How to Implement a Management of Change Procedure

TL;DR

  • Define what counts as a change. Any alteration to equipment, chemicals, technology, procedures, or staffing — but not a genuine replacement in kind.
  • Anchor it in the right rule. OSHA PSM and EPA RMP mandate written change control; ISO 45001 requires it for any organization.
  • Build a staged workflow. Request, screen, technical and hazard review, risk-based authorization, controlled implementation, training, pre-startup check, closeout.
  • Match rigor to risk. A minor swap needs a checklist; a high-hazard change needs a full hazard study and multi-discipline sign-off.
  • Close every action out. Most failures are reviews that spotted a hazard and never drove timely correction.

To implement a management of change procedure, define which changes require review, set risk-based authorization tiers, and route each change through a documented workflow: initiation, technical and hazard review, approval, controlled implementation, training, a pre-startup safety review, and formal closeout. The procedure must update affected process safety information and remain auditable.

A written management of change procedure is not an optional refinement. For any process covered by the US Process Safety Management standard, it is a legal duty under 29 CFR 1910.119(l), which demands documented control of every change to chemicals, technology, equipment, and procedures except a true replacement in kind (US OSHA).

The reason the rule carries weight is the record behind it: a poorly managed change is one of the most common threads running through catastrophic process incidents. What follows is how to build a management of change procedure that actually holds — what qualifies as a change, the standards that govern it, a step-by-step workflow, and the failure patterns that quietly defeat well-written programs.

Circular diagram illustrating the 8-stage Management of Change Lifecycle from identification through documentation, with key components including communication, training, and continuous improvement highlighted at the bottom.

What Counts as a “Change” Under Management of Change

A change is any modification that could alter the risk profile of a process or workplace before it is put in place. The scope is deliberately wide, and getting this boundary right is the single most consequential design decision in the whole procedure.

Regulators and the CCPS Risk-Based Process Safety framework group triggers into a few recognizable families:

  • Physical or technical changes — different equipment, materials, instrumentation, setpoints, or process conditions.
  • Chemical changes — a new substance, a different supplier grade, or a shift in inventory.
  • Procedural changes — revised operating limits, alarm settings, or startup and shutdown steps.
  • Organizational changes — restructuring, staffing reductions, role changes, or budget shifts that affect who supervises a process.

That last family is the one most programs miss. OSHA has been explicit that written MOC procedures apply to changes arising from organizational, personnel, or policy decisions, not only to hardware — a point set out in its standard interpretation on management of organizational change (US OSHA).

The replacement-in-kind line

The counterpart to “change” is the replacement in kind: a swap that satisfies the original design specification exactly. A true like-for-like replacement does not require an MOC — but a part that is almost identical is a change, and treating it as a swap is one of the most common ways hazards slip through.

The practical test is simple to state and easy to get wrong: if any specification, material, tolerance, or operating parameter differs, it is a change, not a replacement. When in doubt, screen it as a change.

Technician in server room replacing a power supply unit with an identical replacement, demonstrating like-for-like substitution in data center maintenance.

The Regulatory Basis: OSHA PSM, EPA RMP, and ISO 45001

Which rules govern your procedure depends entirely on what your facility handles and where it operates. Four frameworks cover the overwhelming majority of cases, and they do not all say the same thing.

Framework (jurisdiction)What it requires for changeApplies to
OSHA PSM, 29 CFR 1910.119(l) (US)Written MOC addressing technical basis, safety and health impact, procedure updates, duration, and authorizationProcesses with highly hazardous chemicals above thresholds
EPA RMP, 40 CFR 68.75 (US)A parallel MOC requirement inside the Program 3 prevention programStationary sources with regulated substances above thresholds
ISO 45001:2018, Clause 8.1.3 (international)A process to control planned temporary and permanent changes, plus review of unintended changes affecting health and safetyAny organization, any sector
COMAH 2015 / Seveso III (UK/EU)Modification procedures within the major-accident prevention dutyEstablishments holding dangerous substances above thresholds

Where the US standards are chemical-process specific, ISO 45001 is broader: Clause 8.1.3 makes change control a requirement for any organization implementing an occupational health and safety management system, from a warehouse to a hospital. If your site sits outside PSM or RMP coverage, this is usually the framework that still obliges you to manage change.

