Skip to main content
Category: Issue and Incident Management

Nonconformity

Also known as: Nonconformance, Non-conformity, Non-conformance
Simply put

A nonconformity is a failure to meet a specified requirement, such as a product, service, or process not matching its stated specifications. In quality management contexts, it signals that something did not turn out as required. The term is sometimes used interchangeably with 'nonconformance,' though some practitioners draw a distinction between the two.

Formal definition

In management-system contexts, a nonconformity is the failure to meet a specified requirement applicable to products, processes, services, or the management system itself. Under ISO 9001, nonconformity denotes a failure to fulfill specified requirements and is commonly classified by severity (for example, major and minor), though the precise classification criteria depend on the applicable standard and audit context. Some practitioners reserve 'nonconformance' for the result of quality-control activity on products and services (an outcome that is 'not OK'), while using 'nonconformity' more broadly; usage varies and the two terms are frequently treated as synonyms. This entry does not cover corrective-action procedures, remediation workflows, or the specific clause references and classification thresholds of individual standards.

Why it matters

Nonconformity is a foundational concept in quality and compliance management because it provides a defined, auditable way to record when a product, service, process, or the management system itself fails to meet a specified requirement. Without a consistent notion of what constitutes a nonconformity, organizations struggle to demonstrate that they have identified where reality diverges from requirements, which undermines the credibility of both internal quality control and external certification audits.

The distinction matters in practice because how a nonconformity is classified, commonly as major or minor under standards such as ISO 9001, can affect the significance attached to a finding and the response it prompts, though the precise classification criteria depend on the applicable standard and audit context. Treating a systemic failure as an isolated defect, or vice versa, can distort an organization's understanding of where its requirements are not being met.

Because the terms 'nonconformity' and 'nonconformance' are frequently treated as synonyms, while some practitioners reserve 'nonconformance' for the result of quality-control activity on products and services, organizations benefit from agreeing on consistent internal usage. Ambiguity in terminology can complicate records, audit trails, and communication across quality, compliance, and operational functions.

Who it's relevant to

Quality management professionals
Those operating quality management systems rely on the concept of nonconformity to record and track where products, services, processes, or the system itself fail to meet specified requirements. Consistent terminology and classification support reliable quality records.
Internal and certification auditors
Auditors use nonconformity findings to document divergence from requirements and commonly classify them by severity, such as major or minor, according to the applicable standard and audit context. Clear definitions help keep findings defensible and comparable.
Compliance officers
Compliance professionals concerned with adherence to internal policies and applicable requirements benefit from a precise understanding of nonconformity, particularly where usage overlaps with 'nonconformance' and where the concept sits within a broader management-system framework.
Operations and process owners
Those responsible for products, services, and processes are the parties whose outputs may be found not to match their specifications. Understanding what constitutes a nonconformity helps them interpret findings that arise from quality-control activity.

Inside Nonconformity

Nonconformity
A failure to fulfill a specified requirement, whether that requirement derives from an external standard, a regulatory obligation, or an internal policy, standard, or procedure. In many management system standards, such as ISO 37301 for compliance management and ISO 31000-related contexts, the term refers specifically to a deviation from a stated requirement rather than to any undesirable event generally.
Requirement basis
The reference point against which conformity is judged. This may be a clause of a standard, a legal or regulatory provision, a contractual term, or an internal control expectation. Identifying the specific requirement that was not met is central to characterizing a nonconformity accurately.
Detection source
The activity through which a nonconformity is identified, commonly including internal audit, external audit, self-assessment, monitoring, management review, or reported incidents. The source can influence how independence and objectivity are considered when the finding is evaluated.
Severity or classification
Many frameworks distinguish degrees of nonconformity, such as major versus minor, based on factors like the extent of the failure or its impact on the effectiveness of the management system. The specific classification scheme and thresholds vary by standard, certification body, and program.
Correction and corrective action
Correction addresses the immediate nonconforming condition, while corrective action addresses the underlying cause to reduce the likelihood of recurrence. These are distinct steps; treating only the symptom without addressing root cause is typically considered an incomplete response in many management system standards.
Documentation and tracking
The record of the nonconformity, its analysis, the actions taken, and verification of effectiveness. Retained records support management review, subsequent assurance activities, and demonstration of program operation, though specific retention practices vary by jurisdiction and program.

Common questions

Answers to the questions practitioners most commonly ask about Nonconformity.

