5.4 Clause 10: Nonconformity, Corrective Action & Continual Improvement
Key Takeaways
Clause 10.1 continually improves AIMS suitability, adequacy, and effectiveness.
Clause 10.2 first reacts to a nonconformity by controlling and correcting it and dealing with consequences as applicable.
The organization evaluates causes and whether similar nonconformities exist or could occur elsewhere.
It implements needed action, reviews effectiveness, and changes the AIMS if necessary.
The standard requires evidence of the nature and actions and the results; it does not prescribe 5 Whys, fishbone analysis, or automatic risk-register updates.
Clause 10: improvement
Clause 10 closes the PDCA loop. It distinguishes ongoing improvement of the management system from corrective action taken after a requirement is not fulfilled.
10.1 Continual improvement
The organization continually improves the suitability, adequacy, and effectiveness of the AIMS.
- Suitability asks whether the AIMS remains appropriate to purpose, context, roles, and scope.
- Adequacy asks whether its design and resources are sufficient.
- Effectiveness asks whether it achieves intended outcomes.
Continual improvement is not the same as continuous change. Improvements can occur through periodic decisions, corrected processes, better criteria, more useful monitoring, stronger competence, revised controls, or clearer responsibility allocation.
Sources include monitoring, internal audits, management review, impact assessments, complaints, supplier changes, incidents, concern reports, and objective results. The standard does not require every metric to improve monotonically or every model to be retrained.
10.2 Nonconformity and corrective action
A nonconformity is non-fulfilment of a requirement. Requirements can come from ISO/IEC 42001, the organization’s own AIMS, or applicable obligations incorporated into it.
When a nonconformity occurs, the organization follows this sequence.
1. React
As applicable, it:
- takes action to control and correct the nonconformity; and
- deals with the consequences.
Control contains the immediate problem. Correction fixes the detected nonconformity. Dealing with consequences addresses effects already produced. The clause does not use the word “immediately” as a universal timing rule, although urgent action can be appropriate for severe consequences.
2. Evaluate the need to eliminate causes
The organization evaluates the need for action so the nonconformity does not recur or occur elsewhere by:
- reviewing the nonconformity;
- determining its causes; and
- determining whether similar nonconformities exist or could potentially occur.
A correction and a corrective action are different. Correcting an incorrect user notice addresses the instance; changing the review process that allowed obsolete notices addresses a cause.
3. Implement needed action
The organization implements action needed to address causes. The action should be proportionate and can be technical, procedural, contractual, organizational, or educational.
4. Review effectiveness
After implementation, the organization reviews whether corrective action was effective. Closing a ticket because a patch was installed is not enough if the problem recurs or the cause was misidentified.
5. Change the AIMS if necessary
If the event exposes a systemic gap, the organization changes the AIMS. That can mean revising criteria, controls, roles, competence, supplier processes, scope, monitoring, or documented information.
Corrective actions must be appropriate to the effects of the nonconformities encountered.
Required evidence
Documented information is available as evidence of:
- the nature of the nonconformities and subsequent actions taken; and
- results of corrective action.
Clause 10.2 does not expressly require an updated Clause 6 risk register in every case. Updating risk or impact assessments can be necessary or sensible when the event changes understanding, but present it as connected management-system action rather than an additional quoted step.
Root-cause methods
The standard requires causes to be determined; it does not prescribe a method. Useful methods include:
- 5 Whys for relatively linear problems;
- cause-and-effect diagrams for multiple contributing factors;
- fault-tree analysis for structured failure logic;
- event timelines for incidents; and
- data and process analysis for recurring model or workflow failures.
Choose a method suitable to complexity. Declaring “operator error” without examining workload, interface, training, incentives, and process design is rarely sufficient.
AI examples
Biased outcome pattern
Monitoring identifies an unexplained subgroup error gap beyond organizational criteria. The organization can pause or limit affected decisions, provide review for impacted cases, analyze data and process causes, change acquisition or evaluation controls, revalidate, and monitor effectiveness. The nonconformity is against defined requirements or criteria—not merely the existence of any difference.
Supplier output change
A vendor update breaks an extraction workflow. The organization controls consequences, restores a safe version or fallback, analyzes why regression monitoring and notification controls failed, strengthens supplier/change processes, and verifies that future changes are detected.
Missing impact reassessment
An internal audit finds that a significant purpose change was deployed without the planned impact assessment. The organization performs the needed assessment and controls the use. Corrective action examines why the change process failed and whether other systems have the same gap.
Incident versus nonconformity
An incident is an event. It becomes a nonconformity when a requirement was not fulfilled. A harmful output may occur despite conformity to a well-designed process; it still needs response and may reveal a need for improvement. Conversely, a missing required record can be a nonconformity even if no harm occurred.
Clause order
ISO/IEC 42001 places 10.1 Continual improvement before 10.2 Nonconformity and corrective action. Do not reverse them when mapping PDCA.
Tip
On a scenario question, first contain and correct as applicable, then investigate cause and recurrence, implement action, verify effectiveness, and change the AIMS if needed.
What is the correct first Clause 10.2 response when a nonconformity occurs?
Delete all evidence
Wait for the next certification audit
React by controlling and correcting it and dealing with consequences as applicable
Immediately replace every AI system
Does Clause 10.2 prescribe 5 Whys as the mandatory root-cause method?
Yes, for all nonconformities
Only for supplier incidents
No root-cause analysis is required
No; it requires causes to be determined but leaves the method to the organization
Which order is correct in ISO/IEC 42001 Clause 10?
10.1 Continual improvement; 10.2 Nonconformity and corrective action
10.1 Risk treatment; 10.2 Impact assessment
10.1 Internal audit; 10.2 Management review
10.1 Competence; 10.2 Awareness
Sections you finish are checked off in the contents.