What Is an Engineering Change Order (ECO)?
The Essential Guide to Requirements Management and Traceability
Chapters
- 1. Requirements Management
- Overview
- 1 What is Requirements Management? A Complete Guide
- 2 Why do you need Requirements Management?
- 3 Four Stages of Requirements Management Processes
- 4 Adopting Agile Requirements Management Tools
- 5 Status Request Changes
- 6 Conquering the 5 Biggest Challenges of Requirements Management
- 7 Three Reasons You Need a Requirements Management Solution
- 8 Guide to Poor Requirements: Identify Causes, Repercussions, and How to Fix Them
- 9 What Is a Requirements Management Plan? A Practical Guide
- 10 Enterprise Requirements Management: Keeping Traceability Current
- 2. Writing Requirements
- Overview
- 1 Functional requirements examples and templates
- 2 What Is a Product Requirements Document? A Complete PRD Guide
- 3 What Is a User Requirement Specification (URS)? How to Write and Manage One
- 4 Identifying and Measuring Requirements Quality
- 5 How to Write a System Requirements Specification (SRS) Document
- 6 The Fundamentals of Business Requirements: Examples of Business Requirements and the Importance of Excellence
- 7 Adopting the EARS Notation to Improve Requirements Engineering
- 8 What Is a Compliance Risk Assessment? Steps, Framework, and Examples
- 9 Jama Connect Advisor™
- 10 Frequently Asked Questions about the EARS Notation and Jama Connect Advisor™
- 11 How to Write an Effective Product Requirements Document (PRD)
- 12 Functional vs. Non-Functional Requirements
- 13 What Are Nonfunctional Requirements and How Do They Impact Product Development?
- 14 What Is a Software Design Specification? Key Components + Template
- 15 Characteristics of Effective Software Requirements and Software Requirements Specifications (SRS)
- 16 8 Do’s and Don’ts for Writing Requirements
- 17 Project Requirements: Types, Process, and Best Practices
- 18 INCOSE Guide to Writing Requirements
- 19 How to Write Technical Requirements That Survive Verification
- 3. Requirements Gathering and Management Processes
- Overview
- 1 Requirements Engineering
- 2 Requirements Analysis
- 3 A Guide to Requirements Elicitation for Product Teams
- 4 Requirements Gathering Techniques for Agile Product Teams
- 5 Requirements Gathering in Software Engineering: Process, Techniques, and Best Practices
- 6 Defining and Implementing a Requirements Baseline
- 7 Managing Project Scope — Why It Matters and Best Practices
- 8 Requirements Decomposition and How AI Supports It
- 9 How Long Do Requirements Take?
- 10 How to Reuse Requirements Across Multiple Products
- 11 Requirements Prioritization Techniques: 7 Methods for Engineers
- 12 How to Run a Requirements Gathering Workshop
- 4. Requirements Traceability
- Overview
- 1 What Is Traceability in Product Development? A Guide for Regulated Teams
- 2 Tracing Your Way to Success: The Crucial Role of Traceability in Modern Product and Systems Development
- 3 Bidirectional Traceability: What It Is and How to Implement It
- 4 Change Impact Analysis (CIA): A Short Guide for Effective Implementation
- 5 What is Engineering Change Management (ECM)? A Complete Guide
- 6 What is Meant by Version Control?
- 7 Key Traceability Challenges and Tips for Ensuring Accountability and Efficiency
- 8 The Role of a Data Thread in Product and Software Development
- 9 Unraveling the Digital Thread: Enhancing Connectivity and Efficiency
- 10 What is a Traceability Matrix? A Guide to Requirements Traceability
- 11 How to Create and Use a Requirements Traceability Matrix (RTM)
- 12 Requirements Traceability Matrix Pros and Cons: A Practical Guide
- 13 Live Traceability vs. After-the-Fact Traceability
- 14 Overcoming Barriers to Live Requirements Traceability™
- 15 Requirements Traceability, What Are You Missing?
