Business Operations

AI for SOPs, Policies and Institutional Knowledge

Most institutional knowledge lives in a few people’s heads. AI can help turn it into procedures worth following, provided a person owns each document and approves every version.

BYBO Editorial9 min read

FigureHow a procedure stays alive
  1. What people doThe real process, still unwritten
  2. CapturedRecorded walkthroughs and real cases
  3. DraftedA first version in your template
  4. ApprovedOne named person signs it off
  5. MaintainedDated, owned, reviewed on change
Contents
  1. In brief
  2. Why do SOPs stop matching how the work is really done?
  3. How do you get what experienced staff know out of their heads?
  4. What can AI safely draft, refresh or summarise?
  5. How should versions and approvals work?
  6. How do you keep policies from contradicting each other?
  7. How does this help training and onboarding?
  8. How is this different from an internal knowledge assistant?
  9. Where this has limits
  10. Questions
  11. Sources

In brief

  • Written procedures drift from real work. The gap shows up as inconsistency, rework and dependence on two or three people.
  • Ask experienced staff to correct a draft rather than write one. Correcting is faster and produces a better document.
  • AI can draft, refresh, summarise and translate procedures. A named person approves every version before it is published.
  • Version, date and owner should travel with the document, so an answer taken from it can be trusted later.

Why do SOPs stop matching how the work is really done?

Most companies have two procedures for everything. There is the written one, produced for a certification, a client audit or an investor, and there is the real one, which lives in the hands of the people doing the work. The written version was accurate on the day it was signed. Then a portal changed, a tax rule changed, a large customer insisted on a different label, and the real process moved on without telling the document.

The cost is easy to see once you look for it. New joiners learn from whoever sits closest, so two branches handle the same case differently. Nobody can cover for a colleague on leave. When someone with fifteen years of context resigns, a month of notice is not enough to get it out of their head, and the knowledge leaves with them. This is institutional knowledge: valuable, entirely undocumented and completely invisible on a balance sheet.

How do you get what experienced staff know out of their heads?

Asking your best dispatch supervisor to “write the SOP” usually fails. Writing is a separate skill, it competes with a full day of work, and the parts they know so well that they no longer notice them are exactly the parts a newcomer needs. Talking is easier than writing, and correcting a draft is easier still.

  1. Record a thirty-minute walkthrough while they do the task, narrating what they check and why.
  2. Follow one real case end to end, including a messy one, rather than the ideal version.
  3. Capture exceptions as they happen. When someone handles a case unusually, ask that day why.
  4. Harvest what already exists: the long chat answers, the email they resend every week, the notebook checklist.
  5. Interview two people who do the job differently. The disagreement is the interesting part.

AI helps with the tedious middle. A recording becomes a transcript, the transcript becomes a first draft in your own template, and the draft comes with a list of the questions it could not answer: which system the record is created in, who approves the exception, what happens on a holiday. The supervisor then spends twenty minutes correcting a draft instead of a week failing to start a blank page.

What can AI safely draft, refresh or summarise?

Treat it as a drafting assistant with no authority. It can produce, compare and reformat text quickly. It cannot decide what your policy is, and it does not know which of two contradictory documents the business intends to follow.

Drafting tasks and who signs them off
TaskWhat the system doesWho approves
First draftTurn a walkthrough into a procedureThe person interviewed
RefreshMark passages a change affectsThe process owner
SummaryA one-page version for onboardingThe process owner
TranslationA regional-language versionA fluent colleague
Consistency checkList where documents disagreeThe policy owner

Every row ends with a name, and that is the point. NIST’s profile for generative AI notes that organisational use of these systems may warrant additional human review, tracking and documentation, and greater management oversight. Its parent framework asks for policies and procedures that define and differentiate roles and responsibilities for human oversight of AI systems. India’s own AI governance guidelines make a related point, calling for human-in-the-loop mechanisms at critical decision points so that outputs can be reviewed, overridden or supplemented by human judgement before they cause harm. For SOPs that becomes one sentence in your document control note: a generated draft stays a draft until the named approver signs the version.

How should versions and approvals work?

Document control sounds like an audit word, and it is really just five fields. Any team can keep them, and without them nobody can tell which copy is real. If you already work to a quality standard, you will have most of this in place; the discipline matters more than the format.

  • One live version per procedure, with a version number and an effective date.
  • A named owner who maintains it, and a named approver who signed it.
  • A short change note saying what changed and why, in plain words.
  • Superseded versions archived rather than deleted, so you can show what applied in March.
  • A review date, plus a rule that a system change triggers a review immediately.

