ISO 45001 Change Management: Keeping Your OH&S System Current
You introduce new equipment to speed up production. Nobody thinks to ask: How does this change the hazards? The equipment comes in. Workers start using it without updated procedures or training. Within two weeks, someone is injured.
You’ve failed ISO 45001 Clause 8.1.3 change management.
Change is constant. New equipment, new processes, staffing changes, regulatory updates, facility expansions, technology adoption — any of these can alter your risk profile. If you don’t systematically evaluate how changes affect hazards and controls, you’re flying blind.
Change management (Management of Change, or MOC) is the discipline that ensures changes are implemented safely. It’s not a bureaucratic process that slows change; it’s a thinking process that prevents change from creating new hazards.
This article walks you through what constitutes change, the MOC process, how to assess risk, communicate effectively, and integrate change management into your operational rhythm.
What Constitutes Change Under ISO 45001
Change is any modification to your operations, facilities, processes, materials, equipment, organisational structure, regulations, or external conditions that affects your OH&S risk profile.
This includes:
Operational Changes
- New processes or process modifications
- New equipment or replacement of existing equipment
- New materials or suppliers
- Changes to production volumes or schedules
- Changes to work locations or facilities
- Shift pattern changes or staffing changes
Organisational Changes
- Restructures or role changes
- Outsourcing of functions (including OH&S responsibilities)
- Acquisition or merger
- Changes to contractor relationships
System Changes
- Updates to procedures or processes
- Changes to training or competency requirements
- Modifications to hazard controls
- Changes to how you communicate or engage with workers
External Changes
- New regulations or legal requirements
- Changes in industry standards
- Supplier or contractor changes
- Supply chain disruptions affecting control availability
The scope is broad. The key question: Does this change affect our risk profile? If yes, it requires change management assessment.
The Management of Change Process
A structured MOC process has distinct phases:
Phase 1: Change Identification
The change is identified. It might come from operations (we need faster equipment), management (cost reduction initiative), regulatory (new standard takes effect), or workers (there’s a better way to do this).
Key: whoever identifies it should formally notify the MOC coordinator or process. Don’t let changes happen quietly.
Phase 2: Change Description and Rationale
Document what’s changing and why. What’s the current state? What will be different? Why is this change necessary?
Who will be affected? What roles are impacted? When will the change occur?
This documentation forces clarity on what you’re actually changing before you rush to assess it.
Phase 3: Hazard Assessment
Review the change through the lens of hazards. Will new hazards be introduced? Will existing hazards be modified? Will controls still be effective after the change?
Use your existing hazard identification process (see your HIRA). For each new or modified activity, identify hazards. For each hazard, assess risk if no control is applied. Then specify the controls that will manage the risk.
This should be done before implementation. Not after, when it’s too late to redesign safely.
Phase 4: Control Review and Risk Assessment
For each hazard identified, do your existing controls still apply? Do you need new controls? Are the controls adequate?
Document:
- Which controls remain unchanged
- Which controls need to be modified
- Which new controls need to be added
- Residual risk after controls are applied
If residual risk is unacceptable, you either improve controls or don’t proceed with the change.
Phase 5: Stakeholder Consultation and Communication
Consult with people who will be affected. Workers doing the changed work should have input. Supervisors managing them need to understand what’s changing. Relevant functions (training, maintenance, procurement) should be aware.
Communication should explain: What’s changing. Why. How it affects your work. What new risks exist. What controls are in place. What training is needed.
Engagement builds buy-in. People who understand a change are more likely to implement it safely.
Phase 6: Approval and Authorisation
Someone with authority (typically a manager or committee) reviews the change assessment and approves the change. This isn’t a rubber stamp — the reviewer should satisfy themselves that hazards have been adequately identified and controls are sufficient.
For major changes, consider a change review committee with representation from operations, safety, training, and HR.
Phase 7: Implementation Planning
Plan how the change will be implemented. What needs to happen before launch? What training is required? What procedures need to be updated? What equipment needs to be installed?
Who will do each task? By when?
Consider a phased approach for significant changes — pilot in one area, learn, then roll out more broadly.
Phase 8: Implementation
Execute the change. Install new equipment. Update procedures. Deliver training. Communicate the change to the broader organisation.
Monitor the implementation. Are things progressing as planned? Are there unexpected issues?
Phase 9: Post-Change Review
After the change has been operating for a period (typically 4-12 weeks, depending on the change complexity), review: Did the change work as intended? Are there unexpected issues? Are workers following new procedures? Are the hazards being controlled as expected?
If issues emerge, address them. If the change is working well, formalise it. Make sure hazard assessment reflects the new state.
Phase 10: Documentation and System Update
Update your documented information. Hazard register reflects new hazards. Procedures reflect new processes. Training records show who was trained. Incident investigation processes reference the change (so future investigations remember the context).
Temporary vs. Permanent Changes
Temporary changes still require MOC assessment, but the rigour can be proportionate.
Temporary change example: Maintenance work means a production line shuts down for two weeks. Equipment is reconfigured during shutdown. The change is temporary (equipment reverts to normal operation after maintenance).
Assessment required: During the maintenance period, what hazards exist? Are barriers different? Is it safe to work in the equipment with new configurations? What controls are needed during maintenance?
You might do a simplified assessment (don’t need full hazard identification, but you do need to think through risks). You still get approval before work starts. You still communicate to workers. But the process might be lighter than a permanent change.
Emergency Changes
Sometimes you need to change immediately to respond to an emergency (equipment failure, regulatory demand, crisis).