- 16 Requirements Traceability: Links in the Chain
- 17 What Are the Benefits of End-to-End Traceability During Product Development?
- 18 Requirements Volatility: 7 Essential Management Strategies
- 19 FAQs About Requirements Traceability
- 20 What Is AI Traceability? How to Implement It
- 21 Product Traceability for Regulated Industries: A Complete Guide to Audit-Ready Compliance
- 22 What Is the Traceability Information Model?
- 23 Supply Chain Traceability: What to Send Suppliers and What to Get Back
- 24 What Is an Engineering Change Order (ECO)?
- 5. Requirements Management Tools and Software
- Overview
- 1 Selecting the Right Requirements Management Tools and Software
- 2 Why Investing in Requirements Management Software Makes Business Sense During an Economic Downturn
- 3 Why Word and Excel Alone is Not Enough for Product, Software, and Systems Development
- 4 Can You Track Requirements in Excel?
- 5 What Is Application Lifecycle Management (ALM)?
- 6 Is There Life After DOORS®?
- 7 Requirements Management Tools Jira
- 8 Checklist: Selecting a Requirements Management Tool
- 6. Requirements Validation and Verification
- 7. Meeting Regulatory Compliance and Industry Standards
- Overview
- 1 Understanding ISO Standards
- 2 Understanding ISO/IEC 27001: A Guide to Information Security Management
- 3 What is DevSecOps? A Guide to Building Secure Software
- 4 Compliance Management
- 5 What Is Functional Safety (FuSa)? Standards, Lifecycle, and Where Programs Fail
- 6 Failure Mode and Effects Analysis (FMEA) Explained
- 7 TÜV SÜD: Ensuring Safety, Quality, and Sustainability Worldwide
- 8 What is IEC 62443? A Guide to Industrial Cybersecurity
- 9 DFARS Compliance: A Guide for Defense Contractors
- 10 CMMC vs FedRAMP: What’s Different and Which One Applies to You
- 11 Automotive SPICE (ASPICE) 4.0: A Complete Guide
- 12 Restriction of Hazardous Substances (RoHS) Compliance Guide
- 13 MISRA C and MISRA C++ Explained: Rules for Safer Embedded Code
- 14 REACH Compliance for Product Engineering Teams
- 15 Radio Equipment Directive (RED) Cybersecurity Requirements
- 8. Systems Engineering
- Overview
- 1 What is Systems Engineering? A Guide for Modern Engineering Teams
- 2 How Do Engineers Collaborate? A Guide to Streamlined Teamwork and Innovation
- 3 The Systems Engineering Body of Knowledge (SEBoK)
- 4 What Is MBSE? Model-Based Systems Engineering Explained
- 5 Digital Engineering Between Government and Contractors
- 6 Digital Engineering Tools: The Key to Driving Innovation and Efficiency in Complex Systems
- 7 What Is Bill of Materials (BOM) Management? A Guide to Controlling Product Data
- 9. Automotive Development
- Overview
- 1 Understanding IATF 16949: A Quick Guide to Automotive Quality Management
- 2 What Is ISO 21434? Automotive Cybersecurity Engineering Explained
- 3 What Is ISO 26262? A Guide to Functional Safety in Automotive
- 4 What Is ASIL? A Guide to Automotive Safety Integrity Levels in ISO 26262
- 5 What Is SOTIF? A Guide to ISO 21448 for ADAS Safety
- 10. Medical Device & Life Sciences Development
- Overview
- 1 The Importance of Benefit-Risk Analysis in Medical Device Development
- 2 Software as a Medical Device: Revolutionizing Healthcare
- 3 What’s a Design History File, and How Are DHFs Used by Product Teams?
- 4 Navigating the Risks of Software of Unknown Pedigree (SOUP) in the Medical Device & Life Sciences Industry
- 5 What Is ISO 13485? A Guide to Medical Device Quality Management Systems
- 6 What Is a Device Master Record (DMR)? Definition and FDA Requirements
- 7 What Is IEC 62304? Medical Software Guide
- 8 ISO 13485 vs ISO 9001: Understanding the Differences and Synergies
- 9 What You Need to Know: ANSI/AAMI SW96:2023 — Medical Device Security
- 10 Failure Modes, Effects, and Diagnostic Analysis (FMEDA) for Medical Devices: What You Need to Know
- 11 Embracing the Future of Healthcare: Exploring the Internet of Medical Things (IoMT)
- 12 What Is General Safety and Performance Requirements (GSPR)? What You Need To Know
- 13 What Is IEC 62366? Usability Engineering for Medical Devices
- 14 What Is the Quality Management System Regulation (QMSR)?
- 15 510(k) vs PMA: Differences in FDA Device Approval and Clearance
- 16 EU MDR Compliance Requirements and Timeline
- 17 Essential Performance Requirements and How to Identify Them
- 18 DHF vs DMR vs DHR: What Changed Under the FDA QMSR
- 19 Computer Software Assurance for Production and Quality Systems
- 20 IVDR Compliance: What Manufacturers Need to Know
- 21 IEC 60601-1 Guide for Medical Devices
- 22 A Guide to Medical Device Requirements Management
- 11. Aerospace & Defense Development
- Overview
- 1 What is ITAR Compliance? What Engineering Teams Need to Know
- 2 What Is DO-278A? A Guide for Compliance Teams
- 3 ARP4754B Explained: Changes, Recognition, and Compliance
- 4 What Is a Safety Integrity Level (SIL)? How to Calculate and Apply It
- 5 A Guide to Aerospace Requirements Management
- 6 What Is ARP4754A? A Complete Guide to Civil Aircraft and Systems Development Assurance
- 7 Understanding ARP4761A: Guidelines for System Safety Assessment in Aerospace
- 8 What Is DO-254? A Complete Guide to Airborne Hardware Design Assurance
- 9 What Is DO-178C? A Guide to Airborne Software Certification
- 12. Architecture, Engineering, and Construction (AEC industry) Development
- 13. Industrial Manufacturing & Machinery, Automation & Robotics, Consumer Electronics, and Energy
- 14. Semiconductor Development
- 15. AI in Product Development
- Overview
- 1 What Is AI in Product Development? A Complete 2026 Guide
- 2 AI Test Case Generation: A Complete Guide for Regulated QA Teams
- 3 Using AI to Write Software Requirements: What Works and What Doesn’t
- 4 What Is the Model Context Protocol (MCP) for Requirements Management?
- 5 AI for Systems Engineering: Benefits, Risks, and How to Start
- 6 How to Automate Requirements Management
- 7 Artificial Intelligence in Requirements Management
- 16. Risk Management
- 17. Product Development Terms and Definitions
Chapter 4: What Is an Engineering Change Order (ECO)?
Chapters
- 1. Requirements Management
- Overview
- 1 What is Requirements Management? A Complete Guide
- 2 Why do you need Requirements Management?
- 3 Four Stages of Requirements Management Processes
- 4 Adopting Agile Requirements Management Tools
- 5 Status Request Changes
- 6 Conquering the 5 Biggest Challenges of Requirements Management
- 7 Three Reasons You Need a Requirements Management Solution
- 8 Guide to Poor Requirements: Identify Causes, Repercussions, and How to Fix Them
- 9 What Is a Requirements Management Plan? A Practical Guide
- 10 Enterprise Requirements Management: Keeping Traceability Current
- 2. Writing Requirements
- Overview
- 1 Functional requirements examples and templates
- 2 What Is a Product Requirements Document? A Complete PRD Guide
- 3 What Is a User Requirement Specification (URS)? How to Write and Manage One
- 4 Identifying and Measuring Requirements Quality
- 5 How to Write a System Requirements Specification (SRS) Document
- 6 The Fundamentals of Business Requirements: Examples of Business Requirements and the Importance of Excellence
- 7 Adopting the EARS Notation to Improve Requirements Engineering
- 8 What Is a Compliance Risk Assessment? Steps, Framework, and Examples
- 9 Jama Connect Advisor™
- 10 Frequently Asked Questions about the EARS Notation and Jama Connect Advisor™
- 11 How to Write an Effective Product Requirements Document (PRD)
- 12 Functional vs. Non-Functional Requirements
- 13 What Are Nonfunctional Requirements and How Do They Impact Product Development?
- 14 What Is a Software Design Specification? Key Components + Template
- 15 Characteristics of Effective Software Requirements and Software Requirements Specifications (SRS)
- 16 8 Do’s and Don’ts for Writing Requirements
- 17 Project Requirements: Types, Process, and Best Practices
- 18 INCOSE Guide to Writing Requirements
- 19 How to Write Technical Requirements That Survive Verification
- 3. Requirements Gathering and Management Processes
- Overview
- 1 Requirements Engineering
- 2 Requirements Analysis
- 3 A Guide to Requirements Elicitation for Product Teams
- 4 Requirements Gathering Techniques for Agile Product Teams
- 5 Requirements Gathering in Software Engineering: Process, Techniques, and Best Practices
- 6 Defining and Implementing a Requirements Baseline
- 7 Managing Project Scope — Why It Matters and Best Practices
- 8 Requirements Decomposition and How AI Supports It
- 9 How Long Do Requirements Take?
- 10 How to Reuse Requirements Across Multiple Products
- 11 Requirements Prioritization Techniques: 7 Methods for Engineers
- 12 How to Run a Requirements Gathering Workshop
- 4. Requirements Traceability
- Overview
- 1 What Is Traceability in Product Development? A Guide for Regulated Teams
- 2 Tracing Your Way to Success: The Crucial Role of Traceability in Modern Product and Systems Development
- 3 Bidirectional Traceability: What It Is and How to Implement It
- 4 Change Impact Analysis (CIA): A Short Guide for Effective Implementation
- 5 What is Engineering Change Management (ECM)? A Complete Guide
- 6 What is Meant by Version Control?
- 7 Key Traceability Challenges and Tips for Ensuring Accountability and Efficiency
- 8 The Role of a Data Thread in Product and Software Development
- 9 Unraveling the Digital Thread: Enhancing Connectivity and Efficiency
- 10 What is a Traceability Matrix? A Guide to Requirements Traceability
- 11 How to Create and Use a Requirements Traceability Matrix (RTM)
- 12 Requirements Traceability Matrix Pros and Cons: A Practical Guide
- 13 Live Traceability vs. After-the-Fact Traceability
- 14 Overcoming Barriers to Live Requirements Traceability™
- 15 Requirements Traceability, What Are You Missing?
- 16 Requirements Traceability: Links in the Chain
- 17 What Are the Benefits of End-to-End Traceability During Product Development?
- 18 Requirements Volatility: 7 Essential Management Strategies
- 19 FAQs About Requirements Traceability
- 20 What Is AI Traceability? How to Implement It
- 21 Product Traceability for Regulated Industries: A Complete Guide to Audit-Ready Compliance
- 22 What Is the Traceability Information Model?
- 23 Supply Chain Traceability: What to Send Suppliers and What to Get Back
- 24 What Is an Engineering Change Order (ECO)?
- 5. Requirements Management Tools and Software
- Overview
- 1 Selecting the Right Requirements Management Tools and Software
- 2 Why Investing in Requirements Management Software Makes Business Sense During an Economic Downturn
- 3 Why Word and Excel Alone is Not Enough for Product, Software, and Systems Development
- 4 Can You Track Requirements in Excel?
- 5 What Is Application Lifecycle Management (ALM)?
- 6 Is There Life After DOORS®?
