SOPs and EOPs: What They Are, How They Differ, and How To Write Them

Most organisations have procedures. Fewer have the right kind.
A standard operating procedure and an emergency operating procedure sound similar. Both are formal documents. Both tell people what to do. But they serve completely different purposes, activate under different conditions, and fail in completely different ways when they are poorly written.
This guide explains the distinction between SOPs and EOPs, when each applies, what good ones look like, and how to build them. It also includes ready-to-use templates for four of the most common scenarios in security and facilities management.
For more information on Tasks & Procedures, read our article ‘Standardising Security Procedures: A Guide to Task Management in Operations’.
What is a Standard Operating Procedure (SOP)?
A standard operating procedure is a documented set of steps for carrying out a routine task or process. SOPs govern day-to-day operations. They exist to ensure consistency, reduce reliance on individual judgement, and give teams a reliable reference point for recurring activities.
In security and facilities contexts, SOPs are the backbone of operational delivery. They cover everything from how a guard completes an access control check to how a building manager logs a maintenance fault. The goal is always the same: the same task, done the same way, every time.
| An SOP answers the question: ‘What is the standard process for this activity, and who is responsible for each step?’ |
SOPs are not just useful for training new staff. They are the foundation of accountability. When an incident occurs, an SOP is what allows a team to demonstrate that correct process was followed. Without them, every review becomes a matter of recollection rather than record.
What makes a good SOP?
The most effective SOPs share a set of characteristics:
- Clear scope. The document states exactly what it covers and who it applies to.
- Named responsibilities. Each role is identified. Tasks are not left to ‘staff’ in general.
- Step-by-step logic. Steps follow a natural sequence. There is no ambiguity about what comes next.
- Reporting requirements. The SOP specifies what gets logged, where, and in what timeframe.
- Review schedule. A good SOP has a named review date and a process for updating it.

What is an Emergency Operating Procedure (EOP)?
An emergency operating procedure is a formal document that governs how an organisation responds to an emergency or critical event. Where an SOP describes how to carry out a normal task, an EOP describes what to do when normality has broken down.
EOPs apply in scenarios where standard operations cannot continue: fires, medical emergencies, security threats, civil unrest, severe weather, or any event that poses an immediate risk to people or property. They need to be written in advance, distributed to all relevant staff, and practised regularly.
| An EOP answers the question:‘What do we do right now, and who is responsible for each action, when an emergency is happening?’ |
The key difference in how EOPs are written is urgency. They use clear, directive language. They assign roles by title, not name, because the individual holding a role may change. They include communication protocols, escalation paths, and post-incident recovery steps.
EOPs are also closely linked to your organisation’s incident management framework. In practice, an EOP will trigger activity in your incident management system: logging the event, notifying key personnel, coordinating communications, and generating an audit trail.
What makes a good EOP?
- Scenario-specific. Each EOP covers a defined emergency type. A single ’emergency procedure’ that tries to cover everything is rarely effective.
- Role-based, not name-based. Assign tasks to ‘Security Lead’, ‘Facilities Manager’, ‘First Responder’ — not ‘Dave’.
- Includes communications. Internal alerts, emergency services contact, media handling — all should be covered.
- Covers recovery. Good EOPs do not end at the immediate response. They include debrief, documentation, and return-to-normal steps.
- Tested regularly. An untested EOP is a plan, not a procedure. Drills and tabletop exercises are essential.
SOP vs EOP: a quick comparison
The table below summarises the key differences between the two document types.
| SOP | EOP | |
| Purpose | Guides routine operational tasks | Governs emergency and crisis response |
| Trigger | Triggered by normal operations | Triggered by an emergency or critical event |
| Frequency of use | Regular, day-to-day | Infrequent — activated when needed |
| Audience | Operational and frontline staff | All staff, plus emergency services |
| Tone | Step-by-step process guide | High-urgency response framework |
| Review cycle | Annual or on process change | Post-incident and at minimum annually |
| Example | Slip, trip and fall response | Medical emergency, terrorist threat |
Note on Terminology
Some organisations use the term ‘Emergency Response Procedure’ (ERP) instead of EOP. The structure and purpose are the same. What matters is that your organisation uses consistent terminology and that all staff know the difference between a routine procedure and an emergency one.
How SOPs and EOPs work together
SOPs and EOPs are not alternatives. They are complementary layers of an operational framework.
A robust security operation will have SOPs for its routine activities: access control checks, patrol logs, visitor sign-in, key management, maintenance reporting. It will also have EOPs for its emergency scenarios: fire evacuation, medical emergency, security threat, data breach.
When an emergency occurs, the EOP takes over from normal SOPs. But good operational SOPs often contain triggers that tell staff when to escalate to an EOP. For example, an SOP for handling a suspicious item should include a clear escalation point at which the EOP for a terrorist threat is activated.
That integration between routine operations and emergency response is what makes a security programme genuinely resilient. It is also what Martyn’s Law requires for premises above the standard duty threshold: documented procedures that bridge day-to-day operations and emergency response, maintained and reviewed at a senior level.
Martyn’s Law Note
Venues and premises with an occupancy of 200 or above must have a terrorism protection plan in place under the Terrorism (Protection of Premises) Act 2025. EOPs for threat scenarios are a core component of a compliant protection plan. Enhanced duty premises (800+ occupants) must go further, with documented and tested procedures across a wider range of threat types.

SOP templates
The following templates provide a practical starting point for two common security and facilities scenarios. Adapt each template to your location, staffing structure, and regulatory requirements.
SOP Template 1: Slip, Trip and Fall Incident
| Standard Operating Procedure: Slip, Trip and Fall Incident Response | |
| Document reference | [Your reference number] |
| Version | [e.g. v1.0] |
| Review date | [Date] |
| Document owner | [Role — e.g. Facilities Manager / Safety Officer] |
| Purpose | |
| Objective | To establish a consistent response to slip, trip and fall incidents at [Location], ensuring immediate assistance, accurate reporting, and corrective action to prevent recurrence. |
| Scope | |
| Applies to | All employees, contractors, visitors, and any other persons present at [Location]. |
| Responsibilities | |
| All staff | Report hazards that could lead to a slip, trip or fall. Assist with incident response as directed. |
| First Aider / Safety Officer | Provide first aid, coordinate response, and lead the investigation. |
| Facilities Management | Maintain safe premises and rectify identified hazards. |
| Line Manager / HR | Review incident reports and implement preventive measures. |
| Procedure | |
| Step 1: Immediate response | Assess the scene for your own safety before approaching.Offer reassurance to the injured person. Do not move them unless in immediate danger.Call for medical assistance if required. Use [emergency number] or direct a colleague to call.If trained and safe to do so, administer first aid. |
| Step 2: Report the incident | Notify the Safety Officer or designated person immediately.Log the incident in [your incident management system / occurrence book], including: date and time, location, description of what happened, names of any witnesses, photographs where safe and appropriate. |
| Step 3: Secure the scene | Cordon off the affected area using barriers or warning signs.Preserve any evidence that may assist the investigation. |
| Step 4: Medical follow-up | Accompany the injured person for medical treatment if required.Obtain a written medical report for records. |
| Step 5: Investigation | Conduct a formal investigation to identify the root cause.Review any available CCTV footage.Interview the injured party and witnesses.Document all findings. |
| Step 6: Corrective action | Implement remedial measures to prevent recurrence (repairs, process changes, training).Record all actions taken and assign completion dates. |
| Step 7: Follow-up | Monitor the effectiveness of corrective measures.Provide ongoing support to the injured individual.Review incident patterns quarterly. |
| Documentation | |
| Records required | Incident log, investigation report, corrective action record, medical report (where applicable). All records retained per [your retention policy]. |
| Training | |
| Requirements | All staff: hazard awareness and reporting. First Aiders and Safety Officers: incident response and investigation. |
| Review | |
| Review schedule | Annually, or following any slip, trip or fall incident, or change to premises layout or staffing. |
SOP Template 2: Unauthorised Access
| Standard Operating Procedure: Unauthorised Access Response | |
| Document reference | [Your reference number] |
| Version | [e.g. v1.0] |
| Review date | [Date] |
| Document owner | [Role — e.g. Head of Security / Facilities Manager] |
| Purpose | |
| Objective | To establish a consistent and coordinated response to unauthorised access incidents at [Location], protecting occupants, assets, and premises. |
| Scope | |
| Applies to | All security personnel, facilities staff, and any individual responsible for or affected by a security breach at [Location]. |
| Responsibilities | |
| Security Personnel | Primary responders. Responsible for detection, assessment, containment, and reporting. |
| Facilities Management | Support security measures and assist with access to areas as required. |
| All Staff | Report suspicious behaviour or attempted unauthorised access to security immediately. |
| Procedure | |
| Step 1: Detection | Confirm the breach via alarm, access control system, visual sighting, or staff report.Note identifying features of the individual(s): clothing, build, direction of travel.Report immediately via radio or platform to the control room. |
| Step 2: Containment | Initiate containment measures to limit the individual’s movement.Activate relevant access control zones or gate locks where available.Do not engage physically unless trained and authorised to do so. |
| Step 3: Notification | Notify the Head of Security or Facilities Manager immediately.Contact local law enforcement if the situation poses a risk to occupants or involves a suspected criminal act. |
| Step 4: Engagement | Approach only if it is safe to do so.Communicate clearly and calmly. Instruct the individual to stop and identify themselves.If the individual is aggressive or poses a threat, do not engage. Wait for law enforcement. |
| Step 5: Evacuation (if required) | If the incident escalates to a direct safety threat, activate the relevant EOP (see EOP: Domestic Threat).Follow established evacuation routes and assembly procedures. |
| Step 6: Documentation | Log all details of the incident: time of detection, description of individual(s), actions taken, outcome.Capture CCTV footage and access control logs as evidence.Issue a banning notice if appropriate.Add individual to risk database where relevant. |
| Step 7: Review | Debrief with all involved personnel and law enforcement where applicable.Update access control procedures or site security measures as required. |
| Documentation | |
| Records required | Incident log, evidence record (CCTV, access logs), banning notice (where issued). Retained per [your retention policy]. |
| Training | |
| Requirements | Security personnel: conflict de-escalation, access control systems, reporting procedures. Conducted [annually / on induction]. |
| Review | |
| Review schedule | Annually, or following any unauthorised access incident. |
EOP templates
The following templates cover two emergency scenarios that every security and facilities operation should have documented procedures for. Both templates should be reviewed by your security team, tested through drills, and updated following any activation.
EOP Template 1: Medical Emergency
| Emergency Operating Procedure: Medical Emergency | |
| Document reference | [Your reference number] |
| Version | [e.g. v1.0] |
| Review date | [Date] |
| Document owner | [Role — e.g. Safety Officer / Head of Security] |
| Purpose | |
| Objective | To provide a structured and immediate response to medical emergencies at [Location], ensuring the safety and care of the individual and the coordination of emergency services. |
| Scope | |
| Applies to | All staff, contractors, visitors, and any other persons at [Location] at the time of the emergency. |
| Definitions | |
| Medical emergency | Any sudden illness or injury that poses an immediate risk to a person’s health or life and requires immediate intervention. |
| First Responder | The first trained person to reach the casualty. |
| Emergency Response Team (ERT) | Designated staff trained in emergency response. |
| Procedure | |
| Step 1: Initial assessment | Quickly assess the nature and severity of the emergency.Check your own safety before approaching the casualty (hazards, environment). |
| Step 2: Alert | Call 999 (or the relevant emergency number) immediately if the situation is life-threatening.Report the incident to the control room via [radio / mobile platform].Provide: nature of emergency, exact location (building, floor, room), number of people affected, your name and contact details. |
| Step 3: Immediate response | Administer first aid or CPR if trained and it is required.Do not move the casualty unless there is an immediate danger (fire, toxic hazard).Send a colleague to meet emergency services at the building entrance.Use the on-site emergency medical kit as required. |
| Step 4: Evacuation (if required) | If the emergency requires evacuation of the area, follow the site evacuation procedure.Ensure the casualty is evacuated safely where this is necessary and safe to do. |
| Step 5: Documentation | Log the incident in full once the immediate emergency has been managed.Include: nature of emergency, time of alert, actions taken, outcome, names of responders.Notify HR or Safety Officer as required. |
| Step 6: Debrief and review | Conduct a debrief with all involved parties.Identify any gaps in response: training, equipment, communications.Update this EOP as required based on lessons learned. |
| Equipment | |
| Required resources | First aid kit (locations: [specify]), defibrillator (locations: [specify]), communication devices. |
| Training | |
| Requirements | All staff: basic emergency awareness. First Aiders and ERT: full first aid and incident response training. |
| Review | |
| Review schedule | Annually, or following any activation of this EOP. |
EOP Template 2: Domestic Threat or Terrorist Incident
| Emergency Operating Procedure: Domestic Threat or Terrorist Incident | |
| Document reference | [Your reference number] |
| Version | [e.g. v1.0] |
| Review date | [Date] |
| Document owner | [Role — e.g. Head of Security / Senior Responsible Individual] |
| Purpose | |
| Objective | To establish a coordinated, life-safety response to any domestic threat or terrorist-related emergency at [Location], protecting occupants, minimising harm, and supporting emergency services. |
| Scope | |
| Applies to | All individuals at [Location], including employees, contractors, visitors, and any other persons present during the incident. |
| Definitions | |
| Domestic threat / terrorist incident | Any act or credible threat of violence intended to cause harm or fear, including but not limited to: bomb threats, active shooters, armed assault, or chemical/biological attacks. |
| Lockdown | Securing all rooms and access points. Individuals remain in position, away from windows, silent until an official all-clear is given. |
