← Back to blog

Seven Stage SOP Change Control Mapped to ICH Q9 and Q10

September 29, 2026
Seven Stage SOP Change Control Mapped to ICH Q9 and Q10

An SOP for change control is a risk-based, documented process that ensures every operational change is evaluated, approved, implemented, and verified with an auditable trail. The single rule to follow is that formality should scale with risk across the full change lifecycle, not just the paperwork step. Success looks like a closed record: a change that was authorized, executed under control, and confirmed to work before anyone calls it finished.


TL;DR:

  • Changes affecting critical quality attributes or regulatory filings require detailed impact analysis, expanded testing, and sign-offs from expert teams at high risk levels.
  • Regulatory changes, such as site modifications or device amendments under FDA guidance, demand specific documentation and may trigger filings like pre-approval supplements or change notifications.
  • An effective SOP must include a comprehensive change request form, impact assessment, approval matrix, training records, and a retention schedule to ensure full traceability and compliance.
  • Automating routing and notifications speeds up the process but must still preserve human oversight, audit trails, and proper risk tiering to avoid common delays and compliance issues.
  • Cross-functional review panels, portfolio audits, and metrics on knowledge sharing mitigate common QA traps of treating change control as isolated paperwork rather than a strategic launchpad.

Haiphai
Streamline Your Change Control Operations
HaiPhai helps life sciences teams identify operational bottlenecks and integrate AI into processes such as regulatory drafting and clinical site activation.
Explore HaiPhai

Table of Contents

Change control versus change management: scope and triggers

Change control is the tactical procedure that reviews and authorizes one specific change. Change management is the broader, portfolio-level system that governs how an organization plans, prioritizes, and learns from changes across products and processes over time. ICH Q10 treats change management as a lifecycle discipline that sits above individual change-control transactions and requires quality risk management, expert input, and evaluation after implementation.

Confusing the two is a common SOP-drafting mistake: teams write a single procedure for approving changes but never build the portfolio view that catches recurring problems or resourcing conflicts. U.S. drug manufacturers must also anchor their SOPs to 21 CFR 211.100, which requires written procedures for production and process control, drafted and approved by the quality unit.

Typical triggers your SOP should list explicitly, including process or specification changes such as yield adjustments, equipment changes from calibration updates to replacements, supplier or raw material changes including vendor list edits, analytical method updates and revalidation, software or automated system configuration changes, and revisions to batch records or master documents ranging from formatting to critical field edits.

Change control versus change management: scope and triggers — overview diagram

Step-by-step change control process to include in the SOP

Your SOP should walk a change through seven stages, each with defined inputs, outputs, and a named owner.

  1. Initiation: The requester submits a change request with a description, business or quality rationale, affected product or process, and proposed timeline.
  2. Assessment: The change owner maps scope: which documents, systems, equipment, and downstream processes are touched.
  3. Risk tiering: Quality assurance assigns a risk level that determines the review path and testing depth.
  4. Approval: Defined reviewers sign off, with escalation to management or a change control board when risk or scope crosses a set threshold.
  5. Implementation: Execution happens under controlled conditions, including training completion and controlled distribution of updated documents before use.
  6. Verification and monitoring: Acceptance criteria are checked, sampling or trending data confirms performance, and any nonconformance links to CAPA.
  7. Closure: A post-implementation review confirms the change achieved its intent, and the full record is retained per your document control procedure.

Pro Tip: Build a single change request form that carries the record through every stage rather than switching templates between initiation and closure. It cuts data re-entry and keeps the audit trail intact.

Each stage needs a clear handoff. A change that stalls between assessment and approval because nobody owns the escalation is the most frequent finding auditors raise.

Mapping ICH Q9 and Q10 to your risk criteria

Quality risk management is the engine that decides how much scrutiny a change gets, not a separate compliance exercise bolted onto the process. ICH Q10 requires that change management draw on the same risk principles as ICH Q9, and that expert teams evaluate changes touching product or process understanding before and after implementation.

A workable three-tier structure:

  • Low risk: Administrative or cosmetic changes with no impact on quality attributes; documented approval by the change owner and quality assurance is sufficient.
  • Medium risk: Changes affecting a validated parameter or supplier; require impact assessment, defined testing, and cross-functional sign-off.
  • High risk: Changes affecting critical quality attributes or regulatory filings; require expert-team review, expanded testing, and documented rationale for every control decision.

Recurring audit findings center on missing rationale, incomplete impact analysis on downstream documents, and skipped post-implementation verification, according to practitioner guidance built on ICH and FDA materials. SOPs that force explicit fields for rationale and verification close most of that gap.

