Morgan Compliance Group

How Should a Business Respond to an ISO Nonconformity?

An ISO nonconformity should be addressed through a structured corrective action process: contain the immediate issue, identify the genuine root cause rather than just the symptom, implement a corrective action, and check afterwards that the action actually worked. This should be documented, since certification bodies expect to see evidence of the full process, not just that the issue was noticed.

Book a Free Consultation

Reviewed by Daniel Morgan, TechIOSH - Last reviewed 2026-09-24

A common and costly mistake is fixing the immediate symptom without identifying why it happened. This often means the same nonconformity, or a close variant of it, recurs at the next audit - which certification bodies specifically look for as a sign of an ineffective corrective action process.

Root cause analysis does not need to be complex for straightforward issues, but it should go beyond the first obvious explanation. A missed inspection, for example, might genuinely be caused by a training gap, a resourcing issue, an unclear responsibility, or a scheduling system failure - and the correct action differs depending on which of these is the real cause.

Certification bodies generally expect corrective actions to be completed within an agreed timescale, and the severity of the original finding affects how quickly. Major nonconformities can affect certification status directly if not resolved appropriately within the required window.

Documentation of the process itself matters as much as the fix. An auditor reviewing a closed nonconformity expects to see the original finding, the root cause identified, the action taken, who was responsible, and evidence that the action was checked for effectiveness afterwards - not just a note saying the issue was resolved.

Recurring minor nonconformities, even individually small, can be treated more seriously at review if they suggest a systemic weakness rather than isolated one-off lapses.

Frequently asked questions

What is the difference between a minor and major nonconformity?

A minor nonconformity is usually an isolated lapse that does not affect the overall system’s ability to meet requirements. A major nonconformity indicates a more significant failure or a systemic issue.

Does every nonconformity require a full investigation?

The depth of investigation should be proportionate to the risk and significance of the issue, but every nonconformity should be documented and have some form of corrective action recorded.

Can unresolved nonconformities affect future certification?

Yes. Unresolved major nonconformities, or repeated minor ones, can affect certification decisions at surveillance or recertification audits.

How is root cause analysis actually carried out?

Methods range from a simple structured “five whys” approach for straightforward issues to more formal techniques for complex or recurring problems, but the goal is always to identify the underlying cause rather than the immediate symptom.

What evidence should be kept after closing a nonconformity?

The original finding, the identified root cause, the corrective action taken, who was responsible, the completion date, and evidence that the action was later checked for effectiveness.

Can a nonconformity be closed before the corrective action is fully implemented?

Generally no. Certification bodies expect evidence that the action has been implemented and, where relevant, verified as effective before considering the nonconformity closed.

Related

How we can help

Explore Compliance Audits for practical support.

Need ongoing advice? See Monthly Safety Support.

Not Sure Where to Start?

Book a free consultation and explain what your business is trying to achieve. Morgan Compliance Group will help identify the most practical next step.

Book a Free Consultation