Free · Private · No sign-up

Write a clear SOP for anything, in minutes.

Start from 116 professional templates or type any topic or career. Edit the steps, owners and checks, then download Word, PDF or Markdown.

No accountWord and PDFWorks offline
Standard operating procedure
Employee Onboarding
Northwind Studio
CompanyNorthwind StudioSOP IDSOP-HR-EO-01
Version1.0DepartmentPeople and HR
OwnerPeople LeadApproved byHiring Manager
Effective date2026-10-01ReviewEvery 12 months, or after new hire survey scores fall below target for a quarter

1. Purpose

To give every new employee a consistent, well-organised start with the equipment, access, knowledge and relationships they need. Good onboarding shortens time to productivity and reduces early attrition.

2. Scope

Covers all new employees from signed contract to the end of their first 90 days. It does not cover contractors, internal transfers or the formal probation decision, which has its own SOP.

3. Definitions

TermMeaning
PreboardingActivities between contract signature and day one.
Onboarding buddyA peer, not the manager, who helps the new hire with informal questions in the first weeks.
30-60-90 planA written plan of goals and learning for the first three months.
Access provisioningCreating accounts and permissions the role needs, following least privilege.

4. Roles and responsibilities

RoleResponsibilities
People LeadOwns the onboarding checklist, HR paperwork and induction sessions.
Hiring ManagerWrites the 30-60-90 plan, sets first tasks and holds weekly check-ins.
IT AdministratorProvides equipment and system access before day one.
Onboarding BuddySupports the new hire socially and with day-to-day questions.
New HireCompletes required forms, training and acknowledgements on time.

5. Prerequisites, tools and materials

  • Signed contract and completed pre-employment checks
  • Onboarding checklist in [HRIS tool]
  • Role access matrix
  • Equipment stock or supplier order lead time
  • Employee handbook and mandatory policies

6. Procedure

#Step and howOwner
6.1Start the checklist
People Lead opens the onboarding checklist in [HRIS tool] at least 10 business days before the start date and assigns tasks to each owner.
People Lead
6.2Order equipment and access
IT Administrator orders the laptop and peripherals and creates accounts per the role access matrix, ready 2 business days before day one.
IT Administrator
6.3Send the welcome pack
People Lead emails the new hire a week before start with day-one time, location or video link, what to bring, first-week agenda and payroll forms.
People Lead
6.4Prepare the 30-60-90 plan
Hiring Manager writes the plan with clear outcomes for each period and lines up a meaningful first task achievable in week one.
Hiring Manager
6.5Assign a buddy
Hiring Manager picks a buddy from a different reporting line where possible and briefs them on their role.
Hiring Manager
6.6Deliver day one
People Lead runs the welcome session covering company story, values, policies and tools. Hiring Manager meets the new hire for at least 1 hour the same day.
People Lead
6.7Complete mandatory items
New Hire completes tax and bank forms, policy acknowledgements and mandatory training such as security awareness within the first 5 business days.
New Hire
6.8Schedule introductions
Hiring Manager books introductions with key colleagues and cross-functional partners across the first 2 weeks.
Hiring Manager
6.9Hold weekly check-ins
Hiring Manager holds a 30-minute check-in every week for the first 6 weeks, reviewing progress against the plan and any blockers.
Hiring Manager
6.10Run a 30-day pulse
People Lead sends a short survey at day 30 on equipment, clarity of role and support, and follows up on any score below 3 out of 5.
People Lead
6.11Review at 90 days
Hiring Manager reviews the 30-60-90 outcomes with the New Hire and records a summary, feeding into the probation review.
Hiring Manager
6.12Close the checklist
People Lead confirms all tasks are complete and closes the checklist, logging any onboarding improvements raised.
People Lead

7. Quality checks and controls

  • Equipment and access ready before day one
  • All policy acknowledgements recorded within 5 business days
  • Access granted matches the role access matrix, no extra privileges
  • 30-60-90 plan shared by end of day one
  • Payroll details captured before first pay run cut-off

8. Measures of success (KPIs)

MeasureTarget
Day-one readiness95% of hires have working equipment and access on day one
New hire 30-day survey score4 out of 5 or above
90-day retentionAt least [95]%
Mandatory training completion in week one100%

9. Risks and controls

RiskControl or mitigation
Excess access grantedRole access matrix and manager approval for any exception.
Poor first impression causing early exitChecklist with lead times and 30-day pulse.
Missed first payrollPayroll forms in welcome pack and cut-off tracking.
Compliance training skippedSystem tracking with reminders and manager escalation at day 7.

10. Related documents

  • Job Offer and Pre-employment Checks
  • Probation Review
  • Training and Development
  • IT Access Management Policy

11. Revision history

VersionDateChangeBy
1.02026-10-01First issuePeople Lead
NameSignatureDate
Prepared byA. Pandey
Approved byHiring Manager
SOP-HR-EO-01 · Version 1.0 · Uncontrolled when printed. Check the latest version before use.
Standard operating procedure
Refunds and Returns
Northwind Studio
CompanyNorthwind StudioSOP IDSOP-CS-RR-01
Version1.0DepartmentCustomer support and success
OwnerSupport AgentApproved bySupport Lead
Effective date2026-10-01ReviewEvery 12 months, or after a policy or pricing change

1. Purpose

To process refunds and returns quickly and fairly while protecting [Company] from fraud and errors. It makes decisions consistent with the published refund policy.

2. Scope

Covers refunds for subscriptions and services and returns of physical goods requested by customers. It does not cover chargebacks already raised with a card issuer, which go to Finance, or supplier returns.

3. Definitions

TermMeaning
RMAReturn merchandise authorisation number issued before goods are sent back.
Goodwill refundA refund outside policy approved as an exception.
Pro-rata refundRefund for the unused part of a subscription period.

4. Roles and responsibilities

RoleResponsibilities
Support AgentReceives requests, checks eligibility and processes refunds within their limit.
Support LeadApproves refunds above the agent limit and goodwill exceptions.
FinanceApproves refunds above [finance limit], reconciles and handles chargebacks.
Warehouse OperativeReceives, inspects and restocks returned goods.

5. Prerequisites, tools and materials

  • Published refund and returns policy
  • Access to [billing or payment system] with refund permissions by limit
  • Return label or RMA process
  • Refund log

6. Procedure

#Step and howOwner
6.1Log the request
Record order or invoice number, reason code and requested amount in the ticket.
Support Agent
6.2Check eligibility
Check the request against policy: time window, usage, condition of goods and previous refunds on the account.
Support Agent
6.3Try to resolve first
Where the cause is a fixable issue, offer a fix or replacement, but never block a refund the customer is entitled to under policy or law.
Support Agent
6.4Get approval by limit
Agents approve up to [agent limit], Support Lead up to [lead limit], Finance above that. Goodwill exceptions always need Support Lead approval.
Support Lead
6.5Issue RMA for physical goods
Send the RMA number, return address and label with packing instructions within 1 business day.
Support Agent
6.6Inspect returned goods
Inspect within 2 business days of receipt, record condition and photos, and restock, refurbish or write off.
Warehouse Operative
6.7Process the refund
Refund to the original payment method within [5] business days of approval or receipt of goods.
Support Agent
6.8Confirm to customer
Send confirmation with amount, method and expected bank timing, and close the ticket with a reason code.
Support Agent
6.9Reconcile monthly
Match refunds in the payment system to the refund log and accounting records and investigate differences.
Finance
6.10Review reasons
Monthly, report refund volume and top reasons to product and operations for root-cause fixes.
Support Lead

7. Quality checks and controls

  • Every refund above agent limit has recorded approval
  • Refunds go only to the original payment method
  • Returned goods inspected before refund where policy requires
  • Monthly reconciliation signed off

8. Measures of success (KPIs)

MeasureTarget
Refund processing time95% within 5 business days of approval
Refund rateBelow [x]% of revenue
Reconciliation errorsZero unexplained differences
Chargeback rateBelow [0.5]% of transactions

9. Risks and controls

RiskControl or mitigation
Refund fraud or abuseAccount history check and approval limits
Refund to wrong accountOriginal payment method only and no manual bank details by email
Non-compliance with consumer lawPolicy aligned with local consumer rights; check local law

10. Related documents

  • Refund and Returns Policy
  • Customer Complaint Handling
  • Accounts Receivable and Credit Notes
  • Chargeback Handling

11. Revision history

VersionDateChangeBy
1.02026-10-01First issueSupport Agent
NameSignatureDate
Prepared byA. Pandey
Approved bySupport Lead
SOP-CS-RR-01 · Version 1.0 · Uncontrolled when printed. Check the latest version before use.
Standard operating procedure
Security Incident Response
Northwind Studio
CompanyNorthwind StudioSOP IDSOP-IT-SIR-01
Version1.0DepartmentIT and security
OwnerIncident LeadApproved byIT Administrator
Effective date2026-10-01ReviewEvery 12 months, after every SEV1 incident, or after an annual tabletop exercise

1. Purpose

To limit the damage and recovery time of security incidents such as account compromise, malware or unauthorised access. It sets out who leads, how decisions are made and how evidence is preserved.

2. Scope

Covers suspected or confirmed security incidents affecting company systems, devices, accounts or data, including at suppliers that hold company data. It does not cover production outages without a security cause, which follow the Production Incident and On-call SOP.

3. Definitions

TermMeaning
Security incidentAn event that threatens the confidentiality, integrity or availability of systems or data.
Incident LeadThe person with authority to direct the response until closure.
ContainmentActions that stop an incident spreading, such as isolating a device or disabling an account.
SeveritySEV1 critical (active attack or data exposure), SEV2 high, SEV3 contained or low impact.

4. Roles and responsibilities

RoleResponsibilities
Incident LeadDeclares severity, directs actions and approves closure.
IT AdministratorPerforms containment, evidence collection and recovery actions.
Communications OwnerHandles internal updates and any customer or partner messages.
Executive SponsorApproves major decisions such as shutting systems or engaging outside help.
Data Protection LeadAssesses whether personal data is involved and triggers breach notification.

5. Prerequisites, tools and materials

  • Incident contact list with out-of-hours numbers
  • Incident log template and dedicated chat channel
  • Contracts or contacts for external forensic support and cyber insurer
  • Admin access to IdP, endpoint management and logging tools

6. Procedure

#Step and howOwner
6.1Report and log
Anyone who suspects an incident reports it to [security email or channel] immediately. The first responder opens an incident log with time, reporter and what was seen.
IT Administrator
6.2Triage and assign severity
Within 30 minutes, assess scope and assign SEV1 to SEV3. SEV1 incidents page the Incident Lead and Executive Sponsor at any hour.
Incident Lead
6.3Open the response channel
Create a private incident channel and bridge, invite only those needed and record all decisions with timestamps in the log.
Incident Lead
6.4Contain the threat
Isolate affected devices from the network, disable compromised accounts, revoke sessions and tokens and block malicious domains. For SEV1, aim to contain within 4 hours.
IT Administrator
6.5Preserve evidence
Before wiping anything, export relevant logs, take disk or memory images where feasible and record hashes. Keep evidence in restricted storage.
IT Administrator
6.6Assess data impact
Determine whether personal or confidential data was accessed or exfiltrated. If personal data may be involved, start the Personal Data Breach Notification SOP immediately.
Data Protection Lead
6.7Decide on outside help
For SEV1 or where in-house skills are insufficient, the Executive Sponsor decides within 4 hours whether to engage forensic responders and notify the cyber insurer.
Executive Sponsor
6.8Eradicate the cause
Remove malware, close the exploited weakness, patch systems and reset all credentials that may be exposed.
IT Administrator
6.9Recover services
Restore from clean backups where needed, monitor closely for 72 hours for signs of return and confirm normal operation with system owners.
IT Administrator
6.10Communicate
Send internal updates at least every 4 hours for SEV1 and daily for SEV2. Customer or partner messages are approved by the Incident Lead and Executive Sponsor before sending.
Communications Owner
6.11Close and review
Close the incident when contained, eradicated and recovered. Hold a blameless review within 10 business days and track actions to completion.
Incident Lead

7. Quality checks and controls

  • Incident log has timestamps for detection, containment and recovery
  • Evidence preserved before systems are rebuilt
  • Data protection assessment recorded for every incident
  • Post-incident actions have owners and due dates

8. Measures of success (KPIs)

MeasureTarget
Time to triageWithin 30 minutes for 95% of reports
Time to contain SEV1Within 4 hours
Review completion100% of SEV1 and SEV2 reviewed within 10 business days
Repeat incidents from same causeZero within 12 months

9. Risks and controls

RiskControl or mitigation
Evidence destroyed during cleanupMandatory evidence step before eradication
Attacker monitoring company chat or emailUse an out-of-band channel for SEV1 incidents
Regulatory deadlines missedEarly involvement of the Data Protection Lead
Confusion over who is in chargeSingle named Incident Lead per incident

10. Related documents

  • Personal Data Breach Notification
  • Phishing Report Handling
  • Data Backup and Restore Testing
  • Blameless Post-mortem
  • Information Security Policy

11. Revision history

VersionDateChangeBy
1.02026-10-01First issueIncident Lead
NameSignatureDate
Prepared byA. Pandey
Approved byIT Administrator
SOP-IT-SIR-01 · Version 1.0 · Uncontrolled when printed. Check the latest version before use.

