Back to Columns
ISMS & Certification13 min read

Common Audit Nonconformities and How to Prevent Them

September 14, 2026

Common Audit Nonconformities and How to Prevent Them
Share this article

The first time a team hears the word "nonconformity" in an ISMS audit, the reaction is usually alarm. Will we lose the certification? Was the preparation wasted?

In practice, nonconformities are not unusual. What matters is which kind, and how many. A minor nonconformity corrected within the agreed period does not prevent certification and does not sour the relationship with the certification body. A major nonconformity, by contrast, halts the certification decision itself and pushes the schedule out significantly.

The inconvenient part is that the common patterns are almost always the same ones. They are not obscure clauses of the standard; they are the same structural finding — "the system is not actually being operated" — appearing in different clothes. Which also means that if you know the patterns, you can clear most of them yourself before the audit.

This article sorts nonconformities by severity and by pattern, gives the prevention for each, and walks through corrective action after a finding. For the audits themselves, see What Stage 1 Looks At and What Stage 2 Looks At. For the overall picture, see What Is an ISMS (ISO/IEC 27001)? A Complete Guide for Healthcare Companies.

Disclaimer: This article is general information. Classification of findings, naming, and corrective-action deadlines vary by certification body. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Base decisions on those and on your own body's guidance.

Findings Come in Three Grades

Findings recorded in an audit report generally fall into three grades. Names vary between bodies; the structure does not.

GradeMeaningEffect on certificationResponse
Major nonconformityPart of the management system is not functioning, or no mechanism exists to meet a requirementThe certification decision does not proceed until correction is verifiedRoot cause analysis and corrective action, usually with an additional verification visit
Minor nonconformityThe mechanism exists, but there is an isolated deviation or a gap in recordsThe decision proceeds once a corrective action plan is submitted and carried outCorrective action report; effectiveness checked at the next audit
Observation / opportunity for improvementNot a breach of the standard, but improvement is advisableNoneOptional — but leaving it can turn it into a nonconformity next time

Observations are the most misunderstood. Hearing "this is not a nonconformity" and doing nothing until next year invites a minor nonconformity on the grounds that the condition persisted. Read an observation as "we are letting this go this time, and we will look again."

What separates major from minor

The dividing line is not the seriousness of the finding but whether a mechanism exists at all.

  • One employee's training record is missing → the mechanism exists, a single lapse → minor
  • Training was never planned or delivered → no mechanism meets the requirement → major
  • The internal audit ran but skipped a department → minor
  • No internal audit has ever been performed → major

Several minor nonconformities that share one root cause can be aggregated into a judgement that "the system is not functioning" — and become major. Scattered findings of the same type are a warning sign.

The Recurring Patterns

The following are the findings that typically arise in ISMS audits. These are not case studies of particular organisations; they are the general patterns produced by the places where the standard's requirements and day-to-day operation most easily drift apart.

#PatternWhy it happensPrevention
1Internal audit performed as a formalityThe checklist is a column of ticks with no trace of how evidence was examined; the auditee's self-report is transcribed as-isRecord what was inspected (screen, register, log, physical item) as the basis for each judgement. Design on the assumption that an audit report with zero findings itself draws suspicion
2Missing training recordsMid-year joiners, returners from leave, and contractors fall outside the target list; completion is only tallied at year endTie the target list to HR data so joining and transfer automatically enrol people. Review completion monthly
3Risk assessment never updatedThe table built in year one stands unchanged; new services, new systems, and reorganisations are not reflectedWrite the update triggers into the procedure (annual / new system introduced / major incident / scope change) and record each time a trigger fires
4Supplier management not actually performedContracts are signed but periodic evaluation never happens, and sub-contracting is not trackedMaintain a supplier register with a defined evaluation frequency and method. Put prior-approval clauses for sub-contracting in the contract and verify reality annually
5Records diverge from practiceThe procedure says logs are reviewed quarterly; in reality it is once a year. The procedure is stricter than the organisationRewrite the procedure to match reality. Delete or relax rules you cannot keep — a procedure is a promise, not an aspiration
6SoA out of step with the proceduresA control marked "applicable" in the Statement of Applicability has no corresponding documented procedure; or an exclusion is justified with a bare "not applicable"Link each SoA row to the procedure and records that implement it. Ground every exclusion in the risk assessment result
7Corrective action is a pledge, not a changeNo root cause analysis; the report closes with "we will remind staff"Trace the event back through the process. Include at least one measure that does not rely on human attentiveness
8Management review inputs incompleteThe minutes omit inputs the standard requires — audit results, progress against objectives, changes in riskFix the review agenda as a template mapped to the standard's required inputs

Patterns 1, 3 and 5 tend to surface not immediately after first certification but at the surveillance audits from year two onward. During the build, an external partner is usually alongside; once operation begins, the organisation runs it alone and the checking and updating quietly stop. See Preparing for the Surveillance Audit and Preparing for Recertification in Year Three.

Extra Ground for Healthcare Companies

If you handle medical information, general IT-company preparation is not sufficient. Whether or not your auditor has a healthcare background, including medical information handling in scope invites proportionate scrutiny.

  • Can you show, in documents, how responsibility is divided with the hospital? Know immediately whether it sits in the contract, the SLA, or the operating procedure (Demarcating Responsibility)
  • How the three-ministry guidelines relate to your ISMS documents. Maintained separately, one set inevitably goes stale (The Three-Ministry Guidelines)
  • Handling of production data. Is real data taken into development or test environments — and if so, is there an approval and deletion record?
  • Access log retention and review frequency consistent with customer contracts and industry expectations

None of this is readable directly from the clauses, so unless you raise it yourself, the preparation gets missed.

After a Finding Is Raised

The process generally runs as follows; timescales and forms follow your certification body's instructions.

StepContentCommon stumble
① Establish the factsConfirm the finding and the requirement it maps toArguing on the spot and losing the thread. First ask what evidence produced the judgement
② Immediate correctionFix the deviation in front of you (produce the missing record, etc.)Stopping here and never reaching root cause
③ Root cause analysisTrace back through the process to why the condition aroseStopping at "the owner forgot." Push down to what in the mechanism failed to detect it
④ Decide and implement corrective actionChange the mechanism so it cannot recurAdding a sentence to a procedure without adding an operational checkpoint
⑤ Report and verify effectivenessSubmit the corrective action report; the body verifiesOmitting the evidence — the revised documents and records

For a major nonconformity, evidence that step ④ is complete is normally required. For a minor one, submitting the plan usually lets the decision proceed, with effectiveness checked at the next audit — though this too varies by body. See Writing a Corrective Action Report and Clause 10: Improvement.

On pushing back

If you believe a finding rests on a factual misunderstanding, asking the auditor to review it with evidence in hand is a legitimate step. Do it by presenting the relevant records and establishing the facts, not by arguing. If the finding stands, every certification body has a defined appeals procedure — ask about it while you are still selecting one (Choosing a Certification Body).

Clearing Them Yourself Beforehand

A self-check one to two months before the audit removes most of the typical findings. The point is to set aside time to look with an auditor's eyes, separately from the internal audit.

Records and dates

  • Are there records of one actually completed cycle of internal audit and management review, dated before the audit?
  • Are training records complete for everyone on the roster, including mid-year joiners and contractors?
  • Is the risk assessment's last-updated date later than the most recent organisational or system change?
  • Are corrective action reports closed out, including those from the previous audit?

Consistency between documents

  • Does every control marked applicable in the SoA have a corresponding procedure?
  • Is every exclusion's justification consistent with the risk assessment?
  • Do the frequencies stated in procedures match the frequencies evidenced in the records?
  • Does the scope statement match the current organisation chart, sites, and services?

Reality

  • Do entry logs, access permission lists, and asset registers match what actually exists?
  • Do leavers and transferees still have live accounts?
  • Is the supplier register current, with evaluation records?
  • Can front-line staff explain their own department's rules in their own words?

That last item is easy to dismiss, but the on-site audit verifies operation through interviews. Staff who do not know what the document says is, for audit purposes, a system that is not being operated.

Conclusion

  1. Findings come in three grades — major, minor, and observation. The line is not seriousness but whether a mechanism exists
  2. An observation is notice that the same point will be examined again; left alone it can escalate
  3. The patterns are finite: formalistic internal audits, missing training records, stale risk assessments, unperformed supplier management, records diverging from practice, and an SoA out of step with the procedures
  4. Divergence between records and practice is fixed by rewriting the procedure to match reality — stop publishing rules you cannot keep
  5. Corrective action must go past the immediate fix: trace the cause through the process and add a measure that does not depend on human attentiveness
  6. A self-check one to two months out, separate from the internal audit, clears most typical findings in advance

Pottech supports ISMS construction and operation with a focus on healthcare. We prepare anticipated audit questions, perform internal audits, and — where a finding is raised — carry out the root cause analysis and write the corrective action report. We can also take the roles of internal audit manager and internal auditor.

See ISMS Certification Support for scope and pricing. If you already have findings to close and time is short, contact us.

References and Sources

Note: the naming of finding categories, submission deadlines for corrective action, and whether a further visit is required all vary by certification body. Interpretation of requirements and controls, and the handling of accreditation and certification, are governed by the standard itself and the publications of the accreditation and certification bodies. Guidelines are revised; always check the current edition.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.