Are SOPs a legal requirement for pharmacies?
Yes. Section 72A of the Medicines Act 1968 requires the responsible pharmacist to establish, maintain and keep under review procedures designed to secure the safe and effective running of the pharmacy in relation to the sale and supply of medicines, and regulation 4 of the Medicines (Pharmacies) (Responsible Pharmacist) Regulations 2008 defines what those procedures must cover. They must be recorded in writing or electronic form and be available at the premises for inspection at all times.
Regulation 4(1) lists nine matters, and the table below maps each to the SOP documents a typical pharmacy holds against it.
| Regulation 4(1) requirement | What it means in your SOP set |
|---|---|
| (a) Arrangements to secure medicines are ordered, stored, prepared, sold, supplied, delivered outside the pharmacy and disposed of safely and effectively | The core dispensing suite: ordering and receipt, storage and cold chain, dispensing and accuracy checking, sales of P medicines, deliveries, waste and returns |
| (b) Circumstances in which non-pharmacist staff may give advice about medicinal products | Counter protocols, referral criteria, the questions that must reach the pharmacist |
| (c) Identification of staff competent to perform certain tasks | Competence matrix linking each SOP to the named, trained people permitted to perform it |
| (d) Keeping of records about the arrangements in (a) | What gets recorded, where, by whom, retained for how long |
| (e) Arrangements during the responsible pharmacist's absence | What continues, what stops, contact arrangements |
| (f) Steps on a change of responsible pharmacist | Handover, record entries, outstanding-work transfer |
| (g) Complaints procedure | Receipt, investigation, response, the annual report feed |
| (h) Incident procedure | Errors and near misses, immediate actions, recording, review triggers |
| (i) How changes to procedures are notified to staff | Version control and the communication step most SOP sets forget they are legally required to have |
Above this legal floor sit the GPhC standards for registered pharmacies, which expect risks to be identified and managed and services to be delivered safely and effectively. In practice, inspectors read your SOPs as the evidence for both. That is the whole legal picture, and it is deliberately brief here, because the law is not where pharmacies fail.
Why most pharmacy SOPs fail
Most pharmacy SOPs fail because they were written for the inspector, not for the person doing the task. The GPhC's April 2026 review of weight management inspections recorded staff not following their pharmacy's own standard operating procedures on clinical checks before supply among its findings, and 28% of all failed standards in that review fell under safe and effective service delivery. Read plainly: the documents existed, the practice did not match them, and the regulator now checks the gap between the two rather than the existence of the folder.
In our experience building quality systems, including a 56-document quality management system assembled for a GPhC inspection, the failures come in three recognisable forms. First, SOPs written as policy prose: three pages of context and principle wrapped around four actual instructions, unusable mid-task. Second, SOPs written once, usually at opening or after a template purchase, then never owned by anyone, so the procedure describes a workflow the pharmacy stopped using two staff generations ago. Third, SOPs that describe the idealised task rather than the real one, which trains the team that the documents are fiction and guarantees divergence everywhere, not just where divergence is safe.
The fix for all three is the same discipline: write for the moment of use, give every document a living owner and review on triggers rather than guilt. The next three sections take each in turn.
Structure: how to write an SOP someone can follow at 5:45pm on a Friday
The test of structure is whether a competent, tired person can follow the procedure at the busiest moment of the week, because that is when errors happen and when the SOP earns its existence. That test produces rules. One task per SOP: "receiving and storing a fridge line delivery" is a procedure, "cold chain management" is a chapter heading pretending to be one. Actions, not descriptions: every numbered step starts with a verb and one person can perform it. Short: if the procedure runs past two pages, it is probably two procedures.
A working format, refined across many inspections, runs: a one-sentence purpose; scope, stating what this SOP does and does not cover; who may perform this task, linking to the competence matrix required by regulation 4(1)(c); the numbered procedure itself; a "when it goes wrong" section, because exception handling is where safety lives and where most SOPs are silent; the records this task generates and where they go; and a version box with owner, approval, date and next review. That last box is not bureaucracy: it is the audit trail of amendment and review the regulatory regime expects, and it is the first thing an inspector reads.
Two format judgements matter more than templates admit. Checklists beat prose wherever the task is sequential and completeness is the risk, such as date checking, fridge receipt or a responsible pharmacist changeover. Prose with decision points beats checklists wherever judgement is the task, such as counter referral criteria or declining a supply. Forcing judgement tasks into tick boxes produces false assurance, which is worse than no document at all.
Ownership: every SOP needs one name on it
"An SOP without a named owner is already out of date; nobody has noticed yet."
Ownership means one person, named in the version box, who is accountable for the procedure matching reality: not necessarily the author, and not the superintendent for every document, because a superintendent who owns fifty SOPs owns none of them. The workable model is that the superintendent or responsible pharmacist approves, a named team member owns, and ownership sits with the person closest to the task: the senior dispenser owns the dispensing suite, the delivery driver's manager owns the delivery SOP, the service lead owns each clinical service procedure.
Ownership connects directly to the competence requirement. Regulation 4(1)(c) requires procedures to identify which staff are competent for which tasks, and the clean implementation is a competence matrix cross-referencing every SOP against every team member, with sign-off dates, maintained as part of training records. When an inspector asks "who may do this, and how do you know they can", the matrix is the answer; without it, the answer is a shrug in document form.
Ownership also answers the turnover problem, which quietly kills SOP systems. When an owner leaves, their documents must be reassigned as part of leaver process, not discovered ownerless at the next inspection. A quarterly sweep of the version boxes, which takes twenty minutes against a document register, catches orphaned SOPs, lapsed review dates and unapproved local variations before they become findings. It belongs in the quarterly rhythm alongside the checks in our compliance calendar.
