Nonconformity, Corrective Action and Continual Improvement
In ISO/IEC 27001:2022, Clause 10 (Improvement) contains two requirements: 10.1 Continual Improvement and 10.2 Nonconformity and Corrective Action. A nonconformity is the non-fulfilment of a requirement. That requirement may come from the standard itself, the organization's own ISMS policies and pro… In ISO/IEC 27001:2022, Clause 10 (Improvement) contains two requirements: 10.1 Continual Improvement and 10.2 Nonconformity and Corrective Action. A nonconformity is the non-fulfilment of a requirement. That requirement may come from the standard itself, the organization's own ISMS policies and procedures, legal or contractual obligations, or interested party expectations. Nonconformities can be identified through internal audits, management reviews, security incidents, monitoring and measurement, or external certification audits. Lead auditors typically grade them as major or minor. A major nonconformity is the absence or total breakdown of a required process, or raises significant doubt about the ISMS achieving its intended outcomes. A minor nonconformity is an isolated lapse that does not compromise the system. When a nonconformity occurs, the organization must first react by controlling and correcting it and dealing with its consequences. This is called correction. It must then evaluate the need to eliminate the cause so the problem does not recur or occur elsewhere. This involves reviewing the nonconformity, determining root causes using tools such as 5 Whys or fishbone analysis, and checking whether similar nonconformities exist or could occur. Corrective actions must be appropriate to the effects of the nonconformity. The organization must implement them, review their effectiveness, and change the ISMS where necessary. It must retain documented information on the nature of nonconformities, actions taken, and results. Auditors distinguish correction (the immediate fix) from corrective action (eliminating the root cause). They verify effectiveness, not merely closure. Continual improvement requires the organization to continually improve the suitability, adequacy and effectiveness of the ISMS. Inputs include audit results, risk assessment outcomes, performance metrics, incident trends and management review decisions (Clause 9.3). Clause 10 corresponds to the Act phase of Plan-Do-Check-Act thinking. During audits, the lead auditor looks for evidence that improvement is systematic, measured and driven by top management rather than purely reactive. Such evidence shows a mature, learning ISMS that adapts to changing threats, risks and business context.
Nonconformity, Corrective Action and Continual Improvement (ISO/IEC 27001 Clause 10)
Introduction
Clause 10 of ISO/IEC 27001 (titled Improvement) is the Act stage of the Plan-Do-Check-Act (PDCA) cycle. It turns findings from monitoring, internal audits, management reviews and security incidents into lasting improvements. For a Lead Auditor, this clause matters on two levels. First, you must audit whether the organization handles its own nonconformities properly. Second, you must raise and follow up nonconformities as part of the certification process. Exam questions often test both views, so you need to understand the standard's wording, the terms around it and how auditing works in practice.
Why It Is Important
1. It closes the PDCA loop. Without Clause 10, problems found in Clause 9 (performance evaluation) would be recorded but never fixed. An ISMS that never fixes its weaknesses cannot stay effective.
2. It stops problems coming back. Fixing a symptom (correction) without removing the cause means the same failure will happen again, often more seriously.
3. It shows management commitment. Certification bodies treat a working corrective action process as strong evidence that the ISMS is real and not just paperwork.
4. It drives certification decisions. Under ISO/IEC 17021-1 and ISO/IEC 27006, certification depends on how nonconformities are resolved. Major nonconformities must be closed and verified before certification is granted.
5. It supports risk-based thinking. Root causes found through corrective action feed back into risk assessment and treatment (Clauses 6.1 and 8).
What It Is: Structure of Clause 10
In ISO/IEC 27001:2022 the order of the sub-clauses was swapped compared with the 2013 edition:
- 10.1 Continual improvement
- 10.2 Nonconformity and corrective action
(In ISO/IEC 27001:2013, 10.1 was Nonconformity and corrective action and 10.2 was Continual improvement. Watch for this if a question cites clause numbers.)
Key Definitions (ISO/IEC 27000 and the Harmonized Structure, Annex SL)
- Nonconformity: non-fulfilment of a requirement. The requirement may come from the standard, the organization's own policies and procedures, legal or contractual obligations, or customer requirements.
- Correction: action to eliminate a detected nonconformity. It is the immediate fix, such as disabling an orphaned user account.
- Corrective action: action to eliminate the cause of a nonconformity and to prevent it from recurring. An example is fixing the joiner-mover-leaver process so orphaned accounts are no longer created.
- Continual improvement: recurring activity to enhance performance.
- Preventive action: this term was removed as a separate requirement in the 2013 edition. Its purpose is now covered by risk-based planning (Clause 6.1). Corrective action still includes checking whether similar nonconformities exist or could potentially occur elsewhere.
How It Works: Clause 10.2 Nonconformity and Corrective Action Step by Step
When a nonconformity occurs, the organization shall:
a) React to the nonconformity and, as applicable:
- take action to control and correct it (correction / containment);
- deal with the consequences.
b) Evaluate the need for action to eliminate the causes so it does not recur or occur elsewhere, by:
- reviewing the nonconformity;
- determining its causes (root cause analysis);
- determining whether similar nonconformities exist or could potentially occur.
c) Implement any action needed.
d) Review the effectiveness of any corrective action taken.
e) Make changes to the ISMS, if necessary.
Corrective actions shall be appropriate to the effects of the nonconformities encountered. This is the principle of proportionality: not every minor slip needs a major project.
Documented information shall be available as evidence of:
- the nature of the nonconformities and any subsequent actions taken;
- the results of any corrective action.
Sources of Nonconformities
- Internal audits (9.2) and external or certification audits
- Management review outputs (9.3)
- Monitoring, measurement, analysis and evaluation (9.1)
- Information security incidents and events (Annex A 5.24 to 5.28)
- Complaints from customers or interested parties
- Supplier reviews, penetration tests and vulnerability scans
- Regulatory inspections
Root Cause Analysis Techniques
- 5 Whys: keep asking why until you reach a systemic cause.
- Ishikawa (fishbone) diagram: sorts possible causes into categories such as people, process, technology, environment and management.
- Pareto analysis: focuses effort on the few causes behind most problems (the 80/20 rule).
- Fault tree analysis and barrier analysis.
A good root cause is usually a process or system weakness. Simply saying human error is rarely enough. Auditors should challenge root causes that blame individuals.
Worked Example
Finding: Three leavers still had active VPN access 30 days after leaving.
Correction: Disable the three accounts immediately and review their logs for misuse (dealing with consequences).
Root cause: HR leaver notifications were sent by email to a shared mailbox that nobody monitored.
Similar cases: Check all other systems that rely on the same notification (for example cloud SaaS apps and badge access).
Corrective action: Automate deprovisioning through the HR system, assign ownership and add a monthly reconciliation.
Effectiveness review: After three months, the reconciliation shows zero orphaned accounts.
ISMS change: Update the access control procedure and the risk register.
How It Works: Clause 10.1 Continual Improvement
The organization shall continually improve the suitability, adequacy and effectiveness of the ISMS.
- Suitability: the ISMS fits the organization's purpose and context.
- Adequacy: the ISMS is sufficient in scope and resources.
- Effectiveness: the ISMS achieves its intended results and objectives.
Continual improvement goes beyond fixing problems. It covers proactive enhancements identified through:
- management review outputs (9.3.3 requires decisions on continual improvement opportunities);
- trend analysis of metrics and incidents;
- benchmarking, new technologies and lessons learned;
- opportunities for improvement (OFIs) raised by auditors.
Continual means improvement in steps over time. It does not have to be constant or continuous.
The Auditor's Perspective
1. Auditing the organization's Clause 10 process
- Ask for the nonconformity and corrective action log or register.
- Sample records and trace each one: finding, then correction, then root cause, then action, then effectiveness check, then closure.
- Check that effectiveness was actually verified, not just that the action was closed.
- Look for repeat nonconformities. These show that root cause analysis failed.
- Confirm that the records are kept as documented information.
- Check links to management review, risk assessment and internal audit.
2. Raising nonconformities during a certification audit
A well-written nonconformity statement contains three parts:
- Requirement: the clause or control and what it requires.
- Evidence: objective, verifiable facts (records, interviews, observations).
- Statement of nonconformity: a clear explanation of how the evidence fails the requirement.
Grading (ISO/IEC 17021-1 terms):
- Major nonconformity: affects the ability of the management system to achieve its intended results. Examples are the total absence of a required process (no internal audits at all, no management review) or a systemic failure. It must be corrected and the corrective action verified (often through a follow-up audit) before certification is granted or kept.
- Minor nonconformity: does not affect the system's ability to achieve its intended results. It is usually an isolated lapse. The organization submits a corrective action plan, which is accepted by the audit team and verified at the next audit.
- Opportunity for improvement (OFI) / observation: not a nonconformity. It is a suggestion or a potential weakness. Auditors must not give consulting advice or prescribe solutions.
Several minor nonconformities against the same requirement may together point to a systemic problem and be upgraded to a major.
3. The auditee's responsibilities vs. the auditor's
- The auditee determines the root cause and proposes corrections and corrective actions.
- The auditor reviews the plan for acceptability and verifies that it was implemented and effective. The auditor must not design the solution, because that would threaten impartiality.
Common Pitfalls Auditors Look For
- Correction mistaken for corrective action (the symptom fixed, the cause left in place)
- Root cause recorded as human error or staff not trained, with no deeper analysis
- Actions closed without any effectiveness review
- No check for similar nonconformities elsewhere
- Corrective actions out of proportion to the impact
- Lessons from incidents never fed back into the risk assessment
- Continual improvement claimed but no evidence of decisions in management review
Exam Tips: Answering Questions on Nonconformity, Corrective Action and Continual Improvement
1. Separate correction from corrective action. This is the most tested distinction. If an option fixes the immediate problem, it is a correction. If it removes the cause to prevent recurrence, it is a corrective action. Scenario questions often ask for the BEST or MOST appropriate response, and the answer is usually the one that addresses root cause.
2. Remember the order of steps: react (control, correct, deal with consequences), then evaluate the cause, then check for similar cases, then implement, then review effectiveness, then update the ISMS. Questions may ask what should happen FIRST (react and contain) or what is often MISSED (the effectiveness review).
3. Preventive action is not a separate clause. If an option says ISO/IEC 27001:2022 requires a documented preventive action procedure, it is wrong. Prevention is handled through risk-based thinking in Clause 6.1.
4. Know which documented information is required. Evidence of the nature of the nonconformities, the actions taken and the results of corrective action. A documented procedure for corrective action is not mandatory.
5. Grade nonconformities using the definition, not your feelings. Ask whether the issue affects the ISMS's ability to achieve its intended results, or whether a required element is completely missing or failing systemically. If yes, it is a major. If it is an isolated lapse, it is a minor. If no requirement is breached, it is an OFI. A single missed signature is usually minor. No internal audit programme at all is major.
6. Every nonconformity must be traceable to a requirement. In essay or scenario questions, cite the clause or Annex A control, state the objective evidence and write a clear statement. Never raise a nonconformity on opinion or best practice alone.
7. Do not act as a consultant. If an option has the auditor designing the corrective action, it is usually wrong. The auditee owns the root cause analysis and the action plan. The auditor accepts and verifies.
8. Know the follow-up rules. Majors are closed and verified before the certification decision, sometimes through a special or follow-up audit. Minors need an accepted action plan, with verification at the next surveillance audit.
9. Know the three improvement words: suitability, adequacy and effectiveness. These appear in 10.1 and in management review (9.3). Exams may test them as a set.
10. Watch for edition traps. In 2022, 10.1 is Continual improvement and 10.2 is Nonconformity and corrective action. In 2013 the order was reversed. Read the edition in the question.
11. Link Clause 10 to other clauses. Good answers show how Clause 10 connects to internal audit (9.2), management review (9.3, including the review of nonconformities and corrective actions as an input), risk treatment (6.1.3, 8.3) and incident management (Annex A 5.26 and 5.27, learning from incidents).
12. Treat repeat findings as a warning sign. If a scenario describes the same issue happening again after it was closed, the correct conclusion is usually that root cause analysis or the effectiveness review failed. This may justify a nonconformity against 10.2 itself.
13. Apply proportionality. Choose answers where the action is appropriate to the effects. Neither over-engineering nor superficial fixes are correct.
14. Use keywords in written answers: objective evidence, root cause, containment, recurrence, effectiveness verification, documented information, proportionate, systemic and PDCA Act phase. Examiners reward precise ISO terms.
15. Elimination strategy for multiple-choice questions: rule out options that (a) only fix the symptom, (b) blame individuals without analysis, (c) skip the effectiveness check, (d) have the auditor prescribing solutions or (e) cite requirements that do not exist (such as a mandatory preventive action procedure).
Quick Revision Summary
- Nonconformity = non-fulfilment of a requirement.
- Correction = fix the problem. Corrective action = remove the cause.
- Steps: react, then evaluate causes and similar cases, then implement, then review effectiveness, then change the ISMS.
- Keep documented information on the nonconformity, the actions taken and the results.
- Continual improvement covers the suitability, adequacy and effectiveness of the ISMS.
- Major = system-level failure, closed before certification. Minor = isolated lapse, action plan required. OFI = not a nonconformity.
- The auditor verifies and never designs the solution.
Learn these principles well and you will be able to answer recall questions and complex audit scenarios with confidence.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!