VariloVIMS

Management of Change — assess the risk before the change reaches production

Most serious events do not come from routine work but from something new: a replaced unit, an altered parameter, a different raw material, a reshuffled crew. MOC brings order to the moment when risk appears that no assessment describes yet.

  • Change management
  • Change risk assessment
  • Approval routing
  • Post-change verification
V-IMS — Management of Change module showing a change request register with category, risk score, approval path, implementation task list and reviewers
V-IMS — Management of Change module showing a change request register with category, risk score, approval path, implementation task list and reviewers

The temporary fix that stayed

The hardest case in change management is rarely technically complex. It is the workaround introduced for a single shift to keep production running: a bypassed interlock, a different hose, a substitute pump, a sensor switched off for a moment. Nobody planned for it to last, so no record was created.

A few weeks later nobody remembers the current state is improvised. The operating instruction describes the original layout, the risk assessment describes the original layout, and the plant runs differently. The next overhaul or the next change is layered on top of an unregistered modification.

The point of MOC is precisely this: a temporary change gets an end date, an owner and conditions for returning to the target state. The register is not there to slow work down — it is there to stop a workaround quietly becoming the norm.

Four categories of change, four different risks

A technical change concerns equipment, installations and safeguards. Its risk is the most tangible and the most often assessed, because it is visible on site and usually requires work to be carried out.

A process change — a different parameter, formulation or raw material — can be invisible and still transform the nature of the hazard. A new solvent with a different flash point looks no different from the last one, yet it calls for a different approach to explosive atmospheres and different controls.

An organisational change is the one most often skipped. Reducing night shift staffing, moving supervision, removing a checking station or redefining duties reshapes the safety system just as genuinely as replacing a machine.

The fourth kind is documentary: a new revision of an instruction, a different emergency procedure, a modified training scope. It looks harmless in itself, but it is often the only trace left by a change from one of the other three categories.

What the Management of Change module gives you

Change request register

Every change with its category, description, justification, initiator and planned implementation date.

Change risk assessment

Analysis of the hazards the change introduces, carried out before implementation rather than after.

Review and approval routing

Required positions from engineering, safety, maintenance and production on a single path.

Implementation tasks

Conditions to be met before start-up: documentation, training, safeguards and checks.

Temporary changes with an expiry

Time-limited solutions with an end date and a reminder to restore the target state.

Post-change verification

Confirmation that the change works as intended and that documentation has been updated.

How a change request flows

The path is graded: the depth of assessment and number of approvals follow the change's impact on safety.

  1. 1Change raised with description and justification
  2. 2Classification and assessment of the risk it introduces
  3. 3Review by engineering, production and safety
  4. 4Approval together with implementation conditions
  5. 5Pre-start tasks completed and change implemented
  6. 6Documentation updated and change verified

Proportionality, or how not to kill MOC with formality

The usual reason an MOC rollout fails is not resistance to risk assessment but the weight of the procedure. If swapping an identical pump for an identical pump follows the same path as rebuilding a process unit, people start bypassing the system and revert to verbal arrangements.

The process therefore has to be graded. A low-impact change needs a short record and one approval. A medium-impact change needs a risk assessment and input from several departments. A high-impact change takes the full path with analysis, pre-start tasks and verification afterwards.

The criteria for assigning a category are worth agreeing once and writing down rather than leaving to judgement. Three questions usually suffice: does the change touch safeguards, does it affect exposure factors, and does it change how people do the work.

A change does not end at start-up

The moment of start-up is deceptive. The plant runs, production flows, the request looks closed — while the workplace instruction still describes the previous layout, the risk assessment has not been reviewed, and the third shift learned about the change from the handover book.

Closing an MOC request should therefore require confirming the things most easily skipped: documentation updated, information passed to every shift, workplace instruction refreshed, and the risk assessment reviewed for the affected roles.

It is also worth scheduling a review some time after start-up. Some consequences only appear in unusual conditions — during restart after a shutdown, at full load or during a failure, which is exactly when you least want to discover something was not anticipated.

Findings from such a review connect naturally to corrective actions, so a change that needs fixing does not end up without an owner and a date.

Frequently asked questions about Management of Change

How does MOC differ from a maintenance request?

A maintenance request restores the original state; MOC covers situations where the state after the work differs from before. Like-for-like restoration needs no change assessment, introducing something new does.

Does every small change need the full path?

No. The process should be graded by impact on safety. Low-impact changes need a short record, while full analysis is reserved for significant ones.

Who should review a request?

Usually maintenance, technology, production and the safety team, and for substance-related changes also those responsible for chemicals and environment. The set depends on the change category.

How are temporary changes controlled?

A temporary change receives an owner and an expiry date, and a reminder appears before that date to either restore the target state or formalise the change permanently.

Is MOC connected to risk assessment?

Yes. An approved change signals a review of the risk assessments for the affected workplaces, because the hazard description no longer matches reality.

What should be required to close a request?

Confirmation that implementation tasks are done, documentation and instructions updated, all shifts informed, and verification that the change performs as intended.

Related modules

VIMS module

Run risk assessment online: hazards, risk levels, control measures and reviews in one place, connected to what actually happens on site.

Risk assessment

VIMS module

No more action lists in a spreadsheet. Every action has an owner, a deadline, a status and an effectiveness check — all in one view.

CAPA

VIMS module

One substance register, current safety data sheets available from a phone and full control over what is used where on site.

Chemicals and SDS

Take control of changes before they change your risk

Book a demo and follow an MOC request from submission through to post-implementation verification.