The first time a team hears the word "nonconformity" in an ISMS audit, the reaction is usually alarm. Will we lose the certification? Was the preparation wasted?
In practice, nonconformities are not unusual. What matters is which kind, and how many. A minor nonconformity corrected within the agreed period does not prevent certification and does not sour the relationship with the certification body. A major nonconformity, by contrast, halts the certification decision itself and pushes the schedule out significantly.
The inconvenient part is that the common patterns are almost always the same ones. They are not obscure clauses of the standard; they are the same structural finding — "the system is not actually being operated" — appearing in different clothes. Which also means that if you know the patterns, you can clear most of them yourself before the audit.
This article sorts nonconformities by severity and by pattern, gives the prevention for each, and walks through corrective action after a finding. For the audits themselves, see What Stage 1 Looks At and What Stage 2 Looks At. For the overall picture, see What Is an ISMS (ISO/IEC 27001)? A Complete Guide for Healthcare Companies.
Disclaimer: This article is general information. Classification of findings, naming, and corrective-action deadlines vary by certification body. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Base decisions on those and on your own body's guidance.
Findings Come in Three Grades
Findings recorded in an audit report generally fall into three grades. Names vary between bodies; the structure does not.
| Grade | Meaning | Effect on certification | Response |
|---|---|---|---|
| Major nonconformity | Part of the management system is not functioning, or no mechanism exists to meet a requirement | The certification decision does not proceed until correction is verified | Root cause analysis and corrective action, usually with an additional verification visit |
| Minor nonconformity | The mechanism exists, but there is an isolated deviation or a gap in records | The decision proceeds once a corrective action plan is submitted and carried out | Corrective action report; effectiveness checked at the next audit |
| Observation / opportunity for improvement | Not a breach of the standard, but improvement is advisable | None | Optional — but leaving it can turn it into a nonconformity next time |
Observations are the most misunderstood. Hearing "this is not a nonconformity" and doing nothing until next year invites a minor nonconformity on the grounds that the condition persisted. Read an observation as "we are letting this go this time, and we will look again."
What separates major from minor
The dividing line is not the seriousness of the finding but whether a mechanism exists at all.
- One employee's training record is missing → the mechanism exists, a single lapse → minor
- Training was never planned or delivered → no mechanism meets the requirement → major
- The internal audit ran but skipped a department → minor
- No internal audit has ever been performed → major
Several minor nonconformities that share one root cause can be aggregated into a judgement that "the system is not functioning" — and become major. Scattered findings of the same type are a warning sign.
The Recurring Patterns
The following are the findings that typically arise in ISMS audits. These are not case studies of particular organisations; they are the general patterns produced by the places where the standard's requirements and day-to-day operation most easily drift apart.
| # | Pattern | Why it happens | Prevention |
|---|---|---|---|
| 1 | Internal audit performed as a formality | The checklist is a column of ticks with no trace of how evidence was examined; the auditee's self-report is transcribed as-is | Record what was inspected (screen, register, log, physical item) as the basis for each judgement. Design on the assumption that an audit report with zero findings itself draws suspicion |
| 2 | Missing training records | Mid-year joiners, returners from leave, and contractors fall outside the target list; completion is only tallied at year end | Tie the target list to HR data so joining and transfer automatically enrol people. Review completion monthly |
| 3 | Risk assessment never updated | The table built in year one stands unchanged; new services, new systems, and reorganisations are not reflected | Write the update triggers into the procedure (annual / new system introduced / major incident / scope change) and record each time a trigger fires |
| 4 | Supplier management not actually performed | Contracts are signed but periodic evaluation never happens, and sub-contracting is not tracked | Maintain a supplier register with a defined evaluation frequency and method. Put prior-approval clauses for sub-contracting in the contract and verify reality annually |
| 5 | Records diverge from practice | The procedure says logs are reviewed quarterly; in reality it is once a year. The procedure is stricter than the organisation | Rewrite the procedure to match reality. Delete or relax rules you cannot keep — a procedure is a promise, not an aspiration |
| 6 | SoA out of step with the procedures | A control marked "applicable" in the Statement of Applicability has no corresponding documented procedure; or an exclusion is justified with a bare "not applicable" | Link each SoA row to the procedure and records that implement it. Ground every exclusion in the risk assessment result |
| 7 | Corrective action is a pledge, not a change | No root cause analysis; the report closes with "we will remind staff" | Trace the event back through the process. Include at least one measure that does not rely on human attentiveness |
| 8 | Management review inputs incomplete | The minutes omit inputs the standard requires — audit results, progress against objectives, changes in risk | Fix the review agenda as a template mapped to the standard's required inputs |
Patterns 1, 3 and 5 tend to surface not immediately after first certification but at the surveillance audits from year two onward. During the build, an external partner is usually alongside; once operation begins, the organisation runs it alone and the checking and updating quietly stop. See Preparing for the Surveillance Audit and Preparing for Recertification in Year Three.
Extra Ground for Healthcare Companies
If you handle medical information, general IT-company preparation is not sufficient. Whether or not your auditor has a healthcare background, including medical information handling in scope invites proportionate scrutiny.
- Can you show, in documents, how responsibility is divided with the hospital? Know immediately whether it sits in the contract, the SLA, or the operating procedure (Demarcating Responsibility)
- How the three-ministry guidelines relate to your ISMS documents. Maintained separately, one set inevitably goes stale (The Three-Ministry Guidelines)
- Handling of production data. Is real data taken into development or test environments — and if so, is there an approval and deletion record?
- Access log retention and review frequency consistent with customer contracts and industry expectations
None of this is readable directly from the clauses, so unless you raise it yourself, the preparation gets missed.
After a Finding Is Raised
The process generally runs as follows; timescales and forms follow your certification body's instructions.
| Step | Content | Common stumble |
|---|---|---|
| ① Establish the facts | Confirm the finding and the requirement it maps to | Arguing on the spot and losing the thread. First ask what evidence produced the judgement |
| ② Immediate correction | Fix the deviation in front of you (produce the missing record, etc.) | Stopping here and never reaching root cause |
| ③ Root cause analysis | Trace back through the process to why the condition arose | Stopping at "the owner forgot." Push down to what in the mechanism failed to detect it |
| ④ Decide and implement corrective action | Change the mechanism so it cannot recur | Adding a sentence to a procedure without adding an operational checkpoint |
| ⑤ Report and verify effectiveness | Submit the corrective action report; the body verifies | Omitting the evidence — the revised documents and records |
For a major nonconformity, evidence that step ④ is complete is normally required. For a minor one, submitting the plan usually lets the decision proceed, with effectiveness checked at the next audit — though this too varies by body. See Writing a Corrective Action Report and Clause 10: Improvement.
On pushing back
If you believe a finding rests on a factual misunderstanding, asking the auditor to review it with evidence in hand is a legitimate step. Do it by presenting the relevant records and establishing the facts, not by arguing. If the finding stands, every certification body has a defined appeals procedure — ask about it while you are still selecting one (Choosing a Certification Body).
Clearing Them Yourself Beforehand
A self-check one to two months before the audit removes most of the typical findings. The point is to set aside time to look with an auditor's eyes, separately from the internal audit.
Records and dates
- Are there records of one actually completed cycle of internal audit and management review, dated before the audit?
- Are training records complete for everyone on the roster, including mid-year joiners and contractors?
- Is the risk assessment's last-updated date later than the most recent organisational or system change?
- Are corrective action reports closed out, including those from the previous audit?
Consistency between documents
- Does every control marked applicable in the SoA have a corresponding procedure?
- Is every exclusion's justification consistent with the risk assessment?
- Do the frequencies stated in procedures match the frequencies evidenced in the records?
- Does the scope statement match the current organisation chart, sites, and services?
Reality
- Do entry logs, access permission lists, and asset registers match what actually exists?
- Do leavers and transferees still have live accounts?
- Is the supplier register current, with evaluation records?
- Can front-line staff explain their own department's rules in their own words?
That last item is easy to dismiss, but the on-site audit verifies operation through interviews. Staff who do not know what the document says is, for audit purposes, a system that is not being operated.
Conclusion
- Findings come in three grades — major, minor, and observation. The line is not seriousness but whether a mechanism exists
- An observation is notice that the same point will be examined again; left alone it can escalate
- The patterns are finite: formalistic internal audits, missing training records, stale risk assessments, unperformed supplier management, records diverging from practice, and an SoA out of step with the procedures
- Divergence between records and practice is fixed by rewriting the procedure to match reality — stop publishing rules you cannot keep
- Corrective action must go past the immediate fix: trace the cause through the process and add a measure that does not depend on human attentiveness
- A self-check one to two months out, separate from the internal audit, clears most typical findings in advance
Pottech supports ISMS construction and operation with a focus on healthcare. We prepare anticipated audit questions, perform internal audits, and — where a finding is raised — carry out the root cause analysis and write the corrective action report. We can also take the roles of internal audit manager and internal auditor.
See ISMS Certification Support for scope and pricing. If you already have findings to close and time is short, contact us.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27001 Information security management systems | ISO
- ISO/IEC 17021-1 Conformity assessment — Requirements for bodies providing audit and certification of management systems | ISO
- Guidelines for the Safe Management of Medical Information Systems | MHLW
Note: the naming of finding categories, submission deadlines for corrective action, and whether a further visit is required all vary by certification body. Interpretation of requirements and controls, and the handling of accreditation and certification, are governed by the standard itself and the publications of the accreditation and certification bodies. Guidelines are revised; always check the current edition.