Any business task, job or career. The builder finds the closest template or writes a starter draft for your topic.

Three steps, no sign-up.

01

Pick a template or a topic

Search 116 templates by department, or type any topic for a starter draft.

02

Make it yours

Edit roles, steps, owners, checks, KPIs and risks. The preview updates as you type.

03

Download and roll out

Word, PDF or Markdown, with a sign-off block and revision history.

Templates for every part of the business.

Written for startups and growing teams. Fill in the square-bracket placeholders and they are ready to use.

Most used templates.

HREmployee OnboardingPrepares, welcomes and integrates new hires so they are equipped, compliant and productive by day 90.HRRecruitment and Job RequisitionTurns an approved hiring need into a budgeted, well-defined job requisition and a live job advert.SupportRefunds and ReturnsHandles refund and return requests fairly and consistently with clear eligibility checks and approval limits.FinanceCustomer Invoicing and BillingEnsures every billable sale is invoiced accurately, on time and in the right format so cash arrives when expected.FinanceMonth-end CloseCloses the books within a set number of working days with reconciled balances and reliable management accounts.ITSecurity Incident ResponseDetects, contains, investigates and recovers from security incidents in a controlled way, with clear severity levels and communication.ProductProduct ReleaseMoves a tested product version into production in a controlled, communicated way with a clear go or no-go decision.SalesLead QualificationScores and qualifies inbound and outbound leads consistently so sales time goes to buyers who fit and are ready.OperationsPurchase Requests and Purchase OrdersTurns internal buying needs into approved purchase orders so spend is authorised, budgeted and traceable before suppliers deliver.RetailStore OpeningThe store opens on time, safe, clean, stocked and with a verified till float, every trading day.MarketingSocial Media Posting and ModerationKeeps company social channels active, on-brand and safe, with clear rules for replies, moderation and escalation.ProjectsProject KickoffEvery project starts with agreed objectives, scope, roles, plan and governance, documented in a charter.
See all 116 templates

What every SOP includes.

One proven structure, so your procedures look and read the same across the company.

  1. 01Document controlID, version, owner, approver, effective and review dates.
  2. 02Purpose and scopeWhy it exists, who it covers and what it does not.
  3. 03DefinitionsThe terms a new starter might not know.
  4. 04Roles and responsibilitiesWho does what, so every step has an owner.
  5. 05PrerequisitesAccess, tools, forms and training needed first.
  6. 06ProcedureNumbered steps, each with an owner, timing and limits.
  7. 07Quality checksThe control points that catch mistakes.
  8. 08KPIsHow you know the process is working.
  9. 09Risks and controlsWhat can go wrong and what stops it.
  10. 10Related documentsForms, policies and linked SOPs.
  11. 11Revision history and sign-offEvery change, and who approved it.

New to writing SOPs? Read the guide to writing an SOP.

No account

Nothing to sign up for or pay for. No watermark.

Private

Your SOP is saved on this device only. Nothing is uploaded.

Word, PDF, Markdown

Edit it in Word or Google Docs, print it, or paste it into a wiki.

Audit-ready layout

Document control and revision history in the ISO 9001 style.

Quick answers

What is an SOP?

A standard operating procedure is a written, step-by-step description of how a task is done in your business, who does each step and how you check it was done right. It lets anyone trained on it get the same result every time.

Is this SOP maker free?

Yes. All 116 templates, the builder and every download are free, with no account and no watermark.

Can I make an SOP for a topic that has no template?

Yes. Type any topic or job, such as "dental surgery sterilisation" or "night shift handover", choose the kind of procedure, and the builder gives you a complete starting draft to edit.

What format do I get?

A Word file (.docx) you can edit in Word, Google Docs or Pages, a PDF from the print window, Markdown for wikis like Notion or Confluence, and plain text. You can also save the SOP as a file and open it again later.

Is my SOP stored on a server?

No. The builder runs in your browser and saves only on your device. The Word file and PDF are made on your device too.

Do the templates meet ISO 9001?

The layout follows the document-control habits ISO 9001 auditors look for: an ID, version, owner, approver, effective date, review cycle and revision history. Whether your process complies depends on what you write in it, so check the content with whoever owns your quality system.

How long should an SOP be?

Long enough that a trained new starter can follow it without asking. Most good SOPs fit on two to four pages with 6 to 15 steps. Split anything longer into separate SOPs.

Ready to write yours?