# Nonconformity and corrective action procedure

Source: https://aestech.com.au/policy-templates/#nonconformity-and-corrective-action-procedure
Markdown URL: https://aestech.com.au/policy-templates/nonconformity-and-corrective-action-procedure.md

Handles clause 10.1 end to end: raising nonconformities, containment, root cause, corrective action and effectiveness checks.

Frameworks: ISO 27001

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This procedure defines how [Company Pty Ltd] reacts to nonconformities in the ISMS, corrects them, addresses their causes so they do not recur, and records the results, per ISO/IEC 27001:2022 clause 10.1.

2. Scope
Applies to any failure to meet a requirement of ISO/IEC 27001, our own policies and procedures, legal or contractual security obligations, or planned control operation. Sources include internal and external audits, incidents, monitoring results, supplier reviews, and staff reports.

3. Raising a nonconformity (NC)
3.1 Anyone may raise an NC via [ticketing system / form / email to ISMS Manager].
3.2 Each NC record states: what requirement was not met, the objective evidence, where and when it was found, and who raised it.
3.3 The [ISMS Manager] triages within [2] business days, assigns a unique ID (NC-[YYYY]-[nn]), a severity ([major/minor]) and an owner.

4. Immediate correction and containment
4.1 The owner takes action to control and correct the nonconformity and to deal with its consequences, for example disabling an exposed account, restoring a control, or notifying affected parties.
4.2 If the NC involves a security incident, invoke the [Incident Response Plan] in parallel; the NC record links to the incident record.

5. Root cause analysis
5.1 For every major NC, and for minor NCs at the owner discretion or where a pattern exists, evaluate the need for action to eliminate the cause.
5.2 Use a structured method such as [5 Whys / fishbone analysis], and check whether similar nonconformities exist or could occur elsewhere in the ISMS.
5.3 Record the root cause, distinguishing symptom (what happened) from cause (why the system allowed it).

6. Corrective action
6.1 Define actions proportionate to the effects of the NC, with owner and due date: [major NCs within 30 days, minor within 90 days, or as agreed].
6.2 Update risk assessments, policies, training or the Statement of Applicability where the cause reveals a gap in them.

7. Effectiveness check
After actions complete, the [ISMS Manager] or an independent reviewer verifies, after a suitable operating period of [30 to 90] days, that the NC has not recurred and the control now operates. Ineffective actions reopen the NC.

8. Register and reporting
The [ISMS Manager] maintains an NC register with columns: ID, date raised, source, description, severity, owner, correction, root cause, corrective action, due date, effectiveness check result, closure date. Trends and open items are reported to every management review.

9. Roles and responsibilities
All staff: report suspected NCs. NC owner: correction, root cause, actions. [ISMS Manager]: triage, register, verification, reporting. [Top management]: resources and escalation path for overdue majors.

10. Records
Retain NC records and the register for at least [3] years in [location] as clause 10.1 evidence.

11. Review
Review annually. Owner: [ISMS Manager]. Version: [x.y]. Approved by: [name/role]. Date: [date].
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md