What Is an Engineering Change Order (ECO)?

Chapters

Chapter 4: What Is an Engineering Change Order (ECO)?

Chapters

What Is an Engineering Change Order (ECO)?

A released design cannot be changed by editing the drawing and telling people afterwards. The change runs through a controlled instruction called an engineering change order (ECO), which says what is changing and routes it for formal approval.

Most of what an ECO asks for is procedure. The impact assessment is the part that decides whether the record holds up, because a thin one looks the same on the form as a thorough one until something ships. The difference never shows up in the signatures, only months later in a test nobody re-ran or a supplier still building to a superseded drawing.

The Quality Management System Regulation (QMSR) took effect on February 2, 2026 and made that assessment an inspection target. It amended 21 CFR Part 820 to incorporate ISO 13485 by reference, and the design-control section it replaced is now reserved.

ECOs run in every regulated hardware programme, and the medical device rules changed most recently, so this guide works from those. This guide covers what an ECO record must contain, what the standards require, how an order moves from request to closure, and why the impact assessment decides whether any of it survives an inspection.

What an ECO Record Has to Contain

The document that carries the instruction is the ECO record, and it has to hold enough for someone who was not in the room to reconstruct the decision.

A released design sits under a configuration baseline set by engineering, after which change becomes a formalized process. Changes affecting form, fit, or function typically go through the ECO. A text correction to a work instruction that leaves the design untouched can move through a lighter document change order (DCO), so classifying the change comes first.

Three documents move a change from proposal to production floor, and only one of them authorizes work:

Document What it does Authorizes work?
Engineering change request (ECR) Examines necessity and feasibility, identifies affected parts and documents, estimates cost and resources No
Engineering change order (ECO) Defines the approved change, lists affected items with updated drawings and files, routes for formal approval, tracks implementation Yes, once approved
Engineering change notice (ECN) Records what actually changed and when it takes effect, and tells manufacturing, service, and supplier quality which configuration is now in force No, it reports a change already authorized

Auditors read the approval record as evidence that the team reviewed the change before implementation, and a complete record takes more than signatures. The evidence it carries falls into three groups:

  • Change definition: The ECO number, requestor and date, what is changing, the justification, and the classification the company’s own procedure defines, which usually bands changes by safety impact.
  • Affected items and impact: The part numbers, documents, specifications, and bills of materials (BOMs) touched, plus the cross-functional impact assessment and the updated risk management file.
  • Evidence and release: Verification results, the effectivity date or lot from which the change applies, disposition of work in progress and of field and supplier stock, and signatures with roles and dates.

Three out of three change records that were reviewed in a 2025 inspection of one medical device manufacturer failed to record what was changing, why, or what the change would affect. FDA issued the warning letter that October, under the regulation the QMSR has since replaced. The firm’s corrective action was to rewrite what its change requests have to carry, including a before-and-after comparison of the device and an evaluation of safety and risk.

What the Standards Require of a Design Change

Both the US and EU regimes ask for the same sequence. A team determines how significant the change is, then reviews, verifies, validates as appropriate, and approves it before implementation. ISO 13485, the medical device quality management systems standard, sets that pattern in Clause 7.3.9 and measures significance against function, performance, usability, safety, and applicable regulatory requirements. The review reaches constituent parts and product in process or already delivered, and the inputs and outputs of risk management. The documented assessment is what determines whether verification, validation, or both are appropriate.

The QMSR is what puts that clause in front of an FDA investigator rather than a certification body. Since February 2, 2026 the agency has inspected under Compliance Program 7382.850. Records once outside routine review, including management review and supplier audit reports, are now in scope.

Europe runs a similar sequence with a different approval authority. Under EU MDR 2017/745 the conformity assessment annexes govern change control, and a change that could affect safety or performance needs notified body approval. For a legacy device still trading on a Medical Device Directive (MDD) or Active Implantable Medical Device Directive (AIMDD) certificate, Medical Device Coordination Group (MDCG) guidance 2020-3 Rev.1 asks two cumulative questions. Is this a change in design or intended purpose, and is that change significant? Answer yes twice and the certificate no longer covers the device.

How an ECO Moves From Request to Closure

An ECO moves through six stages, though the number of named steps varies by procedure. Step two is the one the rest of this guide comes back to:

  1. Request: Anyone in engineering, quality, production, or the supply base raises an ECR describing the problem and what it appears to affect.
  2. Impact analysis: Reviewers run a change impact analysis covering effects on cost, schedule, safety, compliance, interfaces, and downstream documents. For regulated hardware-software products, the risk evaluation and the test plan take shape at this stage.
  3. ECO creation: The team creates the controlled ECO record from the request and the impact analysis.
  4. CCB review and approval: The change control board (CCB) approves, rejects, or defers. Approval also fixes effectivity and the verification evidence required, and a rejection goes back with documented rationale.
  5. Implementation and notification: Teams execute against the approved ECO, updating drawings, the bill of materials, specifications, and work instructions. The ECN then tells manufacturing, service, and supplier quality what changed and when it applies.
  6. Verification and closure: The team checks the first units built under the change and reviews the verification and validation results. Closure updates the design and development file, runs an effectiveness check on anything that came from a Corrective and Preventive Action (CAPA), and records signatures and dates.

