What this is
What is a Change Risk Review?
What is a Change Risk Review?
It is the risk assessment half of a management of change process: before a change goes ahead, it records what new hazards the change introduces, what existing controls it might weaken or remove, and whether the residual risk is acceptable with or without conditions. It does not replace the MOC record; it is raised alongside it.
How is a Change Risk Review different from a general Risk Assessment?
A Risk Assessment evaluates an existing task or process as it stands. A Change Risk Review is specifically about the delta a proposed change creates, comparing the state before and after, which is why it has separate sections for what the change adds and what it takes away.
Who decides whether a change is acceptable?
The assessor scores the residual risk band and the change owner signs alongside them. Both signatures exist because the person proposing the change and the person judging its risk should not be the same person making the final call alone.
Scope
When is a change risk review required?
This is the risk assessment attached to a specific proposed change, not a standing task risk assessment and not the change record itself. Using it outside a live change produces a review with nothing to review.
Use this template when
- A management of change record has been opened and needs its risk assessed before approval
- The change is a new product, recipe change, legal change, customer request or design refresh with a Change Type worth naming
- A critical control, asset or existing risk assessment might be affected by the proposed change
- A new record is needed; each one gets its own ID in the form RSK-2026-000
- You are running the Critical Control and Fatal Risk programme and this review links back to MOC
Do not use it for
- Job Safety Analysis, which breaks a stable job into steps and sets controls, rather than assessing the risk of a proposed change to it.
- Risk Assessment, which evaluates a task or process as it currently stands, not the delta a change is about to introduce.
- Bowtie Analysis, which maps one already-known top event's causes and barriers, rather than the specific hazards a single change creates.
- Pre-Task Risk Assessment, which is a short crew-level check immediately before work starts, not a documented change approval.
- Anything outside KnowSafe, which belongs in the workspace that owns the process being changed
Compliance mapping
Which ISO 45001 cl.8.1.3 requirements does this satisfy?
ISO 45001's management of change clause requires organisations to assess OH&S risks before introducing planned changes; the clauses below map that requirement, and its supporting risk-assessment clause, onto the template's sections.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 45001 cl.8.1.3 | The organisation shall establish a process for the implementation and control of planned changes, including assessment of the OH&S risks of new products, services or processes | Header |
| ISO 45001 cl.8.1.3(a) | New hazards and OH&S risks are identified before the change proceeds | What the change introduces |
| ISO 45001 cl.6.1.2.1 | Hazard identification is ongoing and proactive, including consideration of changes to the organisation, its operations or materials | What the change introduces |
| ISO 45001 cl.8.1.3(b) | Legal requirements and other requirements are considered as part of the change assessment | Wider effects |
| ISO 45001 cl.8.1.3(c) | Risks arising from the change to existing operations are managed, including where controls are removed or weakened | What the change removes |
| ISO 45001 cl.8.2 | Emergency preparedness and response arrangements are reviewed where a change could affect them | Wider effects |
| ISO 45001 cl.6.1.3 | Applicable legal and other requirements are determined and kept up to date, including where a change triggers new ones | Outcome |
What it does not cover
- Existing Controls Affected, which was answered No while Controls Removed Or Weakened, a field that only opens on Yes, contains a description of a guard being relocated.
- Critical Control Affected, which was answered No for a change to an asset that Critical Control links directly to, without the reviewer checking the control register first.
- Compensating Control Added, which reads N/A even though Critical Control Affected is Yes, leaving a weakened critical control with nothing recorded in its place.
- Residual Risk Band, which is marked Pass while Change Acceptable is Yes with conditions, with no Conditions On Approval text explaining what the conditions actually are.
- Existing Risk Assessments Need Updating, which is answered Yes with no Risk Assessment record linked, leaving the update as an intention rather than a tracked action.
Global
Change Risk Review requirements by country
Management of change risk assessment is a near-universal management-system expectation, but the weight it carries differs by regime and by whether the site also sits under a major-hazard regulator.
ISO 45001:2018, cl.8.1.3
Requires a documented process to assess OH&S risk before implementing planned changes, whether organisational, operational or to products and processes
This is the certifiable baseline. An auditor will ask for evidence a review happened before the change went ahead, not a retrospective write-up after it did.
OSHA Process Safety Management, 29 CFR 1910.119(l)
For covered processes, management of change requires the technical basis, safety and health effects, and necessary time period to be assessed before the change is made
Where the changed process is a covered highly hazardous chemical process, this review is not just good practice under ISO 45001, it is a specific regulatory requirement with its own inspection exposure.
Management of Health and Safety at Work Regulations 1999, reg.3
Requires a suitable and sufficient risk assessment covering any new or changed work activity
A change that is not assessed before it happens is a live breach the moment work starts under the new arrangement, independent of whether an MOC record exists at all.
How to complete it
How to complete a change risk review, step by step
The fields are straightforward; the judgement calls are about how honestly the removal side is assessed and how the outcome is actually enforced.
New Hazards Created invites a reviewer to think forward; Controls Removed Or Weakened requires them to think backward, comparing the process as it was against the process as it will be. The second exercise takes more discipline and is where reviews most often go shallow.
Marking Compensating Control Added as Pass should require the new control to be named and verified, not implied by the change description. A critical control weakened without a named, working replacement is a fatal-risk exposure, not a residual risk to accept.
Conditions On Approval is free text with no structural link to the Action Required field. Deciding whether a condition becomes a tracked action with an owner and a CAPA ID, or stays as a note nobody re-checks, determines whether 'yes with conditions' means anything at implementation.
Affects Adjacent Areas, Affects Emergency Arrangements and Affects Food Safety are each single judgement calls made by the assessor at the point of review, before the change has actually run. Treating them as final rather than provisional is a common source of surprises after implementation.
What auditors find
Most common change risk review findings
These are the failure patterns that recur when a Change Risk Review is checked against the change it actually approved.
| Finding | Clause | What fixes it |
|---|---|---|
| Controls Removed Or Weakened left blank while the Change Description clearly alters a physical guard or procedural check | ISO 45001 cl.8.1.3(c) | Require Existing Controls Affected to be justified against a control register lookup rather than answered from memory. |
| Critical Control Affected answered No without checking the Critical Control pick list against the changed asset | ISO 45001 cl.6.1.2.1 | Auto-populate candidate critical controls from the linked Asset so the reviewer confirms or rejects rather than starting blank. |
| Compensating Control Added marked Pass with no named replacement control | ISO 45001 cl.8.1.3(c) | Make a text field for the replacement control mandatory whenever Compensating Control Added is Pass or Partial. |
| Change Acceptable recorded as 'Yes with conditions' with an empty Conditions On Approval field | ISO 45001 cl.8.1.3 | Block submission when Change Acceptable is 'Yes with conditions' and Conditions On Approval is empty. |
| Affects Emergency Arrangements marked No for a change to egress routes or fire systems | ISO 45001 cl.8.2 | Cross-check Affects Emergency Arrangements against the Change Type and Change Description for keyword triggers, flagging for a second reviewer. |
| Existing Risk Assessments Need Updating marked Yes with no Risk Assessment record linked | ISO 45001 cl.6.1.2.1 | Require a Risk Assessment ID whenever this field is Yes, and track it as an open action until the linked record is updated. |
Case in point
Case in point: the guard that moved for access
A change was raised to relocate a machine guard six inches to allow a new sensor bracket to fit. The Change Risk Review recorded the sensor as a new control, scored New Hazards Created as None, and marked Existing Controls Affected as No, because nothing about the guard's function had changed on paper.
The relocation reduced the guard's coverage at the pinch point by just enough that an operator's hand could pass underneath during a specific maintenance sequence. The review had correctly assessed the addition and entirely missed the removal, because the question 'did anything get weaker' was never actually asked against the physical change, only against the stated intent of it.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- SAF-064
- Archetype
- Assessment
- Record ID
- RSK-2026-000
- Scoring
- Change risk band
- Direction
- High is bad
- Singleton
- No
- Basis
- ISO 45001 cl.8.1.3
- Links
- Links MOC
- Tags
- Risk, Change
- Sections
- 5
- Fields
- 43
- Follow up fields
- 6
- Repeating sections
- 0
- Links out
- 8
Header
12 fieldsReview ID*
Auto sequence. Format CRR-2026-0000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
MOC ID*
Links to FDN-020 MOC ID
Review Date*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Change Description*
Change Type*
Asset
Asset ID
Format AST-0000.
Links to FDN-002 Asset ID
Task
Job ID
Format JOB-000.
Links to FDN-004 Job Task ID
What the change introduces
5 fieldsNew Hazards Created*
New Hazard Detail
Likelihood*
- Rare3 pts
- Possible1 pt
- Likely0 pts
Severity*
- Minor3 pts
- Moderate1 pt
- Serious0 pts
Risk Band*
- Acceptable4 pts
- Investigate2 pts
- Change soon1 pt
- Change now0 pts
What the change removes
7 fieldsThe Question People Skip
Changes take things away as well as adding them. A guard removed for access, a step that used to catch errors, a person who used to notice. Ask what protection quietly disappears.
Existing Controls Affected*
- No3 pts
- Yes0 pts
Controls Removed Or Weakened
Critical Control
Control ID
Format CCTRL-000.
Links to FDN-011 Control ID
Critical Control Affected*
- No3 pts
- Yes0 pts
Compensating Control Added
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Wider effects
8 fieldsAffects Adjacent Areas*
- No3 pts
- Yes0 pts
Affects Emergency Arrangements*
- No3 pts
- Yes0 pts
Affects Food Safety*
- No3 pts
- Possibly1 pt
- Yes0 pts
Existing Risk Assessments Need Updating*
Risk Assessment
Risk ID
Format RSK-2026-00000.
Links to FDN-012 Risk ID
Training Or Briefing Needed*
Course ID
Links to FDN-007 Course ID
Outcome
11 fieldsResidual Risk Band*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Change Acceptable*
- Yes3 pts
- Yes with conditions2 pts
- No0 pts
Conditions On Approval
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Assessor*
Signature*
Change Owner*
Second Signature*
SAF-064 · record IDs look like RSK-2026-000 · Links MOC
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The review itself is a single form; what slips is tracing every affected control and condition through to something that actually gets checked.
Holds the Change Risk Review against the linked MOC and critical control registers, and flags any compensating control marked Pass with no replacement named.
Confirms whether a control named in Critical Control is a maintained asset, so 'affected' can be checked against real maintenance state, not the change description alone.
Tracks the Training Or Briefing Needed outcome through to actual course completion for the crew working the changed process, rather than leaving it as an unchecked Yes.

Coordinates the assessor and change owner sign-offs, rolls open conditions and linked actions into one view, and holds every write for approval before it touches a record.
This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.
Meet KnowSafe→Glossary
Change Risk Review definitions and key terms
- Management of change (MOC)
- A formal process for reviewing and approving changes to equipment, processes, materials or procedures before they are implemented, to prevent unassessed risk from entering operations.
- Residual risk
- The risk that remains after existing and any new controls are accounted for, which is what a change acceptable decision is actually judged against, not the raw risk before mitigation.
- Critical control
- A control identified as essential to preventing or limiting a fatal or catastrophic event, whose removal or weakening requires a compensating control rather than simple acceptance.
- Compensating control
- A new or strengthened control introduced specifically to offset a critical control that a change has removed or degraded.
- Change type
- A classification of why the change is happening (new product, recipe change, legal change, customer request, design refresh), used to route the review and anticipate which hazard categories are likely.
FAQ
Frequently asked questions about change risk review
What is a Change Risk Review based on?+
It implements ISO 45001 clause 8.1.3, which requires OH&S risk to be assessed before planned changes are implemented, alongside the hazard identification requirements of clause 6.1.2.1.
What sections does the Change Risk Review contain?+
Five sections: Header, What the change introduces, What the change removes, Wider effects and Outcome. Together they hold 43 fields, 26 of which are required.
How is a Change Risk Review different from the MOC record it's raised alongside?+
The MOC record describes and authorises the change; the Change Risk Review assesses its risk. They are raised together and reference each other, but neither replaces the other.
Which programme does the Change Risk Review belong to?+
It is part of Critical Control and Fatal Risk, and links back to the management of change record that triggered it.
How is a Change Risk Review scored?+
Each new hazard gets a likelihood, severity and risk band; any affected critical control gets its own pass or fail; the whole review closes with a residual risk band and a change-acceptable decision.
Can the Change Risk Review template be changed?+
Yes. The hazard categories, scoring and conditional fields are all editable. Most sites run it as delivered for a cycle before tightening what triggers the removal-side questions.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Critical Control and Fatal Risk
Bow Tie Analysis Record
Maps threats, the top event, consequences and the barriers on each side for a major hazard
Barrier Health Review
Reviews whether the barriers relied on in a bow tie are actually in place and working
Critical Control Register
Lists the controls that stand between your people and a fatal or catastrophic event, with an owner and a required check frequency for each
Risk Assessment
The single risk assessment used across the whole business
Serious Potential Incident Report
Used when an event could have killed or seriously injured someone, whatever the actual outcome
Job Safety Analysis
Breaks a job into steps, finds the hazards in each and sets the controls
More in Risk Studies
Job Safety Analysis
Breaks a job into steps, finds the hazards in each and sets the controls
Pre-Task Risk Assessment
A short check done by the crew right before work starts, covering what has changed today
Task Risk Assessment
A fuller assessment of a task, its hazards and its controls, using the shared risk method
Hazard Identification Study
A structured search for hazards across an area, process or new installation
Bowtie Analysis
Maps a major hazard from its causes through to its consequences, and shows which barriers sit in between
What If Study
A guided team discussion asking what could go wrong at each stage of a process

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 45001:2018 — Occupational health and safety management systems, cl.8.1.3
- OSHA Process Safety Management — 29 CFR 1910.119(l)
- Management of Health and Safety at Work Regulations 1999 — reg.3
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.