Registered Office: Paradigm Shift Consulting Ltd,The Old Mill, 9 Soar Lane,Leicester, LE3 5DE, United Kingdom

Paradigm Shift Consulting Logo

0330 133 0920

Paradigm Shift Consulting Logo

Standard Operating Procedures: The Skeleton of your Licenced Operation

If your Quality Management System (QMS) were a house, Standard Operating Procedures (SOPs) would be the joists, hidden from view by design, but essential to keeping everything standing up.

In the world of Good Distribution Practice (GDP), SOPs aren’t optional suggestions; they’re legally required guidance tools that ensure medicines are handled consistently, safely and in compliance from receipt to delivery.

If you ask most Responsible Persons, Quality Managers or Licence Holders what keeps them awake at night, it often comes down to a few common concerns: Documentation controls, procedural gaps, or knowing that an MHRA audit is due. And there’s good reason for that.
In a Good Distribution Practice (GDP) environment, the entire Quality Management System (QMS) rests on the shoulders of clear, controlled, well‑implemented Standard Operating Procedures (SOPs). Without them, the system may technically “exist,” but it’s never truly compliant or inspection‑ready.

Despite their importance, SOPs and document control issues continue to feature prominently in MHRA GDP inspection findings, with Quality Systems identified as the single largest category of deficiencies in official reports.

As an award-winning GDP consultancy of course, we have written about SOPs in the past. However in this refreshed blog, written specifically for those in senior GDP governance roles, we explore why SOPs matter so deeply, how they commonly go wrong, and how you can strengthen yours to ensure compliance, support inspection readiness, and protect patients.

What the EU GDP Guidelines Say

The EU GDP Guidelines (2013/C 343/01) that underpin UK GDP require a robust quality system that covers all aspects of distribution.

Chapter 1.2 of the guidelines state:

“The system for managing quality should encompass the organisational structure, procedures, processes and resources, as well as activities necessary to ensure confidence that the product delivered maintains its quality and integrity and remains within the legal supply chain during storage and/or transport”

Chapter 4.2 goes into further detail, stating:

“Documentation comprises all written procedures, instructions, contracts, records and data, in paper or in electronic form.”

“Documentation should be sufficiently comprehensive with respect to the scope of the wholesale distributor’s activities and in a language understood by personnel. It should be written in clear, unambiguous language and be free from errors.”

“Procedure should be approved signed and dated by the responsible person. Documentation should be approved, signed and dated by appropriate authorised persons, as required”

“Attention should be paid to using valid and approved procedures. Documents should have unambiguous content; title, nature and purpose should be clearly stated. Documents should be reviewed regularly and kept up-to-date. Version control should be applied to procedures. After revision of a document, a system should exist to prevent inadvertent use of the superseded version. Superseded or obsolete procedures should be removed from workstations and archived.”

Although the guidelines don’t spell out exact SOP titles or how to write an SOP, they make it clear:

If it affects the quality or traceability of medicines, it must be clearly documented and controlled in a manner that is unambiguous and easily understood by personnel involved in GDP activities.

This is why SOPs are not “nice-to-have” checklists or “optional”, they are regulatory expectations and evidence of a fully functioning system.

Why SOPs Matter Especially for RPs and Senior Management

As previously mentioned, GDP Guidelines embed written procedures into every major chapter. For those in senior compliance roles, they are obligated to ensure such written procedures exist within the organisation’s QMS and are appropriately trained out to relevant personnel:

Licence Holders

Your WDA(H) licence depends on the organisation having a functionally implemented and documented QMS. An integral part of your responsibilities is to appoint a suitably qualified and experienced Responsible Person and ensure there are adequate resources to manage, monitor and maintain the QMS. Poor QMS management, documentation control, and SOP implementation and review, can lead to deficiencies, sanctions, or in the worst cases, licence suspension.

Responsible Persons (RPs)

It is your statutory duty is to ensure GDP compliance across all activities.

“Procedures should be approved signed and dated by the responsible person.”
(Chapter 4 subsection 4.2)

This includes SOPs. Regulatory authorities assess not only whether procedures exist, but whether they are implemented, understood, effective and periodically reviewed. Weak, unclear or outdated SOPs directly undermine your oversight and can expose you to regulatory criticism.

