Knowella

Management of Change

A management of change record exists to stop a change reaching the floor before its consequences have been thought through. Its recurring failure is not a missing form but a captured one: the like-for-like box gets ticked to avoid the process, or approval is chased after the equipment is already running, and the record becomes a justification written after the fact rather than a gate the change had to pass through first.

EllaGeneralRecordFDN-02047 fields across 8 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
OSHA 1910.119(l), ISO 45001 cl.8.1.3
Workspace
General
Form type
Record
Review trigger
Any change that is not a true like-for-like replacement
Completed by
Change owner; approved by technical, safety and operations, plus a senior approver at high risk

The short version

  • OSHA 1910.119(l) exempts replacements in kind from the management of change procedure. That exemption is the most exploited part of the standard, because the determination of what counts as in kind is made by the same person who benefits from the change being easy.
  • The MOC record is not the risk assessment. It decides whether a change is significant enough to need one, and what else the change disturbs: procedures, training, drawings, spares, permits, emergency plans. A change record with no linked risk assessment for a non-like-for-like change has skipped a step.
  • ISO 45001 clause 8.1.3 requires organisations to review the consequences of unintended changes and take action to mitigate adverse effects, which extends management of change beyond the deliberate changes this record is raised for.
  • The question that gets skipped is what the change removes, not what it introduces. A new interlock, a faster pump, or a different supplier's gasket each remove some existing safeguard or assumption, and that loss is harder to see than the new hazard because nothing new has been added to look at.
  • Temporary changes are the category most likely to become permanent by neglect. An expiry date with no owner chasing it is not a control; it is a date that will be quietly extended or simply missed.
  • Approval has to precede implementation, not follow it. A record completed after the equipment is already running has stopped being management of change and become a change log, and it will not stand up to the question an investigator actually asks: who approved this before it happened.

What this is

What is management of change?

What is management of change?

Management of change is the process of assessing a change to equipment, process, material, people or procedure before it is implemented, so that new hazards, lost safeguards and the training, documentation and permit implications are identified while the change can still be stopped or modified. It is distinct from the risk assessment it triggers: the MOC record decides whether a change needs assessing and what else it disturbs, and the risk assessment does the hazard analysis itself.

What counts as a like-for-like replacement?

A replacement that is functionally, materially and operationally identical to what it replaces, installed the same way, under the same operating conditions, with no change to the process safety information. Same manufacturer, same specification, same rating, installed by the same method. If any of those differ, the change is not like-for-like, even when the part looks interchangeable, and it needs the full MOC process rather than the exemption.

Why does a temporary change need an expiry date?

Because a temporary change with no expiry is a permanent change nobody assessed as permanent. Temporary bypasses, jumpers and workarounds are approved against a time-bound justification; once that justification's clock runs out with no review, the change either needs re-authorising as permanent, with the full assessment that implies, or removing. An expiry date is what makes that decision happen instead of drifting.

Scope

When is a management of change required?

This record is the general gate for any change that is not routine like-for-like replacement. Where a specific change-control instrument already exists for the type of change, it should carry the technical detail and this record should track the gate, not duplicate the assessment.

Use this template when

  • New or modified equipment, process, material, people, procedure or organisational arrangement is being introduced and is not a straight like-for-like replacement
  • A temporary bypass, workaround or interim measure is needed and must be time-bound and tracked to removal or re-authorisation
  • An emergency change has to be made faster than the normal cycle allows, and needs retrospective authorisation and a documented reason
  • A change could remove an existing safeguard, interlock, procedure step or competency requirement, even where it also appears to be an improvement
  • A change needs to be linked so that the procedure, training, drawing, spares and permit implications are tracked to closure rather than assumed

Do not use it for

  • Risk Assessment (FDN-012), which does the hazard analysis a non-like-for-like change triggers; the MOC record links to it rather than replacing it
  • Product Change Request / Process Change Request (QUA-069 / QUA-070), which carry the quality-system detail for a formulation or process parameter change
  • Validation Record (QUA-071), which proves a changed process, cleaning method or equipment actually performs to specification after the change
  • Temporary Change Authorization (QUA-072), where a quality system needs deviations tracked on a shorter, dedicated review cycle than this record's expiry field provides
  • Waiver and Concession Record (FDN-030), which accepts a one-off nonconformance against a specification rather than authorising a change to the specification itself

Compliance mapping

Which OSHA 1910.119(l) requirements does this satisfy?

