An ISO 27001 nonconformity is an auditor’s formal record that a requirement of the standard is not being met, and the grade attached to it decides whether you leave the audit with a certificate or with a follow-up visit on the calendar. Most teams meet their first one during a Stage 2 audit or an internal audit, react by writing another policy, and then watch the same finding come back a year later. This guide explains how findings are classified, what your certification body expects after the closing meeting, and how to write a corrective action that closes on the first attempt.
What Counts as an ISO 27001 Nonconformity
An ISO 27001 nonconformity is the non-fulfilment of a requirement. In an information security management system (ISMS) audit, “requirement” is broader than most people expect, covering three sources:
- Clauses 4 to 10 of the standard — the management system requirements, from context and leadership through to corrective action.
- Annex A controls you declared applicable in your Statement of Applicability. ISO/IEC 27001:2022 lists 93 controls across four themes: 37 organizational, 8 people, 14 physical and 34 technological.
- Your own documented ISMS. If your access control procedure promises quarterly reviews and you did two last year, that is a finding — even though the standard never mentions a quarterly cadence.
That third source catches most organizations: an ISO 27001 nonconformity raised against your own procedure rather than the standard. Over-specified documents create obligations auditors will happily sample against.
Clause 10.2 sets out what happens next: react and correct, deal with the consequences, evaluate whether action is needed to eliminate the cause, implement it, review its effectiveness, and change the ISMS if necessary. You must also retain documented information on the nature of the nonconformities, the actions taken and the results. Note the numbering — in the 2022 edition continual improvement moved to 10.1 and nonconformity and corrective action to 10.2, reversing the 2013 layout. Edition details are on the official ISO/IEC 27001 standard page.
Not everything an auditor writes down is an ISO 27001 nonconformity. Audit reports usually carry three kinds of entry:
- Nonconformity — a requirement is not met. Corrective action is mandatory.
- Observation — a weakness that is not yet a breach. No corrective action is required, but ignoring it for two cycles tends to convert it into a finding.
- Opportunity for improvement (OFI) — a suggestion. Purely advisory.
Major vs Minor ISO 27001 Nonconformity
Whether an ISO 27001 nonconformity is graded major or minor is the most consequential line in the report. A minor finding is an isolated lapse inside a process that otherwise works. A major means the process is absent, broken systemically, or the failure puts information at real risk.
| Aspect | Minor nonconformity | Major nonconformity |
|---|---|---|
| What it means | A single or isolated lapse in a process that is otherwise designed and operating | A required element is absent, a process has failed systemically, or a pattern of minors shows the system is not working |
| Typical example | Two of twenty leavers had access revoked late; one management review agenda missed a required input | No internal audit programme at all; a risk assessment that exists on paper but was never performed; the Statement of Applicability does not match the risk treatment plan |
| Effect on initial certification | Certificate can normally still be recommended, with the finding closed afterwards | Blocks the certification decision until closure is submitted and accepted |
| Effect at surveillance | Tracked and reviewed at the next visit | Can trigger a special visit and, if unresolved, suspension of the certificate |
| What the certification body wants | Correction plus a stated cause and planned corrective action | Correction, documented root cause analysis, corrective action, and objective evidence of implementation |
| How closure is verified | Usually a desk review of submitted evidence | Often a follow-up or special audit, on site or remote |
| Typical closure window | Around 30 to 90 days, agreed with the auditor | Shorter and firmer — commonly a plan within 14 to 30 days and evidence inside 60 to 90 days |
Auditors have discretion and they use it. A cluster of related minors in the same clause is often escalated to one major, because together they show the process is not controlled. The reverse also happens: a serious-looking gap you had already detected, logged and started fixing is frequently graded down, because your ISMS demonstrably worked.
The Clock That Starts at the Closing Meeting
Once an ISO 27001 nonconformity is issued, you are on a schedule. Missing a date is itself a problem — certification bodies escalate silence far faster than bad news.
| Stage | Typical window | What you submit |
|---|---|---|
| Classification and agreement | At the closing meeting | Nothing yet — but this is your one chance to query wording or scope |
| Correction (containment) | Immediately to 14 days | Evidence the specific instance has been fixed |
| Root cause and corrective action plan | 14 to 30 days | Cause analysis, planned actions, named owners, target dates |
| Evidence of implementation | 30 to 90 days | Records, screenshots, logs, updated documents |
| Certification body verification | After submission | Desk review, or a follow-up audit for majors |
| Effectiveness check | Next internal audit or surveillance visit | Evidence the cause has not recurred |
For initial certification, most bodies want Stage 2 findings resolved within roughly 90 days of the last audit day. Past that, a partial or full re-audit may be required, which costs real money. Read your own report — its dates override any rule of thumb, including this one.
Six Findings That Generate Most ISO 27001 Nonconformity Reports
Across certification bodies, the same handful of gaps come up again and again:
- Statement of Applicability out of step with the risk treatment plan. Controls marked applicable with no corresponding treatment, or exclusions with no justification. Clause 6.1.3 makes the SoA mandatory, and auditors read it line by line.
- An internal audit programme that does not cover the whole ISMS. Clause 9.2 expects the full system to be audited across the cycle. Auditing the same three easy clauses every year is a finding. Our guide to the ISO 27001 internal audit walks through building a programme that survives scrutiny.
- Management reviews missing required inputs. Clause 9.3 lists what must be considered. A thirty-minute meeting with no minutes covering audit results, risk status, objectives and interested-party feedback will be written up.
- A risk assessment performed once and never repeated. Risk assessment has to run at planned intervals and when significant changes occur — not only in the month before the audit.
- Access reviews and the leaver process without evidence. The policy exists, the reviews are claimed, but no signed records exist. If it is not recorded, the auditor treats it as not done.
- Supplier controls documented but not applied. A supplier security policy with no evidence of assessment, contract clauses or monitoring for the actual vendors handling your data.
Every item on that list is detectable in advance — which is the argument for treating your internal audit as a rehearsal rather than a formality, and for reviewing gaps months before a surveillance audit.
How to Close an ISO 27001 Nonconformity on the First Attempt
Certification bodies reject corrective action submissions constantly, almost always for the same reasons. A response that gets accepted has five parts.
1. Separate correction from corrective action. Correction fixes the instance the auditor found — you revoke the three accounts. Corrective action fixes the reason those accounts survived — the offboarding checklist had no IT sign-off step. Submitting only the correction is the most common reason a response bounces.
2. Do a real root cause analysis. “Human error” is not a root cause; it is where the analysis stops too early. Ask why until you reach something you can change: a missing control point, an unclear owner, a process that depended on one person remembering. Five Whys or a simple cause-and-effect diagram is enough — the technique matters less than the evidence that you actually did it.
3. Check whether the same cause exists elsewhere. Clause 10.2 asks whether similar nonconformities exist or could potentially occur. If the auditor sampled one system and found the gap, look at the other systems yourself and say what you found. This single step converts a defensive response into a credible one.
4. Make actions specific, owned and dated. Each needs a named person, a date and a deliverable someone else could verify. “Improve awareness” is unverifiable. “Add an IT revocation step to the offboarding form, owned by the HR Operations Lead, live by 15 October, evidenced by the next five leaver records” is.
5. Plan the effectiveness check. Say how and when you will confirm the cause is gone — a targeted sample of leavers at the next internal audit, for instance. Closing an ISO 27001 nonconformity without one is how the same finding reappears at recertification.
Mistakes That Turn a Minor Finding Into a Major One
Escalation is usually self-inflicted. Five habits reliably turn a manageable ISO 27001 nonconformity into a major one:
- Arguing the classification after the closing meeting. Raise factual errors immediately and politely, with evidence. Once the report is issued, energy spent disputing it is energy not spent fixing it.
- Fixing only what was sampled. Auditors sample. If they found two late revocations in a sample of twenty, they assume the rest of the population looks similar until you prove otherwise.
- Writing a new policy as the whole answer. A new document is rarely a root cause fix, and it adds another commitment you will be audited against next year.
- Going quiet on a deadline. If you will miss a date, say so before it passes and propose a new one. Bodies accommodate reasoned delays and escalate unexplained ones.
- Closing internal findings without verification. A finding closed by the person who caused it, with no independent check, is itself a clause 10.2 problem waiting to happen.
ISO 27001 Nonconformity: Frequently Asked Questions
Can you still get certified with an open minor ISO 27001 nonconformity?
Usually yes. Most certification bodies will recommend certification with minor findings outstanding, provided you submit an accepted correction and corrective action plan within the agreed window. Majors are different — they generally have to be closed and verified before the certificate is issued.
How many minor findings add up to a major?
There is no fixed number. Escalation is driven by pattern, not arithmetic. Several minors against the same clause, or the same finding repeated from a previous audit, signal that the management system is not correcting itself, and that is what turns them into a major.
What is the difference between an observation and a nonconformity?
An observation flags a weakness or a trend without asserting that a requirement has been breached, so no corrective action is mandatory. An ISO 27001 nonconformity asserts a requirement is not met and obliges you to respond under clause 10.2. Treat repeated observations as early warnings.
Can a major nonconformity cost you your certificate?
It can. At surveillance or recertification, an unresolved major typically leads to suspension, and a suspension that is not lifted within the body’s stated period leads to withdrawal. Meeting the agreed dates is what prevents that, not the severity of the original finding.
Who is allowed to close an internal nonconformity?
Someone independent of the work that produced it. In a small company that need not mean a separate department, but the reviewer must not be the person who performed the corrective action. Record who verified closure and on what evidence.
Getting Ahead of the Next Finding
Nearly every ISO 27001 nonconformity traces back to a gap between what your documentation promises and what your records prove. The fastest route to fewer findings is an ISMS that is realistic about cadence, owners and evidence, plus an internal audit honest enough to test it. If you are rebuilding documentation after a finding, the ISO 27001 Toolkit gives you 175 editable templates — policies, procedures, registers and audit records aligned to the 2022 edition — for $99, so you edit rather than start from a blank page.
For the wider picture on how the assessment cycle fits together, start with our guide to ISO 27001 certification.