Use Case: Change Management
Title for GRC: “The Controlled Change – Evidence, Approvals, and Residual Risk”
Title for Ops: “The Friday Afternoon Fix That Blew Up the Weekend”
GRC Team Version
The scene
A developer submits a production change ticket at 4:47 p.m. on a Thursday. The change is labeled “urgent” and “low risk.” The ticket contains a short description, a test plan that consists of three bullet points, and an approval from the developer’s own manager. No independent reviewer signed off. No rollback plan is attached. The change is pushed Friday morning. By Friday night the system is unstable. By Saturday morning the war room is open.
Workflow (GRC view)
Change request is logged in the official tool with required fields completed.
Risk rating is assigned (High / Medium / Low).
Required approvals are obtained according to the risk level (peer review + change advisory for Medium/High).
Testing evidence is attached.
Implementation window and rollback plan are documented.
Post-implementation review is completed and closed.
All artifacts are retained for the audit period.
Controls
Preventive: No production change can be deployed without the required approvals and evidence.
Detective: Periodic sampling of closed change tickets to verify completeness and segregation of duties.
Evidence: Ticket history, approval records, test results, rollback plan, and post-implementation notes.
Audit focus
Sample 25 production changes. Test whether the required approvals, testing evidence, and rollback plans existed before deployment. Rate residual risk for any gaps and assign owners with due dates.
Communication goal
Give the GRC team a clean view of design effectiveness, operating effectiveness, residual risk, and remediation tracking so the control stands up under examiner scrutiny.
Operations Leaders Version
The scene
It’s Thursday afternoon. A well-meaning engineer has a “quick fix” that will solve a customer complaint. The change process feels like bureaucracy, so the ticket is light on detail and the approval is basically a rubber stamp. The change goes in Friday morning. By 7 p.m. Friday the monitoring alerts start screaming. By 10 p.m. three senior people are on a call trying to figure out what changed. The weekend is gone. Customer trust takes a hit. The team spends the next two weeks in cleanup mode and everyone is exhausted and annoyed.
What it feels like on the ground
“Urgent” changes become the norm instead of the exception.
People start skipping steps because “we don’t have time.”
When something breaks, the first question is always “What changed?” and no one has a clean answer.
The team loses credibility with both customers and leadership.
The better version
Every production change has a clear owner, a risk rating, and the right level of review.
Testing evidence is attached before the change is allowed to proceed.
A simple rollback plan exists so the team can undo the change in minutes instead of hours.
Post-implementation reviews are short and focused on “Did it work and what did we learn?”
Result: fewer weekend fire drills, faster recovery when something does go wrong, and a team that looks competent instead of reactive.
Business impact in real terms
Fewer unplanned outages and emergency war rooms.
Less burnout from weekend recovery work.
Higher trust from customers and leadership because changes are predictable.
When an auditor asks “Show me your change control,” the answer is clean instead of a scramble.
Communication goal
Help Operations Leaders see change management as a practical way to protect their weekends, their reputation, and their ability to deliver—not as paperwork that slows them down.
Strengths
Same underlying control, two very different emotional realities.
The colorful framing makes the risk memorable for Ops while staying precise enough for GRC and auditors.
Easy to adapt to almost any environment that has production systems.