- 7 Requirements Management Tools Jira
- 8 Checklist: Selecting a Requirements Management Tool
- 6. Requirements Validation and Verification
- 7. Meeting Regulatory Compliance and Industry Standards
- Overview
- 1 Understanding ISO Standards
- 2 Understanding ISO/IEC 27001: A Guide to Information Security Management
- 3 What is DevSecOps? A Guide to Building Secure Software
- 4 Compliance Management
- 5 What Is Functional Safety (FuSa)? Standards, Lifecycle, and Where Programs Fail
- 6 Failure Mode and Effects Analysis (FMEA) Explained
- 7 TÜV SÜD: Ensuring Safety, Quality, and Sustainability Worldwide
- 8 What is IEC 62443? A Guide to Industrial Cybersecurity
- 9 DFARS Compliance: A Guide for Defense Contractors
- 10 CMMC vs FedRAMP: What’s Different and Which One Applies to You
- 11 Automotive SPICE (ASPICE) 4.0: A Complete Guide
- 12 Restriction of Hazardous Substances (RoHS) Compliance Guide
- 13 MISRA C and MISRA C++ Explained: Rules for Safer Embedded Code
- 14 REACH Compliance for Product Engineering Teams
- 15 Radio Equipment Directive (RED) Cybersecurity Requirements
- 8. Systems Engineering
- Overview
- 1 What is Systems Engineering? A Guide for Modern Engineering Teams
- 2 How Do Engineers Collaborate? A Guide to Streamlined Teamwork and Innovation
- 3 The Systems Engineering Body of Knowledge (SEBoK)
- 4 What Is MBSE? Model-Based Systems Engineering Explained
- 5 Digital Engineering Between Government and Contractors
- 6 Digital Engineering Tools: The Key to Driving Innovation and Efficiency in Complex Systems
- 7 What Is Bill of Materials (BOM) Management? A Guide to Controlling Product Data
- 9. Automotive Development
- Overview
- 1 Understanding IATF 16949: A Quick Guide to Automotive Quality Management
- 2 What Is ISO 21434? Automotive Cybersecurity Engineering Explained
- 3 What Is ISO 26262? A Guide to Functional Safety in Automotive
- 4 What Is ASIL? A Guide to Automotive Safety Integrity Levels in ISO 26262
- 5 What Is SOTIF? A Guide to ISO 21448 for ADAS Safety
- 10. Medical Device & Life Sciences Development
- Overview
- 1 The Importance of Benefit-Risk Analysis in Medical Device Development
- 2 Software as a Medical Device: Revolutionizing Healthcare
- 3 What’s a Design History File, and How Are DHFs Used by Product Teams?
- 4 Navigating the Risks of Software of Unknown Pedigree (SOUP) in the Medical Device & Life Sciences Industry
- 5 What Is ISO 13485? A Guide to Medical Device Quality Management Systems
- 6 What Is a Device Master Record (DMR)? Definition and FDA Requirements
- 7 What Is IEC 62304? Medical Software Guide
- 8 ISO 13485 vs ISO 9001: Understanding the Differences and Synergies
- 9 What You Need to Know: ANSI/AAMI SW96:2023 — Medical Device Security
- 10 Failure Modes, Effects, and Diagnostic Analysis (FMEDA) for Medical Devices: What You Need to Know
- 11 Embracing the Future of Healthcare: Exploring the Internet of Medical Things (IoMT)
- 12 What Is General Safety and Performance Requirements (GSPR)? What You Need To Know
- 13 What Is IEC 62366? Usability Engineering for Medical Devices
- 14 What Is the Quality Management System Regulation (QMSR)?