Quality Managers

You are the architects of operational consistency. SOPs are the structure that ensures processes are done correctly, every time, by everyone. SOPs are the backbone of training, deviation management, change control, and continuous improvement as a Quality Manager, you should be confident in reporting any gaps or errors in written procedures and documentation. A weak SOP framework or poor documentation management will inevitably lead to inconsistent practice, non‑conformances and inspection findings.

Why SOPs Are So Important

Standard Operating Procedures are communication tools that express how your organisation performs GDP related activities, controls risk, trains staff, responds to problems, and ensures quality every day. Pharmaceutical wholesalers are accountable for ensuring that the QMS is adequate for the activities it performs.

Well-written, trained and followed SOPs provide:

Consistency Across Operations

SOPs ensure accuracy and consistency across activities whereby everyone completes the task the same way, every time.  This should be the case whether the procedure relates to receiving products, performing temperature mapping exercises, or handling deviations. Without SOPs, your organisation becomes vulnerable to variability, mistakes and risk.

Evidence for Inspectors

Regulators like the MHRA assess your QMS by reviewing your SOPs and how they’re implemented. If procedures are missing, unclear, out of date or irrelevant to your business model, you can be sure that the inspector will notice and will document this in their findings.

Training & Competence

GDP requires that personnel are trained on the procedures that affect their work:

“Personnel should receive initial and continuing training relevant to their role, based on written procedures and in accordance with a written training programme.”
(Chapter 2, subsection 2.4).

SOPs are the core training reference point. If training doesn’t match procedure content, or staff can’t follow them in practice, that is a regulatory red flag. It is not enough for staff to “read and understand” an SOP. They must be deemed competent in the procedure and able to demonstrate the SOP in practice.

Traceability & Data Integrity

Properly written and controlled SOPs support record-keeping and traceability, from temperature logs to delivery documentation and CAPA actions. Records relating to GDP activities must be retained for a minimum of 5 years, be easily accessible and retrievable.

Standard Operating Procedures A no-nonsense guide 2

Where SOPs Commonly Go Wrong and Common Audit Findings

The MHRA’s own data shows that pharmaceutical Quality Systems, which include procedures and associated documentation, are the most cited noncompliance findings in GDP inspections, consistently ranking highest among inspection findings.

At the 2026 Distributing Pharmaceuticals conference, both Peter Brown, Expert GDP Medicines Inspector and John McNulty, Head of GDP Team 2 of the Medicines and Healthcare products Regulatory Agency reiterated that QMS and documentation records both feature highly in their list recorded deficiencies when inspecting WDA facilities.

Below are some examples of SOP audit findings:

 “Some written procedures and processes were missing.”

MHRA and Paradigm Shift Consulting client audits have repeatedly shown that SOPs are often incomplete or lacking sufficient detail for effective guidance. In Quality System deficiencies, inspectors and auditors have found procedures completely missing from the QMS or combined with other processes, leaving critical activities undocumented.

 “Not enough detail included in some procedures/records.”

Even when SOPs exist, inspectors and auditors frequently note that they lack specific, actionable detail or clear and concise language, forcing staff to interpret what should be prescriptive instructions. This may relate to documentation, change control, or examples where forms referenced in the procedure do not match actual practice. It is a common finding by Paradigm Shift consultants that SOPs lack the work instructions or “How to” guides to carrying out the procedures or processes.

Documentation and record‑keeping issues

Historical MHRA deficiency reports show recurring findings such as lack of formal document control processes, retention gaps, and poor record‑keeping, including failure to maintain complete historic records or ensure traceability in documents that support operations.

These findings underscore the importance of meticulous document control, particularly where SOPs interact with forms, logs and reports.

Standard Operating Procedures A no nonsense guide 4

Work Instructions and How‑To Guides: The devil is in the detail

One of the most effective ways to make SOPs operational and inspection‑ready is through work instructions or how‑to guides as attachments or linked appendices. While the main SOP outlines the procedure, a work instruction provides task‑level clarity on putting the procedure into practice.

For example, an SOP on temperature monitoring might include appendices that show:

    • How to download and interpret data from environmental monitoring systems.
    • How to complete alarm logs and assess excursion records.
    • Which fields on the temperature report must be completed, and how.

This dual‑layered approach keeps the main document functional and lets work instructions evolve more rapidly alongside technology or task updates without compromising procedure integrity.

