Evidence
Document control without a document management project
The clause sounds like it demands enterprise document management. It demands considerably less than that, and organisations routinely over-build it.
Facts checked — 2026-09-11
What does document control actually require?
Documented information needs to be identifiable, reviewed and approved, version-controlled, available where it is needed, and protected from unintended changes. A wiki with page history and defined owners satisfies all of that; so does a repository with pull requests.
What fails is ambiguity about which copy is current. Three versions of the access control policy in three places — one in the wiki, one in a shared drive, one attached to an old email — is the finding, and it is a filing problem rather than a tooling one.
The bottom line
Pick one home for the current version and delete the copies. Most document-control findings are duplicates, not missing controls.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
Related insights
Evidence
Running an internal audit that is worth the day it costs
Its job is to find things before the external auditor does, not to pass.
Evidence
Corrective action is not the same as fixing it
A fix addresses the instance. Corrective action addresses why it happened.
Evidence
Evidence that collects itself
If producing evidence is a separate task, it will be skipped in a busy quarter.