Policy shop › IT & Information Security
IT Change Control Policy
A professionally drafted IT Change Control Policy for banks, deposit-taking institutions and finance companies, covering information security and technology risk controls. Global edition — written to international standards (Basel Committee, FATF, ISO, COSO, NIST and FSB) and deliberately jurisdiction-neutral, with bracketed prompts marking the points where your local law or regulator's requirements must be inserted. Supplied as a fully editable Microsoft Word document, de-identified and ready to adapt to your organisation. Typical owner: Chief Information Officer; approval: Chief Executive Officer.
| Typical owner | Chief Information Officer |
|---|---|
| Typical approval | Chief Executive Officer |
| Length | ~7,014 words (approx. 18 pages) |
| Last reviewed | July 2026 — verify currency for your circumstances before use |
| Format | Microsoft Word (.docx), fully editable |
| Delivery | Instant download after purchase; re-download any time from your account |
| Licence | Single-organisation licence |
| Guarantee | Materially defective or misdescribed? We'll resupply, replace or refund within 30 days — see Terms |
Preview the first 6 pages (PDF) See the real cover, document control page and opening sections before you buy.
What's inside
- Contents
- 1. Purpose
- 2. Scope
- 3. Definitions
- 4. Regulatory Framework
- 5. Policy Statement and Principles
- 6. Change Categories and Approval Authorities
- 7. Change Advisory Board
- 8. Change Records
- 9. Change Risk Assessment
- 10. Testing and Verification Requirements
- 11. Scheduling, Change Windows and Freeze Periods
- 12. Emergency Changes
- 13. Segregation of Duties and Access Controls
- 14. Third-Party and Cloud Provider Changes
- 15. Unauthorised Change Detection and Consequence Management
- 16. Roles and Responsibilities
- 17. Reporting, Metrics and Escalation
- 18. Breaches of this Policy
- 19. Training, Awareness and Records
- 20. Review of this Policy
- Appendix A: Change Record Completeness Checklist
- Appendix B: Emergency Change Retrospective Review Template
- Policy Administration
Related documents
Not ready to buy? Take the sample pack.
We'll email you preview extracts from three of the most-used documents in the library — the Risk Management Framework, the AML/CFT Program and the Operational Risk Policy — plus the full index of every document we publish. No cost, no obligation.
One email with the samples, then occasional notes when new documents are published. Unsubscribe in one click. See our privacy policy.