Planning of Changes
Planning of Changes is a requirement that says when an organization needs to change how its management system works, it should think through the change in advance rather than making it in an ad hoc way. This means considering why the change is being made, what could go wrong, and who and what is needed to carry it out. The goal is to keep the management system working properly while the change is introduced.
Planning of Changes refers to the management system clause (numbered 6.3 in both ISO 9001 and, following the 2022 revision, ISO/IEC 27001:2022) requiring that when an organization determines a need to change its management system, the change is carried out in a planned manner. Guidance associated with the clause typically indicates that planning should consider the purpose of the changes and their potential consequences, the integrity of the management system, the availability of resources, and the allocation or reallocation of responsibilities and authorities. In an ISMS context under ISO/IEC 27001:2022, this clause sits within the Clause 4-10 requirements that are assessed for certification; it is distinct from, though related to, operational change control and change management processes, and its precise application depends on the organization's scope and the certification body's evaluation. Note that the evidence provided describes this clause principally in relation to ISO 9001 (a quality management system standard), while the substantively identical requirement also appears in ISO/IEC 27001:2022; specific wording and interpretation should be confirmed against the applicable standard edition.
Why it matters
Management systems are not static. As an organization grows, adopts new technology, restructures teams, or responds to emerging risks, it inevitably needs to change how its management system operates. Planning of Changes (Clause 6.3, which appears in both ISO 9001 and, following the 2022 revision, ISO/IEC 27001:2022) exists to ensure those changes are introduced deliberately rather than in an ad hoc manner. When changes are made haphazardly, an organization risks undermining the very system it relies on to manage quality or information security, potentially creating gaps that go unnoticed until they cause problems.
In an ISMS context, the stakes are particularly relevant because unplanned changes can inadvertently weaken controls, disrupt responsibilities, or introduce risks that were never assessed. The clause's emphasis on maintaining the integrity of the management system means that an organization must think through what could go wrong before acting, rather than discovering the consequences afterward. This discipline supports the broader goal of keeping the management system functioning properly while a change is being carried out.
Because Clause 6.3 sits within the Clause 4-10 requirements assessed for ISO/IEC 27001:2022 certification, how an organization plans and evidences its changes can be evaluated by a certification body. The precise application depends on the organization's scope and the certification body's evaluation, so demonstrating a considered, documented approach to change planning helps show that the ISMS is being managed as intended rather than drifting through uncontrolled modifications.
Who it's relevant to
Inside Planning of Changes
Common questions
Answers to the questions practitioners most commonly ask about Planning of Changes.