Change control is often reduced, in practice, to a log of what changed and when. Its actual purpose is narrower and more consequential: every equipment, process, or system change needs an explicit, documented assessment of whether that change requires re-qualification or re-validation — not just a record that the change occurred.
The re-qualification question, explicitly
A change control record that doesn't ask — and answer — "does this change require re-qualification?" has recorded the change but skipped the actual quality decision. This is the gap between a change log and real change control.
Specific, real inspection findings
- Calibration status not verified at IQ (Installation Qualification) execution — the qualification was performed on equipment whose current calibration wasn't confirmed.
- OQ (Operational Qualification) acceptance criteria set looser than the actual process requirements — proving the equipment works over a range wider than what you'll actually use it for, without proving it works for your real conditions.
- Change control records that don't explicitly assess whether re-qualification is needed — the change is logged, but the quality question is never asked.
Why this connects directly to Quality Risk Management
Revised Schedule M formally introduced Quality Risk Management (QRM) as a named requirement. Change control is one of the most concrete places QRM should show up in practice — every change assessed for risk, not just recorded.
A complete change control record
- What changed, and why — the business or quality reason driving the change.
- Explicit risk assessment: what could this affect?
- Explicit re-qualification/re-validation decision, with justification either way.
- Approval before implementation, not after-the-fact documentation.
- Linkage to any resulting validation activity, so the evidence chain stays connected.
Ready to see this in your own lab? Book a free ValiCore demo.