SOP vs Policy: What Each Document Does and How They Work Together

SOP vs Policy

You sort out SOP vs policy the day an auditor asks you to prove that staff follow a rule. You open the policy manual and find twelve-step checklists. You open the SOP binder and find rules that leadership hasn’t approved.

A policy sets the rule and the reason for it. An SOP tells one role how to carry out that rule, step by step, under document control. Keep the two apart and you get documents your staff can follow and your auditors can trace.

Key Takeaways

 

  • A policy states a rule, the reason for it, and the people it covers. Leadership approves it.
  • An SOP gives one role numbered steps for a recurring task, with a document number, a version, and an owner.
  • An SOP is a procedure you have placed under document control, with a fixed format and a version history.
  • One policy often anchors several SOPs, and each SOP should cite the policy it serves.
  • The SORT test helps you place any line: stability, owner, reader, and tools.

What Is a Policy?

 

A policy is a short, approved statement of what your organization requires and why. It names the people the rule covers, and it uses firm language such as “must,” “shall,” and “may not.” Your board, executive team, or a delegated committee signs off on it, and it stays stable for years.

A good policy takes a few minutes to read. It sets the boundary and leaves the method to the documents below it. A privacy policy, for example, commits you to collect the least personal information the work needs. It does not tell a clerk which fields to fill in on the intake screen.

For a broader look at how policies differ from procedures in general, read our guide to policy vs procedure.

What Is an SOP?

 

A standard operating procedure (SOP) is a numbered, step-by-step instruction for a task your team repeats. It tells a named role what to do, in what order, with which form or system, and what record to keep at the end.

The wrapper around the steps separates an SOP from loose notes. A typical SOP carries:

  • A document number and title
  • A version number, effective date, and next review date
  • Purpose and scope
  • Roles and responsibilities
  • Numbered steps
  • Related forms, records, and documents

The City of Brampton’s guide to SOPs describes them as documented, business-specific instructions for completing tasks. It advises owners to test drafts before release and review SOPs at least once a year. Our SOP guide covers how to write one from scratch.

SOP vs Policy at a Glance

 

Use this table to check any document that you can’t place.

Policy SOP
Purpose Sets the rule and the reason for it Gives one role the steps to complete a task
Typical language “must,” “shall,” “may not” “Open,” “record,” “send within two hours”
Reader The people the rule covers The role that performs the task
Approver Board, executive team, or delegated committee Department head or quality lead
Change trigger New law, new risk, new strategy New system, form, or workflow
Length One to three pages As long as the task needs
Audit evidence Shows you set a rule Shows staff follow the rule, through records
Breach response Discipline or legal exposure Corrective action and retraining

SOP vs Procedure: Why “Standard Operating” Matters

 

Many guides treat SOP and procedure as synonyms. In casual speech they overlap. In a regulated setting, auditors notice the difference.

A procedure is any ordered set of steps. You can write one on a whiteboard. An SOP is a procedure you have formalized. It has a number, an owner, an approval record, a version history, and a format your staff recognize. The word “standard” means one approved version exists, and the people who perform the task follow that version.

Regulators care about that formality. Under 21 CFR 211.100, the U.S. Food and Drug Administration requires drug manufacturers to keep written procedures for production and process control.

Staff must follow them, document each step as they perform it, and record and justify any deviation. ISO 9001 quality systems ask for the same discipline: you control the documented information your processes depend on. Those expectations call for version control, sign-off, and records, which is the wrapper an SOP provides.

How a Policy and Its SOPs Connect

 

Think of your documentation as a chain. Each link answers a narrower question.

  1. Policy: the rule and the reason
  2. SOP: the steps one role follows to meet the rule
  3. Work instruction: the detail for one step, such as a screen-by-screen guide
  4. Form or record: the evidence that someone did the work

One policy often anchors several SOPs. An information security policy might sit above separate SOPs for user access, password resets, and laptop disposal.

Each SOP should name its parent policy in the header, and the policy should list the SOPs that carry it out. With that cross-reference in place, an auditor can trace a rule down to a signed record in minutes.

Our post on SOP vs work instructions covers the lower tiers. Our guide to document control procedures explains how to number and version each document so the chain holds. If you are building the whole set from scratch, start with our overview of policies and procedures.

One Rule, Two Documents: A Worked Example

 

Take incident reporting. Healthcare providers, residential care homes, manufacturers, and most employers with safety obligations need it.

The policy (POL-HS-001):

 

Staff must report any workplace incident, injury, or near miss to their supervisor before the end of the shift in which it occurred. Management reviews incident reports to prevent recurrence. Staff who report in good faith will not face retaliation.

The SOP (excerpt):

 

SOP-HS-004: Incident Reporting. Version 3.1. Owner: Health and Safety Coordinator. Parent policy: POL-HS-001.

  1. Make the area safe and get first aid for anyone who needs it.
  2. Tell the shift supervisor in person or by phone.
  3. Complete Form HS-12 in the incident log within two hours.
  4. The supervisor reviews the form, adds witness names, and signs it.
  5. The supervisor sends the signed form to the Health and Safety Coordinator before the shift ends.

