Knowella

Change Risk Review

Most change reviews are graded on what the change adds: a new hazard, a new control, a new training need. The failure that actually causes harm is usually on the other side of the ledger, the guard removed for access or the check that quietly stops applying once the change lands, and that side of the form is the one teams rush through because nothing about it feels like new work.

KnowSafeAssessmentSAF-064Pinned in navigation43 fields across 5 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 45001 cl.8.1.3
Workspace
KnowSafe
Form type
Assessment
Trigger
Raised alongside every MOC record
Completed by
Change owner with affected areas

The short version

  • A Change Risk Review assesses the risk a proposed change creates before it goes ahead, and is raised alongside every management of change record, not as a substitute for one.
  • It covers two directions deliberately: what the change introduces (new hazards) and what it removes (existing controls weakened or dropped).
  • The template holds 43 fields across 5 sections, with a residual risk band and a change-acceptable decision as the final outcome.
  • Scoring is a change risk band where high is bad, and an unresolved 'Yes' on Critical Control Affected should stop the change, not just flag it.

What this is

What is a Change Risk Review?

What is a Change Risk Review?

It is the risk assessment half of a management of change process: before a change goes ahead, it records what new hazards the change introduces, what existing controls it might weaken or remove, and whether the residual risk is acceptable with or without conditions. It does not replace the MOC record; it is raised alongside it.

How is a Change Risk Review different from a general Risk Assessment?

A Risk Assessment evaluates an existing task or process as it stands. A Change Risk Review is specifically about the delta a proposed change creates, comparing the state before and after, which is why it has separate sections for what the change adds and what it takes away.

Who decides whether a change is acceptable?

The assessor scores the residual risk band and the change owner signs alongside them. Both signatures exist because the person proposing the change and the person judging its risk should not be the same person making the final call alone.

Scope

When is a change risk review required?

This is the risk assessment attached to a specific proposed change, not a standing task risk assessment and not the change record itself. Using it outside a live change produces a review with nothing to review.

Use this template when

  • A management of change record has been opened and needs its risk assessed before approval
  • The change is a new product, recipe change, legal change, customer request or design refresh with a Change Type worth naming
  • A critical control, asset or existing risk assessment might be affected by the proposed change
  • A new record is needed; each one gets its own ID in the form RSK-2026-000
  • You are running the Critical Control and Fatal Risk programme and this review links back to MOC

Do not use it for

  • Job Safety Analysis, which breaks a stable job into steps and sets controls, rather than assessing the risk of a proposed change to it.
  • Risk Assessment, which evaluates a task or process as it currently stands, not the delta a change is about to introduce.
  • Bowtie Analysis, which maps one already-known top event's causes and barriers, rather than the specific hazards a single change creates.
  • Pre-Task Risk Assessment, which is a short crew-level check immediately before work starts, not a documented change approval.
  • Anything outside KnowSafe, which belongs in the workspace that owns the process being changed

Compliance mapping

Which ISO 45001 cl.8.1.3 requirements does this satisfy?

ISO 45001's management of change clause requires organisations to assess OH&S risks before introducing planned changes; the clauses below map that requirement, and its supporting risk-assessment clause, onto the template's sections.

ClauseRequirementWhere it lands
ISO 45001 cl.8.1.3The organisation shall establish a process for the implementation and control of planned changes, including assessment of the OH&S risks of new products, services or processesHeader
ISO 45001 cl.8.1.3(a)New hazards and OH&S risks are identified before the change proceedsWhat the change introduces
ISO 45001 cl.6.1.2.1Hazard identification is ongoing and proactive, including consideration of changes to the organisation, its operations or materialsWhat the change introduces
ISO 45001 cl.8.1.3(b)Legal requirements and other requirements are considered as part of the change assessmentWider effects
ISO 45001 cl.8.1.3(c)Risks arising from the change to existing operations are managed, including where controls are removed or weakenedWhat the change removes
ISO 45001 cl.8.2Emergency preparedness and response arrangements are reviewed where a change could affect themWider effects
ISO 45001 cl.6.1.3Applicable legal and other requirements are determined and kept up to date, including where a change triggers new onesOutcome

What it does not cover

  • Existing Controls Affected, which was answered No while Controls Removed Or Weakened, a field that only opens on Yes, contains a description of a guard being relocated.
  • Critical Control Affected, which was answered No for a change to an asset that Critical Control links directly to, without the reviewer checking the control register first.
  • Compensating Control Added, which reads N/A even though Critical Control Affected is Yes, leaving a weakened critical control with nothing recorded in its place.
  • Residual Risk Band, which is marked Pass while Change Acceptable is Yes with conditions, with no Conditions On Approval text explaining what the conditions actually are.
  • Existing Risk Assessments Need Updating, which is answered Yes with no Risk Assessment record linked, leaving the update as an intention rather than a tracked action.

Global

Change Risk Review requirements by country

Management of change risk assessment is a near-universal management-system expectation, but the weight it carries differs by regime and by whether the site also sits under a major-hazard regulator.

International

ISO 45001:2018, cl.8.1.3

Requires a documented process to assess OH&S risk before implementing planned changes, whether organisational, operational or to products and processes

This is the certifiable baseline. An auditor will ask for evidence a review happened before the change went ahead, not a retrospective write-up after it did.

United States

OSHA Process Safety Management, 29 CFR 1910.119(l)

For covered processes, management of change requires the technical basis, safety and health effects, and necessary time period to be assessed before the change is made

Where the changed process is a covered highly hazardous chemical process, this review is not just good practice under ISO 45001, it is a specific regulatory requirement with its own inspection exposure.

United Kingdom / EU

Management of Health and Safety at Work Regulations 1999, reg.3

Requires a suitable and sufficient risk assessment covering any new or changed work activity

A change that is not assessed before it happens is a live breach the moment work starts under the new arrangement, independent of whether an MOC record exists at all.

How to complete it

How to complete a change risk review, step by step

The fields are straightforward; the judgement calls are about how honestly the removal side is assessed and how the outcome is actually enforced.

Whether the removal side gets the same scrutiny as the addition side

New Hazards Created invites a reviewer to think forward; Controls Removed Or Weakened requires them to think backward, comparing the process as it was against the process as it will be. The second exercise takes more discipline and is where reviews most often go shallow.

What 'compensating control' has to mean when a critical control is affected

Marking Compensating Control Added as Pass should require the new control to be named and verified, not implied by the change description. A critical control weakened without a named, working replacement is a fatal-risk exposure, not a residual risk to accept.

Whether Change Acceptable 'with conditions' is actually enforceable

Conditions On Approval is free text with no structural link to the Action Required field. Deciding whether a condition becomes a tracked action with an owner and a CAPA ID, or stays as a note nobody re-checks, determines whether 'yes with conditions' means anything at implementation.

How far wider effects are traced before sign-off

Affects Adjacent Areas, Affects Emergency Arrangements and Affects Food Safety are each single judgement calls made by the assessor at the point of review, before the change has actually run. Treating them as final rather than provisional is a common source of surprises after implementation.

What auditors find

Most common change risk review findings

These are the failure patterns that recur when a Change Risk Review is checked against the change it actually approved.

FindingClauseWhat fixes it
Controls Removed Or Weakened left blank while the Change Description clearly alters a physical guard or procedural checkISO 45001 cl.8.1.3(c)Require Existing Controls Affected to be justified against a control register lookup rather than answered from memory.
Critical Control Affected answered No without checking the Critical Control pick list against the changed assetISO 45001 cl.6.1.2.1Auto-populate candidate critical controls from the linked Asset so the reviewer confirms or rejects rather than starting blank.
Compensating Control Added marked Pass with no named replacement controlISO 45001 cl.8.1.3(c)Make a text field for the replacement control mandatory whenever Compensating Control Added is Pass or Partial.
Change Acceptable recorded as 'Yes with conditions' with an empty Conditions On Approval fieldISO 45001 cl.8.1.3Block submission when Change Acceptable is 'Yes with conditions' and Conditions On Approval is empty.
Affects Emergency Arrangements marked No for a change to egress routes or fire systemsISO 45001 cl.8.2Cross-check Affects Emergency Arrangements against the Change Type and Change Description for keyword triggers, flagging for a second reviewer.
Existing Risk Assessments Need Updating marked Yes with no Risk Assessment record linkedISO 45001 cl.6.1.2.1Require a Risk Assessment ID whenever this field is Yes, and track it as an open action until the linked record is updated.

Case in point

Case in point: the guard that moved for access

A change was raised to relocate a machine guard six inches to allow a new sensor bracket to fit. The Change Risk Review recorded the sensor as a new control, scored New Hazards Created as None, and marked Existing Controls Affected as No, because nothing about the guard's function had changed on paper.

The relocation reduced the guard's coverage at the pinch point by just enough that an operator's hand could pass underneath during a specific maintenance sequence. The review had correctly assessed the addition and entirely missed the removal, because the question 'did anything get weaker' was never actually asked against the physical change, only against the stated intent of it.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

43fields
5 sections
Reference
SAF-064
Archetype
Assessment
Record ID
RSK-2026-000
Scoring
Change risk band
Direction
High is bad
Singleton
No
Basis
ISO 45001 cl.8.1.3
Links
Links MOC
Tags
Risk, Change
Sections
5
Fields
43
Follow up fields
6
Repeating sections
0
Links out
8
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

12 fields
Text

Review ID*

Generated on save

Auto sequence. Format CRR-2026-0000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Text

MOC ID*

Linked

Links to FDN-020 MOC ID

Date & Time

Review Date*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Text

Change Description*

Single Choice

Change Type*

EquipmentProcessMaterialPeople or organisationLayoutProcedure
Pick List

Asset

OptionalFrom FDN-002 Asset NameFilter: Site matches
Text

Asset ID

OptionalLinked

Format AST-0000.

Links to FDN-002 Asset ID

Pick List

Task

OptionalFrom FDN-004 Task Name
Text

Job ID

OptionalLinked

Format JOB-000.

Links to FDN-004 Job Task ID

What the change introduces

5 fields
Multi Choice

New Hazards Created*

MachineryChemicalElectricalErgonomicFireFood safetyEnvironmentalNone
Text

New Hazard Detail

Optional
Single Choice

Likelihood*

Scored
  • Rare3 pts
  • Possible1 pt
  • Likely0 pts
Single Choice

Severity*

Scored
  • Minor3 pts
  • Moderate1 pt
  • Serious0 pts
Single Choice

Risk Band*

Scored
  • Acceptable4 pts
  • Investigate2 pts
  • Change soon1 pt
  • Change now0 pts

What the change removes

7 fields
Info

The Question People Skip

Changes take things away as well as adding them. A guard removed for access, a step that used to catch errors, a person who used to notice. Ask what protection quietly disappears.

Single Choice

Existing Controls Affected*

Scored
  • No3 pts
  • Yes0 pts
Text

Controls Removed Or Weakened

OptionalShows if Existing Controls Affected equals Yes
Pick List

Critical Control

OptionalFrom FDN-011 Control NameFilter: Site matches
Text

Control ID

OptionalLinked

Format CCTRL-000.

Links to FDN-011 Control ID

Single Choice

Critical Control Affected*

Scored
  • No3 pts
  • Yes0 pts
Single Choice

Compensating Control Added

OptionalScoredShows if Critical Control Affected equals Yes
  • Pass2 pts
  • Partial1 pt
  • Fail0 pts
  • N/Aexcluded from denominator

Wider effects

8 fields
Single Choice

Affects Adjacent Areas*

Scored
  • No3 pts
  • Yes0 pts
Single Choice

Affects Emergency Arrangements*

Scored
  • No3 pts
  • Yes0 pts
Single Choice

Affects Food Safety*

Scored
  • No3 pts
  • Possibly1 pt
  • Yes0 pts
Single Choice

Existing Risk Assessments Need Updating*

NoYes
Pick List

Risk Assessment

OptionalFrom FDN-012 Risk Title
Text

Risk ID

OptionalLinked

Format RSK-2026-00000.

Links to FDN-012 Risk ID

Single Choice

Training Or Briefing Needed*

NoYes
Text

Course ID

OptionalLinkedShows if Training Or Briefing Needed equals Yes

Links to FDN-007 Course ID

Outcome

11 fields
Single Choice

Residual Risk Band*

Scored
  • Pass2 pts
  • Partial1 pt
  • Fail0 pts
  • N/Aexcluded from denominator
Single Choice

Change Acceptable*

Scored
  • Yes3 pts
  • Yes with conditions2 pts
  • No0 pts
Text

Conditions On Approval

Optional
Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Assessor*

Signature

Signature*

Users

Change Owner*

Signature

Second Signature*

SAF-064 · record IDs look like RSK-2026-000 · Links MOC

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The review itself is a single form; what slips is tracing every affected control and condition through to something that actually gets checked.

KnowSafe

Holds the Change Risk Review against the linked MOC and critical control registers, and flags any compensating control marked Pass with no replacement named.

KnowMaintain

Confirms whether a control named in Critical Control is a maintained asset, so 'affected' can be checked against real maintenance state, not the change description alone.

KnowTrain

Tracks the Training Or Briefing Needed outcome through to actual course completion for the crew working the changed process, rather than leaving it as an unchecked Yes.

Ella
Ella

Coordinates the assessor and change owner sign-offs, rolls open conditions and linked actions into one view, and holds every write for approval before it touches a record.

This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.

Meet KnowSafe→

Glossary

Change Risk Review definitions and key terms

Management of change (MOC)
A formal process for reviewing and approving changes to equipment, processes, materials or procedures before they are implemented, to prevent unassessed risk from entering operations.
Residual risk
The risk that remains after existing and any new controls are accounted for, which is what a change acceptable decision is actually judged against, not the raw risk before mitigation.
Critical control
A control identified as essential to preventing or limiting a fatal or catastrophic event, whose removal or weakening requires a compensating control rather than simple acceptance.
Compensating control
A new or strengthened control introduced specifically to offset a critical control that a change has removed or degraded.
Change type
A classification of why the change is happening (new product, recipe change, legal change, customer request, design refresh), used to route the review and anticipate which hazard categories are likely.

FAQ

Frequently asked questions about change risk review

What is a Change Risk Review based on?+

It implements ISO 45001 clause 8.1.3, which requires OH&S risk to be assessed before planned changes are implemented, alongside the hazard identification requirements of clause 6.1.2.1.

What sections does the Change Risk Review contain?+

Five sections: Header, What the change introduces, What the change removes, Wider effects and Outcome. Together they hold 43 fields, 26 of which are required.

How is a Change Risk Review different from the MOC record it's raised alongside?+

The MOC record describes and authorises the change; the Change Risk Review assesses its risk. They are raised together and reference each other, but neither replaces the other.

Which programme does the Change Risk Review belong to?+

It is part of Critical Control and Fatal Risk, and links back to the management of change record that triggered it.

How is a Change Risk Review scored?+

Each new hazard gets a likelihood, severity and risk band; any affected critical control gets its own pass or fail; the whole review closes with a residual risk band and a change-acceptable decision.

Can the Change Risk Review template be changed?+

Yes. The hazard categories, scoring and conditional fields are all editable. Most sites run it as delivered for a cycle before tightening what triggers the removal-side questions.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 45001:2018 — Occupational health and safety management systems, cl.8.1.3
  • OSHA Process Safety Management — 29 CFR 1910.119(l)
  • Management of Health and Safety at Work Regulations 1999 — reg.3

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.