A customer receives the wrong product, an internal audit finds that a required check hasn’t taken place or a certification auditor identifies a gap in your management system. Each could be a non-conformity.
Now, you may be able to fix the immediate problem, but that, alone, won’t stop it from happening again. You need to understand what went wrong, address the cause and confirm that your actions have worked.
And that’s the purpose of non-conformity management. It gives you a structured process for recording, controlling, investigating and resolving failures to meet requirements.
ISO QSL helps your organisation take control of its ISO certification. We help businesses identify and address non-conformities, reducing the risk of negative audit findings and recurring operational problems. Here’s what you need to know.
Are you prepared for ISO 9001:2026?
We here to help you review your current quality management system, identify likely transition priorities and prepare for ISO 9001:2026.
About the author
Jodie Turner – Marketing Team Leader
During my time as ISO QSL, I’ve developed extensive knowledge of digital marketing alongside a strong understanding of the ISO standards that help organisations improve.
What counts as a non-conformity?
A non-conformity is the non-fulfilment of a requirement. That requirement might come from an ISO standard, but it could also come from a law or regulation, a customer contract or specification, your own management system or a product, service or process specification.
Non-conformities may come to light through audits, inspections, monitoring, customer complaints, incidents or routine work. However, a complaint or mistake isn’t automatically a non-conformity. You need to compare the evidence against the applicable requirement.
What’s the difference between correction and corrective action?
In ISO terms, correction deals with the non-conformity you’ve already found. Corrective action addresses its cause to prevent it from recurring.
Suppose you send a customer an outdated version of a report. Sending the correct version is a correction. It resolves the immediate issue but doesn’t explain why your team used the wrong file.
But you might then find that outdated templates are still available in a shared folder and there’s no control for replacing them. Removing the old versions and changing the document control process would be corrective action.
How do you manage a non-conformity?
Your exact process should suit your organisation and ISO standard, but it will typically include something along these lines:
#1 Record the non-conformity
Describe the issue in factual terms. Record the relevant requirement, objective evidence, date, process or location and potential consequences.
Avoid vague statements such as ‘the procedure wasn’t followed’. Specify which part of the procedure wasn’t followed and what evidence supports that finding.
#2 Control the immediate problem
Take action to prevent the issue from causing further harm. Depending on the situation, you might stop work, isolate a product, correct a document, withdraw access to a system or contact an affected customer.
You should also deal with the consequences. For example, replacing a defective product won’t address delays the customer has experienced or costs it has incurred.
#3 Determine the cause
Investigate why the non-conformity occurred. Methods such as the five whys or a fishbone diagram may help, but ISO standards don’t require a particular tool.
Don’t stop at ‘human error’. Ask why the system allowed the error to happen. Were instructions unclear? Was training missing? Did the equipment fail? Were responsibilities unclear? Did time pressure lead people to bypass a control?
You should also check whether similar non-conformities exist or could occur elsewhere.
#4 Decide on and implement corrective action
Evaluate whether corrective action is needed. If it is, choose an action that addresses the cause and is proportionate to the effects and associated risk of the non-conformity.
You may need to update a process, improve a control, change responsibilities, provide training or review an external supplier. Assign an owner and completion date so the action doesn’t remain open indefinitely.
Update your assessment of risks and opportunities and make any necessary changes to your management system.
#5 Review effectiveness and close the non-conformity
Completing an action doesn’t always prove that it worked. Review suitable evidence before closing the non-conformity.
You might repeat an inspection, sample later records, conduct a follow-up audit or monitor performance over an appropriate period. Your records should show the nature of the non-conformity, the actions taken and the results.
How do you make non-conformity management effective?
Maintain a controlled register of open findings, responsibilities, deadlines and effectiveness checks. This could be held in a spreadsheet or management system platform, depending on the scale of your organisation.
Review trends rather than treating every finding in isolation. Several minor errors in one process may indicate a wider weakness. Non-conformity rates, recurring causes and overdue corrective actions can provide useful inputs for your Management Review Meeting.
Most importantly, don’t use the process to assign blame. If your employees expect punishment when they report a problem, issues are likely to stay hidden (and getting worse) until they affect a customer or appear during an audit. Focus on evidence, causes and improvements.
At ISO QSL, we help you establish a non-conformity process that works in practice, respond to audit findings and use corrective action to improve your management system. Get in touch with our team to discuss ISO consultancy, training or certification.