Efixera

Blog · C6

Risk passport, Management of Change, and non-conformance: one routed approval trail

Diagram of risk, change, and non-conformance icons merging into one routed approval chain.

Risk, change, and non-conformance are three views of the same problem: something departs from the approved state, and someone has to formally accept, coordinate, and close that departure — with a record proving it happened. Handled on paper, all three lose their trail; handled as one routed approval process, all three become auditable by construction.

Why a formal, routed process changes the outcome, not just the paperwork

Digital Management of Change is a well-studied case: refineries running digital MOC report 72% fewer process-safety incidents in the first year compared to the paper-based process it replaced (API, 2025). The mechanism is not the paperwork — it's that an unauthorized or inadequately reviewed change can introduce a hazard nobody notices until it causes an incident, and a routed, mandatory review step is what catches it before that happens, not after.

The three mechanisms, and what each one enforces

Risk passport. A risk catalog and a risk passport per identified risk, assessed and formalized in real time rather than compiled ahead of a review. The passport is the object a Management of Change or a non-conformance can point back to when a change is triggered by a risk finding.

Management of Change (MOC). A change is created in real time and routed to the specific responsible person for coordination and approval — not filed and reviewed whenever someone gets to it. The routing is the control: a change that was never routed to the right person is a change that was never really reviewed.

Non-conformance management (NCR). Every non-conformance carries a registration number (PREFIX-YEAR-SEQ, e.g. IA-2025-001) assigned by a central quality coordinator, with hybrid routing: the coordinator registers, numbers, validates, and closes; a per-unit process owner accepts and executes the corrective action. Verification stays with the coordinator — acceptance and verification are different steps, not the same signature. Configurable SLA timers (an acceptance deadline in working days, a verification cadence in calendar days) mean a non-conformance can't sit unacknowledged indefinitely by default.

What this replaces

  • A risk identified in a meeting and never formally logged.
  • A change made because "it's basically the same thing" with no MOC written for it — the exact failure pattern behind several documented process-safety incidents, where a modification was treated as a like-for-like replacement and never triggered a change review.
  • A non-conformance report that exists as a memo with no registration number, no deadline, and no independent verification that the fix actually worked.

One more connection: risk, change, and non-conformance don't stay separate

A risk passport can trigger a Management of Change. A failed inspection, safety check, or lab test can raise a non-conformance automatically, cross-referenced to the specific instrument, project task, or document that caused it — so the three mechanisms feed each other instead of existing as three unrelated logs a coordinator has to reconcile by hand.

Sources

  • Refineries running digital Management of Change report 72% fewer process-safety incidents in year one versus the paper process — American Petroleum Institute (API), 2025.
  • Registration, routing, and SLA mechanism — 02_Products_and_SaaS/e_qms.md.