Skip to content
compliancebase

Change management policy template

SaaS change management policy template for production changes, emergencies, and segregation of duties — maps to SOC 2 CC8.1 and ISO A.8.32 themes.

Download .docx

Change management policy

**Document control**

| Field | Value | |---|---| | Organization | [COMPANY NAME] | | Policy owner | [OWNER NAME / ROLE] | | Approver | [APPROVER NAME / ROLE] | | Version | [VERSION] | | Effective date | [YYYY-MM-DD] | | Next review | [YYYY-MM-DD] |

**Mapped themes:** SOC 2 CC8.1; ISO/IEC 27001:2022 Annex A.8.32, A.8.9 (educational mapping).

1. Purpose

This policy ensures changes to information processing systems are authorized, tested as appropriate, and recoverable so unauthorized or poorly controlled changes do not undermine security objectives.

2. Scope

Applies to production application, infrastructure-as-code, identity, and security-control changes for in-scope systems. Standard low-risk changes may follow a pre-approved path documented below.

3. Change types

  • **Standard:** Pre-approved, low risk, documented runbook (e.g. routine dependency patch within policy).
  • **Normal:** Requires review/approval before production deploy.
  • **Emergency:** Production hotfix with retrospective review within [N] business days.

4. Policy statements

  • Production changes are linked to a ticket or change record with requester, description, and risk notes.
  • Normal changes require peer review (pull request or equivalent) and successful required CI checks before merge/deploy.
  • Deployments to production are performed through approved pipelines; direct undocumented production edits are prohibited except break-glass with logging.
  • Rollback or remediation plans are considered for high-risk changes.
  • Emergency changes are logged and reviewed after the fact by [ROLE].
  • Segregation of duties is applied proportionate to risk; compensating controls are documented when the same engineer must author and deploy.

5. Related documents

Information security policy; Access control policy; Secure development standards [LINK].

---

**Disclaimer:** Educational template only — not legal advice. Adapt with your auditor. ComplianceBase is vendor-neutral and independent.

Framework versions referenced in this page:

Last verified: July 2026 · Primary sources linked above