Which statement about the authorisation of a standard change is correct?
ITIL 4 Foundation, objective 7. Seven ITIL practices in detail medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Not correct A change advisory board must review and approve each occurrence before it is implemented
Wrong. Routing every occurrence through a board is precisely what the pre-authorised category avoids; a board reviewing repetitive low-risk work adds delay without adding control.
Correct Authorisation is granted in advance to the documented procedure itself, so no separate approval is needed when it is carried out
Correct. The authorisation attaches to the pre-approved procedure, which is why standard changes can be triggered and completed without a per-occurrence decision.
Not correct No risk assessment is ever performed for a standard change
Wrong. Risk was assessed — just once, when the procedure was created and approved. 'Pre-authorised' means the assessment happened earlier, not that it never happened.
Not correct Authorisation is granted after implementation, once the outcome is known
Wrong. Retrospective authorisation is not how standard changes work. Even emergency changes, which are the most compressed, are authorised before implementation by an expedited route.
Why
'Pre-authorised' is the defining property of a standard change: the assessment and the authorisation decision were made once, for the procedure, and every conforming instance inherits them. That is different from saying no assessment happened, and different from a board approving each occurrence.
Where this comes from
- Cited
- ITIL 4 syllabus clause 7
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 7 and space the ones you get wrong.
More questions on this objective
- Which statement best describes what the incident management practice is intended to achieve? machine-checked
- How is an incident defined in ITIL? machine-checked
- Several incidents are open at once and the support team must decide which to work on first. On what basis should the order be decided? machine-checked
- A difficult incident is worked on by pulling several specialists from different teams into the same session at the same time; once it becomes clear who is best placed to continue, the others step away. What is this technique called? machine-checked
- Why does an organisation define a separate procedure for major incidents rather than handling them exactly like all other incidents? machine-checked
- A support team routinely fixes incidents by phone and updates the incident record only with the word 'fixed'. What is the most significant consequence of this? machine-checked