Major and Minor Nonconformities
In an ISO/IEC 27001 certification audit, a nonconformity is the non-fulfilment of a requirement. That requirement may come from the standard's clauses 4 to 10, the organization's own ISMS documentation, the Statement of Applicability and Annex A controls it has chosen, or legal and contractual obli… In an ISO/IEC 27001 certification audit, a nonconformity is the non-fulfilment of a requirement. That requirement may come from the standard's clauses 4 to 10, the organization's own ISMS documentation, the Statement of Applicability and Annex A controls it has chosen, or legal and contractual obligations. Following ISO/IEC 17021-1 and ISO/IEC 27006, auditors grade each nonconformity as major or minor based on objective evidence. A Major Nonconformity is one that affects the ability of the ISMS to achieve its intended results. Typical triggers include: - the total absence or complete breakdown of a required process - significant doubt that effective process control is in place - several minor nonconformities against the same requirement, which together show a systemic failure Examples include no information security risk assessment or risk treatment process, no internal audit programme, no management review, or a missing or meaningless Statement of Applicability. A major nonconformity prevents the lead auditor from recommending certification. During surveillance, it can lead to suspension. The organization must perform a correction, analyse the root cause and implement corrective action. The certification body must then verify this, often through a follow-up or special audit, within a defined period, commonly around 90 days. A Minor Nonconformity does not affect the ISMS's ability to achieve its intended results. It is usually an isolated lapse or a partial implementation within an otherwise functioning system. Examples include one overdue access rights review, a single missing competence record, or an outdated document version in use. Certification can still be recommended once the auditor has accepted the organization's corrective action plan. Its effectiveness is normally verified at the next surveillance audit. Lead auditors must write each nonconformity clearly. A good statement identifies the requirement, the objective evidence observed and the nature of the gap, so that it is factual, traceable and reproducible. Nonconformities differ from observations and opportunities for improvement, which are not breaches of requirements. Correct grading keeps the audit fair, consistent and credible, and it drives genuine improvement in information security.
Major and Minor Nonconformities in ISO/IEC 27001 Audits: A Complete Guide for Lead Auditors
Introduction
Grading nonconformities is one of the most important judgement calls an ISO/IEC 27001 Lead Auditor makes. The grade decides whether an organisation is recommended for certification, whether an existing certificate is put at risk, and how quickly corrective action must be taken. Lead Auditor exams, such as those from PECB, IRCA/CQI, BSI and Exemplar Global, test this topic heavily, usually through scenarios that ask you to classify a finding and justify the classification.
Why It Is Important
1. Certification decisions depend on it. Under ISO/IEC 17021-1 and ISO/IEC 27006-1, a certification body cannot grant initial certification until major nonconformities are corrected and the correction is verified. For minor nonconformities, it must have accepted the organisation's correction and corrective action plan.
2. It protects the credibility of certification. Grading too leniently lets an ineffective ISMS be certified. Grading too harshly damages trust and wastes the client's resources.
3. It drives proportionate improvement. The grade tells the auditee how serious the problem is and how fast it must be fixed.
4. It reflects risk-based thinking. Grading looks at the effect on the ISMS's ability to achieve its intended outcomes, protecting the confidentiality, integrity and availability of information. A fault in a single record is treated differently from a fault in the whole system.
5. It is a core competence for auditors. ISO 19011 expects auditors to evaluate evidence objectively and reach audit findings that can be defended.
What It Is: Key Definitions
Nonconformity (ISO/IEC 27000 / ISO 9000): Non-fulfilment of a requirement. The requirement can come from:
- ISO/IEC 27001 clauses 4 to 10
- Annex A controls the organisation has chosen to apply (as declared in its Statement of Applicability)
- the organisation's own policies, procedures and ISMS documentation
- legal, regulatory and contractual obligations within the ISMS scope
Major Nonconformity (ISO/IEC 17021-1, clause 3.12): A nonconformity that affects the capability of the management system to achieve its intended results. Typical situations include:
- A required clause or process is completely absent or has broken down. Examples: no risk assessment has been done, no internal audit programme exists, or management review has never taken place.
- There is significant doubt that effective process control is in place, or that products and services will meet specified requirements.
- Several minor nonconformities against the same requirement or process together show a systemic failure.