Review: cycles that respond to reality, not just the calendar
The regulations require procedures to be maintained and kept under review with an audit trail of changes, and the professional convention, reflected in sector templates and inspection expectations, is a maximum review cycle of two years. Treat that two-year date as the backstop, not the system. A review system that only fires on calendar dates will always be reviewing the wrong documents at the wrong moments, because the events that make an SOP wrong do not consult the calendar.
Four triggers must beat the date. An incident or near miss touching the task: the incident procedure required by regulation 4(1)(h) should end with "review the relevant SOP", and the review should ask whether the procedure was wrong or just unfollowed, which have different fixes. A service change: launching, amending or ceasing any service invalidates its procedures by definition. A regulatory change: the February 2025 distance selling guidance rewrote what a compliant online supply procedure looks like, and pharmacies that did not reopen their SOPs that month were non-compliant with documents that still said "reviewed recently". And staff feedback that a step is unworkable, which is the most valuable trigger and the least used: a team member reporting "we never actually do step four" has just handed you a free inspection finding to fix, and a team that gets thanked for that report keeps making it.
Every review, calendar or triggered, ends the same way: version incremented, change log updated, owner and approver recorded, and the change actively notified to staff, which regulation 4(1)(i) makes a legal requirement rather than a courtesy. Notification means a brief that people acknowledge, not a new PDF placed silently in a folder.
The professional judgement boundary
An SOP is not a substitute for professional judgement, and a system that pretends otherwise is unsafe in both directions. The regulatory position, set out in guidance discussed in the PDA's briefing on responsible pharmacist obligations, is that a pharmacist who diverges from established procedures is professionally accountable for that decision; the Pharmacists' Defence Association argued when the regime was designed that real situations routinely require judgement that no written procedure anticipated, and any superintendent who has covered a Saturday knows they were right.
The defensible standard is not "always follow the SOP" but "follow the SOP or record why not". Build the divergence path into the documents themselves: professional judgement may justify departure, the pharmacist remains accountable and the divergence and rationale are recorded.
This does two things. It makes the SOP honest, which sustains the team's trust in the whole system. And it converts divergence from invisible drift into documented decisions, which is exactly the distinction fitness to practise committees draw between a professional exercising judgement and a pharmacy that ignores its own procedures.
What the boundary does not license is standing divergence. If the same step is being overridden weekly, that is not judgement, it is a wrong procedure generating unrecorded workarounds, and the review trigger above should have fired.
SOPs for new and private services
The SOP gap that catches growing pharmacies is launching new services on the dispensing-era document set. A pharmacy that adds weight management, a travel clinic or online supply has added tasks with no procedures: identity and BMI verification, consultation records, prescriber handoffs, safeguarding refusals, cold chain despatch, refunds. The GPhC's April 2026 review findings, absent risk assessments, no working verification process, staff not following clinical check procedures, are largely descriptions of services that outran their documentation, and the February 2025 distance selling guidance reads, for these purposes, as a specification of what the missing SOPs must contain.
The practical method for any new service is to write the procedure suite before the first patient, walk it end to end with test cases, and treat the first month's divergences as review triggers rather than annoyances. This is also where systems help honestly: procedures that live inside the workflow, a structured assessment the SOP requires, generated by the same platform that captures the record, get followed at a rate paper folders never achieve, because the procedure and the task have become the same object.
A worked skeleton
The table below shows the format applied to a generic task, compressed. It is a skeleton to steal, not a template library.
| Section | Example content |
|---|---|
| Title and reference | SOP-014 Receiving and storing refrigerated deliveries, v3 |
| Purpose | To ensure cold chain medicines are received, checked and stored without breaks in the cold chain |
| Who may perform | Staff signed off on the competence matrix for SOP-014 |
| Procedure | 1. Take the delivery directly to the fridge area, do not leave at the counter. 2. Check the delivery note against items... (numbered verbs to completion) |
| When it goes wrong | Item warm on arrival: quarantine, label "do not use", record on the incident log, inform the RP the same day |
| Records | Fridge receipt log; incident log where applicable |
| Version box | Owner: [name]. Approved: [superintendent, date]. Next review: [date] or on trigger |
Key takeaways
- Pharmacy procedures are legally required under section 72A of the Medicines Act 1968 and regulation 4 of the Responsible Pharmacist Regulations 2008, which defines nine matters they must cover.
- The GPhC's April 2026 review found staff not following their own SOPs among recurring inspection failures, so the regulator checks practice against documents, not the documents alone.
- Write one task per SOP, in numbered actions, with an exception section, at a length usable mid-shift.
- Every SOP needs one named owner close to the task, with a competence matrix linking documents to the staff signed off to perform them.
- The two-year review cycle is a backstop; incidents, service changes, regulatory changes and staff feedback are the triggers that must beat it.
- Notifying staff of SOP changes is itself a legal requirement under regulation 4(1)(i), so version control ends with an acknowledged brief, not a silent file.
- Professional judgement can justify divergence, but the defensible standard is follow or record why not, and repeated divergence means the procedure is wrong.
FAQs
Procedure and practice, one object.
The hardest part of an SOP system is not writing the documents; it is keeping procedure and practice as the same thing. Dataforge PMR embeds the procedure into the workflow itself, with structured clinical assessments, task ownership, version-controlled records and the audit trail generated as the work happens. See it against your own SOP set in 30 minutes.
Book a demo