Skip to main content
Category: ISMS Clauses and Planning

Planning of Changes

Also known as: Clause 6.3, Planning for Changes, Planning of Changes (Clause 6.3)
Simply put

Planning of Changes is a requirement that says when an organization needs to change how its management system works, it should think through the change in advance rather than making it in an ad hoc way. This means considering why the change is being made, what could go wrong, and who and what is needed to carry it out. The goal is to keep the management system working properly while the change is introduced.

Formal definition

Planning of Changes refers to the management system clause (numbered 6.3 in both ISO 9001 and, following the 2022 revision, ISO/IEC 27001:2022) requiring that when an organization determines a need to change its management system, the change is carried out in a planned manner. Guidance associated with the clause typically indicates that planning should consider the purpose of the changes and their potential consequences, the integrity of the management system, the availability of resources, and the allocation or reallocation of responsibilities and authorities. In an ISMS context under ISO/IEC 27001:2022, this clause sits within the Clause 4-10 requirements that are assessed for certification; it is distinct from, though related to, operational change control and change management processes, and its precise application depends on the organization's scope and the certification body's evaluation. Note that the evidence provided describes this clause principally in relation to ISO 9001 (a quality management system standard), while the substantively identical requirement also appears in ISO/IEC 27001:2022; specific wording and interpretation should be confirmed against the applicable standard edition.

Why it matters

Management systems are not static. As an organization grows, adopts new technology, restructures teams, or responds to emerging risks, it inevitably needs to change how its management system operates. Planning of Changes (Clause 6.3, which appears in both ISO 9001 and, following the 2022 revision, ISO/IEC 27001:2022) exists to ensure those changes are introduced deliberately rather than in an ad hoc manner. When changes are made haphazardly, an organization risks undermining the very system it relies on to manage quality or information security, potentially creating gaps that go unnoticed until they cause problems.

In an ISMS context, the stakes are particularly relevant because unplanned changes can inadvertently weaken controls, disrupt responsibilities, or introduce risks that were never assessed. The clause's emphasis on maintaining the integrity of the management system means that an organization must think through what could go wrong before acting, rather than discovering the consequences afterward. This discipline supports the broader goal of keeping the management system functioning properly while a change is being carried out.

Because Clause 6.3 sits within the Clause 4-10 requirements assessed for ISO/IEC 27001:2022 certification, how an organization plans and evidences its changes can be evaluated by a certification body. The precise application depends on the organization's scope and the certification body's evaluation, so demonstrating a considered, documented approach to change planning helps show that the ISMS is being managed as intended rather than drifting through uncontrolled modifications.

Who it's relevant to

ISMS Managers and Compliance Leads
Those responsible for maintaining an ISO/IEC 27001:2022 management system need to ensure that changes to the ISMS are planned rather than made ad hoc. This includes documenting the purpose and potential consequences of a change, confirming resources are available, and reassigning responsibilities where needed, so that the integrity of the system is preserved throughout the change.
Internal Auditors and Certification Bodies
Because Clause 6.3 falls within the Clause 4-10 requirements assessed for certification, auditors evaluate whether an organization plans changes to its management system in a considered, evidenced way. How this clause is applied and interpreted depends on the organization's scope and the certification body's evaluation.
Quality Management Professionals
The requirement originates in and is most extensively documented for ISO 9001, so quality professionals managing a QMS apply Clause 6.3 to maintain the integrity of the quality management system and the organization's ability to continue delivering its outputs while changes are introduced.
Change and Operations Teams
Teams that run operational change control processes should understand where planned management-system change (Clause 6.3) ends and day-to-day operational change control begins. The two are related but distinct, and clarifying the boundary helps avoid treating one as a substitute for the other.

Inside Planning of Changes

Clause 6.3 (Planning of Changes)
A requirement introduced in the ISO/IEC 27001:2022 revision as Clause 6.3, part of the certifiable ISMS requirements in clauses 4 through 10. It specifies that when an organization determines a need for changes to the information security management system, those changes are to be carried out in a planned manner rather than in an ad hoc fashion.
Purpose and Consequences of the Change
Clause 6.3 directs the organization to consider the purpose of a proposed change and its potential consequences before implementation, so that the reason for and downstream effects of the change are understood.
Integrity of the Management System
A mandated consideration requiring that the integrity of the ISMS be maintained as changes are made, so that modifications do not undermine the coherence or effectiveness of the system as a whole.
Availability of Resources
The clause requires the organization to consider whether the resources needed to implement the change are available, ensuring changes are supported adequately rather than attempted without sufficient means.
Allocation of Responsibilities and Authorities
Clause 6.3 requires consideration of the allocation or reallocation of responsibilities and authorities associated with a change, clarifying who is accountable for planning and executing it.
Relationship to Other Clauses
Planning of changes typically connects to the broader planning requirements in Clause 6 and interacts with risk assessment and treatment, though the clause itself sets out the change-planning considerations rather than prescribing a specific procedure or tool.