Teams that blur the two documents put lines in the wrong place. The table shows four common slips.

Line Wrong home Right home
“Staff who report in good faith will not face retaliation.” Step 6 of the SOP Policy
“Complete Form HS-12 within two hours.” Policy, paragraph 3 SOP, step 3
“Management reviews reports to prevent recurrence.” SOP preamble Policy
“Scan the signed form to the shared drive.” Policy appendix SOP or work instruction

You revise the policy when the law or your risk tolerance changes. You revise the SOP when you replace Form HS-12 or move the log online. With the two kept apart, you can swap a form without a board vote. Our procedure writing guide covers the step-writing technique in detail.

The SORT Test: Does This Line Belong in the Policy or the SOP?

 

During a review, run each line that feels misplaced through four questions.

S: Stability

 

Would the line still hold if you changed software, forms, or staff next month? If yes, it belongs in the policy. “Staff must protect client records” survives a system change. “Log in to the case management system and open Client Files” does not, so it belongs in the SOP.

O: Owner

 

Ask who must approve a change to this line. If the answer is the board or the executive team, the line is policy. If a department head or quality lead can update it, the line belongs in the SOP. Mix them, and leadership ends up signing off on form layouts.

R: Reader

 

Does the line apply to the whole group the rule covers, or to one role? “Visitors must sign in” speaks to the whole group and sits in the policy. “Reception checks photo ID against the visitor log” speaks to one role and sits in the SOP.

T: Tools

 

Does the line name a screen, form, device, or location? Tool names change often and belong to one workflow, so they go in the SOP or a work instruction. A policy that names a form number goes out of date the day you redesign the form.

Signs Your Policies and SOPs Have Blurred Together

 

  • Your policy runs past ten pages because it contains step lists.
  • An SOP cites no parent policy, so staff can’t find the rule it supports.
  • Two versions of the same SOP circulate, and supervisors disagree on the current one.
  • Leadership must approve a change to a form layout.
  • An SOP lists no owner, and staff still follow steps for a system you retired last year.

If you spot two or more, plan a restructure rather than a patch. The Write Direction’s procedure manual writers can rebuild the set so each rule has one home and each SOP has one owner.

From Our Client Work

Our team writes policy and procedure manuals for Ontario children’s residential care operators licensed under the Child, Youth and Family Services Act (CYFSA) and its regulations, O. Reg. 155/18 and 156/18.

Ministry of Children, Community and Social Services (MCCSS) inspectors review these homes, so each requirement needs a clear home in the manual.

On these projects we build a compliance crosswalk first. It maps each regulatory requirement to the policy statement that commits the home to it, then to the procedure and form that show staff carry it out.

The crosswalk exposes gaps fast: a rule with no procedure under it, or a form with no rule above it. Our team at The Write Direction uses the same crosswalk for revisions. A regulation change traces to the exact policy line and SOP step, and the client receives the edits as tracked changes.

Frequently Asked Questions

 

What is the difference between an SOP and a policy?

 

A policy states what your organization requires and why, and leadership approves it. An SOP gives one role the numbered steps to meet that requirement, with a document number, version, and owner. In the SOP vs policy split, the policy sets the rule, and the SOP shows staff how to follow it on the job.

Is an SOP a policy or a procedure?

 

An SOP is a procedure. It sits below policy in your document hierarchy and carries out a policy’s requirements.

An SOP differs from an informal procedure through control: it has an approved format, a version history, a named owner, and a review date. Those controls let auditors confirm that staff use the current version.

Can an SOP replace a policy?

 

No. An SOP without a policy gives staff a method with no stated rule, reason, or scope, and leadership has made no recorded commitment. Auditors look for both: the policy shows the commitment, and the SOP and its records show staff follow it. Small teams can keep policies to a page, but they still need them.

Which should you write first, the policy or the SOP?

 

Write the policy first. It defines the rule, the scope, and the approval authority, so your SOP has a clear target. If staff already follow an undocumented routine, record it as a draft SOP, then write the policy and adjust the SOP to match. That order keeps the SOP vs policy relationship clear from the start.

Do regulators expect both policies and SOPs?

 

In regulated sectors, yes. Health, residential care, food, and pharmaceutical regulators look for written commitments and written methods. In U.S. drug manufacturing, 21 CFR 211.100 requires written procedures that staff follow and document.

Residential care inspectors often ask for the policy and the records your procedures produce. Check your regulator’s standards for exact document requirements.

Get Your Policies and SOPs Working Together

 

Your policies and SOPs should read like two halves of one system. The policy tells your people what the organization stands behind. The SOP shows them how to deliver it on a busy shift. If your current set mixes the two, you pay for it in audit findings, longer training, and conflicting versions.

At The Write Direction, we write and restructure policy manuals and SOPs for organizations in healthcare, residential care, and other regulated sectors across Canada and the US.

We sort each rule into its right home, build the cross-references, and set up version control your team can maintain. Book a consultation or email us at [email protected] to get started.

Leave A Comment

Your email address will not be published. Required fields are marked *