What is Standard operating procedure (SOP), and what should an ABA practice owner know before applying it? A standard operating procedure, or SOP, is a controlled instruction for recurring work. It defines the trigger, authorized roles, prerequisites, steps, decisions, evidence, exceptions, escalation, and closure. Owners should connect each rule to its source, test the procedure, train affected roles, control versions, and monitor real use.
An SOP turns a rule into repeatable work
The CASP Organizational Guidelines public overview describes recommendations across ABA business operations, clinical operations, and risk management. CASP sells the detailed guidelines. The SOP structure below is an editorial operating design based on the public frame, rather than a CASP-prescribed template.
Several documents serve different purposes:
| Document | Primary job |
|---|---|
| Policy | States an organizational rule, principle, or required outcome |
| SOP | Explains how authorized roles execute recurring work |
| Checklist | Prompts a user to verify defined items within a procedure |
| Job aid | Supports a task with a quick reference, example, or decision tree |
| Clinical protocol or treatment plan | Directs individualized clinical work under qualified authorship and applicable consent |
| Payer manual or law | Supplies an external requirement whose authority and scope must be interpreted before it enters an SOP |
An SOP cannot create licensure, competence, consent, payer participation, coverage, signature authority, or legal permission. It should name the decision owner for each gate and route uncertainty to that role.
Include the controls needed to execute it
A usable SOP has more than numbered steps. Include:
- title, purpose, scope, definitions, owner, approvers, version, and effective date
- triggering event, eligible records, prerequisites, inputs, and prohibited starts
- authorized roles, segregation of duties, reserved decisions, and required supervision
- ordered actions, decision branches, system fields, deadlines, and approved channels
- source authority, jurisdiction, payer or product, service, effective date, verifier, and evidence location
- completion evidence, reconciliation, exception states, stop conditions, and escalation route
- privacy, security, access, safety, documentation, and retention controls
- training audience, competency check when warranted, release test, monitoring, and review trigger
- change log, superseded version, migration plan, and archive location
Use precise verbs. “Review promptly” leaves the actor, deadline, and result unclear. “The authorization coordinator compares the requested codes, units, dates, provider, and place of service with the current member-specific evidence by noon two business days before submission” can be observed and audited.
Keep source rules separate from practice choices
For each requirement, record whether it comes from law, regulation, contract, payer or program material, professional standard, clinical decision, or internal operating choice. Preserve the source, version, effective date, scope, and verification date. A portal instruction may describe an operational route while a governing contract or law supplies separate authority.
The HHS OIG General Compliance Program Guidance discusses written policies and procedures as part of healthcare compliance infrastructure. OIG explicitly describes the GCPG as voluntary, nonbinding guidance. It is not an ABA procedure, payer rule, or determination that a particular control satisfies the law.
Owners should apply a source-change trigger. When a payer bulletin, law, contract, system, service model, or clinical risk changes, pause affected automation, preserve the prior source, assess impact, approve a revised version, test it, train affected roles, and record the deployment date.
Preserve clinical authorship and client involvement
An operations SOP can verify that required fields and signatures are present, compare administrative values, route inconsistencies, submit through an approved channel, and preserve evidence. Only an appropriately qualified clinician can author or change clinical goals, procedures, dosage, medical-necessity rationale, risk controls, or treatment recommendations within scope. Software should surface a conflict without silently rewriting clinical content.
For BCBA and BCaBA certificants and people who completed an application for either credential, the BACB Ethics Code addresses competence, delegation, confidentiality, documentation, client and stakeholder involvement, informed consent and assent when applicable, collaboration, billing and reporting, continuity, and transitions. The BACB has no separate jurisdiction over organizations or corporations. Organization-wide procedures must cover every role and applicable source.
An SOP should preserve the person's communication access, choice, dissent, accommodations, and safe-stop route. A standardized workflow creates consistent access to individualized decisions; it should not force identical clinical content or treat a family's question as process failure.
Control access, versions, and exceptions
Publish one current, approved version at the point of work. Limit editing rights, record approvals, and keep an immutable change history. Retire outdated copies from active links while retaining them under the applicable record schedule. The effective version for a past action should remain identifiable.
HIPAA supplies a scoped example. The current HHS Security Rule summary says regulated entities must adopt reasonable and appropriate policies and procedures for the Security Rule, make required documentation available to responsible implementers, retain specified documentation for six years after the later of creation or last effect, and update it for environmental or organizational changes affecting electronic protected health information. Those duties concern Security Rule documentation, rather than every ABA SOP or medical record.
Exceptions need a designed state. Record the failed prerequisite, immediate safeguard, authorized exception owner, time limit, evidence, follow-up, and whether work stops. Repeated exceptions should trigger root-cause review instead of becoming an unofficial procedure.
A fictional authorization SOP test
A fictional practice tests a concurrent-authorization submission SOP on 20 synthetic cases. The procedure requires current payer and member evidence, an approved clinical narrative, exact code-unit-date-provider alignment, a separate operations check, permitted submission, and confirmation capture. Clinical changes return to the responsible clinician.
Eighteen cases follow every required step on the first run, reported as 18 of 20. One case stops because the payer source has expired. Another returns because the units conflict with the signed narrative. Both are successful control outcomes because the predefined stop or return path worked. The practice reports 20 of 20 correctly routed, with 18 of 20 first-pass complete, rather than calling the two holds failures.
Useful measures include eligible executions, correct starts, required stops, unauthorized bypasses, first-pass completion, evidence completeness, version mismatches, processing time, overdue exceptions, retraining, and downstream reopenings. State the numerator, denominator, period, source version, exclusions, and expected outcome. A faster process with missing evidence has failed its acceptance test.
Related terms
Sources
- Council of Autism Service Providers, Organizational Guidelines public overview
- U.S. Department of Health and Human Services Office of Inspector General, General Compliance Program Guidance
- Behavior Analyst Certification Board, Ethics Code for Behavior Analysts
- U.S. Department of Health and Human Services, Summary of the HIPAA Security Rule
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni