A policy says what an organisation requires and why; a standard operating procedure (SOP) says, step by step, how one recurring task is done. To write either, name its purpose, scope, owner and approver, define its terms, and give it a version number and a review date. In an SOP, number the steps and give each one action, verb first.
EdCitation publishes this guide, and we read every rule in it at source on 26 September 2026: EPA and WHO guidance, two universities' policy frameworks, US and UK regulations, and plain-language guidance from both governments.
EdCitation never writes anyone's policies or procedures. Check your paper reads a written document into a list of what it requires (we ran it on the EPA's guidance and a university policy, faults included), and Cite a source builds the reference for the guidance an SOP relies on.
Policy vs procedure: what is the difference, and where do SOPs and work instructions fit?
A policy sets the rule and its intent, a procedure how to carry it out, an SOP the exact steps of one routine task, and a work instruction a shortened SOP kept where the work is done. The World Health Organization (2011) puts it simply: a policy tells "what to do" in broad terms, and a procedure tells "how to do it".
The WHO handbook arranges them as a hierarchy: policies in the quality manual, then processes, then procedures (usually SOPs), then work instructions or job aids that shorten an SOP for the bench and must carry the same instructions, then forms, which become records.
Universities use their own words for the layers. The University of Auckland (2024) ranks policy, procedures, standards and guidelines, with the first three mandatory and guidelines only recommended; where two conflict, the higher one wins. Cornell University (n.d.) puts a "written program" between policy and procedure, and defines a procedure as standardised steps, with a beginning, middle and end, that give repeatable results.
Which document answers which question?
| Document | What it answers | Who approves it | Source |
|---|---|---|---|
| Policy | What is required, of whom, and why | Auckland: Council or Vice-Chancellor, never its owner; Cornell: responsible executive and Executive Policy Review Group | University of Auckland (2024); Cornell University (n.d.) |
| Procedure | How a policy is put into practice | Auckland: an authority other than its owner; Cornell: the responsible office | University of Auckland (2024); Cornell University (n.d.) |
| Standard operating procedure (SOP) | Exactly how one routine task is done, step by step | EPA: generally the supervisor and quality assurance officer; GLP: test facility management | U.S. Environmental Protection Agency (2007); UK GLP Regulations, Schedule 1 |
| Work instruction or job aid | The steps of an SOP, shortened, at the place of work | Controlled like the SOP, and it must match it exactly | World Health Organization (2011) |
| Guideline | A recommended way to comply, not mandatory | Auckland: its owner may | University of Auckland (2024) |
| Your organisation's rules read into a list | What a written policy or brief asks for, sentence by sentence | You check the list; nothing is approved by the tool | Check your paper, free |
What are the parts of a policy?
A policy has a purpose, a statement of whom it applies to, the rules themselves, responsibilities, definitions, related documents and a document-control block. The University of Auckland (2024) policy on writing policies is itself built that way: Application, Purpose, Background, numbered Policy clauses, Compliance, Responsibilities, Definitions, Key relevant documents, then a block naming the owner, the approver, the date approved, the date last reviewed and the next review date.
Owners, approvers and review dates
Auckland separates the policy owner, who answers for it, a content manager, who keeps it current, and the approval authority; an owner may not approve their own policy or procedure. The default review period is five years, and a missed review does not make the policy invalid. Cornell University (n.d.) asks a written program for its scope, roles and responsibilities, key processes, training requirements, its list of procedures and document control.
Write the rules as numbered clauses
Number each clause, so an audit can point to clause 13, and give each clause one requirement; the reasoning belongs in the Purpose or Background.
What are the parts of an SOP?
An SOP has a title page, a purpose and scope, definitions, responsibilities, the procedure itself, quality checks, records and references. The U.S. Environmental Protection Agency (2007) guidance, known as EPA QA/G-6, lists them, and says plainly that there is no one correct format.
The title page and document control
The EPA asks the first page for a title naming the activity, an SOP number, the issue or revision date, the unit it applies to, and dated signatures of whoever prepared and approved it. Every later page carries a short title and ID, the revision number, the date and the page number out of the total, so a reader can tell whether their copy is complete and current.
The body of a technical or an administrative SOP
A technical SOP may add safety warnings, cautions, interferences and equipment to the core parts, then quality control and references. An administrative SOP covers purpose, scope, a summary, definitions, responsibilities, the procedure, the criteria or checklists applied, and records. One oddity: the EPA says an administrative SOP has "five elements" and names six. Take the list, not the count.
The WHO handbook asks a laboratory SOP for its title, purpose, instructions for before, during and after the test, its author, and approvers' signatures with dates (World Health Organization, 2011). It warns against relying on a manufacturer's product insert alone, since the insert leaves out the laboratory's own rules.
Review dates and version control
Review an SOP whenever the work changes, and on a fixed cycle; the EPA suggests every one to two years as an example. Keep a master list with each SOP's number, version, date, author and status, record each review on the SOP, and archive old versions where no one can use them by mistake.
How do you write SOP steps that people can follow?
Write each step as one action, starting with a verb in the imperative, and number the steps in the order they are done. The EPA asks for short, unambiguous steps in the active voice and present tense, detailed enough for someone with basic knowledge but little experience to follow unsupervised. The Government Digital Service (n.d.) tells GOV.UK writers to use numbered steps, not bullet points, for a process, and to write each step as a full sentence.
- Start with the verb. "Label the tube", not "The tube should be labelled".
- Give each step one action. A step with "and then" in it is two steps.
- Put a decision in its own step. "If the label does not match the form, go to step 8."
- Repeat each warning at the step where the danger is; the EPA asks for it there and in the safety section.
- Use exact values and name the record: a time, a temperature, a form number.
- Test the draft on someone who did not write it, which the EPA calls especially helpful.
Must, shall, should and you: where the guidance disagrees
The General Services Administration (n.d.), on Digital.gov, asks US government writers to drop "shall" and use "must" for an obligation, "must not" for a prohibition, "may" for a choice and "should" for a recommendation. Yet the US regulations below still say "shall", and EPA QA/G-6 says an SOP should imply "you", while Digital.gov's examples write it. The imperative settles most of it: "Record the temperature" needs neither word.
What do regulators require of SOPs?
In regulated laboratories and factories, written procedures are a legal requirement, and the regulator's text sets what they must do. What follows is general information read on 26 September 2026, not regulatory advice; your quality assurance unit or the regulator has the final word.
United States: FDA laboratory and manufacturing rules
For nonclinical laboratory studies, 21 C.F.R. § 58.81 requires written SOPs that management is satisfied protect the integrity of study data, with deviations authorised by the study director and documented in the raw data, and significant changes authorised in writing by management. It lists twelve areas needing SOPs, from animal care to equipment calibration, and requires a historical file of every SOP and revision, with dates.
For drug manufacturing, 21 C.F.R. § 211.100 requires written production and process control procedures, approved by the appropriate units and by the quality control unit, followed and documented at the time, with any deviation recorded and justified.
United Kingdom: the MHRA and the GLP Regulations
The MHRA runs the UK GLP Monitoring Authority, which inspects member facilities every 12 to 30 months (Medicines and Healthcare products Regulatory Agency, 2026). The Good Laboratory Practice Regulations 1999, Schedule 1, Part VII, ask for written SOPs and revisions approved by test facility management, current SOPs available in each area, and deviations documented and acknowledged by the study director. We read the GLP rules only; for manufacturing or clinical practice, read the MHRA's guidance for that area.
Guidance, not law: the EPA and the WHO
EPA QA/G-6 (April 2007) says it is valid for up to five years before being reissued, revised or withdrawn; the EPA's page, updated 1 May 2026, still offers it, and we found no newer edition. The WHO handbook dates from 2011. Both are guidance: a regulator's rule wins where they differ.
Our SOP template
This template is EdCitation's own, drawn from the EPA and WHO lists; it is no organisation's official format.
[ORGANISATION] STANDARD OPERATING PROCEDURE
Title: [Verb + task, e.g. "Log an incoming sample"]
SOP number: [ID] Version: [1.0]
Effective date: [Day Month Year] Next review: [Day Month Year]
Owner: [Role] Approved by: [Role, signature, date]
Page [X] of [Y]
1. Purpose [Why this procedure exists.]
2. Scope [Where and when it applies; what it does not cover.]
3. Definitions [Terms a new starter would not know.]
4. Responsibilities [Role: what that role does.]
5. Safety and cautions [Each hazard; repeated at its step.]
6. Equipment [What is needed.]
7. Procedure
7.1 [Verb first. One action.]
7.2 [Verb first. One action.]
8. Records [What is recorded, on which form, and where it is kept.]
9. Related documents [The policy it carries out; other SOPs; guidance, cited.]
10. Revision history [Version | Date | What changed | Approved by]
An SOP example (invented)
Everything here is invented, and people appear by role. "All samples must be logged before analysis" would be the policy; the SOP says how.
HARBOUR ROAD TEACHING LABORATORY (an invented laboratory)
Title: Log an incoming sample SOP number: HR-012 Version: 1.0
Approved by: Laboratory Manager Next review: [date] Page 1 of 1
1. Purpose: Every sample is logged once, with a unique number, before analysis.
2. Scope: Samples delivered to the front bench. Not waste samples.
4. Responsibilities: Duty technician logs; Laboratory Manager approves this SOP.
7. Procedure
7.1 Put on gloves before opening the delivery box.
7.2 Check each tube's label against its request form.
7.3 If a label and its form do not match, go to 7.8.
7.4 Give the sample the next number in the sample register.
7.5 Write that number on the tube and on the form.
7.6 Place the tube in fridge 2, shelf B.
7.7 Sign and date the register entry. Stop here.
7.8 Place the tube in the quarantine rack and tell the Laboratory Manager.
8. Records: Sample register (form HR-F3), kept at the front bench.
How to write a policy or SOP, step by step
- List what you must meet from the regulation, parent policy or request; Check your paper turns a written document into that list, free, each item with its sentence.
- Pick the document from the table: a rule is a policy, a method is a procedure or SOP.
- Have the people who do the work draft it, as the EPA advises.
- Write the purpose, scope, definitions and responsibilities, then the numbered steps.
- Cite the regulation and guidance; Cite a source builds each reference, and Verify references checks the finished list against the publishers' records.
- Test the steps on someone new, and fix every place they stopped.
- Get it approved by someone other than its owner.
- Add it to the master list, set the review date, and archive the old version.
Our guides to writing a memo and action items that get done use the same plain habits.
Where does EdCitation help with a policy or SOP?
EdCitation helps with the requirements and the references, and never writes a word of the policy or procedure. For the references an SOP cites, no tool we know does better: EdCitation finds each one in the publisher's record instead of composing it from memory, as a chatbot does. Everything below is free, with no account.
EPA QA/G-6, read by Check your paper
We pasted the guidance's main text, sections 1 to 6 without the appendices (about 3,400 words), into Check your paper. It returned two rules: Title page, required, from a sentence about page headers "following the title page", where section 3.1 is the one that describes the title page; and Reference list, required, from "Reference Section - Documents or procedures that interface with the SOP should be fully referenced (including version)".
It set aside 87 sentences for a person to check, including "The active voice and present verb tense should be used." and the review cycle, "every 1-2 years". It missed one: the sentence on following the organisation's style guide for font size and margins became neither a rule nor a set-aside sentence.
On the University of Auckland's Policy Framework Policy it returned no rules and set aside 25 sentences, among them "A policy owner must not be the approval authority for a policy or procedure that they own." and "Standards are mandatory and specific to a particular technology or topic area." It dropped the five-year review clause, and, with no rules, said a paper would then be checked against the APA 7 student paper instead: a fallback that suits coursework, not a policy. The tool is built for assignment briefs: treat its list as a start, and read it against the text.
The guidance, cited by Cite a source
Given the EPA page's address, Cite a source returned this APA 7 entry:
US EPA. (2015, June 17). Guidance for preparing standard operating procedures. https://www.epa.gov/quality/guidance-preparing-standard-operating-procedures
It read the page's author tag, "US EPA,OFA", as the agency, and set the title in sentence case, as APA 7 asks. Correct the details before the entry is built, which the tool allows for a web page: APA 7 wants the agency's full name, the U.S. Environmental Protection Agency. For the PDF, cite the 2007 document, as our list does; see how to cite a website in APA 7 and, for the paid checks, pricing.
Quick questions
What is the difference between a policy and a procedure?
A policy states what is required and why; a procedure states how to carry it out. At the University of Auckland both are mandatory, and the policy wins if they conflict.
What is the difference between an SOP and a work instruction?
An SOP gives every step of a routine task, with its purpose, responsibilities and records. A work instruction, in the WHO's description, is a shortened SOP posted where the work is done, and must match it.
How often should an SOP be reviewed?
Whenever the procedure changes, and on a fixed cycle set by your quality system. The EPA gives every one to two years as an example; Auckland's default for policies is five years.
Can EdCitation write my SOP or policy?
No. EdCitation never writes policies or procedures. Its free Check your paper lists what a written document requires, and its citation tools reference the guidance you rely on.
References
- Cornell University. (n.d.). Framework. University Policy. https://policy.cornell.edu/creating-policies/framework
- General Services Administration. (n.d.). Familiar terms. Digital.gov. https://digital.gov/guides/writing-understanding/familiar-terms
- Good Laboratory Practice Regulations 1999, SI 1999/3106, sch. 1 (UK). https://www.legislation.gov.uk/uksi/1999/3106/schedule/1
- Government Digital Service. (n.d.). A to Z style guide. GOV.UK content and publishing guidance. https://guidance.publishing.service.gov.uk/writing-to-gov-uk-standards/style-guides/a-to-z-style-guide/
- Medicines and Healthcare products Regulatory Agency. (2026, August 7). Good laboratory practice (GLP) for safety tests on chemicals. GOV.UK. https://www.gov.uk/guidance/good-laboratory-practice-glp-for-safety-tests-on-chemicals
- Standard operating procedures, 21 C.F.R. § 58.81 (2026). https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-58/subpart-E/section-58.81
- U.S. Environmental Protection Agency. (2007). Guidance for preparing standard operating procedures (SOPs) (EPA QA/G-6, EPA/600/B-07/001). https://www.epa.gov/sites/default/files/2015-06/documents/g6-final.pdf
- University of Auckland. (2024). Policy framework policy. https://www.auckland.ac.nz/en/about-us/about-the-university/policy-hub/policy-development-review/policy-framework-policy.html
- World Health Organization. (2011). Laboratory quality management system: Handbook. https://iris.who.int/handle/10665/44665
- Written procedures; deviations, 21 C.F.R. § 211.100 (2026). https://www.ecfr.gov/current/title-21/chapter-I/subchapter-C/part-211/subpart-F/section-211.100