ISO Nonconformity: How to Manage and Close Findings

By July 25th, 2026ISO Audit And Certificate7 min read

An ISO nonconformity is any failure to meet a requirement specified by an ISO management system standard or by the organisation’s own documented processes. For businesses in the GCC pursuing or maintaining ISO certification – whether ISO 9001:2022 (quality), ISO 27001:2022 (information security), ISO 45001 (occupational health and safety) or ISO 14001 (environmental) – knowing how to identify, manage and close nonconformities is essential to certification success.

This guide covers the complete nonconformity management lifecycle: classification, root cause analysis, corrective action and prevention of recurrence.

What Is a Nonconformity in ISO?

Under ISO management system standards, a nonconformity is defined as the non-fulfilment of a requirement. The requirement may come from the standard itself (e.g. a clause in ISO 9001), a regulatory obligation or the organisation’s own quality manual or procedures. Nonconformities are identified during internal audits, external certification audits, management reviews or daily operations.

Major vs Minor Nonconformity

ISO auditors classify nonconformities into categories that determine the urgency and depth of the required response.

CategoryDefinitionImpact on CertificationExamples
Major NonconformityA significant failure that affects the ability of the management system to achieve intended results. This includes systemic issues or the complete absence of a required process.Certification cannot be granted or must be suspended until corrective action is verified.No internal audit programme in place; no documented scope of the management system; no procedure for corrective actions.
Minor NonconformityAn isolated lapse that does not affect the overall effectiveness of the system. Usually a one-off failure to follow a procedure.Certification can proceed, but a corrective action plan must be submitted within an agreed timeframe.A single training record missing; one calibration certificate overdue; a minor documentation error.
Observation / Opportunity for Improvement (OFI)A finding that is not a nonconformity but identifies a potential weakness or area that could be improved.No direct impact. No formal corrective action required.Inefficient document control workflow; suggestion to strengthen monitoring frequency.

Root Cause Analysis

Before you can close a nonconformity, you must understand its root cause. Surface-level fixes – correcting the immediate error without addressing the underlying cause – lead to recurring findings in subsequent audits. Three widely used root cause analysis techniques are:

TechniqueBest ForHow It Works
5 WhysSimple, linear issuesAsk “Why?” five times, tracing the causal chain from the symptom to the root cause. Example: training record missing → why? no logging system → why? budget not allocated → root cause.
Fishbone (Ishikawa) DiagramComplex issues with multiple contributing factorsBrainstorm causes across categories: People, Process, Equipment, Materials, Environment, Measurement. Visual map of all potential causes.
Fault Tree AnalysisSafety or critical system failuresTop-down deductive analysis combining events using logic gates (AND, OR) to identify the combination of failures leading to the nonconformity.

Corrective Action Process (CAPA)

The corrective and preventive action (CAPA) process is the structured approach ISO requires for addressing nonconformities. The steps are:

  • Identify and document – record the nonconformity in the corrective action register with description, date, source and classification.
  • Contain the immediate impact – take interim measures to stop the issue from affecting customers, products or services (e.g. quarantine nonconforming product).
  • Determine root cause – apply one of the analysis techniques above.
  • Plan corrective action – define what will be done, who is responsible and the target completion date.
  • Implement and verify – execute the action and verify its effectiveness through testing, review or re-audit.
  • Close the finding – update the register, retain records and report closure to management.

Timeline for Closing Findings

ISO certification bodies and internal audit procedures typically require nonconformities to be closed within specific timelines:

Finding TypeTypical Closure TimelineNotes
Major Nonconformity30–90 daysMay require an additional site visit to verify closure before certification can be granted.
Minor Nonconformity90 days to next surveillance auditCorrective action plan must be submitted within 30 days. Evidence of implementation reviewed at next audit.
Observation / OFINo formal deadlineRecommended to address before the next audit to demonstrate continual improvement.

GCC businesses should note that some local accreditation bodies may impose shorter timelines. Always check requirements with your certification body.

Common Nonconformities by ISO Standard

Certain nonconformities appear frequently across GCC organisations. Awareness of these common findings helps you focus your internal audit programme:

  • ISO 9001:2022 (Quality) – Documented information not controlled (Clause 7.5.3); monitoring and measurement resources not calibrated (Clause 7.1.5); customer complaint handling process ineffective (Clause 8.2.1).
  • ISO 27001:2022 (Information Security) – Risk assessment not updated (Clause 6.1.3); supplier security not managed (Clause 5.19); awareness training records incomplete (Clause 6.3).
  • ISO 45001 (OH&S) – Hazard identification not comprehensive (Clause 6.1.2.1); emergency drills not conducted (Clause 8.2); worker consultation not evidenced (Clause 5.4).
  • ISO 14001 (Environmental) – Compliance obligations not evaluated (Clause 6.1.3); waste management records incomplete (Clause 8.1); environmental objectives not monitored (Clause 6.2.2).

Preventing Recurrence

The ultimate goal of nonconformity management is preventing recurrence. Beyond individual corrective actions, consider systemic improvements:

  • Trend analysis – review the corrective action register quarterly to identify patterns. If the same type of finding appears repeatedly, the root cause is systemic.
  • Process redesign – when procedures are consistently bypassed, redesign them to reflect actual workflow rather than enforcing compliance through audits.
  • Competence building – invest in auditor training and staff awareness to embed a quality-first culture.
  • Technology enablement – use compliance management software to automate document control, monitoring and corrective action tracking.

Frequently Asked Questions

What is the difference between a nonconformity and a finding?

A finding is a broad term that includes any conclusion from an audit. Nonconformities are a subset of findings that represent a failure to meet a requirement. Other findings include observations, opportunities for improvement and positive findings.

Can I get ISO certification with open nonconformities?

No. Major nonconformities must be closed before certification is granted. Minor nonconformities must have an accepted corrective action plan in place. The certification body will not issue the certificate until conditions are met.

How many nonconformities are acceptable in an ISO audit?

There is no fixed number. What matters is the severity and systemic nature. A single major nonconformity blocks certification. Multiple minor nonconformities in the same area indicate a systemic weakness that an auditor may elevate to a major finding.

Who is responsible for closing nonconformities?

The process owner is responsible for implementing the corrective action. The quality or compliance manager is typically responsible for tracking, verifying and reporting closure to the management review meeting.

What records must be kept for nonconformity management?

ISO standards require documented evidence of: the nature of the nonconformity, the corrective actions taken, the results of any corrective action, and the review of effectiveness. These are typically maintained in a corrective action register.

How can BitrixMe help with ISO nonconformity management?

BitrixMe provides ISO consultancy, internal audit services and corrective action facilitation across the GCC. Our team of lead auditors helps you close findings efficiently and prepare for certification or surveillance audits with confidence.

Need urgent support? Message us on WhatsApp.