OSHA's management of change requirement is written for covered processes handling highly hazardous chemicals above threshold quantities, and is specific about what the procedure must address before a change is made. ISO 45001 states the same duty in general terms for any organisation with any process, which is why this record is used across sites that are not PSM-covered at all.

ClauseRequirementWhere it lands
OSHA 1910.119(l)(1)Written procedures to manage change to process chemicals, technology, equipment and procedures, excluding replacements in kindChange detail
OSHA 1910.119(l)(2)(i)The technical basis for the proposed change addressed prior to the changeChange detail
OSHA 1910.119(l)(2)(ii)Impact of the change on safety and health assessed before implementationRisk assessment
OSHA 1910.119(l)(2)(iii)Modifications to operating procedures identified and addressedRequirements triggered
OSHA 1910.119(l)(2)(iv)Necessary time period for the change establishedChange detail
OSHA 1910.119(l)(2)(v)Authorisation requirements for the proposed change defined and followedApproval
OSHA 1910.119(l)(3)Affected employees informed of, and trained in, the change prior to start-upRequirements triggered
ISO 45001 cl.8.1.3Process to implement and control planned changes, and review the consequences of unintended changesImplementation and closure

What it does not cover

  • Risk Assessment, which performs the actual hazard identification and control evaluation a non-like-for-like change should trigger; this record decides that one is needed, it does not do it.
  • Process Change Request or Product Change Request, which carry the formulation, recipe or process-parameter detail a quality system requires for a change to what is made or how, beyond the safety gate this record provides.
  • Validation Record, which proves after implementation that the changed process, method or equipment performs to specification; approval to proceed is not evidence that it worked.
  • Effectiveness Verification, which confirms the change achieved its intended outcome without introducing a new problem, and is a separate check from the post-implementation review closing this record.
  • The underlying procedure, training and drawing updates themselves, which belong in the document register, course catalogue and drawing system; this record tracks that they are required and done, it is not where they live.

Global

Management of Change requirements by country

The duty to manage change formally is narrow in US law and broad in international management-system standards. What differs most is the threshold at which the requirement bites and how prescriptive it is about what the assessment must cover.

United States

OSHA 1910.119(l), Process Safety Management of Highly Hazardous Chemicals

Written management of change procedures required for covered processes above the threshold quantities in Appendix A, with five specific considerations mandated.

Outside a PSM-covered process there is no federal MOC requirement by name, though an unassessed change causing recognised harm can still be pursued under the General Duty Clause.

United Kingdom / European Union

COMAH Regulations 2015 (Seveso III Directive)

Major hazard establishments must have arrangements to identify and review changes to plant, process or organisation that could affect major accident hazards.

COMAH's definition of change is wider than OSHA's and explicitly includes organisational change, staffing and outsourcing.

Canada

Provincial OHS regulations; CCPS-based process safety guidance

No single federal MOC standard; process sites typically adopt an MOC element modelled on CCPS or OSHA practice.

Where MOC is adopted voluntarily, its rigour is internal programme design rather than an enforceable clause.

Australia

Model WHS Regulations; AS/NZS ISO 45001

General duty to manage risk extends to changes, with major hazard facilities carrying specific obligations under safety case regulations.

For most workplaces, assessing a change sits inside the general risk duty rather than a named MOC clause.

International

ISO 45001:2018 clause 8.1.3

Requires a process to implement and control planned temporary and permanent changes and review consequences of unintended ones.

Auditors treat this as commonly weak, because sites without a chemical-safety history often have no MOC process until ISO 45001 requires one.

How to complete it

How to complete a management of change, step by step

The template captures the change and the sign-offs. The judgement calls that decide whether the record actually prevented a bad change are made in the parts nothing forces an answer to.

