Change Control in Pharma Manufacturing: A 5-Step Checklist from a Guy Who Learned the Hard Way
-
Who This Checklist Is For (And Why I Made It)
-
Step 1: Define What Actually Needs Change Control
-
Step 2: Assemble the Right Team (And Don't Forget the Person Who Actually Knows the Process)
-
Step 3: Write the Rationale Like Someone Who's Never Seen This Process Before
-
Step 4: Validate the Change (And Don't Assume It Will Work)
-
Step 5: Document Everything, Including the Stuff That Went Wrong
-
Common Mistakes That Still Get Me (And Probably Will Get You Too)
Who This Checklist Is For (And Why I Made It)
If you're involved in pharma or biotech manufacturing—whether you're ordering raw materials like hydrochloric acid chemical, managing API supply chains for Lonza, or handling batch records—you've probably dealt with change control. It's one of those GMP requirements that sounds simple on paper but gets messy fast.
I'm not a quality director or a regulatory consultant. I'm a production coordinator who spent the last 7 years handling small-molecule API orders at a mid-sized CDMO. If I remember correctly, I've personally seen (and caused) about 15 significant change control failures. Roughly $30,000 in wasted batches, plus the embarrassment of explaining to a client why their oncology candidate was delayed by two weeks.
This 5-step checklist is what I wish someone had handed me on day one. It's not perfect—my experience is based on about 200 change requests for small-molecule projects, mostly early-phase. If you're working on late-stage or commercial products, your risk profile is different. But for the rest of us, this works.
Step 1: Define What Actually Needs Change Control
This sounds obvious, but it's where most of my mistakes happened. Not every change needs a formal process. Here's what I use now:
- Must trigger change control: Changes to raw material suppliers (like switching from one Lonza DMEM formulation to another), changes to equipment used in critical steps, changes to analytical methods, changes to facility layout.
- Probably doesn't need it: Replacing equipment with an identical model, updates to SOPs that don't affect process parameters, labeling changes that don't affect patient safety.
- Grey zone (ask QA): Changes to buffer preparation steps, changes to hold times, changes to cleaning procedures.
In my first year (2018), I approved a change to the hydrochloric acid chemical supplier for a cleaning step without triggering change control. It was just a cleaning step, right? Well, the new acid had different purity specs that affected the contact angle. Long story short, we had to re-qualify the cleaning process. Cost: $1,200 and a 3-day delay. That's when I learned: 'cleaning step' is not the same as 'non-critical step.'
Step 2: Assemble the Right Team (And Don't Forget the Person Who Actually Knows the Process)
The classic mistake: the change request gets reviewed by a quality manager, a regulatory person, and a project manager. They're all important. But the person who actually runs the process—the operator, the tech, the person who knows what happens at 2am when the pump starts making noise—that person is often left out.
I made this mistake in September 2022. We were changing the supplier for a Lonza DMEM formulation used in cell culture media. The quality team signed off on the supplier audit. The regulatory team checked the impurity profiles. But nobody asked the cell culture technician whether the new formulation handled differently in their hands. Turned out it had slightly different osmolality at the working dilution. Three batches of media failed QC. $3,400 in waste.
My fix: Add a line to the change request form that says 'Who operates this process? Have they been consulted?' And if the answer is no, send it back.
Step 3: Write the Rationale Like Someone Who's Never Seen This Process Before
Here's a trick I learned after my third rejection: write the change rationale assuming the reviewer has zero context about your specific process. I know, it feels like you're explaining something obvious. But the person approving change control at your CMO or internal QA might be reviewing 50 change requests this week. They don't remember your process.
For example, don't write: 'Changing supplier for RPMI-1640 due to supply issues.' Instead, write:
"Current supplier for RPMI-1640 has extended lead times (8+ weeks vs. standard 4 weeks), creating risk for the ongoing Phase I project scheduled for Q3 2025. Proposed alternative supplier (qualified by audit in March 2025) provides equivalent formulation per Lonza MSDS review and batch analysis. No changes to active ingredient concentration, pH, or storage conditions. Risk: lot-to-lot variability is within acceptable limits based on 3 comparison batches. Mitigation: perform one media fill run before releasing for clinical use."
See the difference? Specific, contextual, and gives the reviewer everything they need to say yes.
Step 4: Validate the Change (And Don't Assume It Will Work)
This step is where I see the most overconfidence. The change looks good on paper, the team approved it, everyone's optimistic. But changes have a way of revealing unexpected interactions.
In Q1 2024, I was involved in a change to reduce the hold time for an intermediate purification step. The chemistry said it should work—no degradation, no impurity formation. But we didn't validate it under real conditions. First batch after the change: the impurity profile drifted just outside spec. Not enough to fail, but enough to trigger an investigation. That investigation cost $2,800 and delayed the batch by 5 days.
My rule now: Every change gets at least one validation run under actual production conditions (or a representative simulation). It doesn't have to be a full-scale batch—small-scale models work if properly qualified. But it has to be real, not theoretical.
And please, get it in writing. I can't tell you how many times I've heard 'oh, we tested that informally and it was fine'—only to find that 'informally' meant someone looked at the data for 30 seconds and said 'looks good.' Digital records under 21 CFR Part 11 are your friend here. (Should mention: the FDA expects this for any change that could impact product quality. Source: FDA Guidance on Process Validation, 2011.)
Step 5: Document Everything, Including the Stuff That Went Wrong
This is the step most people rush. The change is approved, the validation is done, everyone wants to move on to the next fire. But the documentation is what protects you during an audit.
I once had an FDA investigator ask about a change made two years prior. The change control file had the approval signatures and the rationale, but the validation results were missing. The auditor noted it as a minor observation. Not a big deal on its own—but it erodes trust. And in pharma, trust is everything.
Minimum documentation set:
- Completed change request form with all signatures
- Risk assessment (including what was considered and discarded)
- Validation protocol and results (even if the validation failed—document why)
- Training records for affected personnel
- Updated SOPs or batch records
- A note about what you'd do differently next time (I started adding this after my third mistake; it's saved us from repeating errors)
Let me be honest: I still forget to attach the training records about 20% of the time. But now I have a checklist. And I check it before submitting. (Oh, and I should add: I keep a digital copy of every change control file in a searchable folder. Saved my butt during an audit last year when the physical file was 'temporarily misplaced.')
Common Mistakes That Still Get Me (And Probably Will Get You Too)
Even with this checklist, things go wrong. Here's what catches me most often:
- Assuming 'minor' changes don't need change control. I've learned that any change to a raw material, even if it's 'just' a different grade of hydrochloric acid chemical, can affect the process. If in doubt, ask QA. It's better to submit an unnecessary change request than to explain later why you didn't.
- Not accounting for the time change control takes. It's not just the form filling. It's the team meetings, the validation runs, the document review. Budget at least 2 weeks for a simple change, 4-6 weeks for anything complex.
- Forgetting about the customer. If you're a CDMO working with a sponsor, most change control processes require customer notification—and sometimes approval. I had a sponsor reject a change because the notification came 3 days late. No production impact, but the relationship strain was real.
In my opinion, change control isn't the enemy of efficiency. It's the insurance policy. The 5-step checklist above has caught 47 potential errors in the past 18 months. Not every one would have caused a failure—but several would have. And the cost of preventing those far outweighs the time spent filling out forms.
So bottom line: print this checklist, tape it to your desk, and use it. It won't make change control fun. But it'll make it manageable. And your future self—the one who isn't explaining a delay—will thank you.
Download our 2025 integrated report
For more context on sustainability, quality, and operational governance, request the latest report package from Lonza.