01Why SOPs need their own chapter
In any compliance curriculum, SOPs risk becoming scenery — mentioned in passing as "the documents that tell people what to do", then never examined on their own terms. That is a mistake with real consequences.
SOPs are the operational skeleton of a regulated company. Principles declare intent. Policies translate intent into rules. SOPs translate rules into action — step by step, role by role, document by document. Without them, a quality system is a set of wishes. With poorly written or un-followed ones, it is something worse: a paper shield that hides uncontrolled variation.
Regulatory agencies know this. In US FDA Warning Letters, inadequate or missing SOPs appear in the top five most-cited deficiencies year after year. The same pattern holds in EMA inspection findings and PMDA corrective-action reports. Inspectors do not just ask "do you have an SOP?" — they ask "does your practice match it, and can you prove it?"
"We did not find that the company lacked policies. We found that the policies had never reached the floor." — composite paraphrase of FDA inspection feedback, frequently echoed across multiple Warning Letters since 2018.
This gap — between what is written and what is done — is the central problem SOPs exist to close, and the central problem they most often fail to close. That tension is what this chapter is about.
02What is an SOP — origin in GMP/cGMP, purpose, format
The term "Standard Operating Procedure" entered regulated-industry language through Good Manufacturing Practice (GMP), codified in the US by the FDA's Current GMP regulations (21 CFR Parts 210–211, first effective 1978). GMP required manufacturers to establish written procedures for every phase of production — and to follow them. The modifier "current" in cGMP signals that the standard moves with the state of science; SOPs must keep pace.
At its core, an SOP is a document that specifies, in sufficient detail, how a defined activity is to be performed consistently. "Sufficient detail" is deliberate: not so sparse that two trained people interpret the step differently, not so exhaustive that the document is unusable in practice.
SOP formats vary by organisation and regulatory context, but the major elements are stable:
- Purpose — what the procedure achieves and why it exists
- Scope — which processes, systems, sites, or roles the SOP applies to
- Responsibilities — who executes, who reviews, who approves, who is accountable
- Definitions — terms that carry specific regulatory or technical meaning in this context
- Procedure — the sequential steps, decision points, and required records
- References — parent policies, related SOPs, regulatory citations
- Attachments / Appendices — forms, templates, flowcharts that support execution
Some organisations add a "revision history" section; others embed that in a document-management system. What matters is that every reader — including a new employee or an external inspector — can pick up the document and understand what to do, in what order, with what authority, and leaving what trace.
03The role SOPs play in the three-layer model
Compliance architecture is often described as a three-layer model: Principle → Policy → Procedure. SOPs occupy the third layer, but their meaning depends entirely on what lives above them.
The model works when each layer is coherent with the layers above it. It fails when:
- Policies are written without regard to operational feasibility (staff follow a workaround, then write the SOP to match the workaround)
- SOPs proliferate without a governing policy (hundreds of procedures, no unifying rationale)
- Principles exist only on office walls and never inform what policies say
A well-functioning SOP is therefore not just a procedure document — it is evidence that the organisation's principles have travelled all the way down to daily motion. When an inspector reads your adverse-event SOP, they are, in effect, reading a claim about your values. The procedure either substantiates that claim or contradicts it.
04GxP SOPs vs. general business SOPs
Not all SOPs carry the same regulatory weight. The "GxP" family — Good Clinical Practice, Good Laboratory Practice, Good Manufacturing Practice, Good Pharmacovigilance Practice, Good Distribution Practice — each imposes specific SOP requirements that carry legal force in the jurisdictions where the company operates.
General business SOPs — for HR processes, procurement, IT change management — also matter, but a deficiency there rarely triggers a regulatory action. The critical discipline for pharma professionals is knowing which of their daily tasks fall under a GxP umbrella and therefore require a higher standard of authoring, approval, training, and deviation management.
Confusion between the two tiers is common and costly. An MR who treats a GCP-required informed-consent procedure with the same informality as a travel-expense form is making a category error that can reach as far as a clinical trial being considered unreliable.