Test the like-for-like claim, don't accept it

Ask what specifically is identical: manufacturer, specification, rating, installation method, operating envelope. If any of those differ, it is not like-for-like regardless of how similar the parts look. This determination is where most MOC failures originate, because everything downstream depends on it, and it is the answer the change owner has the clearest incentive to get wrong.

Name what the change removes, not just what it adds

A faster machine, a different chemical, or a simplified procedure each solve the problem they were designed for while quietly retiring a safeguard or a piece of tacit knowledge the old arrangement depended on. The 'what could this remove' question is easy to leave blank because nothing prompts an answer the way a new hazard does; blank does not mean nothing was lost.

Give every temporary change a real expiry and an owner who is chased

A temporary change with no expiry, or an expiry nobody is accountable for acting on, converts into a permanent change with none of the assessment a permanent change requires. The record should force a choice at expiry: remove it, or re-authorise it as permanent, not extend it by default.

Match the approval chain to the risk band, and verify the order

A high or very high risk band should mean a senior approver actually signed before the implementation date, not that the field was populated afterwards to match a date already past. The sequence is the control; a record where implementation predates approval has recorded a change that already happened, not managed one.

What auditors find

Most common management of change findings

Management of change findings are rarely about a missing record. They are about a record that exists, was completed correctly on paper, and still didn't stop the thing it was meant to catch.

FindingClauseWhat fixes it
Change marked like-for-like where specification, rating or installation method actually differed.OSHA 1910.119(l)(1)Require a one-line justification for every like-for-like determination, not just the checkbox.
Implementation date precedes the approval date.OSHA 1910.119(l)(2)(v)Block implementation logging until approval status is Approved or Approved with conditions.
Temporary change has no expiry date, or the expiry date has passed with no closure or re-authorisation.Change Category field, ISO 45001 cl.8.1.3Escalate automatically at expiry; require removal or full re-authorisation, not a silent extension.
Risk assessment marked required but no Risk ID is linked.OSHA 1910.119(l)(2)(ii)Make the risk assessment link mandatory wherever Risk Assessment Required is Yes.
"What could this remove" left blank or answered "none" without examination.OSHA 1910.119(l)(2)(ii)Prompt with the categories that are usually lost: interlocks, cross-checks, redundancy, competency.
Training required marked but no course or completion evidenced before start-up.OSHA 1910.119(l)(3)Link the required course and block closure until training completion is evidenced for affected staff.
Senior approver missing on a high or very high risk band change.OSHA 1910.119(l)(2)(v)Enforce the senior approver field as required whenever the risk band is High or Very high.
Change closed with "all requirements complete" ticked while a triggered item, such as a drawing or permit update, is still open.ISO 45001 cl.8.1.3Derive closure eligibility from the state of every triggered requirement rather than a single manual checkbox.
No post-implementation review recorded, or review outcome missing on a change that should have one.ISO 45001 cl.8.1.3Schedule the post-implementation review at approval and require an outcome before the record is archived.
Emergency change implemented with no retrospective authorisation or documented reason for bypassing the normal sequence.OSHA 1910.119(l)(2)(v)Require emergency-category changes to carry a named authoriser and a reason within a defined grace period.

Case in point

Case in point: the jumper that outlived its justification

A packaging line's product detection interlock began nuisance-tripping during a supplier changeover. Maintenance raised an emergency MOC to fit a temporary jumper bypassing the interlock, marked Temporary, Emergency, with a five-day expiry set for the replacement part to arrive.

The part arrived late. The expiry passed with no escalation configured and no owner chasing it, because the field was informational rather than something anyone was accountable for. The jumper stayed in for eleven weeks, through a shift change and two supervisors, until an unrelated layered process audit noticed the bypass cable still in place.

