
What should be retrained when an SOP changes?
Use a change-impact process to decide who needs communication, targeted learning, practice, reassessment, or documented retraining after an SOP revision.
Read article →
Use a source-to-training change-control process to find affected lessons, decide who needs retraining, and preserve defensible records.
By Alireza Ibrahimi
10 min read
Framework
When an approved SOP changes, the related training should enter change control immediately. That does not mean every edit requires a new course or organization-wide retraining. It means someone must identify the training that depends on the SOP, evaluate what changed, update the affected learning content, make a documented retraining decision, and secure the right approval before the revised training becomes active.
Without that link, a company can maintain a current procedure and an outdated course at the same time. The LMS may show 100% completion while employees are confidently following yesterday's process.
This article presents an original LoreGraph framework for managing that risk. It adapts established ideas from training quality, configuration management, and regulated change control; it is not a universal legal standard. Industry, jurisdiction, contract, and organizational policy may impose additional requirements.
An outdated course is usually not just an editing problem. It is a traceability problem.
The organization may know that SOP 4.2 changed, but not that it supports three courses, seven lessons, two quiz questions, an onboarding checklist, and a supervisor observation form. If those relationships live only in one instructional designer's memory, every document update becomes a scavenger hunt.
The first control is therefore not “review courses more often.” It is a visible chain from an authoritative source to every learning artifact that relies on it. At minimum, the organization should be able to answer:
The CDC Quality Training Standards recommend that subject-matter experts ensure content is accurate, evidence-based, and up to date. They also recommend giving training an expiration date so it can be reviewed, updated, or retired. A review date catches aging content; a dependency link catches a specific source change sooner.
The complete lifecycle is:
Approved source → linked course and lessons → source changes → impact review → affected content updates → reapproval → notification or retraining → historical evidence preserved
This framework borrows the discipline of configuration management. NIST Special Publication 800-128 describes a formal change-control process in which changes are requested, recorded, evaluated for impact, tested, approved, implemented, verified, and closed. The publication concerns information-system security, not workplace training, but its underlying lesson transfers cleanly: a controlled asset should not change without evaluating the downstream consequences and recording the decision. NIST also notes that the rigor can vary with organizational risk and system impact.
Apply that lifecycle to training in seven stages:
The process should also support urgent changes. A company may need to communicate a critical instruction before a full course revision is ready. In that case, issue a controlled interim notice, identify the affected population, record acknowledgement or training as appropriate, and reconcile the formal course as soon as practical. “Emergency” should shorten the path, not erase it.

A dependency register is the practical backbone of this lifecycle. It can begin as a controlled spreadsheet, but it should behave like a small data model rather than a loose list of filenames.
| Record | Minimum information |
|---|---|
| Source | ID, title, owner, version, status, approval date, effective date, next review date |
| Course | ID, owner, risk level, status, current version, approval date |
| Dependency | Source version, course version, affected lesson or artifact, nature of dependency |
| Change | Previous and new source versions, summary or diff, reason, effective date |
| Impact decision | Affected artifacts and people, risk assessment, required action, rationale |
| Release | Updated artifacts, reviewers, approvers, approval dates, publication date |
| Learner action | Notification or retraining assignment, due date, completion and assessment evidence |
Lesson-level mapping takes more effort than course-level mapping, so use risk to decide the depth. A low-risk reference course may only need a source-to-course relationship. A safety, clinical, financial, or compliance course may justify mapping individual source sections to instructions and scored answers.
This is also where reusable sources become more than a content-production convenience. A source should be a managed object with ownership, history, and visible downstream uses. LoreGraph's July 2026 Product Update describes source reuse, versioning, change detection, ownership, and downstream updates as important directions for a stronger knowledge-to-training system.
Do not use word count as the decision rule. A one-word change from “may” to “must” can matter more than a rewritten page of background information.
Evaluate the change across five questions:
Then choose the smallest action that controls the actual risk:
| Change impact | Typical action | Examples |
|---|---|---|
| No learning impact | Record “no training impact” | Formatting, grammar, document owner title |
| Minor clarity change | Update the course; optional notice | Clearer wording that does not alter an action or answer |
| Material knowledge change | Update affected content and notify targeted people | New definition, responsibility, deadline, or system location |
| Material performance change | Targeted retraining with practice or verification | Changed sequence, decision rule, exception, or escalation path |
| High-risk or mandated change | Controlled retraining before affected work, when required | New hazard, safety control, regulated step, or critical prohibition |
These are governance defaults, not legal conclusions. For example, OSHA's Process Safety Management rule applies to covered processes involving highly hazardous chemicals. Within that scope, it requires affected employees to be informed and trained in a change before startup, and it requires affected process information and operating procedures to be updated. The rule also requires a training record identifying the employee, training date, and method used to verify understanding. See 29 CFR 1910.119.
Other rules use different triggers. OSHA's Hazard Communication standard requires training when a new chemical hazard that employees have not previously been trained about enters their work area—not simply whenever any sentence changes. See 29 CFR 1910.1200(h). These examples illustrate why retraining should follow the applicable requirement and the operational impact, not a blanket rule.

Updating a course should create a new version, not erase the old one. The historical record must show what employees were expected to know at a particular time.
Preserve at least:
Retention is not one-size-fits-all. Define it with records management, privacy, legal, compliance, and operational owners. Keep enough information to demonstrate the decision and the learner's applicable training state, but avoid collecting personal data with no clear purpose or retention rule.
Regulated environments show why source approval, training currency, and historical evidence must connect. Current US drug-manufacturing rules, for example, require changes to specified written procedures to be reviewed and approved by appropriate units and require continuing training in current good manufacturing practice and applicable written procedures. See 21 CFR 211.100 and 21 CFR 211.25. Those requirements are industry-specific, but they demonstrate the broader governance problem: an approved procedure, current training, and proof of qualification cannot live in separate worlds.

Consider a hypothetical non-medical home-care agency. Its incident-reporting SOP changes the escalation timing and assigns a new responsibility to the on-call supervisor.
The dependency register shows that the SOP supports a caregiver onboarding course, a supervisor course, and a downloadable job aid. The impact review maps the change to one caregiver lesson, two supervisor scenarios, three scored questions, and the job aid.
The agency does not rebuild every course from scratch. It updates the affected content, retires the invalid questions, tests the revised scenarios, and sends the new versions to the operations owner and training owner for approval.
Its audience decision is also targeted:
This example does not establish what any real agency is legally required to do. It demonstrates the framework's purpose: connect the changed source to affected content and people, then choose evidence proportionate to the change.
Relying only on annual review dates. A course can become wrong the day after its review. Calendar reviews are a backstop; source-change triggers are the faster control.
Overwriting the existing course. This destroys the ability to prove what a learner completed and which instructions were active at the time.
Retraining everyone after every edit. Blanket reassignment creates noise, wastes time, and teaches employees that training alerts are administrative clutter.
Updating lessons but not assessments. A revised lesson paired with an old “correct” answer makes the course internally inconsistent.
Letting AI infer the impact alone. AI may help compare versions and suggest affected passages, but accountable owners should confirm materiality, audience, approval, and retraining decisions.
Treating acknowledgement as understanding. A click may document receipt. It does not show that someone can apply a changed decision or procedure. Match the verification method to the performance risk.
When an SOP changes, ask:
Start with one high-value SOP and build its dependency map. If you cannot trace that document to the lessons, assessments, owners, and learners that rely on it, your first job is not generating more training. It is repairing the chain of trust.
Alireza Ibrahimi
Founder, LoreGraph
Software engineer and Learning Engineering researcher building AI systems that transform workplace knowledge into measurable learning experiences.
Put it into practice
Use LoreGraph to transform process documents into structured lessons, practice, assessment, and measurable progress.
Explore SOP training
Use a change-impact process to decide who needs communication, targeted learning, practice, reassessment, or documented retraining after an SOP revision.
Read article →

Old procedures can survive long after an SOP changes. Learn why this happens and how to replace outdated knowledge, habits, and workplace cues.
Read article →

Diagnose whether a performance gap needs training, process repair, better tools, clearer expectations, management action, or a combined intervention.
Read article →