10.4 Audit Types, Nonconformity Documentation & Follow-Up

Key Takeaways

  • Audits are classified by the relationship between auditor and auditee: first-party audits are internal, second-party audits are conducted by or on behalf of a customer, and third-party audits are conducted by an independent certification body.
  • ISO 19011:2018 provides guidance for first- and second-party auditing, whereas third-party certification auditing is governed by the requirements of ISO/IEC 17021-1:2015.
  • A major nonconformity is a systemic failure, a total absence of a required process, or a breakdown that undermines the BCMS's ability to deliver intended outcomes; a minor nonconformity is an isolated lapse in an otherwise functioning process.
  • A defensible nonconformity statement has exactly three parts — the requirement, the objective evidence, and the statement of failure — and never contains the auditor's proposed solution.
  • ISO 19011 distinguishes verifying that corrective action was completed from verifying that it was effective; a nonconformity is closed only when effectiveness has been demonstrated.
Last updated: August 2026

Section 10.2 built the internal audit programme and Section 10.3 covered management review and corrective action. Two Domain 5 knowledge statements remain, and both are examined more often than their apparent simplicity suggests: "Knowledge of the importance of audit for organizations and the differences between internal and external audits" and "Knowledge of documenting nonconformities", together with the competency "Ability to document nonconformities and follow up on them."

This section closes them, and in doing so supplies the vocabulary that Domain 7 (Chapter 11) assumes you already have.


1. Why Audit at All

Before the taxonomy, the purpose. Clause 9.2 requires internal audits because an organization cannot tell whether its BCMS works by asking the people who run it. Business continuity is uniquely prone to false assurance: plans exist, so the organization believes it is prepared; the plans have never been tested against evidence, so the belief is untested. Audit is the mechanism that converts assumption into evidence.

Audit delivers four things a management review alone cannot:

  1. Independent verification that documented processes are actually operating, not merely written
  2. Evidence for the management review — Clause 9.3.2 lists audit results as a mandatory input
  3. Early detection of nonconformities while they are cheap to fix, rather than at Stage 2 or during a real disruption
  4. Credibility with regulators, customers, and insurers, who treat unaudited continuity claims as unsubstantiated

2. The Three Audit Parties

Audits are classified by the relationship between the auditor and the auditee, not by who physically performs the work. This distinction is the one candidates get wrong.

First-partySecond-partyThird-party
Also calledInternal auditSupplier / customer auditCertification audit
Who audits whomThe organization audits itselfA customer audits its supplier, or an agent audits on the customer's behalfAn independent certification body audits the organization
PurposeConformity, effectiveness, and improvement for management's own useAssurance for a contracting party before or during a commercial relationshipCertification, surveillance, or recertification against ISO 22301
Governed byISO 19011:2018 (guidance)ISO 19011:2018 (guidance)ISO/IEC 17021-1:2015 (requirements)
Required by ISO 22301?Yes — Clause 9.2NoNo — certification is voluntary
OutcomeFindings for correction and improvementContract award, continuation, or remediation demandCertificate granted, maintained, suspended, or withdrawn

Two consequences the exam relies on:

  • An internal audit performed by a hired external contractor is still a first-party audit. The classification follows the relationship, not the payroll. An organization with insufficient independent internal auditors may lawfully outsource the work under Clause 9.2 — it remains its own audit, of its own BCMS, for its own purposes.
  • When you audit a critical supplier's BCMS (Section 7.3), you are performing a second-party audit. ISO 19011 is your guidance; you are not certifying anyone, and you may not claim to.

Internal versus external audit, side by side

DimensionInternal audit (Clause 9.2)External certification audit
MandatedYes, by ISO 22301No — a commercial or regulatory choice
Audit criteriaThe organization's own requirements and ISO 22301ISO 22301, plus the organization's documented BCMS
Independence standardAuditors must not audit their own workFull organizational independence; the CB may not have provided consultancy to the client
Scope controlSet by the organization; may be partial and risk-prioritised across a cycleSet by the CB; must cover the full certified scope across the cycle
FrequencyAt planned intervals determined by the organizationStage 1 and Stage 2, then surveillance at least annually, recertification at 3 years
Consequence of a major findingCorrective action under Clause 10.1Certification blocked, suspended, or withdrawn
Report goes toManagement, for review under Clause 9.3The CB's independent certification decision-maker

The exam-relevant asymmetry: an internal audit can be broader and deeper than a certification audit, and should be. The CB samples; the organization need not. An internal audit programme that merely rehearses what the CB will sample has misunderstood Clause 9.2, which requires the organization to determine whether the BCMS is effectively implemented and maintained — not whether it will pass an inspection.


3. Major and Minor Nonconformities

Clause 3 of ISO 22301 defines a nonconformity as non-fulfilment of a requirement. The grading is not defined in ISO 22301 itself; it comes from auditing practice and is applied consistently across certification schemes.

Major nonconformityMinor nonconformity
NatureSystemic failure, or total absence of a required processIsolated lapse within a process that otherwise functions
EffectRaises significant doubt that the BCMS can achieve its intended outcomesDoes not undermine overall capability
Typical triggersA required process does not exist at all; complete breakdown of an existing process; several related minors revealing a systemic cause; a failure with direct consequences for prioritised activitiesA single missing record; one overdue review; an isolated procedural deviation
Certification effectBlocks certification until corrective action is verifiedDoes not block certification if an acceptable corrective action plan is accepted

Worked contrasts, which is how the exam tests this:

  • Major: No business impact analysis has been performed for any in-scope activity. Clause 8.2.2 requires one; the process is absent, and everything downstream — strategies, plans, recovery objectives — is therefore unfounded.
  • Minor: A BIA has been performed for all 46 in-scope activities; two were last reviewed 14 months ago against a documented 12-month review cycle. The process exists and operates; two instances are overdue.
  • Major: Business continuity plans have never been exercised. Clause 8.5 requires an exercise programme; its complete absence means recovery capability is unproven.
  • Minor: The exercise programme runs to schedule; one after-action report from a tabletop exercise was issued five weeks after the exercise against a documented four-week requirement.

[!IMPORTANT] The accumulation rule. Several minor nonconformities against the same requirement may be re-graded as a single major, because a repeated pattern is evidence of systemic rather than isolated failure. Three overdue BIA reviews across three different departments is not three minors — it is evidence that the review process itself is not being managed.


4. Documenting a Nonconformity

ISO 19011:2018 requires that a finding of nonconformity be recorded against a specific requirement and contain a clear statement of the nonconformity identifying in detail the objective evidence on which it is based. In practice this produces a three-part structure.

PartContentTest
1. RequirementThe precise clause or internal document and the obligation it imposesCould the auditee look it up and read the same words?
2. Objective evidenceWhat was seen: document names and versions, record IDs, dates, roles interviewed, observationsCould another auditor re-find it?
3. Statement of failureThe specific way the evidence fails to meet the requirementDoes it state a fact, not an opinion?

A worked example.

Requirement: ISO 22301:2019 Clause 9.2.2(c) requires the organization to ensure that the results of internal audits are reported to relevant management.

Evidence: The internal audit report for the BCMS audit conducted 14-16 April 2026 (report ref. IA-BCMS-2026-01, issued 22 April 2026) was reviewed. Management review minutes for the meetings of 30 April 2026 and 31 July 2026 were examined and contain no reference to the audit or its four findings. The BCMS Manager confirmed in interview on 12 August 2026 that the report was circulated to the IT Director only.

Statement: The results of the April 2026 internal audit were not reported to relevant management.

Note what the statement does not do. It does not say the BCMS Manager was negligent, does not speculate on why, and does not instruct the organization to add audit results to the management review agenda. ISO 19011 is explicit that the auditor shall refrain from suggesting the cause of nonconformities or their solution. An auditor who prescribes the fix has assumed ownership of the remedy and compromised the independence of any future audit of it.

Common defects in nonconformity statements

DefectExampleWhy it fails
No requirement cited"Audit reporting is weak."Nothing to conform to; not auditable or arguable
Opinion presented as evidence"Management does not appear to take continuity seriously."Not objective evidence
Solution embedded"The organization should add audit results to the management review agenda."Auditor has designed the corrective action
Evidence not identifiable"Some records were missing."Cannot be re-verified; cannot be closed
Multiple failures bundledOne finding covering BIA, plans, and exercisingCannot be tracked or closed individually; obscures grading

Nonconformities must also be discussed with the auditee before the audit closes, so that the evidence is confirmed as accurate and understood. Disagreements that cannot be resolved are recorded as unresolved points rather than suppressed.


5. Follow-Up: Completion Is Not Closure

Clause 10.1 requires the organization to react to the nonconformity, evaluate the need for action to eliminate its causes, implement action, review effectiveness, and retain documented information. The audit programme's job is to verify all of that happened.

The follow-up cycle:

  1. Auditee responds with a correction (immediate containment), a root cause analysis, and a corrective action plan with owners and dates
  2. Auditor reviews the plan for adequacy — does the proposed action actually address the stated root cause, or only the symptom?
  3. Auditee implements and submits evidence
  4. Auditor verifies completion — the action was performed
  5. Auditor verifies effectiveness — the nonconformity has not recurred and cannot recur through the same cause
  6. Closure is recorded, with the verifying evidence and date

Steps 4 and 5 are different questions, and conflating them is the most common failure in nonconformity management. "We have revised the procedure" answers step 4. "The revised procedure has operated for a quarter and the subsequent audit sample found no recurrence" answers step 5. A nonconformity is closed only after effective implementation of corrective action has been demonstrated.

Effectiveness verification needs elapsed operating time. A corrective action closed the day after the plan was signed has been verified for completion only, and the closure is not defensible.

Open nonconformities, their ages, and their closure rates are themselves BCMS performance indicators (Section 10.1) and mandatory management review inputs under Clause 9.3.2. An organization with a growing population of overdue corrective actions has a Clause 10.1 problem regardless of how well any individual audit was conducted.


6. PECB Exam Warning Traps & Implementation Pitfalls

[!WARNING] Trap 1 (Party is about relationship, not payroll): An external contractor hired to perform the Clause 9.2 internal audit is conducting a first-party audit. Options equating "external auditor" with "external audit" are wrong.

[!WARNING] Trap 2 (Two different standards): ISO 19011:2018 gives guidance for first- and second-party auditing. Third-party certification auditing is governed by the requirements of ISO/IEC 17021-1:2015. Do not cite ISO 19011 as the governing standard for a certification body's conduct.

[!WARNING] Trap 3 (Auditing a supplier is second-party): Verifying a critical supplier's BCMS is a second-party audit. It never certifies the supplier, and it never substitutes for the supplier holding its own third-party certificate.

[!WARNING] Trap 4 (Absence of a process is major; a lapse within one is minor): The discriminator is systemic versus isolated, not how serious the topic sounds. No BIA at all is major. Two overdue BIA reviews within a functioning annual cycle are minor — unless the pattern shows the review process itself is unmanaged, in which case accumulation re-grades them.

[!WARNING] Trap 5 (Auditors do not prescribe solutions): ISO 19011 states the auditor shall refrain from suggesting the cause of nonconformities or their solution. Root cause analysis and corrective action design belong to the auditee, and an exam option showing an auditor writing the corrective action plan is describing an error.

[!WARNING] Trap 6 (Completed is not closed): Verifying that corrective action was implemented and verifying that it was effective are separate steps. Closure requires demonstrated effectiveness over real operating time, not a signed completion form.

Loading diagram...
Audit Parties, Nonconformity Grading, and the Path to Effectiveness-Verified Closure
Test Your Knowledge

An organization has only one trained BCMS auditor, who personally designed and implemented the incident response procedures. To satisfy Clause 9.2 it engages an independent consultancy to audit those procedures. How is this audit classified?

A
B
C
D
Test Your Knowledge

An internal auditor finds that the organization's documented BIA review cycle is 12 months, and that of 46 in-scope activities, three in three different departments were last reviewed 15, 16, and 18 months ago. What is the most defensible grading and reasoning?

A
B
C
D
Test Your Knowledge

Which of the following is a properly constructed nonconformity statement?

A
B
C
D