


Every IT change carries risk. A routine update can take down a critical service if it is rushed. Change management is the process that lets you make changes safely, without causing new incidents.
This guide explains what change management is, the types of change, and the process that keeps changes controlled. It also covers the common mistakes to avoid.

Change management is the ITSM process for controlling how changes to IT services are made. A change is any addition, modification, or removal that could affect a service.
The goal is to make changes with as little risk as possible. That means reviewing, approving, and scheduling changes rather than making them on the fly.
Good change management balances two needs. It protects stability while still allowing the business to move forward.
“The Complete Guide to IT Service Management (ITSM).”
Unplanned or careless changes are a leading cause of incidents. A single untested update can disrupt a service that thousands rely on.
Change management reduces that risk. By reviewing changes before they happen, it catches problems early and avoids costly outages.
It also creates a record. Every change is documented, so if something breaks, the team can trace what changed and roll it back.

Not every change needs the same level of control. Most frameworks define three types.
A standard change is low-risk and pre-approved. Because it is routine and well understood, it does not need a fresh review each time.
Examples include a password reset or a routine software update. These follow a set procedure.
A normal change is not pre-approved and must be assessed. It goes through review, approval, and scheduling before it is made.
Most significant changes fall here. They carry enough risk to justify a proper review.
An emergency change must happen fast, usually to fix a major incident. It follows a shortened approval path so it is not delayed.
Even emergencies are documented. The speed is higher, but the change is still recorded and reviewed afterward.
The table below summarizes the three.
| Type | Risk | Approval | Example |
|---|---|---|---|
| Standard | Low | Pre-approved | Routine software update |
| Normal | Medium to high | Full review | Migrating a database |
| Emergency | Varies, urgent | Fast-tracked | Patching a live outage |
A normal change usually follows a clear sequence. Each step reduces risk.
Each step should be recorded. That trail is what makes changes safe to trace and reverse.

Larger organizations use a change advisory board, or CAB. It is a group that reviews and approves higher-risk changes.
The CAB brings together the right people to judge impact and risk. It helps ensure a change will not disrupt other services.
Smaller teams do not always need a formal CAB. A single approver or a lightweight review can be enough at lower scale.
A few habits keep change management effective rather than bureaucratic.
A few errors turn change control into a bottleneck instead of a safeguard.
The first is treating every change the same. Forcing a low-risk update through a heavy review wastes time and frustrates the team.
The second is skipping the rollback plan. Approving a change with no way to undo it turns a small failure into a long outage.
The third is poor communication. When affected users are not warned, even a smooth change can feel like a surprise outage.
Hengine SDP is a service management platform with the building blocks for controlled change. Its Workflow Automation can route change requests, trigger approvals, and notify stakeholders automatically.
The ServiceHub engine tracks each request through its lifecycle, while Access and Permissions ensures only the right people approve sensitive changes. A full activity timeline gives every change an audit trail.
This structure helps a team apply change control without heavy manual overhead. Standard requests move quickly, while higher-risk changes get the review they need.
“Problem Management Explained.” Tie to the Route Without Limits feature section.
Next step: Route and approve IT changes with automated workflows. Book a Hengine demo or start with the free Fremium plan.
Standard, normal, and emergency. Standard changes are low-risk and pre-approved. Normal changes need a full review, and emergency changes are fast-tracked to fix urgent issues.
A change advisory board (CAB) is a group that reviews and approves higher-risk changes. It brings together the right people to assess impact and risk. Smaller teams can use a lighter review instead of a formal board.
Change management controls whether and how a change is approved and made. Release management handles packaging and deploying changes into production. They work together, with change management governing the decision.
A rollback plan lets you undo a change quickly if it causes problems. Requiring one before approval means that even if a change fails, service can be restored fast, which limits the impact of any issue.