What "controlled document" actually means for a lab SOP
6 min read · Updated 22 August 2026
"Is that SOP controlled?" is a question that means something quite specific, and the honest answer in most research labs is no. A folder of Word files with names like protocol_v3_FINAL_jl_edit.docx is a document store, not a document control system. The difference isn't bureaucracy — it's whether anyone can prove which version was in force on a given day, and who had read it.
The five properties that make a document controlled
Strip away the quality-management vocabulary and document control comes down to five things being true at once. A document is controlled when it has:
- Identity — a unique reference that never changes, so the document can be cited unambiguously.
- Version — a number that increments, with a record of what changed and why.
- Approval — someone with the authority to approve it did so, before it was issued, and that is recorded with a date.
- Availability — the current version is the one people actually reach at the point of use, without having to work out whether it is current.
- Retirement — superseded versions are removed from use but kept, so the record of what was in force in 2024 still exists in 2027.
The last one is the one shared drives fail hardest. Deleting the old version destroys the audit trail; leaving it in the folder means somebody will open it by accident. You need both, which is why "just keep a folder" cannot work.
Why the filename is not a version
Version-in-filename fails for a reason that has nothing to do with discipline. A filename is metadata anyone can change and nobody can audit. It survives being copied, emailed, printed and pinned to a wall, at which point the printed page on the wall is indistinguishable from a current one.
A controlled version is a property of the document record, not of its name — which is what makes it possible to answer "what did this say in March?" without archaeology.
Read-and-sign is the part that pays for itself
Approving an SOP proves it was authorised. It does not prove anyone read it. In a lab with rotating students and postdocs, the second question is the one that actually comes up — after an incident, during an audit, at a competency review.
A read-and-sign record makes that answerable: this named person acknowledged this specific version on this date. The version matters. An acknowledgement of version 2 is not evidence about version 4, and a system that carries the signature forward across revisions is quietly telling you something untrue.
It also changes behaviour in a useful way. When a revision resets the acknowledgements, the author has to think about whether the change genuinely warrants re-reading — which is a healthier question than whether the edit is worth the version bump.
Review dates, and the honest way to handle them
Most document control regimes expect a periodic review — an explicit statement that the document has been looked at and is still correct. A review is not the same as a revision: "reviewed, no change required" is a legitimate and useful outcome, provided it is recorded.
Two practical points. First, a review date is only useful if it is visible somewhere people look; a date buried in a header is a date nobody sees. Second, a standing list of what is coming up for review should not be filtered by whatever the reader happens to be searching for — the point of that list is to show what is about to be chased, including the documents nobody was thinking about.
Whose branding goes on it
A controlled document belongs to the institution that issued it, and it should carry the institution's identity and its own document-control block — reference, version, owner, approver, effective date, review date, revision history. It should not carry a software vendor's logo.
This matters more than it sounds. The document may end up in an inspection, in a tender, or in a contract dispute, and it needs to read as the institution's own record rather than as an output of whatever tool happened to produce it.
Getting there without a quality department
Research labs rarely have a document controller, and a process that assumes one will not survive contact with a Tuesday. What does survive is a system where the control properties are structural rather than voluntary — where you cannot edit a published version in place, where issuing a new version supersedes the old one automatically, and where assigning a reader creates the record that they read it.
The test of whether you have got there is simple, and worth applying to any approach: can you produce, for a named procedure, the exact text that was in force on a date two years ago, together with the list of people who had acknowledged it? If the answer involves opening a folder and squinting at filenames, the documents are stored, not controlled.
Key takeaways
- Identity, version, approval, availability and retirement — all five, or it isn't controlled.
- A filename is not a version, and a printed copy has no version at all.
- Approval proves authorisation; read-and-sign proves readership, per version.
- "Reviewed, no change" is a valid outcome — record it.
- Controlled documents carry the institution's identity, not a vendor's.