Written and maintained by CASRAI Editorial Board
Last updated
A search for “how to write an SOP” answers the wrong question for a clinical trial site or sponsor. The mechanics of SOP authoring — numbering, version control, a review cycle — are generic and covered elsewhere on this site. What a site coordinator standing up a new research office, or a sponsor building out a quality system, actually needs to know is which SOPs a clinical trial operation cannot run without, and what each one has to specify to survive a monitoring visit or a regulatory inspection. This page is that list, worked through in the depth an inspector actually checks: informed consent, adverse event reporting, source documentation, and monitoring visit preparation, plus the site-level operational SOPs that sit around them.
For the mechanics of writing any individual SOP — template structure, numbering conventions, review cycles — see How to Write a Lab SOP: Step-by-Step Template and Guide. This page assumes you already know how to write one and answers the harder question: which ones, covering what, for a clinical research operation specifically.
The Core SOP Set a Clinical Trial Site Needs
Neither ICH E6 nor 21 CFR Part 312 hands a site a numbered list of required SOP titles — GCP is a principles-based framework, not a document checklist. In practice, though, sites and sponsors converge on close to the same set, because each SOP maps to a distinct GCP responsibility that an FDA inspector or sponsor auditor will independently check for. The table below is that convergent set, not an exhaustive one — a site running gene therapy or device trials will layer on protocol-specific procedures, but these are the ones a general clinical-trial site cannot operate without.
| SOP | What it governs | What it’s checked against |
|---|---|---|
| Informed consent process | Who obtains consent, when, using which version of the ICF, and how re-consent is triggered | 45 CFR 46.116 / 21 CFR Part 50; site delegation log |
| Adverse event & SAE/SUSAR reporting | Internal detection-to-escalation timeline, causality/expectedness assessment, sponsor and IRB reporting | 21 CFR 312.32 sponsor timelines; institutional IRB reporting policy |
| Source documentation | What counts as a source document, how entries are made and corrected, ALCOA+ compliance | ICH E6(R2) §8; FDA data integrity guidance |
| Monitoring visit preparation & hosting | Pre-visit readiness checks, staff availability, closing out prior findings | Monitoring plan; sponsor SDV/RBM approach |
| Delegation of authority | Who is authorized to perform which trial-related tasks, and on what basis (training, licensure) | ICH E6(R2) §4.1; investigator accountability |
| Investigational product accountability | Receipt, storage, dispensing, and reconciliation of study drug/device | 21 CFR 312.62; ICH E6(R2) §5.14/4.6 |
| Protocol deviation identification & reporting | What constitutes a deviation vs. a major/reportable deviation, and the IRB reporting path | Institutional IRB policy; protocol |
| Essential document / regulatory binder maintenance | What belongs in the site’s essential documents, and keeping it inspection-ready between visits | ICH E6(R2) §8 essential documents list |
The four sections below — informed consent, AE reporting, source documentation, and monitoring visit prep — are where drafting mistakes are most common, usually because a generic SOP template gets adapted without addressing what’s actually specific to a regulated trial.
Informed Consent SOP
An informed consent SOP that just says “obtain consent before enrollment” doesn’t tell staff anything a monitor or inspector will accept as a controlled process. It needs to specify, concretely:
- Who is authorized to consent — tied directly to the delegation of authority log, not a blanket “the study team.” Obtaining consent is a delegable task; the SOP should state how that delegation is documented and what training (GCP, protocol-specific) is a prerequisite.
- Timing — legally effective consent (or an IRB-approved waiver) must be in place before any research-specific procedure begins, not just before the primary endpoint is assessed. This is the “prospective consent” rule under 45 CFR 46.116, and it’s a common inspection finding when a screening procedure happens to precede a fully executed ICF by even a day.
- The elements the ICF must carry — the required disclosures under 45 CFR 46.116(a) (purpose, procedures, risks/benefits, alternatives, confidentiality, compensation for injury where applicable, voluntariness, and contact information for questions), plus the explicit prohibition on exculpatory language: an ICF cannot include anything that reads as the participant waiving their legal rights or releasing the investigator or sponsor from liability for negligence (45 CFR 46.116(a)(6)).
- Re-consent triggers — when a protocol amendment or new safety information changes the risk/benefit picture materially enough to require re-consenting already-enrolled participants. The SOP should state that the IRB, not the study team, makes this determination, and define the internal process for routing an amendment to the IRB for that call.
- Version control — which ICF version is current, how staff confirm they’re using it, and how superseded versions are retired from active use without being purged from the regulatory file (a superseded, signed ICF is itself an essential document).
- eConsent and translated materials, where applicable — if the site uses an electronic consent platform or non-English materials, the SOP needs its own subsection; these aren’t edge cases anymore at a site running international or decentralized-element protocols.
For the full step-by-step consent process this SOP encodes, see The Informed Consent Process in Clinical Trials: Step by Step and The 4 Principles of Informed Consent.
Adverse Event & SAE/SUSAR Reporting SOP
This is the SOP most likely to have a real regulatory clock attached to it, and the one where an ambiguous internal process directly causes a missed external deadline. It needs to answer four questions explicitly, in order:
- What starts the clock? The site’s own awareness of the event, not the date it’s entered into the EDC system. A common SOP gap is defining the reporting timeline only from data entry, which silently adds days the sponsor’s external deadline doesn’t have.
- Who assesses seriousness, causality, and expectedness, and by when internally? This is a qualified-personnel judgment (typically the investigator or a designated sub-investigator, per 21 CFR 312.32’s expectation of qualified medical review), not an administrative task — the SOP should name the role, not just “study staff.”
- What are the external timelines this feeds? Sponsors must report unexpected fatal or life-threatening suspected adverse reactions (SUSARs) to FDA within 7 calendar days of the sponsor becoming aware, with a complete follow-up report within an additional 8 days; other SUSARs within 15 calendar days (21 CFR 312.32). The site’s internal escalation timeline to the sponsor has to leave enough margin inside that window for the sponsor to actually act — a site SOP that allows 10 days to notify the sponsor of a fatal SUSAR doesn’t leave room for the sponsor to meet its own 7-day FDA obligation.
- What does the site’s own IRB reporting obligation require, separately from the sponsor-to-FDA path? Institutional IRB reporting policies on unanticipated problems and reportable events are set locally and are not identical to the sponsor’s FDA timeline — the SOP needs its own IRB-facing branch, not an assumption that sponsor notification satisfies it.
See Pharmacovigilance in Clinical Research: AE, SAE, and SUSAR Reporting for the full definitional distinctions between AE, SAE, and SUSAR, and Adverse Event Reporting to the IRB: What Must Be Reported, and When for the IRB-specific reporting path this SOP has to route into. The Adverse Event (AE) and SUSAR dictionary entries give the precise definitional boundaries staff need to apply the assessment step consistently.
Source Documentation SOP
Source documentation failures are one of the most common findings in both sponsor audits and FDA inspections, largely because “document it in the source” is treated as self-explanatory when it isn’t. The SOP needs to establish:
- What counts as source at this specific site — paper worksheets, the EHR, a dedicated research chart, or some combination. ICH E6(R2) defines source documents as the original records where trial data first appears (clinical findings, observations, or other trial-related activities), and a site running a hybrid paper/EHR workflow needs to say, in writing, which record is authoritative for which data element.
- ALCOA+ compliance as the working standard, not just a training-slide reference: entries must be attributable, legible, contemporaneous, original (or a certified true copy), and accurate, plus complete, consistent, enduring, and available when needed. The governing principle staff actually apply day to day is simpler: if it isn’t documented, it didn’t happen — and if it needs correcting, it gets corrected, not erased.
- The correction procedure — a single line through the original entry (never obliterated), the correct entry entered alongside it, and the correction initialed, dated, and reasoned. This applies identically to paper and electronic source; an EHR or EDC correction still needs an auditable original-to-corrected trail, which is what the system’s audit-trail function exists to preserve.
- What source data verification will actually check against these records, so staff understand the SOP isn’t an abstract compliance exercise. Note for anyone drafting this section: ICH E6(R2) does not mandate 100% SDV — a risk-based monitoring plan may specify a reduced or targeted SDV approach, and the SOP shouldn’t overstate the requirement as universal 100% verification.
See Source Data Verification (SDV) and ALCOA+ (Clinical Trial Data Integrity Principles) for the full definitions, and Good Documentation Practices for the broader documentation-discipline guide this SOP operationalizes for a single site.
