A quiet office corridor during a transition, with archive boxes and filing cabinets stacked on one side and a glass-walled, modern workspace visible beyond an open door, suggesting organisational change and movement from old systems to new

What Regulators Look for When Organisations Are in Flux

January 30, 20265 min read

Turning organisational change into a strength, not a regulatory blind spot

Regulatory inspections are inherently about change. Inspectors want to see not just that you are doing things right today, but that you can continue to do things right tomorrow, even when people, systems, buildings, or technology are changing. In our decades of supporting inspections and hosting regulatory audits, one pattern keeps recurring: when an organisation is in flux, regulators don’t lower expectations. Instead, they look for evidence that change was anticipated, assessed, and controlled. If they find assumptions, implied decisions, or undocumented actions, it becomes a supply of findings, observations, and sometimes enforcement letters.

The cycle of change is familiar to most QA professionals. New facilities come on line, electronic systems replace paper, workflows are redesigned, or teams expand and contract. These are positive developments. But during transitions, the underlying assumptions about quality can be exposed — often not because the work was done badly, but because the plan for managing the change was not explicit, documented, and visible.

This disconnect is something both regulators and experienced quality teams recognise immediately.

What Regulators Are Looking For

Inspectors from agencies such as the US Food and Drug Administration (FDA) and the UK’s Medicines and Healthcare Products Regulatory Agency (MHRA) constantly remind companies that quality systems must continue to function reliably through change. When a facility or process changes, agencies expect evidence of:

  • robust change control with documented justification and risk assessment

  • clear roles, responsibilities, and decision authority

  • traceable, contemporaneous records that can be inspected and reconstructed

  • data integrity through transitions (especially in electronic migration)

These expectations are not abstract. Poor change control is a commonly cited issue in FDA Form 483s and warning letters because changes without documented control risk product quality, data integrity, and patient safety. Agencies have issued warnings explicitly tied to change control failures such as inadequate risk assessments or undocumented implementations. For example, failure to follow change control procedures has been identified as a frequent finding in inspections and a common sources of FDA 483 violations and warning letters.

A regulator doesn’t see a change as an end point. They see it as the moment when a quality system must prove it can adapt without unintended consequences.

Why Change Without a Plan Is Risky

In Headway’s work with clients, we’ve repeatedly seen risks that are latent until after the change has happened:

1. Lost context
Teams implement a new IT system, laboratory platform, or data workflow, and afterwards it is no longer possible to reconstruct the decisions that were made, why they were made, or what assumptions drove them. This is especially common when paper records are discarded or archived without retaining a traceable link to the new system.

2. Assumed authority
We hear statements like “everyone agreed this was OK” or “the team knew what to do.” But in inspection, subjective agreement without documented authority does not satisfy regulatory expectations. Who had the authority to approve the change? Where is the evidence of that authorisation?

3. Documentation drift
Procedures, SOPs, and risk assessments that should be synchronised with the change do not get updated. As a result, inspectors find evidence of practice that diverges from documents, creating an immediate compliance finding even if the practice itself was technically safe.

4. Poor risk assessment in data migration
One of the most impactful examples comes from moving from paper to electronic records. Organisations may discover after the migration that errors entered into the new system cannot be reconciled with originals — sometimes because the source was destroyed prematurely. This goes beyond inconvenience: regulators view this as a breakdown in data integrity because you can no longer demonstrate reliable reconstruction of records.

These outcomes are not theoretical. They are exactly the sorts of issues that flow into regulatory observations when there is no defensible narrative of planning, decision-making, validation, and control.

Regulation and Change Control: Expectations from the Agencies

Regulatory frameworks inherently assume that change will happen, and that organisations must control it. In the GxP context, change control is not optional. The expectations align around four practical principles:

1. Documented change control is fundamental
Change control is a formal part of quality management. Agencies expect any physical change, process change, software implementation, or data migration to follow a documented procedure. Even “minor changes” should be evaluated to determine whether formal change control is required, and why.

2. Risk assessment must be visible and defensible
Risk assessments should demonstrate how a change could impact product quality, safety, or data integrity — and what mitigation is in place. This is not simply a line in a spreadsheet; it is a record a regulator can review and judge.

3. Decisions must be attributable and timely
Regulators will ask not just what was decided, but who made the decision, when, and based on what evidence. This links closely to data integrity expectations that records be attributable and contemporaneous.

4. Retaining continuity of control
Inspectors look for continuity. Where systems have changed, agencies want to see the audit trail from old to new, and evidence that the new system functions at least as well as the old one in terms of quality control.

Taken together, these principles mean that change is not acceptable unless it is visible, documented, evaluated, and controlled. This might feel like extra work in the short term. But real advantage comes when it prevents findings and strengthens the organisation’s resilience when the next inspection arrives.

Turning Change Into a Quality Advantage

If facility changes, data migration, or software transitions are undertaken thoughtfully and documented robustly, they provide an opportunity to demonstrate control, not invite regulatory reprimand. Inspection-readiness during change requires:

  • writing a clear change management plan before implementation

  • retaining decision rationale and approvals in a searchable, audit-ready format

  • aligning SOPs, training records, and risk assessments with the new reality

  • ensuring data transitions preserve integrity and traceability

When regulators see that an organisation has anticipated risk, documented decisions, and maintained control through a transition, it becomes a competitive strength rather than a weakness. This is the essence of the theme for this month: change, when managed well, is itself a quality advantage.

Paul Davidson

Paul Davidson

Paul Davidson is a quality consultant, leadership coach, and founder of Headway Quality Evolution. With over a decade of experience in pharmaceutical R&D and regulatory compliance, he helps technical professionals bridge the gap from expert to impactful leader.

LinkedIn logo icon
Back to Blog