The SOP says: verify the part number before installation. The operator says: “we don’t really do it that way anymore.”
That sentence can change the direction of an audit very quickly. A procedure can be approved, revision controlled, and available in the document system — none of that proves the process is actually performed as written. Auditors generally do not stop at the document. They observe work, interview employees, review records, and follow transactions to compare what the QMS says should happen with what actually happens. That is where some of the most important quality-system weaknesses become visible, because when the SOP and actual practice tell different stories, at least one of them is probably wrong.
Note
The SOP tells the auditor what should happen. The process tells the auditor what actually happens. The evidence tells the auditor whether the two agree.
ISO’s own 9001 Auditing Practices Group specifically advises auditors to evaluate processes through objective evidence and to gather evidence where activities are actually taking place. Its process-auditing guidance also recommends sampling whether an organization’s documented description of its processes is a proper reflection of how those processes actually interact. A controlled SOP is evidence of a defined process. It is not automatically evidence of effective implementation.
ISO 9001 Auditing Practices Group — Guidance on Processes and Evidence Collection. APG papers provide auditing guidance and are not themselves additional ISO 9001 requirements.
The Three Versions of a Process
In many organizations, there are actually three versions of the same process. A healthy QMS keeps them reasonably aligned; problems begin when they drift apart.
- The written process — what the SOP says should happen.
- The understood process — what employees believe the procedure means.
- The actual process — what people really do when the work needs to get done.
For example: the SOP requires two-person verification before release. The employee understands that a second person should review it “when someone is available.” In actual practice, the primary operator verifies their own work when the department is busy. The procedure looks perfectly compliant sitting in document control. The weakness becomes visible only when someone observes the process.
“That’s Not How We Really Do It”
Few statements create more useful audit information than “that’s what the procedure says, but that’s not how we actually do it.” Sometimes the difference is minor. Sometimes the employee has misunderstood the requirement. Sometimes the SOP is outdated. Sometimes the official process is so impractical that employees have built a workaround just to get the work done. And sometimes management already knows the documented process isn’t being followed. Each scenario means something different, and the auditor will likely want to understand which one it is.
Common reasons SOPs drift away from reality include: the process changed but the SOP did not, the SOP was written by someone who doesn’t perform the work, equipment or software changed, responsibilities shifted, employees found a faster workaround, a temporary fix became permanent, or different shifts developed different ways of doing the same job. The fix depends on why the difference exists — simply telling employees to “follow the SOP” may not solve a process-design problem.
A Current FDA Example
In an April 15, 2026 warning letter to Par Health USA and Endo USA, FDA described investigators observing operators who were not following written aseptic-processing procedures. The firm’s response included procedural changes and additional operator training. FDA, however, said the response did not sufficiently address broader underlying issues, including equipment design and ergonomic weaknesses, excessive manual manipulation, inadequate barrier protection, and other fundamental process concerns.
That distinction matters. Employees were observed deviating from procedures, but FDA did not treat “revise procedure + retrain employee” as automatically sufficient. The agency also examined whether the process and equipment design contributed to the problem.
U.S. Food and Drug Administration. Par Health USA, LLC & Endo USA, Inc. — Warning Letter 722121, April 15, 2026. This is a pharmaceutical CGMP enforcement example, cited to illustrate the importance of evaluating actual practice and underlying process conditions — not as a universal requirement for every QMS environment.
Sometimes the SOP Is Wrong — Sometimes the Process Is
When employees do something differently from the procedure, Quality’s first reaction is often that the employee failed to follow the SOP. Maybe. But investigate the other possibility: the SOP no longer reflects the process. Is the written sequence realistic? Does the equipment still operate this way? Are the listed roles, forms, and software still correct? A procedure should control the process — it should not describe an imaginary version of it. If competent employees consistently need to work around a procedure to accomplish the task, that is useful quality information.
The opposite also occurs: the procedure is current, clear, practical, and properly trained, and employees still aren’t following it. Then the organization should determine why — weak supervision, production pressure, normalization of deviation, and inconsistent enforcement are common causes. The point isn’t to assume the document is wrong. The point is to determine which part of the system has broken down.
Workarounds are quality data
A workaround is often an undocumented process-improvement request. Not every workaround is good — some create real quality risk — but a workaround usually means the approved process and the operational need are no longer aligned. Instead of asking only “who authorized this,” also ask “why did employees believe they needed it?” Removing the workaround without addressing the reason it exists often guarantees another one will appear.
For example: employees maintain a local spreadsheet because the approved system takes too long, or technicians keep unofficial reference copies because the controlled document is hard to reach at the point of use. Those behaviors may still need to stop — but removing the workaround without addressing why it exists usually just pushes the same gap somewhere less visible.
Don’t “Fix” It by Coaching Employees for the Audit
When an audit approaches, some organizations focus on telling employees how to answer questions. That misses the point. Don’t tell employees to describe the SOP if the SOP doesn’t describe what they actually do. Instead: observe the work, compare it to the procedure, resolve legitimate discrepancies, update outdated documents, correct inappropriate practices, and train where needed. The goal isn’t to make the employee’s answer match the document for one day — it’s to make the process and the documented system genuinely agree.
Document control should ensure that controlled information stays appropriate, current, and aligned with the process it’s meant to control — not just approved and signed. A perfectly controlled obsolete procedure is still obsolete. That’s why the most useful periodic-review question isn’t “does this SOP need revision?” It’s: “Does this document still describe how this process actually works?”
Five Questions to Test Whether an SOP Matches Reality
Take any important SOP and ask:
- Could an employee actually perform the process exactly as written today?
- Would the people who perform the work describe the process the same way the SOP does?
- Do the forms, software, equipment, and responsibilities referenced in the SOP still match reality?
- Do the records produced by the process support the steps described in the SOP?
- Are there common workarounds that have become “the way we really do it”?
If any answer is no, investigate why. Don’t wait for the external auditor to perform that comparison for you — a well-run internal audit should test whether documented procedures match actual practice before an outside auditor does.
When You Find a Mismatch
| What you find | Possible response |
| SOP outdated, actual process appropriate | Update and control the SOP |
| SOP correct, employee misunderstood | Training / clarification |
| SOP correct, intentional shortcut | Investigate behavior and process conditions |
| Workaround reveals impractical process | Redesign process and update documentation |
| Equipment or software changed | Evaluate change control and documentation impact |
| Same mismatch across employees | Investigate systemic cause |
| Different practices by shift or site | Standardize, or intentionally define differences |
The answer is not automatically “rewrite the SOP” or “retrain the employee.” The response should address why the mismatch exists, and it should be proportional to the risk involved — not every minor difference requires a formal corrective action.
The Takeaway
Athyrion
The SOP is the promise. The process is the proof.
A mature QMS doesn’t create perfect documents that employees work around. It creates controlled processes that employees can realistically follow — and documentation that accurately reflects those processes. Before the next auditor walks onto the floor, ask: if they read our SOP and then watch us work, will they see the same process? If not, you’ve already found something worth fixing, and it’s much better for your internal audit to find it first.
References
ISO 9001 Auditing Practices Group. Guidance on Processes.
ISO 9001 Auditing Practices Group. Evidence Collection.
U.S. Food and Drug Administration. Par Health USA, LLC & Endo USA, Inc. — Warning Letter 722121, April 15, 2026.