Management of Change is the PSM element that catches every hazard a plant introduces to itself. Under 29 CFR 1910.119(l), every change to process chemicals, technology, equipment, procedures, or facilities in a covered process needs a written MOC procedure that addresses technical basis, safety impact, authorization, training, and pre-startup safety review before the change goes live. It is one of the most frequently cited PSM elements in OSHA enforcement because changes happen continuously — a pump swap, an operating window tweak, an organizational shift — and each one has the potential to invalidate an existing safeguard. A working MOC system routes the review, captures the approval, and holds the chain to the next PHA revalidation.
iFactory / Management of change
Route Every Process Change Through PSM Discipline — Before It Goes Live
Structured MOC workflow that captures technical basis, routes risk and PHA impact review, records approvals, links to training and PSI updates, and closes with PSSR sign-off — full 29 CFR 1910.119(l) audit trail retained through the next PHA cycle.
1
Request & technical basis
2
Risk / PHA impact review
3
Approvals & training update
1910.119(l)
PSM MOC compliant
5 gates
request → PSSR closeout
PHA-cycle
retention aligned
The Problem in Process Safety Change Control
A running chemical or refinery process changes every week. A control valve gets swapped for a different trim. An operating window tightens because a downstream unit is more sensitive. A new alternative feedstock enters trial. Reorganization moves the console operator to a different unit. Every one needs an MOC under 29 CFR 1910.119(l) unless it is a replacement in kind — and the burden of proving that exemption sits on the employer. Plants run MOC on paper forms or shared drives never designed for authorization workflow. Reviews stall on inboxes. Training linkage gets skipped. PSSR happens verbally at startup. When OSHA arrives after an incident, the traceable chain from request to signed PSSR is where citation lands.
Where MOC Discipline Actually Slips
MOC failure modes are consistent across chemical, refining, and PSM-covered facilities. Each is a specific 1910.119(l) sub-element that goes unmet.
Replacement-in-kind abuse
Real changes classified as replacement in kind to skip the MOC. When the substituted equipment has a different failure mode, the safeguard the PHA assumed is now missing.
Review inbox stall
Change request emailed to a distribution list. Sits unread for weeks. Plant needs the change, so the operator implements a workaround — undocumented — and the formal MOC never closes.
Training update skipped
Change approved but training records not updated. Operators run against a procedure that describes the pre-change plant. First upset condition exposes the gap.
PSSR verbal-only
Pre-startup safety review conducted as a walk-through with no signed record. Change goes live. Post-incident audit finds no PSSR documentation existed at time of startup.
What Good Looks Like in MOC
A working MOC system holds four disciplines together — structured request with technical basis, routed review with named approvers, linked PSI/training/procedure updates, and PSSR closeout with signed record.
Structured Request
Every MOC starts with the six required inputs: technical basis, safety impact, procedure impact, timing, authorization requirements, and training requirements — captured before the workflow routes for review.
Six inputs, upfront
Routed Review
Reviews route to named approvers by change type — process engineer, operations lead, mechanical integrity, safety, plant manager — with time-bound response and escalation on no-response.
Named approvers, time-bound
Linked Updates
Approved MOCs auto-link to PSI updates (P&ID, MSDS, PHA reference), operating procedure revisions, and training assignments — no chance the linkage is forgotten.
PSI + training linked
PSSR Closeout
Pre-startup safety review captured as structured checklist with signed sign-off. MOC is not closed until PSSR is complete. Startup blocked in the workflow until closure.
Signed before startup
How iFactory AI Fits
iFactory AI overlays your existing PSI repository, PHA study, learning management system, and CMMS — Meridium, Sphera, Enablon, Cority, Intelex — adding the MOC workflow layer without replacing the systems your process safety team already uses.
MOC Request
Workflow Layer
Structured form with all 1910.119(l)(2) technical basis, safety impact, procedure impact, timing, authorization, and training fields captured upfront.
Review Router
Workflow + Identity
Routes to named approvers by change category with time-bound response, delegation, and escalation on no-response. No inbox stalls, no orphan MOCs.
Linked Records
Workflow + PSI/LMS
Approved changes trigger linked updates to PSI (P&ID, MSDS, PHA), operating procedures, and LMS training assignments — with acknowledgment tracking.