- A minor nonconformity from a previous audit has not been effectively addressed, which some schemes or certification bodies may escalate to major.
- An incident or breach caused by a control failure has a significant impact.
Minor Nonconformity (ISO/IEC 17021-1, clause 3.13): A nonconformity that does not affect the capability of the management system to achieve its intended results. Typically:
- It is an isolated lapse, such as one missed access review, one unsigned NDA, or one outdated procedure version.
- The process exists and generally works, but was not followed completely in a specific instance.
Related Terms (Not Nonconformities)
Observation / Area of Concern: Something that is not yet a nonconformity but could become one if left unchecked. Note that many certification bodies use 'Opportunity for Improvement' interchangeably with this term.
Opportunity for Improvement (OFI): A suggestion to improve efficiency or effectiveness where the requirement is already met. Auditors must not give consultancy, so OFIs must not prescribe a specific solution.
Conformity / Good Practice: A positive finding worth recording.
How It Works: The Process
Step 1 – Collect objective evidence. Use interviews, observation and document and record review, following ISO 19011 sampling methods. Evidence must be verifiable, meaning factual and not based on opinion or hearsay.
Step 2 – Compare evidence against audit criteria. Identify exactly which requirement is not fulfilled, for example 'ISO/IEC 27001:2022 clause 9.2.2' or 'Annex A 5.18 Access rights', or the organisation's own access control policy.
Step 3 – Determine if it is a nonconformity. If there is no requirement, there is no nonconformity. The issue may be an OFI instead.
Step 4 – Grade the nonconformity. Ask these questions:
- Is the issue systemic (affecting the whole process) or isolated (a single instance)?
- Does it undermine the ISMS's ability to achieve its intended outcomes?
- Is a mandatory clause requirement (clauses 4 to 10) totally missing?
- Is there a pattern? For example, several minors in the same area may combine into a major.
- What is the actual or potential impact on information security risk?
- Has it happened before, such as an unresolved previous finding?
Step 5 – Write the nonconformity statement. A good NC report has three elements:
1. Requirement: what should happen, citing the clause, control or procedure.
2. Evidence: what was actually found, with specific and traceable facts such as dates, record IDs and samples.
3. Statement of nonconformity: why the evidence fails the requirement.
Example (Minor): 'Requirement: The Access Control Policy (AC-01 v3) requires quarterly user access reviews (ISO/IEC 27001 A 5.18). Evidence: Of 4 business applications sampled, the Q2 2024 review for the HR system was not performed; the other 3 were completed. Nonconformity: Access rights for the HR system were not reviewed as required.'
Example (Major): 'Requirement: Clause 6.1.2 requires the organisation to define and apply an information security risk assessment process. Evidence: No risk assessment has been performed since the ISMS was established; the risk register is blank and the SoA is not linked to any risk treatment. Nonconformity: The organisation has not implemented an information security risk assessment process.'
Step 6 – Communicate the finding. Agree the facts with the auditee during the audit, then present it at the closing meeting. Make sure the auditee understands it. Differences of opinion should be discussed and resolved if possible. If they are not resolved, both opinions are recorded.
Step 7 – Correction and corrective action (clause 10.2). The auditee must:
- carry out a correction, which is an immediate fix to the problem
- perform root cause analysis
- implement corrective action to prevent recurrence
- review its effectiveness
Step 8 – Verification and follow-up. Deadlines are set by the certification body. Typical certification body practice is:
- Majors: often an on-site follow-up or document verification, usually within about 90 days (some schemes allow up to 6 months). Certification is withheld, or an existing certificate may be suspended, until the major is closed.
- Minors: the certification body accepts a corrective action plan, typically within 30 to 90 days, and checks implementation at the next surveillance audit.
Practical Grading Examples
- No internal audits performed in the certification cycle: Major (clause 9.2 absent).
- Internal audit performed but one auditor audited their own work: Minor (clause 9.2.2 objectivity lapse).
- Management review never held: Major (clause 9.3).
- Management review held but did not cover one required input: Minor.
- No Statement of Applicability: Major (clause 6.1.3 d).
- SoA exists but one exclusion lacks justification: Minor.
- One former employee's account still active out of 50 leavers sampled: Minor.
- Fifteen former employees' accounts still active, with no leaver process followed: Major (systemic failure of A 5.18 / A 8.2 / A 5.11).
- Backups never tested and a ransomware incident caused unrecoverable data loss: Major.
- Top management cannot explain the information security policy and no ISMS objectives exist: Major (clauses 5 and 6.2).
- Training record missing for one new employee: Minor.
- Recommending a better tool for log analysis where logging works: OFI, not a nonconformity.
Common Pitfalls
- Raising a nonconformity without a clear requirement. Every NC must trace back to a 'shall' or a documented commitment.
- Grading based on personal opinion or best practice rather than the criteria.
- Writing vague findings such as 'Access control is weak' without evidence.
- Prescribing solutions inside the NC, which is consultancy and compromises impartiality.
- Ignoring the cumulative effect of multiple minors.
- Confusing correction (fixing the instance) with corrective action (removing the root cause).
- Raising NCs against Annex A controls that are legitimately excluded in the SoA. You may, however, challenge an exclusion that is not justified.
Exam Tips: Answering Questions on Major and Minor Nonconformities
1. Use the 'capability' test. The single most important question is whether the finding affects the ISMS's ability to achieve its intended results. If yes, it is Major. If no, it is Minor. Quote this reasoning in essay answers.
2. Look for keywords in scenarios.
- Words such as 'never', 'no evidence at all', 'not established', 'none of the sampled', 'across all departments' and 'repeatedly' point to Major.
- Words such as 'one instance', 'single record', 'isolated', 'otherwise effective' and '1 out of 20' point to Minor.
- Phrases such as 'could be improved', 'not a requirement' and 'auditor suggests' point to an OFI.
3. Always cite the requirement. In written or case-study exams, state the exact clause or Annex A control (ISO/IEC 27001:2022 numbering, for example A 5.15, A 8.13, clause 9.2). Marks are often awarded separately for the requirement, the evidence and the grading justification.
4. Use the three-part structure. Write Requirement, then Evidence, then Nonconformity statement. This is what examiners expect and it demonstrates ISO 19011 competence.
5. Justify your grade. Do not just write 'Major'. Explain why, for example: 'This is major because clause 6.1.2 is entirely absent, meaning risk-based control selection cannot occur, which affects the ISMS's capability to achieve intended outcomes.'
6. Watch for traps.
- Is it actually a requirement? Check whether the control is excluded in the SoA, or whether the scenario describes good practice rather than a 'shall'.
- Is the evidence objective? Hearsay ('someone told me') is not sufficient evidence alone. It must be verified.
- Is the auditor being asked to give advice? That is not allowed.
7. Remember the clustering rule. If a scenario lists several small failures in the same process, consider whether they collectively indicate a systemic breakdown and therefore a Major.
8. Know the consequences. Exams often ask what happens next. A major prevents certification recommendation until it is closed and verified, and may lead to suspension during surveillance. A minor requires an accepted action plan and is verified at the next audit.
9. Distinguish correction, corrective action and preventive thinking. ISO/IEC 27001:2022 clause 10.2 requires reacting to the nonconformity, evaluating the need for action to eliminate causes, implementing the action, reviewing effectiveness and updating the ISMS if necessary.
10. Know your standards. Gradings are defined in ISO/IEC 17021-1, ISMS-specific certification requirements are in ISO/IEC 27006-1, and audit evidence and findings guidance is in ISO 19011. Mentioning these adds authority to your answers.
11. In multiple-choice questions, eliminate extremes. Avoid options that grade on emotion ('the auditor felt it was serious'), recommend a specific fix, or ignore evidence. Choose the answer based on objective evidence and impact on the system.
12. Manage your time in case studies. Identify all potential findings first, then grade each one, then write them up. Prioritise clarity and traceability over length.
Summary
A nonconformity is the non-fulfilment of a requirement. A Major nonconformity affects the ISMS's capability to achieve its intended results: it is systemic, a requirement is absent, or the impact is significant. A Minor nonconformity is an isolated lapse that does not compromise the system overall. Effective auditors base every finding on objective evidence, cite the requirement precisely, grade according to impact and pattern, and follow up proportionately. In the exam, apply the capability test, use the Requirement, Evidence, Statement structure, and always justify your grading.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!