Clause 7
Document Control
Internal Audit
ISO 27001 Document Control Audit Guide: Version History, Approvals, Review Dates, and Published Policies
A practical guide for auditing ISO 27001 document control evidence, including version history, approvals, review dates, published policies, obsolete files, SharePoint permissions, and certification readiness.
Quick Answer
How do you perform an ISO 27001 document control audit?
An ISO 27001 document control audit checks whether ISMS documents are controlled, approved, reviewed, protected, and easy to identify.
Auditors should review the document register, version history, approval workflow, review dates, published policy library, obsolete archive, communication evidence, and SharePoint permissions.
The goal is simple. Employees should know which document is current, and auditors should see clear proof that the document is approved.
Document Control Sounds Simple Until the Audit Starts
Document control often looks simple.
The organization may have policies, procedures, templates, registers, and evidence folders.
It may also have a SharePoint site.
However, problems appear when the auditor asks direct questions.
Which version is current? Who approved it? When is the next review? Where is the published version? Who can edit it?
Practical rule: document control proves that the ISMS is governed, not just documented.
The Main Audit Question
The strongest question is not, “Do you have policies?”
A better question is:
Can the organization prove that current approved policies and procedures are controlled, reviewed, published, protected, and communicated?
ISO 27001 Document Control Audit Snapshot
| Audit Area | What to Test |
|---|---|
| Document Register | Owners, approvers, versions, review dates, status, and published links. |
| Version History | Current version, change summary, and old versions. |
| Approvals | Approval evidence linked to the current published version. |
| Review Dates | Scheduled reviews, overdue reviews, and change-triggered reviews. |
| Published Policies | Approved-only library with drafts and old files separated. |
| Permissions | Who can read, edit, approve, publish, and delete documents. |
Why Document Control Matters
Document control protects the integrity of the ISMS.
If employees use old policies, the ISMS becomes inconsistent.
If procedures are edited without approval, controls may change without oversight.
Also, if review dates are missed, documents may no longer reflect current risks.
What Strong Document Control Looks Like
A controlled document should answer basic audit questions quickly.
It should show who owns it, who approved it, which version is current, and where the official copy lives.
1. Review the Document Register
Start with the document register.
It should be the master list of controlled ISMS documents.
Audit Questions
- Does a document register exist?
- Does it include policies and procedures?
- Does it list document owners?
- Does it show current versions?
- Does it show approval and review dates?
- Does it link to the published document?
Common finding: policies exist, but the register does not include owners, approval dates, review dates, or current versions.
2. Test Version History
Version history proves that changes are traceable.
It should be easy to identify the current version and what changed.
Weak Version Evidence
Policy_Final.docx, Policy_Updated.docx, Policy_New_Final.docx, or Policy_UseThisOne.docx.
Strong Version Evidence
Version number, owner, approval date, review date, published status, and change summary.
Practical rule: version control should remove doubt, not create more copies.
Need to Clean Up ISO 27001 Document Control?
Canadian Cyber helps organizations audit ISO 27001 document control evidence, clean up policy libraries, verify approvals, test version history, review SharePoint permissions, and prepare certification-ready document registers.
We help move ISMS documents from scattered folders to controlled evidence.
3. Test Approval Evidence
Policies and procedures should be approved before release.
Approval shows that the organization authorized the document.
Audit Questions
- Who approves each policy?
- Is approval authority defined?
- Is approval recorded?
- Is approval linked to the current version?
- Did approval happen before publication?
Common finding: a policy is published as current, but approval evidence for that exact version is missing.
4. Test Review Dates
Policies and procedures should be reviewed on schedule.
They should also be reviewed when meaningful changes occur.
Review Triggers
- New system or cloud platform.
- New vendor or client requirement.
- New AI tool.
- New incident or audit finding.
- New risk treatment decision.
Practical rule: a review date is only useful if someone monitors it.
5. Test Published Policies
Published policies are the official versions employees should use.
Therefore, the published library should contain approved documents only.
Audit Questions
- Is there a published policy library?
- Are only approved documents published?
- Are drafts excluded?
- Can employees find current policies?
- Are old versions archived?
Common finding: approved and draft documents are stored in the same library.
6. Separate Drafts, Published Documents, and Obsolete Versions
Drafts should not look like approved documents.
Old versions should not be used by mistake.
Practical rule: employees should not need to guess whether a document is official.
7. Test Document Ownership
Every controlled document should have an owner.
The owner keeps the document accurate, current, and ready for review.
Audit Questions
- Does each document have an owner?
- Does the owner understand the responsibility?
- Is the owner still in the role?
- Is there a backup owner?
- Are owners notified before review dates?
Common finding: several policies have no owner or list a person who no longer performs the role.
8. Test Access Permissions
Document control depends on permissions.
Approved documents should be easy to read and difficult to change without approval.
Audit Questions
- Who can edit approved policies?
- Who can approve documents?
- Who can publish documents?
- Are permissions reviewed?
- Are external users restricted?
Common finding: too many users have edit access to approved policy libraries.
9. Test Policy Communication
A policy is not effective if employees do not know it changed.
Publishing a policy is not the same as communicating it.
| Communication Area | Evidence to Review |
|---|---|
| Policy update | Email, Teams post, communication log, or announcement. |
| Policy acknowledgment | Acknowledgment report linked to the current version. |
| Control owner update | Procedure update notice and owner response. |
10. Test External Document Control
Some external documents affect the ISMS.
These documents should be controlled when they influence risks, controls, obligations, or evidence.
Practical rule: external documents that affect the ISMS should have owners, review dates, and mappings.
Document Control Evidence Matrix
| Audit Area | Strong Evidence | Weak Evidence |
|---|---|---|
| Register | Owner, version, approval, review date, status, and link. | Incomplete spreadsheet. |
| Version History | Clear current version and change log. | Multiple final copies. |
| Approval | Workflow history tied to current version. | Verbal or missing approval. |
| Published Policies | Approved-only library. | Drafts and approved files mixed. |
| Permissions | Controlled edit and approval access. | Everyone can edit. |
Sample Document Control Finding
Weak Finding
Document control is poor.
Stronger Finding
The internal audit sampled five ISMS policies. Three policies were stored in multiple SharePoint folders with different file names. The document register did not identify the approved version, approval date, owner, or next review date for two sampled policies. Draft and published versions were also stored in the same library. As a result, employees may rely on outdated or unapproved ISMS documents.
How SharePoint Can Support Document Control
SharePoint can be a strong ISO 27001 document control platform when it is configured properly.
It can track owners, approvers, versions, review dates, published documents, drafts, obsolete files, permissions, and evidence links.
Store approved documents only.
Separate drafts from official policies.
Track owner, approver, version, and review date.
Track approval workflow history.
Protect old versions from accidental use.
Show overdue reviews and missing approvals.
How Canadian Cyber Helps
Canadian Cyber helps organizations audit ISO 27001 document control evidence and prepare clean, certification-ready policy libraries.
We help teams move from scattered documents to controlled, approved, reviewed, and published ISMS documentation.
Our support includes document register cleanup, policy approval review, version history review, review date tracking, SharePoint ISMS document control, obsolete archive setup, permissions review, communication evidence review, corrective action tracking, and certification readiness reporting.
Senior Advisory Support
Canadian Cyber also provides senior advisory support for ISO 27001 internal audits, Clause 7 documented information reviews, SharePoint ISMS dashboards, corrective action tracking, management review preparation, and vCISO guidance.
Frequently Asked Questions
What is document control in ISO 27001?
Document control means managing ISMS documents so current approved versions are identifiable, protected, reviewed, communicated, retained, and available where needed.
What evidence proves document control?
Strong evidence includes a document register, version history, approval workflow, review dates, published policy library, obsolete archive, communication records, and controlled SharePoint permissions.
What is a common document control audit finding?
A common finding is that multiple versions of the same policy exist in different folders, and the organization cannot prove which version is approved and current.
Should old policy versions be deleted?
Old versions do not always need to be deleted. However, they should be archived, restricted, and clearly marked obsolete.
Can SharePoint help with ISO 27001 document control?
Yes. SharePoint can support version history, approvals, metadata, published libraries, obsolete archives, permissions, review reminders, and policy acknowledgment evidence.
Can Canadian Cyber help audit document control?
Yes. Canadian Cyber helps organizations review ISO 27001 document control, clean up SharePoint libraries, verify approvals, build document registers, and prepare for certification readiness.
Takeaway
Document control is not just about storing files.
It proves control over the information that runs the ISMS.
A strong ISO 27001 document control audit should test version history, approvals, owners, review dates, published policies, draft separation, obsolete archives, permissions, communication, external documents, and SharePoint structure.
For certification readiness, the answer to “Which version is current?” should already be clear.
Make Your ISO 27001 Documents Audit-Ready
Canadian Cyber can help your organization review document control evidence before an ISO 27001 internal audit or certification audit.
We support ISO 27001 document control audits, Clause 7 documented information reviews, policy approval testing, version history review, SharePoint ISMS library setup, corrective action tracking, management review preparation, vCISO support, SOC 2 readiness alignment, ISO 42001, ISO 27017, ISO 27018, and cybersecurity assessments.
Stay Connected With Canadian Cyber
Follow Canadian Cyber for practical guidance on ISO 27001 internal audits, document control, version history, policy approvals, review dates, published policies, certification readiness, SharePoint ISMS, corrective actions, SOC 2 readiness, AI governance, vCISO services, ISO 42001, ISO 27017, ISO 27018, and cybersecurity maturity.
