How to create a change control process

How to design a change control process: define your change categories, keep the pre-approved list short, require a rollback plan, and draw the emergency route rather than pretending it does not exist.

A worked example, stage by stage

  1. Triage decides everything downstream

    Raised, logged in the register, then a three-way type decision. Standard changes skip straight to implementation, normal changes go to assessment, emergencies go to their own authority — one decision that determines the cost of the whole change.

  2. The assessment is the board's input

    Impact and risk assessed, scope and downtime window confirmed, the assessment recorded, then CAB review and approval. If the record does not specify what it must contain, the board spends its meeting asking for information rather than deciding.

  3. Rejection is a route, not a stop

    CAB feedback returns to the requester, who can revise and resubmit or accept deferral — and the emergency route joins here with its own authorisation. Processes without a revise loop produce changes that are abandoned rather than improved.

  4. Plan the rollback before the change

    Implementation and rollback planned together, window scheduled, change implemented. Planning the rollback at the same time as the change is what makes it real; written afterwards it is a paragraph nobody has tested.

  5. Verify, and loop if it failed

    Test and verify, with failure executing the rollback and returning to planning, then a post-implementation review and closure. A change control process that ends at implementation has no way of knowing its changes work.

How it works

  1. Define your three categories

    Write down what qualifies as standard, normal and emergency in your organisation, in terms of risk and blast radius rather than effort. A one-line configuration change to a payment system is not a standard change; a large but well-rehearsed routine deployment might be.

  2. Keep the pre-approved list short and owned

    Standard changes only work if the list is maintained. Give it an owner and a review date, and require a normal change to prove itself repeatedly before it joins. An unmaintained standard list becomes the route people use for everything.

  3. Specify the assessment record

    Turn the assessment step into a checklist: affected services and users, downtime window, risk rating, dependencies, test approach, rollback approach and who has been consulted. This is the single change that most improves a change advisory board's usefulness.

  4. Name the change authority and its cadence

    Who approves, how often they meet, and the cut-off for the agenda. Then name the emergency authority separately — the person who can authorise an out-of-hours fix is rarely the whole board, and leaving that undefined is how emergency changes end up unapproved.

  5. Require a rollback plan and decide who calls it

    Every change gets one, planned alongside the implementation. Decide in advance who has the authority to trigger it, how long it takes, and what threshold makes the call — during an incident nobody wants to be interpreting a policy.

  6. Draw the emergency route honestly

    Every organisation has one. Give it criteria, a named authority and a mandatory retrospective record within a fixed window afterwards. A drawn emergency route with a documentation obligation is a control; an undrawn one is just what happens at 2am.

Frequently asked questions

What is the difference between change control and change management?

Change control is the procedural part: how a specific proposed change is requested, assessed, authorised, implemented, verified and closed, with a record at each step. Change management is broader — the strategy, categories, roles, communication and improvement of the process itself, and in some organisations the people-side of organisational change entirely. The flowchart people need first is almost always change control, because it is what they follow day to day.

What are standard, normal and emergency changes?

A standard change is pre-approved, low-risk and repeatable, so it skips the board and follows a defined procedure. A normal change goes through assessment and authorisation. An emergency change is authorised by a reduced authority because waiting for the normal route would cause more harm than the change's risk. Define each by risk and blast radius rather than by size, and require emergencies to be documented retrospectively within a fixed window.

Who should be on a change advisory board?

People who can assess impact and speak for the affected services: service owners, operations, security where relevant, and someone representing the customer or business impact. Keep it small enough to make decisions and give it a chair with a casting vote. A board of fifteen reviews nothing carefully — and if a member has never raised a concern, they are attending rather than reviewing.

What should happen when a change fails verification?

Execute the rollback and return to planning, rather than trying to fix forward under time pressure. That is why the rollback plan is written alongside the change and the authority to trigger it is named in advance. After recovery, the failed change goes back through assessment with what was learned — treating it as a new change with no history repeats the same failure with different people.

Create your own change control process

The template behind this guide

Change control process flowchart — A change control process flowchart covering request, impact assessment, CAB approval, implementation, verification and closure, plus an emergency route.

More in Process mapping guides