Nonconformity Reports
In an ISO/IEC 27001 audit, a Nonconformity Report (NCR) is the formal document an auditor uses to record a failure to fulfil a requirement. The requirement may come from the ISO/IEC 27001 standard, the organization's own Information Security Management System (ISMS) policies and procedures, contrac… In an ISO/IEC 27001 audit, a Nonconformity Report (NCR) is the formal document an auditor uses to record a failure to fulfil a requirement. The requirement may come from the ISO/IEC 27001 standard, the organization's own Information Security Management System (ISMS) policies and procedures, contractual obligations, or applicable legal and regulatory requirements. Under ISO 19011 and ISO/IEC 17021-1 principles, every nonconformity must be based on objective, verifiable audit evidence, not opinion or assumption. A well-written NCR has three core elements. First, the requirement: the specific clause or control that applies, for example Clause 9.2 Internal Audit or Annex A control 5.15 Access Control. Second, the evidence: factual, traceable observations such as document references, records reviewed, interviewees' roles, dates and sample sizes. Third, the statement of nonconformity: a clear, concise description of what was not fulfilled. The NCR should be understandable to someone who was not present during the audit. Nonconformities are typically graded. A major nonconformity is the absence or total breakdown of a required process, or a situation that raises significant doubt about the ISMS's ability to achieve its intended outcomes. Examples include no risk assessment performed or no management review conducted. A minor nonconformity is an isolated or partial lapse that does not undermine the system's overall effectiveness. Auditors may also record observations or opportunities for improvement, which are not nonconformities. The Lead Auditor reviews all NCRs for accuracy and consistency, and presents them at the closing meeting so the auditee understands and acknowledges them. The auditee is then responsible for correction (immediate fixing), root cause analysis, and corrective action to prevent recurrence, as required by Clause 10.2. In certification audits, major nonconformities usually must be resolved and verified, sometimes through a follow-up visit, before certification is granted. Minor nonconformities typically require an accepted action plan, which is verified at the next surveillance audit. Auditors must remain impartial and avoid prescribing solutions.
Nonconformity Reports in ISO/IEC 27001 Lead Auditor: Complete Guide and Exam Tips
Introduction
Nonconformity Reports (NCRs) are among the most important outputs of an ISO/IEC 27001 audit. They are where the auditor formally records that a requirement has not been fulfilled, backed by objective evidence. For the ISO 27001 Lead Auditor exam, you must understand what an NCR is, how to write one correctly, how to grade it and how it drives corrective action. Exam questions often test whether you can tell a genuine nonconformity from an opinion, an observation or an opportunity for improvement.
Why Nonconformity Reports Are Important
1. They give the audit credibility. An audit conclusion is only as strong as the evidence behind it. A well-written NCR shows that findings are factual, traceable and verifiable rather than subjective.
2. They drive improvement. Clause 10.2 of ISO/IEC 27001 (Nonconformity and corrective action) requires the organization to react to nonconformities, find their causes and take action to stop them recurring. The NCR is the trigger for this process.
3. They support certification decisions. In third-party audits, the number and grade of nonconformities directly affects whether certification is recommended, granted, maintained, suspended or withdrawn. ISO/IEC 17021-1 and ISO/IEC 27006 govern how certification bodies handle them.
4. They protect information security. Each nonconformity points to a weakness in the ISMS that could expose the organization to risks to the confidentiality, integrity or availability of information.
5. They create an audit trail. NCRs are retained as records. They allow follow-up audits, surveillance audits and recertification audits to check that issues were resolved.
What Is a Nonconformity?
Under ISO/IEC 27000 and ISO 19011, a nonconformity is the non-fulfilment of a requirement. A requirement can come from:
- The ISO/IEC 27001 standard itself (Clauses 4 to 10 are mandatory).
- The organization's own ISMS documentation, such as policies, procedures, the Statement of Applicability (SoA) and the risk treatment plan.
- Applicable legal, regulatory and contractual requirements.
- Annex A controls that the organization has declared applicable in its SoA.
An audit finding is the result of evaluating the collected audit evidence against the audit criteria. Findings can show conformity, nonconformity or opportunities for improvement. A nonconformity is a finding that shows a requirement is not met.
What Is a Nonconformity Report?
A Nonconformity Report is the formal, documented statement of a nonconformity raised during an audit. It is usually presented at the closing meeting and accepted (ideally signed) by the auditee's representative.
Key Components of a Well-Written NCR
A good NCR is often summarized as having three essential parts:
1. Statement of the nonconformity (the problem): A clear, concise description of what is wrong.
2. Audit criteria (the requirement): The exact requirement not met, such as ISO/IEC 27001 Clause 7.2, Annex A control 5.15 or an internal procedure reference.
3. Objective evidence (the proof): The verifiable facts observed, such as records sampled, interviews held, documents reviewed or activities observed, including dates, locations and reference numbers.
Other common fields include:
- NCR reference number
- Audit date, auditor name and auditee or department
- Grade or classification (major or minor)
- Clause or control reference
- Auditee acknowledgement or signature
- Correction, root cause analysis and corrective action (completed later by the auditee)
- Agreed deadlines
- Verification of effectiveness and closure (completed by the auditor)
Example of a Well-Written NCR
Requirement: ISO/IEC 27001:2022 Clause 7.2 c) requires the organization to retain appropriate documented information as evidence of competence.
Nonconformity: The organization could not show evidence of competence for all personnel doing work that affects information security performance.
Evidence: Of 10 system administrators sampled in the IT Operations department, training and competence records were not available for 3 (employee IDs 1045, 1078 and 1102), as confirmed by the HR Manager on 12 March.
Notice the NCR is factual, specific, traceable and free of blame or opinion. It states what is wrong, not how to fix it.
Grading Nonconformities
Major Nonconformity:
- Absence of, or total breakdown of, a system or process required by the standard (for example, no management review has ever been held, no risk assessment exists or internal audits are not performed).
- A situation that raises significant doubt about the ISMS's ability to achieve its intended outcomes.
- Several minor nonconformities against the same requirement that together point to a systemic failure.
- A failure that could result in a significant information security breach or failure to meet legal requirements.
In certification audits, major nonconformities usually prevent certification until they are corrected and verified, often through an on-site follow-up visit. Under ISO/IEC 17021-1, corrections and corrective actions must normally be verified within the time limit set by the certification body (commonly within 6 months of the last day of stage 2) before certification can be granted.
Minor Nonconformity:
- An isolated lapse or a single observed failure that does not indicate a systemic breakdown.
- The ISMS remains effective overall.
Certification may be recommended once the certification body accepts the auditee's corrective action plan. Implementation is then checked at the next surveillance audit.
Observations and Opportunities for Improvement (OFIs):
These are not nonconformities. An OFI points to an area that meets the requirement but could be improved, or a potential risk that may lead to a nonconformity in future. Certification bodies must not give specific consultancy-style solutions, so OFIs are phrased generically.
How the Nonconformity Process Works
Step 1: Collect evidence. Through interviews, observation and document or record review, using sampling. Evidence must be verifiable.
Step 2: Evaluate against criteria. Compare the evidence with the audit criteria to produce findings.
Step 3: Confirm with the auditee. Good practice is to discuss potential nonconformities with the auditee during the audit, so there are no surprises at the closing meeting and facts can be checked.
Step 4: Review in the audit team. The audit team leader reviews findings for consistency, correct grading and adequate evidence.
Step 5: Document the NCR. Write the requirement, the nonconformity statement and the evidence.
Step 6: Present at the closing meeting. Explain the findings and their grades. Any diverging opinions should be discussed and, if possible, resolved. Unresolved disagreements must be recorded.
Step 7: Auditee response. The auditee is responsible for:
- Correction: immediate action to remove the detected nonconformity (for example, completing the missing training records).
- Root cause analysis: finding why it happened, using tools such as 5 Whys, fishbone (Ishikawa) diagrams or fault tree analysis.
- Corrective action: action to remove the cause and prevent recurrence (for example, adding a competence check to the onboarding process).
Step 8: Auditor review of the action plan. The auditor checks that the root cause analysis and the proposed actions are adequate.
Step 9: Verify effectiveness. By document review (often enough for minors) or a follow-up on-site audit (often needed for majors).
Step 10: Close the NCR. Once effectiveness is verified, the NCR is formally closed and records are retained.
Correction vs Corrective Action vs Preventive Action
- Correction: fixes the immediate problem (the symptom).
- Corrective action: removes the root cause to prevent recurrence.
- Preventive action: addresses a potential nonconformity to prevent occurrence. In ISO/IEC 27001:2013 and 2022, this concept is built into risk-based thinking (Clause 6.1) rather than kept as a separate requirement.
Principles for Writing Effective NCRs
- Be factual: report only what was seen, heard or read and verified.
- Be specific: include dates, document numbers, locations, sample sizes and the people interviewed (by role).
- Be traceable: anyone should be able to find the same evidence again.
- Be concise and clear: avoid jargon, ambiguity and emotional language.
- Be objective and impartial: no blame, personal opinion or assumptions.
- Do not prescribe solutions: the auditor identifies the problem. The auditee decides how to fix it. This is especially important for third-party auditors, who must avoid consultancy.
- Link to a requirement: without a requirement, there is no nonconformity.
- Grade correctly: based on impact on the ISMS, not on how severe the auditor feels it is.
Common Mistakes to Avoid
- Raising a nonconformity without objective evidence (relying on hearsay or assumptions).
- Raising a nonconformity against best practice or personal preference rather than a requirement.
- Raising an NCR against an Annex A control that was justifiably excluded in the SoA, without first checking whether the exclusion itself is justified (the exclusion justification falls under Clause 6.1.3 d).
- Writing vague statements such as 'Training is poor.'
- Recommending specific solutions or products.
- Combining several unrelated issues into one NCR.
- Grading a single isolated lapse as major, or a systemic failure as minor.
- Accepting a correction as if it were a corrective action.
Exam Tips: Answering Questions on Nonconformity Reports
1. Always identify the requirement first. In scenario questions, ask yourself which clause or control is not met. If you cannot link the situation to a requirement in ISO/IEC 27001, the organization's own documents or legal obligations, it is probably not a nonconformity. It may be an OFI.
2. Use the three-part structure. When asked to write an NCR, always include: (a) the requirement, with clause reference; (b) the statement of nonconformity; (c) the objective evidence. Examiners often award marks separately for each part.
3. Know the clause numbers. Memorize the main mandatory clauses: 4.1 to 4.4 (context and scope), 5.1 to 5.3 (leadership, policy, roles), 6.1 to 6.3 (risks, objectives, planning of changes), 7.1 to 7.5 (support, competence, awareness, communication, documented information), 8.1 to 8.3 (operation, risk assessment and treatment), 9.1 to 9.3 (monitoring, internal audit, management review), 10.1 and 10.2 (continual improvement, nonconformity and corrective action). Know the Annex A themes in the 2022 version: Organizational (5.x, 37 controls), People (6.x, 8 controls), Physical (7.x, 14 controls) and Technological (8.x, 34 controls), 93 controls in total.
4. Justify the grade. When asked to classify a finding, explain why. Use phrases such as 'isolated incident with no evidence of systemic failure' for minor, or 'complete absence of a required process' or 'raises significant doubt about the ISMS's ability to achieve its intended outcomes' for major.
5. Watch for distractors in multiple-choice questions. Wrong answers often include: the auditor proposing a solution, NCRs based on opinion, nonconformities raised against excluded controls without checking the justification, or confusing correction with corrective action.
6. Separate auditor and auditee responsibilities. The auditor identifies, documents, grades and verifies. The auditee corrects, analyses root cause and implements corrective action. Questions asking 'who is responsible for determining corrective action?' expect the answer: the auditee.
7. Remember the closing meeting rules. Findings are presented at the closing meeting. Disagreements should be discussed and, if unresolved, recorded. The audit team leader has final responsibility for the audit conclusions.
8. Look for the evidence in the scenario. Exam scenarios include specific details such as dates, names and documents. Use them in your NCR to show traceability. Do not invent facts that are not in the scenario.
9. Think about sampling. If the scenario says 2 out of 20 samples failed, this usually suggests a minor nonconformity. If all samples failed, or the process does not exist, consider major.
10. Check the organization's own requirements. A nonconformity can be raised if the organization fails to follow its own policy, even if that policy goes beyond the standard. For example, if the policy requires password changes every 60 days and records show 120 days, that is a nonconformity against the organization's own requirement.
11. Do not confuse nonconformities with incidents. A security incident is not automatically a nonconformity. The question is whether the organization handled it according to its requirements, such as the incident management process under controls 5.24 to 5.28.
12. Remember follow-up and closure. Know that major nonconformities usually need verification (often on site) before certification, while minor nonconformities may be verified at the next surveillance audit after an acceptable action plan is approved.
13. Use precise auditing vocabulary. Terms such as audit criteria, audit evidence, audit findings, objective evidence, correction, corrective action, root cause and verification of effectiveness show your expertise and match ISO 19011 language.
14. Manage your time in essay questions. For a typical 'write an NCR' question, spend a minute finding the requirement, a minute pulling out the evidence from the scenario, then write a clean three-part NCR with a justified grade.
Sample Exam Question and Model Answer
Scenario: During an audit, you find that the organization's information security policy requires annual access reviews for all critical systems. For the ERP system, the last documented access review was 22 months ago. The IT Manager says reviews are 'done informally.'
Model answer:
- Requirement: The organization's Access Control Policy (ref. ISP-AC-01) requires annual access rights reviews for critical systems. This is also linked to Annex A control 5.18 (Access rights) and Clause 8.1 (operational planning and control).
- Nonconformity: Access rights to the critical ERP system were not reviewed at the frequency the organization has defined.
- Evidence: The last documented access review for the ERP system was dated 22 months before the audit. The IT Manager stated that reviews are performed informally, but no records were available to support this.
- Grade: Minor, as this appears to be an isolated failure affecting one system. However, if access reviews were missing for several critical systems, it would be raised as a major nonconformity because it would indicate a systemic breakdown of the access control process.
Summary
Nonconformity Reports turn audit evidence into actionable, verifiable findings. A strong NCR clearly states the requirement, the nonconformity and the objective evidence. It is graded correctly and does not prescribe solutions. In the exam, anchor every answer to a specific requirement, use evidence from the scenario, justify your grading, and keep the auditor's role separate from the auditee's. Master these principles and you will handle NCR questions with confidence.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!