Management of Change: The ISO Requirement Businesses Commonly Forget

Businesses change constantly.
A new software platform is introduced.
A supplier is replaced.
A team is reorganised.
A company moves premises.
New equipment is installed.
A process that has worked for years is redesigned.
Most of these changes are made for good reasons. They are intended to improve efficiency, reduce cost, support growth or solve an existing problem.
But change also creates risk.
And one of the most commonly overlooked parts of an ISO management system is making sure those risks are considered before the change is introduced.
This is where management of change matters.
Why change creates problems
The difficulty with change is that businesses naturally focus on the intended benefit.
A new software system might promise better reporting. A new supplier might reduce costs. A restructure might improve accountability.
What tends to receive less attention is what else might be affected.
For example, introducing new software could change:
how records are stored
who can access information
how staff complete their work
how data is backed up
how customers interact with the business
None of those issues necessarily mean the change is a bad idea.
They simply mean the change needs to be thought through properly.
The same principle applies across ISO 9001, ISO 14001, ISO 45001 and ISO 27001. Different standards approach change in different ways, but the underlying expectation is similar:
When something significant changes, consider the consequences before simply putting it into practice.
Changing software is about more than IT
Software changes are a good example because they often look deceptively simple.
A company decides to replace its CRM, document management platform or accounting system.
The decision may initially be viewed as an IT project.
But the effect can extend much further.
People may need retraining. Procedures may become outdated. Existing records may need migrating. Access permissions may change. Interfaces with other systems may stop working as expected.
From an ISO 27001 perspective, there may also be information-security implications.
From an ISO 9001 perspective, the change may affect how customer or operational records are controlled.
A sensible change process does not need to be bureaucratic, but it should ask:
What will change?
Who will be affected?
What could go wrong?
What controls need updating?
How will we know the change worked?
That small amount of structured thinking can prevent a lot of avoidable problems later.
Moving premises can affect far more than the address
Moving office, warehouse or operational premises is another classic example.
The obvious actions are usually handled well: utilities, IT, furniture, signage and customer notifications.
But a management-system perspective goes further.
Does the new location introduce different fire risks?
Are emergency arrangements still suitable?
Has the environmental aspects register been reviewed?
Are security controls appropriate for the new building?
Have legal or regulatory requirements changed?
Do customers or certification bodies need to be notified?
A premises move can potentially affect quality, environmental, health and safety and information-security controls at the same time.
If the management system is not reviewed, documents can quickly describe arrangements that no longer exist.
Supplier changes can introduce hidden risk
Changing supplier is often driven by cost, availability or performance.
But replacing a supplier can also affect quality, lead times, compliance, environmental performance or information security.
Imagine changing to a cheaper component supplier.
The price improves, but:
material specifications differ slightly
lead times are less predictable
traceability is weaker
inspection requirements increase
Or consider switching to a new cloud service provider.
The functionality may be better, but the organisation now needs to understand where data is stored, how access is controlled and what contractual protections exist.
Supplier approval should therefore not be treated as a one-off administrative exercise.
A significant change in supplier is a business change - and should be assessed as one.
Equipment changes need more than installation
New equipment can create similar issues.
A new machine might improve productivity, but it may also introduce new hazards, maintenance requirements or competence needs.
Before putting equipment into use, businesses should consider whether:
employees need training
risk assessments need updating
maintenance arrangements are defined
operating instructions are available
environmental impacts change
inspection or calibration requirements apply
The important point is that the equipment itself is only part of the change.
The surrounding system may need to change too.
Organisational changes are often underestimated
One of the most overlooked areas is organisational restructuring.
A manager leaves. Two departments are merged. Responsibilities are redistributed. A compliance role becomes part-time.
These changes can look harmless on an organisational chart.
But management systems rely heavily on ownership and accountability.
If responsibilities change, questions should follow.
Who now owns the process?
Who reviews performance?
Who approves corrective actions?
Who manages legal compliance?
Who organises internal audits?
Who has authority to escalate problems?
If those questions are not answered clearly, important controls can quietly disappear between job descriptions.
This is particularly common when an experienced person leaves and much of the system existed in their head rather than in the business.
Process changes can create unintended consequences
Businesses regularly improve processes, and rightly so.
But even a sensible improvement can create knock-on effects.
For example, removing a review stage may speed up delivery but reduce quality assurance.
Automating a manual step may reduce administrative effort but introduce dependence on software.
Outsourcing a process may reduce internal workload but increase supplier risk.
The purpose of management of change is not to prevent improvement.
It is to make sure improvement does not accidentally weaken something else.
What does a practical change process look like?
For most businesses, it does not need to involve a complicated change-control committee.
A simple approach is often enough.
Before a significant change is approved, consider:
What is changing and why?
What processes, risks or controls could be affected?
What actions are needed before implementation?
Who is responsible?
How will the change be reviewed afterwards?
The level of detail should match the significance of the change.
Replacing a printer does not need the same level of control as replacing your entire production system.
Changing an office chair supplier does not need the same scrutiny as changing a critical subcontractor.
Management of change should be proportionate.
The common mistake: reviewing change after something goes wrong
Many organisations are very good at investigating failures.
A problem happens, a nonconformity is raised, root cause is investigated and corrective action follows.
That is useful.
But management of change is about doing some of that thinking before the problem occurs.
If a major change is planned, asking “what could this affect?” is often much cheaper than discovering the answer later through:
complaints
downtime
incidents
data loss
compliance failures
rework
This is one of the reasons change management links so closely with risk-based thinking.
Your documents should change when the business changes
Another common weakness is that the business changes but the management system does not.
A new process is introduced, yet the old procedure remains.
A department is reorganised, yet responsibilities in the manual are unchanged.
A new supplier replaces the old one, but the approved supplier register is never updated.
Over time, this creates a gap between how the business says it works and how it actually works.
That gap is often where audit findings begin.
A good management system should move with the organisation.
Management review should look at significant change
Management review is also an ideal place to consider whether major changes have created new risks or altered priorities.
Rather than simply asking whether objectives have been achieved, management should also consider:
what has changed since the last review
whether existing controls are still appropriate
whether new risks have appeared
whether resources or responsibilities need adjusting
whether the management system itself needs updating
This helps keep the system relevant instead of allowing it to become a historical description of the business.
Final thought
Businesses should change.
They should adopt better technology, improve processes, find stronger suppliers and restructure when necessary.
ISO is not there to slow that down.
The purpose of management of change is simply to make sure improvement is controlled rather than accidental.
The most useful question to ask before any significant change is:
“What else could this affect?”
That one question can prevent a great deal of disruption.
Because the biggest risk is often not the change itself.
It is the consequence nobody thought to look for.
How well does your management system handle change?
If your organisation has recently changed software, suppliers, premises, equipment, processes or responsibilities, it is worth checking whether your ISO management system has kept pace.
Our free ISO Readiness Check can help you identify where your current arrangements may no longer align with the requirements of ISO 9001, ISO 14001, ISO 45001 or ISO 27001 - and highlight the areas that may need attention before your next audit.
👉 Take the free ISO Readiness Check here: https://www.aaa-cert.co.uk/get-certified-the-quick-and-easy-way
A few minutes now could highlight a gap that would otherwise only become visible when something goes wrong - or when an auditor finds it.




Comments