Quality · Quality system

Change control

Change control is the formal process by which proposed changes are assessed for quality, validation and regulatory impact, approved, implemented and verified — before the change is made, not after.

In one line

Change control is the formal process by which proposed changes are assessed for quality, validation and regulatory impact, approved, implemented and verified — before the change is made, not after.

Plain-English explanation, then the primary regulation it comes from.

Explanation

Understanding change control

Change control fails in two opposite directions, and the fix differs. In one, everything queues behind a single committee, the business learns to route around it, and changes happen informally. In the other, changes pass on a signature with no real impact assessment, and the site discovers the consequences during a validation review or an inspection. Both look like a working process on paper.

The assessment is where the value sits. A proper one asks what the change does to product quality, to validation status, to qualified equipment, to the regulatory dossier and to any quality agreement with a customer. The dossier question is the one most often missed: a change that is invisible on the shop floor can still require a variation, and implementing it first is a regulatory problem rather than a quality one.

Risk tiering is what makes the process survivable. Minor changes with no quality or regulatory impact should move quickly through a defined route. Significant ones get genuine cross-functional assessment. Publishing which is which, with examples, prevents the tiering from becoming a negotiation each time.

Nothing should be implemented before the assessment that should have preceded it. Temporary and IT changes are the usual exceptions people take, and both are routinely examined — a temporary change that has been in place for a year is not temporary.

What it requiresThe substance of the requirement, stated plainly.
Assessed before implementation
The point of the process is to think before acting, not to document afterwards.
Cross-functional impact
Quality, validation, equipment qualification, regulatory dossier, and quality agreements.
Risk-tiered routing
Minor changes move; significant ones get proper assessment. Publish the criteria.
Covers temporary and IT changes
Both are frequently excluded in practice and frequently examined in inspection.
Closed with verification
Implementation is confirmed, and any validation or documentation follow-up is completed.
Where it goes wrongThe part a definition alone will not tell you.

Common failure modes

  • A single committee as the only route, so urgent changes are made informally and documented later, if at all.
  • Impact assessment that considers quality but not the regulatory dossier.
  • Temporary changes with no expiry, still running a year later.
  • Change closed at implementation, leaving the validation or SOP update outstanding indefinitely.
Primary sourcesAlways verify against the primary source before acting; guidance is revised.

Where this is written down

Related

Read next

Applying this to your site

Knowing the requirement is not the same as closing the gap

If you want to know where your site actually stands against this, the readiness score covers seven quality-system domains in twenty questions, and takes about ten minutes.