Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

Nonconformance & Corrective Action in ISO 9001 (with Examples)

Every business gets the occasional nonconformance: a calibration that lapses, a document at the wrong revision, a late delivery. They’re not a sign of failure; what matters to ISO 9001 is how you respond. This guide explains what a nonconformance is, the difference between correction and corrective action, what auditors expect to see in your records, and how to close one out properly, with examples.

Tilt-shift miniature of auditors inspecting findings: ISO 9001 nonconformance and corrective action
A correction fixes what happened. Corrective action changes the system that allowed it to happen.

What is a nonconformance in ISO 9001?

A nonconformance (or nonconformity) is any failure to meet a requirement: a requirement of ISO 9001, of your own documented processes, or of a customer or legal obligation. It’s simply a gap between what should happen and what actually happened.

Minor vs major nonconformities

A minor nonconformity is an isolated lapse that doesn’t undermine the system, for example a single overdue calibration. A major nonconformity is a significant or systemic failure, such as a whole clause not being addressed, and must be resolved before certification can proceed. Our guide to ISO 9001 audits explains the full set of audit findings.

Correction vs corrective action

These two are often confused. A correction fixes the immediate problem. A corrective action removes the underlying cause so the problem doesn’t come back. ISO 9001 expects both where they’re warranted. Patching the symptom isn’t enough on its own.

What happened to “preventive action”?

If your last system was built to ISO 9001:2008, you’ll remember preventive action as its own clause, and auditors still get asked where it went. The 2015 revision didn’t abolish it; it promoted it. Prevention now runs through the whole standard as risk-based thinking (clause 6.1): instead of reacting with “preventive actions” after near-misses, you identify risks and opportunities up front and build controls into your processes. If an auditor asks how you do preventive action, your risk assessment and planning records are the answer.

The corrective action process, step by step

  1. Record the nonconformity: what happened, where and against which requirement.
  2. Contain and correct: deal with the immediate issue and any product or service affected.
  3. Analyse the root cause: a distinct, essential step. Ask why it really happened (the “5 whys” is a simple, effective tool). The root cause is what determines the right response.
  4. Decide whether corrective action is needed: corrective action is warranted when the root-cause scenario has happened before, or could happen again. A genuine one-off may need only the correction.
  5. Establish the corrective action: change the process, training or controls to remove or control the cause. Where the situation could recur, this usually means putting ongoing controls in place to reduce its likelihood or consequence.
  6. Verify effectiveness: check the action actually worked and the issue hasn’t recurred.
  7. Close it out: record the outcome and feed it into your management review.

Examples of nonconformities and corrective actions

NonconformityCorrection (immediate)Corrective action (root cause)
Calibration certificate expired on a gaugeRe-calibrate the gaugeAdd calibration due-dates to a tracked schedule with reminders
Customer complaint about a late deliveryExpedite the order and apologiseReview the scheduling process and address the capacity or planning gap
A document found at the wrong revisionReplace it with the current revisionFix document control so only current versions are accessible
Internal audit not completed on scheduleComplete the outstanding auditResource and re-plan the audit programme with clear ownership

When the nonconformity comes from a regulator

Clause 10.2 is common text. It is worded the same in ISO 9001, ISO 45001, ISO 14001, ISO 27001 and ISO 42001, so everything above applies whichever standard you are certified to.

That matters most when the nonconformity does not come from your own internal audit. A regulator’s notice is a nonconformity with a statutory deadline and a named remedy attached, arriving from outside your system. Which is exactly why it tends to land in somebody’s inbox rather than in the corrective action register. Two Victorian prosecutions in August 2026 show what that costs.

The close-out was the offence

WorkSafe Victoria fined a Coolaroo chemical company $40,000. An inspection found a dangerous goods storage breach, and the improvement notice gave two weeks to do four things: secure the dangerous goods on pallets, risk assess the pallet racking, write a safe work procedure for it, and set up a racking inspection schedule with defect reporting and tag out.

Read that list again. It is a management system build, almost word for word. Re-inspection two weeks later found it had not been done. It ultimately took five months.

Eleven days after that re-inspection, a further inspection found four 205 litre drums of a Class 3 flammable liquid stored directly beside IBCs of a Class 8 corrosive. Incompatible goods, no separation. A second improvement notice followed.

The fine split $25,000 for failing to comply with the first notice and $15,000 for the segregation failure. The paperwork failure drew about one and a half times the penalty of the chemical hazard itself.

Three visits, the same finding

In the second matter, a Stawell electrical contractor was convicted and fined $30,000 over a solar installation. Four workers were in harnesses on an industrial roof, none attached to an anchor point, 5.1 metres above the ground. Guard rails were on the wrong side and not to the manufacturer’s specification. The job safety analysis had been drawn on the back of a scrap sheet of paper, and there was no safe work method statement for high risk construction work.

A prohibition notice was issued and the site was compliant within four days. That is a fast correction by any measure.

The investigation then found three prior WorkSafe visits across 2022 and 2023, each finding the same missing edge protection, two of them also finding no safe work method statement. The Court noted that three interactions over eighteen months “should have put AGS on notice as to what is required and expected”.

Fixed in four days, three separate times, and nobody asked why the same finding kept arriving.

What this means for your register

That second case is clause 10.2 in a sentence. The clause does not stop at fixing the problem. It asks you to determine whether similar nonconformities exist or could occur, and to review the effectiveness of the action you took. A correction that works three times and has to be repeated a fourth is evidence the corrective action was never done.

So when a notice arrives, enter it in the register as a nonconformity like any other. Record the requirement it breaches, the correction, the root cause, the corrective action, and the effectiveness review. An auditor who sees regulator notices actioned and filed, but never analysed, has found the same gap the Court did.

If your notice relates to plant or equipment, the racking remedy above maps directly onto a plant risk assessment. If you operate in New South Wales, note that codes of practice are now enforceable there, which changes what an inspector can hold you to. For the safety system itself, see ISO 45001.

What to include in a nonconformance report

You don’t need special software: a register with the right fields does the job. A good nonconformance record captures:

  • Reference and date: so it can be tracked and trended.
  • Description: what happened, where, and the requirement it breaches.
  • Source: internal audit, customer complaint, supplier issue, certification audit.
  • Correction taken: the immediate fix and who did it.
  • Root cause: the outcome of your “5 whys” or equivalent analysis.
  • Corrective action: what changed in the process, with an owner and a due date.
  • Verification of effectiveness: evidence it worked, checked after enough time has passed.
  • Status: open, in progress, or closed.

What auditors look for in your corrective action records

At a certification or surveillance audit, your corrective action register is one of the first things reviewed. It shows whether the system genuinely self-corrects. Auditors typically check that nonconformities are being raised at all (an empty register is a red flag, not a badge of honour), that root causes are recorded rather than restatements of the problem, that actions were verified as effective before closure, and that trends feed into internal audits and management review. A handful of well-worked records beats a hundred rows of “retrained the operator, closed”.

How to reduce nonconformities

The businesses with the fewest nonconformities aren’t lucky. They have simple, well-understood processes, keep records as they go, run honest internal audits, and act on small issues before they grow. Treat every nonconformity as a free improvement, not a black mark. Each one you close permanently is a line taken straight off your cost of poor quality. As the old quality quote goes: give your people better processes and get better performance from your people.

When corrective actions become risk controls

Root cause analysis is the bridge between a nonconformity and the right corrective action. It tells you whether the situation was a true one-off or something that could recur. Where it could happen again, an effective corrective action usually includes ongoing controls that reduce the likelihood or the consequence of it recurring. At that point the corrective action is no longer a one-time fix: it becomes a control in your organisation’s risk management framework, the “risk-based thinking” required by ISO 9001 clause 6.1, which is most robust when it follows a recognised approach such as ISO 31000. In short, your corrective actions feed your risk controls, and good risk thinking helps prevent the next nonconformity.

How Streamline can help

We help businesses build straightforward corrective-action processes that satisfy ISO 9001 without drowning in paperwork, and we run independent internal audits that find issues early, while they’re still easy to fix. Working towards certification? Start with our guide to ISO 9001 certification in Australia.

Nonconformance & corrective action: FAQs

What’s the difference between a correction and a corrective action?

A correction fixes the immediate problem; a corrective action removes the root cause so it doesn’t happen again.

Do all nonconformities need corrective action?

No. The test is recurrence: if the root-cause scenario has happened before, or could happen again, it needs corrective action. A genuine one-off, low-risk issue may only need a correction, and root cause analysis is what tells you which it is.

What is a major nonconformity at a certification audit?

A significant or systemic failure: for example, a required process missing entirely. It must be resolved and verified before the certificate can be issued or maintained.

Does ISO 9001 still require preventive action?

Not as a separate clause. Since the 2015 revision, prevention is handled through risk-based thinking (clause 6.1). You identify risks up front and build controls into your processes, and your planning records are the evidence.

Speak with an experienced ISO auditor

Email hello@streamline.business or call us. You’ll deal directly with an experienced ISO auditor who’ll tailor a practical approach to your business. You’re also welcome to get in touch via our contact page.

General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • Quality inspector in an Australian machining workshop checking a machined aluminium component against a tablet record, with CNC machines and Australian flags behind
    How Much Does ISO 9001 Certification Cost in…
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • Tilt-shift miniature naval shipyard inspection bay with a submarine hull section on keel blocks and workers in hi-vis checking tagged components in a parts quarantine area
    ISO 19443: The Nuclear Supply Chain Standard, and…
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • ISO 9001 quality management inspection
    ISO 9001 Quality Management Consulting, Audits & Mentoring
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • Manager reviewing a budget spreadsheet
    ISO 27001 Certification Cost & Timeline in Australia…

Filed Under: Articles Tagged With: #Continualimprovement, #iso9001, #qms

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire