Every process plant changes constantly — a different catalyst supplier, a modified control setpoint, a temporary bypass during a shutdown, a new reporting line for the shift supervisor. Management of change process safety practice exists because the moment a change is made without a structured review, the plant's original hazard analysis stops describing reality. A workable MOC process screens each change, routes it to the right level of technical review, and closes it out with updated documents and trained people before the change is allowed to become permanent.
Management of change (MOC) is a documented process that identifies, technically reviews, authorises, communicates and closes out any modification to equipment, process conditions, chemicals, procedures, software or organisation before the modification is implemented, so that new hazards introduced by the change are recognised and controlled rather than discovered after an incident.
What counts as a change
The first failure point in most MOC systems is a narrow definition of "change" that only catches equipment swaps. A defensible MOC process has to cover four categories, because incidents have originated from all four.
Equipment, process, chemical and software changes
Equipment changes include replacing a pump, valve, vessel or instrument with a different make, model or material of construction. Process changes include altering a setpoint, operating pressure, temperature, flow rate, batch sequence or production rate outside the range the original design and hazard studies assumed. Chemical changes include a new raw material, catalyst, solvent or additive, or a different supplier grade of an existing chemical that changes purity or impurity profile. Software and control-system changes include a modified PLC or DCS logic, a changed alarm setpoint, a revised interlock, or an updated SCADA/HMI screen — these are easy to implement quickly and are frequently under-screened because no physical hardware moves.
Personnel and organizational changes
Organizational change risk is the category most operations teams miss. Removing a shift position, changing a reporting line, outsourcing a maintenance function, reducing a crew size, or losing an experienced engineer without a structured handover can degrade the safety margins that were assumed when procedures and staffing levels were originally set. Several major investigated incidents have identified an unreviewed staffing or organisational change as a contributing factor. Any change to roles, responsibilities, staffing levels, competency requirements or the chain of technical authority for safety-critical decisions should be screened through the same MOC gate as a physical change.
Why uncontrolled change causes incidents
A hazard study — a HAZOP, a PHA or a what-if analysis — is only valid for the configuration it examined. When a change is implemented outside that boundary without re-assessment, three things typically go wrong together: the technical basis for a safeguard quietly disappears (a relief valve sized for the old flow rate, an interlock tuned to the old setpoint), the people operating the changed equipment were never told what changed, and the documentation — P&IDs, operating procedures, training records — falls out of step with the physical plant. None of these gaps is dramatic on its own; together they are how a "minor" change becomes a serious loss event. A structured MOC process is the control that keeps the technical basis, the workforce's knowledge and the documentation moving together. MOC is recognised internationally as a core process-safety management element — it appears as a named element in the OSHA process safety management standard and in the AIChE Center for Chemical Process Safety (CCPS) body of guidance, both of which treat it as a distinct management system rather than a one-off review step.
Investigators reviewing serious process-safety events repeatedly find the same pattern in the timeline: a change was made with good intentions, under schedule pressure, by people who understood their own discipline but were not asked to check the interfaces with other systems. A control-room setpoint change made without consulting the relief-system design basis, a pipe-spec substitution made without checking corrosion compatibility with the actual process stream, or a staffing reduction made without re-checking whether one person could still perform a two-person safety-critical task — each looks reasonable in isolation and only becomes dangerous in combination with everything else already running at the plant. MOC exists precisely to force that cross-check before implementation, not after an incident investigation reconstructs it.
MOC applicability and screening
Not every change needs the same depth of review, but every change needs to pass through a screening decision. The screening step answers two questions: does this fall inside the scope of MOC at all, and if so, what level of technical review does it require?
Replacement in kind decision
"Replacement in kind" (RIK) is the standard exemption used across process-safety MOC systems: replacing an item with one of the same specification, material, capacity and function, installed in the same way, is not a change requiring full MOC review. The decision has to be made against a written specification, not from memory — an operator or maintenance technician's judgement that a substitute part "looks the same" is not sufficient basis for an RIK call. Confirm your organisation's own RIK definition and the roles authorised to make that call before relying on this exemption; sector-specific rules may narrow it further.
| Change type | Example | Typical review needed |
|---|---|---|
| Equipment | Different pump seal material or motor rating | Technical review; may qualify as replacement in kind if specification matches |
| Process | Increased batch temperature to raise throughput | Full MOC with hazard re-assessment |
| Chemical | New solvent supplier with different flash point | Full MOC including safety data sheet review and compatibility check |
| Software/control | Revised high-pressure alarm setpoint | Full MOC with independent verification of the new setpoint basis |
| Temporary | Bypass of a level transmitter during calibration | Temporary MOC with a fixed expiry date and restoration step |
| Organizational | Reduced weekend shift staffing | Full MOC assessing coverage of safety-critical tasks |
Step-by-step MOC workflow
A practical MOC process runs as a sequence of gated steps, each with a named owner and a record that an auditor can trace end to end. The workflow below is deliberately linear because that is what an auditor or investigator needs to reconstruct after the fact; in practice, sites often run it through a form-based or software workflow so that a step cannot be skipped without an explicit override that is itself logged.
- Change is proposed and logged in the MOC register with a unique reference.
- Screening determines whether it is replacement in kind, a temporary change, or a change requiring full MOC review.
- Technical review assesses the hazard using a method proportionate to complexity.
- Risk is ranked and the required approval level is identified.
- Designated approvers sign off before implementation begins.
- Affected documents, procedures and training are updated.
- Pre-startup safety review is completed where the change affects a covered process.
- The change is implemented and monitored.
- The MOC is closed with verification evidence, or extended with justification if temporary.
Change description and technical basis
Every MOC record should state, in the requester's own words, what is changing, why, and the technical basis relied upon — a vendor datasheet, a process calculation, a code reference. A record that only says "upgrade pump" without a stated basis cannot be reviewed meaningfully.
Affected-document identification and risk ranking
The reviewer identifies every document the change touches: P&IDs, operating procedures, safe operating limits, the legal register entry, training material, emergency response plans and the relevant hazard study. Risk ranking — often a simple low/medium/high scale tied to the site risk matrix — determines how many approval signatures and how much hazard-study rigour the change requires.
Approval authority and technical review
Approval authority should scale with risk ranking, not with organisational rank alone: a low-risk instrumentation change might need a shift engineer and area owner; a change that alters a safety-critical interlock should require a process safety or technical authority signature in addition to operations. The MOC RACI below is a starting template — adapt the actual names and thresholds to the site's own risk matrix and delegation of authority.
| MOC stage | Responsible | Accountable | Consulted | Informed |
|---|---|---|---|---|
| Change request & screening | Requester | Area/shift supervisor | MOC coordinator | Affected crew |
| Technical review | Process/technical authority | Site HSE or process safety lead | Operations, maintenance | Requester |
| Approval | Approvers per risk ranking | Plant/site manager (high risk) | Technical authority | MOC coordinator |
| Document & training update | Document owner, trainer | Area owner | Affected personnel | MOC coordinator |
| PSSR & startup | Operations lead | Plant manager | Maintenance, technical authority | Shift teams |
| Close-out | MOC coordinator | Area owner | Requester, reviewers | Site management |
Risk-assessment methods by change complexity
The hazard-review method should match the complexity and novelty of the change, not be fixed at one technique for every MOC.
HAZOP/What-if/JSA selection
A simple, well-understood change to a single parameter within an already-studied range can often be assessed with a focused what-if review or a job safety analysis for the implementation work itself. A change that introduces a new chemical, alters process chemistry, changes a safety-critical control philosophy, or affects multiple interconnected systems warrants a scaled-down or full hazard and operability study (HAZOP) revalidation of the affected nodes. Facilities that already run what-if analysis or a documented preliminary process hazard analysis (PHA) programme should route MOC technical reviews through the same trained facilitators and worksheets, so the change assessment is consistent with the plant's existing hazard-study evidence rather than a one-off judgement call.
Temporary and emergency changes
Temporary change is one of the most misused categories in weak MOC systems: a bypass installed "for two days" during a breakdown quietly becomes permanent because no one owns the restoration date. A defensible temporary-change control needs a written justification, a fixed expiry date, a named owner responsible for restoration, and compensating measures — extra monitoring, restricted operating limits, additional supervision — while the temporary condition exists.
Overdue temporary changes and extensions
Every temporary MOC needs an active tracking mechanism, not a filed piece of paper. When a temporary change reaches its expiry date, the register should force one of three outcomes: restore the original condition, extend with a fresh justification and a new expiry date approved at the same or higher authority level, or convert it to a permanent change through full MOC review. Emergency changes made under time pressure to protect people or plant should still be logged and reviewed retrospectively within a defined period, because the review after the fact is what prevents an emergency workaround from becoming an unreviewed standard practice.
Pre-startup safety review
A pre-startup safety review (PSSR) is a documented check, carried out immediately before a changed or new process is started up, confirming that construction and installation match the design, safety-critical systems are functional, procedures and training are in place, and the MOC or project's action items have been closed or have an agreed interim plan.
PSSR criteria
A workable PSSR checklist typically confirms: the change matches the approved design and the as-built condition; all instrumentation, interlocks and relief devices tied to the change are tested and in service; operating and emergency procedures reflect the change; affected personnel have completed training; and outstanding MOC action items are either closed or formally tracked with an interim risk control. Confirm the trigger conditions for a mandatory PSSR — which classes of change require it versus which can start up on supervisor sign-off — against the site's own process safety management procedure and any applicable major-hazard obligations before publishing a fixed rule.
Document, training and communication updates
A change is not complete when the equipment is running; it is complete when every document and every affected person reflects the new reality. The required-document matrix below is a starting checklist for what a change typically touches.
| Document/record type | When it must be updated | Typical owner |
|---|---|---|
| P&IDs and process drawings | Any equipment, piping or instrumentation change | Engineering |
| Operating and emergency procedures | Any change affecting operating steps or limits | Operations |
| Safe operating limits/critical alarm register | Any change to setpoints or safety-critical limits | Process safety/technical authority |
| Training records and competency matrix | Any change affecting how a task is performed | Training coordinator |
| HSE legal register entry | Any change affecting a permit condition or legal obligation | HSE/compliance |
| Hazard-study worksheet (HAZOP/PHA/what-if) | Any change materially affecting a previously studied node | Process safety lead |
Training evidence
Training evidence should record who was trained, on what version of the procedure, when, and how understanding was confirmed — a signature on an attendance sheet without a competency check is weak evidence in an audit or investigation. Where the change affects contractors or shift crews on rotation, the coordinator should track training completion against the full roster, not just the crew present when the change went live.
Close-out and post-implementation review
Closing an MOC record is a verification step, not an administrative formality. The coordinator should confirm, with evidence, that the physical change matches the approved scope, documents and training are updated, PSSR (where required) is complete, and any post-implementation monitoring period specified during approval has run its course without adverse findings.
Closure verification
Closure verification typically means a site walk-down against the approved MOC package, sign-off from the technical reviewer that no open action items remain, and a dated record filed against the MOC reference number. Some organisations add a fixed post-implementation review — for example thirty to ninety days after startup — to confirm the change is performing as intended before the file is fully archived; set this interval against your own procedure rather than assuming a universal figure.
MOC audit checklist and KPIs
An MOC system is only as strong as the evidence it can produce during an audit. The checklist below is a practical starting point for a self-audit of screening, approval and close-out discipline.
- Every change, including organisational and temporary changes, is logged in a single MOC register with a unique reference.
- Screening decisions, including replacement-in-kind calls, are documented against a written specification.
- The hazard-review method used is proportionate to the change's complexity and is documented.
- Approval signatures match the risk ranking and delegation of authority.
- All affected documents are identified and updated before or at startup.
- Training evidence exists for every affected role, not just the requesting department.
- PSSR is completed and recorded for every change that triggers it.
- Temporary changes have a fixed expiry date, a named owner and active tracking.
- Overdue temporary changes are escalated, not silently extended.
- Close-out evidence is filed against the original MOC reference and is retrievable on request.
| KPI | What it shows | Note |
|---|---|---|
| MOC cycle time (request to close) | Whether the process is fast enough to avoid workaround pressure | Track by risk tier, not as one blended average |
| Percentage of temporary changes overdue | Discipline of the temporary-change control | A rising trend signals expiry tracking is failing |
| Percentage of MOCs with completed PSSR before startup | Whether startup discipline is being followed | Should trend toward 100% for in-scope changes |
| Overdue MOC action items | Whether close-out is genuinely verified, not just signed | Age items by risk ranking |
| Changes implemented without a logged MOC (found in audit) | Whether the screening gate is actually being used | The most sensitive leading indicator of system erosion |
Requesting an MOC system gap assessment is a practical next step if any of these checks are difficult to answer with documented evidence today; Himaya Prevention reviews screening rules, approval routing and close-out discipline against your site's own process-safety obligations and helps close the gaps a self-audit finds. Contact info@himpre.com to scope a review. Teams that want the MOC register, approval routing and action tracking running as one connected workflow rather than spreadsheets and email chains can also request a demonstration of the HSEFQ.com MOC workflow module, which manages screening, risk review, approvals and action tracking in a single auditable record.
MOC screening & workflow maturity check
This is a screening aid to illustrate how an MOC decision might be reasoned through. It does not replace your organisation's approved MOC procedure, risk matrix or a competent reviewer's judgement.
Frequently asked questions
What is replacement in kind?
Replacement in kind is a change to equipment, a part or a material that keeps the same specification, capacity, material of construction and function, installed the same way, so it does not introduce a new hazard and does not require full MOC review. The determination must be made against a written specification by an authorised reviewer, not from visual similarity alone.
Does an organizational change require MOC?
Yes, where the change affects staffing levels, reporting lines, competency requirements or the chain of technical authority for safety-critical decisions. Organizational change risk has contributed to major incidents where reduced staffing or lost technical knowledge was never assessed through a formal review before implementation.
When is PSSR required?
A pre-startup safety review is generally required before starting up a new or changed process that could affect process safety, once construction matches design, safety systems are verified, and procedures and training are updated. Confirm the exact trigger conditions against your own process safety management procedure and any applicable major-hazard regulation.
How are temporary changes controlled?
Through a written justification, a fixed expiry date, a named owner accountable for restoration, defined compensating measures while the temporary condition exists, and active tracking that forces a decision — restore, extend with fresh approval, or convert to permanent — when the expiry date is reached.
Which MOC KPIs should be monitored?
Useful leading and lagging indicators include MOC cycle time by risk tier, the percentage of temporary changes overdue, the percentage of changes with PSSR completed before startup, overdue close-out action items, and — found only through audit — the number of changes implemented without ever being logged in the MOC system.
0 Comments