Every business gets the occasional nonconformance: a calibration that lapses, a document at the wrong revision, a late delivery. They’re not a sign of failure; what matters to ISO 9001 is how you respond. This guide explains what a nonconformance is, the difference between correction and corrective action, what auditors expect to see in your records, and how to close one out properly, with examples.

What is a nonconformance in ISO 9001?
A nonconformance (or nonconformity) is any failure to meet a requirement: a requirement of ISO 9001, of your own documented processes, or of a customer or legal obligation. It’s simply a gap between what should happen and what actually happened.
Minor vs major nonconformities
A minor nonconformity is an isolated lapse that doesn’t undermine the system, for example a single overdue calibration. A major nonconformity is a significant or systemic failure, such as a whole clause not being addressed, and must be resolved before certification can proceed. Our guide to ISO 9001 audits explains the full set of audit findings.
Correction vs corrective action
These two are often confused. A correction fixes the immediate problem. A corrective action removes the underlying cause so the problem doesn’t come back. ISO 9001 expects both where they’re warranted. Patching the symptom isn’t enough on its own.
What happened to “preventive action”?
If your last system was built to ISO 9001:2008, you’ll remember preventive action as its own clause, and auditors still get asked where it went. The 2015 revision didn’t abolish it; it promoted it. Prevention now runs through the whole standard as risk-based thinking (clause 6.1): instead of reacting with “preventive actions” after near-misses, you identify risks and opportunities up front and build controls into your processes. If an auditor asks how you do preventive action, your risk assessment and planning records are the answer.
The corrective action process, step by step
- Record the nonconformity: what happened, where and against which requirement.
- Contain and correct: deal with the immediate issue and any product or service affected.
- Analyse the root cause: a distinct, essential step. Ask why it really happened (the “5 whys” is a simple, effective tool). The root cause is what determines the right response.
- Decide whether corrective action is needed: corrective action is warranted when the root-cause scenario has happened before, or could happen again. A genuine one-off may need only the correction.
- Establish the corrective action: change the process, training or controls to remove or control the cause. Where the situation could recur, this usually means putting ongoing controls in place to reduce its likelihood or consequence.
- Verify effectiveness: check the action actually worked and the issue hasn’t recurred.
- Close it out: record the outcome and feed it into your management review.
Examples of nonconformities and corrective actions
| Nonconformity | Correction (immediate) | Corrective action (root cause) |
|---|---|---|
| Calibration certificate expired on a gauge | Re-calibrate the gauge | Add calibration due-dates to a tracked schedule with reminders |
| Customer complaint about a late delivery | Expedite the order and apologise | Review the scheduling process and address the capacity or planning gap |
| A document found at the wrong revision | Replace it with the current revision | Fix document control so only current versions are accessible |
| Internal audit not completed on schedule | Complete the outstanding audit | Resource and re-plan the audit programme with clear ownership |
When the nonconformity comes from a regulator
Clause 10.2 is common text. It is worded the same in ISO 9001, ISO 45001, ISO 14001, ISO 27001 and ISO 42001, so everything above applies whichever standard you are certified to.
That matters most when the nonconformity does not come from your own internal audit. A regulator’s notice is a nonconformity with a statutory deadline and a named remedy attached, arriving from outside your system. Which is exactly why it tends to land in somebody’s inbox rather than in the corrective action register. Two Victorian prosecutions in August 2026 show what that costs.
The close-out was the offence
WorkSafe Victoria fined a Coolaroo chemical company $40,000. An inspection found a dangerous goods storage breach, and the improvement notice gave two weeks to do four things: secure the dangerous goods on pallets, risk assess the pallet racking, write a safe work procedure for it, and set up a racking inspection schedule with defect reporting and tag out.
Read that list again. It is a management system build, almost word for word. Re-inspection two weeks later found it had not been done. It ultimately took five months.
Eleven days after that re-inspection, a further inspection found four 205 litre drums of a Class 3 flammable liquid stored directly beside IBCs of a Class 8 corrosive. Incompatible goods, no separation. A second improvement notice followed.
The fine split $25,000 for failing to comply with the first notice and $15,000 for the segregation failure. The paperwork failure drew about one and a half times the penalty of the chemical hazard itself.
Three visits, the same finding
In the second matter, a Stawell electrical contractor was convicted and fined $30,000 over a solar installation. Four workers were in harnesses on an industrial roof, none attached to an anchor point, 5.1 metres above the ground. Guard rails were on the wrong side and not to the manufacturer’s specification. The job safety analysis had been drawn on the back of a scrap sheet of paper, and there was no safe work method statement for high risk construction work.
A prohibition notice was issued and the site was compliant within four days. That is a fast correction by any measure.
The investigation then found three prior WorkSafe visits across 2022 and 2023, each finding the same missing edge protection, two of them also finding no safe work method statement. The Court noted that three interactions over eighteen months “should have put AGS on notice as to what is required and expected”.
Fixed in four days, three separate times, and nobody asked why the same finding kept arriving.
What this means for your register
That second case is clause 10.2 in a sentence. The clause does not stop at fixing the problem. It asks you to determine whether similar nonconformities exist or could occur, and to review the effectiveness of the action you took. A correction that works three times and has to be repeated a fourth is evidence the corrective action was never done.
So when a notice arrives, enter it in the register as a nonconformity like any other. Record the requirement it breaches, the correction, the root cause, the corrective action, and the effectiveness review. An auditor who sees regulator notices actioned and filed, but never analysed, has found the same gap the Court did.
If your notice relates to plant or equipment, the racking remedy above maps directly onto a plant risk assessment. If you operate in New South Wales, note that codes of practice are now enforceable there, which changes what an inspector can hold you to. For the safety system itself, see ISO 45001.
What to include in a nonconformance report
You don’t need special software: a register with the right fields does the job. A good nonconformance record captures:
- Reference and date: so it can be tracked and trended.
- Description: what happened, where, and the requirement it breaches.
- Source: internal audit, customer complaint, supplier issue, certification audit.
- Correction taken: the immediate fix and who did it.
- Root cause: the outcome of your “5 whys” or equivalent analysis.
- Corrective action: what changed in the process, with an owner and a due date.
- Verification of effectiveness: evidence it worked, checked after enough time has passed.
- Status: open, in progress, or closed.
What auditors look for in your corrective action records
At a certification or surveillance audit, your corrective action register is one of the first things reviewed. It shows whether the system genuinely self-corrects. Auditors typically check that nonconformities are being raised at all (an empty register is a red flag, not a badge of honour), that root causes are recorded rather than restatements of the problem, that actions were verified as effective before closure, and that trends feed into internal audits and management review. A handful of well-worked records beats a hundred rows of “retrained the operator, closed”.
How to reduce nonconformities
The businesses with the fewest nonconformities aren’t lucky. They have simple, well-understood processes, keep records as they go, run honest internal audits, and act on small issues before they grow. Treat every nonconformity as a free improvement, not a black mark. Each one you close permanently is a line taken straight off your cost of poor quality. As the old quality quote goes: give your people better processes and get better performance from your people.
When corrective actions become risk controls
Root cause analysis is the bridge between a nonconformity and the right corrective action. It tells you whether the situation was a true one-off or something that could recur. Where it could happen again, an effective corrective action usually includes ongoing controls that reduce the likelihood or the consequence of it recurring. At that point the corrective action is no longer a one-time fix: it becomes a control in your organisation’s risk management framework, the “risk-based thinking” required by ISO 9001 clause 6.1, which is most robust when it follows a recognised approach such as ISO 31000. In short, your corrective actions feed your risk controls, and good risk thinking helps prevent the next nonconformity.
How Streamline can help
We help businesses build straightforward corrective-action processes that satisfy ISO 9001 without drowning in paperwork, and we run independent internal audits that find issues early, while they’re still easy to fix. Working towards certification? Start with our guide to ISO 9001 certification in Australia.
Nonconformance & corrective action: FAQs
What’s the difference between a correction and a corrective action?
A correction fixes the immediate problem; a corrective action removes the root cause so it doesn’t happen again.
Do all nonconformities need corrective action?
No. The test is recurrence: if the root-cause scenario has happened before, or could happen again, it needs corrective action. A genuine one-off, low-risk issue may only need a correction, and root cause analysis is what tells you which it is.
What is a major nonconformity at a certification audit?
A significant or systemic failure: for example, a required process missing entirely. It must be resolved and verified before the certificate can be issued or maintained.
Does ISO 9001 still require preventive action?
Not as a separate clause. Since the 2015 revision, prevention is handled through risk-based thinking (clause 6.1). You identify risks up front and build controls into your processes, and your planning records are the evidence.
Speak with an experienced ISO auditor
Email hello@streamline.business or call us. You’ll deal directly with an experienced ISO auditor who’ll tailor a practical approach to your business. You’re also welcome to get in touch via our contact page.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











