscription — no new license to justify.
- Co-authoring and search. Real-time editing and decent search across content.
For a very small, low-risk operation that just needs organized files, that can be enough. The problems appear the moment you’re certified — or getting there — and control has to be provable.
Where SharePoint falls short for ISO document control
ISO document control (Clause 7.5 in 9001, 4.2.4/4.2.5 in 13485) asks for more than storage with version history. Here’s where a stock SharePoint setup leaves gaps:
- Formal, controlled approval before release. ISO wants documents reviewed and approved for suitability before use, through a defined workflow. SharePoint’s built-in approval is basic and easy to bypass — nothing stops someone editing and “publishing” a controlled document without the right sign-offs.
- Compliant electronic signatures. If you’re regulated, approvals need to meet 21 CFR Part 11 — attributable, permanently recorded, with the meaning of the signature captured. SharePoint’s approvals are not Part 11 e-signatures out of the box.
- Obsolete-document control. SharePoint keeps old versions, but it doesn’t actively remove obsolete revisions from use or make the “current” one unmistakable. Someone opening last year’s work instruction from a search result is exactly the scenario ISO wants prevented.
- Training tied to the release. This is the big one. When a procedure changes, the standard expects the people who use it to be trained on the current revision — and you to prove it. SharePoint can’t assign a read-and-acknowledge to a specific revision or show you who’s outstanding.
- An audit-ready trail. SharePoint has version history, but assembling it into the clean, exportable evidence an auditor asks for — who created, reviewed, approved, released, and retired a document — is a manual scramble.
- Controlled distribution. Proving the right people have the current controlled copy (and only that) is assumed, not enforced.
None of these are impossible in SharePoint — but closing them means heavy customization (workflows, Power Automate flows, third-party add-ons, lists to track training) plus someone to build and maintain it. Many firms discover they’ve quietly built a fragile, one-person-dependent QMS on top of a file platform.
What ISO auditors actually flag
On a SharePoint-based system, the findings tend to cluster in predictable places:
- A superseded revision still in circulation — because obsolete control wasn’t enforced.
- No evidence of formal approval for a released document, or approvals that don’t meet Part 11 in a regulated context.
- Training gaps — people working to a procedure with no record they’ve read the current revision.
- Incomplete change control — a document changed without a documented, approved change.
- Slow, manual evidence — the “prove it” moment turns into a hunt through version histories and emails.
The pattern is consistent: the documents are fine; the controls and evidence around them are what fall short.
Not sure whether your SharePoint setup would survive an audit? Book a 20-minute walkthrough →
When SharePoint is “enough” — and when you’ve outgrown it
Honest guidance, not a sales pitch:
- SharePoint may be enough if you’re very small, not yet certified, low-risk, and your document set is tiny — and you accept the manual effort of keeping control provable.
- You’ve likely outgrown it if you’re certified (or pursuing it), regulated (ISO 13485 / FDA), growing, or if audit prep has become a recurring fire drill. At that point the customization needed to make SharePoint compliant costs more — in time, fragility, and risk — than a purpose-built system.
The tell is usually the fire drill. If every audit means days of assembling evidence and chasing down who’s trained on what, SharePoint has already stopped scaling with you.
The step up: purpose-built document control
Moving off SharePoint doesn’t mean an enterprise deployment. What it means is document control that does — automatically, without custom-building it — what SharePoint makes you bolt on:
- Controlled review and release with 21 CFR Part 11 electronic signatures.
- Obsolete-document control that pulls superseded revisions from use automatically.
- Training tied to each release, so “prove they’re trained on the current version” is a one-click answer.
- A complete, exportable audit trail — your evidence, generated as you work.
- Formal change control, not an in-place edit.
That’s the profile TLM was built for: everything ISO 9001 and 13485 document control requires, Part 11-ready, sized and priced for a small or mid-sized team — with onboarding that gets your people actually using it, so you stay audit-ready between inspections instead of rebuilding evidence before each one.
See document control that’s built to be controlled →
Frequently asked questions
Can you use SharePoint for document control?
You can use SharePoint to store and version controlled documents, and very small, low-risk firms sometimes do. But meeting ISO document control requirements — formal approval before release, obsolete-document control, training tied to releases, and audit-ready evidence — requires heavy customization SharePoint doesn’t provide out of the box.
Is SharePoint ISO 9001 compliant?
SharePoint itself isn’t “ISO 9001 compliant” or non-compliant — compliance depends on your controls. A stock SharePoint setup leaves gaps around controlled approval, obsolete-document control, training records, and provable audit trails. Closing those gaps means significant custom configuration and ongoing maintenance.
Does SharePoint meet 21 CFR Part 11?
Not out of the box. SharePoint’s built-in approvals are not Part 11-compliant electronic signatures (attributable, permanent, with signature meaning captured). Regulated medical device and life-science companies generally need a purpose-built system for Part 11 e-signatures and audit trails.
SharePoint vs. document control software — what’s the difference?
SharePoint is a file-management platform: storage, versioning, permissions. Document control software adds governance — controlled approval workflows, e-signatures, obsolete-document control, training tied to releases, and audit trails — so documents meet ISO and regulatory requirements without you building the controls yourself.
When should we move off SharePoint for document control?
When control has to be provable: once you’re certified or pursuing certification, working in a regulated space, growing, or spending days on audit prep. At that point the cost and fragility of customizing SharePoint typically outweighs a right-sized, purpose-built system.
Wondering how your SharePoint-based document control would hold up in an audit? Book a short walkthrough — bring a real procedure and we’ll show you the difference between storing a controlled document and actually controlling it.