| Shelter-in-place | Used for chemical or biological threats. Individuals remain inside with windows and doors sealed. HVAC systems disabled. |
| Evacuation | Organised removal of individuals to a pre-designated safe assembly point. |
| Procedure | |
| Step 1: Threat identification | Any individual who identifies or receives information about a potential threat must immediately alert [Security Control Room / Designated Emergency Number].Provide as much detail as possible without compromising personal safety. |
| Step 2: Immediate response | Lockdown: Initiate if the threat involves an active intruder. Secure all access points. Instruct occupants to stay in position, away from windows. Do not open doors until an official all-clear is confirmed.Shelter-in-place: Initiate for chemical, biological or radiological threats. Seal windows and doors. Disable HVAC. Remain inside.Evacuation: Initiate if the threat is external or if instructed by emergency services. Use designated routes only. Do not use lifts. |
| Step 3: Communications | Notify emergency services immediately. Follow their instructions.Use on-site PA, mass notification system, or messaging platform to brief occupants without compromising safety.Designate a single spokesperson for external communications, including media. |
| Step 4: Support to emergency services | Assign a staff member to meet emergency services at the site perimeter.Provide building plans, access information, and known threat details.Follow all instructions from emergency services. |
| Step 5: Post-incident | Conduct a headcount to account for all occupants.Provide first aid to any injured persons until emergency medical services take over.Secure and preserve the scene for law enforcement investigation. |
| Step 6: Recovery and debrief | Hold a structured debrief with all involved staff.Provide psychological support and welfare check-ins for affected individuals.Review this EOP against the actual response and update as required. |
| Regulatory note | |
| Martyn’s Law | This EOP forms part of the terrorism protection plan required under the Terrorism (Protection of Premises) Act 2025 for qualifying venues. Standard duty premises (200-799 capacity) require a documented plan. Enhanced duty premises (800+ capacity) must additionally test procedures through regular exercises. Ensure this document is reviewed by a nominated Senior Responsible Individual. |
| Equipment | |
| Required resources | Communication devices (radio, mass notification system), first aid kit, building plans, emergency contact list, lockdown materials where applicable. |
| Training | |
| Requirements | All staff: awareness of lockdown, shelter-in-place, and evacuation procedures. Security personnel: full response training, including coordination with emergency services. Drills conducted [at least annually]. |
| Review | |
| Review schedule | Annually, or following any activation, significant change to premises, or update to relevant legislation or guidance. |
Keeping your SOPs and EOPs current
A procedure that has not been reviewed is a liability, not an asset. Both SOPs and EOPs should be treated as living documents.
For SOPs, review triggers include: any operational change, a recurring incident of the same type, a staffing restructure, or a change in regulatory requirements. At minimum, SOPs should be reviewed annually.
For EOPs, the review cycle is both time-based and event-based. After any activation, a structured post-incident debrief should be used to identify what worked, what did not, and what needs changing. Tabletop exercises and live drills also generate learning that should feed directly back into the documents.
Under the Building Safety Act 2022, the concept of the ‘golden thread’ requires that safety-related documentation for higher-risk buildings is kept accurate, complete, and accessible. While this framework is specifically designed for higher-risk residential buildings, it reflects a broader principle that applies to all well-managed estates: your procedures are only as good as their currency.
| Linking SOPs and EOPs to your incident management platform: When SOPs and EOPs are integrated into your incident management system, the benefit is immediate. Rather than staff searching for paper documents or outdated files, procedures can be accessed in real time, from any device, during the incident itself. Actions can be logged against the procedure as they happen, generating an automatic audit trail. Post-incident reviews draw on live data rather than recollection. |

A note on digital procedures
Paper-based SOPs and EOPs are a common failure point. They go missing, become outdated without anyone noticing, and cannot be accessed remotely.
Digitising your procedures does not mean making them longer or more complex. It means making them accessible. A security officer on patrol at 2am needs to be able to open the correct EOP immediately, not locate a binder in a control room.
The most effective security operations embed their SOPs and EOPs within their operational platform: version-controlled, role-accessible, and linked directly to their incident management workflow. When a procedure is triggered, it opens automatically. When it is completed, the actions are logged.
That is not technology for its own sake. It is the difference between a procedure that exists and a procedure that works.
To find out more about Zinc’s Task & Procedures system and how it could help your organisation, contact our team today or head to our Task & Procedures page.





















+44 (0)20 3989 4859