12.2 Root Cause Analysis Evaluation & Corrective Action Follow-Up

Key Takeaways

  • Under ISO 45001 Clause 10.2 and ISO/IEC 17021-1 Clause 9.4.9, the auditee must clearly distinguish between immediate correction (containment of the detected symptom) and corrective action (eliminating the systemic root cause to prevent recurrence).
  • Lead Auditors must critically evaluate root cause analyses, rejecting superficial conclusions such as 'operator error' or 'worker carelessness' that fail to examine underlying procedural, training, design, or leadership failures.
  • Common root cause analysis methodologies—including 5 Whys, Ishikawa (Fishbone) diagrams, Bow-Tie modeling, and Fault Tree Analysis—must identify multi-factorial organizational vulnerabilities.
  • Corrective Action Plans (CAP) must be assessed against five rigorous criteria: adequacy of root cause determination, extent of impact across similar processes, suitability under the hierarchy of controls, feasibility of deadlines, and clear ownership.
  • Verification of corrective action implementation differs by nonconformity severity: Minor NCs may be closed via desktop evidence review, whereas Major NCs necessitate an on-site follow-up audit within a maximum 90-day window.
Last updated: September 2026

12.2 Root Cause Analysis Evaluation & Corrective Action Follow-Up

Lead Auditor Core Concept: When an audit team issues a nonconformity, the certification journey does not end—it transitions into the post-audit verification phase. Under ISO 45001:2018 Clause 10.2 and ISO/IEC 17021-1:2015 Clause 9.4.9, an auditee's response must do far more than fix the isolated symptom found during the audit. The organization must take immediate containment action, conduct a deep root cause analysis to identify systemic organizational vulnerabilities, and implement robust corrective actions that prevent recurrence. As a Lead Auditor, rubber-stamping weak root cause analyses like "the worker forgot" or "re-trained the employee" represents a fundamental failure of auditor competence.


1. Immediate Correction (Containment) vs. Corrective Action (ISO 45001 Clause 10.2)

One of the most frequent points of confusion in management systems auditing is the fundamental distinction between Correction and Corrective Action. ISO 45001 Clause 10.2 explicitly separates the requirement to react to the nonconformity (Clause 10.2.a) from the requirement to evaluate the need for corrective action to eliminate the root causes (Clause 10.2.b).

Definitions and Operational Distinctions

  • Correction (Immediate Remediation / Containment): Action taken to eliminate a detected nonconformity or mitigate its immediate occupational health and safety consequences. Correction addresses the symptom on the spot. It is immediate, localized, and restores operational safety temporarily, but does nothing to prevent the breakdown from happening again.
  • Corrective Action (Systemic Elimination): Action taken to eliminate the root cause of a nonconformity and to prevent its recurrence. Corrective action addresses the underlying systemic, managerial, design, or procedural failure. It changes the organization's processes, infrastructure, governance, or systems permanently.
Assessment DimensionCorrection (Immediate Containment)Corrective Action (Systemic Recurrence Prevention)
Primary PurposeContain the immediate hazard, protect workers, and restore conformity for the specific sample observed.Eliminate the fundamental underlying breakdown to ensure the issue never recurs anywhere in the organization.
TimingImmediate (hours to days following notification).Planned, structured execution over an agreed timeframe (typically 30 to 90 days).
Typical TargetThe isolated physical condition, document, or individual worker observed during the audit.Management processes, risk assessment methodologies, procurement systems, supervision regimes, engineering designs.
OH&S Example 1 (Chemical Spill)Neutralize the spilled chemical with absorbent pads and dispose of contaminated material in hazardous waste drums.Redesign the transfer pipe manifold with double-walled piping, install automatic shutoff valves, and revise preventive maintenance schedules.
OH&S Example 2 (Missing Machine Guard)Immediately lock out the machine and bolt an available metal cover over the exposed high-speed drive pulley.Audit all machines across the facility for guarding gaps, update engineering pre-commissioning checklists, and train design engineers.
OH&S Example 3 (Uncalibrated Gas Detector)Tag out the uncalibrated detector and replace it with a calibrated unit from the safety storeroom.Establish an automated calibration tracking database with automated lockout alerts, and reassign asset management to a dedicated technician.

