Critical Ops HubOperations Resource
MCOPS-PRO-020Rev 1.0
MOP / SOP / EOP

MOP vs SOP vs EOP: What’s the Difference?

MOP, SOP and EOP are not three names for the same document. They are three different control types, separated by what triggers them, how much of the activity is known in advance, and who holds authority while they are in use.

By Critical Ops HubPublished 21 August 2026Updated 21 September 20269 min read

Scope note

This article provides general operational guidance. Apply site-specific engineering review, risk controls, manufacturer requirements and applicable regulations before use.

Overview

Choosing the wrong type is an operational problem, not a paperwork problem. A planned intrusive activity run under a standing SOP loses its prerequisite checks, its hold points and its back-out. An emergency handled by searching for a planned procedure loses time that the facility does not have.

This article compares the three, shows how they interact during a single event, and gives a decision route for selecting the right one. It does not teach you how to write or review a MOP — those are separate articles, linked below.

This article provides general operational guidance. Apply site-specific engineering review, risk controls, manufacturer requirements and applicable regulations before use.

The three document types at a glance

The distinction is easiest to hold if you read it as a question of predictability and authority. A MOP controls a specific planned activity with a known start, a known sequence and a defined return to service. An SOP controls an activity that recurs in essentially the same form under normal conditions. An EOP controls a response to an abnormal or emergency condition that was not chosen and cannot be scheduled.

Sites use different names — method statement, operating procedure, emergency response procedure, work instruction — and contracts sometimes impose their own naming. Compare the control content, not the title on the cover sheet. Where site or client terminology differs, map it explicitly in your procedure register rather than assuming equivalence.

Procedure type comparison (illustrative; adapt to site governance)
MOPSOPEOP
PurposeControl one planned activity on live plantControl a repeatable task under normal conditionsControl the response to an abnormal or emergency condition
TriggerApproved, scheduled workRoutine operation or a defined recurring taskAn event: alarm, failure, loss of supply, abnormal condition
PredictabilityKnown scope, known sequence, known end stateKnown and unchangingCondition known in type, not in timing or extent
Typical authority during useNamed approver, with operations retaining release and return-to-service controlCompetent person working within standing authorityShift authority acting under pre-delegated response authority, escalating as defined
Redundancy exposurePlanned, time-bounded and accepted in advanceNormally noneAlready degraded or lost when the document is opened
Review cyclePer activity, plus revision before reusePeriodic, per site governancePeriodic, plus after any activation or drill

MOP: planned, one-off, controlled

A MOP exists because a specific activity will change the state of live plant. It names the assets, the affected systems, the prerequisites that must hold on the day, the numbered sequence, the hold points, the testing and the back-out. Its scope is deliberately narrow: this activity, this plant, this window.

Two features separate a MOP from the other types. First, it accepts a temporary reduction in resilience — the document should state the reduced state, its expected duration and the conditions that end it. Second, it is approved for a particular execution, so the revision issued is the revision executed.

  • Use a MOP when the activity is planned, intrusive or changes the state of a critical system.
  • Use a MOP when redundancy, capacity or protection will be reduced for a period.
  • Use a MOP when the sequence, tests and recovery need to be reviewed and authorised before the work starts.

SOP: repeatable normal operation

An SOP governs work that recurs in the same form: routine rounds, environmental readings, access control handling, alarm acknowledgement and triage, shift handover, routine BMS operations within defined limits. It is written once and used many times by competent people operating inside their standing authority.

The practical test is whether the conditions are stable enough that the same instruction remains valid every time. Where an SOP starts to accumulate site-specific caveats — 'unless the second chiller is on maintenance', 'unless the generator is under test' — that activity has outgrown the SOP and should be controlled by a MOP for the affected occasions.

  • Use an SOP when the task recurs unchanged under normal conditions.
  • Use an SOP when no planned reduction in redundancy or protection is involved.
  • Do not use an SOP to authorise a switching, isolation or configuration change that requires case-by-case review.

EOP: abnormal and emergency response

An EOP is written for conditions you do not choose: loss of utility supply, UPS on battery, generator failure to start, loss of cooling in a data hall, water ingress, fire alarm activation, loss of BMS or EPMS visibility. It is opened when something has already gone wrong, so it is written differently from a planned document — immediate actions first, then stabilisation, then escalation, then recovery and reporting.

Two design rules follow from that. The first actions must be executable from memory or from a single page, because nobody reads a twenty-page document during a first-minute response. And the authority model must be explicit in advance: who acts without waiting, who is notified, and at what point operations, engineering, the client or emergency services are engaged.

Recovery after an event is normally not part of the EOP. Once the facility is stable, planned restoration work — returning plant to normal configuration, replacing failed components, re-proving redundancy — is usually controlled by a MOP prepared for that purpose.

  • Use an EOP when the condition is unplanned and response time matters.
  • Keep the immediate-action set short, unambiguous and available at the point of use.
  • Define escalation by role and threshold, not by individual name.
  • Return to planned control — normally a MOP — once the situation is stable.

How the three interact during a single event

The document types are not alternatives; a single sequence of events can move through all three. The following illustrative sequence is based on a common arrangement and is not a site-specific instruction.

A planned generator load test is controlled by a MOP: prerequisites confirmed, hall load and UPS autonomy verified, hold point acknowledged before transfer, defined stop conditions and a written back-out. During the test, the generator shuts down on an unexpected fault. The activity stops at the stop condition written into the MOP, and the EOP for loss of standby capability governs what happens next — stabilise supply, confirm UPS state, notify operations and the client, record the time. Routine monitoring, rounds and shift handover continue under their SOPs, because normal operation of the rest of the facility has not changed. Once the fault is understood, a new MOP is prepared for the repair and the re-test; the original MOP is not reopened and adapted in the field.

One event, three control types
PhaseGoverning documentWhat it controls
Planned load testMOPPrerequisites, sequence, hold points, stop conditions, back-out
Unexpected generator faultEOPImmediate actions, stabilisation, notification, escalation
Continuing normal operationsSOPRounds, monitoring, alarm handling, shift handover
Repair and re-testNew MOPNew scope, new prerequisites, new review and approval

Choosing the right document type

Work through the questions in order and stop at the first that applies. The route below is a decision aid; the site's governance process remains the authority on which activities require which document.

  • Is the condition unplanned and does it require immediate response? Use the EOP.
  • Will the activity change the state of a critical system, remove redundancy or protection, or require isolation or switching? Use a MOP.
  • Is this the same task, performed the same way, under normal conditions, by someone with standing authority? Use the SOP.
  • Is it routine in principle but the plant is currently degraded, under test, or subject to concurrent works? Control it under a MOP for that occasion.
  • Are you unsure? Escalate the selection decision before work starts — the point of doubt is the cheapest point to resolve it.
Common selection errors
SituationFrequent errorOperational consequenceCorrect control
Routine task performed while redundancy is already reducedRun under the standing SOPNo prerequisite check against the current plant state; reduced state not accepted by anyoneMOP for that occasion
Planned switching described in a contractor method statementTreated as sufficient on its ownSite operational controls — release, hold points, return to service — are absentSite MOP incorporating the contractor method
Emergency response written as a long planned procedureSame format as a MOPImmediate actions buried; delay in the first minutesEOP with a short immediate-action set
Repeated MOP for an activity that now runs unchangedContinue raising one-off MOPsReview effort spent on a stable task; inconsistent executionConvert to an SOP through the site governance process
Recovery work after an eventContinue under the EOPRestoration performed without prerequisites, testing or approvalNew MOP prepared for the restoration

Who owns and approves each

Ownership arrangements vary by organisation and contract, so treat the following as a common pattern rather than a rule. MOPs are typically drafted by the party performing the work — in-house engineering or a contractor — then reviewed technically and operationally and approved by a named site role before issue. SOPs are usually owned by the operations function, because they describe how the site runs. EOPs are normally owned jointly by operations and engineering, with input from safety and, where relevant, the client, because they commit the site to a response.

Whatever the arrangement, three things should be unambiguous in the register: who may approve each type, what the review interval is, and which revision is current. Procedure sets fail more often through document control than through technical content — superseded revisions in circulation, procedures that reference decommissioned assets, and EOPs that have never been walked through after a change to the plant they cover.

  • Record the approver by role for each document type, not by individual.
  • Set a review interval for SOPs and EOPs, and review EOPs after every activation or drill.
  • Withdraw superseded revisions from the point of use, not only from the document system.
  • Re-check procedures against the asset register after any change to the plant they cover.

Key takeaways

  • 01MOP, SOP and EOP differ by trigger, predictability and authority — not by formatting.
  • 02A planned change to the state of live plant needs a MOP, even if the task itself is routine.
  • 03An SOP is valid only while conditions are normal; degraded plant moves the activity to a MOP.
  • 04An EOP must be usable in the first minute: short immediate actions and pre-defined escalation.
  • 05One event can pass through all three document types; recovery after an event belongs in a new MOP.
  • 06Document control — approver, review interval, current revision — fails more often than technical content.

Frequently asked questions

Is a MOP the same as a method statement?
Not necessarily. A contractor method statement describes how that contractor intends to perform the work. A site MOP controls the activity within the facility's operational controls — release, plant state, prerequisites, hold points, stop conditions and return to service. A method statement is often an input to a MOP rather than a replacement for it.
Can one document be both a MOP and an SOP?
It is better to keep them separate. If a task is stable enough to run under standing authority, control it with an SOP. If a particular occasion carries additional exposure — degraded plant, concurrent works, isolation — raise a MOP for that occasion and reference the SOP where the technical method is unchanged.
Who writes EOPs?
Practice varies. EOPs are commonly developed by operations and engineering together, with safety and client input where relevant, because they commit the site to an immediate response and to an escalation path. Approval authority should be defined in the site's procedure governance.
How often should procedures be reviewed?
Set the interval in site governance rather than assuming a universal figure. In addition to any periodic review, revise a procedure after a plant or configuration change, after an activation or drill, after an execution that exposed a defect in the document, and when referenced assets or roles change.

Free resource

MOP Review Checklist

Review scope, prerequisites, step quality, hold points and recovery arrangements before approval.

Get the checklist

Professional toolkit

MOP / SOP / EOP Toolkit

Controlled templates and review tools for maintenance, standard operations and emergency response procedures.

US$59

Coming soon — not available for purchase

View product

Continue reading

Related articles

MOP / SOP / EOP6 min read

How to Write a Data Centre MOP

A practical process for writing a data centre method of procedure: scope, affected systems, prerequisites, risk, sequence, hold points, testing, rollback, approval and close-out.

Read article

Back to the MOP / SOP / EOP pillar →