Change control
Change control is the formal process by which proposed changes are assessed for quality, validation and regulatory impact, approved, implemented and verified — before the change is made, not after.
Change control is the formal process by which proposed changes are assessed for quality, validation and regulatory impact, approved, implemented and verified — before the change is made, not after.
Plain-English explanation, then the primary regulation it comes from.
Understanding change control
Change control fails in two opposite directions, and the fix differs. In one, everything queues behind a single committee, the business learns to route around it, and changes happen informally. In the other, changes pass on a signature with no real impact assessment, and the site discovers the consequences during a validation review or an inspection. Both look like a working process on paper.
The assessment is where the value sits. A proper one asks what the change does to product quality, to validation status, to qualified equipment, to the regulatory dossier and to any quality agreement with a customer. The dossier question is the one most often missed: a change that is invisible on the shop floor can still require a variation, and implementing it first is a regulatory problem rather than a quality one.
Risk tiering is what makes the process survivable. Minor changes with no quality or regulatory impact should move quickly through a defined route. Significant ones get genuine cross-functional assessment. Publishing which is which, with examples, prevents the tiering from becoming a negotiation each time.
Nothing should be implemented before the assessment that should have preceded it. Temporary and IT changes are the usual exceptions people take, and both are routinely examined — a temporary change that has been in place for a year is not temporary.
- Assessed before implementation
- The point of the process is to think before acting, not to document afterwards.
- Cross-functional impact
- Quality, validation, equipment qualification, regulatory dossier, and quality agreements.
- Risk-tiered routing
- Minor changes move; significant ones get proper assessment. Publish the criteria.
- Covers temporary and IT changes
- Both are frequently excluded in practice and frequently examined in inspection.
- Closed with verification
- Implementation is confirmed, and any validation or documentation follow-up is completed.
Common failure modes
- A single committee as the only route, so urgent changes are made informally and documented later, if at all.
- Impact assessment that considers quality but not the regulatory dossier.
- Temporary changes with no expiry, still running a year later.
- Change closed at implementation, leaving the validation or SOP update outstanding indefinitely.
Where this is written down
- European CommissionEudraLex Volume 4 — EU GMP guidelines
Part I, Chapter 1; Annex 15 for revalidation triggers
- ICHICH Quality guidelines (Q1–Q14)
ICH Q10 change management; ICH Q12 for lifecycle management and established conditions
Read next
Quality management system (QMS)
ReadTechnicalValidation
ReadTechnicalQualification (URS, DQ, IQ, OQ, PQ)
ReadQualityQuality risk management (QRM)
ReadLooking for a definition rather than an explanation? The GMP glossary covers the abbreviations in one line each.
Knowing the requirement is not the same as closing the gap
If you want to know where your site actually stands against this, the readiness score covers seven quality-system domains in twenty questions, and takes about ten minutes.