13.4 Corrective Action Follow-Up & Verification
Key Takeaways
- Corrective action plans must address correction (fix), root cause, corrective action (prevent recurrence), and effectiveness checks—not cosmetic rewrites alone.
- Major NCs typically demand shorter response and verification timeframes than minors; CB procedures define exact clocks.
- Verification methods include document/record review and follow-up audit; depth matches severity and risk.
- NCs close only when evidence shows the action is implemented and effective—not when a plan is merely promised.
- After Stage 2, the lead auditor’s role shifts toward CA review and verification inputs; surveillance continues the certification-cycle link.
13.4 Corrective Action Follow-Up & Verification
Auditor focus: A polished corrective action plan is not closure. Closure requires implemented, effective action against the requirement that failed—especially for AI systems that keep changing after Stage 2.
From finding to action: the CA package
After NCs are issued, the auditee (or responsible process owner) produces a corrective action (CA) response. Strong packages separate four ideas:
| Element | Meaning | AIMS example |
|---|---|---|
| Correction | Immediate fix of the detected nonconformity | Complete missing impact assessment for system X; update outdated model card Y |
| Root cause | Why the failure occurred (systemic reason, not “human error” alone) | No release gate in CI/CD for impact assessment; ownership unclear after reorg; training never covered A.5 process |
| Corrective action | Action to eliminate cause and prevent recurrence | Enforce pipeline gate; RACI update; competence refresh; internal audit focus on high-risk releases |
| Effectiveness check | How the organization will know the fix worked | Sample next N high-risk releases; management review KPI; re-audit of process in 90 days |
Weak CA responses (reject or return)
- “We will try harder / retrain everyone” with no process change
- Rewriting the procedure text only while production gates stay open
- Root cause: “auditor was strict” or “documentation oversight” for systemic failures
- Closing NCs by deleting the requirement from local procedures (unless a justified SoA/applicability change is valid—and even then residual risk must be managed)
- Plan dates with no owners or evidence artifacts
Strong CA responses
- Specific owners and due dates
- Root cause beyond the single record (process, resources, competence, tools, culture of override)
- Technical and managerial fixes for AI (registry gates, monitoring, contracts, impact templates)
- Defined effectiveness evidence the verifier can check
Reviewing the plan: lead auditor / CB lens
When reviewing CA plans (and later evidence):
- Does correction address the exact NC statement? (system IDs, process gaps)
- Is root cause plausible and deep enough for majors/systemic issues?
- Will corrective action prevent recurrence under real release pressure?
- Is the effectiveness method measurable within a sensible horizon?
- Are residual risks accepted transparently if full elimination is impossible (e.g., third-party model limits)?
For AIMS, challenge plans that fix one model’s paperwork but leave the fleet process broken. A single completed impact assessment does not correct “no process” unless the process, roles, and gates are established and applied more broadly as required.
Timeframes: major vs minor
Exact clocks are CB- and procedure-specific. Conceptual norms in MS certification:
| Severity | Typical expectations (always follow applicable CB rules) |
|---|---|
| Major | Rapid containment/correction; CA plan often due in a short window (e.g., within days to ~2 weeks); implementation and verification often required before certification decision or within a tight post-decision period; follow-up audit more likely |
| Minor | CA plan within a moderate window; implementation often verified at next surveillance if risk allows—or earlier if CB requires; document review may suffice |
Never invent universal day counts on the exam or in client advice if the CB procedure states otherwise—state the principle: majors are more urgent and more deeply verified; minors are still mandatory to fix.
Internal AIMS audits should define timeframes in the organization’s NC procedure and escalate overdue majors to top management.
Verification methods
| Method | When it fits | AIMS illustration |
|---|---|---|
| Document/record review | Clear recordable fixes; lower residual risk | New procedure + completed assessments + release tickets showing gate checks |
| Remote verification | Hybrid evidence (screen share of registry gates, tickets) | Live demo that promotions block without evaluation artifacts |
| Follow-up audit (on-site/hybrid) | Majors, complex implementation, trust concerns, high-risk AI | Re-sample high-impact systems; interview owners; observe monitoring and oversight queues |
| Verification at surveillance | Agreed for some minors / residual actions | Check sustained performance of CA six months later |
What “verified effective” means
- Evidence shows correction done
- Evidence shows cause addressed (gate exists and is used; competence records real)
- Sample of post-fix performance does not recreate the same NC pattern
- For AI: version lineage shows the control applied to current production systems, not only a pilot from the CA week
If effectiveness cannot yet be shown (too soon after fix), the NC may remain open with progress notes until evidence exists—per CB rules. Do not close on intent alone.
When to close NCs
Close when verification criteria are met and documented.
Do not close when:
- Only a future promise exists
- Procedure changed but sampling still fails
- Scope of fix is narrower than the NC extent (one system fixed; systemic NC claimed organization-wide)
- Evidence is unverifiable or contradicted by observation
- The organization “closed” by narrowing criteria without justified change control
Record closure date, verifier, method, and evidence references in the CA log / CB system.
Lead auditor role after Stage 2
After Stage 2 fieldwork the team finalizes the controlled report, reviews CA plan adequacy, performs or supports assigned verification while remaining impartial, and provides inputs to CB decision makers without self-approving certification when independence rules forbid it. The auditee owns the AIMS and the CA; the auditor evaluates evidence of conformity restoration. Do not design the client’s fix when acting as independent CB auditor if that breaches impartiality rules for the engagement.
Surveillance linkage
Certification is a cycle. Open or recently closed NCs inform surveillance sampling (revisit weak AI systems and themes). Recurring themes (e.g., third-party AI every year) signal ineffective CA—raise attention. Material changes since Stage 2 may expand surveillance or trigger special audits. Paper-only closure should be challenged at the next visit. Audit program managers use CA performance as program-risk and competence input (Chapter 14).
End-to-end AIMS example
Major NC: no AI impact assessment process for high-impact systems. Correction: assess current high-impact production systems; block new high-impact go-lives until complete. Root cause: process never operationalized; no release gate; delivery speed over governance. Corrective action: procedure + template, RACI, mandatory registry gate, management-review KPI, competence modules. Effectiveness: current assessments linked to model versions; next high-impact releases show gate evidence; internal audit samples releases. Verification: follow-up hybrid audit (interviews, sample assessments, observe gate, review minutes). Closure when verification passes; surveillance rechecks a sample next visit.
Bottom line: Follow-up completes the audit PDCA loop—plan the fix, implement it, check effectiveness, act on residual risk. For ISO/IEC 42001, verify that AI lifecycle and impact controls work on living systems, not only that templates were uploaded after Stage 2.
Which corrective action package element specifically targets prevention of recurrence rather than only fixing the instance found?
When is it appropriate to close a major nonconformity after an ISO/IEC 42001 Stage 2 audit?
A major NC cited total absence of an impact assessment process. The auditee completes one assessment for a single system and requests closure. What should the verifier conclude?
How do closed and open AIMS nonconformities typically link to surveillance after certification?