The US picture is also moving. EPA’s 2024 Safer Communities by Chemical Accident Prevention rule revised the RMP prevention program, with most provisions phasing in through 2027; the agency then announced in 2025 that it was reconsidering that rule, and proposed further changes in 2026 to realign RMP with OSHA PSM (US EPA). The core MOC requirement is stable, but the surrounding prevention-program obligations are genuinely in flux — so build your procedure against the current regulation, not a summary.

Regulatory content here reflects a general HSE professional understanding of US, UK, and international requirements as of 2026. It is not legal advice. Specific compliance questions, citations, or enforcement situations should go to qualified legal counsel in the applicable jurisdiction.

Four change management frameworks illustrated: ADKAR Model showing awareness through reinforcement, Kotter's 8-step process ascending stairs to sustained change, Lewin's three-step model of unfreeze-change-refreeze, and McKinsey 7S Framework with shared values at center.

How to Implement a Management of Change Procedure, Step by Step

A workable procedure routes every change through the same defined path, then scales the depth of review to the risk. The steps below reflect the elements OSHA requires under 29 CFR 1910.119(l) and the sequence competent programs use in practice.

  1. Initiate and screen. The originator submits a change request stating the technical basis and the reason. A gatekeeper decides whether it is a replacement in kind or a change, and assigns a risk tier.
  2. Assess the hazards. Scale the method to the risk — a what-if checklist for minor changes, a full HAZOP for complex or high-hazard ones. Evaluate the impact on safety, health, and the environment, including knock-on effects on adjacent equipment.
  3. Authorize. Competent, named approvers sign off against the assessed risk. Authorization also fixes the conditions and the time period the change may run for.
  4. Implement under controls. Execute only within the authorized scope, with interim safeguards defined. Any deviation restarts the review.
  5. Update information. Where the change alters process safety information — drawings, data sheets, safe operating limits — update it. Where it alters procedures, revise them before restart.
  6. Train affected people. Inform and train operators, maintenance, and contractor staff whose tasks the change touches, before startup. This is a specific requirement, not a courtesy.
  7. Conduct a pre-startup safety review. For new or modified covered facilities, verify readiness through a PSSR under 29 CFR 1910.119(i) before hazardous material is introduced.
  8. Close out. Confirm every action item is complete, make temporary changes permanent through proper documentation or reverse them, and record the change so the next audit can trace it.

Match authorization to risk

Not every change deserves the same scrutiny, and forcing a full hazard study on a trivial swap trains people to route around the system. Tier the review instead.

Change riskReview depthTypical approver
Low (clear, minor)Checklist review by an authorized personArea supervisor or process owner
MediumDocumented hazard review, e.g., what-ifOperations, engineering, and safety
High (hazardous, novel)Full hazard study plus PSSRMulti-discipline team and senior authority

This article provides general HSE knowledge. Life-critical changes — such as modifications to processes handling highly hazardous chemicals — must be reviewed and authorized by a competent person with relevant training, jurisdiction-specific authority, and a site-specific risk assessment. For structured competence, recognized pathways include NEBOSH and IOSH process safety qualifications, OSHA outreach training, and CCPS resources. The workflow here does not replace that.

Infographic illustrating eight sequential steps of a change management workflow, from identifying needs through documentation, with icons and descriptions for each phase in a business process.

Where Management of Change Procedures Fail

The most instructive failures are rarely a missing procedure — they are a procedure that ran and still let a hazard through. The published incident record points to a consistent set of breakdowns.

  • The MOC that never closed out. In the CSB’s 2025 investigation of three hydrogen fluoride incidents at Honeywell’s Geismar, Louisiana facility, corrosion had been identified years before a fatal release, yet replacement of the affected gaskets was repeatedly deferred (US Chemical Safety Board, 2025).
  • Temporary changes that quietly became permanent. A bypass or interim fix authorized “for a week” outlives its risk assessment when no expiry date or re-review is enforced.
  • The replacement-in-kind loophole. Treating a not-quite-identical part as a like-for-like swap skips the exact review the difference demanded.
  • Organizational change left unmanaged. Reorganizations, staffing cuts, and budget shifts change who watches a process but rarely trigger an MOC — a gap the CSB has now recommended OSHA close by amending 29 CFR 1910.119 to require MOC reviews for organizational changes affecting process safety (US Chemical Safety Board, 2025).
  • Sign-off without competence. Approvals collected as signatures rather than genuine technical review by people who understand the hazard.