- 15 510(k) vs PMA: Differences in FDA Device Approval and Clearance
- 16 EU MDR Compliance Requirements and Timeline
- 17 Essential Performance Requirements and How to Identify Them
- 18 DHF vs DMR vs DHR: What Changed Under the FDA QMSR
- 19 Computer Software Assurance for Production and Quality Systems
- 20 IVDR Compliance: What Manufacturers Need to Know
- 21 IEC 60601-1 Guide for Medical Devices
- 22 A Guide to Medical Device Requirements Management
- 11. Aerospace & Defense Development
- Overview
- 1 What is ITAR Compliance? What Engineering Teams Need to Know
- 2 What Is DO-278A? A Guide for Compliance Teams
- 3 ARP4754B Explained: Changes, Recognition, and Compliance
- 4 What Is a Safety Integrity Level (SIL)? How to Calculate and Apply It
- 5 A Guide to Aerospace Requirements Management
- 6 What Is ARP4754A? A Complete Guide to Civil Aircraft and Systems Development Assurance
- 7 Understanding ARP4761A: Guidelines for System Safety Assessment in Aerospace
- 8 What Is DO-254? A Complete Guide to Airborne Hardware Design Assurance
- 9 What Is DO-178C? A Guide to Airborne Software Certification
- 12. Architecture, Engineering, and Construction (AEC industry) Development
- 13. Industrial Manufacturing & Machinery, Automation & Robotics, Consumer Electronics, and Energy
- 14. Semiconductor Development
- 15. AI in Product Development
- Overview
- 1 What Is AI in Product Development? A Complete 2026 Guide
- 2 AI Test Case Generation: A Complete Guide for Regulated QA Teams
- 3 Using AI to Write Software Requirements: What Works and What Doesn’t
- 4 What Is the Model Context Protocol (MCP) for Requirements Management?
- 5 AI for Systems Engineering: Benefits, Risks, and How to Start
- 6 How to Automate Requirements Management
- 7 Artificial Intelligence in Requirements Management
- 16. Risk Management
- 17. Product Development Terms and Definitions
What Is an Engineering Change Order (ECO)?
A released design cannot be changed by editing the drawing and telling people afterwards. The change runs through a controlled instruction called an engineering change order (ECO), which says what is changing and routes it for formal approval.
Most of what an ECO asks for is procedure. The impact assessment is the part that decides whether the record holds up, because a thin one looks the same on the form as a thorough one until something ships. The difference never shows up in the signatures, only months later in a test nobody re-ran or a supplier still building to a superseded drawing.
The Quality Management System Regulation (QMSR) took effect on February 2, 2026 and made that assessment an inspection target. It amended 21 CFR Part 820 to incorporate ISO 13485 by reference, and the design-control section it replaced is now reserved.
ECOs run in every regulated hardware programme, and the medical device rules changed most recently, so this guide works from those. This guide covers what an ECO record must contain, what the standards require, how an order moves from request to closure, and why the impact assessment decides whether any of it survives an inspection.
What an ECO Record Has to Contain
The document that carries the instruction is the ECO record, and it has to hold enough for someone who was not in the room to reconstruct the decision.
A released design sits under a configuration baseline set by engineering, after which change becomes a formalized process. Changes affecting form, fit, or function typically go through the ECO. A text correction to a work instruction that leaves the design untouched can move through a lighter document change order (DCO), so classifying the change comes first.
Three documents move a change from proposal to production floor, and only one of them authorizes work:
| Document | What it does | Authorizes work? |
| Engineering change request (ECR) | Examines necessity and feasibility, identifies affected parts and documents, estimates cost and resources | No |
| Engineering change order (ECO) | Defines the approved change, lists affected items with updated drawings and files, routes for formal approval, tracks implementation | Yes, once approved |
| Engineering change notice (ECN) | Records what actually changed and when it takes effect, and tells manufacturing, service, and supplier quality which configuration is now in force | No, it reports a change already authorized |
Auditors read the approval record as evidence that the team reviewed the change before implementation, and a complete record takes more than signatures. The evidence it carries falls into three groups:
- Change definition: The ECO number, requestor and date, what is changing, the justification, and the classification the company’s own procedure defines, which usually bands changes by safety impact.
