How to Audit Your SOPs Before They Quietly Go Stale
An SOP audit compares each written procedure with what people actually do, then decides whether to update, retire or keep it. Old documents describe tools no longer used or processes the team improved without updating them, and a new hire who follows one can reintroduce a problem that took months to fix.
An SOP audit isn't about grading your documentation for style. It's about finding the gap between what's written down and what people actually do, then deciding, procedure by procedure, whether to update it, retire it, or leave it alone.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Pull the list before you judge any single document
Start by listing every SOP that exists, regardless of where it lives: a shared drive, a wiki, a tool like Vanta or Drata if you use one to store policy documents, or someone's personal notes app. You cannot audit what you haven't inventoried, and most companies are surprised by how many versions of the same procedure exist across different tools once they actually look.
For each one, note who wrote it, when it was last edited, and who is supposed to follow it today. That last column is often where the first problem shows up: procedures written for a role that no longer exists, or a team that has since split in two.
Watch someone do the real task, then compare
The only reliable way to know whether an SOP still matches reality is to watch the actual work happen and compare it step by step against the document. Reading the SOP and asking 'does this still sound right' produces confident agreement even when the real process has drifted, because people remember the intent of a procedure more clearly than its exact steps.
When you find a mismatch, resist fixing it on the spot. Note it, finish the observation, and only then decide whether the document needs to catch up to the practice or the practice needs to be pulled back in line with the document. Sometimes the drift was actually an improvement worth keeping.
Sort every SOP into one of three piles
Once you've compared documents against practice, every SOP falls into one of three categories:
- Still accurate: leave it alone, but log the confirmation date so the next audit knows it was checked.
- Drifted but salvageable: rewrite it to match current practice, ideally with the person who actually does the work as the reviewer.
- Dead: the tool, team, or process it describes no longer exists. Retire it instead of leaving it to confuse the next new hire who stumbles across it.
Resist the urge to rewrite everything in the drifted pile in one sitting. Fix the ones tied to the highest-risk work first.
Set a return date, or the drift just restarts
An SOP audit that happens once and never again just delays the same problem. Put a recurring date on the calendar, tied to a trigger rather than an arbitrary interval: a tool migration, a reorg, or a role change should all trigger a re-check of the SOPs that touch them, in addition to whatever standing schedule you set.
Median pay for the operations managers who typically own this kind of audit runs close to $105,770 a year1, which is worth knowing if you're deciding whether to own this yourself or hand it to a hire.
What good documentation actually looks like once it's fixed
A rewritten SOP should read like instructions for someone who has never done the task, not like a summary for someone who already knows it. That means naming the exact tool, the exact field, and the exact decision rule, instead of phrases like 'check as needed' or 'use your judgment,' which are the two phrases that let drift creep back in unnoticed.
If you can't write a step without a qualifier like 'usually' or 'typically,' that's a sign the underlying process itself isn't settled yet, and rewriting the document won't fix that. Settle the process first, then document it.
What Good Looks Like
A healthy SOP library has a confirmed review date on every document and zero procedures describing tools, teams, or steps that no longer exist.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
If you already store policies in Vanta, its version history makes it easier to spot exactly when an SOP was last touched during an audit.
Drata works the same way for teams that keep their compliance-relevant procedures inside it rather than a separate document folder.
Frequently Asked Questions
How often should we audit our SOPs?
At least once a year for anything customer-facing or compliance-related, and immediately after any tool migration, reorg, or major process change. Waiting for an annual cycle alone misses the drift that happens right after a change, which is when documentation tends to fall furthest behind reality.
Should we audit every SOP at once or a few at a time?
Start with the procedures tied to your highest-risk or highest-frequency work, not an alphabetical list. Auditing everything at once usually stalls halfway through. A smaller batch you actually finish and act on beats a full inventory that sits half-reviewed for months.
What should we do with an SOP nobody follows anymore?
Retire it formally rather than just leaving it in the folder. An unlabeled dead procedure is worse than no procedure, since a new hire has no way to know it's outdated. Mark it clearly, note why it was retired, and point to whatever replaced it, if anything did.
Sources
Where we quote a benchmark, we show its source. Other figures in this guide are estimates or general guidance, so check them against your own numbers.
- Annual wage, General and Operations Managers (SOC 11-1021), US all industries. BLS OEWS May 2025, 2025.
Related Guides
Small Business Operations Audit: What to Check and How
Run a one-week operations audit for a small business: what to check in each area, how to score findings, and how to turn them into owned fixes.
Process Street vs SweetProcess vs Trainual: Standard Operating Procedure Software
Compare Process Street, SweetProcess, and Trainual: checklist workflows, interactive SOP documentation, employee onboarding, AI generation, and pricing.
Running a Vendor Sprawl Audit Before Your Next Renewal Cycle
A concrete process for finding the SaaS tools nobody uses anymore, the ones that overlap, and the ones worth keeping, before your next batch of renewals.
The Operational Debt Audit: Finding Fragile Processes Early
How to find the workarounds and manual patches holding your operations together before one of them breaks under real pressure.
Governing AI Agents Before They Touch Your Operations
A practical way to decide which operational tasks an AI agent can run unsupervised, which need a human check, and how to document the difference.
Cutting Status Meetings by Writing Better Async Updates
How to replace recurring status meetings with written updates that actually give people the information they need, across time zones and without a live call.