It was a simple question. “Where is that procedure?” Nobody expected it to be difficult. Someone assumed it was in the compliance folder. Someone else thought the quality manager had it. Another employee remembered seeing it in an email. Someone said: “I think that's the old version.” Then someone opened a shared drive. There were three files with almost identical names. One had an old revision date. Another had no approval information. A third appeared to be the current version—but nobody was completely sure. The procedure existed. Probably. The problem was that nobody could confidently answer: “Where is the current, approved procedure that our employees are supposed to follow?” That moment may seem like an administrative inconvenience. It is actually a useful test of the maturity of a compliance system. Because if finding the procedure is difficult, the organization may have a document-control problem hiding underneath its SOP library.
Having a procedure somewhere is not enough
Most companies understand that important processes should be documented. They create SOPs. They save them. They distribute them. They train employees. But documentation is only useful if people can reliably access the right document at the right time. Imagine an employee needs to perform an important activity. They should not have to ask five people which SOP to use. They should not have to search through old emails. They should not have to guess between three versions. They should not have to rely on someone's memory. The system should make the answer obvious.
The real question is not “Do we have the SOP?”
It is: “Can the person who needs it find the current SOP immediately?” That changes the way you evaluate document control. You may discover that your company has dozens—or hundreds—of procedures. But if employees cannot determine which one is current, the volume of documentation does not necessarily translate into stronger compliance. A controlled document should have a clear identity. Employees should be able to distinguish the current version from obsolete versions. The organization should know who owns it. The organization should know when it was approved or revised. And affected employees should know where to access it.
The three-version problem
This happens more often than businesses realize. An employee searches for the sanitation SOP. They find:
- Sanitation SOP Final
- Sanitation SOP Final 2
- Sanitation SOP Updated
- Sanitation SOP Revised
- Sanitation SOP 2024
- Sanitation SOP NEW
Which one is current? The filenames themselves create uncertainty. That is not necessarily a problem with the procedure's technical content. It is a problem with document control. A controlled system should not require employees to interpret filenames to determine which document governs their work.
The email attachment problem
Another common scenario: a manager updates an SOP. They email it to employees. “Please use this new version starting Monday.” Everyone receives it. Then six months later, a new employee joins. They search the shared folder. The new version is not there. The old version is. The updated version lives in someone's email. Now the company has a document that is technically current but operationally difficult to access. The procedure exists. The controlled system does not.
The “I have a copy” problem
Personal copies can create another layer of confusion. An employee downloads the SOP. A supervisor prints it. Another employee saves it to their desktop. Someone puts a copy in a production binder. Then the master version changes. Which copies are now obsolete? Who knows? This is why document control needs to distinguish between the controlled source and copies used for reference or operational purposes. The organization needs a way to prevent obsolete information from quietly becoming the version employees rely on.
The production-floor test
This is one of the simplest ways to evaluate document control. Go to the production floor. Choose an employee who regularly performs an important task. Ask: “Can you show me the procedure you use?” Do not help them. Let them find it. Watch what happens. If they immediately access the current procedure, good. If they say “I think it's in the binder,” keep watching. If they open a binder containing several versions, you have found something. If they ask a supervisor which one to use, you have found something. If they say “We don't really use the SOP—John showed me how to do it,” you have found an even larger issue.
The procedure should be available where the work happens
A document-control system should consider accessibility. The person who needs a procedure may be on the production floor, in the warehouse, in receiving, in sanitation, in a laboratory, working remotely, or at a contract manufacturing facility. The appropriate access method depends on the operation. It could be:
- Controlled electronic access
- A managed production binder
- A document-management platform
- An approved digital workstation
- Another controlled method
The important point is that the employee should be able to access the applicable current procedure without relying on informal knowledge.
The revision problem
Now imagine the SOP is easy to find. Good. But when was it last reviewed? The procedure may still be current. Or the process may have changed significantly since it was written. A mature document-control system should provide visibility into:
- Current revision
- Revision history
- Approval
- Effective date
- Document owner
- Review requirements
- Related forms
- Related training
This makes the document more than a file. It becomes a controlled component of the operating system.
The process changed. Did the procedure change?
Suppose the production team replaced a piece of equipment. The new equipment performs the same basic function. Everyone assumes the SOP is still fine. But then ask: Does the cleaning process remain the same? Does the monitoring process remain the same? Does the employee's responsibility remain the same? Does the record remain the same? Does the training remain the same? Maybe nothing needs to change. Maybe several things do. The important point is that the process change should trigger a document review rather than being ignored.
The “old procedure” problem
An obsolete procedure can be more dangerous than a missing procedure. If the document is missing, employees know they need help. If the old document is readily available, employees may confidently follow it. That creates a false sense of control. Imagine the current sanitation procedure requires one process. An old version still sits in a binder on the production floor. An employee follows the old version because that is what they found. The employee may believe they are complying. The document was wrong for the current operation. That is why obsolete documents need to be controlled.
Document control is also people control
Not in the sense of controlling employees. In the sense of controlling who is responsible for what information. Ask:
- Who owns this SOP?
- Who can revise it?
- Who approves revisions?
- Who determines who needs training?
- Who distributes the current version?
- Who removes obsolete versions?
- Who verifies that the current procedure is being used?
If those responsibilities are unclear, document control becomes informal. And informal document control eventually creates confusion.
The “who approved this?” question
Imagine someone opens an SOP. It has a title. It has instructions. But there is no clear approval information. Who authorized it? When did it become effective? Was it reviewed? Is this an official procedure or someone's working draft? That distinction matters. Employees need to know that the document they are following is part of the organization's controlled system.
Drafts should not become procedures by accident
This can happen easily. Someone creates a document titled “New Receiving Procedure – Draft.” They email it to a supervisor. The supervisor forwards it to an employee. The employee starts using it. A month later, nobody remembers whether it was ever formally approved. Now a draft has become an operational document without a controlled transition. A good document-control process separates: draft → review → approval → effective → revision → obsolete. That makes the lifecycle clear.
The procedure should connect to training
A document changes. What happens to the employees who use it? Suppose the company revises the allergen-control SOP. The document is approved. It is uploaded. Done? Not necessarily. The affected employees may need to be trained on the revised process. The training record should show what happened. The organization should know who was affected. This is where document control and training management become connected.
The procedure should connect to records
The same thing happens with forms. An SOP is revised. The required form changes. But employees continue using the old form because it is the one available at their workstation. Now the procedure says one thing. The form captures something else. This is why controlled documents cannot be managed in isolation. Related forms and records need to be considered when procedures change.
The procedure should connect to verification
Suppose management reviews a process and discovers that employees are using an outdated form. That finding should not simply be filed away. It may indicate a document-distribution problem, a training problem, a records problem, or a supervisory problem. The organization should determine the cause and take appropriate action. Verification is not just about checking whether an activity happened. It can also reveal whether the documentation system itself is functioning.
The “show me the current version” test
Choose five important procedures. Ask someone who does not manage document control: “Show me the current version of each one.” Do not tell them where to look. See what happens. If they find all five quickly, your system may be working well. If they find three. If they find two. If they ask someone else. If they find multiple versions. If they cannot determine which one is current. You have a useful diagnostic result.
The “new employee” test
Imagine someone joins the company tomorrow. They need to perform a specific food safety activity. Can their supervisor tell them “here is the current procedure”? Can the employee access it? Can they identify the associated form? Can they receive training? Can they determine who reviews their work? Can they find the current version six months later? If yes, the system is becoming institutionalized. If the answer is “We'll have John show you,” the company may still depend heavily on tribal knowledge.
The “employee on vacation” test
Another simple test: the person responsible for document control is unavailable. Can the business still:
- Find current SOPs?
- Identify obsolete documents?
- Determine which revision is active?
- Train employees?
- Process a document change?
- Retrieve records?
If not, the system may have a single point of failure. A good document-control process should not disappear when one person is out of the office.
The folder problem
A shared folder can be useful. It can also become a digital version of a messy filing cabinet. Imagine folders named GMP, Old, New, Final, Archive, Training, Forms, Drafts, Supplier, and Miscellaneous. Employees may not know where to look. The solution is not necessarily more folders. It is a clear information architecture. People should understand:
- Where do current controlled documents live?
- Where do records live?
- Where do obsolete documents live?
- Where do drafts live?
- Who has access to each area?
That structure is what makes the folder useful rather than confusing.
The paper binder problem
Paper binders can work. But they require management. If a controlled SOP is revised, someone needs to know:
- Which binders contain the old version
- Where replacement pages go
- Who removes obsolete pages
- Who verifies the update
- How employees know a revision occurred
A binder is not a document-control system by itself. It is simply a storage medium.
The digital system problem
Digital storage has its own risks. Employees may download copies, save local versions, print outdated versions, email documents, or create duplicate folders. Technology can make document control easier. But only if the organization establishes rules for access, revision, distribution, and retention. A cloud folder full of documents is not automatically a controlled document system.
The goal is not to make employees search harder
This is important. Sometimes companies respond to document-control problems by adding more rules. Employees now have to navigate five folders, three platforms, and a complicated naming convention. That is not necessarily improvement. A good system should make the correct document easier to find than the incorrect one. The employee should not need to understand document-control theory. They simply need to know: “Where do I go to get the current procedure?”
A practical document-control workflow
A useful lifecycle looks something like this:
Need identified → procedure drafted → appropriate review → approval → effective date → controlled distribution → employee training where applicable → implementation → periodic or trigger-based review → revision when necessary → obsolete version controlled → new version implemented
The exact workflow can vary. The important thing is that the document has a defined life.
The document should have an owner
Every important SOP should have someone accountable for its maintenance. That does not mean one person performs every task. The owner may coordinate:
- Review
- Revision
- Approval
- Training
- Related forms
- Implementation
- Periodic evaluation
Without ownership, documents tend to age quietly.
Not every document needs the same level of control
A useful system distinguishes between controlled SOPs, forms, records, training materials, reference documents, external documents, drafts, and obsolete documents. Not every file needs the same lifecycle. The goal is to focus control where it matters.
The procedure should reflect the current operation
Document control is not simply about finding files. It is also about accuracy. If the current SOP is easy to find but describes an obsolete process, the system still has a problem. That is why document review should connect to operational change. Ask: Does this still describe what employees actually do? If not, determine whether the process or the document needs to change.
The “walk and find” exercise
Try this with an employee. Give them a task. Then say: “Before you begin, show me the procedure you are supposed to follow.” Watch. Can they find it? Can they identify the current version? Can they locate the associated form? Can they explain the relevant steps? Can they find the record after completing the activity? This simple exercise tests the entire chain: document → employee → activity → record.
When someone asks “Where is that procedure?”—the answer should be easy
The ideal answer is not “I think it's in the shared drive.” It is not “John probably has it.” It is not “Search for ‘final.'” It is: “It is in the controlled document system, under the applicable process. This is the current approved revision.” That answer demonstrates something important. The organization knows where its knowledge lives.
When FSVPServices.com helps bring order to the compliance system
FSVPServices.com supports food companies and brand owners with compliance documentation, SOP development, implementation, training, records management, and ongoing PCQI and FSQA oversight. Depending on the organization's needs, support may include:
- Brand Owner Compliance SOP Templates Package
- cGMP Compliance Documentation and Training Bundle
- cGMP for Human Food Implementation Set-Up Services
- Corrective Action and Incident Response Management Program
- Food Handler Qualification and Training Compliance Program
- Food Safety Plan Development and Implementation
- Food Safety Plan Reanalysis and Update Service
- FSQA Compliance Management Program
- Hazard Analysis Development and Evaluation
- Monthly PCQI Oversight and End-to-End Compliance Support
- PCQI-Managed Compliance Per Product SKU
- PCQI Oversight and Verification Records Maintenance
- Preventive Control Monitoring and Management Program
- Preventive Controls Program Development
- Records Compliance Management Program
- Regulatory Compliance Setup Package for Brand Owners
- Remote PCQI Services for Corrective Action Procedures and Record Review
- Remote PCQI Services for Food Safety Plan Development and Reanalysis
- Remote PCQI Services for Hazard Analysis
- Remote PCQI Services for Monitoring Procedures and Monitoring Record Review
- Remote PCQI Services for Preventive Controls and Preventive Controls Validation
- Remote PCQI Services for Process Change Evaluation
- Remote PCQI Services for Validation Study Review
- Remote PCQI Services for Verification Procedures and Verification Record Review
- SOP Development for Manufacturing Operations
- SOP Development for Food Processing Operations and Raw Material Control
- SOP Development for Sanitation of Food-Contact and Non-Food-Contact Surfaces
- SOP Development for Warehousing and Distribution
- Training Records and Documentation Compliance Program
- Verification, Validation and Effectiveness Review Services
- USDA Organic Compliance Implementation and Certification Support Services
Some companies need SOPs developed. Others already have procedures but need better document control. Some need help connecting document revisions to training. Others need ongoing PCQI or FSQA oversight to ensure procedures, records, and operational activities remain aligned. The appropriate solution depends on the company's products, processes, employees, suppliers, manufacturers, and existing compliance structure. The objective is not to create more files. It is to make the right information available to the right person when it is needed.
A compliance system should know where its knowledge lives
The day someone asks “Where is that procedure?” is a useful test. If everyone immediately knows where to find the current version, that is a sign of a functioning document-control system. If people start searching emails, personal folders, old binders, and shared drives, the question has exposed something important. Your business may have documentation. But it may not yet have document control. And those are different things. Because the purpose of an SOP is not merely to exist. It is to guide the person performing the work. That means the procedure needs to be current, approved, accessible, understandable, implemented, connected to training and records, and replaced when it is no longer current. So the next time someone asks “Where is that procedure?” you should not have to remember. The system should know.
Free consultation
A procedure is only useful when the person who needs it can find the right one.
If your team has SOPs but employees struggle to find the current version, distinguish old documents, locate associated forms, or know which procedure actually governs their work, FSVPServices.com can help you strengthen your documentation and compliance management system. Talk with our compliance team about your SOPs, document control, training, records, food safety plans, PCQI oversight, and ongoing compliance needs.
FSVPServices.com provides compliance consulting and support. Specific regulatory requirements depend on the products, facilities, activities, and facts applicable to each business.