---
name: sop-gap-audit
description: Audit a draft, stale, inherited, or incident-prone standard operating procedure for Operations Managers. Use when an Operations Manager, BizOps lead, team lead, or process owner needs to turn an SOP, checklist, runbook, process notes, workflow transcript, audit finding, or post-incident lesson into a gap audit with missing steps, unclear owners, exception paths, control gaps, training needs, metrics, rollout risks, and an update backlog.
---

# SOP Gap Audit

## Intended User Role

Operations Manager

## Workflow It Solves

Convert a current or draft SOP into an operations-ready gap audit. The skill helps process owners find what is missing, ambiguous, risky, outdated, unowned, hard to train, or not measurable before the SOP is published, updated, or used for onboarding, compliance, handoff, or incident prevention.

This skill reviews and improves process documentation. It does not approve policies, replace legal/compliance review, enforce controls, operate business systems, or rewrite the final SOP unless the user explicitly asks after the audit.

## Required Inputs

- SOP material: draft SOP, current SOP, checklist, runbook, wiki page, Loom transcript, training notes, process map, ticket history, audit finding, incident retrospective, or stakeholder notes.
- Process context if available: process owner, team, trigger event, terminal state, audience, systems used, handoff teams, approval rules, service-level targets, control requirements, and known pain points.
- Evidence if available: process metrics, cycle-time data, error/rework rates, support tickets, escalations, QA/audit findings, training questions, exception logs, customer/internal complaints, or screenshots.
- Target outcome: publish a new SOP, refresh stale documentation, prepare onboarding, close an audit gap, reduce rework, standardize an exception path, or brief stakeholders.

If inputs are incomplete, proceed with explicit assumptions and gaps. Ask one clarifying question only when the missing detail changes process scope, ownership, compliance risk, or the recommended rollout decision.

## Expected Outputs

Produce an SOP gap audit package with:

- Executive summary: process name, audit purpose, readiness rating, top risks, and recommended decision.
- SOP scope check: trigger, end state, included paths, excluded paths, audience, systems, and owner.
- Gap register: missing, ambiguous, stale, duplicated, risky, unowned, unmeasurable, or untrainable elements.
- Exception-path review: edge cases, overrides, escalations, failure modes, approvals, reversals, and rollback steps.
- Ownership and handoff matrix: activity, accountable owner, supporting teams, approval authority, and unresolved owner gaps.
- Control and evidence review: required checks, proof artifacts, audit trail, privacy/security considerations, and retention needs.
- Metrics and operating signals: cycle time, error rate, rework rate, SLA/SLO, volume, aging, adoption, training completion, and review cadence.
- Update backlog: prioritized fixes with owner, effort, risk, dependency, and acceptance criteria.
- Rollout plan: communication, training, migration from old process, effective date, review date, and escalation channel.
- Paste-ready stakeholder note for the process owner or leadership audience.

## Procedure

1. Identify the process boundary before judging the SOP. Confirm the trigger event, terminal state, unit of work, audience, systems of record, accountable owner, and decision the audit should support.
2. Separate the written SOP from operational evidence. Treat the SOP as the stated process. Treat tickets, metrics, audit findings, incident notes, training questions, screenshots, and operator comments as evidence of how the process actually behaves.
3. Build a quick process skeleton:
   - Trigger and intake.
   - Eligibility or preconditions.
   - Main path.
   - Approvals and controls.
   - Handoffs and system updates.
   - Exception paths.
   - Completion criteria.
   - Evidence retained.
4. Compare each SOP step against the evidence. Mark gaps by type:
   - Missing step: the work happens but is absent from the SOP.
   - Ambiguous step: an operator could reasonably choose different actions.
   - Unowned step: no role is accountable.
   - Control gap: a required check, approval, evidence record, or segregation of duties is unclear.
   - Exception gap: a failure, override, rejection, reversal, escalation, or edge case is missing.
   - Measurement gap: no metric proves the process is working.
   - Training gap: a new operator would not know what good execution looks like.
   - Maintenance gap: no review owner, cadence, change trigger, or version discipline exists.
5. Check ownership and handoffs. Prefer role names over individual names. Flag handoffs where the sender, receiver, SLA, required artifact, or confirmation step is unclear.
6. Check exception paths before polishing the main path. Operational failures often come from refunds, overrides, rejected requests, missing data, delayed approvals, access issues, off-hours handling, system downtime, or urgent/manual paths.
7. Check controls and evidence. Do not invent compliance requirements. If the user provides regulatory, security, privacy, finance, quality, or customer-contract constraints, map each one to a concrete SOP step and evidence artifact.
8. Define operating metrics. Include only metrics the team can realistically collect. Label missing instrumentation, unclear data source, or no baseline as a gap.
9. Assign a readiness rating:
   - Ready: clear scope, owners, controls, exceptions, metrics, and rollout path.
   - Ready with fixes: usable after a small set of specific edits.
   - Needs owner review: major scope, ownership, control, or exception gaps remain.
   - Not ready: process risk is high, source evidence conflicts, or operators would likely execute inconsistently.
10. Prioritize the update backlog by operational risk first, then frequency, customer/business impact, audit exposure, rework reduction, and implementation effort.
11. Draft a stakeholder note that states the readiness decision, top risks, owner asks, and the smallest action set needed before rollout.

## Quality Checks

Before finalizing, verify that:

- The audit names the process boundary and does not silently expand into a different process.
- Each major finding cites a supplied SOP section, note, metric, ticket, audit item, or explicitly labeled absence of evidence.
- The output distinguishes must-fix blockers from nice-to-have documentation improvements.
- Exception paths, handoffs, controls, metrics, training needs, and maintenance cadence are all checked.
- Recommendations name accountable roles or mark ownership as unresolved.
- The backlog includes acceptance criteria, not just vague actions such as "clarify process."
- The readiness rating follows from the findings and does not overstate confidence.
- The stakeholder note is concise, action-oriented, and does not expose sensitive customer, employee, vendor, financial, or security details unless appropriate for the internal audience.

## Example Task

User prompt:

```text
I am the Operations Manager for a B2B SaaS company. Please audit this draft SOP before I publish it to the customer onboarding team.

Process: Enterprise customer onboarding after contract signature.
Draft SOP:
- Sales marks deal closed-won in Salesforce.
- CSM creates onboarding project.
- Implementation schedules kickoff.
- Customer sends technical contacts and SSO requirements.
- Implementation configures workspace.
- CSM sends go-live email.

Context and issues:
- Two recent customers went live before billing codes were set up, so invoices were delayed.
- Security review is required for SSO and SCIM, but the draft does not say who checks it.
- Legal says EU customers need a DPA attached before kickoff.
- Support keeps asking where to find the customer's admin contact.
- There is no standard step for customers who miss kickoff twice.
- Target is kickoff within 5 business days and go-live within 30 days.
- Tools: Salesforce, Asana, Zendesk, Stripe, Google Drive.
```

Expected behavior:

- Produce an SOP gap audit for an Operations Manager.
- Rate readiness as `Needs owner review` or `Ready with fixes`, not fully ready.
- Flag missing billing-code setup, security-review ownership, DPA prerequisite, admin-contact system of record, missed-kickoff exception path, and metric instrumentation.
- Create an ownership and handoff matrix using role names such as Sales, CSM, Implementation, Security, Legal, Billing Ops, and Support.
- Recommend a prioritized update backlog with acceptance criteria and owners.
- Include a rollout note covering training, effective date, review date, and escalation channel.
