What this is
What is management of change?
What is management of change?
Management of change is the process of assessing a change to equipment, process, material, people or procedure before it is implemented, so that new hazards, lost safeguards and the training, documentation and permit implications are identified while the change can still be stopped or modified. It is distinct from the risk assessment it triggers: the MOC record decides whether a change needs assessing and what else it disturbs, and the risk assessment does the hazard analysis itself.
What counts as a like-for-like replacement?
A replacement that is functionally, materially and operationally identical to what it replaces, installed the same way, under the same operating conditions, with no change to the process safety information. Same manufacturer, same specification, same rating, installed by the same method. If any of those differ, the change is not like-for-like, even when the part looks interchangeable, and it needs the full MOC process rather than the exemption.
Why does a temporary change need an expiry date?
Because a temporary change with no expiry is a permanent change nobody assessed as permanent. Temporary bypasses, jumpers and workarounds are approved against a time-bound justification; once that justification's clock runs out with no review, the change either needs re-authorising as permanent, with the full assessment that implies, or removing. An expiry date is what makes that decision happen instead of drifting.
Scope
When is a management of change required?
This record is the general gate for any change that is not routine like-for-like replacement. Where a specific change-control instrument already exists for the type of change, it should carry the technical detail and this record should track the gate, not duplicate the assessment.
Use this template when
- New or modified equipment, process, material, people, procedure or organisational arrangement is being introduced and is not a straight like-for-like replacement
- A temporary bypass, workaround or interim measure is needed and must be time-bound and tracked to removal or re-authorisation
- An emergency change has to be made faster than the normal cycle allows, and needs retrospective authorisation and a documented reason
- A change could remove an existing safeguard, interlock, procedure step or competency requirement, even where it also appears to be an improvement
- A change needs to be linked so that the procedure, training, drawing, spares and permit implications are tracked to closure rather than assumed
Do not use it for
- Risk Assessment (FDN-012), which does the hazard analysis a non-like-for-like change triggers; the MOC record links to it rather than replacing it
- Product Change Request / Process Change Request (QUA-069 / QUA-070), which carry the quality-system detail for a formulation or process parameter change
- Validation Record (QUA-071), which proves a changed process, cleaning method or equipment actually performs to specification after the change
- Temporary Change Authorization (QUA-072), where a quality system needs deviations tracked on a shorter, dedicated review cycle than this record's expiry field provides
- Waiver and Concession Record (FDN-030), which accepts a one-off nonconformance against a specification rather than authorising a change to the specification itself
Compliance mapping
Which OSHA 1910.119(l) requirements does this satisfy?
OSHA's management of change requirement is written for covered processes handling highly hazardous chemicals above threshold quantities, and is specific about what the procedure must address before a change is made. ISO 45001 states the same duty in general terms for any organisation with any process, which is why this record is used across sites that are not PSM-covered at all.
| Clause | Requirement | Where it lands |
|---|---|---|
| OSHA 1910.119(l)(1) | Written procedures to manage change to process chemicals, technology, equipment and procedures, excluding replacements in kind | Change detail |
| OSHA 1910.119(l)(2)(i) | The technical basis for the proposed change addressed prior to the change | Change detail |
| OSHA 1910.119(l)(2)(ii) | Impact of the change on safety and health assessed before implementation | Risk assessment |
| OSHA 1910.119(l)(2)(iii) | Modifications to operating procedures identified and addressed | Requirements triggered |
| OSHA 1910.119(l)(2)(iv) | Necessary time period for the change established | Change detail |
| OSHA 1910.119(l)(2)(v) | Authorisation requirements for the proposed change defined and followed | Approval |
| OSHA 1910.119(l)(3) | Affected employees informed of, and trained in, the change prior to start-up | Requirements triggered |
| ISO 45001 cl.8.1.3 | Process to implement and control planned changes, and review the consequences of unintended changes | Implementation and closure |
What it does not cover
- Risk Assessment, which performs the actual hazard identification and control evaluation a non-like-for-like change should trigger; this record decides that one is needed, it does not do it.
- Process Change Request or Product Change Request, which carry the formulation, recipe or process-parameter detail a quality system requires for a change to what is made or how, beyond the safety gate this record provides.
- Validation Record, which proves after implementation that the changed process, method or equipment performs to specification; approval to proceed is not evidence that it worked.
- Effectiveness Verification, which confirms the change achieved its intended outcome without introducing a new problem, and is a separate check from the post-implementation review closing this record.
- The underlying procedure, training and drawing updates themselves, which belong in the document register, course catalogue and drawing system; this record tracks that they are required and done, it is not where they live.
Global
Management of Change requirements by country
The duty to manage change formally is narrow in US law and broad in international management-system standards. What differs most is the threshold at which the requirement bites and how prescriptive it is about what the assessment must cover.
OSHA 1910.119(l), Process Safety Management of Highly Hazardous Chemicals
Written management of change procedures required for covered processes above the threshold quantities in Appendix A, with five specific considerations mandated.
Outside a PSM-covered process there is no federal MOC requirement by name, though an unassessed change causing recognised harm can still be pursued under the General Duty Clause.
COMAH Regulations 2015 (Seveso III Directive)
Major hazard establishments must have arrangements to identify and review changes to plant, process or organisation that could affect major accident hazards.
COMAH's definition of change is wider than OSHA's and explicitly includes organisational change, staffing and outsourcing.
Provincial OHS regulations; CCPS-based process safety guidance
No single federal MOC standard; process sites typically adopt an MOC element modelled on CCPS or OSHA practice.
Where MOC is adopted voluntarily, its rigour is internal programme design rather than an enforceable clause.
Model WHS Regulations; AS/NZS ISO 45001
General duty to manage risk extends to changes, with major hazard facilities carrying specific obligations under safety case regulations.
For most workplaces, assessing a change sits inside the general risk duty rather than a named MOC clause.
ISO 45001:2018 clause 8.1.3
Requires a process to implement and control planned temporary and permanent changes and review consequences of unintended ones.
Auditors treat this as commonly weak, because sites without a chemical-safety history often have no MOC process until ISO 45001 requires one.
How to complete it
How to complete a management of change, step by step
The template captures the change and the sign-offs. The judgement calls that decide whether the record actually prevented a bad change are made in the parts nothing forces an answer to.
Ask what specifically is identical: manufacturer, specification, rating, installation method, operating envelope. If any of those differ, it is not like-for-like regardless of how similar the parts look. This determination is where most MOC failures originate, because everything downstream depends on it, and it is the answer the change owner has the clearest incentive to get wrong.
A faster machine, a different chemical, or a simplified procedure each solve the problem they were designed for while quietly retiring a safeguard or a piece of tacit knowledge the old arrangement depended on. The 'what could this remove' question is easy to leave blank because nothing prompts an answer the way a new hazard does; blank does not mean nothing was lost.
A temporary change with no expiry, or an expiry nobody is accountable for acting on, converts into a permanent change with none of the assessment a permanent change requires. The record should force a choice at expiry: remove it, or re-authorise it as permanent, not extend it by default.
A high or very high risk band should mean a senior approver actually signed before the implementation date, not that the field was populated afterwards to match a date already past. The sequence is the control; a record where implementation predates approval has recorded a change that already happened, not managed one.
What auditors find
Most common management of change findings
Management of change findings are rarely about a missing record. They are about a record that exists, was completed correctly on paper, and still didn't stop the thing it was meant to catch.
| Finding | Clause | What fixes it |
|---|---|---|
| Change marked like-for-like where specification, rating or installation method actually differed. | OSHA 1910.119(l)(1) | Require a one-line justification for every like-for-like determination, not just the checkbox. |
| Implementation date precedes the approval date. | OSHA 1910.119(l)(2)(v) | Block implementation logging until approval status is Approved or Approved with conditions. |
| Temporary change has no expiry date, or the expiry date has passed with no closure or re-authorisation. | Change Category field, ISO 45001 cl.8.1.3 | Escalate automatically at expiry; require removal or full re-authorisation, not a silent extension. |
| Risk assessment marked required but no Risk ID is linked. | OSHA 1910.119(l)(2)(ii) | Make the risk assessment link mandatory wherever Risk Assessment Required is Yes. |
| "What could this remove" left blank or answered "none" without examination. | OSHA 1910.119(l)(2)(ii) | Prompt with the categories that are usually lost: interlocks, cross-checks, redundancy, competency. |
| Training required marked but no course or completion evidenced before start-up. | OSHA 1910.119(l)(3) | Link the required course and block closure until training completion is evidenced for affected staff. |
| Senior approver missing on a high or very high risk band change. | OSHA 1910.119(l)(2)(v) | Enforce the senior approver field as required whenever the risk band is High or Very high. |
| Change closed with "all requirements complete" ticked while a triggered item, such as a drawing or permit update, is still open. | ISO 45001 cl.8.1.3 | Derive closure eligibility from the state of every triggered requirement rather than a single manual checkbox. |
| No post-implementation review recorded, or review outcome missing on a change that should have one. | ISO 45001 cl.8.1.3 | Schedule the post-implementation review at approval and require an outcome before the record is archived. |
| Emergency change implemented with no retrospective authorisation or documented reason for bypassing the normal sequence. | OSHA 1910.119(l)(2)(v) | Require emergency-category changes to carry a named authoriser and a reason within a defined grace period. |
Case in point
Case in point: the jumper that outlived its justification
A packaging line's product detection interlock began nuisance-tripping during a supplier changeover. Maintenance raised an emergency MOC to fit a temporary jumper bypassing the interlock, marked Temporary, Emergency, with a five-day expiry set for the replacement part to arrive.