Step two is the only stage that runs on judgment, and nothing in the finished record reports how far that judgment reached.

Why the Impact Assessment Decides Whether an ECO Holds Up

The assessment that step two produces fails quietly, because a thin one and a thorough one look identical on paper. Both are a completed form with a list of affected items and a set of signatures. Nothing on either one records what the assessor looked at, or what they couldn’t see.

An assessment reaches only as far as the team can see what a change touches, and that boundary usually sits earlier than anyone assumes. The ECO record lives in a change or product lifecycle system, and almost nothing it has to be assessed against lives there with it. Requirements sit in a requirements tool or a Word file, tests in a test tool or a spreadsheet, and risk items somewhere else again. Nothing crosses that boundary on its own, so the assessment covers whatever the assessor thought to open. A connector spec moves, the requirement changes, the ECO records it, and the test cases that exercise the mating force never reach the affected-items list, because they live somewhere the change record cannot see. Undocumented design changes are a recurring theme in FDA warning letters. An assessment that cannot see across this boundary is one way a change record ends up without the impact evaluation an auditor expects.

The manual compensation is a requirements traceability matrix maintained by hand. It works until the first change lands, then it drifts from the design it describes, and every subsequent assessment inherits the drift. Nobody notices, because the matrix doesn’t report its own staleness. A reviewer opening it sees a populated grid either way.

Bidirectional traceability changes what the assessment can reach. Engineers trace forward from a changed requirement to affected subsystem requirements and design parameters, and on to each verification procedure that exercises them. They trace backward from existing test plans and risk controls to find which results are still valid and which now rest on a superseded assumption. The output is a list the reviewer didn’t have to take on trust.

“Did you assess the impact?” is answered by the form, and the form is always yes. What did the assessment cover, and what would have told the reviewer if it had missed something? Live trace links answer both questions out of the record itself. Without them the reviewer is taking the assessor’s word for the coverage, and so is the auditor reading it two years later.

How Jama Connect Supports Engineering Change Orders

Jama Connect® is a web-based requirements management and traceability platform for complex, regulated product development, and it works on steps two, four, and six of the workflow above. Impact Analysis runs on an item before the change is made and returns every linked requirement, test case, and risk item across multiple degrees of separation. A CCB then reviews what the change actually reaches. A Traceability Information Model™ (TIM) defines which item types must relate to which, so a system requirement with no linked test case surfaces as a missing required relationship.

Once a change lands, every linked test case, risk item, and design element is flagged as suspect. The engineer who owns it either updates the artifact or clears the flag, which builds the decision trail step six has to close against. Review Center routes the affected items to reviewers and approvers and records each approver’s decision and electronic signature, and version control preserves who approved the change and why.

Making the Next Design Change Defensible Under the QMSR

The same ECO record can satisfy two authorities at once. An FDA investigator evaluates it under the QMSR, and for a device still trading on a legacy certificate a notified body applies the MDCG significant-change test to the same record. Neither one is reading for effort. Both are reading for whether the assessment behind the change can be shown to have covered what the change reached. Trace-link coverage is what decides it, whatever care went into filling in the form.

Jama Connect supports that with baselines that snapshot the item set and its relationships before and after a change, so the reach of the assessment is itself part of the record. If your team reconstructs that reach by hand every time a released requirement moves, you can start a free 30-day trial and run an impact analysis against a change request of your own.

Frequently Asked Questions About Engineering Change Order

Who has the authority to approve an engineering change order?

Authority sits wherever your procedures put it, which is why the procedure is the artifact an auditor asks for first. It should name the reviewers and approvers, set how many approvals are required, state whether consent must be unanimous, and explain what happens when a review stalls. Configurable approval rules in Jama Connect enforce that structure so it doesn’t rest on convention. A formal change management process treats the rule set as a controlled item in its own right.

What is a typical cycle time for an engineering change order?

There is no industry-standard figure, and averaging change types together hides the number that matters, because a stop-ship and a cosmetic revision have nothing in common. The useful discipline is to measure from CCB entry and band by change class. For a reference point, review cycles at Grifols fell from 90 days to fewer than 30 days after reviews moved into Jama Connect, reports Carmen Pazos, Diagnostic Divisions R&D Instruments Senior Manager at Grifols.

How does the QMSR change ECO documentation for medical device teams?

Every controlled document that still cites the old design-control sections now points at a reference that no longer exists. Inventory those controlled documents first, then revise the cross-references for the QMSR, and keep each revision’s author, date, change detail, and approval history so the transition itself stays auditable.

This article was authored by Mario Maldari and published on September 14, 2026.

Book a Demo

See Jama Connect in Action!

Our Jama Connect experts are ready to guide you through a personalized demo, answer your questions, and show you how Jama Connect can help you identify risks, improve cross-team collaboration, and drive faster time to market.