Nothing failed catastrophically, which is why nobody had reopened the question. The fix was not a better original justification; it was making a temporary expiry generate an escalation to a named owner, rather than sitting quietly in a field nobody was required to check.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

47fields
8 sections
Reference
FDN-020
Archetype
Record
Record ID
MOC-2026-000
Scoring
Change risk band
Direction
High is bad
Singleton
Yes
Basis
OSHA 1910.119(l), ISO 45001 cl.8.1.3
Links
Linked from every workspace
Tags
Change
Sections
8
Fields
47
Follow up fields
0
Repeating sections
0
Links out
7
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

6 fields
Text

MOC ID*

Generated on save

Format MOC-2026-00000.

The record's own ID. Other templates point at this value.

Text

Case ID

OptionalThread key

Thread key

Single Choice

Parent Type

Optional
IncidentNear missFindingAuditInspectionRisk assessmentComplaintEquipment failureNonconformanceManagement of change
Text

Parent ID

OptionalThread key

Immediate predecessor record

Date & Time

Raised Date*

Users

Requested By*

Change detail

7 fields
Text

Change Title*

Single Choice

Change Type*

Equipment, process, material, people, procedure or organisational.

EquipmentProcessMaterialPeopleProcedureOrganisational
Single Choice

Change Category*

Permanent, temporary or emergency. Temporary changes must carry an expiry.

PermanentTemporaryEmergency
Text

Description Of Change*

What is changing, from what to what.

Text

Reason For Change*

Single Choice

Like For Like Replacement*

A true like for like replacement does not need full change control.

YesNo
Date & Time

Temporary Expiry Date

Optional

Required for temporary changes. Temporary changes that never expire are how process control disappears.

Scope

8 fields
Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Links to FDN-001 Site ID

Pick List

Assets Affected

OptionalFrom FDN-002 Asset NameFilter: Site matches
Text

Asset ID

OptionalLinked

Links to FDN-002 Asset ID

Pick List

Tasks Affected

OptionalFrom FDN-004 Task Name
Text

Job ID

OptionalLinked

Links to FDN-004 Job Task ID

Numeric Answer

People Affected

Optional
Multi Choice

Departments Affected

Optional
ProductionSanitationMaintenanceQualityWarehouseDespatch

Risk assessment

5 fields
Checkbox

Risk Assessment Required*

Required for anything that is not a like for like replacement.

Text

Risk ID

OptionalLinked

Links to FDN-012 Risk ID

Single Choice

Change Risk Band*

Scored

Drives the level of approval required.

  • Low3 pts
  • Medium2 pts
  • High1 pt
  • Very high0 pts
Text

What Could This Introduce*

New hazards created by the change.

Text

What Could This Remove*

Controls or safeguards that may be lost. This is the question people skip.

Requirements triggered

8 fields
Checkbox

Procedure Update Required

Optional
Checkbox

Training Required

Optional
Checkbox

Drawing Update Required

Optional
Checkbox

Spares Change Required

Optional
Checkbox

Permit Review Required

Optional
Checkbox

Emergency Plan Update Required

Optional
Text

Related Document ID

OptionalLinked

Links to FDN-008 Document ID

Text

Related Course ID

OptionalLinked

Links to FDN-007 Course ID

Related records

1 field
Text

Effectiveness Verification ID

OptionalLinked

The check that the change actually worked.

Links to FDN-016 Verification ID

Approval

7 fields
Users

Technical Approver*

Users

Safety Approver*

Users

Operations Approver*

Users

Senior Approver

Optional

Required where the change risk band is high.

Signature

Approval Signature*

Date & Time

Approval Date*

Single Choice

Approval Status*

Scored
  • Approved2 pts
  • Approved with conditions1 pt
  • Rejected0 pts

Implementation and closure

5 fields
Date & Time

Implementation Date

Optional
Checkbox

All Requirements Complete

Optional

The change cannot close until every triggered requirement is done.

Date & Time

Post Implementation Review Date

Optional
Single Choice

Review Outcome

OptionalScored
  • No change needed3 pts
  • Minor amendment2 pts
  • Major revision1 pt
  • Merge2 pts
  • Retire2 pts
Signature

Closure Signature

Optional

FDN-020 · record IDs look like MOC-2026-000 · Linked from every workspace

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The record is straightforward to fill in. What actually slips is the tail: the expiry nobody chased, the training that was marked required but never linked to a completion, and the procedure update that stayed open after the change went live.

