ISO 27001:2022 Clause 10.2 Nonconformity and Corrective Action Explained

ISO 27001 Clause 10.2 Nonconformity and Corrective Action

ISO 27001 Clause 10.2 Nonconformity and Corrective Action is about effectively managing when things go wrong, correcting it and taking steps to make sure it does not happen again.

In this guide you will learn how to implement ISO 27001 Clause 10.2 and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.

Key Takeaways

What is ISO 27001 Clause 10.2?

A nonconformity is a deviation from the requirements of your ISMS. This could be anything from a broken process, a missed security policy, an incident, or a failed audit finding.

It is important because things change and no management system is 100% effective 100% of the time, so you need a process to handle when things inevitably go wrong.

Purpose and Definition

The purpose of ISO 27001 Clause 10.2 Nonconformity and Corrective Action is to identify when things are not operating as expected and to make sure that when things go wrong they are corrected.

The requirement is that when a non conformity happens that the organisation:

  • take action to control and correct it
  • deal with the consequences
  • review the nonconformity
  • determine the causes of the nonconformity
  • determine if similar nonconformities exist, or could potentially occur
  • implement any action needed
  • review the effectiveness of any corrective action taken
  • make changes to the information security management system, if necessary
  • keep documents and evidence for audit

ISO 27001 Clause 10.2 Training Video

In this free training video for ISO 27001 Clause 10.1 you will learn how to implement it and pass your audit.

ISO 27001 Non-conformity and corrective action process explained

Non-conformity and corrective action are processes that fall within the scope of incident management. This framework can be structured as a Level 2 incident management process or as a dedicated sub-process. The critical first step is to identify that an event has a potential or actual impact on information security. Once this is established, you can invoke your formal processes for managing the non-conformity.

Step RefProcess StepAction RequiredGoal / Deliverable
1React to the NonconformityTake immediate action to control and correct the issue (Correction) and mitigate immediate consequences.Goal: Containment. Deliverable: Incident Log updated with immediate actions.
2Evaluate the NonconformityAnalyse what went wrong and why. Decide on the necessary course of action to prevent recurrence.Goal: Root Cause Identification. Deliverable: Root Cause Analysis (RCA) report.
3Manage (Correct) the NonconformityImplement the planned corrective actions. This may involve updating the ISMS, changing processes, or patching systems.Goal: Remediation. Deliverable: Updated policies, procedures, or system configurations.
4Verify EffectivenessReview the changes after a set period to ensure they actually worked. Often involves a targeted internal audit.Goal: Verification. Deliverable: Audit report or re-test evidence confirming closure.
5Document EvidenceRecord the nature of the nonconformity, actions taken, and verification results as formal evidence for the auditor.Goal: Compliance. Deliverable: Fully completed Corrective Action Log entry.

The ISO 27001 continual improvement process sets out how you make fundamental changes to prevent nonconformities from re occurring. The continual improvement process is include the ISO 27001 Toolkit but to see what it should include take a look at the following contents table:

Continual Improvement Process Example - Page 1
Continual Improvement Process Example – Page 1
Continual Improvement Process Example - Page 2
Continual Improvement Process Example – Page 2
Continual Improvement Process Example - Page 3
Continual Improvement Process Example – Page 3

What are minor nonconformities and major nonconformities?

While a non-conformity is simply a failure to meet a requirement, auditors typically classify them into two main types: minor nonconformities and major nonconformities.

ISO 27001 has built in the distinction between things that on the whole work but on a couple of times it was found it did not work (minor nonconformities) and things that just do not work at all and may even not be implemented (major nonconformities).

This classification is a convention used during audits to determine the severity of the issue and the potential impact on certification.

FeatureMinor NonconformityMajor Nonconformity
DefinitionA single, isolated lapse or partial failure that does not impact the overall effectiveness of the ISMS.A significant failure indicating a systemic breakdown or total absence of a required control/process.
Impact on CertificationCertification Granted: You can still achieve/maintain certification, provided a Corrective Action Plan is accepted.Certification Blocked: The audit is failed. Certification is delayed until the issue is fully resolved and verified on-site.
Audit Severity“It mostly works, but failed once.” (Localised issue)“It doesn’t work at all,” or “You aren’t doing it.” (Systemic issue)
Real-World Examples
  • 1 out of 10 staff missed security training.
  • 1 out of 15 laptops had antivirus disabled.
  • A single document was found outdated.
  • No Disaster Recovery tests performed despite policy.
  • Policies exist but are universally ignored.
  • A previous nonconformity was ignored and recurred.

Minor nonconformity

A minor nonconformity is a single, isolated lapse or a partial failure to meet a requirement that does not significantly impact the overall effectiveness of your management system (e.g., ISO 27001 or ISO 9001). It’s a localised issue that does not compromise the system’s ability to achieve its objectives.

An organisation can still achieve or maintain its certification with minor nonconformities, but it must have a clear plan and timeline for corrective action

Minor nonconformity examples

Here are some examples that I have seen:

  • One person in ten has not done their mandatory information security training
  • One person out of fifteen was seen to have anti virus disabled
  • A document in the management system was found to have not been updated

Major nonconformity

A major nonconformity is a significant failure to meet a requirement that has or could have a serious impact on the management system’s effectiveness. It indicates a systemic or critical breakdown that could compromise the company’s ability to meet its objectives, customer expectations, or regulatory requirements.

A major nonconformity will result in a failed audit and a delay in certification until the issue is fully resolved and verified by the auditor.

Major nonconformity examples

  • You said you do disaster recovery tests but in fact you have not
  • You have policies and procures but no one follows them
  • A previous nonconformity was not addressed, and the issue has recurred.

Implementation Guide

A nonconformity is usually identified by audit or the occurrence of incidents.

For Incidents

Our first step is to handle the incident and to manage the consequences of that incident. We document everything as we go and best practice would be to use and incident management system or a help desk system. Many of these come with capability out of the box and at worst they require some minor tweaks.

This ensures we have a record of the incident and what happened.

Once this step has completed we then do an assessment of what happened. We are looking to see if this was a one off or if there is potential that the incident could happen either again or elsewhere. 

We take appropriate actions to ensure that this does not and cannot occur again. This may include risk management and accepting that it may occur, if the cost of action is too high. That would require us to follow the risk management process and seek to get approval and sign off of the management review team. 

We find the use of an incident and corrective action log is ideal for managing this process. The benefits of having an effective log that meets the requirements of the ISO 27001 standard whilst also efficiently handling the process are worth it.

For Audits

When an audit results in a nonconformity we follow as similar process to handling incidents. The non conformity is recorded on the incident and corrective action log. A root cause analysis is conducted. Remediation is implemented under the guidance of the management review team.

Reporting

The Management Review Team provides the management oversight and decision making body. Be sure to report to the meeting and minute the meeting minutes.

How to implement ISO 27001 Clause 10.2

Based on my experience and what I have seen work well the following are the best practice implementation steps to implement ISO 27001 Nonconformity and Corrective Action.

Implementing ISO 27001 Clause 10.2 requires a structured approach to identifying, fixing, and preventing issues. Follow these 10 steps to implement a robust Nonconformity and Corrective Action process that meets the requirements of the Lead Auditor and ensures your ISMS continually improves.

1. Implement a Continual Improvement Policy

We need an ISO 27001 Continual Improvement Policy. Policies are statements of what we do, not how we do it (which is covered in the process documents), but the policy sets out your approach to how we handle nonconformities and corrective actions.

  • Purpose: To define the rules of engagement for fixing problems.
  • Auditor Check: Ensure this policy is approved by senior management.
ISO 27001 Continual Improvement Policy Template

The continual improvement policy  sets out your approach to how you handle nonconformities and corrective actions.

2. Implement an Incident and Corrective Action Log

Implement and use the ISO 27001 incident and corrective action log that includes the required fields and allows you to manage incidents and corrective actions. This is the main tool for the management of nonconformity.

  • Requirement: The log must capture the issue description, root cause, action taken, and verification of effectiveness.
  • Tip: Keep this log centralised; an empty log is often a red flag for auditors.
ISO 27001 Incident and Corrective Action Log Template

Implement and use an incident and corrective action log that includes the required fields and allows you to manage incidents and corrective actions. This is the main tool for the management of nonconformity.

3. Implement an Incident Management Process

The incident management process sets out how you deal with incidents. Incidents are one of the major sources of identifying nonconformities. You must have a clear channel (e.g., Service Desk or email) for staff to report issues.

  • Integration: Ensure your daily operational ticketing system links to your formal ISMS log.

The incident management process is include the ISO 27001 Toolkit but to see what it should include take a look at the following contents table:

Security and Incident Management Process Example Page 1
Security and Incident Management Process Example Page 1
Security and Incident Management Process Example Page 2
Security and Incident Management Process Example Page 2
Security and Incident Management Process Example Page 3
Security and Incident Management Process Example Page 3

4. Implement a Continual Improvement Process

The ISO 27001 continual improvement process sets out how you make fundamental changes to prevent nonconformities from reoccurring. This moves you beyond simple “bug fixing” to systemic enhancement.

  • Goal: To demonstrate that the ISMS is evolving and maturing over time.

5. Identify a Nonconformity

A nonconformity is usually identified by audit or the occurrence of incidents. It is defined as the non-fulfilment of a requirement, whether that be a standard clause, a control, or an internal policy.

  • Sources: Staff reports, failed backups, access control failures, or internal audit findings.

6. Process Nonconformities from Incidents

Our first step is to handle the incident and to manage the consequences of that incident (Correction). We document everything as you go and best practice would be to use an incident management system or a help desk system. Many of these come with capability out of the box and at worst they require some minor tweaks.

  • Assessment: Once the immediate fix is done, we assess what happened. We look to see if this was a one-off or if there is potential that the incident could happen again or elsewhere.
  • Action: We take appropriate actions to ensure that this does not and cannot occur again. This may include risk management and accepting that it may occur if the cost of action is too high (requiring Management Review sign-off).
  • Tool: We find the use of the ISO 27001 incident and corrective action log is ideal for managing this process.

7. Process Nonconformities from Audits

When an audit results in a nonconformity, we follow a similar process to handling incidents. The nonconformity is recorded on the incident and corrective action log immediately.

  • Remediation: Remediation is planned and implemented under the guidance of the management review team.
  • Evidence: Auditors will look for the “audit trail” from the finding in the report to the entry in the log.

8. Conduct Root Cause Analysis

For every significant nonconformity, a root cause analysis is conducted. You cannot simply fix the symptom; you must evaluate the need for action to eliminate the cause so it does not recur.

  • Method: Use techniques like the “5 Whys” to dig deeper than “human error.”

9. Verify Effectiveness

You must review the effectiveness of any corrective action taken. This usually involves a re-test or a specific check after a defined period (e.g., 3 months) to ensure the issue has not returned.

  • Closure: A nonconformity can only be marked as “Closed” in the log once effectiveness is verified.

10. Report to Management Review

The ISO 27001 Management Review Team provides the management oversight and decision-making body. Be sure to report to the meeting and minute the meeting minutes regarding all open and closed nonconformities.

  • Requirement: Clause 9.3 explicitly requires reporting on “nonconformities and corrective actions.”
Fay-Barker-High-Table
What is ISO 27001 Clause 10.2 Nonconformity and Corrective Action?

The ISO 27001 standard requires that the organisation shall manage when things go wrong, manage the consequences of things going wrong, identify why it went wrong and put in place measures to stop it from happening again.

How do I evidence I meet the requirement of ISO 27001 Clause 10.2 Nonconformity and Corrective Action?

You evidence compliance to the ISO 27001 Clause 10.2 Nonconformity and Corrective Action by being able to demonstrate that you identify when things go wrong, put things right, identify why it went wrong and put in place measures so it does not happen again.

Where can I download ISO 27001 Clause 10.2 Nonconformity and Corrective Action templates?

You can download ISO 27001 Clause 10.2 Nonconformity and Corrective Action templates in the High Table ISO 27001 Toolkit.

Do I report non conformities to senior management?

Yes. Senior management and leadership are informed of non conformities. This is usually via the management review team meeting.

Do I do a root cause analysis on non conformities?

Yes. Non conformities require a root cause analysis to identify why they happened and to help to identify what can be done to prevent it from happening again.

Can I classify non conformities?

You can classify non conformities to help you to prioritise the order in which to tackle them and the recommended actions you should take. This would be aligned with the risk management process.

Can a corrective action be that I do nothing?

Technically yes but by doing nothing you are accepting risk and therefore you would follow your risk management process with sign off and acceptance by the management review team.

How do I report a non conformity?

Non conformities are reported via the incident management process.

Can I pass ISO 27001 certification with non conformities?

Yes you can pass the ISO 27001 certification if you have non conformities as long as they are being effectively managed and reported.

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigour with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Stuart Barker - High Table - ISO27001 Director
  • MSc Security
  • ISO 27001 Lead Auditor
  • 30+ Years Exp
  • Ex-GE Leader
Shopping Basket
Scroll to Top