- Affected items and impact: The part numbers, documents, specifications, and bills of materials (BOMs) touched, plus the cross-functional impact assessment and the updated risk management file.
- Evidence and release: Verification results, the effectivity date or lot from which the change applies, disposition of work in progress and of field and supplier stock, and signatures with roles and dates.
Three out of three change records that were reviewed in a 2025 inspection of one medical device manufacturer failed to record what was changing, why, or what the change would affect. FDA issued the warning letter that October, under the regulation the QMSR has since replaced. The firm’s corrective action was to rewrite what its change requests have to carry, including a before-and-after comparison of the device and an evaluation of safety and risk.
What the Standards Require of a Design Change
Both the US and EU regimes ask for the same sequence. A team determines how significant the change is, then reviews, verifies, validates as appropriate, and approves it before implementation. ISO 13485, the medical device quality management systems standard, sets that pattern in Clause 7.3.9 and measures significance against function, performance, usability, safety, and applicable regulatory requirements. The review reaches constituent parts and product in process or already delivered, and the inputs and outputs of risk management. The documented assessment is what determines whether verification, validation, or both are appropriate.
The QMSR is what puts that clause in front of an FDA investigator rather than a certification body. Since February 2, 2026 the agency has inspected under Compliance Program 7382.850. Records once outside routine review, including management review and supplier audit reports, are now in scope.
Europe runs a similar sequence with a different approval authority. Under EU MDR 2017/745 the conformity assessment annexes govern change control, and a change that could affect safety or performance needs notified body approval. For a legacy device still trading on a Medical Device Directive (MDD) or Active Implantable Medical Device Directive (AIMDD) certificate, Medical Device Coordination Group (MDCG) guidance 2020-3 Rev.1 asks two cumulative questions. Is this a change in design or intended purpose, and is that change significant? Answer yes twice and the certificate no longer covers the device.
How an ECO Moves From Request to Closure
An ECO moves through six stages, though the number of named steps varies by procedure. Step two is the one the rest of this guide comes back to:
- Request: Anyone in engineering, quality, production, or the supply base raises an ECR describing the problem and what it appears to affect.
- Impact analysis: Reviewers run a change impact analysis covering effects on cost, schedule, safety, compliance, interfaces, and downstream documents. For regulated hardware-software products, the risk evaluation and the test plan take shape at this stage.
- ECO creation: The team creates the controlled ECO record from the request and the impact analysis.
- CCB review and approval: The change control board (CCB) approves, rejects, or defers. Approval also fixes effectivity and the verification evidence required, and a rejection goes back with documented rationale.
- Implementation and notification: Teams execute against the approved ECO, updating drawings, the bill of materials, specifications, and work instructions. The ECN then tells manufacturing, service, and supplier quality what changed and when it applies.
- Verification and closure: The team checks the first units built under the change and reviews the verification and validation results. Closure updates the design and development file, runs an effectiveness check on anything that came from a Corrective and Preventive Action (CAPA), and records signatures and dates.
Step two is the only stage that runs on judgment, and nothing in the finished record reports how far that judgment reached.
Why the Impact Assessment Decides Whether an ECO Holds Up
The assessment that step two produces fails quietly, because a thin one and a thorough one look identical on paper. Both are a completed form with a list of affected items and a set of signatures. Nothing on either one records what the assessor looked at, or what they couldn’t see.
An assessment reaches only as far as the team can see what a change touches, and that boundary usually sits earlier than anyone assumes. The ECO record lives in a change or product lifecycle system, and almost nothing it has to be assessed against lives there with it. Requirements sit in a requirements tool or a Word file, tests in a test tool or a spreadsheet, and risk items somewhere else again. Nothing crosses that boundary on its own, so the assessment covers whatever the assessor thought to open. A connector spec moves, the requirement changes, the ECO records it, and the test cases that exercise the mating force never reach the affected-items list, because they live somewhere the change record cannot see. Undocumented design changes are a recurring theme in FDA warning letters. An assessment that cannot see across this boundary is one way a change record ends up without the impact evaluation an auditor expects.
