Nonconformity (NC)

A nonconformity is the non-fulfilment of a requirement: from a standard, from your own policies, from contracts or from legislation. Audits distinguish major from minor nonconformities. The classification determines how quickly you have to respond and whether a certificate is granted or maintained.

ISO 27001Last reviewed:

What makes a finding a nonconformity

Two things have to be present: a requirement that applies, and evidence that it is not met. The requirement can come from the standard, from an internal policy, from a customer contract or from legislation. The second element is the one that decides arguments: without concrete evidence, a finding is an opinion.

Hence the three-part shape of any defensible finding: the requirement breached, the situation observed, and the conclusion drawn from it. Write findings that way and you avoid the most common dispute in an audit, which is not about how to fix something but about whether anything was found at all.

Major and minor

AttributeMajor nonconformityMinor nonconformity
Characterthe requirement is not implemented, or the system fails systematically at this pointan individual case or partial aspect; the system works in principle
Typical triggersa required process is entirely absent, a core requirement is unmet, or several similar minors reveal a patterna record is missing, or a rule was not followed in one case examined
Effect in a certification auditthe certification decision is deferred until correction and root-cause remediation are evidenced; for an existing certificate, suspension is in prospectremediation with an action plan; certification is as a rule not blocked
Evidence expectedoften proof of actual implementation, sometimes with a follow-up auditusually evidenced at the next surveillance audit

The deadlines for response, correction and evidence are set by the certification body within its own procedure. They differ between bodies and by classification. Ask yours rather than planning against assumed figures.

Observations and opportunities for improvement

Not every remark is a nonconformity. An observation describes a situation that is still conforming but could develop towards a nonconformity. An opportunity for improvement is a suggestion with no normative basis.

Neither creates an obligation to act. Neither should be discarded either: recurring observations are the most common precursor to a later major, and the follow-up audit will ask what became of them.

The terms in German and English

Audits often run bilingually, and a German counterparty's own reports and internal terminology use different words from the ones an international certification body's English report does. The mapping is unambiguous:

GermanEnglishCreates an obligation to act
Abweichung, Nichtkonformitätnonconformityyes
Hauptabweichung, schwerwiegende Abweichungmajor nonconformityyes, with root-cause analysis and evidence of effectiveness
Nebenabweichung, geringfügige Abweichungminor nonconformityyes, through a corrective action plan
Beobachtung, Hinweisobservationno
Verbesserungspotenzial, Empfehlungopportunity for improvementno
Korrekturcorrectionimmediate removal of the specific situation
Korrekturmaßnahmecorrective actionremoval of the cause

The last two rows are the ones most often confused. A correction fixes the individual case; a corrective action fixes its cause. Anyone who only corrects closes the nonconformity on paper and meets it again at the next audit.

What follows a finding

The sequence is the same regardless of classification; only the deadline and the depth of evidence differ. Immediate correction of the specific effect, analysis of the cause, definition of a corrective action, implementation, and then a check that the cause has actually been removed.

That last step is the one most often skipped, and it is the only one that evidences that the nonconformity will not recur. It is also the step certification bodies have learned to look for, precisely because it is the one organisations under time pressure quietly drop.

Disputing a classification

Challenging a classification is legitimate and should be argued on the merits. It turns on one of three things: the requirement, the facts, or the assessment of whether a failure is systematic. A challenge has the best prospects where the auditor infers a systemic failure from a single case that the sample does not support. It has no prospects at all where the argument is that the requirement is impractical.

Raise it through the certification body's complaints and appeals procedure rather than in the closing meeting, where nobody has the authority to change a classification anyway.

When no nonconformities appear

An internal audit with no findings at all is rarely a good sign. Usually it means the audit was superficial, that documents were examined instead of operating practice, or that findings were negotiated away beforehand. Certification bodies read it that way too: a clean internal audit report invites more questions than it answers.

What becomes of a nonconformity in Rizzqo

A nonconformity is closed only once its cause is removed, and that is exactly where many action plans quietly stall. In Rizzqo a nonconformity is anchored on the object where it was found: on the requirement left open on a particular system, site or provider. It is therefore a named finding with an owner, not a line in an audit tracker.

Its effect shows through two routes. The requirement stays open until it is closed with a reason and evidence, and the computation is strict: an answer marked fulfilled but not finalised still counts as a gap. In parallel the remediation can be carried as a task whose planned risk reduction only takes effect on completion. The difference between promised and done therefore sits in the numbers.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework