All articles
HSE

Management of Change in High-Risk Operations: Preventing New Hazards Before Work Begins

Published August 20, 2026

Management of Change in High-Risk Operations: Preventing New Hazards Before Work Begins

Small operational changes can invalidate critical safeguards. This practical guide explains how to structure Management of Change from technical justification and risk review through pre-startup verification and effectiveness checks.

Management of Change in High-Risk Operations: Preventing New Hazards Before Work Begins

Many serious incidents do not begin with an obviously unsafe act. They begin with a change that appeared routine: a different chemical, a temporary bypass, a revised maintenance method, new control-system logic, a smaller operating team, a substitute contractor, or equipment used for a new duty.

The original safeguards may have been appropriate for the original design. Once conditions change, however, assumptions can become invalid. A control that worked yesterday may no longer protect people, assets, the environment, or business continuity.

Management of Change, commonly called MOC, provides a structured way to identify and control these risks before the change is implemented. In high-risk operations, it should connect engineering, operations, maintenance, HSE, quality, procurement, contractors, and leadership around one question:

What could become unsafe, noncompliant, or unreliable because of this change?

For organizations in Saudi Arabia and the UAE, an effective MOC process is especially valuable across oil and gas, utilities, construction, logistics, manufacturing, maintenance, laboratories, and other operations where small changes can have significant consequences.

Why Ordinary Risk Assessments Are Not Enough

A task risk assessment or permit to work focuses mainly on the hazards of performing a defined job. MOC addresses a different issue: whether the proposed change alters the process, equipment, operating envelope, organization, or safeguards on which safe performance depends.

The two processes should support each other, but one should not replace the other.

For example, a permit may control the immediate hazards of installing a replacement pump. MOC should determine whether the new pump has a different capacity, pressure, material specification, power demand, failure mode, control philosophy, maintenance requirement, or effect on downstream equipment.

Without that wider review, the installation activity may be completed safely while the modified system is returned to service with a new and unrecognized risk.

Which Changes Should Enter the MOC Process?

Organizations should define clear screening criteria so that employees and contractors know when MOC is required. The process should consider more than permanent engineering modifications.

Potential triggers include:

  • changes to process chemicals, materials, concentrations, or specifications;
  • new equipment or changes to equipment duty, capacity, materials, or design;
  • revised process parameters, alarms, trips, interlocks, or control logic;
  • changes to operating, maintenance, inspection, testing, or emergency procedures;
  • temporary bypasses, overrides, hoses, connections, scaffolds, or alternative work methods;
  • changes to facility layout, access, ventilation, drainage, containment, or hazardous-area classification;
  • new suppliers, contractors, outsourced processes, or logistics arrangements;
  • changes to staffing levels, supervision, competence, roles, shift patterns, or organizational structure;
  • digital-system, software, cybersecurity, or automation changes that can affect operational control;
  • changes introduced after incidents, audits, reliability findings, or regulatory updates.

The organization should also define what qualifies as a genuine replacement in kind. A component is not equivalent simply because it fits physically. Its design basis, material, rating, function, operating limits, and performance characteristics must remain equivalent.

When uncertainty exists, the safer approach is to screen the proposal through MOC rather than allow an informal decision at the point of work.

A Practical Nine-Stage MOC Workflow

1. Define the proposed change and its technical basis

The request should explain what will change, why it is needed, what problem it solves, and what systems, people, documents, or locations may be affected.

A vague description such as "modify the line" is not enough. Reviewers need drawings, specifications, photographs, operating data, vendor information, and a clear description of the intended end state.

The technical basis also helps distinguish a valid improvement from a local workaround that could move risk elsewhere.

2. Screen the change and assign the right review level

Not every change requires the same depth of analysis. A simple, low-risk administrative change may need a short review, while a modification affecting containment, pressure, energy, hazardous materials, safety-critical equipment, or control logic may require a multidisciplinary technical assessment.

