Ask where a document is in a company and the answer is usually the same: on someone's computer, in a folder, maybe in an email. Who holds the latest version of the quality procedure, the date the supplier's certificate arrived, which cabinet holds the original signed delivery note — all of it is carried in people's memories. While things are going well, this arrangement holds. When an audit arrives, when a customer asks for a document going back years, or when the person who knew that document leaves, the search begins. As irritating as the length of the search is the inability to be sure that the document found is the latest version. Three copies of the same file named final, final_revised and final_real is a common sight in the field. Which of those three went to production is usually a question nobody asks.
A shared network folder or cloud drive brings relief at first, but past a certain volume it creates a problem of its own. As the folder tree grows nobody knows where to save; the same document lands in two different places under two different names. Because permissions are granted at folder level, either everyone sees everything or someone has to grant access each time. Who changed a document, when and why is not recorded. Most importantly, because nowhere states how long a document will be kept and when it should be destroyed, the archive grows without end; a quotation file from ten years ago sits in the same place, with the same weight, as this month's signed contract.
A document management system (DMS) turns a document from a file into a record. Every document has an owner, a type, a version history and a permission that determines who it is open to; changes do not overwrite, they accumulate as new versions and the old version stays readable. Enterprise content management (ECM) goes a step wider: alongside the document it also takes in the process around it, its metadata, its retention and destruction rules, its evidential value and content arriving through different channels. Put roughly, a DMS answers the question where is this document and in which version, while ECM answers how did this content come about, whose hands did it pass through, how long will it live and how will it be evidenced. For a small archive need a DMS is enough; in a structure carrying quality, legal and audit load the work widens towards ECM of its own accord.
The most common mistake in setting this up is copying the existing folder structure into the new system as it stands; the result is a more expensive version of the same mess. So document types, owners and retention periods are discussed first, and migration comes afterwards. Let us state the boundary up front as well: the part that reads a document's content and extracts data from it we treat as a separate module; the system on this page stores, versions, permissions and finds documents. In regulated areas such as electronic signature and registered electronic mail we do not take the place of licensed service providers, we connect to their infrastructure. Nor do we usually recommend scanning an entire twenty-year paper archive; in most companies the right decision is to start properly from today and bring across from the past only the files still in use.