The short answer
GMP change control is the formal system that assesses, approves, implements and verifies a planned change before it is made, so the validated state and the registered dossier stay intact. Quality approves before implementation.
- 1Raise the request
- 2Classify the change
- 3Assess the impact
- 4Approve before implementing
- 5Implement and verify
- 6Check effectiveness and close
Change control is the system that keeps a validated, registered and inspected operation true to its own records. A process is validated as it ran on the day the evidence was produced. A marketing authorisation describes the product as it was filed. Every change after that day either keeps that evidence relevant or quietly invalidates it, and change control is how a site knows which one just happened. This guide covers the definition, the regulations, the process step by step, a worked example and the findings inspectors write most often.
What is change control in GMP?
Change control, also called change management, is a formal system in the pharmaceutical quality system by which a proposed change to a facility, system, equipment, process, material, specification, method, supplier or document is requested, assessed by the people who understand each affected area, approved by Quality before it is made, carried out in a controlled way and checked afterwards, with a complete traceable record. It applies to permanent and temporary changes, and to changes that look small. The size of the job does not decide whether something is a change. The possible effect on product quality, the validated state or the registered particulars decides.
Which regulations require it
- EU GMP Chapter 1, paragraph 1.4(xi): arrangements for the prospective evaluation of planned changes and their approval prior to implementation, taking regulatory notification into account.
- EU GMP Annex 15, section 11: written procedures for change, quality risk management of planned changes, and an evaluation of effectiveness after implementation.
- EU GMP Annex 11, section 10: changes to computerised systems are made in a controlled manner according to a defined procedure.
- EU GMP Part II, section 13 (ICH Q7): a formal change control system for active substances, with quality unit review and approval.
- ICH Q10, section 3.2.3: a change management system that provides a high degree of assurance that there are no unintended consequences of the change.
- 21 CFR 211.100(a): written procedures for production and process control, with changes drafted, reviewed and approved by the appropriate organisational units and by the quality control unit.
- Commission Regulation (EC) No 1234/2008: the classification of variations (Type IA, IB and II) that a change to a registered particular can trigger.
- ISO 13485 (clauses 7.3.9 and 4.1.4) and Regulation (EU) 2017/745 for medical devices, including notification of substantial changes to the notified body.
The common thread is timing and authority. The evaluation is prospective, the approval comes before implementation, and approval sits with the Quality Unit. If your procedure permits work to start before Quality has signed, it does not meet any of these texts.
What needs change control
Any intentional modification to something in a controlled state: premises and utilities, equipment, computerised systems, manufacturing and cleaning processes, raw materials and components, specifications and test methods, packaging and labelling, suppliers and contract partners, documents and SOPs, key personnel and organisation, and storage and transport conditions. Routine maintenance under an approved procedure, editorial document corrections and genuine like-for-like replacements usually sit outside the system, but only when your procedure defines them tightly. The full scope question, with examples of what is and is not like-for-like, is in the guide on what needs change control in GMP.
The GMP change control process, step by step
- Raise: the change owner opens a change request before any work starts. It states the current state, the proposed state, the reason and the products, systems and documents expected to be touched. A change that has already been made is not raised; it is a deviation.
- Classify: Quality assigns a class (minor, major or critical, or your own equivalent) against defined criteria and writes down the rationale. The class sets the depth of assessment and who must approve. When in doubt, classify upward.
- Assess: every affected area completes a documented impact assessment. A 'no impact' answer carries a reason. Typical areas are regulatory, product quality and stability, validation and qualification, documents, training, suppliers, computerised systems and data, stock and open batches, and resources.
- Approve: Quality reviews the assessments and approves, rejects or approves with conditions before implementation. Major and critical changes add the department head, the qualified person or responsible person and management. Regulatory approval, where a variation is needed, is obtained before implementation of the affected part.
- Implement and verify: the change owner executes the action plan: revise documents, train people, qualify or validate, notify suppliers, update systems. Each task is closed with evidence, and the change goes live only when every pre-implementation task is complete.
- Check effectiveness and close: after a defined period, someone independent of the change owner confirms the change achieved its purpose and caused no unwanted effect, using the criteria written before approval. Quality closes the record with a conclusion, not a count of closed tasks.
Each step has a failure mode that inspectors know well. Raising late, classifying by convenience, assessing in a single paragraph, approving after the fact, closing on task completion and never checking effectiveness are the six that make up most findings. The guides on classification, impact assessment, approval and verification, and effectiveness checks take each one in turn.
A worked example
Who does what
- Change owner: raises the change, writes the proposal, executes the plan and is responsible for the evidence. Never approves their own change.
- Subject matter experts and department heads: complete the impact assessment for their area and own the actions that follow.
- Quality assurance: classifies, challenges the assessments, approves or rejects, verifies completion and owns the system. Quality approval is never delegated to the person who performs the work.
- Qualified person or responsible person: consulted on major and critical changes and on anything that affects batch certification.
- Regulatory affairs: decides whether a registered particular changes and which variation category applies.
- Management: approves major and critical changes and reviews change metrics in management review.
The findings inspectors write most often
- Change implemented before approval, or approved retrospectively.
- Impact assessment incomplete, generic or written only by the change owner.
- No regulatory assessment against the dossier, or a variation not submitted.
- Like-for-like claimed without a documented equivalence check.
- Validation, training or documents not updated before go-live.
- Temporary or emergency changes that never closed or never reverted.
- No effectiveness check, or one with no criteria.
- Changes to computerised systems made through IT tickets outside change control.
Most of these appear in the weekly findings library on this site with the clause cited and the corrective approach shown. A good habit is to read the findings that match your own area and run the same questions against your last ten closed changes.
How to test your own system
Pick five closed changes at random. For each, check that the request predates the work, that the class has a written rationale, that every affected area has a signed assessment with reasons, that approval predates implementation by date and time, that training and documents were done before go-live, and that an effectiveness check exists with criteria. Then check the other direction: take five maintenance work orders, five SOP revisions and five IT tickets and ask whether any of them was a change that never entered the system. The ten-question self-check and the section-by-section checklist on this site follow the same logic.
Frequently asked questions
- What is change control in GMP?
- Change control is the formal, documented system that evaluates, approves, implements and verifies any planned change that could affect product quality, patient safety, the validated state or the registered dossier. The evaluation happens before the change and approval happens before implementation.
- Which regulations require change control?
- EU GMP Chapter 1 (1.4(xi)), Annex 15 section 11, Annex 11 section 10, Part II section 13 for active substances, ICH Q10 section 3.2.3 and, in the United States, 21 CFR 211.100(a) and 211.68. For devices, ISO 13485 and Regulation (EU) 2017/745 apply.
- What are the steps of a GMP change control process?
- Raise the request, classify the change, assess the impact across every affected area, approve before implementation, implement and verify the tasks, check effectiveness and close the record with evidence.
- Who approves a GMP change?
- The Quality Unit approves every change. Major changes also need the department head, and changes touching the licence, critical process parameters or sterility assurance need the qualified person or responsible person and management. The change owner never approves their own change.
- What is the difference between change control, deviation and CAPA?
- A change is planned and approved before it happens. A deviation is an unplanned departure that is investigated after it happens. A CAPA is the corrective or preventive action that follows an investigation, and it frequently needs a change control record to be implemented.
Related guides
- What needs change control in GMP? The scope question, answered with the regulations
- Change classification: like-for-like, minor, major, and the regulatory question
- The change control impact assessment: cross-functional, evidenced, and not a row of 'no' ticks
- Approval, implementation and verification: getting the sequence right
- Effectiveness checks and closure: proving the change worked
- Change control for computerised systems: Annex 11, GAMP 5 and the patch nobody assessed
- Change control vs deviation vs CAPA: how the three GMP records connect
- Emergency and temporary changes in GMP: how to move fast without losing control
- Change control form, template and SOP example: what a good one contains