The Question Every Quality Manager Eventually Asks
You have decided to run an Integrated Management System combining ISO 9001, ISO 14001, and ISO 45001. You have done the training, mapped your processes, and now someone in your organisation asks: do we need dedicated IMS software, or can we manage this with documents?
On this page
It is a fair question, and the answer is more practical than you might expect. The short version is that ISO standards do not require any particular software platform. What they require is controlled documented information that supports the operation and improvement of your management system. How you store and manage that information is entirely up to you.
But that does not mean the choice is trivial. The wrong approach creates real problems, whether that means a folder structure nobody can navigate, a software platform that costs more than it delivers, or a document library that grows so large it becomes unmanageable. This article walks through what you actually need, when software makes sense, and when well-structured documents do the job just as well.
What ISO Standards Actually Require
Before you spend money on software or hours building document templates, it helps to understand what the standards are actually asking for. ISO 9001, ISO 14001, and ISO 45001 all use the term documented information rather than documents, records, or procedures. This is deliberate. The standards do not prescribe format, medium, or software. They require that certain information exists, is controlled, and is available to the people who need it.
The High Level Structure that underpins all three standards includes Clause 7.5, which covers documented information. The requirements break down into three areas: creating and updating information, controlling it, and retaining it as evidence. That is it. There is no clause that says you need a SharePoint site, a cloud-based IMS platform, or a specific naming convention.
What auditors look for is evidence that your documented information is current, approved, accessible, and protected from unintended changes. Whether that evidence lives in a dedicated software system or a well-managed folder on a shared drive is secondary to whether it actually meets those criteria.
Exemplar Global Recognised Training ProviderRTP No. 310970The Case for Documents First
For most small to medium organisations running an IMS for the first time, starting with documents is the right approach. Here is why.
You Understand What You Are Building
When you write a procedure, complete a risk register, or fill out an aspects and impacts register, you are forced to think through the content. Software platforms often provide pre-built templates and auto-populated fields that can give you a system that looks complete but has not been thought through by your own people. The discipline of building documents from scratch means your team actually understands the system they are operating.
The Cost Is Low
A well-structured folder system on a shared drive, combined with a document register and version control naming convention, costs nothing beyond the time to set it up. For an organisation that is still working out what its IMS actually needs to contain, investing in software before the system is stable is a common and expensive mistake.
Auditors Can Work With It
Certification auditors are accustomed to reviewing documented information in whatever format it comes. A clear folder structure with a document register, version dates, and approval records is perfectly auditable. The format does not impress or concern them. What matters is whether the documents reflect actual practice and whether the people doing the work understand and follow them.
The Risks of Documents Without Structure
Documents work well when they are managed well. The problems arise when organisations treat document control as an afterthought. These are the patterns that create nonconformities.
No Version Control
The most common document control finding is outdated versions in circulation. If your team is working from a procedure that was superseded six months ago, the system is not functioning. Whether you use software or documents, version control is non-negotiable. A simple naming convention such as including a version number and review date in the document footer goes a long way.
No Document Register
Without a central register of what documents exist, what version is current, and who approved them, your document control process has no backbone. The register does not need to be sophisticated. A spreadsheet listing document title, number, version, approval date, and owner is sufficient for most organisations.
Documents That Nobody Reads
Procedures written in isolation, stored in folders that workers never open, do not constitute an effective management system. Documented information is only valuable if it is used. If your team cannot find the procedure they need, or if the procedure does not reflect how work is actually done, you have a compliance gap regardless of what your document library looks like.
When IMS Software Adds Real Value
There are genuine situations where dedicated IMS software is worth the investment. The key is being honest about whether your situation actually fits.
Multiple Sites or Large Workforces
When your IMS needs to serve dozens of sites, hundreds of workers, or a geographically dispersed team, the coordination problem becomes real. Software platforms that allow site-specific versions of documents, role-based access, and automated review notifications solve problems that a shared drive cannot handle well. If you are managing an IMS across construction sites in three states, for example, software that pushes the current version of your SWMS to site supervisors and tracks acknowledgement is genuinely useful.
High Volume of Records
Some industries generate records at a volume that makes manual management impractical. Corrective actions, internal audit findings, calibration records, environmental monitoring data, and incident reports can accumulate quickly. Software that links these records, tracks status, and generates reports for management review saves significant time and reduces the risk of records being lost or overlooked.
Audit Trail Requirements
Certain sectors and certain clients require a detailed audit trail showing who accessed, approved, or changed a document and when. Software platforms with built-in audit trail functionality meet this requirement automatically. For organisations where this level of traceability is important, software is the practical choice.
Integration With Other Business Systems
If your organisation already uses an ERP system, a project management platform, or a safety management tool, IMS software that integrates with these systems can reduce double-handling and improve data quality. The value here depends entirely on whether the integration actually works and whether your team will use it.
What a Practical IMS Document Set Looks Like
Whether you use software or documents, the content of your IMS needs to cover the same ground. Here is a practical breakdown of what an IMS document set typically includes for an organisation certified to ISO 9001, ISO 14001, and ISO 45001.
System Level Documents
- IMS Manual or Policy Statement: A brief document explaining the scope of the system and the integrated policy commitments covering quality, environment, and safety. This does not need to be lengthy. One to two pages is sufficient for most organisations.
- Context of the Organisation: Documentation of internal and external issues, interested parties and their needs, and the scope of the IMS. This is often a single register or table.
