Skip to main content
Category: Audit Process

Nonconformity Tracking

Also known as: Non-Conformance Tracking, Nonconformance Management, Non-Conformance Management, NCR Tracking
Simply put

Nonconformity tracking is the practice of recording, monitoring, and following up on cases where something fails to meet a required standard, specification, or expectation. It helps an organization make sure each identified problem is documented and worked through to resolution rather than being forgotten. Many organizations use dedicated software with workflows and automated reminders to keep this process organized.

Formal definition

Nonconformity tracking is the process of documenting a deviation from a specification, standard, or expectation (often captured in a non-conformance report, or NCR) and managing it through to closure, typically alongside associated corrective actions. In an ISO/IEC 27001 context, this activity supports the ISMS requirements around handling nonconformities and corrective action, which are part of the certifiable clauses (clauses 4 through 10); the specific handling, evidence, and closure expectations depend on the certification body, the defined ISMS scope, and the organization's own procedures. Tracking is frequently operationalized through cloud-based non-conformance management platforms that centralize records, assign workflows, and issue automated reminders so that identified deviations are not overlooked. The term originates in quality management, where a nonconformity is broadly defined as a deviation from a specification, standard, or expectation, and its application to an information security management system reflects that shared conceptual basis rather than a control number or clause that can be asserted here without the applicable standard version at hand.

Why it matters

Nonconformity tracking matters because an identified problem that is not documented and followed through can quietly persist until it undermines the integrity of a management system. Within an ISO/IEC 27001 environment, the handling of nonconformities and associated corrective action sits among the certifiable ISMS requirements found in clauses 4 through 10, so demonstrating that deviations are recorded and driven to closure is part of what a certification body typically expects to see. Without a reliable tracking mechanism, an organization risks losing visibility of open issues, which can weaken both the effectiveness of its ISMS and its ability to evidence corrective action during an assessment.

The practice also carries a broader operational value that predates its information security application. The concept originates in quality management, where a nonconformity is understood as a deviation from a specification, standard, or expectation. Carrying that discipline into an ISMS means treating each deviation as something to be documented, monitored, and resolved rather than left informal or forgotten. This structured follow-through is what turns a one-off observation into a demonstrable improvement.

It is worth noting that the specific evidence, handling, and closure expectations depend on the certification body, the defined ISMS scope, and the organization's own procedures. Tracking nonconformities does not by itself guarantee a conforming management system or freedom from future issues; it provides the record and workflow that make resolution and accountability possible, and its adequacy is judged in context rather than by a single universal rule.

Who it's relevant to

Compliance and GRC Managers
Those responsible for maintaining an ISO/IEC 27001 ISMS rely on nonconformity tracking to demonstrate that identified deviations are documented and driven to closure, supporting the ISMS requirements around handling nonconformities and corrective action found in the certifiable clauses. The specific expectations they must meet depend on the certification body, the ISMS scope, and their own procedures.
Quality and Operations Teams
Because the concept originates in quality management, teams already familiar with non-conformance reports (NCRs) and corrective actions can extend that same discipline into information security. For them, tracking is about ensuring each deviation from a specification, standard, or expectation is recorded and resolved rather than forgotten.
Auditors and Certification Assessors
Assessors evaluating an ISMS typically look for evidence that nonconformities are captured, monitored, and closed with appropriate corrective action. A clear tracking record supports that evaluation, though what constitutes sufficient handling and closure evidence varies by certification body and defined scope.
Security Engineers and Process Owners
Individuals who own controls or processes often use dedicated non-conformance management platforms with workflows and automated reminders to ensure that deviations assigned to them are not overlooked and are worked through to resolution.

Inside Nonconformity Tracking

Nonconformity Record
A documented instance where a requirement is not met, whether against ISO/IEC 27001 ISMS clauses 4 through 10, a selected Annex A reference control, or an organization's own documented policies and procedures. Each record typically captures the nature of the nonconformity, the affected requirement, and the date identified.
Root Cause Analysis
The investigation into why the nonconformity occurred, supporting the corrective action requirements of the ISMS standard. This step distinguishes symptom-level fixes from addressing the underlying cause so recurrence can be evaluated.
Corrective Action Plan
The defined actions taken to control, correct, and address the consequences of a nonconformity, along with actions to eliminate its cause where practicable. In most engagements this includes assigned ownership and target completion dates.
Classification and Severity
Categorization of findings, often distinguishing major from minor nonconformities. The specific classification scheme and its thresholds are typically determined by the certification body or internal audit program rather than fixed universally.
Status and Closure Tracking
Monitoring of each nonconformity from identification through verification of effectiveness and closure, providing an auditable trail that management review and certification audits can reference.
Effectiveness Verification
Confirmation that the corrective action was implemented and achieved its intended result, closing the loop before a nonconformity is formally marked resolved.

Common questions

Answers to the questions practitioners most commonly ask about Nonconformity Tracking.

