Policy shop › IT & Information Security
IT Change Control Policy
A professionally drafted IT Change Control Policy for banks, deposit-taking institutions and finance companies, covering information security and technology risk controls. Global edition — written to international standards (Basel Committee, FATF, ISO, COSO, NIST and FSB) and deliberately jurisdiction-neutral, with bracketed prompts marking the points where your local law or regulator's requirements must be inserted. Supplied as a fully editable Microsoft Word document, de-identified and ready to adapt to your organisation. Typical owner: Chief Information Officer; approval: Chief Executive Officer.
| Typical owner | Chief Information Officer |
|---|---|
| Typical approval | Chief Executive Officer |
| Length | ~7,014 words (approx. 18 pages) |
| Last reviewed | July 2026 — verify currency for your circumstances before use |
| Format | Microsoft Word (.docx), fully editable |
| Delivery | Instant download after purchase; re-download any time from your account |
| Licence | Single-organisation licence |
| Guarantee | Materially defective or misdescribed? We'll resupply, replace or refund within 30 days — see Terms |
Preview the first 6 pages (PDF) See the real cover, document control page and opening sections before you buy.
What's inside
- Contents
- 1. Purpose
- 2. Scope
- 3. Definitions
- 4. Regulatory Framework
- 5. Policy Statement and Principles
- 6. Change Categories and Approval Authorities
- 7. Change Advisory Board
- 8. Change Records
- 9. Change Risk Assessment
- 10. Testing and Verification Requirements
- 11. Scheduling, Change Windows and Freeze Periods
- 12. Emergency Changes
- 13. Segregation of Duties and Access Controls
- 14. Third-Party and Cloud Provider Changes
- 15. Unauthorised Change Detection and Consequence Management
- 16. Roles and Responsibilities
- 17. Reporting, Metrics and Escalation
- 18. Breaches of this Policy
- 19. Training, Awareness and Records
- 20. Review of this Policy
- Appendix A: Change Record Completeness Checklist
- Appendix B: Emergency Change Retrospective Review Template
- Policy Administration