Compensating for SharePoint Document Control Deficiencies

  • by gcarroll@fasttrackaust.com (Greg Carroll)
  • 05 Apr, 2017
The benefits of SharePoint as a content management system and information portal tool are indisputable.  With great search functionality and user definable portal pages SharePoint is now the leading Content Management solution chosen by most IT departments. But what if your business demands strict document controls protocols, not just because it’s good practice but life depends on it?  Unfortunately there is generally a poor appreciation by IT departments of the importance of document control in mission critical business. 

The SharePoint Threat

Although SharePoint does have basic document control features and workflows, where life or operations depend on accurate up-to-date documentation at the coalface, the loose approach of SharePoint can prove disastrous.  Delays in updating documents due to senior management involvement, hold ups in revision/approval processes, lack of awareness of effects/interrelationships between documents and processes, aversion to the ubiquitous search requirements and lack of troubleshooting assistance, turn SharePoint into a deceptive threat of non-compliance with all its ramifications. 

Best of Both Worlds

Early in our extensive experience working with the mission critical fields of Defence, infectious diseases control, hospitals, mining, and biosecurity border control, we identified the need to value-add to SharePoint not just compete with it.  We therefore looked to fill the document control deficiencies of SharePoint by adding a formal document control framework onto the front-end of SharePoint.  This left a user-friendly portal for delivering content to the general population, while protected the organisation’s regulatory compliance by providing a comprehensive document control framework.

With FastTrack we decided to manage the development and revision of documents under a strict document control regime but then publishes them through to SharePoint for use. Here are the key deficiencies we identified in using SharePoint for Document Control in strict regulatory compliant environments, and what we have done to compensate.

Separating edit and approval rights

Combined with keeping separate draft and published documents, this allows updating of document by those at the coalface while enforcing a formal revisions and approval process prior to publication.  This releases senior management from onerous editing duties to just verifying changes and clicking approval, thereby streamline the change and performance proficiency.

Cross referencing documents to legislation and regulatory clauses

In heavy regulated fields understanding and demonstrating regulatory compliance is critical to an organisation being able to even operate. Through the vagaries of small changes over time, non-compliance can creep in inadvertently if not managed.

Visual mapping of document interrelationships

In addition to explaining regulatory compliance, visual mapping also engenders understanding in staff of both the place in the process and their effect on other areas.  Useful in audit and when obsoleting documents it also easily demonstrates to external auditors/assessor the full capability of your compliance management system.

Traffic Lighting of sticking point in revision cycle

An inevitable part of document revisions is that changes get bogged down in the revision process due to key people being away or busy.  Whether the change rectifies a failing in the process, or improves efficiency, the delay can prove costly in more ways than one.  Peer awareness generated by highlighting those cases with traffic lights leads to faster resolution.

Auto reminders and escalation of overdue/outstanding reviews and approvals

We are all torn by demands on our time. Reminders and escalation of those items that fall between the cracks, including hyperlinks to complete the task, expedite hold-ups and improve close out times.

Auto hyperlinking of document references within document content

Documentation is a bureaucratic waste of time if not usable for its intended purpose.  Operational staff invariably need to refer to related information within their current train of thought while reading a document which is not consistent with having to exit and search for the related information.  Automating the linking within documents improves operational usage as documents match the way they work.

Publishing in PDF format while editing in Word/Excel format

Achieving the obvious benefits of making documents available as PDF is commonly done at the expense of ease of modifying content.  By keeping source document in desktop formats allows for ease of updating by those at the coalface without the need of licensing a pdf tool to the whole organisation.

Enforcement of a consistent revision marking program

Reading the whole document when a change is made is not only time consuming but acts as deterrent to senior reviewers.  By automatically enforcing the practice, senior reviewers can by confident that no surreptitious changes have been included.

Inserting current version and issue date identification into document content

Consistency and confidence by automating document control practices is what allows delegation and wider distribution of managing documents which is not only more efficient and productive but develops greater staff involvement and thereby greater buy-in to the management systems.

Generating, scheduling and tracking Training requirements for revisions

In safety critical operations, changes in process can threaten life and limb, so it’s common for changes to require staff training prior to release.  FastTrack’s capability of generating training requirements for selected documents streamlines the process thereby expediting releases.

