IT CHANGE MANAGEMENT
IT change management, without buying a service desk.
If you do not run a full IT service management suite, IT change control is often a spreadsheet and a weekly call. ChangeGate gives IT changes a proper lifecycle, in the same system the rest of the business uses: a change advisory board that decides on the record, test and rollback plans, an emergency route, and an evidence pack for every change.
One system for business, operational and IT change. Live in days, not months.
IT change control
What an IT change process needs, in one place.
Change types that set the route
Standard, Normal, Major and Emergency, each with its own approval path and service level.
A CAB that decides on the record
The agenda, quorum, each member’s vote and the decision, kept with the change.
Segregation of duties
The person who raises a change cannot approve it, and the database enforces it.
Tests and rollback before go-live
Structured test cases and a rollback plan. A change approved on condition cannot start until its rollback plan is written.
Systems linked to every change
When a change touches IT, the systems it affects are linked, or declared as none.
Emergency changes
Go ahead at once with a senior sponsor’s confirmation, then face a retrospective CAB booked automatically.
Freeze windows, hypercare and review
Protect critical periods, watch after go-live, review against the plan.
Evidence
Evidence for SOC 2, ISO 27001 and TISAX.
Each framework asks the same thing in different words: can you show, for any change, who approved it, what was assessed and what happened next.
SOC 2, CC8.1
Asks for changes to be authorised, designed, documented, tested, approved and implemented. ChangeGate answers with approval by role, the CAB vote, test cases, the emergency route, and an evidence pack per change for your auditor to sample.
ISO 27001:2022, Annex A 8.32
Asks for changes to follow a procedure: planned, assessed, tested and approved, with rollback and records. The lifecycle is the procedure; risk, tests, rollback, approval and the audit trail are the record.
TISAX, VDA ISA 5.2.1
Asks for changes to be assessed for security risk, approved, tested and documented. ChangeGate links risks to functions and systems, approves by role, and records tests and the emergency route in an audit trail no user can edit.
NIS2 and DORA
Ask for documented, tested and approved change, with rollback. The same record serves, where your organisation is in scope.
ChangeGate is not a certification body and does not guarantee audit outcomes. It gives you the evidence your auditor asks for.
Service desks
Already have a service desk?
Keep it. ChangeGate does not handle incidents or service requests. It is the governance layer for change: the decision, the risk, the approval and the evidence, in the same place as the business and operational changes that so often depend on IT.
One system
Business, operational and IT change in one system.
IT changes rarely stay in one lane. A new system changes how people work; a supplier switch changes a contract. ChangeGate runs all three kinds through the same lifecycle, the same register and the same audit trail, on one calendar.
Business change
Pricing, policy, suppliers, structure and services.
Business change management
Operational change
Processes, sites, equipment, shifts and suppliers.
Operational change management
IT change
Systems and infrastructure, with a change advisory board and full evidence.
You are here
Run a law firm or another professional services firm? See change governance for professional services.
FAQ
IT change management: common questions.
See IT change control an auditor can follow.
Book a demo
