Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO clause 10 improvement explained — Annex SL harmonized structure

ISO Clause 10: Improvement Explained

ISO Clause 10: Improvement Explained — this guide is part of our series on the ISO harmonized structure, the shared clause framework behind most ISO management system standards.

Most ISO management system standards share the same skeleton. It is set out in Annex SL, Appendix 2 of the ISO/IEC Directives Part 1 — the harmonized structure — and it gives every adopting standard the same ten clauses, the same core text and the same defined terms. Learn clause 10 once and you have learned it for ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 22301, ISO 42001 and the rest.

What ISO clause 10 actually asks for

Clause 10 closes the loop. It is short, it is where nonconformity is handled, and it is the one
clause where the numbering genuinely differs between standards — so check yours
before citing a sub-clause in a document.

The numbering differs — know which one you are on

  • ISO 9001:2015 — 10.1 General,
    10.2 Nonconformity and corrective action, 10.3 Continual improvement.
  • ISO 27001:2022 — 10.1
    Continual improvement, 10.2 Nonconformity and corrective action. Continual improvement moved to the
    front and there are only two sub-clauses.
  • ISO 45001:2018 — 10.1
    General, 10.2 Incident, nonconformity and corrective action, 10.3 Continual improvement. Note that
    incidents are handled in the same sub-clause as nonconformities.

Cross-referencing the wrong sub-clause number in your own procedures is a small error that reads as
carelessness in an audit. It is worth a five-minute check across your document set.

Nonconformity and corrective action

When a nonconformity occurs you must react to it and, as applicable, take action to control and
correct it and deal with the consequences. Then evaluate the need for action to eliminate the causes so
it does not recur or occur elsewhere — by reviewing the nonconformity, determining its causes, and
determining whether similar nonconformities exist or could potentially occur. Implement any action
needed, review effectiveness, and make changes to the system if necessary.

Documented information must be retained on the nature of the nonconformities and actions taken, and
on the results of any corrective action.

Correction is not corrective action

This is the most common conceptual error in the entire standard. Correction fixes
the instance: you re-issue the wrong document, you patch the server. Corrective action
eliminates the cause so it does not happen again: you change the approval workflow, you fix the patch
management process. An audit finding closed with only a correction will be reopened, because clause 10
explicitly requires evaluation of the need to eliminate causes.

Continual improvement

Continually improve the suitability, adequacy and effectiveness of the management system. The
standard does not prescribe a method. Evidence usually comes from objectives being raised over time,
improvement actions arising from management review, and trends in performance data.

Documented information ISO clause 10 expects

  • A nonconformity and corrective action log recording nature, cause, action and effectiveness review
  • Root cause analysis records — five whys, fishbone, or whatever method you use
  • An improvement register or equivalent evidence of continual improvement

Common audit findings against ISO clause 10

  • Correction recorded as corrective action. No cause determined, no systemic fix.
  • Effectiveness never reviewed. Actions closed on completion rather than on evidence
    they worked.
  • No check for similar nonconformities elsewhere, which the clause explicitly
    requires.
  • Continual improvement asserted but not evidenced. Static objectives year on year.

Nonconformity and corrective action, done properly.

Toolkits include a corrective action log that separates correction from corrective action, root cause analysis templates and an effectiveness review step built into the workflow.

Explore the toolkit →

Which standards ISO clause 10 applies to

The harmonized structure covers the great majority of ISO management system standards, including ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 22301, ISO 20000-1, ISO 22000, ISO 42001, ISO 37301, ISO 50001, ISO 55001, ISO 41001, ISO 21001, ISO 28000 and ISO 39001. Adopting standards may add sub-clauses of their own, but they do not renumber the ten top-level clauses.

Two exceptions worth knowing. ISO 13485:2016 deliberately did not adopt the harmonized structure — its technical committee kept the older clause 4 to 8 layout to stay closer to medical device regulation, so the clause numbers on this page do not map to it. ISO/IEC 17025 and ISO 15189 are conformity assessment standards for laboratories rather than management system standards in the Annex SL sense, and they use their own structure.

Toolkits that implement ISO clause 10

Each of these standards uses the harmonized structure, so clause 10 applies to all of them. The toolkit for each ships the documented information the clause requires.

ISO 9001 · ISO 14001 · ISO 45001 · ISO 27001 · ISO 22301 · ISO 42001 · ISO 20000 · ISO 22000 · ISO 27701 · ISO 37301 · ISO 50001 · ISO 55001 · ISO 41001 · ISO 21001 · ISO 28000 · ISO 39001

ISO clause 10: frequently asked questions

What is the difference between correction and corrective action?

Correction fixes the instance. Corrective action eliminates the cause so it does not recur. Clause 10 requires you to evaluate the need for the latter, not just perform the former.

Why do clause 10 sub-clause numbers differ between standards?

Because adopting standards were published at different times and some reordered the sub-clauses. ISO 27001:2022 has continual improvement at 10.1; ISO 9001:2015 has it at 10.3.

References for ISO clause 10

Beyond ISO clause 10: the rest of the series

Clauses 4 to 10 are the harmonized structure shared by most ISO management system standards. Each guide in this series covers one clause across every standard that uses it.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.