Document Control: A Core Regulatory Expectation

Arguably the most inspectable part of the SOP lifecycle and one frequently flagged by Paradigm Shift consultants and MHRA inspectors is document control.
Inspectors expect rigorous control of every SOP and associated record.

This includes:

Version Control:

Each SOP must clearly show a version number, date, and history of changes. Versioning allows tracking of updates and ensures staff always use the correct procedure.

Pagination:

All pages should be numbered (e.g., “Page 2 of 8”) so that missing or altered pages are easily detected.

Approval:

SOPs must be formally approved by the Responsible Person before release. This approval confirms that the document is accurate, compliant and implementable from a given date.

Who Can Update SOPs:

Updates must follow a documented change control process. Only qualified owners or delegates should propose revisions, and changes should always be reviewed and approved by the Responsible Person before implementation.

Retention Timeframes:

Current SOPs must be easily accessible to staff. Superseded versions should be retained for a minimum of 5 years after expiry.
“Documents should be retained for the period stated in national legislation but at least five years.”
(GDP Guidelines – Chapter 4, subsection 4.2).
This is to support historical investigation, audit trails and deviation reviews.

Forms, Logs and Reports:

All records linked to an SOP such as work instructions, logs, temperature charts, deviation logs or corrective action forms, must also be version controlled and included in training. If a form changes but the additional training is not delivered, this disconnect alone can be cited as a finding. Taken together, these elements ensure that both procedures and their associated records are transparent, traceable and auditable, exactly what inspectors and auditors look for.

Standard Operating Procedures A no nonsense guide 3

Training: Beyond “Read and Understand”

MHRA’s inspection experience shows that a simple signature on a training sheet does not demonstrate competency in a procedure. Investigators increasingly look for evidence that staff not only read a procedure but can practice it correctly.

Effective training includes:

    • Facilitated walkthroughs of the SOP with subject matter experts
    • Observed practical assessments where staff execute tasks under supervision
    • Scenario‑based evaluations to verify decision‑making using the procedure
    • Function‑specific assessments tailored to roles and responsibilities

Training must align with SOP current versions and any associated work instructions, forms, logs or reports to ensure the QMS operates as intended in daily practice.

Periodic and Triggered SOP Reviews

Document control is more than versioning; it is about continually evaluating whether procedures remain relevant and effective.

GDP requires SOPs to be reviewed periodically, often at pre‑defined intervals (e.g., annually or bi‑annually). Reviews should not be superficial to meet a review deadline, they should be a comprehensive review of the procedure, process, business model and regulatory or legal requirements. 

When an SOP review is triggered by significant changes, all elements of the procedure and regulatory requirements should be included, not just the element that triggered the review. A common trigger for review is repeated deviations related to the same procedure. It is advisable to include SOP reference numbers on your deviation log so you can see at a glance which procedures have been deviated against and if there are ongoing trends or issues relating to that specific procedure.

If multiple deviations reference the same SOP, this indicates the procedure may be unclear or misaligned with practice. Such patterns are a strong signal that updates are needed. Failing to act on a clear deviation trend is itself an inspection risk and can lead to findings under CAPA and quality system governance.

Final Thoughts: SOPs as Leadership Tools

For Quality Managers, Responsible Persons and Licence Holders, SOPs are far more than static documents.

They are the instruments through which you:

    • articulate operational expectations
    • demonstrate oversight and control
    • manage risk proactively
    • build staff competency
    • outline the expectations of conduct within the business
    • ensure accurate and defendable documentation
    • withstand regulatory scrutiny

When SOPs are clear, controlled and aligned with actual practice, your organisation becomes resilient, audit‑ready and operationally robust. When they are not, even well‑intended companies can find themselves facing findings relating to Quality Systems, documentation, training or implementation control.

Remember: Strong SOPs are not just compliant, they are confidence‑building for staff, providing them with the tools to succeed in their roles, and provide reassurance of compliance to leadership and regulators alike.

Help and Support

At Paradigm Shift Consulting, we focus on helping RPs and QMS leads create quality systems where good documentation and comprehensive SOPs become second nature.

We offer a documentation review service including reviewing, amending and creating SOPs with Good Distribution Practice compliant documents, forms, logs and work instructions. We can also provide gap analyses and remediation support to help you close any deficiencies before they escalate into regulatory action.

Are you compliant with 2013/C 343/01? Not sure? Contact us for more information.