Common questions

Answers to the questions practitioners most commonly ask about Planning of Changes.

Is planning of changes only an ISO 9001 requirement, or does it apply to ISO 27001 as well?
It applies to both. While the concept is often associated with ISO 9001, the ISO/IEC 27001:2022 revision introduced Clause 6.3, 'Planning of changes,' which mirrors the intent of the equivalent quality management clause. For the purposes of an ISMS, the requirement means that when an organisation determines the need for changes to the information security management system, those changes should be carried out in a planned manner rather than ad hoc.
Does 'planning of changes' belong under a QMS category rather than the ISMS clause requirements?
In the ISO 27001 context it belongs squarely within the ISMS clause requirements. Clause 6.3 sits among the certifiable requirements in clauses 4 through 10, which define the management system an accredited certification body assesses. Although a similarly worded clause exists in the quality management standard, the ISO 27001 version governs changes to the information security management system itself and is properly treated as an ISMS planning requirement.
What considerations does Clause 6.3 expect an organisation to address when planning a change?
When planning changes to the ISMS, the clause directs organisations to consider the purpose of the change and its potential consequences, the integrity of the management system, the availability of resources, and the allocation of responsibilities and authorities. Addressing these points helps demonstrate that a change was deliberate and controlled rather than reactive.
How can we demonstrate conformity with Clause 6.3 to an auditor?
Typically, evidence takes the form of records showing that planned changes were considered against the factors the clause names, purpose and consequences, system integrity, resources, and responsibilities. In most engagements this might be reflected in change proposals, meeting minutes, or planning documentation, but the specific evidence an auditor expects depends on the scope and the certification body, so it is worth confirming expectations rather than assuming a single required format.
Does Clause 6.3 replace or overlap with a technical change management control?
They operate at different levels and are not interchangeable. Clause 6.3 concerns planning changes to the management system as a whole, whereas operational change management is typically addressed through Annex A reference controls selected via the Statement of Applicability. Depending on scope, an organisation may rely on both, but satisfying an Annex A change control does not by itself demonstrate conformity with Clause 6.3, and vice versa.
How does Clause 6.3 relate to the risk assessment and Statement of Applicability?
Planning a change may affect the risk picture, so in most implementations the outputs of Clause 6.3 feed back into risk assessment and, where relevant, the Statement of Applicability. If a change alters the applicability of reference controls or introduces new risks, those effects would typically be reflected in the risk assessment and control selection, though how tightly these processes are linked depends on how the ISMS is designed.

Common misconceptions

Planning of Changes (Clause 6.3) is only a quality management concept found in ISO 9001 and does not apply to information security.
While an equivalent Planning of Changes clause exists in ISO 9001, the ISO/IEC 27001:2022 revision introduced its own Clause 6.3 with substantively identical intent. Within the ISO 27001 context, it applies to changes to the ISMS and is part of the certifiable requirements in clauses 4 through 10.
Clause 6.3 prescribes a specific change management procedure or tool that must be followed.
The clause states that changes to the ISMS are to be carried out in a planned manner and identifies considerations to weigh, but it does not mandate a particular procedure, form, or technology. How an organization satisfies the requirement typically varies depending on its context and the certification body's expectations.
Because SOC 2 also addresses change management, satisfying ISO 27001 Clause 6.3 automatically satisfies the corresponding SOC 2 expectations.
SOC 2 addresses change-related controls through the Trust Services Criteria (the Common Criteria) under an AICPA SSAE 18 attestation examination, which is distinct from an ISO 27001 certification against a management system standard. Mapping between the two is possible but partial, and meeting one framework's requirement does not automatically satisfy the other.

Best practices

When planning any change to the ISMS, document the purpose of the change and its potential consequences so the rationale and expected impact are clear to reviewers and auditors.
Explicitly assess whether the change could affect the integrity of the management system, and address any interactions with existing controls, processes, or documentation before proceeding.
Confirm that the resources needed to implement and sustain the change are available, and record how they were identified or provisioned.
Assign and document responsibilities and authorities for each change, clarifying who plans, approves, and executes it.
Integrate change planning with your risk assessment and treatment activities so that changes triggering new risks are evaluated rather than implemented in isolation.
Retain evidence that changes were carried out in a planned manner, since Clause 6.3 is part of the certifiable ISMS requirements and the certification body will typically expect to see how the mandated considerations were applied; note that scope and expectations may vary by certification body.