GlossaryISO 27001

Nonconformity

Short answer

A nonconformity is an audit finding that a requirement of a standard such as ISO 27001 is not being met. It is classified as major or minor, and the organisation must correct it and address its root cause.

Major vs minor

A major nonconformity means a requirement is not met at all or a control is failing in a way that puts the management system at risk. It can stop or delay certification until it is fixed. A minor nonconformity is an isolated lapse that does not undermine the system as a whole. Auditors may also raise observations or opportunities for improvement, which are not nonconformities.

What happens next

The organisation must correct the issue, find the root cause and take corrective action so it does not happen again. For major nonconformities, the certification body usually needs evidence of the fix before issuing or keeping the certificate.

Common examples

Typical findings include access reviews that were never done, missing evidence of training, an out of date risk assessment, or a Statement of Applicability that does not match reality.

Internal nonconformities

Nonconformities found in internal audits follow the same process. Finding them internally first is the point of the internal audit.

Related terms

Keep reading on this topic

ISO 27001 information security management: scope, risk treatment, Annex A controls, internal audit and the certification audit process, explained.

Go to the topic hub