Is a nonconformity the same thing as a SOC 2 exception?
No, and the terms belong to different frameworks. A nonconformity is an ISO 27001 concept referring to a failure to meet a requirement of the ISMS standard (clauses 4 through 10) or a control selected via the Statement of Applicability, and it is typically raised by a certification body auditor or through internal audit. A SOC 2 exception, by contrast, is a deviation noted by a CPA firm during an attestation examination under SSAE 18, indicating that a control did not operate as described. Because the two arise from a certification audit versus an attestation examination, tracking one does not satisfy the other, and their remediation and reporting expectations differ.
Does closing all nonconformities guarantee that no security incidents will occur?
No. Tracking and closing nonconformities addresses gaps between your ISMS and the requirements or controls in scope; it does not guarantee freedom from breaches. An ISO 27001 certificate covers only the defined scope of the ISMS, and nonconformity tracking demonstrates that identified gaps are being managed rather than that the environment is free of risk. Corrective action aims to reduce the likelihood of recurrence within the covered scope, but residual risk typically remains and is managed through the risk assessment and treatment process.
How should we classify nonconformities when we log them?
In most ISO 27001 programs nonconformities are distinguished by severity, commonly separating major from minor findings, though the exact terminology and thresholds depend on the certification body and your internal procedures. A tracking record typically captures the requirement or Annex A control affected, a description of the gap, the source (internal audit, external audit, or management review), the assigned owner, target dates, and the correction taken versus the corrective action addressing root cause. Classification schemes vary, so align your categories with your certification body's expectations.
What information should a nonconformity tracking record contain to support corrective action?
Depending on your procedures, a record typically includes the identified nonconformity, an analysis of its cause, the immediate correction, the corrective action to prevent recurrence, an owner, planned and actual completion dates, and evidence of effectiveness verification. ISO 27001 emphasizes acting to control and correct the nonconformity and evaluating the need to eliminate its cause so it does not recur. Retaining documented information on the nature of nonconformities and subsequent actions is generally expected, though the exact format is left to the organization.
How are nonconformities typically verified as closed?
Closure generally involves confirming that both the correction and the corrective action have been implemented and, where practicable, that the corrective action has been effective. Verification may be performed through follow-up internal audit, review of evidence by a designated owner, or confirmation at management review, and a certification body will often examine open and closed items at a subsequent audit. Because effectiveness sometimes can only be judged over time, some programs keep an item under monitoring after the initial fix before confirming full closure. Practices vary by organization and certification body.
Can the same nonconformity tracking process serve both an ISO 27001 program and a SOC 2 examination?
A single issue-management workflow can be a practical way to record and remediate control gaps across both efforts, but the frameworks treat findings differently, so the process should preserve that distinction. Mapping between SOC 2 and ISO 27001 is partial, and remediating a nonconformity in your ISMS does not automatically resolve an exception in a SOC 2 report, or vice versa. In most engagements, teams find it useful to tag each item with the applicable framework, criteria, or clause and to apply the verification and documentation expectations relevant to each rather than assuming one closure satisfies both.

Common misconceptions

Nonconformity tracking is exclusive to ISO/IEC 27001 and has no relevance to SOC 2 engagements.
Formal nonconformity and corrective action processes are explicit requirements of the ISO/IEC 27001 ISMS clauses. SOC 2 does not use the term 'nonconformity' in the same way; a SOC 2 examination reports on control design and, for Type II, operating effectiveness over a period, and identified deficiencies or exceptions are described in the CPA firm's report rather than tracked through a standardized ISMS corrective action mechanism. The two frameworks handle findings differently and should not be treated as identical.
Logging a nonconformity and applying an immediate fix is sufficient to close it.
Correcting the immediate issue is only part of the process. In most ISMS engagements the standard expects evaluation of the need to eliminate the cause so the nonconformity does not recur, and verification that the corrective action was effective before closure. A quick fix without root cause consideration and effectiveness verification typically leaves the record open.
A clean nonconformity log guarantees the organization is secure and free from breaches.
Nonconformity tracking attests only to how identified findings against defined requirements were managed within the scope of the ISMS. It does not guarantee freedom from breaches, nor does it cover requirements or systems outside the certified scope. It is a management tool, not an assurance of overall security.

Best practices

Maintain a single, centralized register that captures each nonconformity's source, affected requirement, classification, owner, and status so the trail is auditable during management review and certification audits.
Document root cause analysis for each finding and record the rationale where a cause cannot be practicably eliminated, keeping this distinct from the immediate correction applied.
Assign clear ownership and target dates to every corrective action, and track status from identification through effectiveness verification rather than closing on remediation alone.
Verify and document the effectiveness of corrective actions before formal closure, since implementation without confirmed results typically leaves the nonconformity unresolved.
Align classification thresholds (for example, major versus minor) with the expectations of your certification body or internal audit program, and confirm these rather than assuming a universal scheme.
Feed recurring or systemic nonconformities into risk assessment and management review inputs so patterns inform broader ISMS improvement, not just individual fixes.