Back to Resources

    ISO Nonconformities Explained: What They Are and What to Do Next

    ByNicole Webb·
    Share:
    ISO Nonconformities Explained: What They Are and What to Do Next

    Receiving a nonconformity finding at an ISO audit can feel unsettling, particularly if it is your first time. The word itself sounds serious, and the paperwork that follows can seem daunting. The good news is that a nonconformity is not a sign that your management system has failed. It is a mechanism the standards use to drive genuine improvement. Understanding what it means, and what is expected of you in response, makes the whole process far less stressful.

    This guide explains what nonconformities are, how they are classified, how they differ from other types of audit findings, and what your obligations are once you have received one. The principles apply across the four most widely adopted ISO management system standards: ISO 9001 (quality), ISO 27001 (information security), ISO 14001 (environmental), and ISO 45001 (occupational health and safety). All four share the same underlying framework, known as Annex SL, which is why the approach to nonconformities is consistent whichever standard you are working with.

    What Is a Nonconformity?

    A nonconformity is a finding raised by an auditor when objective evidence shows that a requirement has not been met. That requirement might come from the ISO standard itself, from your organisation's own documented procedures, or from both.

    Think of it like a building inspector checking a property against the approved plans. If a wall has been built in the wrong position, that is a finding. It is not necessarily a reason to demolish the building, but it is something that needs to be formally addressed before sign-off.

    Nonconformities are raised during both internal audits (carried out by your own team or an appointed internal auditor) and external audits (carried out by a certification body such as BSI, Bureau Veritas, or SGS). Either type creates an obligation to respond.

    Major and Minor Nonconformities: What Is the Difference?

    Not all nonconformities carry the same weight. Auditors classify them as either major or minor, and the distinction matters significantly for what happens next.

    A major nonconformity indicates a significant failure. This might be a complete absence of a required process, a systemic breakdown, or a finding that, if left unaddressed, could undermine the integrity of the entire management system. Under ISO 9001, for example, a major nonconformity might be raised if there is no documented process for controlling nonconforming outputs, or if the organisation cannot demonstrate that a management review has taken place. Under ISO 27001, failing to conduct a risk assessment or having no operational controls mapped to identified risks would typically be classed as major.

    A minor nonconformity reflects an isolated lapse or a partial failure of a process that otherwise functions correctly. It is the kind of finding where the intent is clearly there, but execution has fallen short in a specific instance. Examples include a single training record that cannot be located or a documented procedure that has not been reviewed within the required timeframe.

    The practical consequence is significant. A major nonconformity will typically prevent initial certification from being granted, or trigger a follow-up visit at a surveillance audit to verify that the issue has been resolved. Minor nonconformities are usually addressed through documented corrective action within an agreed timeframe, without requiring a return visit.

    A Practical Example: Hartley Precision Engineering

    Hartley Precision Engineering Ltd, a Sheffield-based manufacturer, recently underwent its first ISO 9001 surveillance audit. The auditor raised two findings.

    The first was a minor nonconformity: a calibration record for one piece of inspection equipment was missing from the system. The calibration process existed and was followed for all other equipment, but the documentation for this particular item had not been updated after its last service.

    The second was a major nonconformity: the management review meeting required under Clause 9.3 had not taken place within the previous twelve months. There was no record of management inputs being reviewed, and no outputs documented. Because this is a core requirement of the standard and its absence affects the entire management system's effectiveness, it was classified as major.

    Hartley was required to address both findings, but the major nonconformity required a structured response with evidence of completion before the certification body would confirm continued certification.

    What About Opportunities for Improvement?

    Alongside nonconformities, auditors may also note findings described as observations or opportunities for improvement (OFIs). These are not failures. No corrective action is required, and they carry no formal obligation.

    It is worth taking OFIs seriously, nonetheless. They often reflect the auditor's experience across many organisations and can highlight areas where your system is technically compliant but could be made more effective. Common examples include recommendations to further automate a manual process, or to extend an existing control to a related area of risk.

    The key distinction is this: a nonconformity records that a requirement has not been met. An OFI records that a requirement has been met, but there may be a better way.

    How ISO Standards Treat Nonconformities

    All four of the major management system standards take a broadly consistent approach to nonconformities, rooted in the Plan-Do-Check-Act (PDCA) cycle that underpins the Annex SL framework. Each standard requires you to:

    •        React to the nonconformity and, where applicable, take action to control and correct it

    •        Evaluate the need to eliminate the cause so that it does not recur

    •        Implement any corrective action needed

    •        Review the effectiveness of that action

    •        Update risks and opportunities if necessary

    •        Make changes to the management system where required

    This requirement sits at Clause 10.2 in ISO 9001, ISO 14001, and ISO 45001, and at Clause 10.1 in ISO 27001.

    The specific context of each standard shapes how this plays out in practice. Under ISO 27001, a nonconformity relating to access control might require not only a corrective action plan but also a review of whether the associated risk assessment needs updating. Under ISO 45001, a finding related to hazard identification may also trigger a review of worker consultation processes under Clause 5.4.

    What Happens Next: Your Obligations

    Once a nonconformity has been raised, the ball is in your court. Your certification body will set a timeframe for your response, typically 30 to 90 days depending on the severity and the terms of your certification agreement.

    You will need to:

    •        Acknowledge the finding and confirm that you have received and understood the nonconformity

    •        Identify the root cause, meaning not just what went wrong, but why it went wrong

    •        Define and implement corrective action that addresses the root cause rather than just the symptom

    •        Provide evidence through records that demonstrate the action has been completed effectively

    For a detailed walkthrough of the corrective action process, including root cause analysis tools and how to structure your response, see our Guide to Corrective Actions.

    Working With a Consultant or Certification Body

    If you are managing a nonconformity for the first time, or if the finding is significant, you do not have to navigate it alone. An experienced ISO consultant can help you conduct a thorough root cause analysis and structure a corrective action response that satisfies your certification body's requirements.

    When selecting external support, look for consultants familiar with the expectations of an accredited certification body. In the UK, the United Kingdom Accreditation Service (UKAS) oversees the accreditation of certification bodies. In the US, ANAB and IAS fulfil a similar role. In Ireland, the Irish National Accreditation Board (INAB) provides equivalent oversight. A reputable consultant will be familiar with the expectations of whichever accredited certification body issued your finding.

    The Bottom Line

    A nonconformity is a formal signal that something in your management system needs attention. It is not an indictment of your organisation, and in many cases it reflects a process gap rather than a fundamental failure. The standards are designed to surface these gaps so they can be closed. That is the point of the audit cycle.

    Major nonconformities require swift, structured action and usually need to be closed before your certification can be confirmed or maintained. Minor nonconformities require documented corrective action within the agreed timeframe. OFIs require nothing formally, but are worth considering on their merits.

    Understanding the difference puts you in control of the response, rather than simply reacting to it.

    About The Author

    Nicole Webb is an ISO compliance specialist with extensive experience in ISO management systems, accreditation and internal auditing, providing a strong foundation for writing practical, expert-led articles on ISO topics. She has managed accredited management systems and supported Global compliance teams across ISO 9001, ISO 14001, ISO 45001, ISO 22301, ISO 27001 and ISO 13485, giving her a broad, cross-standard perspective that informs her writing. She now runs ISOLiteBites, an ISO-focused training company delivering both e-learning courses and bespoke training for businesses of all sizes.

    Share:

    Need Help With ISO Certification?

    Get quotes from accredited registrars and ISO experts.