5.4 Clause 10: Nonconformity, Corrective Action & Continual Improvement

Key Takeaways

  • Clause 10.1 continually improves AIMS suitability, adequacy, and effectiveness.

  • Clause 10.2 first reacts to a nonconformity by controlling and correcting it and dealing with consequences as applicable.

  • The organization evaluates causes and whether similar nonconformities exist or could occur elsewhere.

  • It implements needed action, reviews effectiveness, and changes the AIMS if necessary.

  • The standard requires evidence of the nature and actions and the results; it does not prescribe 5 Whys, fishbone analysis, or automatic risk-register updates.

Last updated: October 2026

Clause 10: improvement

Clause 10 closes the PDCA loop. It distinguishes ongoing improvement of the management system from corrective action taken after a requirement is not fulfilled.

10.1 Continual improvement

The organization continually improves the suitability, adequacy, and effectiveness of the AIMS.

  • Suitability asks whether the AIMS remains appropriate to purpose, context, roles, and scope.
  • Adequacy asks whether its design and resources are sufficient.
  • Effectiveness asks whether it achieves intended outcomes.

Continual improvement is not the same as continuous change. Improvements can occur through periodic decisions, corrected processes, better criteria, more useful monitoring, stronger competence, revised controls, or clearer responsibility allocation.

Sources include monitoring, internal audits, management review, impact assessments, complaints, supplier changes, incidents, concern reports, and objective results. The standard does not require every metric to improve monotonically or every model to be retrained.

10.2 Nonconformity and corrective action

A nonconformity is non-fulfilment of a requirement. Requirements can come from ISO/IEC 42001, the organization’s own AIMS, or applicable obligations incorporated into it.

When a nonconformity occurs, the organization follows this sequence.

1. React

As applicable, it:

  • takes action to control and correct the nonconformity; and
  • deals with the consequences.

Control contains the immediate problem. Correction fixes the detected nonconformity. Dealing with consequences addresses effects already produced. The clause does not use the word “immediately” as a universal timing rule, although urgent action can be appropriate for severe consequences.

2. Evaluate the need to eliminate causes

The organization evaluates the need for action so the nonconformity does not recur or occur elsewhere by:

  • reviewing the nonconformity;
  • determining its causes; and
  • determining whether similar nonconformities exist or could potentially occur.

A correction and a corrective action are different. Correcting an incorrect user notice addresses the instance; changing the review process that allowed obsolete notices addresses a cause.

3. Implement needed action

The organization implements action needed to address causes. The action should be proportionate and can be technical, procedural, contractual, organizational, or educational.

4. Review effectiveness

After implementation, the organization reviews whether corrective action was effective. Closing a ticket because a patch was installed is not enough if the problem recurs or the cause was misidentified.

5. Change the AIMS if necessary

If the event exposes a systemic gap, the organization changes the AIMS. That can mean revising criteria, controls, roles, competence, supplier processes, scope, monitoring, or documented information.

Corrective actions must be appropriate to the effects of the nonconformities encountered.

Required evidence

Documented information is available as evidence of:

  • the nature of the nonconformities and subsequent actions taken; and
  • results of corrective action.

Clause 10.2 does not expressly require an updated Clause 6 risk register in every case. Updating risk or impact assessments can be necessary or sensible when the event changes understanding, but present it as connected management-system action rather than an additional quoted step.

Root-cause methods

The standard requires causes to be determined; it does not prescribe a method. Useful methods include:

  • 5 Whys for relatively linear problems;
  • cause-and-effect diagrams for multiple contributing factors;
  • fault-tree analysis for structured failure logic;
  • event timelines for incidents; and
  • data and process analysis for recurring model or workflow failures.

Choose a method suitable to complexity. Declaring “operator error” without examining workload, interface, training, incentives, and process design is rarely sufficient.

AI examples

Biased outcome pattern

Monitoring identifies an unexplained subgroup error gap beyond organizational criteria. The organization can pause or limit affected decisions, provide review for impacted cases, analyze data and process causes, change acquisition or evaluation controls, revalidate, and monitor effectiveness. The nonconformity is against defined requirements or criteria—not merely the existence of any difference.

Supplier output change

A vendor update breaks an extraction workflow. The organization controls consequences, restores a safe version or fallback, analyzes why regression monitoring and notification controls failed, strengthens supplier/change processes, and verifies that future changes are detected.

Missing impact reassessment

An internal audit finds that a significant purpose change was deployed without the planned impact assessment. The organization performs the needed assessment and controls the use. Corrective action examines why the change process failed and whether other systems have the same gap.

Incident versus nonconformity

An incident is an event. It becomes a nonconformity when a requirement was not fulfilled. A harmful output may occur despite conformity to a well-designed process; it still needs response and may reveal a need for improvement. Conversely, a missing required record can be a nonconformity even if no harm occurred.

Clause order

ISO/IEC 42001 places 10.1 Continual improvement before 10.2 Nonconformity and corrective action. Do not reverse them when mapping PDCA.

Tip

On a scenario question, first contain and correct as applicable, then investigate cause and recurrence, implement action, verify effectiveness, and change the AIMS if needed.

Test Your Knowledge

What is the correct first Clause 10.2 response when a nonconformity occurs?

A

Delete all evidence

B

Wait for the next certification audit

C

React by controlling and correcting it and dealing with consequences as applicable

D

Immediately replace every AI system

Test Your Knowledge

Does Clause 10.2 prescribe 5 Whys as the mandatory root-cause method?

A

Yes, for all nonconformities

B

Only for supplier incidents

C

No root-cause analysis is required

D

No; it requires causes to be determined but leaves the method to the organization

Test Your Knowledge

Which order is correct in ISO/IEC 42001 Clause 10?

A

10.1 Continual improvement; 10.2 Nonconformity and corrective action

B

10.1 Risk treatment; 10.2 Impact assessment

C

10.1 Internal audit; 10.2 Management review

D

10.1 Competence; 10.2 Awareness

Sections you finish are checked off in the contents.