Change control
Plan and control changes to processes, products, documents, and systems, the ISO 9001 Clause 6.3 / 8.5.6 requirement, through impact assessment, approval, and verification.
| Change | Type | Impact | Approver | Status |
|---|---|---|---|---|
| New cloud region | Infrastructure | High | CTO | Approved |
| Vendor swap | Supplier | Medium | Ops lead | In review |
| Policy update | Document | Low | Security lead | Verified |
| Process rework | Process | Medium | Quality lead | Planned |
ISO 9001 asks you to carry out changes in a planned way (Clause 6.3) and to review and control changes to production and service provision to the extent necessary (Clause 8.5.6). Keel’s change control module gives you that controlled lifecycle: raise a change request for a process, product, document, supplier, or system; assess its impact and risk; approve or reject it; implement it; and verify the result, each step and its owner on the record. It’s part of Keel Quality, the add-on that brings ISO 9001’s product-quality modules onto the same platform as your ISMS.
Changes made first, documented never
When a process or product changes on a hallway decision, the impact is discovered later: in a defect, an audit finding, or a customer complaint. Clause 6.3 / 8.5.6 asks for changes to be planned, reviewed, and controlled; without a register, there’s no evidence any of that happened.
What change control does
A controlled change lifecycle
Work each change through requested → assessing → approved / rejected → implementing → verified → closed, so every change is deliberate and its state is always clear.
Impact assessment & risk
Record what the change affects and its consequences, and rate its risk (low / medium / high), the review Clause 8.5.6 asks for before a change goes ahead.
Approval on the record
Capture who requested and who approved each change, with the approval date stamped automatically, the authorization trail an auditor expects.
Post-change verification
After implementation, record how the change was verified as effective, so you can show the change achieved its intent without new problems.
Why it matters
- Prove ISO 9001 Clause 6.3 / 8.5.6 with a controlled change register
- Assess impact and risk before a change goes ahead
- Keep an approval trail for every change
- Verify changes worked, and see high-risk ones on the Quality dashboard
Get audit-ready, and prove it
Change control is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.
Start freeFrequently asked questions
What does ISO 9001 require for change?
Clause 6.3 requires changes to the quality management system to be carried out in a planned manner; Clause 8.5.6 requires you to review and control changes for production/service provision to the extent necessary to ensure continuing conformity. Keel captures the plan, the impact review, the approval, and the verification.
What kinds of change can it track?
Any: processes, products, documents, suppliers, or systems. Each change request carries a type, a reason, an impact assessment, and a risk level.
Is it included in my plan?
Change control is part of Keel Quality, a paid add-on that layers on any plan. You can manage it from Billing.
Related features: Documented information register · Nonconformities & CAPA · Quality dashboard
Works with: ISO 9001