The most widely used quality management standard in the world, ISO 9001, has a clause dedicated to exactly this: every document that supports an operation must be identified, reviewed and approved before it takes effect — and pulled from circulation once it no longer applies. Clause 7.5 has existed since the 2015 revision. It isn't a new concept; it has been routine quality-audit territory for over a decade.

ISO 27001, the information security standard, points the same direction from a different angle: every information asset needs an owner, responsible for classifying it and reassessing that classification at least once a year. And ISO 42001, published for AI management systems, goes further still — it requires recording where data came from, who collected it and under what authorization, before it feeds an AI system.

Three standards, the same underlying requirement: a document needs an owner, a version in force, and a review date. The problem is that most companies never applied this rigorously even to their own policy and process files — long before any AI entered the picture. Now that same ownerless, dateless file becomes the input for an automated answer, delivered in seconds to whoever asks.

An old discipline, long forgotten

ISO 9001's clause 7.5 is specific: a document needs a title, a date, an author or a reference number, and it goes through review and approval by someone with the authority to do so before it is used. Once approved, changes are controlled and obsolete versions are withdrawn from circulation — they don't stay available "just in case."

In practice, almost no mid-sized company follows this outside the strict scope of a certification audit. The refund policy lives in a shared folder with no effective date. The contract template has three versions saved under similar names, and nobody knows which one is current. The support procedure was written by someone who has since left, and responsibility for updating it was never formally handed to anyone else.

That kind of disorder is tolerable when the only consequence is someone wasting time finding the right file — and that already carries a cost. An IDC study, still cited in recent analyses of document management, estimated that document-related failures account for 21.3% of an employee's lost productivity, close to twenty thousand dollars per person a year. That is money spent searching, redoing, and correcting what should already have been organized.

The difference now is that the same ownerless file no longer just waits for someone to open the wrong folder. It can become the source of an answer that AI delivers in seconds, with the same confidence as a correct one. The mess that used to cost time now costs a decision.

The gaps informal control leaves

The gaps informal control leaves

The most common fix, once someone notices the problem, is to ask for "cleaning up the folder" or "reviewing the files once a year." That helps little, because it treats the wrong symptom. What's missing isn't a one-time clean-up — it's the mechanism ISO 27001 calls an asset owner: a person (or role) formally responsible for that specific document, with an ongoing obligation to keep it correct.

Without that defined role, any reorganization lasts only until the next process change. Someone updates the policy, forgets to remove the old version, and the two sit side by side until a specific question reveals which one is actually in use — usually too late.

Another common gap is treating every document review as a one-time event: written, reviewed, published, done. ISO 27001 asks for the opposite — periodic reassessment, at least yearly, or whenever something relevant changes. And ISO 42001 adds a step almost no company yet practices: recording where information came from, who collected it and under what authorization, before it feeds an AI system. Without that, even a "current" document can have an origin nobody can trace anymore.

What has to be in place

Applying quality-standard discipline to the knowledge that feeds AI doesn't require reinventing anything. It requires taking seriously what these standards have already asked for years.

An owner per document, not per folder. Every critical file has a named person or role responsible for keeping it correct — not "the HR team" in the abstract, but someone identified by name. When that person changes roles or leaves the company, responsibility transfers with them, formally.

A current version with a declared date and scope. A document states when it took effect, which area or country it applies to, and when it's due for review again. "Refund Policy, version 4, effective March 2026, review due March 2027" is traceable. "Refund_Policy_FINAL_v2.docx" is not.

Approval before it takes effect. Critical documents may require two-step review and approval, with segregation of duties and audited exceptions, before becoming official AI knowledge. That isn't extra bureaucracy — it's the same control clause 7.5 already asks for.

Automatic review by date, not by memory. The system flags a document approaching its expiration and prompts the owner for a decision: renew, update, or retire it. Nobody has to remember on their own.

A trail of who approved what. Every version records who wrote it, who approved it, and when. In an audit, or when a specific answer is questioned, that trail is the difference between reconstructing the origin in minutes and not being able to reconstruct it at all.

That's how Skyller was designed: every document with an owner, a current version and a scope by area, and a trail of who approved each change before the content becomes knowledge the AI uses.

From scattered files to a reliable asset

From scattered files to a reliable asset

The most immediate gain is less rework — the same study that estimated the cost of document disorder is, in practice, an estimate of what gets recovered by fixing it. Less time hunting for the right file, less correction after an answer based on the wrong version, fewer meetings held just to confirm "is this still how it works?"

There's also a succession benefit. When a document's owner leaves the company, the knowledge doesn't leave with them — because it was never only in one person's head. The refund rule, the contract template, the support procedure keep their owner, version and date, ready for whoever takes over next. No company needs to design this from scratch: over 170 ready-made policy and process templates already exist to adapt to a given workplace.

And there's a trust gain. An answer that cites the exact version of a document approved by a named person, on a specific date, is verifiable. An answer that comes from "some file in the folder" is not — even if, by chance, it happens to be right.

Before the next quality audit

Before treating this as an AI problem, it's worth reviewing the basic discipline with the quality or compliance team:

  1. Does every critical document have a named owner, not a generic department? If the answer is "the HR team," nobody is individually accountable for keeping that file correct.
  2. Is there a mandatory review date, or is the document only revisited when someone remembers? A deadline that depends on memory isn't a deadline — it's luck.
  3. Can you say, right now, who approved the current version of each critical policy and when? If answering requires digging through old emails, the trail doesn't really exist.
  4. When a document is revoked, does the old version disappear from circulation, or does it stay accessible "just in case"? An accessible old version is an old version still in use, sooner or later.

Discover Skyller