The week the clearance letter arrives, nobody is thinking about document control.
You're thinking about the first production run, the sales hires, or whether your contract manufacturer can actually hold the tolerance they promised in the quote.
And the document system works, because it got you through the submission. Right?
Then it's 14 months later, and headcount went from 11 to 38, you added a second shift, and a manufacturing tech builds 40 units to a work instruction that was superseded in March.
Nobody did anything wrong, exactly. The system just stopped fitting the company, and it took a nonconformance to make that visible.
This piece assumes you already know what document control is. If you want the fundamentals, the requirements, and the vocabulary, the ultimate guide to document control covers all of it. Come back here for the part that only shows up after you commercialize.
BONUS RESOURCE: Document Control for Medical Device Companies: The Ultimate Guide
Design control problems usually announce themselves. When a verification protocol fails, an engineer's calendar clears for a week.
Document control degrades on a slower clock. Every individual shortcut is reasonable in the moment. It makes sense to email the drawing to the supplier because the portal is slow. So does keeping a working copy on the desktop because you're mid-revision. And so does skipping the training assignment because the change was "administrative."
None of those earns an observation on its own. But when you stack 30 of them across 18 months of growth, it starts to feel like you've built a second, undocumented quality system running in parallel with the real one.
What usually happens after is that the truth about which document is current lives in one person's head, and that person is now in back-to-back meetings.
Before commercialization, your documents had one home and about 8 readers. Version control was a naming convention and a person who remembered everything.
After commercialization, try to count the places a controlled document can physically exist:
ISO 13485 clause 4.2.4 asks you to make current documents available where the work happens and to prevent the unintended use of obsolete ones. Under the Quality Management System Regulation (QMSR), which took effect February 2, 2026, that's the text an FDA (U.S. Food and Drug Administration) investigator is working from.
Availability and prevention pull in opposite directions once you have more than one physical location. Getting the current revision everywhere means making copies. Preventing obsolete use means controlling every copy you make.
Ask 3 people in different functions where the current revision of your highest-risk work instruction lives, and how they'd know it's current. If you get 3 different answers, or if any answer includes the phrase "I'd ask Sarah," you already have the problem, you just haven't paid for it yet.
The bill comes as nonconforming product, a lot you have to contain, a corrective and preventive action (CAPA) you have to run, and a week of somebody's life reconstructing which units were built to which revision.
Your first approval workflow was probably pretty straightforward. Somebody printed the change, walked it to the founder, and got a signature in 10 minutes.
That worked beautifully. It also encoded a habit: one person approves everything.
Now you've got a VP of Quality who travels, a regulatory consultant on retainer, an engineering manager in a different time zone, and a change order with 6 required signatures on a label revision that changes a font size.
And if you watch closely, you'll see what people do when approvals get slow. They route around the system.
Red-lined copies start circulating "just so you can see what's coming." Somebody writes a temporary deviation that becomes permanent. A work instruction gets updated in a shared doc with every intention of converting it to a controlled document later, and later never arrives.
Three things usually fix this, prioritized by how fast they pay off:
Approval speed is a quality control. Slow approvals create pressure, and pressure creates the workarounds that show up as 483 observations two years down the road.
When you were a 10 person company, document control and training were the same conversation. If the document changed, everybody heard about it, and everybody was in the loop when it happened.
At 40 people across 2 shifts, those shifts turn into 2 separate systems run by 2 different people, and the gap between them is where auditors go fishing.
If you're curious what an investigator may find, it only takes about 6 minutes: pick an SOP. Pull its revision history. Pull the training records for everybody who performs that procedure. Compare the effective date to the training completion dates.
If the document went effective on March 3 and 4 operators were trained on April 20, the question writes itself. What were those 4 people following for 7 weeks?
ISO 13485 clause 6.2 asks you to determine competence, provide training, and keep the records. If the document said one thing and the floor did another, the records show you didn't notice.
A signature on a read-and-understood sheet proves distribution happened. Evidence of competence takes more than that, however, and the distinction gets sharper the more people you hire.
BONUS RESOURCE: Training management after clearance: what breaks first as your team grows
Before clearance, most of your document activity is design output. Specifications, protocols, reports, drawings. The volume is high, the changes are driven by engineering, and the whole thing points toward a submission.
After clearance, that flips. Design documents settle down, and the documents that change weekly are the ones the floor touches: work instructions, inspection methods, labeling, supplier agreements, complaint handling procedures.
Same document control procedure, completely different workload. And most companies never revisit the SOP that governs it.
This is what that looks like in practice. A change control process built to handle 4 engineering changes a month now has to absorb 30 production changes a month, with different approvers, different urgency, and different consequences for getting it wrong. A labeling change that holds up a shipment is a different animal from a protocol revision that holds up a test.
The fix is unglamorous. Read your document control procedure and your change control procedure against what actually happens now. Where the procedure describes a world that ended at clearance, revise it. Most growth-stage companies find at least 2 clauses that no longer describe how the company works, and those clauses are exactly what an investigator will hold you to.
Each of these 3 failures is the same failure wearing different clothes.
Your early system worked because a person held the state in their head. Which file is current. Who needs to know. Who signed off. That person was fast, accurate, and completely uninterruptible by growth.
Then the company outgrew the capacity of one head. The system kept working right up until the moment it didn't, which is why the first symptom is usually a nonconformance on the floor.
Headcount thresholds make a lousy trigger. Events make a good one, and each of these 5 is a signal that your document control needs to change shape before the next quarter closes.
That last exercise only takes an afternoon, but it's the highest-value afternoon your quality team will spend this quarter, and it costs you nothing but the willingness to find out.
For a deeper look at how the individual controls are supposed to work together, document control for medical device companies walks through the mechanics.
A growth-stage document control system that holds up has a few properties, none of which depend on someone's memory.
One place is where a document is current, and it's obvious from looking at it. Version history is captured as a byproduct of the work rather than as a separate task somebody has to remember. Approvals can be routed by role with compliant electronic signatures. Training is effectively tied to each document, so the connection can't drift. Traceability runs from your design outputs through your device master record to the work instruction a tech is reading before the day shift arrives.
It is possible to build that on a shared drive and a spreadsheet. Companies do it. But it costs about 1 full-time equivalent in administrative work, and it fails in all the ways described above once you add a site or an additional shift.
Greenlight Guru's quality management software was built for medical device companies specifically, which means document control, training records, design controls, risk, and CAPA reference each other instead of sitting in separate tools with a spreadsheet stapled between them. When a document goes effective, the training assignment follows it. When an auditor asks for the trace, it's a simple search rather than an archaeology project.
If you're building out document control for a growth-stage quality system, these related guides go deeper on the pieces that break first:
If your document system is still running on the setup that got you cleared, and headcount has doubled since then, taking a look at another option is worth 30 minutes of your time.