05SOP structure — the seven sections in detail
The seven-section anatomy described in section 02 deserves closer examination, because each section is a failure point if handled carelessly.
Purpose
The purpose statement should name the regulatory or quality objective the SOP serves, not just describe the activity. "To ensure that batch records are reviewed completely and consistently before release" is better than "To describe the batch-record review process." The first answers "why this must exist"; the second just names the topic.
Scope
Scope defines both what is included and what is explicitly excluded. Omitting exclusions is a common error — it leads to disputes at audit time about whether a given activity was governed by the SOP or not. A scope statement should be testable: a reasonable person reading it should be able to determine, for any given situation, whether the SOP applies.
Responsibilities
The responsibility section is where many SOPs go wrong in practice. Listing a role ("QA Manager") without specifying the action ("reviews and signs the completed batch record within two business days of production completion") creates ambiguity that only surfaces under pressure. Use RACI-style language (Responsible, Accountable, Consulted, Informed) where precision matters.
Definitions
Define terms that have regulatory meaning and might be interpreted differently by different readers. "Adverse event", "significant amendment", "critical defect" — each of these has a specific meaning in its regulatory context that may differ from colloquial usage. A definitions section short enough to fit on one page, focused on terms the procedure actually uses, is far more useful than a two-page glossary imported wholesale from a policy.
Procedure
The core of the document. Steps should be numbered, sequential, and written at the level of the person performing them — not the person who designed the process. If a step requires a decision, the decision criteria belong in the step, not in a footnote. If a step produces a record, the record must be named. A procedure that leaves "what to do when X goes wrong" as an exercise for the reader is incomplete.
References
List the documents — parent policies, related SOPs, regulatory citations, validated system user manuals — that a reader would need to understand the full context. Keep this list current; an SOP that references a superseded document version is itself a finding.
Attachments
Forms, templates, flowcharts, and decision trees belong here, not embedded in the procedure body. Keeping attachments separate makes version control cleaner: a form can be updated without triggering a full SOP revision cycle, provided the parent SOP references the attachment by name rather than version number.
06Implementation challenges — bloat, drift, training cost, change management
Even well-written SOPs encounter predictable implementation failures. Naming them explicitly is the first step to avoiding them.
Bloat
Large organisations accumulate SOPs the way old houses accumulate furniture — layer by layer, until movement becomes difficult. A manufacturing site that began with 80 SOPs can reach 800 over a decade of mergers, acquisitions, and regulatory responses. The result: people cannot find the relevant document; documents contradict each other; maintenance becomes a full-time job that crowds out actual compliance work.
The antidote is periodic SOP rationalisation — a deliberate audit that consolidates overlapping documents, retires obsolete ones, and asks "if we were designing this system today, how many SOPs would we actually need?" Most organisations find they can cut their inventory by 20–40% without losing regulatory coverage.
Interpretation drift
An SOP written clearly in Year 1 is interpreted by an expanding team in Year 3, some of whom received only a training summary. Each person applies their own interpretation to ambiguous steps, and over time the actual practice diverges from the written procedure. This is interpretation drift, and it is invisible until an audit or an adverse event makes it visible.
Mitigating drift requires more than periodic retraining. It requires observation-based verification: someone with authority watching the procedure actually performed and noting where practice diverges from text. The divergences usually reveal either a flaw in the SOP or a training gap — and often both.
Training cost
Every new or revised SOP requires training, and every training event has a cost — time taken from productive work, comprehension assessments, records to maintain. In a GxP environment, the record of training is itself a regulatory requirement; "trained but no record" is legally equivalent to "not trained".
Organisations that treat SOP training as a box-checking exercise — push out a PDF, collect an e-signature, move on — find that the investment in writing the SOP yields little return. Training must achieve behavioural change, not just record completion. That usually means scenario-based learning, not document reading.
Change management
Change is the most dangerous moment in an SOP's lifecycle. When a procedure is revised, there is a window during which some staff are working from the old version, some from the new, and some from memory. Without a rigorous cut-over plan — specifying the exact date and shift when the old version is retired, how in-process work is handled, who confirms that all users have been trained before the new version goes live — the change itself creates a compliance gap.
07AI and SOPs — drafting, gap analysis, compliance monitoring
Generative AI has arrived in the SOP space, and it is already changing the economics of authoring. It is worth being precise about what it changes and what it does not.
What GenAI does well
Large language models are good at drafting structured text from a brief. Given a prompt that specifies the process, the relevant regulatory framework, the roles involved, and the key decision points, a capable model can produce a serviceable first draft of an SOP in minutes — a task that previously took an experienced writer several hours. That draft will be grammatically coherent, organised according to convention, and free of many of the stylistic inconsistencies that creep into documents written by committee.
Models are also useful for gap analysis: given an existing SOP and the text of a regulatory requirement, AI can quickly identify sections of the requirement that the SOP does not address. This is tedious work for humans and well-suited to pattern-matching at scale.
What GenAI does not do
AI does not know your process. The draft it produces from a generic prompt will describe a plausible version of the activity — not your version, with your equipment, your roles, your validated systems, your historical deviations. Every AI-generated draft requires substantive review by someone who knows the actual operation.
More critically, AI cannot validate that a procedure works. It can draft a cleaning procedure; it cannot confirm that the cleaning steps are sufficient to reduce contamination risk to acceptable levels. That confirmation requires actual process validation — physical, empirical, documented.
Compliance monitoring
Beyond drafting, AI-assisted monitoring is an emerging application. Systems that compare actual process data (from manufacturing execution systems, electronic lab notebooks, or quality management systems) against SOP-specified parameters can flag potential deviations in near-real time, before they become adverse events or audit findings. This is genuinely new capability — not just faster paperwork, but a different model of compliance verification.
The governance questions for this capability are still being worked out: who is responsible when AI flags a deviation that a human reviewer would have cleared? How is the AI system itself validated? What happens when the AI's monitoring logic becomes outdated relative to a revised SOP? These are not hypothetical — they are active discussions in regulatory submissions today.
08SOPs and quality culture — rules vs. thinking culture
There is a long-standing debate in quality management about whether compliance-by-SOP produces organisations that follow rules or organisations that understand why the rules exist. The distinction matters more than it might first appear.
An organisation that follows SOPs because inspectors check them will tend to have good paper compliance and poor behavioural compliance. Staff do what the document says when they know they are being watched; they do what is convenient when they are not. Deviation rates are underreported. Near-misses go unrecorded because recording them is "more trouble than it's worth."
An organisation with genuine quality culture experiences SOPs differently. The procedure exists because someone thought carefully about how to do the task right; following it is not a compliance burden but a cognitive shortcut — thinking that has already been done, written down, and made available. Deviations are reported not because they are required, but because discovering a better approach and updating the SOP is how the organisation learns.
"The goal is not a company where everyone follows the SOP. The goal is a company where everyone understands why the SOP says what it says — and speaks up when it's wrong." — quality consultant frequently cited in ICH Q10 implementation guidance discussions.
Building that culture requires more than good SOPs. It requires visible leadership behaviour (senior staff who follow procedures rather than bypassing them), psychological safety (people who report deviations are thanked, not blamed), and feedback loops (deviation data actually drives SOP revision, visibly and promptly).
SOPs that are written once and never revised communicate a culture. So do SOPs that are revised frequently based on deviation data and staff input. The document itself is an artefact of the culture that produced it.
09Three remaining challenges
Even organisations that manage the implementation challenges described in section 06 face structural tensions that SOPs alone cannot resolve.
The globalisation gap
A multinational company with a single global SOP for a given process will find that the SOP fits some jurisdictions well and others poorly — because regulations differ, because language nuances matter, and because local practices have evolved for good reasons. The alternative, maintaining separate SOPs by country or region, creates a coordination problem: how do you ensure consistency of outcome when the procedures differ? There is no clean answer; the gap is managed through robust local adaptation processes and strong central oversight, neither of which is cheap.
The speed–rigour tension
In fast-moving situations — a pandemic response, a product crisis, an urgent regulatory request — the normal SOP change-management cycle (draft, review, approve, train, implement) can take weeks. The temptation to act on an informal instruction and "update the SOP later" is understandable and dangerous. "Later" often does not come, or comes after the informal practice has already created a deviation. Emergency SOP provisions, pre-approved and themselves governed by an SOP, are the conventional solution — but they require forethought that crisis conditions do not naturally encourage.
The digital transformation inflection
Manufacturing and laboratory operations are increasingly automated and data-rich. When a validated system enforces a process step — only allowing the operator to proceed when certain conditions are met — does the corresponding SOP section become redundant? Regulators have not yet converged on a clear answer. The current expectation, in most jurisdictions, is that the SOP remains in force and describes why the system is configured as it is. But as digital systems become more sophisticated, the relationship between written procedure and enforced workflow will need to be rethought at a level that current guidance does not yet reach.
10Connections to other chapters
SOPs do not operate in isolation. Their effectiveness depends on, and feeds back into, almost every other dimension of the compliance system described in this series.
- Compliance 01 — Life-Related Industry: The five walls between pharma and patients — information, institution, economics, time, psychology — make explicit why procedural precision matters. An SOP for adverse-event reporting exists because the information wall would otherwise allow safety signals to be missed or suppressed. SOPs are, in part, institutional infrastructure for bridging those walls honestly.
- Compliance 02 — Social Trust: Organisational trust is built in small units, and SOPs are where those units are defined. A company whose SOPs are followed consistently is a company that has made and kept operational promises. Conversely, a gap between written procedure and actual practice is a breach of the implicit contract with regulators and patients — whether or not it is ever discovered.
- Compliance 03 — Conflict of Interest (forthcoming): Conflict-of-interest management depends heavily on clear procedures for disclosure, review, and recusal. An SOP that specifies exactly who reviews what disclosures, within what timeframe, and with what outcome leaves little room for the informal accommodation that conflicts of interest thrive on.
- Compliance 04 — Internal Reporting (forthcoming): Whistleblowing and near-miss reporting systems are themselves governed by SOPs — and the quality of those SOPs is a signal of how seriously the organisation takes the input. A sparse, bureaucratic internal-reporting procedure communicates something very different from one that is detailed, accessible, and clearly linked to improvement cycles.
- Material Review: Every promotional piece that goes to a medical information committee is reviewed against SOPs that specify who participates, what standards apply, and how decisions are documented. Material review quality is inseparable from the quality of the procedures governing it.
SOPs are where organisational principles stop being abstractions and start being instructions. They are also where most compliance systems quietly fail — not because the documents are absent, but because the distance between the document and the daily act is never actually closed.
The challenge is not technical. Writing a good SOP is learnable. Maintaining a set of SOPs that stays current, is actually followed, and is connected upward to the policies and principles that justify it — that is an organisational achievement. It requires sustained attention, honest deviation reporting, and leadership willing to revise procedures when evidence says the current version is wrong.
AI will change some of the economics. Drafting will get faster. Gap analysis will get cheaper. Monitoring will become more continuous. None of that removes the human judgments at the centre: does this procedure reflect how the work should actually be done, and do the people doing the work understand why?
References & Further Reading
- FDA, 21 CFR Parts 210–211: Current Good Manufacturing Practice in Manufacturing, Processing, Packing, or Holding of Drugs (1978, as amended). U.S. Government Publishing Office.
- ICH, Q10: Pharmaceutical Quality System (2008). International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use.
- EMA, Good Manufacturing Practice: Annex 15 — Qualification and Validation (2015). European Medicines Agency.
- ICH, E6(R2): Good Clinical Practice — Integrated Addendum (2016). International Council for Harmonisation.
- EMA, Good Pharmacovigilance Practice Module I: Pharmacovigilance Systems and their Quality Systems (2017). European Medicines Agency.
- WHO, Guidelines on Good Manufacturing Practices: Validation, Appendix 3 — Cleaning Validation, WHO Technical Report Series No. 957 (2010).
- Torbeck, L. & Branning, R., "Why Procedures Can and Do Fail", Pharmaceutical Technology, Vol. 43, No. 3 (2019).