Skip to main content
Category: Audit Process

Nonconformity and Corrective Action Process

Also known as: Corrective Action Process, Nonconformity Management, ISO 27001 Clause 10.2
Simply put

A nonconformity and corrective action process is the structured way an organization identifies when a required control or process has failed to meet a standard, documents it, and takes steps to fix both the immediate issue and its underlying cause. In ISO 27001, this process is used to keep the information security management system (ISMS) working as intended and to prevent the same problem from happening again. It applies only to the ISMS scope and does not, by itself, guarantee that no security failures will occur.

Formal definition

Under ISO/IEC 27001 Clause 10.2, the nonconformity and corrective action process defines how an organization reacts to a nonconformity by taking action to control and correct it, dealing with its consequences, and evaluating the need to eliminate its root cause so that it does not recur. A nonconformity typically ranges from minor (an isolated lapse) to major, where, according to practitioner guidance such as URM Consulting, a major nonconformity may exist when there is a total absence of a required process or control, a systemic failure in the ISMS, or repeated minor issues indicating a broader breakdown. The process usually involves identifying, documenting, and analyzing the nonconformity, determining and implementing corrective action, reviewing its effectiveness, and retaining documented information as evidence; the specific steps, severity thresholds, and timelines depend on the organization's procedures and the certification body's assessment. This clause forms part of the certifiable ISMS requirements in Clauses 4 through 10, and is distinct from the Annex A reference controls selected via the Statement of Applicability. Note that corrective action addresses the cause of a nonconformity and should not be conflated with correction, which addresses only the immediate detected issue.

Why it matters

In ISO/IEC 27001, an information security management system is only as reliable as the organization's ability to detect when something has gone wrong and to fix it durably. The nonconformity and corrective action process under Clause 10.2 is what turns a discovered failure, whether identified through internal audit, management review, incident handling, or a certification body's assessment, into a documented, tracked, and resolved item rather than a lapse that quietly recurs. Without this discipline, an ISMS can pass an initial certification and then degrade over time as the same weaknesses reappear.

The distinction between correction and corrective action is central to why this process matters. Correction addresses only the immediate detected issue, while corrective action addresses the underlying cause so that the problem does not recur. Treating a symptom without eliminating its root cause is one of the most common reasons a nonconformity is later reopened or escalated. According to practitioner guidance such as URM Consulting, a major nonconformity may exist where there is a total absence of a required process or control, a systemic failure in the ISMS, or repeated minor issues that together indicate a broader breakdown, so failing to resolve small issues properly can compound into a more serious finding.

It is important to understand the boundaries of this process. Clause 10.2 applies only within the defined ISMS scope, and a functioning corrective action process does not by itself guarantee that no security failures will occur. It provides a structured, evidence-based mechanism for responding to and learning from failures, which supports the credibility of the ISMS during surveillance and recertification, but it is not a guarantee of freedom from incidents.

Who it's relevant to

ISMS Managers and Owners
Those responsible for maintaining the ISMS use the nonconformity and corrective action process to track findings from internal audits, management reviews, and certification assessments through to closure. They typically own the procedures that define how nonconformities are documented, how root cause is analyzed, and how the effectiveness of corrective action is reviewed and evidenced.
Internal Auditors
Internal auditors identify and record nonconformities against the ISMS requirements and monitor whether corrective actions genuinely address root causes rather than only correcting immediate symptoms. Their findings feed the Clause 10.2 process and provide the documented information that certification bodies review.
Certification Body Assessors
External assessors raise nonconformities during certification and surveillance visits and evaluate whether the organization's corrective actions are adequate. In most engagements the classification of a finding as minor or major, and the acceptable timeline for resolution, is influenced by the certification body's assessment against Clause 10.2.
GRC and Compliance Professionals
Governance, risk, and compliance staff rely on the corrective action process to demonstrate that the ISMS is functioning and continually improving. They often manage the documented evidence of nonconformities and closures, which supports the credibility of the certificate within its defined scope during audits.
Security Engineers and Control Owners
Individuals who operate specific controls may be assigned corrective actions when a control fails to meet a requirement. They implement both the immediate correction and, where relevant, the changes needed to eliminate the underlying cause, then provide evidence that the action was effective.

Inside Nonconformity and Corrective Action Process

Nonconformity Identification
The recognition that a requirement of the ISMS, whether from ISO/IEC 27001 clauses 4 through 10, an applicable Annex A control selected via the Statement of Applicability, or the organization's own documented policies, has not been met. Nonconformities may surface through internal audits, external certification audits, management review, monitoring activities, or incident analysis.
Reaction to the Nonconformity
The immediate steps taken to control and correct the nonconformity and to deal with its consequences. This addresses the specific instance that occurred, distinct from preventing recurrence, and typically includes containment or correction of the affected situation.
Root Cause Evaluation
An assessment of the need to eliminate the cause(s) of the nonconformity so that it does not recur or occur elsewhere. This involves reviewing the nonconformity, determining its causes, and determining whether similar nonconformities exist or could potentially occur.
Corrective Action Implementation
The implementation of any action needed to address the identified root cause, followed by a review of the effectiveness of that action. Corrective actions are expected to be appropriate to the effects of the nonconformities encountered.
Documented Information
Retained evidence of the nature of the nonconformities, any subsequent actions taken, and the results of corrective actions. In most ISO 27001 engagements this documentation supports the certification body's evaluation during audits and management review.
Change to the ISMS
Where warranted, updates to the management system itself arising from corrective action, such as revisions to risk assessments, controls, or procedures, reflecting continual improvement of the ISMS.