The manual compensation is a requirements traceability matrix maintained by hand. It works until the first change lands, then it drifts from the design it describes, and every subsequent assessment inherits the drift. Nobody notices, because the matrix doesn’t report its own staleness. A reviewer opening it sees a populated grid either way.
Bidirectional traceability changes what the assessment can reach. Engineers trace forward from a changed requirement to affected subsystem requirements and design parameters, and on to each verification procedure that exercises them. They trace backward from existing test plans and risk controls to find which results are still valid and which now rest on a superseded assumption. The output is a list the reviewer didn’t have to take on trust.
“Did you assess the impact?” is answered by the form, and the form is always yes. What did the assessment cover, and what would have told the reviewer if it had missed something? Live trace links answer both questions out of the record itself. Without them the reviewer is taking the assessor’s word for the coverage, and so is the auditor reading it two years later.
How Jama Connect Supports Engineering Change Orders
Jama Connect® is a web-based requirements management and traceability platform for complex, regulated product development, and it works on steps two, four, and six of the workflow above. Impact Analysis runs on an item before the change is made and returns every linked requirement, test case, and risk item across multiple degrees of separation. A CCB then reviews what the change actually reaches. A Traceability Information Model™ (TIM) defines which item types must relate to which, so a system requirement with no linked test case surfaces as a missing required relationship.
Once a change lands, every linked test case, risk item, and design element is flagged as suspect. The engineer who owns it either updates the artifact or clears the flag, which builds the decision trail step six has to close against. Review Center routes the affected items to reviewers and approvers and records each approver’s decision and electronic signature, and version control preserves who approved the change and why.
Making the Next Design Change Defensible Under the QMSR
The same ECO record can satisfy two authorities at once. An FDA investigator evaluates it under the QMSR, and for a device still trading on a legacy certificate a notified body applies the MDCG significant-change test to the same record. Neither one is reading for effort. Both are reading for whether the assessment behind the change can be shown to have covered what the change reached. Trace-link coverage is what decides it, whatever care went into filling in the form.
Jama Connect supports that with baselines that snapshot the item set and its relationships before and after a change, so the reach of the assessment is itself part of the record. If your team reconstructs that reach by hand every time a released requirement moves, you can start a free 30-day trial and run an impact analysis against a change request of your own.
Frequently Asked Questions About Engineering Change Order
Who has the authority to approve an engineering change order?
Authority sits wherever your procedures put it, which is why the procedure is the artifact an auditor asks for first. It should name the reviewers and approvers, set how many approvals are required, state whether consent must be unanimous, and explain what happens when a review stalls. Configurable approval rules in Jama Connect enforce that structure so it doesn’t rest on convention. A formal change management process treats the rule set as a controlled item in its own right.
What is a typical cycle time for an engineering change order?
There is no industry-standard figure, and averaging change types together hides the number that matters, because a stop-ship and a cosmetic revision have nothing in common. The useful discipline is to measure from CCB entry and band by change class. For a reference point, review cycles at Grifols fell from 90 days to fewer than 30 days after reviews moved into Jama Connect, reports Carmen Pazos, Diagnostic Divisions R&D Instruments Senior Manager at Grifols.
How does the QMSR change ECO documentation for medical device teams?
Every controlled document that still cites the old design-control sections now points at a reference that no longer exists. Inventory those controlled documents first, then revise the cross-references for the QMSR, and keep each revision’s author, date, change detail, and approval history so the transition itself stays auditable.
This article was authored by Mario Maldari and published on September 14, 2026.
Book a Demo
See Jama Connect in Action!
Our Jama Connect experts are ready to guide you through a personalized demo, answer your questions, and show you how Jama Connect can help you identify risks, improve cross-team collaboration, and drive faster time to market.