Is a nonconformity the same as a risk?
No. A nonconformity is a failure to meet a specified requirement, typically drawn from a standard, policy, procedure, or contractual or regulatory obligation. It describes a condition that already exists or has occurred. A risk, by contrast, concerns the effect of uncertainty on objectives and is forward-looking. A nonconformity may signal or give rise to risk, and a weak control may make nonconformities more likely, but the two concepts belong to different pillars: nonconformity sits primarily within compliance and management-system conformance, while risk sits within risk management. Treating them as interchangeable can obscure whether you are addressing an actual deviation or a potential future effect.
Does identifying a nonconformity automatically mean corrective action is required?
Not automatically in the sense of a single mandated response. Many management-system standards distinguish between correction, the immediate action to address the specific nonconformity, such as fixing or containing it, and corrective action, which addresses the underlying cause to prevent recurrence. Whether corrective action is warranted, and to what depth, commonly depends on the significance of the nonconformity and the organization's own procedures. Some minor nonconformities may be corrected without a full root-cause investigation, while others may trigger a formal corrective action process. The specific requirements vary by standard and by the organization's documented approach.
How should nonconformities be documented so they can be tracked to closure?
Organizations commonly record the requirement that was not met, a description of the actual condition observed, supporting evidence, and the source (for example, an audit, a complaint, monitoring, or self-identification). Many then capture any immediate correction taken, the results of a cause analysis where performed, the corrective action planned, responsibilities, and target dates, followed by verification that the action was effective before closure. The precise fields and workflow depend on the organization's procedures and any applicable standard; this description addresses documentation practice generally and does not prescribe specific tooling.
Who is responsible for raising and resolving a nonconformity?
Responsibilities differ by function and are worth keeping distinct. Under models such as the three lines model described by the Institute of Internal Auditors, management in the first line typically owns and resolves nonconformities within its processes. A second-line function may identify them through monitoring and oversee remediation. Internal audit, as a third-line assurance activity, may identify nonconformities during audits but generally does not remediate them, in order to preserve its independence and objectivity. The specific allocation depends on the organization's structure and the source of the finding.
How can nonconformities be prioritized when resources are limited?
Prioritization commonly considers the significance of the nonconformity, including the nature of the requirement not met, the potential consequences, and whether the issue is isolated or systemic. Some organizations grade findings, for example distinguishing major from minor nonconformities, to guide the urgency and depth of response. Where a nonconformity relates to a legal or regulatory obligation, the applicable context may constrain how it is prioritized. Approaches vary by jurisdiction, sector, and the organization's own risk-based procedures, and this does not constitute legal advice on any specific obligation.
How is the effectiveness of corrective action verified before closing a nonconformity?
Verification typically involves confirming that the planned action was implemented and, where corrective action addressed a cause, that the deviation has not recurred and the underlying condition has been resolved. Evidence may include re-testing, follow-up review, or monitoring over a defined period. Many organizations require that verification be performed by someone other than the person who implemented the action to support objectivity. The rigor and timing of verification generally depend on the significance of the nonconformity and the organization's documented procedures; specific methods are outside the scope of this entry.

Common misconceptions

A nonconformity is the same as a risk.
A nonconformity is a failure to meet a specified requirement that has been identified, which sits within the compliance and management system domain, whereas a risk concerns uncertainty relative to objectives. A nonconformity may reveal or be associated with risk, but the two concepts are distinct and belong to different pillars of GRC.
Identifying a nonconformity means the assurance function has failed to do its job.
Detecting nonconformities is a normal and expected output of assurance and monitoring activities. The role of an independent assurance function is to identify such gaps objectively; the responsibility for correcting them rests with management, keeping the distinction between assurance and management activities clear.
Applying a correction resolves the nonconformity fully.
Correction addresses the immediate issue, but many management system standards expect analysis of the cause and, where appropriate, corrective action to reduce the chance of recurrence. Verification of the effectiveness of that action is commonly part of closing the nonconformity.

Best practices

State the specific requirement that was not met, citing the relevant clause, regulatory provision, or internal policy, so the nonconformity is characterized precisely rather than described in general terms.
Distinguish clearly between correction of the immediate condition and corrective action that addresses the underlying cause, and document both where the applicable framework expects them.
Classify nonconformities using the scheme defined by the relevant standard or program, recognizing that thresholds for major and minor findings vary by standard and certification body.
Preserve the independence of assurance functions by ensuring that those identifying nonconformities are separate from those responsible for remediating them, consistent with the distinction between assurance and management activities.
Maintain records of each nonconformity, its analysis, actions taken, and verification of effectiveness to support management review and subsequent assurance, adapting retention to applicable jurisdictional and program requirements.
Verify the effectiveness of corrective actions before closing a nonconformity, rather than treating the completion of an action as evidence that recurrence has been prevented.
Promotional banner for the Pentest Readiness checklist download