The part arrived late. The expiry passed with no escalation configured and no owner chasing it, because the field was informational rather than something anyone was accountable for. The jumper stayed in for eleven weeks, through a shift change and two supervisors, until an unrelated layered process audit noticed the bypass cable still in place.
Nothing failed catastrophically, which is why nobody had reopened the question. The fix was not a better original justification; it was making a temporary expiry generate an escalation to a named owner, rather than sitting quietly in a field nobody was required to check.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
8 sections
- Reference
- FDN-020
- Archetype
- Record
- Record ID
- MOC-2026-000
- Scoring
- Change risk band
- Direction
- High is bad
- Singleton
- Yes
- Basis
- OSHA 1910.119(l), ISO 45001 cl.8.1.3
- Links
- Linked from every workspace
- Tags
- Change
- Sections
- 8
- Fields
- 47
- Follow up fields
- 0
- Repeating sections
- 0
- Links out
- 7
Header
6 fieldsMOC ID*
Format MOC-2026-00000.
The record's own ID. Other templates point at this value.
Case ID
Thread key
Parent Type
Parent ID
Immediate predecessor record
Raised Date*
Requested By*
Change detail
7 fieldsChange Title*
Change Type*
Equipment, process, material, people, procedure or organisational.
Change Category*
Permanent, temporary or emergency. Temporary changes must carry an expiry.
Description Of Change*
What is changing, from what to what.
Reason For Change*
Like For Like Replacement*
A true like for like replacement does not need full change control.
Temporary Expiry Date
Required for temporary changes. Temporary changes that never expire are how process control disappears.
Scope
8 fieldsSite*
Site ID*
Links to FDN-001 Site ID
Assets Affected
Asset ID
Links to FDN-002 Asset ID
Tasks Affected
Job ID
Links to FDN-004 Job Task ID
People Affected
Departments Affected
Risk assessment
5 fieldsRisk Assessment Required*
Required for anything that is not a like for like replacement.
Risk ID
Links to FDN-012 Risk ID
Change Risk Band*
Drives the level of approval required.
- Low3 pts
- Medium2 pts
- High1 pt
- Very high0 pts
What Could This Introduce*
New hazards created by the change.
What Could This Remove*
Controls or safeguards that may be lost. This is the question people skip.
Requirements triggered
8 fieldsProcedure Update Required
Training Required
Drawing Update Required
Spares Change Required
Permit Review Required
Emergency Plan Update Required
Related Document ID
Links to FDN-008 Document ID
Related Course ID
Links to FDN-007 Course ID
Related records
1 fieldEffectiveness Verification ID
The check that the change actually worked.
Links to FDN-016 Verification ID
Approval
7 fieldsTechnical Approver*
Safety Approver*
Operations Approver*
Senior Approver
Required where the change risk band is high.
Approval Signature*
Approval Date*
Approval Status*
- Approved2 pts
- Approved with conditions1 pt
- Rejected0 pts
Implementation and closure
5 fieldsImplementation Date
All Requirements Complete
The change cannot close until every triggered requirement is done.
Post Implementation Review Date
Review Outcome
- No change needed3 pts
- Minor amendment2 pts
- Major revision1 pt
- Merge2 pts
- Retire2 pts
Closure Signature
FDN-020 · record IDs look like MOC-2026-000 · Linked from every workspace
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The record is straightforward to fill in. What actually slips is the tail: the expiry nobody chased, the training that was marked required but never linked to a completion, and the procedure update that stayed open after the change went live.
Tracks the drawing, spares and equipment record implications of a change through to closure, so a change to an asset updates the asset's own record rather than sitting only in the MOC.
Turns a Training Required tick into an actual course assignment and completion check for affected staff, and blocks the change from closing until it is evidenced.
Holds the linked risk assessment and permit review against the change, and flags a non-like-for-like change with no risk assessment attached.

Watches temporary change expiry dates and post-implementation review dates as they come due, raising them to the named owner rather than waiting for someone to notice.
This template lives in General — control tower. The orchestration layer. Registries and engines every other workspace reads from.
Meet General→Glossary
Management of Change definitions and key terms
- Management of change
- The formal process of assessing a change before it is implemented, so that its technical basis, safety impact, procedure, training and authorisation implications are addressed in advance rather than discovered afterwards.
- Replacement in kind
- A change so identical to what it replaces in specification, rating, manufacturer and installation that it is exempt from the full management of change procedure under OSHA 1910.119(l)(1).
- Process safety information
- The documented technical basis for a covered process: chemistry, technology, and equipment data, which a change must be checked against and, where affected, updated to reflect.
- Change risk band
- The rated significance of a proposed change, used here to drive the level of approval required; a high band should mean a senior approver, not just a technical one.
- Temporary change
- A change approved for a bounded period with a stated expiry, after which it must be removed or re-authorised as permanent through the full process, not extended by default.
- Emergency change
- A change implemented faster than the normal authorisation sequence allows because of an immediate operational or safety need, requiring retrospective authorisation and a documented reason.
- Post-implementation review
- The check, after a change has been running for a period, of whether it worked as intended and whether it should be retained, amended, merged or retired.
- Effectiveness verification
- Confirmation that a completed change achieved its intended outcome without introducing a new failure mode, distinct from the approval that authorised the change to proceed.
FAQ
Frequently asked questions about management of change
Does every change need a management of change record?+
Every change that is not a genuine replacement in kind does. The exemption is narrow: same specification, same manufacturer, same rating, same installation method, same operating conditions. A change that differs on any of those, even where it looks like routine maintenance, should go through the full process rather than being waved through as like-for-like.
Who has to approve a management of change?+
Technical, safety and operations approval as a baseline, with a senior approver added where the change risk band is high or very high. The approval chain should scale with the risk the record itself has just rated, which is why the senior approver field is conditional rather than universal.
What happens if a temporary change's expiry date passes?+
It should force a decision, not disappear. Either the change is removed and the original condition restored, or it is re-authorised as a permanent change through the full assessment, procedure update and approval sequence a permanent change requires. Extending the temporary period without that reassessment defeats the purpose of having called it temporary.
Does a risk assessment have to be attached to every MOC?+
Where the Risk Assessment Required field is Yes, which it should be for anything that is not like-for-like, then yes, and the Risk ID field should be populated with a real linked record, not left blank because the change felt minor. Minor is a conclusion the risk assessment is supposed to reach, not an assumption that excuses doing it.
Can implementation start before approval is complete?+
No. The entire value of management of change is that assessment happens before implementation. A record where the implementation date precedes the approval date has stopped functioning as a gate and become a log of a change that already happened, which will not survive scrutiny after an incident.
What is the difference between management of change and a risk assessment?+
Management of change is the gate that decides a change needs assessing and tracks everything the change disturbs: procedures, training, drawings, spares, permits and emergency plans. The risk assessment is the hazard analysis itself, done as a linked record. Treating the MOC form as though it were the risk assessment is how the hazard analysis gets skipped while the paperwork still looks complete.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Capital Projects and Commissioning
Equipment arriving with its procedures, training and spares rather than after them.
Master Data and Foundations
One place for each thing, so a change updates everywhere rather than in eight lists.
Change Control
Changes assessed before they happen rather than investigated afterwards.
Used together in Capital Projects and Commissioning
Pre-Commissioning Checklist
Confirms a new installation is complete and safe before it is energised or run
Factory Acceptance Test Record
Records testing of new equipment at the supplier's site before it ships
Site Acceptance Test Record
Records testing of new equipment once installed at your site
Shutdown Plan
Plans a planned outage, covering scope, sequence, resources, permits and restart
Capital Project Safety Review
Reviews a capital project at each stage for safety, hygienic design, access and maintainability before money is committed
Equipment Specification Record
Holds the specification a new machine must meet, covering performance, safety, hygiene, energy and maintenance access
More in Engines
Risk Assessment
The single risk assessment used across the whole business
Root Cause Analysis
Finds out why something happened rather than who was involved
Corrective and Preventive Action
The single action record used everywhere
Finding
Records a single deficiency picked up during an audit, inspection or check
Effectiveness Verification
Checks whether an action actually worked, some time after it was put in place
Just Culture Determination
Separates a system problem from a genuine choice to take a risk, using a consistent set of questions

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- OSHA 29 CFR 1910.119(l), Process Safety Management of Highly Hazardous Chemicals — Management of change
- ISO 45001:2018 clause 8.1.3, Management of change
- COMAH Regulations 2015 (Control of Major Accident Hazards), UK/EU
- CCPS Guidelines for Management of Change for Process Safety
- OSHA General Duty Clause, Section 5(a)(1) (US)
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.