Common questions

Answers to the questions practitioners most commonly ask about Nonconformity and Corrective Action Process.

Does a nonconformity found during an ISO 27001 audit mean the organization fails certification?
Not necessarily. Nonconformities are typically classified by the certification body as major or minor, and the outcome depends on their nature and how they are addressed. In most engagements, minor nonconformities can be managed through an agreed corrective action plan without preventing certification, while major nonconformities generally must be resolved or have credible corrective action underway before a certificate is issued or maintained. The specific thresholds and handling depend on the certification body and the audit stage.
Is the nonconformity and corrective action process the same as a SOC 2 exception or finding?
No. Nonconformity and corrective action is a defined requirement of the ISO 27001 ISMS (found within clauses 4 through 10) and relates to conformity with the management system standard. A SOC 2 report, by contrast, is an attestation examination performed by a licensed CPA firm under SSAE 18, and its deviations are typically described as exceptions or noted deficiencies in the controls tested over the covered period. The two arise from different frameworks, and the presence of one does not automatically map to the other.
What information should a nonconformity record typically capture?
In most implementations, a nonconformity record captures a description of what occurred, the requirement or control affected, the evidence observed, an assessment of the consequences, and the correction taken to address the immediate issue. It also commonly documents the analysis of underlying cause, the corrective action selected, responsible owners, target dates, and the evidence used to verify effectiveness. The exact format varies by organization and is not prescribed to a fixed template.
How does correction differ from corrective action in practice?
Correction generally refers to the immediate step taken to contain or fix the specific instance, while corrective action addresses the underlying cause to reduce the likelihood of recurrence. In practice, an organization may apply an immediate correction and then, depending on the significance of the nonconformity, evaluate whether root cause analysis and a broader corrective action are warranted. Not every nonconformity requires the same depth of response, and the level of effort typically scales with risk and impact.
How can an organization demonstrate that a corrective action was effective?
Effectiveness is typically demonstrated through retained evidence showing that the action was implemented and that the underlying cause no longer produces the nonconformity. This may include follow-up review results, updated records, or subsequent internal audit or monitoring outcomes over a period sufficient to observe whether the issue recurs. The evidence expected depends on the nature of the nonconformity and the practices agreed with the certification body or internal auditors.
How does the corrective action process connect to other ISMS activities?
The process is commonly linked to internal audit, management review, risk assessment, and monitoring activities, since nonconformities can surface through any of these. Findings often feed into management review discussions and may inform updates to risk treatment or the Statement of Applicability where relevant. The degree of integration varies by organization, but maintaining these connections helps show that identified issues are tracked through to resolution.

Common misconceptions

A nonconformity raised during an ISO 27001 audit automatically means certification will be denied.
The outcome depends on the certification body and the nature and severity of the finding. Nonconformities are commonly categorized by severity, and organizations are typically given the opportunity to demonstrate correction and corrective action within a defined timeframe before a certification decision is finalized. Practices vary by certification body and scope.
Correction and corrective action are the same thing.
Correction addresses the specific nonconformity that occurred (fixing the immediate issue), while corrective action addresses the underlying root cause to prevent recurrence. Both are typically expected, but they serve different purposes within the process.
The nonconformity and corrective action process only applies to Annex A controls.
It applies to any failure to meet an ISMS requirement, which includes the certifiable requirements in clauses 4 through 10, the Annex A reference controls selected in the Statement of Applicability, and the organization's own documented policies and objectives. This process is a clause-level requirement of the management system, not limited to control failures.

Best practices

Maintain a defined process for logging nonconformities that captures the nature of the finding, its source, and the requirement that was not met, so evidence is available for internal audits, management review, and certification body assessment.
Distinguish clearly between immediate correction and root-cause corrective action, documenting both separately so the record shows how the specific instance was handled and how recurrence is being prevented.
Conduct a structured root cause evaluation and assess whether similar nonconformities exist or could occur elsewhere in the ISMS, rather than treating each finding in isolation.
Ensure corrective actions are proportionate to the effects of the nonconformity, avoiding both under-response and disproportionate effort that does not add value.
Review the effectiveness of corrective actions after implementation and update risk assessments, controls, or procedures where the finding indicates a needed change to the ISMS.
Retain documented information on nonconformities and their outcomes, and align remediation timeframes with expectations set by your certification body, recognizing that specific timelines vary by body and finding severity.