Back to Resources
    Articles
    ISO 9001

    The Most Common Nonconformities in ISO 9001:2015

    ByAssent Risk Management·
    Share:
    Audit checklists and charts illustrating analysis of ISO 9001 nonconformances

    Ahead of the publication of ISO 9001:2026, we look back at 11 years of nonconformity data to discover which clauses gave rise to the most audit findings in the world’s leading quality management standard.

    Assent Risk Management is a global consultancy firm with more than 20 years of experience in the ISO management system field. As part of its efforts to continually improve services, benchmark clients’ quality management systems and identify trends, Assent analysed nonconformity data from ISO 9001 audits. Here are its insights.

    Which ISO 9001:2015 Clauses Generated the Most Audit Findings?

    At the top level, Clause 7, Support, was responsible for the greatest proportion of findings, accounting for 26.8% of the dataset.

    It was followed by Clause 8, Operation, at 20.7% and Clause 6, Planning, at 13.3%.

    Perhaps the most striking figure is that Clauses 7 and 8 together accounted for 47.5% of all findings, nearly half.

    This is significant because these are the parts of ISO 9001 concerned substantially with supporting and operating the quality management system (QMS). Clause 7 encompasses resources, competence, awareness, communication and documented information, while Clause 8 addresses the planning and control of operational processes, suppliers, production and service provision, and nonconforming outputs.

    The data therefore suggests that one of the greatest challenges is not necessarily designing a management system, but maintaining effective control of it during everyday business operations.

    Risks and Opportunities: Clause 6.1

    Looking below the headline clauses reveals an even more interesting result.

    Clause 6.1, Actions to Address Risks and Opportunities, was the most frequently recorded individual requirement, accounting for approximately 5.7% of findings.

    Risk-based thinking was an important new feature of ISO 9001:2015, but the findings suggest that it continued to cause difficulties throughout the standard’s 11-year lifecycle.

    One potential issue is the difference between identifying risks and actually integrating risk-based thinking into the management system.

    A lack of action to address opportunities also featured heavily and increased toward the end of the standard’s lifecycle, as auditors and clients looked toward changes in the ISO 9001:2026 DIS and FDIS.

    Documented Information: Clauses 7.5 and 7.5.3

    Documentation is a significant source of audit findings across most management system standards in Assent’s data.

    Clause 7.5, Documented Information, accounted for approximately 5.0% of findings, while the more specific Clause 7.5.3, Control of Documented Information, accounted for approximately 3.9%.

    These figures should not simply be added together because findings have been categorised against requirements at different levels. Nevertheless, the prominence of both requirements demonstrates the continuing importance of documented information.

    ISO 9001:2015 gave organisations considerable flexibility over their documentation, but the information required by the QMS still needs appropriate controls around availability, protection, changes, retention and use.

    Procedures, forms and records can exist but still generate audit findings if they are outdated, incomplete, inconsistently maintained or do not reflect what actually happens within the organisation.

    Less prescriptive documentation does not mean less control.

    Quality Objectives: Clause 6.2

    Clause 6.2, Quality Objectives and Planning to Achieve Them, accounted for approximately 4.8% of findings.

    This is another requirement that can appear relatively straightforward but becomes more challenging when implemented in practice.

    It is relatively easy to establish an objective such as “improve customer satisfaction,” but harder to show how improvement will be measured, what target is being sought, who is responsible, what resources are required, when it will be achieved and how the results will be evaluated.

    The standard also requires objectives to be set “at relevant functions, levels and processes,” and many audit findings related to this requirement.

    Operational Planning and Control: Clause 8.1

    Clause 8.1, Operational Planning and Control, accounted for approximately 4.6% of findings, making it another of the most frequently cited individual requirements.

    This is particularly important because it takes us beyond the administrative elements of a management system and into the actual delivery of products and services.

    It can be difficult to relate this requirement to the day-to-day operations of the management system.

    Competence: Clause 7.2

    Clause 7.2, Competence, accounted for approximately 3.8% of findings.

    This highlights an important distinction between training and competence.

    Evidence that an employee has been trained does not necessarily demonstrate that they are competent to undertake the work assigned to them.

    Depending on the role, evidence could come from qualifications, experience, observation, supervision, testing or evaluation of performance rather than training records alone.

    Assent saw a particular increase in findings here, driven by external certification bodies’ emphasis on this clause.

    Control of External Providers: Clause 8.4

    Clause 8.4, Control of Externally Provided Processes, Products and Services, accounted for approximately 3.6% of findings.

    This is increasingly relevant as organisations rely on complex supply chains and outsource activities that were once undertaken internally.

    Using an “approved supplier list” is a common mechanism, but it is not necessarily conformant with the standard unless it is supported by appropriate processes, policies and procedures for monitoring and improvement.

    Most importantly, outsourcing an activity does not outsource responsibility for conformity.

    Context and Interested Parties

    Clause 4.2, Understanding the Needs and Expectations of Interested Parties, accounted for approximately 3.8% of findings, while Clause 4.1, Understanding the Organisation and Its Context, accounted for approximately 3.5%.

    One explanation may be that organisations treat these as implementation exercises rather than continuing management activities.

    A context analysis or interested-party register might be created when ISO 9001 is implemented and then reviewed periodically without substantially changing.

    But organisations do change. Customers change, technology develops, competitors emerge, legislation changes, supply chains evolve, and stakeholder expectations shift.

    The 2024 Climate Change Amendment, which requires organisations to consider whether climate change is a relevant issue, also drove an increase in findings from 2024 onward.

    The Most Common Findings Are Not Necessarily the Most Serious

    Across the dataset, approximately 73.0% of records were observations, 22.6% were minor nonconformities and 4.4% were major nonconformities.

    When Assent looked specifically at major nonconformities, the ranking changed.

    Clause 8, Operation, generated the greatest number of major nonconformities, followed by Clause 9, Performance Evaluation, and Clause 7, Support.

    So while Clause 7 generated the most findings overall, Clause 8 generated the greatest number of major nonconformities.

    A high number of observations might indicate an area in which organisations commonly have opportunities to strengthen their systems, but a concentration of major nonconformities potentially points toward requirements where failures can be more fundamental.

    A Note on the Data

    This analysis covers more than 450 audits of ISO 9001:2015 management systems and more than 2,400 individual findings.

    All Assent auditors demonstrate compliance with the Clemark competence scheme, which requires, at minimum, a lead auditor qualification and demonstrable knowledge or experience of ISO 9001.

    The data is used for benchmarking and improvement but should not necessarily be read as an indication of global trends.

    Share:

    Need Help With ISO Certification?

    Get quotes from accredited registrars and ISO experts.