A screening checklist can consider:

  • process-safety significance;
  • occupational health and safety effects;
  • environmental aspects and compliance obligations;
  • quality, product, or service requirements;
  • legal and contractual requirements;
  • asset integrity and reliability;
  • emergency-response implications;
  • cybersecurity and information-security effects;
  • competence and staffing;
  • interfaces with contractors or customers.

The screening decision, its rationale, and the person authorizing the review level should be recorded.

3. Conduct a cross-functional risk assessment

The quality of MOC depends on involving people who understand how the system is designed, operated, maintained, and supervised. Depending on the change, the team may include engineering, operations, maintenance, HSE, quality, inspection, procurement, IT or automation, contractor representatives, and frontline users.

The method should match the complexity and risk. Options can include a structured checklist, What-If analysis, HAZID, HAZOP, FMEA, job-safety analysis, environmental-aspect review, or another approved technique.

The assessment should examine normal operations, startup, shutdown, maintenance, abnormal conditions, foreseeable misuse, simultaneous operations, emergencies, and failure of critical safeguards.

The objective is not to produce the largest risk register. It is to identify credible failure scenarios and define controls that are specific, owned, and verifiable.

4. Identify every affected control and document

Changes often fail at interfaces. The equipment is modified, but the drawing remains old. The procedure is revised, but the training is not. The alarm is changed, but the emergency response plan still assumes the previous condition.

The MOC review should identify affected:

  • process and design information;
  • drawings, line lists, data sheets, and equipment registers;
  • operating and maintenance procedures;
  • inspection and preventive-maintenance plans;
  • alarm, trip, and interlock settings;
  • permits, isolation plans, and lockout requirements;
  • environmental controls and waste arrangements;
  • emergency plans and response resources;
  • competency requirements and training materials;
  • contractor scopes, purchasing specifications, and spare-parts lists;
  • risk assessments, legal registers, and management-system documents.

Each update should have an owner and completion requirement. Marking an action "for information" is not a substitute for confirming that the controlled document has been revised and issued.

5. Approve the change before implementation

Approval should confirm that the technical review is complete, risks are understood, required controls are defined, resources are available, and unresolved actions are managed appropriately.

The approval level should reflect the risk. High-consequence changes may require authorization from engineering authority, operations leadership, HSE, asset integrity, or senior management.

Approval is not merely a signature. It is an accountable decision that the change can proceed under defined conditions.

6. Implement the change under controlled conditions

Implementation should follow approved drawings, specifications, procedures, isolation requirements, permits, quality checks, and inspection or testing plans.

Any deviation from the approved design should stop the work and return to the MOC process. Field changes made without review can invalidate the earlier risk assessment.

Records should show what was installed or changed, who completed and inspected the work, what tests were performed, and whether results met acceptance criteria.

7. Prepare employees and contractors

Affected personnel should understand the change before they operate, maintain, inspect, supervise, or respond to the modified system.

Communication alone may not demonstrate competence. Depending on the risk, verification can include practical demonstration, scenario discussion, simulator exercise, supervisor observation, knowledge assessment, or formal authorization.

Contractors should receive the same relevant information when their work can affect or be affected by the change. Interfaces and responsibilities must be explicit.

8. Complete a pre-startup or pre-use verification

Before returning equipment or a process to service, the organization should verify that:

  • installation matches the approved design;
  • required inspections and tests are complete;
  • safety, environmental, and quality controls are available;
  • procedures and drawings are updated;
  • alarms, trips, interlocks, and emergency systems function as intended;
  • actions required before startup are closed;
  • affected personnel are informed and competent;
  • operating limits and escalation requirements are clear;
  • authorization to start has been given by the designated competent person.

This stage should be based on physical verification and reliable evidence, not only a review of the MOC form.

9. Close the MOC and verify effectiveness

Administrative closure should occur only when required actions and records are complete. The organization should then confirm whether the change achieved its intended result without creating new problems.

Post-implementation review may examine operating data, alarms, defects, environmental performance, maintenance findings, user feedback, incidents, or near misses.

Where lessons are identified, they should improve future designs, risk assessments, specifications, training, and MOC criteria.

Temporary Changes Require Stronger Discipline

Temporary arrangements often become normal through familiarity. A bypass remains in place, a temporary hose is repeatedly reused, additional manual checks replace a failed instrument, or an interim staffing arrangement continues without reassessment.

Every temporary change should therefore have:

  • a defined purpose;
  • the same proportionate risk review as a permanent change;
  • clearly marked equipment or system status;
  • an accountable owner;
  • a start date and expiry date;
  • inspection and monitoring requirements;
  • a restoration or conversion plan;
  • escalation before any extension.

A useful indicator is the number of temporary changes past their expiry date. Any overdue item should receive immediate management attention.

MOC Must Connect With Permit to Work

MOC and permit-to-work systems control different stages of risk.

MOC determines whether the proposed change is technically and organizationally acceptable. Permit to work controls the hazards of executing specific high-risk work, such as hot work, confined-space entry, breaking containment, electrical isolation, or intrusive maintenance.

An approved MOC does not authorize the physical work. A completed permit does not authorize an unreviewed modification.

The two systems should reference each other where applicable, and supervisors should confirm that the installed condition still matches the approved change before the permit is closed and the asset is returned to service.

Useful MOC Performance Indicators

Organizations should monitor both completion and effectiveness. A small set of meaningful indicators may include:

  • open MOCs by risk level and age;
  • overdue actions required before startup;
  • temporary changes approaching or exceeding expiry;
  • percentage of MOCs with completed pre-startup verification;
  • unauthorized changes identified through audits or inspections;
  • repeat incidents linked to ineffective change control;
  • percentage of post-implementation reviews completed;
  • time required to update critical drawings and procedures;
  • competency verification completed before startup;
  • quality of replacement-in-kind decisions.

Metrics should lead to decisions. A growing backlog, repeated extensions, or frequent undocumented field changes indicates a management-system weakness even if every form has eventually been closed.

Common Failure Modes

Weak MOC systems often show recognizable patterns:

  1. The process covers equipment changes but ignores organizational, procedural, digital, or contractor changes.
  2. Replacement in kind is declared without checking specifications and performance.
  3. Risk assessment is completed by one function without operators or maintainers.
  4. Approval is given while critical pre-startup actions remain open.
  5. Temporary changes have no expiry date or restoration plan.
  6. Drawings and procedures are updated after startup, or not at all.
  7. Training attendance is accepted without verifying competence.
  8. The installed condition differs from the approved design.
  9. MOC is closed when installation is complete rather than when effectiveness is verified.
  10. Leaders monitor the number of forms instead of the quality of decisions.

Internal audits should sample complete change histories from request through post-implementation review and verify the physical condition in the field.

Questions Leaders Should Ask

Leaders can test the health of the system by asking:

  • Which high-risk changes are currently open?
  • What actions must be completed before startup?
  • How many temporary changes are overdue?
  • Where have unauthorized changes been identified?
  • Are organizational and staffing changes being screened?
  • How do we confirm that contractors understand modified conditions?
  • What evidence proves updated safeguards work as intended?
  • Which incidents or reliability failures were linked to change?
  • Are MOC lessons influencing future projects and procurement?

These questions shift MOC from document control to operational governance.

Conclusion

Management of Change is one of the strongest defenses against hazards created by new conditions. Its value lies in bringing the right people together before implementation, challenging assumptions, updating affected controls, verifying readiness, and learning from the result.

The objective is not to slow improvement. It is to ensure that improvement does not introduce a hidden pathway to injury, loss of containment, environmental harm, quality failure, or operational disruption.

Quality Track supports organizations in Saudi Arabia and the UAE with MOC procedure development, gap assessments, risk-review workshops, contractor integration, internal-audit programs, competence development, and alignment with integrated QHSE management systems.

Recognized process-safety references include OSHA's Management of Change requirements for covered processes and the UK HSE guidance on plant modification and change procedures: