In this guide
Decide whether the task belongs in an SOP
Choose a recurring, bounded task with a stable purpose: classify non-sensitive feedback, create a first outline from approved notes, reformat a standard update or check a draft against a checklist. The operator should understand the task well enough to recognise a poor result.
Do not standardise a workflow simply because it can be prompted. Exclude high-impact decisions, tasks requiring confidential inputs in an unapproved tool, and work whose quality cannot be verified. Compare the AI-assisted method with a manual or existing alternative before deciding it deserves a procedure.
Write the purpose and boundaries first
At the top of the SOP, state the business purpose, intended user, approved tool and specific output. Add what the workflow does not do. For example: ‘This process drafts a structure for the weekly operating update. It does not approve figures, explain causes or make staffing decisions.’
Boundaries prevent a successful narrow use from quietly expanding into a different task. Name the locations, teams or document types covered. Give the SOP an owner and review date so someone is responsible when the tool, policy or task changes.
Create an input rule
List the information allowed, required and prohibited. Required inputs might include the reporting period, verified figures and open risks. Prohibited inputs might include personal data, credentials, confidential commercial terms or material from a client that has not been approved for the tool.
Tell the operator where the source material should come from and how to check that it is current. If data must be generalised or anonymised, describe the approved method and its limits. ‘Remove names’ is not a complete privacy control when the remaining details can identify a person or business.
Separate the prompt from the procedure
Place the reusable prompt inside the SOP, but do not let it become the whole SOP. The prompt controls the request to the model. The procedure controls the end-to-end work: prepare inputs, run the prompt, inspect the output, correct or reject it, record the result and deliver through the approved channel.
Version the prompt and keep a short change note. A small wording change can alter the output, so test revised prompts against representative fictional examples before replacing the working version.
Make verification observable
Write checks that another competent person can perform. ‘Review carefully’ is not enough. Specify: compare every number with the source; confirm each action has an owner; verify that no explanation appears unless supported; check the output against the required headings; remove content outside the supplied material.
Define who performs the review and whether a second person is required for a sensitive output. The reviewer should be able to see the source, the generated draft and the final version. When corrections are frequent, record the pattern and improve or stop the workflow.
Add stop, escalation and fallback rules
State when the operator must stop: prohibited information is present; the output conflicts with the source; a required fact is missing; the request falls outside the tested purpose; the tool is unavailable; or the consequences are higher than the operator is authorised to accept. Name the person or function to contact.
Include the fallback process. A team should still know how to complete the task without the model. This protects continuity and makes it easier to compare whether the AI workflow continues to add value.
Pilot, train and review
Pilot the SOP with fictional or low-risk examples and a small group who understand the task. Observe where instructions are interpreted differently. Check output quality, total time including review, and the types of correction required. Update the document before wider use.
Train users on the task boundaries and review standards, not only on copying a prompt. Schedule a periodic review and an event-triggered review when the tool, data policy, workflow or risk changes. Retire the SOP when it no longer meets its purpose.
Minimum one-page SOP
Purpose and scope; owner and review date; approved tool; allowed, required and prohibited inputs; preparation steps; versioned prompt; verification checklist; final approver and destination; stop and escalation rules; manual fallback; change log.
Before you move on
- The task is recurring, bounded and suitable for AI assistance.
- Purpose, exclusions, owner and review date are explicit.
- Allowed, required and prohibited inputs are documented.
- The procedure covers preparation, generation, verification and delivery.
- Checks are specific enough for another person to repeat.
- Stop, escalation, fallback and retirement rules are included.
Sources and further reading
These official resources informed the guardrails and practical method in this guide.
This preview uses fictional examples where indicated. Read our editorial approach.