Monitoring Visit Preparation SOP
A site that treats monitoring visit prep as “make sure the coordinator is free that day” is the site that generates repeat findings. A real prep SOP is a checklist the site runs through in the days before every visit, not a one-time onboarding document:
- Regulatory binder / essential documents current and complete against the ICH E6(R2) §8 list — no expired IRB approvals, no missing amendment acknowledgments.
- Every signed ICF on file matches the version that was current when that participant consented, with no unresolved missing signatures or dates.
- Source documents reconciled against the CRF/EDC entries the monitor will spot-check — catching a transcription discrepancy before the monitor does is the entire point of this step.
- Delegation of authority log current, with every listed task actually matching what that staff member’s training record supports.
- Investigational product accountability logs reconciled — dispensing records against remaining inventory, with any discrepancy already explained in writing rather than discovered live.
- All protocol deviations since the last visit logged and, where required, already reported to the IRB — not held for the monitor to surface first.
- Action items from the prior visit’s trip report closed out, with documentation of how, not just a verbal confirmation to the monitor.
See Clinical Trial Monitoring: Visit Types, Source Data Verification & the Monitoring Plan for how sponsors structure visit types and SDV approach, Monitoring Visit Trip Report Writing for what the monitor produces afterward (and therefore what this SOP is implicitly preparing the site to receive well), and Delegation of Authority Log Template for the log this prep step depends on. Site Initiation Visit (SIV) covers the first visit this SOP set has to be fully in place before.
Site-Level vs. Sponsor-Level SOPs
Everything above is written from the site’s operational perspective. A sponsor or CRO maintains a parallel, broader SOP set that a site doesn’t need to author but does need to understand, because site staff operate inside it: CRO oversight and delegated-function accountability, GCP violation classification and CAPA, and protocol deviation escalation at the program level. See Sponsor Oversight of Delegated CRO Functions Under ICH E6(R3) and Common GCP Violations and How to Avoid Them for that sponsor-side layer, and Major Protocol Deviation: What to Do and How to Report It to the IRB for the deviation-reporting SOP’s counterpart at the site.
Keeping the Set Current
An SOP set drafted once at site activation and never revisited is close to as risky as having none — monitors and inspectors both check effective dates and version history, not just current content. Three practical anchors: tie each SOP’s periodic review to the site’s overall quality management cycle rather than an arbitrary annual date picked at random; version-control every revision with an effective date, so a monitoring visit or an inspection can confirm which version governed a given participant’s enrollment; and route staff training on a revised SOP through the same training record that feeds the delegation of authority log, so “trained on current SOP” is demonstrable, not asserted. See Good Clinical Practice (GCP) Certification for how GCP training itself gets documented, and GxP Compliance: What GLP, GCP, GMP, and GDP Actually Require for where this SOP set sits inside the broader GxP quality-system picture.
Frequently Asked Questions
How many SOPs does a clinical trial site actually need?
There’s no regulatory minimum count. The eight in the table above cover the GCP responsibilities every general clinical-trial site has regardless of therapeutic area; protocol-specific requirements (device handling, biospecimen chain of custody, imaging review) add to that base set rather than replacing it.
Do site-level SOPs need sponsor sign-off?
Not typically for a site’s own operational SOPs — those govern how the site runs its own quality system and are the site’s document. What does need to align with the sponsor is the protocol and the monitoring plan; a site SOP that conflicts with what the protocol or CTA requires (an internal AE-escalation timeline too slow for the sponsor’s own FDA obligation, for example) is a real gap even without a formal sign-off requirement.
How often should these SOPs be reviewed?
Sites commonly set a 1–2 year periodic review cycle for stable SOPs, triggered earlier by any relevant regulatory change (an ICH E6(R3) transition, a Common Rule update) or an internal finding that reveals a gap. The review date and outcome should themselves be documented — an SOP with no review history is itself a finding.
What’s the difference between an SOP and a work instruction?
An SOP states the required process and the regulatory basis for it; a work instruction is the granular how-to beneath it (which screen in the EDC system, which specific form). Keeping them separate lets a site update a work instruction (a new EDC interface, for example) without re-issuing and re-training on the whole SOP.
Can one SOP cover multiple protocols at the same site?
Yes, and this is the more common and more maintainable pattern — a single site-level SOP for, say, source documentation or monitoring visit prep, with protocol-specific addenda or work instructions layered on top, rather than a fully separate SOP per protocol.