PSSR Archive
Compliance Layer
Signed PSSR closeout per MOC. Full audit trail retained through the next PHA revalidation cycle per 1910.119(o) audit expectations.
Ask your process safety lead to produce three MOCs from last quarter — request, approvals, PSI updates, training records, and PSSR signoff for each. If any of the four artefacts is missing or on a shared drive, the 1910.119(o) audit will find it. Book an MOC workflow review.
12-Week MOC Rollout on One Covered Process
One PSM-covered process unit, one full change-management cycle, twelve weeks. The pilot proves the workflow catches every change type, satisfies 1910.119(l) sub-elements, and produces the audit trail 1910.119(o) reviewers ask for.
Weeks 1–2
Current-State Audit
Pull last twelve months of MOCs. Baseline against 1910.119(l) sub-elements. Identify where paper, shared drives, or verbal-only artefacts leave gaps. Sample against 1910.119(o) audit criteria.
Weeks 3–4
Workflow Setup
Configure the six-field request form, approver routing per change category, and PSI/training/PSSR linkage. Pilot users trained. Test with three real changes.
Weeks 5–8
Live on Unit
MOC workflow live for one PSM-covered process. Every change during pilot period routes through workflow. Weekly review with process safety lead refines routing and approver assignments.
Weeks 9–12
Audit-Ready Sample
Twelve-week window closes. Sample pilot MOCs against 1910.119(l) and (o) audit criteria. Rollout to remaining covered processes scoped based on completeness numbers.
Who Owns the KPI
MOC crosses process engineering, operations, mechanical integrity, safety, and plant leadership. Each function owns a specific KPI or the discipline reverts to inbox-based approval by default.
Process Safety Lead
MOC compliance rate to 1910.119(l)
Owns the elemental compliance — the share of MOCs with all six required inputs, named approvals, PSI updates, training linkage, and signed PSSR. 100% is the requirement, not the target.
Process Engineer
MOC cycle time (request to close)
Owns the workflow velocity — average days from request to signed PSSR. Long cycle times mean the workaround culture is still driving change outside the system.
Operations Lead
Startups blocked pending PSSR
Owns the pre-startup discipline — count of startup blocks the workflow enforces. Rising early, declining as culture forms is the healthy pattern.
Compliance / EHS
1910.119(o) audit findings on MOC
Owns the outcome — count and severity of MOC-related findings at the triennial PSM audit. Zero repeat findings on documentation gaps is the target.
FAQ
How does this handle organizational changes — OSHA's 2009 memo made those covered too?
Organizational changes (staffing, reporting structure, on-call coverage) that impact a covered process fall under 1910.119(l) per OSHA's March 2009 interpretation. The workflow includes an organizational-change category with fields specific to it — position eliminated or added, coverage impact, training or qualification impact, communication plan — so the same discipline applies. The 1910.119(l) requirement doesn't change; the review criteria do, and the workflow encodes them.
How does this integrate with our existing PSI repository and PHA studies?
The workflow reads PSI references (P&ID revision, MSDS ID, PHA study section) as MOC inputs and writes back updated PSI references at closeout. It does not replace your PSI repository — it links to it. PHA studies stay in your PHA tool (Sphera, DNV Phast, Meridium, or in-house); the workflow captures the PHA impact assessment as an MOC field and references the study. When the next PHA revalidation happens, the accumulated MOC record is exportable as input to the revalidation team.
Book a demo to see the PSI and PHA integration live.
What about EPA RMP MOC — does the same workflow cover it?
Yes. EPA Risk Management Program (40 CFR 68) MOC requirements at 40 CFR 68.75 mirror the PSM 1910.119(l) requirements almost line for line. Facilities covered under both PSM and RMP run one MOC program that satisfies both — the workflow supports that structure natively. State PSM programs (California, Nevada, Washington) add specific requirements that configure as additional fields or approver routes without a separate workflow.
Stop letting change requests stall in inboxes.
Walk Three MOCs Through the Workflow — Live
Bring three recent changes from a covered process — a piping modification, an operating window change, and an organizational change. We'll run all three through the workflow, quantify the current-state completeness gap, and scope the pilot rollout.
1910.119(l)
workflow discipline