Few things cause as much confusion in a Quality Management System as non-conformities. The good news is that, properly understood, they're the exact opposite of a failure: they're the tool that proves the system works.

What a non-conformity is

A non-conformity is the failure to meet a requirement — it can be a requirement of ISO 9001 itself, a legal requirement, an internal requirement your company has set for itself, or something the customer expected and didn't get. Clause 10.2 of the standard (Nonconformity and corrective action) governs how it must be managed.

Major, minor, and observation: not the same thing

The steps to manage a non-conformity properly

  1. React and fix the immediate issue. First you contain and correct the specific problem — this "correction" is not yet the corrective action.
  2. Analyze the root cause. This is the step most often skipped, and the most important one. It's not enough to ask "what happened?" — you have to ask why it happened, and why that happened, until you reach the underlying cause (tools like "5 whys" help a lot here).
  3. Check for similar cases. If this non-conformity could happen here, could it also be happening in another process or site that hasn't been detected yet?
  4. Define the corrective action. An action aimed at the root cause, not just the symptom — different from the one-off correction in step 1.
  5. Verify that the action worked. After a reasonable amount of time, check whether the problem has recurred. If it isn't verified, the non-conformity isn't really closed.
  6. Document everything. The standard requires keeping evidence of the correction, the analysis, and the corrective action — not as red tape, but as proof the cycle genuinely closed.

Most common mistakes

Analyze the root cause with AI's help

In EcoNiora's Non-Conformities module you can describe the problem in your own words and ask the AI to propose a root-cause analysis and a corrective action — always based on what you describe, never inventing facts.

Request access →