KnowMaintain

Tracks the drawing, spares and equipment record implications of a change through to closure, so a change to an asset updates the asset's own record rather than sitting only in the MOC.

KnowTrain

Turns a Training Required tick into an actual course assignment and completion check for affected staff, and blocks the change from closing until it is evidenced.

KnowSafe

Holds the linked risk assessment and permit review against the change, and flags a non-like-for-like change with no risk assessment attached.

Ella
Ella

Watches temporary change expiry dates and post-implementation review dates as they come due, raising them to the named owner rather than waiting for someone to notice.

This template lives in General — control tower. The orchestration layer. Registries and engines every other workspace reads from.

Meet General→

Glossary

Management of Change definitions and key terms

Management of change
The formal process of assessing a change before it is implemented, so that its technical basis, safety impact, procedure, training and authorisation implications are addressed in advance rather than discovered afterwards.
Replacement in kind
A change so identical to what it replaces in specification, rating, manufacturer and installation that it is exempt from the full management of change procedure under OSHA 1910.119(l)(1).
Process safety information
The documented technical basis for a covered process: chemistry, technology, and equipment data, which a change must be checked against and, where affected, updated to reflect.
Change risk band
The rated significance of a proposed change, used here to drive the level of approval required; a high band should mean a senior approver, not just a technical one.
Temporary change
A change approved for a bounded period with a stated expiry, after which it must be removed or re-authorised as permanent through the full process, not extended by default.
Emergency change
A change implemented faster than the normal authorisation sequence allows because of an immediate operational or safety need, requiring retrospective authorisation and a documented reason.
Post-implementation review
The check, after a change has been running for a period, of whether it worked as intended and whether it should be retained, amended, merged or retired.
Effectiveness verification
Confirmation that a completed change achieved its intended outcome without introducing a new failure mode, distinct from the approval that authorised the change to proceed.

FAQ

Frequently asked questions about management of change

Does every change need a management of change record?+

Every change that is not a genuine replacement in kind does. The exemption is narrow: same specification, same manufacturer, same rating, same installation method, same operating conditions. A change that differs on any of those, even where it looks like routine maintenance, should go through the full process rather than being waved through as like-for-like.

Who has to approve a management of change?+

Technical, safety and operations approval as a baseline, with a senior approver added where the change risk band is high or very high. The approval chain should scale with the risk the record itself has just rated, which is why the senior approver field is conditional rather than universal.

What happens if a temporary change's expiry date passes?+

It should force a decision, not disappear. Either the change is removed and the original condition restored, or it is re-authorised as a permanent change through the full assessment, procedure update and approval sequence a permanent change requires. Extending the temporary period without that reassessment defeats the purpose of having called it temporary.

Does a risk assessment have to be attached to every MOC?+

Where the Risk Assessment Required field is Yes, which it should be for anything that is not like-for-like, then yes, and the Risk ID field should be populated with a real linked record, not left blank because the change felt minor. Minor is a conclusion the risk assessment is supposed to reach, not an assumption that excuses doing it.

Can implementation start before approval is complete?+

No. The entire value of management of change is that assessment happens before implementation. A record where the implementation date precedes the approval date has stopped functioning as a gate and become a log of a change that already happened, which will not survive scrutiny after an incident.

What is the difference between management of change and a risk assessment?+

Management of change is the gate that decides a change needs assessing and tracks everything the change disturbs: procedures, training, drawings, spares, permits and emergency plans. The risk assessment is the hazard analysis itself, done as a linked record. Treating the MOC form as though it were the risk assessment is how the hazard analysis gets skipped while the paperwork still looks complete.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • OSHA 29 CFR 1910.119(l), Process Safety Management of Highly Hazardous Chemicals — Management of change
  • ISO 45001:2018 clause 8.1.3, Management of change
  • COMAH Regulations 2015 (Control of Major Accident Hazards), UK/EU
  • CCPS Guidelines for Management of Change for Process Safety
  • OSHA General Duty Clause, Section 5(a)(1) (US)

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.