IT CHANGE RECORD Purpose: Link an approved request to actual state and verified service behavior. Complete before implementation, then record observations and closure. Scale review to the risk. Keep credentials and unnecessary personal data out of it. REQUEST Reference / requester / business owner / date: [ ] Problem and intended result: [ ] Exact systems, configuration items and scope exclusions: [ ] Starting state / baseline / dated evidence location: [ ] Dependencies and security impact: [ ] Implementer / approver / verifier / affected contacts: [ ] PLAN Steps and relevant procedure/version references: [ ] Test environment / test result / differences from production: [ ] Approved window / communication / approval reference: [ ] Required access and recovery prerequisites verified: [ ] VERIFICATION (repeat for each check) Authorized test identity or system / action: [ ] Expected result (including denied access where relevant): [ ] Actual result / time / verifier / evidence: [ ] Dependent service check and result: [ ] ROLLBACK OR FORWARD RECOVERY Stop trigger and decision owner: [ ] Recovery method / expected time / tested prerequisites: [ ] Irreversible steps or side effects: [ ] Observed recovery result, if used: [ ] IMPLEMENTATION AND CLOSURE Actual steps, changes, deviations and timestamps: [ ] Final system state / evidence / comparison with approval: [ ] Outcome: successful / rolled back / incomplete [choose and explain] Runbooks, baselines, monitoring or access records updated: [ ] Outstanding issue / owner / due date: [ ] Acceptance / verifier / date: [ ] Emergency change authority and retrospective review, if applicable: [ ] Source context: NIST SP 800-128 (2011, updated 2019) linked in the guide. This original small-team record is not a compliance certification. A completed ticket without observed verification leaves the control loop unfinished. Yenra | Updated September 9, 2026 Guide: https://yenra.com/closed-loop-change-management/