Information Security Policy Suite

Change Management Policy

Glaxtons Consulting Limited. This policy ensures that changes to the services the Company provides, to its IT systems, and to the locations where Company or client data is stored or processed, are planned, assessed and communicated in a controlled manner.

Ref GCL-CMP-01Version 6.0Effective May 2026

Document control

Document reference
GCL-CMP-01
Classification
Confidential, internal and authorised third parties
Policy owner
Operations Director
Approved by
The Board of Glaxtons Consulting Limited
Effective date
May 2026
Next scheduled review
May 2027
Applies to
Glaxtons Consulting Limited, 3 More London Place, London SE1 2RE

1. Purpose

This policy ensures that changes to the services the Company provides, to its IT systems, and to the locations where Company or client data is stored or processed, are planned, assessed and communicated in a controlled manner.

2. Scope

This policy applies to material changes to Company services, IT systems and data processing locations.

3. Definitions

In this policy, "Company" means Glaxtons Consulting Limited, "Personnel" means employees, workers, contractors, consultants and temporary staff of the Company, and "client" means any current or prospective client, customer or partner of the Company.

4. Policy

4.1 Changes to services

Material planned changes to the services provided to a client are recorded and assessed for their impact on that client. Where a change is expected to affect a client within the following quarter, the client's designated contact is notified with reasonable advance notice appropriate to the nature of the change.

4.2 IT changes affecting data

Planned changes to IT systems that affect the storage, processing or security of Company or client data are subject to a documented change request, including a risk and data protection impact assessment, testing before deployment, a rollback plan, and approval by the Operations Director or the IT lead before implementation. Emergency changes follow an expedited process, with retrospective approval and review within five working days.

4.3 Changes to processing sites

Planned changes to the sites, facilities or cloud regions where Company or client data is stored or processed are assessed in advance for their effect on data location, applicable transfer mechanisms under the Data Protection and Compliance Policy, and physical and environmental security, and are communicated to affected clients ahead of implementation.

4.4 Change log

All changes falling within the scope of this policy are recorded in a central change log, including the nature of the change, its approval, the outcome of testing, and its implementation date, and are reviewed as part of the quarterly risk register review.

5. Alignment with client due diligence requests

This policy addresses the following reference points commonly raised in client and prospective client vendor due diligence and security assessments: V.RA-39, V.RA-40, V.RA-41. Where a client raises a due diligence question falling within this policy's scope, the relevant section of this policy may be used as the basis for the Company's response, subject to review by the Operations Director.

6. Roles and responsibilities

  • The Operations Director approves in-scope changes and reviews the change log quarterly.
  • The IT function carries out technical implementation, testing and rollback where required.
  • Client-facing leads are responsible for communicating relevant changes to affected clients.

7. Non-compliance and exceptions

Breach of this policy may result in disciplinary action up to and including dismissal, and, in the case of a contractor, consultant or supplier, termination of the relevant engagement or contract. Any exception to this policy must be requested in writing, is subject to a documented risk assessment, and requires the approval of the Operations Director before it takes effect.

9. Version history

VersionDateSummary of changeAuthor
6.0May 2026Scheduled annual review, reissued and approved by the Board.Legal Department

Glaxtons Consulting Limited, 3 More London Place, London SE1 2RE. This document is issued under the Company's information security policy suite and is reviewed at least annually. Printed copies are uncontrolled. Published on this page 6 October 2026, from the 6.0 issue.

Due diligence questions on this policy

Section 5 lists the vendor due diligence reference points this policy answers. For anything a questionnaire needs that the text does not cover, contact the policy owner through info@glaxtons.co.uk or 020 3668 5488.

Glaxtons, 3 More London Place, London SE1 2RE

Professional Bid Writing Services UK. 93% Success Rate.

Expert bid consultancy and tender writing for government, NHS and CCS frameworks. £500M+ contracts won. Same-day response. 24/7 urgent support.

Get a Free Quote. Same Day Response. ☎ 020 3668 5488
✓ 93% Success Rate ✓ £500M+ Won ✓ 500+ Tenders ✓ 2-Hour Response

Recent Wins

✓ Won £45M NHS FM contract for healthcare provider

✓ Secured £12M MoD framework for defence SME

✓ Won £8M G-Cloud lot for SaaS company