Core QMS

Change Control Procedure

Manages changes to products, processes, materials, and documents. Ensures all changes are evaluated for regulatory impact, validated where necessary, and properly documented before implementation.

Template Preview

What This Template Covers

  • Change Request Initiation
  • Impact Assessment & Classification
  • Change Review Board (CRB)
  • Implementation & Verification
  • Regulatory Notification Requirements

Unlock the Full Template

Enter your details below to access the complete Change Control Procedure with all sections, procedure steps, and form references.

No spam. Your info will only be used to contact you regarding OctoQMS.

Change Control Procedure

1. Purpose

This procedure defines the process for initiating, evaluating, approving, implementing, and verifying changes to products, processes, materials, suppliers, equipment, software, and documents within the Quality Management System. It ensures that changes are controlled to prevent unintended consequences, maintain product safety and efficacy, and comply with regulatory requirements.

2. Scope

This procedure applies to all changes including but not limited to: - Design changes (materials, specifications, drawings, software) - Manufacturing process changes (equipment, tooling, process parameters, facility) - Supplier or material changes - Labeling and packaging changes - QMS document changes (when the change affects product or process, beyond editorial revisions) - Equipment and calibration changes - Sterilization process changes Editorial corrections to QMS documents that do not affect meaning or intent are managed through Document Control (SOP-DC-001) and do not require a Change Control Request.

3. Responsibilities

Change Requestor: Any employee may initiate a change by completing the Change Control Request Form (FRM-CC-001). Change Owner: Assigned by the Quality Manager; responsible for executing the change plan and gathering evidence of successful implementation. Change Review Board (CRB): Cross-functional team (typically Quality, Engineering, Regulatory, Operations, Supply Chain) that evaluates and approves/rejects change requests. Chaired by the Quality Manager. Regulatory Affairs: Assesses regulatory impact, determines if submissions or notifications are required. Quality Manager: Manages the change control process, chairs the CRB, and approves final closure.

4. Procedure

4.1 Change Request Initiation - Complete the Change Control Request Form (FRM-CC-001) including: description of proposed change, reason/justification for the change, affected products/processes/documents, proposed effective date - Assign a unique Change Control Number: CC-[YYYY]-[Sequential] - Submit to the Quality Manager for triage 4.2 Impact Assessment - The CRB evaluates the change for impact on: - Product safety and performance (risk assessment per ISO 14971) - Regulatory compliance (510(k), CE marking, design dossier, Technical File) - Design verification and validation requirements - Manufacturing process validation - Supplier and supply chain - Labeling and IFU (Instructions for Use) - Sterilization and shelf life - Training requirements - Existing inventory and work-in-process 4.3 Change Classification - Major: Affects product design, intended use, safety, or regulatory status. Requires full CRB review, risk assessment, and may require regulatory submission prior to implementation. - Moderate: Affects manufacturing process, materials, or suppliers. Requires CRB review and may require process validation. - Minor: Administrative changes with no impact on product or process. May be approved by Quality Manager without full CRB review. 4.4 Change Approval - CRB reviews the impact assessment, risk analysis, and proposed implementation plan - Approval requires consensus of CRB members; dissenting opinions documented - Approved changes include: implementation plan with action items, responsible persons, target dates, and verification/validation requirements 4.5 Implementation - Execute the change plan per the approved implementation plan - Activities may include: design verification/validation testing, process validation, supplier qualification, document updates, training, risk file updates - Document completion of each action item with objective evidence - If implementation reveals issues, the CRB must be reconvened 4.6 Verification & Closure - Verify that the change was implemented as planned and that all action items are complete - Confirm that affected documents, training, and risk files have been updated - Quality Manager reviews all evidence and approves closure - Update the Change Control Log (FRM-CC-002) 4.7 Regulatory Considerations - Changes requiring regulatory submission (e.g., new 510(k), letter-to-file justification, Technical File update) must not be implemented until the required submission is accepted/approved - Regulatory Affairs maintains a Change Notification Matrix mapping change types to regulatory actions

5. Records

- Change Control Request Form (FRM-CC-001) - Change Control Log (FRM-CC-002) - CRB meeting minutes - Impact assessments and risk analyses - Verification/validation evidence - Regulatory submissions related to changes

6. References

- ISO 13485:2016 Clause 7.3.9 Design and Development Changes - FDA 21 CFR 820.30(i) Design Changes - FDA Guidance: Deciding When to Submit a 510(k) for a Change to an Existing Device - ISO 14971:2019 Risk Management - SOP-DC-001 Document Control - SOP-RM-001 Risk Management