2. Rigorous Root Cause Analysis Methodologies

To implement effective corrective action, the auditee must investigate why the nonconformity occurred. ISO 45001:2018 Clause 10.2.b.1 mandates that the organization determine the causes of the nonconformity. The Lead Auditor must be competent in evaluating whether the methodology applied was appropriate and conducted with sufficient analytical depth.

A. The 5 Whys Technique

The 5 Whys is an iterative interrogative technique used to explore cause-and-effect relationships. The investigator asks "Why?" repeatedly until the underlying management system failure is uncovered.

  • The Human Error Trap: If an auditee stops asking "Why?" at human error (e.g., "The forklift driver was careless"), the root cause analysis is inadequate. Lead Auditors must reject analyses that blame individual workers.
  • Exam-Grade 5 Whys Example:
    • Symptom: A forklift operator was observed driving with an unsecured, elevated chemical tote without wearing a seatbelt.
    • Why 1? Why was the tote unsecured? Because the operator was rushing to transfer materials to the synthesis reactor.
    • Why 2? Why was the operator rushing? Because the production line ran out of raw materials unexpectedly.
    • Why 3? Why did materials run out unexpectedly? Because inventory levels were not integrated with the production scheduling software.
    • Why 4? Why did the operator not secure the load or wear a seatbelt? Because management did not enforce forklift safety rules, and supervisor pre-shift checks were never performed.
    • Why 5? Why was there no enforcement or supervision? Because supervisor key performance indicators (KPIs) measured output volume exclusively, with zero accountability for OH&S compliance or operational control enforcement (Clause 5.1 / 8.1.1).
    • True Systemic Root Cause: Misalignment of leadership accountability and operational supervision incentives, coupled with supply chain workflow disruptions.

B. Ishikawa (Fishbone / Cause-and-Effect) Diagram

Used for complex, multi-factorial nonconformities. Causes are categorized along six operational branches (the 6Ms):

  1. Methods: Inadequate, ambiguous, or outdated Standard Operating Procedures (SOPs).
  2. Machines / Equipment: Inadequate maintenance, missing interlocks, obsolete technology.
  3. Manpower (People): Inadequate competence, lack of hazard awareness, fatigue, excessive workload.
  4. Materials: Substandard raw materials, defective PPE, missing Safety Data Sheets (SDS).
  5. Measurement: Inaccurate gas monitors, lack of noise dosimeters, uncalibrated pressure gauges.
  6. Milieu (Environment): Poor lighting, extreme thermal stress, excessive ambient noise, slippery floors.

C. Bow-Tie Model and Fault Tree Analysis (FTA)

  • Bow-Tie Model: Places the unwanted incident/hazard release at the center (the "knot"). On the left side are threats and proactive prevention barriers (pre-event controls). On the right side are reactive mitigation barriers and consequences (post-event controls). Used to evaluate where safety barriers failed.
  • Fault Tree Analysis (FTA): A deductive, top-down failure analysis using Boolean logic gates (AND/OR gates) to trace how component failures, software bugs, and human actions combined to produce a system failure.

3. Evaluating the Auditee's Corrective Action Plan (CAP)

When an auditee submits a Corrective Action Plan (CAP), the Lead Auditor must evaluate it systematically against five mandatory criteria before granting approval:

┌─────────────────────────────────────────────────────────────────────────────┐
│               LEAD AUDITOR EVALUATION CRITERIA FOR A C.A.P.                 │
├──────────────────────────┬──────────────────────────────────────────────────┤
│ Evaluation Criterion     │ Verification Question & Scrutiny Checkpoint      │
├──────────────────────────┼──────────────────────────────────────────────────┤
│ 1. Containment Adequacy  │ Has immediate correction isolated the hazard     │
│    (Correction)          │ and eliminated immediate worker risk?            │
├──────────────────────────┼──────────────────────────────────────────────────┤
│ 2. Root Cause Depth      │ Did the RCA uncover systemic management system   │
│    (True System Failure) │ failures, or merely scapegoat frontline workers? │
├──────────────────────────┼──────────────────────────────────────────────────┤
│ 3. Extent Analysis       │ Did the organization examine whether similar     │
│    (Cross-Process Scope) │ conditions exist in other units, shifts, or sites?│
├──────────────────────────┼──────────────────────────────────────────────────┤
│ 4. Control Hierarchy     │ Do proposed corrective actions follow the        │
│    (Clause 8.1.2)        │ hierarchy of controls (engineering > PPE)?       │
├──────────────────────────┼──────────────────────────────────────────────────┤
│ 5. Feasibility & Action  │ Are completion deadlines realistic, with clear   │
│    (Resources & Owners)  │ accountability assigned to named positions?      │
└──────────────────────────┴──────────────────────────────────────────────────┘

Protocol for Rejecting an Inadequate CAP

If the Lead Auditor determines that a submitted CAP is superficial, unfeasible, or fails to address the root cause, the Lead Auditor must formally reject the plan. The auditor provides written feedback explaining why the submission was unsatisfactory (e.g., "The root cause cites operator distraction; please conduct an in-depth analysis of training, ergonomics, and supervisory oversight"). The auditee must revise and re-submit the plan within a strict timeframe.


4. Verification Protocols: Desk Review vs. On-Site Follow-Up Audit

Under ISO/IEC 17021-1 Clause 9.5.2 and 9.5.3, the certification body must verify the implementation and effectiveness of any corrective action before issuing or renewing certification. The verification method is directly dictated by the grading of the nonconformity:

A. Minor Nonconformity Verification (Desktop Review)

  • Applicability: Minor Nonconformities representing isolated lapses, paperwork oversights, or minor procedural inconsistencies that do not directly threaten worker life or systemic integrity.
  • Method: Desktop review of documented evidence submitted electronically by the auditee.
  • Evidence Examined: Revised standard operating procedures, signed training attendance logs, calibrated equipment certificates, photos/videos of physical modifications, updated legal registers, and management review minutes.
  • Long-Term Verification: The operational effectiveness of the action is formally evaluated during the next scheduled surveillance audit.

B. Major Nonconformity Verification (Mandatory On-Site Follow-Up Audit)

  • Applicability: Major Nonconformities representing total absence of a standard clause, widespread procedural failure, or direct unmitigated life-safety hazards.
  • Method: Mandatory on-site follow-up audit (special audit). A desk review of documents is strictly insufficient to close a Major Nonconformity.
  • Audit Execution: The auditor visits the specific facility and operational Gemba, directly observes physical operations, tests safety systems, inspects live records, and interviews frontline workers to confirm that the corrective action is fully operational.

Verification of Implementation vs. Verification of Effectiveness

A critical distinction on the Lead Auditor exam:

  • Verifying Implementation: Confirming that the planned action was carried out (e.g., "The company purchased and installed the machine guard on July 14.").
  • Verifying Effectiveness: Confirming that the action successfully achieved its intended outcome of eliminating the root cause and preventing recurrence (e.g., "During three unannounced inspections across two months, operators utilized the guard properly, zero bypasses were attempted, and maintenance logs show 100% interlock verification.").

5. Nonconformity Close-Out & Impact on the Certification Decision

Under ISO/IEC 17021-1 Clause 9.5.2, strict statutory and accreditation timelines govern nonconformity resolution:

The 90-Day and 6-Month Rules

  1. The 90-Day Target: Major nonconformities identified during initial Stage 2 audits or surveillance audits must normally be resolved, verified, and closed out within 90 calendar days.
  2. The Absolute 6-Month Hard Limit: ISO/IEC 17021-1 Clause 9.5.2 establishes an absolute outer boundary: if the certification body cannot verify the implementation and effectiveness of corrective actions for any Major Nonconformity within six months (180 days) from the final day of the Stage 2 audit, the Stage 2 audit must be repeated in its entirety before certification can be recommended.
  3. Surveillance Audit Failure: If a Major Nonconformity identified during a periodic surveillance audit is not closed within the prescribed timeframe (typically 90 days), the certification body must initiate formal suspension of the organization's ISO 45001 certification. If unresolved following suspension (usually within 6 months), the certificate must be permanently withdrawn.
  4. Formal Close-Out Form: The Lead Auditor completes and signs the Nonconformity Report (NCR) Close-Out section, recording the date, specific evidence evaluated, verification method, and definitive recommendation to close the finding.

6. Real-World Audit Scenario: The Superficial CAP at Apex Logistics

Audit Context: During an initial certification audit of Apex Logistics, an auditor identified a Major Nonconformity under Clause 8.1.2 (Hierarchy of Controls) and Clause 6.1.2 (Hazard Identification). In the high-bay pallet racking warehouse, three automated guided vehicles (AGVs) had their optical obstacle-detection sensors covered with masking tape to prevent them from slowing down during high-volume shipping shifts.

