Skip to main content
Category: Audit Process

Nonconformity

Also known as: Nonconformance, Non-conformity
Simply put

A nonconformity is a failure to meet a specified requirement. In a compliance context, it typically means that something an organization does, or fails to do, does not satisfy the rules of a standard it is being measured against. Identifying nonconformities helps an organization correct problems and improve.

Formal definition

A nonconformity is the non-fulfillment of a specified requirement. In the context of a management system standard, it describes a situation where a product, process, service, or the management system itself fails to meet requirements. The related term 'nonconformance' is sometimes distinguished by practitioners as applying to the results of quality control on products and services (an outcome that is 'not OK'), whereas 'nonconformity' is often used more broadly, including at the system level. The precise classification, severity grading (for example, major versus minor), and treatment of a nonconformity depend on the applicable standard and the auditor or certification body's methodology, and the evidence provided here does not establish a single universal definition across frameworks.

Why it matters

In a management system context, nonconformities are the primary mechanism by which auditors and certification bodies signal that something does not meet a specified requirement. Because a standard is only meaningful if compliance can be tested against it, the identification of nonconformities is central to how an organization demonstrates that its controls, processes, or the management system itself actually satisfy the rules it is being measured against. Rather than being purely negative findings, nonconformities are typically the starting point for correction and improvement.

The way a nonconformity is treated, including whether it is graded as major or minor, depends on the applicable standard and the auditor or certification body's methodology. There is no single universal definition or severity scheme that applies across all frameworks, so the same underlying issue may be handled differently depending on the engagement and the standard in scope. This variability is why practitioners pay close attention to how a certification body classifies findings and what remediation it expects.

Because the term is used broadly, precision matters. Some practitioners distinguish 'nonconformance' (used when quality control on a product or service produces a 'not OK' result) from 'nonconformity' (often used more broadly, including at the management system level). Understanding which sense is intended in a given finding helps an organization respond appropriately.

Who it's relevant to

Compliance and GRC Managers
Compliance managers are usually responsible for responding to nonconformities raised during an assessment. Understanding that classification and severity depend on the applicable standard and the certification body's methodology helps them prioritize remediation and manage the correction and improvement process effectively.
Auditors and Assessors
Auditors identify and document nonconformities as failures to fulfill specified requirements. Because there is no single universal definition or grading scheme across frameworks, they apply the classification and severity approach defined by the applicable standard and their own methodology.
Security Engineers and Process Owners
Engineers and process owners often need to distinguish whether a finding relates to a product or service result that is 'not OK' (sometimes termed nonconformance) or to a broader gap at the process or management system level, so they can direct the appropriate corrective action.
Quality and Management System Leads
Those maintaining a management system rely on nonconformities as inputs to continual improvement. Since a standard is only meaningful when compliance can be tested against it, tracking and resolving nonconformities is how they demonstrate that requirements are met over time.

Inside Nonconformity

Definition
A nonconformity is a failure to fulfill a requirement. In the ISO 27001 context, this typically means a deviation from a requirement of the standard (clauses 4 through 10), the organization's own ISMS policies and procedures, or applicable legal, regulatory, or contractual obligations.
Major nonconformity
Generally understood as a significant failure that indicates the ISMS is not fulfilling one or more requirements, or a systemic breakdown of a process. In most certification engagements, a major nonconformity must be resolved before a certification body will issue or maintain certification, though the precise treatment depends on the certification body.
Minor nonconformity
Typically an isolated or lower-impact lapse that does not represent a systemic failure of the ISMS. In most engagements these can be addressed through a corrective action plan without necessarily blocking certification, subject to the certification body's judgment.
Corrective action linkage
ISO 27001's requirements address how nonconformities are handled: the organization is expected to react to the nonconformity, evaluate the need to eliminate its cause so it does not recur, implement action, and review effectiveness. Nonconformities and the associated corrective actions are generally documented as evidence.
Source of identification
Nonconformities may be raised through internal audits, management review, external certification audits (initial, surveillance, or recertification), or ongoing monitoring. The context in which one is raised influences how it must be handled and by whom.
Root cause consideration
Addressing a nonconformity typically involves determining its underlying cause rather than only correcting the immediate symptom, so that recurrence is prevented where reasonably possible.

Common questions

Answers to the questions practitioners most commonly ask about Nonconformity.

Does a nonconformity apply to SOC 2 engagements the same way it does to ISO 27001?
No. 'Nonconformity' is a term specific to ISO 27001 and other ISO management system standards, referring to a failure to meet a requirement of the standard (clauses 4 through 10) or the organization's own ISMS requirements. SOC 2 engagements use different language: a CPA firm performing the SSAE 18 attestation identifies exceptions or deviations in control operation, which may result in a qualified opinion, rather than raising a 'nonconformity.' The two frameworks are distinct, and applying ISO terminology to a SOC 2 report can create confusion during audits.
Does a single nonconformity mean an organization automatically loses or fails to obtain ISO 27001 certification?
Not necessarily. In most certification schemes, nonconformities are typically categorized by severity, commonly as major or minor, and the outcome depends on the certification body's assessment and the nature of the finding. A major nonconformity generally must be addressed before certification can be granted or maintained, while minor nonconformities are often handled through an agreed corrective action plan. The specific thresholds and handling depend on the accredited certification body and the scope of the ISMS.
How should an organization respond after a nonconformity is raised during an ISO 27001 audit?
The typical response involves the corrective action process described in Clause 10 of ISO 27001. In most cases this includes reacting to the nonconformity to control and correct it, evaluating the need to eliminate its underlying cause so it does not recur (root cause analysis), implementing the necessary actions, and reviewing their effectiveness. Organizations generally document these steps and retain evidence, since the certification body will typically verify closure at a follow-up review or the next audit. Specific timelines and evidence expectations vary by certification body.
What is the difference between a nonconformity and an observation or opportunity for improvement?
A nonconformity is a documented failure to meet a specified requirement and typically requires corrective action. An observation or opportunity for improvement generally flags a potential weakness or a suggestion that does not currently breach a requirement and usually does not mandate formal corrective action. The exact terminology and how findings are classified can differ between certification bodies and individual auditors, so organizations should confirm the definitions used in their particular engagement.
How does the Statement of Applicability relate to nonconformities involving Annex A controls?
The Statement of Applicability records which Annex A reference controls an organization has determined to be applicable, informed by its risk assessment, along with justifications for inclusions and exclusions. A nonconformity can arise if a control the organization declared applicable is not actually implemented or operating as described, or if the SoA itself is incomplete or inconsistent with the risk assessment. Because Annex A was restructured in the 2022 revision, organizations should ensure their SoA references the correct version of the standard when addressing such findings.
How can an organization reduce the likelihood of nonconformities before a certification audit?
Common practices include conducting internal audits and management reviews as required by Clauses 9 and 10, performing a gap assessment against the ISMS requirements, and verifying that documented controls in the Statement of Applicability are actually implemented and evidenced. Many organizations also run a pre-assessment or readiness review with a qualified party. These measures typically help surface gaps early, though they do not guarantee that no nonconformities will be raised, since outcomes depend on the certification body, auditor, and the defined scope of the ISMS.

Common misconceptions

A nonconformity in a SOC 2 examination is the same thing as an ISO 27001 nonconformity.
The term "nonconformity" belongs to the ISO 27001 management system vocabulary. A SOC 2 engagement is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard and instead uses concepts such as exceptions or deviations noted against the applicable Trust Services Criteria. The two frameworks are distinct, and satisfying one does not automatically satisfy the other, so the terminology should not be used interchangeably.
Any nonconformity automatically prevents ISO 27001 certification.
Treatment depends on severity and on the certification body's judgment. A major nonconformity typically must be resolved before certification is issued or maintained, whereas a minor nonconformity can often be managed through a corrective action plan. Outcomes vary by certification body and by the defined scope of the ISMS.
Closing a nonconformity simply means fixing the immediate problem that was observed.
Correcting the immediate issue is only part of the expectation. ISO 27001 generally calls for evaluating and, where appropriate, eliminating the underlying cause so the nonconformity does not recur, and for reviewing whether the action taken was effective.

Best practices

Classify each nonconformity as major or minor based on impact and whether it reflects a systemic issue, and confirm the certification body's classification criteria rather than assuming a fixed rule.
Document each nonconformity, the correction taken, the root cause analysis, and the corrective action, so this record can serve as evidence during surveillance and recertification audits.
Address the underlying cause of the nonconformity, not only the immediate symptom, to reduce the likelihood of recurrence.
Review the effectiveness of corrective actions after implementation and feed the results into management review.
Use internal audits and management review proactively to surface nonconformities before an external certification audit, since the source of identification affects how they must be handled.
Track corrective action commitments against agreed timelines with the certification body, prioritizing any major nonconformity that could block issuance or maintenance of certification.