How to Run a Temporary Change Review Before Work Starts
Temporary changes become high-risk when the site treats them as minor exceptions. This practical guide shows supervisors, engineers, and EHS leaders how to review a temporary modification, assign control ownership, test the new conditions, and define a safe return to the normal state before work begins.

Key takeaways
- 01A temporary change is controlled only when the altered conditions and replacement safeguards are visible in the field.
- 02The review should separate the normal state from the temporary state so weakened or newly required controls are not hidden.
- 03Every critical control needs one named owner, a clear handoff, an operating limit, and an observable stop condition.
- 04Field verification must test current evidence rather than rely on a signature or an unchanged checklist.
- 05A temporary change needs a review date and a restoration test before work starts, because temporary workarounds can quietly become normal.
A temporary change often arrives with harmless language. A bypass will last only one shift. A contractor will use a different access route. A pump will operate below its normal capacity until a replacement arrives. The risk grows when that temporary condition receives less scrutiny than the permanent design it replaces.
This guide gives supervisors, engineers, and EHS leaders an eight-step review that can be completed before work starts. The central idea is simple but demanding. A temporary change is not controlled when someone has approved it. It is controlled when the altered conditions, new dependencies, decision owner, verification evidence, and return plan are visible to the people who will operate the work.
What you need before starting
A temporary change review is a documented field decision that identifies what has changed, how the change alters exposure and controls, who owns each safeguard, how the operation will verify readiness, and what must happen before the normal condition is restored.
Bring the proposed change, the current procedure, relevant drawings or task information, the people who operate and maintain the area, and the person who can authorize a delay. Review the existing risk picture, but do not assume that the old assessment describes the new work. The review exists because a small deviation can move risk into a control that nobody has named. The temporary risk waiver framework helps keep the expiry, recovery owner, and interim protection visible.
Use the existing management-of-change analysis when the team needs to challenge the belief that temporary decisions are automatically low risk. The review below focuses on what the team must do at the worksite before execution.
Step 1: Describe the change in operational terms
Write what will be different, where it will be different, when it will start, and how long it is expected to last. Avoid phrases such as “minor modification” or “short-term workaround” because they describe attitude rather than condition.
State the affected equipment, process, people, materials, interfaces, and operating limits. If a guard is removed, name the guard and the exposed movement. If a route changes, name the crossing, access point, and people who will use it. A precise description gives the rest of the review something that can be tested.
Ask the person closest to the work to explain the change in their own words. When that description differs from the written request, stop and reconcile the difference before moving forward.
Step 2: Separate the temporary condition from the normal condition
Compare the proposed state with the approved operating state. Identify which barriers remain, which barriers are weakened, which barriers are replaced, and which new actions now depend on human attention.
This comparison matters because teams often preserve the old checklist while quietly changing the work. A normal inspection may assume a fixed platform, a closed line, or a functioning interlock. The temporary state may depend on a spotter, a manual reading, or a restricted operating window instead.
Record the differences in a short table or marked-up sketch that the crew can use at the point of work. The document should show the changed condition, not only the approval path.
Step 3: Identify new exposure and credible failure paths
Walk through how the change could create harm, including failures that are not obvious from the original request. Consider unexpected movement, stored energy, loss of containment, blocked access, poor visibility, communication failure, simultaneous work, weather, fatigue, and delayed response.
Do not stop at the first hazard named by the requester. Ask what happens if the replacement control is missed, unavailable, misunderstood, or removed during a handover. James Reason’s work on latent failures is useful here because the immediate error may be visible while the conditions that made it likely remain hidden.
In projects supported by Andreza Araujo, this is where a temporary decision is tested against the operation rather than against its paperwork. The risk review should expose the trap that the market often minimizes, namely that a workaround can become normal before anyone formally accepts it as the new normal.
Step 4: Assign one owner to every critical control
Name the person or role that will make each safeguard available, verify it, and respond when it fails. “Operations” or “the team” is not an owner because a group cannot be held visibly accountable at the moment a decision is needed.
Clarify who owns isolation, inspection, monitoring, access control, communication, emergency response, and restoration. If one control depends on another department, record the handoff and the evidence that confirms it occurred.
Test the assignment with a direct question. If this control is missing at 2:00 a.m., who has the authority to stop the job and who must be called next? If the answer takes too long, the control is not yet ready for field use.
Step 5: Define operating limits and stop conditions
Set the limits that make the temporary condition acceptable, including duration, load, speed, weather, personnel, access, monitoring frequency, and simultaneous work. Then define the conditions that require an immediate stop or a fresh review.
Stop conditions should be observable. Examples include a failed alarm, an unavailable spotter, a changed wind condition, a new leak, a missed reading, a different crew, or a task that extends beyond the approved boundary. Avoid relying on a vague instruction to “use judgment” when the operation needs a clear trigger.
The supervisor should review these conditions with the crew before work begins. A control that exists only in the approver’s file cannot protect people who never heard it.
Step 6: Verify the changed condition in the field
Walk the area with the people who will execute the work. Confirm the physical change, the replacement controls, access, lighting, isolation, tools, communication route, and emergency path. Compare what is visible with the description from Step 1.
Use evidence that can be checked later, such as a current reading, equipment status, inspection record, photograph where permitted, or direct demonstration. A signature confirms participation, but it does not prove that a barrier can perform.
When field conditions differ from the approved request, do not edit the decision informally. Pause the work, revise the review, and obtain a new authorization from the correct decision owner.
Step 7: Brief every affected interface
Temporary changes rarely affect one crew. They can alter maintenance access, production timing, contractor movement, emergency response, control-room decisions, and the work of a neighboring area.
Brief each affected interface on what changed, what remains prohibited, which controls are temporary, who owns the decision, and how to escalate a concern. Ask the receiving person to repeat the consequence for their work because a one-way announcement can create the appearance of communication without shared understanding.
Record the handover when the change crosses a shift, contractor boundary, or department boundary. The next team must receive the current condition, not merely a reference to the original approval.
Step 8: Set the review date and restoration test
Give the temporary condition an owner, an expiry or review date, and a restoration plan before the first task begins. The date should be tied to the work and the risk, not chosen because it is convenient for the calendar.
Define what “back to normal” means. The team may need to reinstall a guard, restore a line, remove a bypass, close a temporary route, update a procedure, or verify that the original alarm and interlock operate as intended. Restoration is complete only when the physical condition and the operating information agree.
Schedule a review before expiry, especially when the work is delayed or the workaround is extended. More than 250 cultural-transformation projects across 30+ countries have reinforced a practical lesson for Andreza Araujo: temporary controls lose credibility when nobody owns the moment at which they must be challenged or removed.
Final checklist for the review owner
- Is the changed condition described precisely enough for a field worker to recognize it?
- Are weakened, replaced, and newly required controls visible?
- Does every critical control have one named owner and a defined handoff?
- Are the operating limits and stop conditions observable?
- Has the changed condition been verified at the worksite with current evidence?
- Have affected crews, departments, contractors, and shifts received the same decision?
- Is the review date linked to a restoration test rather than an administrative reminder?
A temporary change review earns its value before the work starts, when the team can still alter the plan without defending sunk effort. By making the changed condition, control owner, field evidence, stop trigger, and restoration test explicit, the operation prevents a workaround from becoming an unexamined permanent risk.
Frequently asked questions
What is a temporary change review?
When should a temporary change be reviewed?
Who should participate in the review?
What makes a stop condition effective?
How do you close a temporary change?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.