Every certification audit ends with a closing meeting, and most closing meetings include findings. What happens next depends on how those findings are graded and how well you respond. This article explains the difference between a major and a minor nonconformity, what each means for your certificate, and how to write a corrective action that closes the finding the first time rather than bouncing back for another round.
What a nonconformity is
A nonconformity is the non-fulfilment of a requirement. In a certification audit, the requirement may come from the standard, from your own management system documentation, from legal requirements within scope, or from certification rules. A well-written nonconformity has three parts: the requirement, the objective evidence observed, and a statement of why the evidence does not meet the requirement.
Major vs minor nonconformity
ISO/IEC 17021-1 defines the two grades used by accredited certification bodies. A major nonconformity is one that affects the capability of the management system to achieve its intended results. A minor nonconformity is one that does not affect that capability. The grade is about the system, not about how serious the individual incident felt at the time.
| Major nonconformity | Minor nonconformity | |
|---|---|---|
| Definition | Affects the capability of the system to achieve intended results | Does not affect that capability |
| Typical examples | A required process absent altogether; a systemic failure across samples; a significant doubt that effective process control is in place | An isolated lapse in an otherwise working process |
| Effect on initial certification | Certification cannot be granted until correction and corrective action are reviewed and verified | Certification can be granted once the corrective action plan is accepted |
| Verification | Usually by review of evidence or a follow-up audit, before certification or continued certification | Normally verified at the next audit |
Several minor nonconformities against the same requirement or process can indicate a systemic failure and may be graded as a major. Auditors may also record opportunities for improvement; these are not nonconformities and do not require corrective action, though they are worth considering.
Correction, corrective action and root cause
Most rejected responses fail because they confuse three things. Correction is action to eliminate the detected nonconformity — recalibrating the instrument, updating the document, retraining the person. Corrective action is action to eliminate the cause of the nonconformity and prevent recurrence. Root cause is the reason the system allowed the nonconformity to occur in the first place.
A response that describes only correction has fixed the example the auditor found, not the process that produced it. The auditor will ask why the same thing will not happen elsewhere or next month, and the response will be returned.
How to write an effective corrective action
1. Restate the nonconformity precisely
Make sure you and the auditor agree on what was found. If the finding is unclear, ask for clarification at the closing meeting, not after it.
2. Contain and correct
Deal with the immediate problem and check for the same problem elsewhere. If one instrument was out of calibration, check the others. If one supplier had not been evaluated, check the approved supplier list. This extent-of-problem check is often what distinguishes an accepted response from a rejected one.
3. Find the root cause
Use a structured method — five whys, a cause-and-effect diagram, or a simple fault tree — and keep asking until you reach a cause in the system that you can change. Test the cause by asking: if we fix this, would the nonconformity have been prevented? If the answer is "only if people are more careful", you have not reached the root cause.
Human error is where root cause analysis should start, not where it ends. The question is why the system made the error easy to make and hard to notice.
4. Define corrective action against the cause
Each action should address the identified cause, have an owner and a target date, and be proportionate to the effect of the nonconformity. Changing a process, adding a system check, redesigning a form, introducing an automated reminder or clarifying a responsibility are corrective actions. "Retrain the operator" is usually a correction, unless the root cause genuinely was a gap in the training programme itself.
5. Verify effectiveness
State how and when you will check that the action worked — for example, by reviewing the next three months of records or re-auditing the process. Effectiveness is judged by whether the problem recurs, so it cannot always be verified immediately. The certification body will look for this evidence at the next audit.
A worked example
- Nonconformity: clause 8.4.1 requires evaluation of external providers; two of five sampled raw material suppliers added during the year had no evaluation record
- Correction: both suppliers evaluated; approved supplier list reviewed, and one further unevaluated supplier found and evaluated
- Root cause: the ERP system allowed purchase orders to be raised to a new vendor code before the quality evaluation was complete, and the procedure did not assign responsibility for that check to purchasing
- Corrective action: ERP vendor codes blocked for purchasing until quality approval is recorded; procedure updated to define responsibility; purchasing team briefed on the change
- Effectiveness check: review of all new vendors added over the next quarter by the quality manager, reported to management review
Common reasons corrective action responses are rejected
- Only correction described, with no root cause or corrective action
- Root cause stated as "human error", "oversight" or "lack of awareness" without further analysis
- No extent-of-problem check beyond the example the auditor found
- Actions with no owner, no date or no evidence of implementation
- No plan to verify effectiveness
Good root cause analysis is the single biggest lever an organisation has over its certification timeline. If you have questions about a finding raised in a GMSCPL audit or about response timelines, talk to your audit team or contact us.