Within change enablement, what is a change authority?
ITIL 4 Foundation, objective 7. Seven ITIL practices in detail medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Not correct The person who implements the change and confirms it worked
Wrong. Implementing and verifying is delivery work. Keeping authorisation distinct from implementation is part of what makes the assessment meaningful.
Not correct A permanent committee that must convene to approve every change in the organisation
Wrong. Centralising all authorisation in one standing committee is a bottleneck ITIL 4 explicitly moves away from; in high-velocity organisations authorisation is often decentralised to peer review.
Correct The person or group that authorises a change
Correct. 'Change authority' names the role of authorising, whoever fills it — an individual, a peer reviewer, or a board — and different change types and models assign it differently.
Not correct The document that records the risk assessment for a proposed change
Wrong. That is an artefact produced during assessment. A change authority is a person or group holding a decision right, not a record.
Why
A change authority is simply whoever holds the right to authorise a given change. It is assigned by the change model that applies, which is why a routine normal change, a high-risk normal change, and an emergency change can each have a different change authority — and why highly automated organisations can push authorisation down to peer review without abandoning control.
Where this comes from
- Cited
- ITIL 4 syllabus clause 7
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 7 and space the ones you get wrong.
More questions on this objective
- Which statement best describes what the incident management practice is intended to achieve? machine-checked
- How is an incident defined in ITIL? machine-checked
- Several incidents are open at once and the support team must decide which to work on first. On what basis should the order be decided? machine-checked
- A difficult incident is worked on by pulling several specialists from different teams into the same session at the same time; once it becomes clear who is best placed to continue, the others step away. What is this technique called? machine-checked
- Why does an organisation define a separate procedure for major incidents rather than handling them exactly like all other incidents? machine-checked
- A support team routinely fixes incidents by phone and updates the incident record only with the word 'fixed'. What is the most significant consequence of this? machine-checked