The Auditee's Initial CAP Submission:

  • Correction: Removed the masking tape from the three AGV sensors.
  • Root Cause: Night-shift AGV operators showed poor attitude and laziness.
  • Corrective Action: Issued written warnings to the two night-shift operators and posted a sign in the breakroom: "Do Not Tamper with AGV Sensors."
  • Timeline: 7 days.

Lead Auditor Evaluation & Decisive Action:

  1. Formal Rejection of the CAP: The Lead Auditor rejects the submission within 48 hours. The root cause analysis is superficial and unacceptable because it attributes a severe systemic safety bypass to individual worker attitudes while completely ignoring production pressure, inadequate supervision, lack of engineering lockouts, and absence of management oversight.
  2. Mandated Revision: The Lead Auditor requires Apex Logistics to conduct a multidisciplinary root cause analysis using the 5 Whys or Fishbone method involving workers and maintenance engineers.
  3. Acceptance of Revised CAP: Apex submits a revised CAP identifying that AGVs were experiencing frequent false-positive laser sensor tripping due to loose plastic shrink-wrap tails on pallets, creating massive shipment backlogs that led operators to bypass sensors. The revised corrective action includes: (a) re-tuning laser sensor filtering software, (b) upgrading pallet stretch-wrapping tension, (c) installing tamper-proof electronic interlocks that permanently disable AGV motors if sensors are obscured, and (d) introducing weekly supervisory interlock audits.
  4. On-Site Verification: The Lead Auditor conducts an on-site follow-up audit 60 days later, observes AGV operations during live loading shifts, interviews warehouse workers, inspects tamper-proof interlocks, verifies zero sensor bypasses, and officially signs off on the Major Nonconformity close-out.

7. Common Exam Traps and Candidate Errors

  • Trap 1: Believing a Major Nonconformity Can Be Closed via Email / Desk Review. ISO/IEC 17021-1 establishes that closing a Major Nonconformity requires direct verification, which almost universally mandates an on-site follow-up visit. Accepting photos or scanned procedures to close a Major safety hazard is a critical audit malpractice.
  • Trap 2: Confusing Correction with Corrective Action. Exam questions frequently describe an immediate fix (e.g., "clearing a blocked fire exit") and ask if this constitutes corrective action. It does not; it is merely an immediate correction. Corrective action requires changing the storage management and inspection process so fire exits never become blocked.
  • Trap 3: Accepting "Operator Re-training" as Sufficient Corrective Action. While training may accompany corrective action, relying solely on training/re-training to solve an engineering or procedural issue ranks lowest on the hierarchy of controls (Clause 8.1.2) and fails to address systemic root causes.
  • Trap 4: Exceeding the 6-Month Major NC Limit. If an auditee requests an extension beyond six months to fix a Major NC from an initial Stage 2 audit, the auditor cannot grant it. The 6-month rule is absolute under ISO/IEC 17021-1; exceeding it requires repeating Stage 2.
Loading diagram...
ISO 45001 Corrective Action Lifecycle, Root Cause Analysis & Verification Gate Architecture
Test Your Knowledge

An audit team discovers that workers in a chemical formulation area are decanting toxic solvents without respiratory protection because the local exhaust ventilation (LEV) system failed three weeks ago and was never reported. The auditee immediately issues respirators to workers and replaces the LEV exhaust fan motor. Which statement correctly distinguishes this response under ISO 45001 Clause 10.2?

A
B
C
D
Test Your Knowledge

During the evaluation of an auditee's Corrective Action Plan (CAP) submitted to address a Major Nonconformity regarding uncalibrated atmospheric gas detectors in confined spaces, the safety manager writes: 'Root cause: The safety technician was careless and forgot the calibration date. Corrective action: Verbally reprimanded the technician and reminded him to check the date.' As the Lead Auditor, how must you evaluate this submission?

A
B
C
D
Test Your Knowledge

Following a Stage 2 initial certification audit, an auditor issues a Major Nonconformity for the complete absence of contractor safety management procedures (Clause 8.1.4.2). The auditee submits a comprehensive Corrective Action Plan with updated policies and contractor pre-qualification logs. Under ISO/IEC 17021-1 Clause 9.5.2, what verification protocol must the certification body follow to close this nonconformity?

A
B
C
D