None of this is new territory. The CSB flagged unmanaged change as a recurring cause of chemical incidents in a safety bulletin more than two decades ago, and the same pattern keeps surfacing — which tells you the fix is disciplined execution, not a better form.

Infographic explaining six key reasons why management of change programs fail, including poor communication and lack of leadership, with solutions and best practices for successful change management highlighted at the bottom.

Auditing and Sustaining a Management of Change Procedure

A management of change procedure decays the moment it stops being measured. Sustaining it means watching a small set of indicators that reveal whether the system is genuinely controlling change or just generating paperwork.

Track leading and lagging signals

Leading indicators tell you the process is working before something goes wrong; lagging indicators tell you where it already broke.

Indicator typeWhat to watch
LeadingPercentage of changes screened before implementation; open action items past due
LeadingTemporary changes with a defined expiry versus those without
LaggingIncidents or near-misses traced to an uncontrolled or bypassed change
LaggingAudit findings of MOC records that were never closed out

Keep the backlog honest

The most reliable warning sign is a growing list of overdue MOC actions. Review it on a fixed cadence, escalate anything tied to a hazard control, and treat a stalled action item as an open risk, not administrative debt.

Periodic revalidation matters too. Where standards require hazard studies to be revalidated on a set cycle, confirm that changes made since the last review were actually captured — drift between the plant as documented and the plant as operated is exactly what MOC exists to prevent.

Infographic showing five interconnected stages of Management of Change program health check: preparation and scoping, process assessment, technology and systems review, performance measurement, and consultant engagement, with icons representing risk mitigation, compliance, efficiency, and training.

Frequently Asked Questions

Management of change is a safety-driven review that checks whether a physical, procedural, or organizational change introduces new hazards before it is implemented. Change management is a broader business discipline focused on adoption, communication, and project delivery. They overlap, but MOC exists specifically to protect people, process integrity, and the environment.

No — provided it is a genuine replacement in kind, meaning the new item satisfies the original design specification exactly. The trap is mislabeling. If any material, tolerance, rating, or operating parameter differs, it is a change and must go through the full procedure, however minor the difference appears.

Yes, for covered processes. Under 29 CFR 1910.119(l) (US OSHA), employers running processes with highly hazardous chemicals above threshold quantities must establish written MOC procedures. Outside PSM coverage, ISO 45001 Clause 8.1.3 still requires organizations with a health and safety management system to control change.

Only for the duration the authorization specifies. Every temporary change should carry an expiry date and a mandatory re-review at that point — either to reverse it or to convert it into a permanent, fully documented change. Temporary fixes that outlive their authorization are a leading cause of process incidents.

Approval should sit with competent people matched to the assessed risk, not a single default signature. A minor change may need one authorized reviewer; a high-hazard change needs sign-off from operations, engineering, and safety, plus a pre-startup safety review. The point is genuine technical judgment, not administrative endorsement.

A PSSR under 29 CFR 1910.119(i) (US OSHA) is triggered for new facilities and for modified covered facilities where the change is significant enough to require updated process safety information. It confirms construction matches design, safety systems are in place, procedures are current, and training is complete before hazardous material is introduced.

Infographic showing six sequential steps for management of change implementation: gaining leadership commitment, defining scope and objectives, developing robust processes, implementing technology and tools, training personnel, and monitoring with continuous improvement.

Getting It Right

Implementing a management of change procedure comes down to four decisions you cannot afford to get wrong. Draw the change-versus-replacement line clearly, tier authorization so rigor tracks risk, drive every review to a closed-out action, and give temporary changes an expiry they cannot outlive.

The frameworks — OSHA PSM, EPA RMP, ISO 45001, COMAH — set the floor, but the failures in the record are almost never about a missing rule. They are about a change that was reviewed and then not finished, which is why the discipline of closeout matters more than the elegance of the form.

Treat the procedure as a living control, audited against its own backlog, and it does the job it was built for: catching the hazard in the change before the change catches you.