Back to Explore
🔨

Technology

Change Management Controls

Discipline of IT change approvals, emergency changes and unauthorised changes across production systems.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why undisciplined change threatens system integrity

Uncontrolled changes to production systems are a leading cause of outages, data corruption and undetected fraud, and they undermine the reliability of every automated control that the AGSA might otherwise rely upon. Disciplined change management, with proper approvals and tight handling of emergency and unauthorised changes, is a core IT general control. AuditPro Core measures change-approval discipline and the incidence of emergency and unauthorised changes across production.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Changes deployed

428

Properly approved

94%

▲ 2%

Emergency changes

31

7% of total

Unauthorised

6

▼ 3

Change approval compliance by month

Change discipline by system

SystemChangesApproved %Unauthorised
Financial (BAS)132961
Payroll (PERSAL)74932
Billing system118922
Web portal104951

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Authorised change

A controlled change is requested, assessed, approved and tested before deployment. The approval step is what separates a managed change from an uncontrolled one.

Emergency changes

Emergency changes bypass the normal queue to fix urgent problems and are sometimes unavoidable. They become a risk when their volume is high or retrospective approval is skipped.

Unauthorised changes

An unauthorised change reaches production without any approval. Each one is a control breakdown and a potential vector for error or malicious activity.

Segregation in deployment

The person who writes a change should not be the one who approves and deploys it unchecked. Segregation across the change lifecycle limits both error and abuse.

How AuditPro Core Bridges the Gap

  • Approval tracking: changes are monitored for evidence of proper authorisation before deployment.
  • Emergency oversight: the platform tracks emergency-change volume and retrospective approval compliance.
  • Exception workflow: detected unauthorised changes raise an immediate investigation action.
  • Traceability to source: every production change links to its request, approver and testing evidence.

Key Takeaways

  • Uncontrolled change undermines the reliability of automated controls.
  • Emergency changes are acceptable only with retrospective approval and low volume.
  • Every unauthorised change is a control breakdown requiring investigation.
  • Segregate who builds, approves and deploys changes to limit abuse.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.