Your procedure should allow expedited MOC:
- Verbal or expedited hazard assessment (documented afterward)
- Verbal approval (documented afterward)
- Implementation proceeds immediately
- Post-change review and full documentation happen within a defined timeframe (usually 2-4 weeks)
Emergency changes are exceptions. If every change claims to be emergency, you’ve created a loophole. Use emergency processes only for genuine emergencies.
Change Management and Continual Improvement Connection
Change management is sometimes viewed as preventing change. In reality, it enables smart change.
Improvements require change (new procedure, new equipment, new process). MOC ensures improvements are implemented safely and that all consequences are considered.
By the same logic, all changes are opportunities for improvement. When you’re implementing a change, ask: Are there related improvements we should make at the same time? If equipment is being upgraded, should we also review the maintenance procedure?
Common Change Management Failures
Failure 1: Silent Change
Change happens without formal notification. Equipment is swapped. A new contractor starts. A procedure is quietly modified. Nobody assesses whether new hazards exist.
Fix: Build a culture where changes are reported. Make it easy to notify (simple form, accessible process). Encourage people to ask: Is this a change that needs assessment?
Failure 2: Assessment Without Action
You do a hazard assessment for a change. You identify new risks. Then you proceed with the change anyway, hoping to address the risks later. You never do.
Fix: Make the assessment actionable. If the assessment identifies risks, they must be controlled before implementation. If controls aren’t ready, either delay the change or implement temporary controls until permanent ones are ready.
Failure 3: Hazard Assessment on Paper Only
You assess hazards theoretically but don’t actually observe the changed work in practice. Issues that were invisible in theory become obvious in practice, but too late.
Fix: Do a post-change review. Observe people working under the new conditions. Ask them what’s different. What’s harder? What’s unexpected? Use their observations to refine controls or procedures.
Failure 4: No Training on Changed Work
Equipment is changed. Procedure is updated. But workers aren’t trained on the new version. They continue using old methods or avoid the new equipment because they don’t understand it.
Fix: Include training in the implementation plan. Train before the change goes live, not after. Document who was trained (so you know everyone gets it). Verify competence after training.
Failure 5: No Communication to Relevant Functions
A process change happens in Operations, but Maintenance doesn’t know, so they maintain it for the old process. Training doesn’t know, so new workers are trained on the old procedure. Procurement doesn’t know, so they source components for the old equipment.
Fix: Identify all functions affected by the change. Notify them proactively. For each function, specify what they need to do (update procedures, arrange maintenance, source new parts). Verify they’ve acted.
MOC Documentation and Records
Your change management process should produce documented records:
- Change request form: What’s changing? Why? Who requested it?
- Hazard assessment: What hazards exist in the changed process? How is each controlled?
- Risk assessment: What’s the residual risk? Is it acceptable?
- Approval record: Who approved the change? When?
- Implementation checklist: What needs to happen for this change to go live?
- Training records: Who was trained? When? Did they demonstrate competence?
- Post-change review: Did the change work as expected? What issues emerged? What was adjusted?
These records become evidence that your MOC process was followed. Auditors will review them to verify that change management is systematic, not ad hoc.
Integrating Change Management Into Operations
For MOC to be effective, it needs to be embedded into how people work, not a separate compliance process.
Assign a MOC coordinator: Someone responsible for maintaining the process, tracking changes, ensuring completeness. This doesn’t have to be full-time (might be part of Safety Manager’s role), but there’s a single point of accountability.
Create a simple change request form: One page. Easy to complete. Available and accessible (physical or digital). Clear instructions on what to do with a completed form.
Establish clear escalation: Who decides whether a change requires formal assessment? For straightforward changes (office relocation, new cleaning supplier), maybe simplified assessment. For operational changes (new equipment, process modification), full assessment.
Make change review visible: If you have monthly safety meetings, include a standing change review agenda item. What changes are in progress? What are we concerned about? This makes change management part of the operational rhythm.
Use changes as learning opportunities: When a change is reviewed, share what was learned. At team meetings, discuss changes happening in the organisation. Help people understand that change management isn’t about creating bureaucracy; it’s about thinking through safety implications.
What Auditors Look For
Certification auditors will examine your change management process:
Completeness: Are all significant changes captured? Or do some slip through informally? The auditor might ask: “Have you had any changes in the past year?” and compare your list to what they observe in operations.
Timeliness: Is assessment happening before implementation? Or are changes implemented first and assessed afterward?
Rigor: Is hazard assessment credible? Or is it perfunctory? Are controls actually specified, or is the assessment vague?
Implementation: Do people actually follow the new procedures? Are they trained? Or was the change implemented but people revert to old habits?
Post-change review: Is there evidence that changes are reviewed after implementation? Or does a change disappear after launch with no follow-up?
Organisations with a mature MOC process can walk an auditor through a change from request through post-change review, showing how the process ensured safe implementation.
Practical Checklist: Strong Change Management
- Create a clear MOC procedure defining what constitutes change and the assessment process
- Design a simple change request form that captures key information
- Assign a MOC coordinator responsible for tracking and ensuring process compliance
- Establish clear criteria for determining when full assessment is needed vs. simplified assessment
- For each change, conduct hazard assessment before implementation
- Identify all affected functions and notify them of changes relevant to their work
- Develop a training and communication plan for each significant change
- Get formal approval before implementation proceeds
- Plan and track implementation to ensure it occurs as designed
- Conduct post-change review 4-12 weeks after implementation
- Update your hazard register and procedures to reflect the changed work
- Maintain documentation of the complete MOC process for audit purposes
- For genuine emergencies, allow expedited assessment with retrospective documentation
Ready to strengthen your change management process? Our consultants can help you design a practical MOC procedure, train your team, and build change management into your operational culture. Let’s build a robust change management system.
FAQ: Change Management in Practice
Recent Comments