Document Control in SharePoint for ISO, SOX, and GDPR

“We need SharePoint to be audit-ready for ISO / SOX / GDPR” usually means four different things smashed into one sentence. Ownership. Approval evidence. Retention. And sometimes proof that people actually read the policy.
SharePoint can carry a serious controlled-document program. It is not, out of the box, a complete document control system. Knowing which layer does what saves you from buying the wrong thing or building a brittle Power Automate forest you’ll regret in nine months.
Two products, two jobs (read this first)
Inside SharePoint Designs we split the problem on purpose:
Don’t confuse them. DocVault is not your acknowledgement engine. SOP Manager is not your general engineering DMS. Auditors care about both classes of evidence; the tooling shouldn’t pretend they’re identical.
What “document control” means in audit language
Strip the acronyms. Controllers and auditors typically probe:
- Is there a current approved version and can we prove it?
- Who owned it, who approved it, when?
- Are obsolete versions retained or withdrawn per policy?
- Do retention and deletion match legal/regulatory periods?
- For policies: did the right people attest?
- Who can change what?
ISO-style quality systems lean hard on (1)–(3) and often (5) for SOPs. SOX-style ITGC / financial reporting controls lean on change control, access, and retention evidence around financial-relevant docs. GDPR leans on lawful retention, minimization, and being able to find/erase personal data when required which collides with “keep forever” culture.
SharePoint participates in all of that. It doesn’t auto-complete any of it.
What SharePoint already gives you (use it)
Out of the box, treat these as foundation not the finish:
- Versioning — major/minor if you configure it; history of who changed what
- Co-authoring — real-time editing in Office files
- Microsoft Purview retention labels/policies — keep/delete/record timelines
- Sensitivity labels — confidentiality markings / protection
- Search — findability when IA isn’t a dumpster
That’s a stronger base than most file shares ever had. For how retention should be designed (paper map → labels → content types → pilot), see Purview retention for SharePoint documents.
What SharePoint does not give you natively
These gaps show up in almost every controlled-document RFP we see:
- Automatic document numbering (SOP-004 Rev C style schemes that don’t depend on filename discipline)
- Multi-stage approval with escalation (not a single “approve” button someone forgets)
- Scheduled review / pre-expiry as an operational loop, not a calendar reminder someone created once
- Native read-and-acknowledge for policies
- Controlled creation dashboard stop random “Upload” into the wrong library with no type, no owner, no template
You can approximate pieces with Power Automate, list formatting, and custom SPFx. We’ve done it. It depends on how much you enjoy owning that code when the maker leaves. Honest build-vs-buy framing: build vs buy a SharePoint DMS and SharePoint document management cost (DocVault is one-time pricing (see the product page), unlimited users, in-tenant Microsoft 365 when packaged beats DIY).
Information architecture auditors can follow
Control fails quietly when the library is a folder museum.
Rules we enforce on controlled libraries:
- Metadata over deep folders. More than three folder levels → redesign. Prefer columns and views.
- 4–8 fields per document type. Baseline: Document Type, Owner, Department, Status, Review Date.
- Term store for Department / Document Type — not free text.
- Content types bundle metadata + template + retention intent.
- Stay ahead of the 5,000-item view threshold with indexed columns; treat ~100k items/library as a split-or-justify checkpoint.
Longer treatment: metadata vs folders. Platform question: can SharePoint be a DMS?.
Permissions: the control that gets skipped
Wrong access blows SOX and ISO conversations faster than a missing metadata column.
Practical rules:
- Assign groups, not people
- Avoid item-level permissions as the default — they don’t scale and they’re invisible in day-to-day admin
- Prefer open by default inside the intended audience, restricted by exception — or separate libraries when the boundary is truly hard (HR vs everyone)
Item-level ACL spaghetti is also why Copilot surfaces the wrong draft: it grounds on content the user can access. Sprawl, bad naming, unclear current version, and folder dumps are the usual root causes — why Copilot returns the wrong document.
Mapping the three acronyms without fake certifications
We are not claiming DocVault or SharePoint Designs “certifies you” for ISO, SOX, or GDPR. Tools support a program. Auditors certify your program.
ISO-style quality / controlled documents
Focus: current approved copy, revision history, ownership, review cycles, obsolete control. SharePoint: versioning + content types + Purview + permissions. Add: numbering, multi-stage approval + escalation, scheduled review — DocVault territory for general controlled docs. If the artifact is a policy/SOP requiring attestation: SOP Manager, not DocVault.
SOX-oriented financial reporting / ITGC flavor
Focus: change control on documents that support controls, restricted access, retention of evidence, clear ownership. SharePoint: group-based permissions, retention labels, audit logs in M365. Add: controlled intake (no shadow uploads), approval trails that survive scrutiny. Retention periods: map with counsel. Example only — financial records are often discussed in ~7 year ranges as typical legal counsel planning figures; confirm for your entity. Not a DocVault guarantee.
GDPR-oriented privacy
Focus: know where personal data lives, retain only as long as lawful, respond to access/erasure where applicable, don’t treat every file as an immortal record. SharePoint: search + retention + minimization of open sharing. Process: records vs deletable personal data is a counsel call. Declaring everything a record “for safety” can fight erasure obligations. Purview records declaration is powerful — use it on purpose.
It depends on your regulator mix. A medical device ISO shop and a SaaS company with SOX-lite ITGCs should not copy-paste the same label set.
Scar: the acknowledgement we bolted on wrong
On a 2022 quality rollout we tried to fake read-and-acknowledge with a custom list + flow “to save budget.” It worked in UAT. In production, managers forwarded PDFs in email, people “acknowledged” the wrong revision, and the list fell out of sync with the document library. The auditor asked one simple question — “show me who attested to the effective version” — and the demo fell apart.
We replaced that path with a proper policy acknowledgement approach later (today we’d send that requirement to SOP Manager). The scar: don’t DIY attestation on the side of a general DMS. And don’t pretend a general DMS is an attestation product.
Migration warning for controlled estates
If you’re moving a network drive full of “controlled” folders into SharePoint by recreating the tree, you will import findability failure into an audit scope. Lift-and-shift folder clones fail. Classify, apply content types, then migrate. See moving a network drive to SharePoint. Comparisons for teams evaluating other repos: SharePoint vs M-Files, SharePoint vs Dropbox.
Putting DocVault in the right slot
When the SharePoint + Purview foundation is in place and the remaining gaps are numbering, multi-stage approval with escalation, scheduled review/pre-expiry, and controlled creation for general controlled documents that’s DocVault: in-tenant Microsoft 365, one-time (see the product page), unlimited users. Deep architecture: document management system guide.
When the requirement is policy lifecycle and read-and-acknowledge, use SOP Manager. Same SharePoint estate. Different control surface.
faqs

Venkatesh Maran
Founder and CEO of SharePoint Designs, a Microsoft ISV with 6 products live on AppSource. We build products that solve the problems Microsoft left on the table. Intranets that people actually use. Document management systems that don't fight your workflows. Knowledge platforms that surface what matters. And now, AI agents built on Microsoft Copilot that take the repetitive work off your team's plate. Every product we build gets designed around your brand, your culture, and how your teams actually work. Trusted by enterprises across 23 countries, primarily in the US and Europe, with deep expertise in SharePoint, Power Platform, Microsoft Copilot, and Microsoft 365. Over 15 years in the ecosystem and still going. Our mission is simple: make work more fun.










