7.1 Identifying, Grading, and Documenting Nonconformities

Key Takeaways

  • Audit findings result from evaluating objective evidence against audit criteria and may be conformities, nonconformities, or opportunities for improvement.
  • Major nonconformities indicate systemic or high-impact ISMS failures; minor nonconformities are isolated lapses that do not undermine overall ISMS capability.
  • A complete nonconformity statement always includes the requirement citation, objective evidence, and a clear statement of failure.
  • Opportunities for Improvement must never disguise unmet requirements; unmet criteria must be graded as nonconformities.
Last updated: July 2026

Introduction to Audit Findings

During an ISO/IEC 27001 Information Security Management System (ISMS) audit, the audit team collects objective evidence and evaluates it against the audit criteria. Those criteria typically include ISO/IEC 27001:2022 clauses and Annex A controls, the organization's Statement of Applicability (SoA), documented ISMS processes, and any contractual or regulatory requirements included in the audit scope. The results of that evaluation are audit findings. Findings may indicate conformity, nonconformity, or—where criteria are met but improvement is still possible—an Opportunity for Improvement (OFI).

For a CQI/IRCA ISMS Lead Auditor working to PR373 expectations, documenting findings accurately is not administrative paperwork. Findings drive corrective action, certification recommendations, and management's understanding of residual information security risk. Weak documentation causes disputes at closeout, shallow root-cause work, and ineffective corrective actions. Strong documentation is factual, traceable, graded consistently, and free of personal opinion.

Evaluating Evidence Against Criteria

Every candidate finding must answer three questions before it is raised:

  1. What requirement applies? Cite the specific clause, control, policy, or procedure.
  2. What objective evidence was obtained? Identify records, observations, interviews, or system outputs with enough detail for another competent auditor to retrace the trail.
  3. Does the evidence show the requirement was fulfilled? If yes, record conformity or an OFI if enhancement is warranted. If no, raise a nonconformity.

Auditors must separate facts from interpretation. "The VPN account for employee 458 remained enabled on 15 July 2026" is a fact. "IT is careless" is an opinion and has no place in a finding. The Lead Auditor calibrates team findings so similar evidence receives similar grading across departments and auditors.

Grading Nonconformities

When evidence shows a requirement is not fulfilled, the finding is a nonconformity (NC). In management-system auditing practice aligned with ISO 19011 and certification body schemes under ISO/IEC 17021-1, NCs are typically graded as Major or Minor. Grading reflects impact on the ISMS's ability to achieve intended outcomes—especially effective information security risk management—not the auditor's frustration level or the auditee's seniority.

Major Nonconformity

A Major Nonconformity indicates a significant failure that raises serious doubt about the ISMS's capability to achieve its intended outcomes. Typical triggers include:

  • Absence of a required process: No internal audit programme (Clause 9.2), no management review (Clause 9.3), no risk assessment process (Clause 6.1.2), or no Statement of Applicability.
  • Systemic breakdown: The process exists on paper but fails repeatedly across sites, functions, or time periods—for example, access rights are not removed on termination in multiple business units.
  • Significant risk impact: The failure creates material doubt that information security risks are being managed (for example, encryption keys for production systems stored unencrypted in a shared mailbox with no compensating control).
  • Accumulation of related minors: Several Minor NCs against the same requirement or process that, taken together, demonstrate systemic failure rather than isolated error.

In third-party certification audits, an open Major NC typically blocks initial certification or certificate continuation until the certification body verifies effective correction and corrective action. Exact timelines and verification methods are defined by the certification body's procedures; auditors follow those procedures rather than inventing local pass/fail thresholds.

Minor Nonconformity

A Minor Nonconformity is an isolated lapse that does not, by itself, undermine the overall capability of the ISMS. The requirement is generally addressed, but implementation failed in a limited instance. Examples:

  • One controlled document missing a required approval signature while the document-control process otherwise works.
  • A single overdue risk treatment action with evidence that the treatment process normally operates.
  • One incomplete training record in an otherwise functioning competence programme.

Minor NCs still require root-cause analysis and corrective action. They are not "optional" findings.

Opportunity for Improvement (OFI)

An OFI is recorded when criteria are currently met, but the auditor identifies a credible enhancement or a condition that could drift into nonconformity if left unattended. Critical rule: never use an OFI to hide an unmet requirement. If the requirement is not met, raise an NC—even if the issue seems small or the auditee is cooperative.

Finding typeCriteria met?Typical impactAuditee obligation
Major NCNoSystemic / significant doubt about ISMS capabilityCorrection + corrective action; verification before certification progression
Minor NCNoIsolated lapse; ISMS still generally capableCorrection + corrective action within agreed timeframe
OFIYesEnhancement opportunity or early warningConsider and respond per programme rules; not a nonconformity
ConformityYesRequirement fulfilledMaintain performance

Structure of a Complete Nonconformity Statement

A robust NC statement is complete only when it contains three linked parts: requirement, evidence, and failure (statement of nonconformity). Many certification bodies and IRCA-aligned courses teach this as a non-negotiable drafting standard.

1. Requirement Citation

Cite the exact source that was not fulfilled—ISO/IEC 27001:2022 clause or Annex A control, SoA commitment, or the organization's own mandatory procedure. Prefer specific references (for example, Annex A Control 5.18) over vague phrases such as "access control requirements."

2. Objective Evidence

Record verifiable facts: document titles and versions, record IDs, dates, locations, system report names, and observed conditions. Avoid "some," "several," or "many" without identifiers.

3. Statement of Failure

State clearly what failed relative to the requirement. Focus on the system or process failure, not individuals.

Worked example (Minor NC draft):

  • Requirement: ISO/IEC 27001:2022 Annex A Control 5.18 requires that access rights be removed or adjusted upon termination of employment.
  • Evidence: HR termination list for April 2026 shows employees 458, 492, and 501 departed. Active Directory export dated 15 July 2026 still shows enabled VPN accounts for those three IDs.
  • Failure: The organization did not ensure access rights of terminated users were removed upon termination of employment.

If the same failure appears across multiple departments with no effective monitoring, the Lead Auditor may grade the finding as Major because the pattern indicates systemic failure of the leavers process.

Drafting Discipline and Auditee Acknowledgement of Facts

During fieldwork, discuss potential NCs with process owners as soon as evidence is clear. Seek acknowledgement of the facts even if the auditee disputes grading or interpretation. Clarifying facts early prevents closing-meeting surprises. The Lead Auditor reviews every team NC for:

  • Correct grading (Major vs Minor vs OFI)
  • Completeness of the three-part statement
  • Consistency with sampling and risk-based priorities
  • Absence of consulting language that designs the solution for the auditee

Auditors raise findings; auditees own correction and corrective action. Clear NC statements make that handoff possible and protect the integrity of the audit conclusion.

Test Your Knowledge

Which scenario best supports raising a Major nonconformity during an ISO/IEC 27001 ISMS audit?

A
B
C
D
Test Your Knowledge

A complete nonconformity statement must include which three elements?

A
B
C
D
Test Your Knowledge

Access-control procedures meet ISO/IEC 27001 requirements, but the auditor sees that linking HR offboarding tickets to identity management would reduce manual delay risk. How should this be recorded?

A
B
C
D