How to Build SOPs That Employees Actually Follow
By BiPivot Team · 29 August 2026

Ask any controller at a ₹200-300 crore turnover Indian company where the SOP manual is, and they'll point to a folder. Ask them when it was last opened by someone doing the actual job, and the answer is usually a shrug. That gap — between the document that exists for the auditor and the process that actually runs on the shop floor or in the AP team — is where most governance failures start.
This isn't a documentation problem. It's a design and behavior problem. And for CFOs of mid-sized Indian companies operating under the Companies Act, GST, and TDS regimes simultaneously, it's an expensive one to get wrong.
Why do SOPs exist on paper but not in practice?
Because most SOPs are written the wrong way round: a consultant or internal auditor documents "the process as it should be," circulates it for sign-off, files it, and moves on. Nobody asks the person actually processing 400 vendor invoices a month whether the steps match reality.
Common reasons employees quietly abandon documented procedures include seeing them as impractical, treating the training session as a box-ticking formality, never understanding why a step exists, not knowing the SOP exists at all, or — most damaging — finding that the SOP describes a process the company stopped using two systems ago (SciLife, 2024). The single biggest killer is the last one: the documented procedure no longer reflects the current software, team structure, or business process, so employees quietly build their own workaround and the SOP becomes shelf-ware (source).

In India specifically, three additional pressures compound this: diverse literacy and language levels across a workforce that may span a Coimbatore plant and a Gurugram head office, geographically dispersed teams who never sit in the same training room, and the sheer pace of regulatory change — GST notifications, e-invoicing thresholds, TDS rate revisions — that outdates a written SOP faster than most SMEs can revise it (SPCC Global).
What is actually at stake for a mid-sized company's finance function?
This is not an abstract governance nicety. It shows up directly on the P&L and in board minutes.
Under Section 134(5)(e) of the Companies Act, 2013, directors of listed companies must formally state that internal financial controls are adequate and operating effectively — and this discipline is increasingly expected of private and unlisted mid-sized companies too, particularly ahead of a funding round or IPO (MSN Global). Statutory auditors, under Section 143(3)(i), are separately required to report on whether those internal financial controls over financial reporting actually work in practice — not just whether a document describing them exists (Taxaj). We've covered what "adequate and effective" actually means for IFC design in our Internal Financial Controls Explained piece; SOPs are the operational layer that makes IFC real rather than aspirational.
The MCA has been explicit that it wants corporate governance treated as a business imperative, not a compliance formality — a signal that "we have a policy document" is no longer a sufficient answer in an inspection or diligence process (Rachit Agarwal).
The financial exposure of ignoring this is concrete, not theoretical:
- MCA late filing fees run at ₹100 per day with no upper cap on many forms, and additional Companies Act penalties can add ₹10,000 plus ₹100/day, capped at ₹2,00,000 for the company and ₹50,000 per officer in default (Commenda).
- Late TDS/TCS statement filing attracts a fee of ₹200 per day, capped at the tax amount itself (Commenda).
- Delayed TDS payment under GST draws 18% per annum interest (Jethani Associates).
- At the sector level, RBI alone imposed ₹54.78 crore in penalties across 353 regulated entities in FY 2024-25 for compliance violations (Probe42) — a reminder that regulators are actively enforcing, not just publishing guidance.
Worked example: A Pune-based auto-ancillary company with ₹180 crore revenue missed a TDS deposit deadline by 40 days on a ₹12 lakh deduction because the person who normally filed it was on leave and no one else knew the login credentials or the due-date calendar existed. The SOP said 'Finance Executive – TDS' was responsible, but there was no backup owner named, no checklist, and no calendar reminder built into the process. Interest at 18% per annum on ₹12 lakh for 40 days works out to roughly ₹23,600 — a small number until you multiply it across a dozen similar near-misses a year, plus the reputational cost of an internal audit finding flagged to the board.
How should you actually design an SOP so people use it?
Stop writing SOPs as narrative documents. Start writing them as decision-support tools for the person doing the task under time pressure.
-
Co-create with the process owner, not just the process auditor. The AP executive who processes GRNs daily knows exactly where the current three-way-match process breaks. Interview them before drafting a single line. This single change — involving the people who'll follow the SOP in writing it — is the difference between adoption and quiet resistance.
-
Write for the "why," not just the "what." A step that says "obtain vendor PAN and verify against GST portal before processing payment" gets ignored under deadline pressure. A step that adds "— non-verification risks ITC reversal and a notice under GST reconciliation mismatches" gets followed, because the person understands the consequence, not just the instruction. We've written separately about the specific reconciliation mismatches that trigger ITC risk in our GST Reconciliation Using AI guide — that level of specificity belongs inside the SOP itself, not just in a training slide.
-
Design for the lowest-literacy, most time-pressured user in the chain. If your SOP has to work at a Bhiwandi warehouse and a Bengaluru corporate office simultaneously, use flowcharts and checklists over paragraphs, bilingual instructions where needed, and screenshots of the actual ERP screen rather than generic descriptions of "enter the invoice details."
-
Name a single accountable owner per SOP, plus a named backup. Not a department — a person. "Finance Team" as an owner is how the TDS deadline above got missed. "Rahul Mehta, Senior Executive – Statutory Compliance; backup: Priya Nair" is how it doesn't.
-
Build the trigger into the calendar, not just the document. A GST or TDS SOP that isn't tied to a due-date reminder system is a passive document waiting to be forgotten. Link every compliance SOP to a recurring calendar task with escalation if not marked complete 48 hours before the statutory deadline.
-
Version and date-stamp every SOP, and set a mandatory review trigger. Every regulatory amendment — a GST rate notification, a new e-invoicing threshold, an MCA circular — should trigger a review of every SOP that touches it, not wait for the annual audit cycle to surface the gap.

What does a good finance SOP actually look like in an Indian context?
Take GST input tax credit review as an example, since it's one of the highest-value-at-risk processes in most mid-sized companies. GST risk management genuinely requires structured internal controls covering transaction-level controls, ITC review, and reconciliation discipline, not a one-line policy statement (TaxTMI). CBIC has itself issued a formal SOP for TDS under GST, spelling out specific conditions for deduction and payment — a useful reminder that "SOP" isn't a soft internal concept, regulators themselves think in these terms (Jethani Associates).
A usable version of a monthly ITC-review SOP should specify, at minimum:
- Trigger: 3rd working day of every month, after GSTR-2B is generated
- Owner: Named GST executive, with the AP manager as approver
- Steps: Download GSTR-2B → reconcile against purchase register → flag mismatches above ₹5,000 → follow up with vendor within 5 working days → escalate unresolved mismatches beyond 15 days to the CFO
- Exception path: What to do if a vendor hasn't filed and ITC is at risk of reversal
- Escalation contact: Named person, not a department inbox
If your reconciliation process still runs manually against downloaded Excel sheets, note that AI-assisted reconciliation tools can compress a multi-day manual matching exercise into hours and catch mismatches a tired human eye misses — something we've detailed separately in Common GST Errors AI Can Detect Before They Cost You ITC. The SOP should specify which tool does the first-pass matching and which human does the exception review — that division of labour is what actually gets followed, because nobody wants to manually re-key data they know a system already extracted correctly. If invoice data is still being re-typed from scanned bills, that's also worth fixing structurally before you even finalize the SOP — see OCR for GST Compliance for why treating OCR as a data-entry shortcut alone under-delivers.
How do you train people so the SOP sticks, not just gets acknowledged?
A signed acknowledgment form is not training. It's a legal fig leaf.
Effective SOP training in a mid-sized Indian company should include:
- Role-specific walkthroughs, not one generic session for the whole finance team.
- Scenario-based testing, not just a read-through. Give the trainee a deliberately broken invoice and ask them to apply the SOP to catch the error.
- Regional-language job aids where the operational team's first language isn't English, especially at plant or warehouse level.
- A live "SOP champion" per function — someone whose job explicitly includes flagging when the documented process and actual practice diverge, and feeding that back for a revision, rather than waiting for the annual internal audit to catch it.
The payoff is measurable, not just cultural. SOP-based training can cut onboarding time by 30-50% (IMARC Engineering), which matters directly in finance teams with 15-20% annual attrition at the executive level — a routine reality in most mid-sized Indian companies. Standardized processes built around well-followed SOPs can reduce errors by up to 90% (Beyond the Chaos), and reduced error rates translate into real avoided cost: ₹10,000-₹50,000 saved per incident in inventory or tax-filing errors alone (SPCC Global).
Worked example: A Chennai-based textiles exporter with a 40-person finance and commercial team calculated that onboarding a new AP executive used to take three weeks of shadowing before they could process invoices independently. After rebuilding the invoice-processing SOP with screenshots of their actual Tally screens, a decision-tree for handling GST-exempt versus taxable purchases, and a two-day scenario-based test, onboarding time dropped to roughly 10 working days — a saving of nearly two weeks of a senior executive's time per new hire, on top of fewer downstream reconciliation errors.
How do you keep SOPs from going stale again?
This is the part most companies skip, and it's the part that determines whether your SOP program survives past year one.
Treat every SOP as a living document with an explicit owner and review cadence — not an annual ritual, but a trigger-based one:
- Regulatory trigger: Any GST notification, TDS rate change, or MCA circular relevant to a process should automatically flag every linked SOP for review within 15 days.
- System trigger: Any ERP upgrade, new module go-live, or migration (Tally to a cloud platform, for instance) should force a re-walkthrough of every SOP that references specific screens or fields.
- People trigger: Every SOP revision should be logged with version number, date, and the name of the person who last validated it against actual practice — so an auditor or new hire can trust that the document in front of them is current, not a relic.
This ties directly into the broader governance shift many mid-sized Indian companies are navigating right now, where AI-enabled tools are changing not just how transactions are processed but how controls themselves need to be designed and monitored — a theme we explore in Governance in the Age of AI. An SOP program that doesn't build in a mechanism to catch its own obsolescence will fail exactly the same way the old one did, just more slowly.

A simple, low-cost version of this for a resource-constrained SME: a shared dashboard (even a well-maintained Excel tracker to start) listing every SOP, its owner, last review date, and next review trigger, reviewed for 15 minutes in the monthly finance team huddle. It costs nothing beyond discipline and catches drift before an auditor does.
Is this worth the effort for a company that isn't listed yet?
Yes — and increasingly, this is a diligence and fundraising issue, not just an audit one. Investors and lenders evaluating a mid-sized company for a growth round or debt facility now routinely ask for evidence of documented, followed internal controls, not just financial statements. A company that can demonstrate SOPs are actually used — through revision logs, training records, and low error rates — signals operational maturity that directly supports valuation and reduces due-diligence friction.
SOPs done properly aren't a compliance tax. They're what lets a finance function scale headcount, absorb attrition, and expand into new states or business lines without re-inventing the invoicing process every time someone leaves. The alternative — tribal knowledge held by two or three long-tenured employees — is a resilience risk that becomes obvious the day one of them resigns.
How BiPivot helps
BiPivot works with finance teams at mid-sized Indian companies to redesign SOPs around how work actually happens — mapping current process gaps, building practical decision-trees instead of narrative documents, and linking controls to the compliance calendars and reconciliation tools your team already uses. If you're rebuilding your internal controls framework or preparing for a funding round, explore our approach at bipivot.com.