
Ask a quality manager to reconstruct the story behind any painful nonconformance and there’s usually a change hiding in the middle of it. The supplier switched resin grades. Maintenance replaced a worn cam with a “better” one. The new scheduler moved the anneal step to second shift, where the oven runs cooler. Nobody intended harm; each change looked local and small to the person making it. The damage came from the absence of anyone asking the boring question: what else does this touch?
ISO 9001 knows this, which is why change appears in at least four places: clause 6.3 for planned changes to the QMS itself, clause 8.1 for controlling planned changes and reviewing the consequences of unintended ones, clause 8.3.6 for design and development changes, and clause 8.5.6 for changes in production and service provision. Teams often flatten all of these into one “management of change” form, and the flattening is where the trouble starts, because the clauses are asking different questions on different timescales.
6.3: changing the system on purpose
Clause 6.3 governs deliberate changes to the quality management system: reorganizing departments, adopting new software, adding a site, retiring a process. It asks four things be considered: the purpose of the change and its potential consequences, the integrity of the QMS, the availability of resources, and the allocation or reallocation of responsibilities and authorities.
That third and fourth item are the ones that get skipped. The classic 6.3 failure isn’t a bad decision, it’s an orphaned responsibility: the company restructures, the person who owned supplier audits leaves, and eight months later the audit schedule has a hole exactly the shape of their old job. Nobody decided to stop auditing suppliers. The change just never answered the question of who inherits what. A 6.3 review can be a single page, but the page has to name names.
8.5.6: the shop floor doesn’t schedule its changes
Clause 8.5.6 is narrower and faster: review and control changes for production or service provision to the extent necessary to ensure continuing conformity, and retain documented information describing the results of the review, who authorized the change, and any actions arising.
The phrase doing the load-bearing work is “to the extent necessary.” A full change board for swapping a coolant brand is theater; a verbal okay for moving a process to a different machine is negligence. Proportionality needs written criteria, the same way NCR triage does. A workable split: changes touching a customer requirement, a validated process, or a product characteristic get formal review with evidence; like-for-like replacements get a log entry; everything in between gets a named approver and a one-paragraph rationale. What can’t happen is the decision about which tier applies being made silently by the person who wants the change approved quickly.
The record requirement is precise and worth reading twice: results of the review, the authorizer, and actions arising. It’s the same triad as clause 8.7’s concession records, and for the same reason. A change is a small bet that conformity will survive it, and the standard wants to know who placed the bet and what they checked first.
The changes that never asked
Clause 8.1’s quiet second half requires reviewing the consequences of unintended changes and acting to mitigate adverse effects. This is the standard admitting something honest: some changes don’t announce themselves. The supplier’s sub-supplier changed. The raw material is at the other end of its spec band this quarter. The experienced operator retired and their replacement follows the work instruction exactly, which would be fine if the work instruction had ever matched what the experienced operator actually did.
You can’t review changes you never see, so the practical discipline is building tripwires. First-article checks after maintenance, not just after setup. Trend charts positioned to catch drift, not just breach. Supplier notification-of-change clauses in purchase agreements, with teeth. And the humblest tripwire of all: when an NCR investigation finds a change at the root, feed that back as a question about why the change traveled ungoverned, not just as a fix for the part.
One change, many documents
The most common audit finding in this territory isn’t a missing change form. It’s the half-propagated change: the process changed, the form was signed, and the work instruction still describes the old process. Now the shop floor has two authorities that disagree, and clause 7.5’s document control requirements have quietly failed because the change process and the document control process were never connected.
This is a systems problem more than a diligence problem. When the change record and the affected documents live in the same place, the change can’t close until the impacted documents list is dispositioned: revised, confirmed unaffected, or retired. When they live in different places, a spreadsheet here and a shared drive there, propagation depends on someone remembering, and the standard has strong opinions about controls that depend on remembering. The same linkage argument applies to training under clause 7.2: if the change altered how the work is done, the change record should show who needed to know and when they found out, or the first person to follow the old method isn’t committing an error, they’re following orders.
The audit you can run this week
Pick the last five changes you know happened, from any source: maintenance logs, purchasing records, revision histories. For each one, ask three questions. Was it reviewed before or after it took effect? Can you name the person who authorized it? Do the documents the operator sees today reflect it? Five changes, fifteen questions, one afternoon. If more than a couple of answers are “after,” “unclear,” and “not yet,” you don’t have a change management gap, you have a change management process that exists mainly on the day the auditor visits, and the difference between those is exactly what clause 8.5.6 was written to catch.