Change Control

Change Control is the formal process medical device manufacturers use to identify, evaluate, document, and approve changes to a device’s design, manufacturing process, or quality system before those changes take effect. It applies across the product lifecycle and is required under ISO 13485:2016 Clause 7.3.9, the FDA Quality Management System Regulation (QMSR), and EU MDR 2017/745.


What is Change Control?

Change Control is the discipline that stops a good idea from becoming an unapproved deviation. A proposed change to a device (a component, a supplier, firmware, a work instruction, a specification) enters a controlled workflow: someone raises it, someone assesses the impact, someone verifies or validates the result, and someone with authority signs off before the change reaches production or the field.

In a medical device quality management system, change control sits at the intersection of design controls (ISO 13485 Clause 7.3), document control (Clause 4.2.4), and corrective and preventive action (Clause 8.5.2, 8.5.3). It links engineering, regulatory affairs, and manufacturing, keeping the design history file, risk management file, and technical documentation in sync with what the company ships.


Why Change Control matters in medical device development

Skip proper change control and the consequences show up fast: a supplier substitution that quietly shifts biocompatibility, a firmware patch that alters an alarm threshold, a tooling tweak that changes wall thickness past what verification testing covered. These are the kinds of findings FDA investigators and notified body auditors flag most often during inspections, not hypotheticals.

Under EU MDR 2017/745, a change that affects a device’s design or intended purpose can be classified as significant, which can trigger a new conformity assessment and notified body notification under Article 120(3) and MDCG 2020-3 guidance. Under FDA’s QMSR, an uncontrolled change is a direct nonconformance against ISO 13485 Clause 7.3.9, which the regulation now incorporates by reference. Weak change control also erodes the traceability a recall, or CAPA, depends on, and slows time to market as engineers redo undocumented work.


How Change Control works

A working change control process moves through a defined sequence, whether it lives in a paper form or a PLM/QMS software platform:

  • Change request. Someone documents what is changing, why, and what triggered it: a nonconformance, a CAPA, a supplier notice, a cost or supply-chain driver.
  • Impact assessment. Cross-functional review of the effect on design outputs, the risk management file (ISO 14971), verification and validation status, labeling, and regulatory filings.
  • Significance determination. A decision on whether the change requires re-verification, re-validation, or notification by a notified body or the FDA.
  • Approval. Sign-off from the functions with authority (design, quality, regulatory, sometimes manufacturing) before implementation, per ISO 13485 Clause 7.3.9.
  • Implementation and verification. The change goes into effect, with objective evidence that it does what was intended and did not introduce new risk.
  • Record retention. The design and development file (Clause 7.3.10) and, where relevant, the device history record capture what changed and why.

For software-driven devices, IEC 62304 change control follows the same review, verify, approve pattern, and most teams run both through one procedure rather than two.


Common challenges and best practices

The most common failure is treating change control as paperwork instead of a risk decision. Teams fill out the form after the change has already shipped, which defeats the purpose: the review must happen before implementation, not as an after-the-fact justification.

Another frequent gap is scope. Companies build a solid process for design changes but leave supplier changes, software patches, or manufacturing process tweaks running on a separate, looser track. A device that fails because of an unassessed supplier substitution is just as noncompliant as one that fails because of a flawed design change.

Good practice looks like a single, risk-based procedure that scales effort to the change: a label wording fix does not need the same rigor as a material substitution in an implant. Linking change records to the risk management file and the design history file, instead of storing them as an isolated log, keeps the change history usable when an auditor or a new engineer needs to reconstruct why a decision was made.


How SJML helps with Change Control

SJML builds change control into its design and manufacturing programs rather than treating it as a separate audit exercise. Its engineering teams run phase-gate development with structured change governance, so design changes are assessed against risk management and verification status before they move forward. On the compliance side, SJML’s QARA Compliance-as-a-Service supports regulatory sustenance work, including design history file remediation and risk file updates, and its Product Lifecycle Management practice focuses on structured change governance that reduces the revalidation burden as a device evolves after launch.

Talk to SJML’s QARA team →


Frequently asked questions

What is the difference between change control and change management?

Change control refers to the technical and regulatory review of a proposed change: impact assessment, verification, and approval before implementation. Change management is the broader organizational discipline of managing all types of change, including process, personnel, or strategic shifts. In a medical device QMS, change control is a defined, auditable subset of change management focused on product and process changes.

Does every design change require a notified body notification under the EU MDR?

No. Only changes classified as significant under MDR Article 120(3) for legacy devices or substantial changes to the quality system or certified device range for MDR-certified devices require notification. MDCG 2020-3 provides flowcharts that manufacturers and notified bodies use to make that determination. Administrative changes, such as a manufacturer’s address, are generally not significant.

How did the FDA QMSR change requirements for change control?

Since February 2, 2026, the QMSR replaced the design and document change provisions formerly in 21 CFR 820.30 and 820.40 with ISO 13485:2016 by reference. Manufacturers now demonstrate change control primarily against Clause 7.3.9, with FDA-specific definitions and record requirements layered on top instead of a separate US-only framework.

What records does a change control process need to keep?

At minimum: the change request and its rationale, the impact assessment, verification or validation evidence, the significance determination, and the approval signature with date. These records typically live in or are referenced from the design history file and, where the risk profile changed, the risk management file.

Can a small change skip formal change control?

No, but the rigor can scale. ISO 13485 Clause 7.3.9 requires the organization to determine the significance of each change, so a minor label correction can move through a lighter review than a material substitution, as long as the process documents why that determination was made.


Related terms

  • Design Verification
  • Corrective and Preventive Action (CAPA)
  • Document Control
  • Design History File (DHF)
  • Risk Management File

Table of Contents

Free EU MDR Technical Documentation Compliance Checklist

Understand documentation gaps and use our single-window worksheet to prepare for Notified Body review.

Related Glossaries

Ask Sygma AI

AI-Powered Assistant

SJ Assistant