What's the best document control software for ISO 9001 & ISO 13485?

best document control software for ISO 9001 and ISO 13485There’s plenty of document management and file-sharing software available on the market, but not all of it is able to control documents in a way required by quality standards like ISO 9001 and ISO 13485. What does the best document control software look like? How can it help your business fulfill its regulatory obligations while meeting your commercial needs?

What is document control?

Document controls are the processes you impose to ensure that the highest level of authentication, trackabiltiy and change protections apply to your organisation’s documentation. Document controls are referred to in the ISO 9001 and ISO 13485 standards as the procedures by which your business should:

  • Approve documents
  • Review, update and re-approve documents when required
  • Identify changes made and current document revision status
  • Make documents available at points of use
  • Ensure documents remain legible and readily identifiable
  • Identify external documents and control their distribution
  • Prevent obsolete documents from being used accidentally
  • Apply suitable identification if obsolete documents are retained

Being able to control files in this way means that your organisation has complete power over who can create, approve, discover, change and delete certain kinds of documents within your system. It ensures you always know which is the most up to date and approved version of each document in a QMS (Quality Management System). It allows you to distribute documents for access by specific teams or individuals while keeping them inaccessible to others.

Document control ensures the quality of end products

But document control is not control for its own sake.

Control over documentation is, ultimately, the way the quality of end products is maintained and tracked by your organisation. It ensures:

  • Consistency in process and procedures resulting in products of uniform and required quality
  • Certainty around the latest approved version of requirements, specifications and designs
  • Accountability and traceability around all your decision-making processes in product design, development and issue resolution
  • Complete, transparent access for auditors to ensure quality processes have been adhered to

But, of course, not every business requires this level of document control to operate successfully. And for some, managing this granular level of secure access, tracking, indexing and archiving would be a sledgehammer to crack a nut.

A closer look at Document Control for ISO 9001


Where does your software sit within the document control pyramid?

It’s true that when it comes to document control - not every file storage solution is created equal.

Think of it like a pyramid - a hierarchy of information management.:

Document control Pyramid

Simple file sharing

At the bottom of the hierarchy of solutions are the low-cost or no-cost, frictionless file-sharing tools such as the basic versions of Google Docs, Box or Dropbox. They are designed specifically to make life easier for teams who need to collaborate rapidly across platforms without a strict and enduring record of what has gone before.

Document management

Enterprise document management solutions can offer more sophisticated opportunities for version control, managed collaboration and better archiving. You might have more power to allow or deny access to documents by named individuals with more granularity around sharing/editing permissions. There may be better indexing and larger storage potential. Simple workflows can be achieved to automate some processes, though frequently with limitations. Users can manage documentation more effectively, but they ultimately don’t have the extended functionality required to properly oversee the 5 stages of document control: creation, publication, change control, retrieval and managed obsolescence.

Document Control

At the summit of the triangle are the ‘heavy duty’ document control solutions - software that is designed to answer the demands for authentication, scrutiny and traceability required by ISO standards or regulators like the FDA. The workflows available at this level ensure the most robust approval processes can be built out to support, for example, multiple sign off and phase gating processes to impose design controls.

In these systems there is one master version of each document. There is an audit trail and a full activity history. This goes beyond mere event logs; it will be possible to easily view the activity history around a document when it was in a previous version. These versions will be retained for as long as the law requires.

Electronic signatures are also built into the system itself, ensuring the highest level of authentication, and an indelible record of the ‘meaning’ of each signature applied to each document.

Only with this kind of functionality can you meet the kind of change control requirements demanded by the ISO standards, the FDA and others:

“Each manufacturer shall maintain records of changes to documents. Change records shall include a description of the change, identification of the affected documents, the signature of the approving individual(s), the approval date, and when the change becomes effective.”

FDA, QSR 820

Is all Document Control Software created equal?


Document control software built to meet the requirements of the most demanding regulation (like ISO 13485 for medical device developers) can often be rigid and unbending in the way it functions. And in many ways that’s the point, to ensure documents are treated consistently and that quality processes cannot be circumvented or activity falsified.

But the document control software we encounter often asks you to manage the flow of documentation in ways the supplier demands rather than what the regulation actually requires.

Why not just use Google Drive as a document management system?

When you pick document control software you need to be sure that it’s not going to condemn you to needlessly rework your existing processes and procedures to fit in with a software developer’s templates. Instead, you should be able to use the robust document control tools they offer to fulfil the regulations and meet your business needs.

Too little or too much? 

When start-ups and SMEs trying to break into regulated industries are faced with options for formalising their document and quality management systems, it’s easy for them to end up doing too little or too much.

Some opt to use file sharing platforms stitched together with email and PM tools to create improvised workflows and control their documents. This kind of solution can be complex to administer and, ultimately, unequal to the task.

Others choose the expensive, ‘best in breed’ options used by large pharma and med tech giants to ensure they can take the most robust approach to their regulatory challenges. These businesses can risk getting bogged down by complexity, imprisoned by overly rigid systems and burdened with a costly interface that no one in the company likes and no one can really use.

Everyone’s needs are different, of course, but the best document control software is the application that gives you the level of control you need to meet regulatory obligations while running your business in the most logical and cost effective way.

Want to be a successful Medical Device Developer


Tags: medical device development

Joe Byrne

Written by Joe Byrne

Joe Byrne is the CEO of Cognidox. With a career spanning medical device start-ups and fortune 500 companies, Joe has over 25 years of experience in the medical device and high-tech product development industries. With extensive experience in scaling businesses, process improvement, quality, medical devices and product development, Joe is a regular contributor to the Cognidox DMS Insights blog where he shares expertise on scaling and streamlining the entire product development cycle, empowering enterprises to achieve governance, compliance, and rigour.

Related Posts

Medical Device Technical File requirements: what you need to know

What is the medical device technical file? What should it contain and how should it be structured? ...

What is post-market surveillance for medical devices?

The PIP scandal, in which thousands of women were injured by faulty breast implants over a period ...

MD, IVD, AIMD or SaMD? What is a medical device?

Question for you: what exactly is a medical device? Is the product you are developing a Medical ...