These fields also pay off later. When a procedure becomes a source for an internal assistant, the version and the review date should travel with any answer taken from it. That is how our Enterprise Knowledge work is set up: source owners keep the content, and the answers show what was used and when it was last reviewed.

How do you keep policies from contradicting each other?

Contradiction is the quiet failure of a growing document set. Each policy is fine on its own. Read together, the branch manual and the finance approval matrix say different things about who may approve what, and staff follow whichever they were shown first. Comparing documents is dull, mechanical work, which makes it a good use for a drafting assistant: it can list every place two documents disagree and quote both.

Run the comparison when any policy changes, and once a quarter across the whole set. Keep the output as a list a person works through, not as automatic edits. The value is in surfacing the disagreement early, while it is still a document problem rather than a customer complaint.

How does this help training and onboarding?

Good procedures make a new joiner useful faster, and they make cover for leave possible. Once the documents are current and owned, a few small things help more than a training platform.

  • A reading path per role, in order, with the current version of each document.
  • A one-page summary of each long procedure, approved by the same owner.
  • Practice questions drafted from the procedure and checked by the owner.
  • A short note to the team whenever a procedure changes, saying what is different.
  • A record of who has read the current version, which also answers audit questions.

Keep the limits honest. Reading a procedure is not the same as being able to follow it under pressure with an annoyed customer on the line. Supervised practice, a buddy for the first weeks and a named person to ask are still the parts that make somebody competent. Documentation makes those conversations shorter; it does not replace them.

How is this different from an internal knowledge assistant?

Two jobs sit side by side and are often confused. This one is about the source: capturing what people know, writing it down, approving it and keeping it current. The other is about the surface: answering everyday questions from those documents, with citations and permissions. How to build an internal knowledge system employees can trust covers the second in detail.

They depend on each other. An assistant sitting on a stale, contradictory document set will answer confidently and wrongly, and your team will stop using it within a month. A beautifully maintained set of procedures nobody can find at the moment they need one is only slightly better. Fix the sources first, then make them easy to reach, and give both halves the same owner so neither becomes somebody else’s problem.

Where this has limits

  • A drafting assistant cannot decide policy. Where two documents disagree, or a rule has a legal consequence, a person has to choose and take responsibility.
  • Generated procedures can be plausible and wrong, especially about steps that exist only inside a system your documents never described.
  • Documentation does not create competence. Judgement under pressure comes from supervised practice, not from reading the current version.
  • Regulated activities may set their own requirements for document control, approval and retention. Treat this as general practice, not compliance advice.
  • If nobody is given time to own a document set, the tooling will not save it. Ownership is a workload question before it is a technology one.

Frequently asked questions

Can AI write our SOPs for us?

It can write the draft, not the procedure. Give it a recorded walkthrough, an old document or a set of real cases, and it will produce something in your template within minutes, along with the questions it could not answer. What it cannot do is decide how your business works. A named owner corrects the draft and a named approver signs the version.

How do we capture knowledge from staff who are about to retire?

Record conversations rather than asking for written notes. Walk through real cases, including the exceptions they handle instinctively, and ask why at each decision point. Turn the transcripts into drafts, let them correct the drafts, and prioritise the tasks only they perform. Start with the work that stops when they are away, not with the easiest procedure to write.

How often should SOPs and policies be reviewed?

On a fixed cycle and on every trigger. A quarterly or half-yearly review suits most procedures, but the more important rule is that any change to a system, a rule or a supplier triggers a review of the documents it touches. Add a review date to each document, and make the owner accountable for it in the same way as any other task.

Who should approve a procedure written with AI?

The same person who would approve one written by hand: the owner of that process, named in the document. Approval should mean they have walked through the steps where the work happens, not that they skimmed a draft. Record who approved it, on what date and what changed, so a later question about which version applied has an answer.

Is it safe to put confidential policies into an AI tool?

It depends entirely on the tool and the agreement behind it. Check where the data goes, whether it is retained, whether it is used for training and who inside your organisation can reach the results. Use company-controlled accounts, keep personal data out of drafts that do not need it, and treat unapproved consumer tools as unsuitable for confidential material.

Where BYBO fits

Sources

  1. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)National Institute of Standards and Technology (NIST)
  2. Artificial Intelligence Risk Management Framework (AI RMF 1.0)National Institute of Standards and Technology (NIST)
  3. India AI Governance Guidelines: Enabling Safe and Trusted AI InnovationMinistry of Electronics and Information Technology, IndiaAI Mission

General information for business readers, not legal, financial or regulatory advice. Examples are illustrative, not client work. Published 11 September 2026.

Bring us one recurring problem.

Talk to BYBO