- Objectives Register: Quality, environmental, and OH&S objectives with measurable targets, timelines, and responsible owners.
Risk and Compliance Documents
- Risk Register: Covering risks and opportunities relevant to the QMS.
- Aspects and Impacts Register: Environmental aspects, their significance, and associated controls.
- Hazard Register: Identified hazards, risk ratings, and controls under the hierarchy of controls.
- Compliance Obligations Register: Legal and other requirements applicable to quality, environment, and safety.
Operational Procedures
These are the documents that describe how work is done. For an IMS, the goal is to write procedures that address the requirements of all three standards where they overlap, rather than writing three separate sets of procedures. A procedure for managing contractors, for example, can address quality, environmental, and safety requirements in a single document.
- Document and record control
- Internal audit
- Management review
- Nonconformity and corrective action
- Emergency preparedness and response
- Operational controls specific to your business activities
Records
Records are the evidence that your system is operating. They include completed checklists, audit reports, training records, inspection records, incident reports, and management review minutes. The standard requires that you retain records for defined periods and protect them from loss or damage.
Choosing the Right Tool for Your Organisation
The decision between software and documents should be driven by your actual situation, not by what a software vendor tells you that you need. Ask yourself these questions.
- How many people need to access IMS documents, and where are they located?
- What volume of records does your system generate each month?
- What is your current document management capability, and is it working?
- What is your budget, and does the cost of software justify the benefit?
- Do you have the technical capability to implement and maintain a software platform?
If your answers point to a small, single-site organisation with a manageable document set, a well-structured shared drive with a document register and clear naming conventions will serve you well. If your answers point to complexity, volume, or geographic distribution, software is worth investigating seriously.
Common Mistakes to Avoid
Having reviewed IMS documentation across dozens of organisations in various industries, these are the patterns that cause the most trouble.
Buying Software Before You Understand Your System
Implementing software before your IMS is stable means you will be configuring a platform around a system that is still changing. The result is usually a partially implemented platform that nobody trusts, sitting alongside a parallel set of documents that people actually use. Build your system first, stabilise it through at least one internal audit cycle, and then consider whether software adds value.
Treating Software as a Substitute for Understanding
Some organisations implement IMS software and assume the system is working because the platform is populated. Software does not make your system effective. It is a container. What matters is whether the content is accurate, whether people follow it, and whether it drives improvement. An auditor reviewing your IMS will look past the platform and ask whether the people doing the work understand and apply the documented requirements.
Over-Documenting
ISO standards do not require a procedure for everything. The requirement is for documented information to the extent necessary to support the operation of your processes and to have confidence that they are being carried out as planned. If a process is simple, well-understood, and consistently performed, a detailed procedure may add no value. Focus your documentation effort on processes where variability matters and where evidence of control is needed.
Under-Controlling
The opposite problem is equally common. Organisations that treat document control as bureaucracy end up with outdated documents, missing approvals, and no clear ownership. Document control is not about paperwork for its own sake. It is about ensuring that the people doing the work are working from current, accurate information. That is a safety and quality issue, not just a compliance issue.
Exemplar Global Recognised Training ProviderRTP No. 310970Practical Steps to Get Your IMS Documentation Right
- Start with a document register. Before you write anything, create a register of what you need. Map it to the clauses of each standard and identify what already exists and what needs to be created.
- Integrate where you can. Where two or three standards have similar requirements, write one document that addresses all of them. A single internal audit procedure that references ISO 9001 Clause 9.2, ISO 14001 Clause 9.2, and ISO 45001 Clause 9.2 is cleaner and easier to maintain than three separate procedures.
- Assign document ownership. Every document should have a named owner who is responsible for keeping it current. Without ownership, documents drift out of date.
- Set review frequencies. Critical procedures should be reviewed at least annually. Less critical documents can be reviewed on a longer cycle. Your document register should track next review dates.
- Test usability before finalising. Ask the people who will use a procedure to read it and tell you whether it reflects how they actually work. If it does not, revise it before it becomes an official document.
For organisations working through their first IMS implementation or preparing for certification, understanding the documented information requirements of each standard is essential. Audit Workshop's training courses for auditing an IMS across ISO 9001, 14001 and 45001 cover exactly how auditors assess documented information in an integrated context, giving you a practical understanding of what good looks like from both sides of the audit table.
If you are building your IMS from the ground up, the article on how to integrate management systems provides a solid foundation for understanding how to combine the three standards without creating unnecessary duplication. And if you are working toward certification, the guidance on what an integrated management system actually is helps clarify the scope of what you are building before you commit to a documentation approach.
The Bottom Line
There is no single right answer to the software versus documents question. What matters is that your documented information is controlled, current, accessible, and actually used by the people it is intended for. A modest, well-maintained document set beats an expensive, poorly implemented software platform every time.
Start with what you need, not what a vendor is selling. Build your system around the requirements of the standards and the reality of your operations. Review it regularly, assign clear ownership, and make sure the people doing the work can find and understand the documents that apply to them.
If you are preparing to implement or audit an IMS and want practical training grounded in real audit experience, Audit Workshop offers courses at Foundation, Internal Auditor, and Lead Auditor levels across ISO 9001, ISO 14001, and ISO 45001. The training is built around what actually happens in audits, not just what the standards say on paper.