Managing targeted lists of relevant document per role/dept/topic

Talk to operational staff and you’ll find the need for ubiquitous searches to find critical information in times of stress, is a major issue.  The workaround is for individuals to set up their own subscriptions which is not very productive, if done at all.  Why not have the system identify and maintain them for staff based on their role/dept/topic?

Integrating documents with internal audits and corrective actions

Due diligence demands that in addition to making policies, practices and procedures available to staff, you also ensure their adherence and application.  Linking document, audit, corrective action, regulations, and obligations all together demonstrates active due diligence.

Maintaining comprehensive audit logs of actions affecting each document

Knowing who made what changes when, to document metadata as well as content, is a key requirement of mission critical document control.  Changes to ownership, distribution, and access control all need to be kept for the life of a document as future legal actions may require that knowledge in years to come.

Linking Lessons Learnt to documents and workflow steps

Lessons learn being readily available for handling people or circumstances, as well as FAQs and hints, all add to improving productivity and operational staff acceptance of management systems.  Ignoring informal information practices leads to the development of a parallel universe that undermines buy-in to formal management systems.

 

In the end it’s not about throwing the baby out with the bath water nor settling for risk of non-compliance.  It’s about choosing the best of breed for each purpose.

by gcarroll@fasttrackaust.com (Greg Carroll) 5 April 2017
The benefits of SharePoint as a content management system and information portal tool are indisputable.  With great search functionality and user definable portal pages SharePoint is now the leading Content Management solution chosen by most IT departments. But what if your business demands strict document controls protocols, not just because it’s good practice but life depends on it?  Unfortunately there is generally a poor appreciation by IT departments of the importance of document control in mission critical business. 
by gcarroll@fasttrackaust.com (Greg Carroll) 15 September 2016
Senior management have to come to grips with the fact that Digital Transformation is not an Event but rather the operating environment of 21st century business. 
by gcarroll@fasttrackaust.com (Greg Carroll) 22 August 2016
Last week saw the latest in misguided innovation talkfests, the AFR Innovation Summit #Innovation16.  For several days academics, public servants, journalists, and corporate employees put forward their insights into how Australia can develop an Innovation culture. 
by gcarroll@fasttrackaust.com (Greg Carroll) 25 July 2016
Effectiveness is the holy grail of Compliance Management.  Whether regulatory or ERM, ensuring business is conducted as intended is the base requirement to optimising your organization’s performance.
by gcarroll@fasttrackaust.com (Greg Carroll) 17 June 2016
2016 has seen a virtual tsunami of compliance failures involving some of our largest companies. From Mitsubishi to VW, from ANZ to Target, almost weekly there have been media reports about some company employees having run amok – unbeknownst to their executives and boards. People are asking: “What happened to the compliance management systems that are supposed to monitor and prevent such abuses?” Executives and boards are naturally starting to question the entire compliance management function. 
by gcarroll@fasttrackaust.com (Greg Carroll) 7 September 2015
The Compliance Manager’s role in the modern organization is to enable/empower decision makers to take action and leave the building defensive walls to the Risk Manager with his heat maps. So how can compliance managers start realising their value adding role?
by gcarroll@fasttrackaust.com (Greg Carroll) 18 July 2015
With the release of the Final Draft of ISO9001:2015 this week and its focus on risk-based Compliance Management, I thought I would share our approach to Risk-Based Auditing from our experience with the likes of Defence Aviation and the Australian Quarantine Inspection Service, both leaders in the field.
by gcarroll@fasttrackaust.com (Greg Carroll) 3 July 2015
Mere compliance with a Framework is an insufficient audit approach; it is critical to assess whether it is current, timely, communicated broadly, and meets the needs of the business. The 4 biggest mistakes are:       Not being Outcome focused      Not using Risk base targeting      Not Value Adding      Not being timely
by gcarroll@fasttrackaust.com (Greg Carroll) 28 May 2015
Why, with the number of fertile minds that exist in our field, is it still a case of an irresistible force meeting an immovable object.  The paradox I believe, like our would-be entrepreneurs, is one of approach.
by gcarroll@fasttrackaust.com (Greg Carroll) 22 April 2015
Return of Investment (ROI) does not come for automating a process but from using it to add value.  Value adding comes from targeting time and resources, risk based thinking, and Business Intelligence where they can deliver the greatest benefit to achieving the organisation’s strategic goals. 
Show More
Share by: