“We have an SOP for that.” We did too. They didn’t match.

“We have an SOP for that.” We did too. They didn’t match.

There’s a particular kind of compliance risk that doesn’t show up on a dashboard. It doesn’t trigger an alert. It lives quietly inside the gap between what your documentation says and what your team is actually doing – and it tends to stay quiet right up until it doesn’t. 

Here’s a version of how it surfaces.

A compliance review is coming up. Leadership does a reasonable thing: they pull the relevant SOPs, confirm they’re current in the system, and verify that training records show completion. Everything looks right on paper. Then someone does a process walkthrough – not a document review, but an actual observation of how the work runs. They find that two steps critical to the documented procedure have been consolidated into one. This wasn’t done maliciously or carelessly. A senior team member found a more efficient approach 18 months ago. It made sense, and it spread. The training record is accurate, but the process people are actually following isn’t the one they were trained to. 

In a manufacturing context, that’s an efficiency problem. In a regulated industry, it’s a finding.

The documentation gap in regulated environments

Regulated industries run on the assumption that documented processes and actual practices are the same thing. Auditors don’t just want to see your SOPs. They want evidence that your people, across your organization, are consistently following them. The question isn’t, “Does this document exist?” It’s, “Does this document reflect reality?”

Most organizations can answer the first question confidently. Fewer can answer the second one honestly. 

Process drift happens in regulated environments the same way it happens everywhere else. Someone else finds a better way. A system changes and the SOP doesn’t get updated. A new hire learns the job from a tenured colleague rather than the documented process, picks up that colleague’s workarounds along with their knowledge, and passes them forward. None of this is negligence. It’s just how organizations work when documentation is treated as a one-time event rather than a living, breathing reflection of practice. 

The risk isn’t in your people doing something wrong. It’s in the fact that what they’re doing and what you’ve documented have quietly become two different things, and you may not know it until someone external points it out. 

What auditors are really looking for

Experienced compliance auditors know that document review and process reality are not the same thing. They ask follow-up questions. They talk to frontline staff. They may even shadow someone doing the work. They notice when the answer a senior leader gives doesn’t quite match the answer someone on the team gives. The gap between those two answers is where audit findings live.

“How do you ensure that your documented procedures reflect current practice?” has a real answer or it doesn’t. “We update our SOPs annually” is not the same as “here’s our process for capturing practice changes and reconciling them against documentation, and here’s how we verify that what’s in the system matches what’s happening on the floor.”

The organizations that do well in audits aren’t necessarily the ones with the documentation library that could fill an actual library. They’re the ones whose documentation and practice are genuinely aligned, and that alignment is easily demonstrated. 

Closing the gap before someone else finds it

The starting point is observation, not document review. Before anything else gets rewritten, think like an auditor. See how the work actually runs, ideally across multiple teams, locations, functions. That observation is a genuine, honest picture of current practice, which is the only way to do a real gap analysis. 

From there, the work is comparative. Where does actual practice match the documentation and where (and why) has it drifted? Some drift represents genuine improvement that the documentation should reflect, while some represents risk that needs to be corrected. The document alone does not tell you which is which. 

The output from this exercise isn’t just updated SOPs. It’s an organization that knows its documentation reflects reality, which is a very different (and ideal) position to be in when an auditor walks through the door. 

If you’re not certain your documented procedures match what your team is actually doing, that’s worth knowing now. 

When did you last compare your documented processes to what’s actually happening – not a document review, but an actual observation?