Quality Systems

Change Control

What a definition is not

A definition is SPEQ’s plain-language decode of how a term is used in practice, cited to the documents that define it. It is a practitioner reference, not legal or regulatory advice, it does not replace the definition in the source, and where a regulator’s wording differs the regulator’s wording governs.

The formal process for evaluating, approving, implementing, and documenting changes to a validated process, system, or document — assessing risk before implementation so improvements do not introduce new problems.

FULL EXPLAINERChange Control

Change control is the system that lets a validated operation change without losing its validated state. Every proposed change — to a process, material, supplier, equipment, facility, computerised system, or document — is assessed before implementation for its impact on product quality, on the validated status of what it touches, and on the marketing authorisation or registration.

The critical question is regulatory reportability, and it is frequently mishandled. Some changes are internal; others require notification or prior approval from every regulator where the product is registered, and the thresholds differ by market. Implementing a change that needed prior approval, or shipping product made under it, is a serious compliance failure — and the assessment must cover every market, not just the home one.

The back half of the process is where systems fail quietly. A change is not complete when it is approved: it needs implementation actions tracked, affected documents and training updated, requalification or revalidation where required, and a post-implementation review confirming the change did what it was supposed to and introduced nothing unexpected. ICH Q12 extended this thinking with established conditions and post-approval change management protocols, agreeing in advance how defined future changes will be handled.

KEY POINTS
  • Assess before implementation: product quality, validated status, and regulatory impact.
  • Determine reportability for every market where the product is registered — thresholds differ.
  • Never implement a prior-approval change before approval, or ship product made under it.
  • Track implementation: documents, training, requalification/revalidation.
  • Post-implementation review confirms the intended effect and no unintended ones.
  • ICH Q12 (established conditions, PACMPs) agrees the handling of future changes in advance.
REGULATORY BASIS

21 CFR 211.100 and 314.70 (post-approval changes); EU GMP Part I Chapter 4 and Annex 15 §11; Commission Regulation (EC) No 1234/2008 on variations; ICH Q10 §3.2.3 (change management system) and ICH Q12 (lifecycle management).

Frequently asked questions

What is Change Control?

The formal process for evaluating, approving, implementing, and documenting changes to a validated process, system, or document — assessing risk before implementation so improvements do not introduce new problems.

Which regulations cover Change Control?

21 CFR 211.100 and 314.70 (post-approval changes); EU GMP Part I Chapter 4 and Annex 15 §11; Commission Regulation (EC) No 1234/2008 on variations; ICH Q10 §3.2.3 (change management system) and ICH Q12 (lifecycle management).