Regulatory triggers and filing considerations

Some changes trigger a regulatory obligation, not just an internal approval. Your SOP needs a checklist step that flags these before implementation begins.

  • Predetermined Change Control Plans (PCCPs): Under Section 515C and FDA's draft guidance, device manufacturers can pre-authorize categories of future modifications within a marketing submission, described through a Description of Modifications, a Modification Protocol, and an Impact Assessment. The SOP must document conformance to the approved PCCP and include deviation controls for anything outside its bounds.
  • Manufacturing site changes: FDA guidance on site change supplements outlines when a site or manufacturing change requires a PMA supplement versus a 30-day notice, and what to document, including inspection history and supplier changes.
  • Drug-sector written procedures: 21 CFR 211.100 ties every procedural change back to quality unit review, with deviations recorded and justified.
  • Cross-border changes: confirm whether a change affects an existing marketing authorization in another region before implementation.

Essential SOP elements and records

A change control SOP is only as strong as the forms and records it requires. At minimum, build in:

  • A change request form capturing requester, date, affected product or process, description, and business or quality rationale
  • An impact assessment section covering affected documents, systems, equipment, and validation status
  • An approval and signature matrix defining required reviewers by risk tier, with escalation rules for disagreement
  • A training record and controlled distribution plan confirming affected staff were trained before the change went live
  • A retention schedule that keeps the full record, from request to closure, available for the product's documented retention period

21 CFR 211.180 requires records to support annual product quality evaluations and to identify when specifications or procedures need revision, which is a direct reason to keep change records searchable rather than filed away.

Recordkeeping and versioning without vendor lock-in

Keep one document library as the single source of truth for SOPs and change records, with strict version control so no one can execute against an outdated procedure. Electronic systems used for approvals should maintain audit trails and honor basic Part 11 considerations around electronic signatures and record integrity.

  • Automate routing, reviewer notifications, and training assignment: repetitive, rule-based steps that do not require judgment
  • Keep risk tiering, rationale review, and final approval as human-reviewed decisions
  • Log every automated action in the same audit trail as manual steps, not a separate system log

Pro Tip: Automate the reminder that a training record is overdue, but never automate the decision that a change is low risk. That judgment call is where audit findings live.

How an embedded operational partner speeds compliant change control

Operational diagnostics on live change control processes typically reveal that most delay happens between assessment and approval, not in execution. Governed automation can shorten that administrative gap, but it still needs quality-unit oversight and validation before it touches regulated records.

  • Diagnostic review maps where changes stall and why, before any tooling is proposed
  • Automation gets built around existing approval hierarchies, not around a generic template
  • Every automated step stays subject to the same governance and audit trail as a manual one

Common traps QA teams fall into

QA teams often treat change control as isolated, reactive paperwork, missing the portfolio view and skipping documented rationale. The fix is a cross-functional review panel, scheduled portfolio audits, and metrics on knowledge transfer between changes.

— John

HaiPhai's approach to governed change control automation

An embedded operational partner approach starts with a diagnostic on your change control bottlenecks and builds a prioritized roadmap from there.

  • The operating partnership and AI Velocity Diagnostic identify where administrative delay sits in your current process
  • Governed automation gets implemented with quality-unit sign-off built into every step
  • Teams that want hands-on help can start with a diagnostic review of their current change control cycle

Haiphai

Sources

FAQ

What is change control SOP?

A change control SOP is a written procedure that governs how a proposed change to a process, document, equipment, or system gets evaluated, approved, executed, and verified. It requires a documented rationale, a risk assessment, and a closure record confirming the change worked as intended.

What are the 5 C's of change leadership?

Definitions vary across change management frameworks, and no single sourced version applies universally to regulated change control SOPs. Most versions emphasize communication, commitment, capability, culture, and continuity, but a regulated SOP should be built on ICH Q9 and Q10 risk principles rather than a generic leadership model.

What does SOP stand for in ATC?

In air traffic control, SOP stands for Standard Operating Procedure, the same general concept used across regulated industries: a written procedure that standardizes how a task or decision gets performed. In quality and regulatory settings, an SOP for change control applies that same idea specifically to evaluating and authorizing changes.

What are the steps of a change control procedure?

A change control procedure typically runs through initiation, assessment, risk tiering, approval, implementation, verification, and closure. Each step needs a defined owner and a documented output, from the initial change request to the post-implementation review that confirms the change met its objective.

Why does change control matter for audit readiness?

Change control records are one of the first things inspectors review because they show whether a company controls its own process instead of drifting from it undocumented. 21 CFR 211.180 requires records that support annual product quality evaluation, which means an incomplete change record can flag a broader documentation gap during inspection.