13.1 Classifying Nonconformities & Observations
Key Takeaways
- A nonconformity is non-fulfilment of a requirement; severity (major vs minor) reflects systemic failure or total absence versus an isolated, contained lapse.
- Major NCs in AIMS audits include total absence of required processes (e.g., no AI system impact assessment process) or systemic failures that prevent the AIMS from achieving its intended outcomes.
- Minor NCs are isolated failures with limited extent (e.g., one outdated model card) when the process otherwise exists and operates.
- Observations and opportunities for improvement (OFIs) are not nonconformities—they must not be used to soften a genuine NC or to invent unstated requirements.
- Every finding needs requirement, evidence, and a clear statement of nonconformity (or observation) written so an independent reader can verify the judgment.
13.1 Classifying Nonconformities & Observations
Auditor focus: Classification is a professional judgment under ISO 19011 and certification practice (ISO/IEC 17021-1), not a negotiation with the auditee. Wrong severity distorts certification risk; vague wording makes verification and corrective action impossible.
From evidence to findings
During Stage 2 (and internal or supplier AIMS audits), the team evaluates audit evidence against audit criteria—ISO/IEC 42001 clauses, applicable Annex A controls, the organization’s AIMS documented information, and other agreed requirements (legal, contractual, or client-specific). The output is audit findings: conformity, nonconformity, or other observations.
A nonconformity (NC) is the non-fulfillment of a requirement. Requirements may be:
- Explicit ISO/IEC 42001 clause obligations (e.g., 6.1.4 AI system impact assessment where applicable)
- Applicable Annex A controls the organization has determined are needed (and related SoA / control decisions)
- The organization’s own mandatory AIMS procedures and criteria
- Other requirements included in the audit criteria (regulation, contracts, customer AI policies)
If there is no requirement, there is no nonconformity—only perhaps an OFI or a note outside criteria.
Major vs minor nonconformity (management-system practice)
Certification bodies and lead auditors commonly use two severity levels. Exact CB procedures may use additional labels, but the conceptual split is stable across MS audits:
| Grade | Core idea | Typical signals |
|---|---|---|
| Major nonconformity | Systemic failure, total absence of a required process/element, or a failure that raises significant doubt that the AIMS can achieve its intended results / control AI risk | Missing mandatory process end-to-end; repeated failures across systems; deliberate bypass of controls; ineffective core clause (risk, impact, operation, improvement) |
| Minor nonconformity | Isolated lapse or limited failure; process exists and generally works, but a requirement was not met in a contained instance | Single record gap; one system’s artifact outdated; partial implementation with evidence the control framework is otherwise in place |
Major NC—definition in practice
Treat a finding as major when there is total absence of a required AIMS element; systemic failure of the same requirement across systems/sites/samples; breakdown of intended outcomes (AIMS cannot reasonably govern AI risk/impact); or failure of a critical clause theme that undermines confidence in the system as a whole (e.g., operational control that never gates production models).
AIMS example — major: No AI system impact assessment process, no procedure, no roles, and no completed assessments for any high-impact systems in scope. That is absence of a core planning/control expectation under ISO/IEC 42001—not “documentation polish.” Grade major.
Minor NC—definition in practice
Treat a finding as minor when a requirement is not met but extent is limited, the process exists and usually operates, and residual risk is localized without redesigning the whole AIMS.
AIMS example — minor: Procedure requires a current model card for each production model; 14 of 15 cards are current; one recommender still lists an old evaluation suite and a retired owner after a reorg. Process exists; failure is isolated → minor.
Do not inflate or deflate severity: total process absence is not “minor paperwork”; one missing signature is rarely a major; related minors that show the same root failure mode across samples (e.g., no evaluation artifacts on every high-risk release for six months) may warrant a major systemic finding instead of five separate minors. Grade on evidence—not pressure tactics.
Observations and opportunities for improvement (OFI)
Not every improvement idea is a nonconformity. An observation / OFI applies when criteria are met (or no requirement is failed) but the auditor notes a way to strengthen effectiveness or clarity. Positive findings are optional for balance—not substitutes for NCs.
AIMS example — OFI: Impact assessments and model cards meet criteria, but performance and fairness metrics are documented inconsistently across teams, making management review harder. Recommend a shared metrics taxonomy—OFI, not NC, unless criteria already mandate a specific metrics standard that is missing.
OFI discipline: never use an OFI to avoid a genuine NC; never invent requirements outside criteria; phrase OFIs as voluntary suggestions; track them separately from NCs.
Writing clear findings: three parts
Every nonconformity (and strong observation) should be readable by someone who was not on the audit. Use three elements:
| Element | Content | AIMS illustration |
|---|---|---|
| 1. Requirement | Cite clause/control/procedure and quote or paraphrase the obligation | “ISO/IEC 42001 6.1.4 / A.5 theme — organization shall assess impacts of AI systems…; Procedure IA-01 §3 requires completed impact assessment before production release of high-impact systems.” |
| 2. Evidence | Objective, verifiable facts: samples, IDs, dates, who showed what | “Inventory lists 6 high-impact systems. Sample of 4 production systems (IDs …): no impact assessment records; process owner confirmed no assessments completed; release tickets show production go-live without IA gate.” |
| 3. Statement of nonconformity | Clear sentence: what requirement is not fulfilled | “The organization has not established and applied an AI system impact assessment process for high-impact systems prior to production use.” |
Avoid vague language: “culture is weak,” “AI ethics is immature,” “team seemed confused.” Replace with who, what, when, which requirement, which sample. Confirm the requirement is in criteria, evidence is retrievable, severity matches extent, and wording stays within report confidentiality limits.
AIMS classification scenarios (worked)
| Scenario | Grade | Why |
|---|---|---|
| No AI impact assessment process, no assessments for any high-risk system | Major | Total absence of a core required activity; systemic gap |
| Impact process exists; 1 of 12 high-risk systems missing a current assessment after a major use-change | Minor (if isolated) | Process present; single lapse—confirm no pattern |
| Model cards required by procedure; one card outdated, others current | Minor | Isolated documentation failure |
| Every production promotion in 6 months lacks required fairness evaluation though procedure mandates it | Major | Systemic failure of operational control / lifecycle gate |
| Metrics documented inconsistently; criteria met | OFI | Improvement, not non-fulfillment |
| Supplier foundation model used with no due diligence while A.10/procedure requires it | Major if systemic/absent; minor if one incomplete pilot file | Depends on extent and whether the control framework exists |
Grading discipline and consistency
Before the closing meeting, the lead auditor calibrates the team: same evidence should yield the same grade and consistent extent language (“1 of 5 sampled systems” vs “organization-wide”). Apply the same yardstick to AI and non-AI themes—do not soft-grade human-oversight logging failures for automated credit decisions while hardening unrelated admin gaps. Follow the CB’s classification procedure for certification audits; for internal audits, keep major/minor logic coherent so Stage 2 is not a surprise. Listen to factual corrections (wrong sample ID, superseded procedure); re-evaluate only on new evidence, not relationship pressure.
Classification drives follow-up intensity (Section 13.4) and certification recommendations (Section 13.2): majors need urgent plans and deeper verification; minors may allow longer windows and document checks. Grade on requirement + evidence + systemic extent. Write findings so a stranger can audit your judgment.
In an ISO/IEC 42001 Stage 2 sample, the organization has no defined AI system impact assessment process, no owners, and no completed assessments for any high-impact production systems. How should this typically be graded?
Which finding wording best meets the three-part standard (requirement, evidence, statement of nonconformity)?
When is an opportunity for improvement (OFI) the appropriate classification?
Sampling shows that for six consecutive months every high-risk model promotion lacked the fairness evaluation required by the release procedure, though a procedure document exists. What grading logic is most sound?