· QUALITY CAPABILITY

Change Control

GMPCSVQMS

Change control is the organisation's ability to manage deliberate change to anything in a validated or controlled state — a process, a material, a piece of equipment, a system, a specification, a supplier — so that its impact is understood and its regulatory and quality consequences are handled before it happens. The defining word is before. A change assessed and approved ahead of implementation is change control; the same change discovered after the fact is a deviation. That single distinction separates a capability that enables improvement from one that merely records damage.

All 16 capabilities →

What this page does not claim

A capability is something an organization must be able to do; it is not a maturity score and not an assessment domain. The scored domains measure how consistently capabilities are performed, they do not map one-to-one, and nothing on this page rates your organization.

What this capability is

Change control is the organisation's ability to manage deliberate change to anything in a validated or controlled state — a process, a material, a piece of equipment, a system, a specification, a supplier — so that its impact is understood and its regulatory and quality consequences are handled before it happens. The defining word is before. A change assessed and approved ahead of implementation is change control; the same change discovered after the fact is a deviation. That single distinction separates a capability that enables improvement from one that merely records damage.

The capability has three moving parts that are easy to do badly: a complete impact assessment that reaches everything the change touches (including the regulatory filings and the other systems that depend on it), an approval that involves the right owners, and verification that the change was implemented as approved and had the intended effect without an unintended one. Its hardest edge is scope — recognising that a "minor" change to a shared utility, a raw-material source, or a software configuration can reach far beyond where it was made.

WHY IT MATTERS

  • Change is how an organisation improves, and also how it loses control. Without a working change-control capability, every improvement is a gamble that nothing downstream broke — and the organisation cannot answer the inspection question of which version of the process made which batch.
  • The costliest failures are changes that were real but never recognised as changes: a supplier who altered their process, a "like-for-like" component swap that was not, a configuration change waved through as trivial. The capability's maturity is largely its ability to catch the change that does not announce itself.
  • It is the seam between quality and the regulatory filing. ICH Q12's established-conditions concept exists precisely to define which changes bind the marketing authorisation and which the quality system may manage itself — and a change-control capability that cannot see the filing will approve, in good faith, a change that required a regulatory submission.

[ POSITION IN THE FRAMEWORK ]

7 DIMENSIONS · 28 LINKS

Change control governs every deliberate move of a validated or filed state — process, material, equipment, system, supplier — so impact is assessed, approved, and verified before the change is made, wherever in the lifecycle it happens.

06 · QUALITY MATURITY — CHANGE CONTROL, REACTIVE TO ADAPTIVE

L1
Reactive

Changes happen and are documented afterwards, if at all. Impact assessment is whatever the person making the change thought to consider, and "we always did it that way" masks a drift of uncontrolled changes.

L2
Defined

A change-control procedure requires assessment and approval before implementation, with defined roles. It works for obvious changes but relies on people recognising that something is a change — so the subtle ones still slip through as deviations.

L3
Controlled

Change categories, impact-assessment criteria, and required approvers are defined and enforced; regulatory impact is screened against known commitments; and implementation is verified before the change is closed. Re-validation is scoped to what the change actually touched.

L4
Predictive

Change data is trended — volume, cycle time, the rate of changes that later caused problems — and used to tune the system. Established conditions are mapped, so the filing-versus-internal decision is made by construction rather than by memory.

L5
Adaptive

Change is managed as knowledge flow across the product lifecycle: the organisation anticipates the changes a process will need, pre-agrees fast paths for them (PACMP-style), and its change system connects seamlessly to suppliers, contract sites, and filings so a change anywhere is assessed everywhere it matters.

SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →

07 · REGULATORY & EVIDENCE

GOVERNING STANDARDS · 6

Derived from the 6 standards SPEQ maps to this subject, across 5 regulatory bodies: FDA, EMA, ICH, ISO, ISPE.

RECORDS & OBJECTIVE EVIDENCE

  • Change records with impact assessments reaching every touched system and filing
  • Regulatory-impact screening against registered commitments and established conditions
  • Pre-implementation approvals by the defined owners for each change class
  • Implementation verification and effectiveness evidence before closure
  • Supplier and contract-partner change notifications entering the same system

COMMON INSPECTION FINDINGS

  • Changes implemented before assessment and approval were complete
  • "Like-for-like" replacements never evaluated as changes
  • Impact assessment stopping at the department that made the change
  • Changes closed on implementation with no verification they worked
  • Supplier process changes discovered in deviations, not notifications
EVERY CHIP IS A DOOR · WALK THE FRAMEWORK FROM ANY SUBJECTHow SPEQ maps the framework →

HOW YOU’D SEE WHERE YOU SIT

  • Pick a recent process change and trace whether its impact assessment reached the regulatory filing, the connected systems, and the contract partners — or stopped at the department that made it.
  • How the organisation handles a supplier's notification of a change to their own process: as an incoming change control, or as an email that reaches no one with authority.
  • The ratio of planned changes to deviations that turned out to be unrecognised changes — a high proportion of the latter is the tell.
  • Whether "minor" is defined by criteria or by whoever wants the change to move quickly.
  • Whether change closure requires evidence the change worked as intended, or just evidence it was implemented.

Observable behaviours, not a self-rating — what a capability looks like from the outside, the same way SPEQ’s Quality Culture assessment reads behaviour rather than felt safety.

FREQUENTLY ASKED

What is the difference between change control and deviation management?

Timing, and it is the whole point. Change control handles an intended change before it is made — you propose it, assess its impact, get approval, then implement and verify. Deviation management handles an unintended departure from the approved state after it has happened — you contain it, investigate the root cause, and correct it. The same alteration to a process is a change if you planned it and a deviation if you discovered it. An organisation whose "changes" keep arriving as deviations does not have a change problem; it has a change-control-capability problem.

Why does change control need to consider the regulatory filing?

Because some changes to a product or process are commitments made in the marketing authorisation, and altering them without the right regulatory submission is a compliance failure even if the change itself improves quality. ICH Q12 introduced the concept of established conditions to draw this line explicitly: the elements that legally bind the filing versus those the quality system can manage on its own authority. A change-control capability that cannot see which is which will approve a change in good faith that actually required prior regulatory approval — a gap that surfaces at the worst possible moment.

How is change control measured in the maturity assessment?

Through the Documentation & Change Control domain, which scores how consistently an organisation evaluates and controls change before it happens rather than recording it afterwards. This capability page explains what the change-control function is and what maturity looks like from reactive to adaptive; the assessment domain measures where your organisation actually sits. The capability is what you must be able to do; the domain measures how well you do it.

MEASURED THROUGH THE MATURITY ASSESSMENT

This capability is about what you must be able to do. How consistently you do it is what the maturity assessment scores — through the domain below.

Contributes to the FDA QMM practice area Advanced Pharmaceutical Quality System (a SPEQ mapping).

Score your quality system →