11.2 Grading Findings: Major NC, Minor NC & Opportunities for Improvement
Key Takeaways
- Audit findings are formally graded under ISO/IEC 17021-1 Clause 9.4.5 into Major Nonconformities, Minor Nonconformities, or Opportunities for Improvement (OFIs).
- A Major Nonconformity represents the total absence of or systemic failure to implement a mandatory ISO 45001 requirement, a situation creating significant doubt regarding system effectiveness, or an imminent high risk of serious injury or fatality.
- A Minor Nonconformity is an isolated procedural lapse or single implementation failure that does not undermine the integrity of the overall OH&S management system or generate direct, severe risk to workers.
- Under the aggregation rule, multiple related minor nonconformities across different departments or operational units must be synthesized and escalated to a single systemic Major Nonconformity.
- Opportunities for Improvement (OFIs) highlight areas of potential enhancement without citing standard breaches; auditors are strictly prohibited under ISO/IEC 17021-1 from providing consulting advice or specific solutions.
11.2 Grading Findings: Major NC, Minor NC & Opportunities for Improvement
Lead Auditor Core Concept: Grading audit findings is one of the most critical responsibilities of an ISO 45001 lead auditor. Under ISO/IEC 17021-1:2015 Clause 9.4.5, the audit team must analyze all audit evidence to determine conformity or nonconformity, and classify findings into Major Nonconformities, Minor Nonconformities, or Opportunities for Improvement (OFIs). Incorrectly grading a finding compromises audit integrity: under-grading a systemic hazard exposes workers to serious injury, while over-grading an isolated clerical error creates unjustified certification delays.
1. Normative Foundations for Finding Classification
Audit findings represent the results of evaluating collected audit evidence against specified audit criteria (ISO 45001:2018 requirements, statutory regulations, and internal organizational procedures). ISO/IEC 17021-1 Clause 9.4.5 establishes the normative framework for certification audits:
- The audit team must identify nonconformities where requirements are not fulfilled.
- The audit team must classify nonconformities as Major or Minor based on operational risk, systemic prevalence, and impact on system effectiveness.
- Audit findings must be formally recorded, clearly explained, and supported by verified objective evidence.
┌──────────────────────────────────────────────┐
│ ISO/IEC 17021-1 FINDING TAXONOMY │
└──────────────────────┬───────────────────────┘
│
┌───────────────────────────────┼───────────────────────────────┐
▼ ▼ ▼
┌─────────────────────────┐ ┌─────────────────────────┐ ┌─────────────────────────┐
│ MAJOR NONCONFORMITY │ │ MINOR NONCONFORMITY │ │ OPPORTUNITY FOR │
│ • Total clause absence │ │ • Isolated lapse │ │ IMPROVEMENT │
│ • Systemic breakdown │ │ • Single failure │ │ • Conforming practice │
│ • Doubt on intended │ │ • No direct high risk │ │ • Area of vulnerability │
│ OH&S outcomes │ │ • System integrity │ │ • Zero consultancy or │
│ • Imminent fatality/harm│ │ remains intact │ │ prescriptive advice │
└────────────┬────────────┘ └────────────┬────────────┘ └────────────┬────────────┘
▼ ▼ ▼
┌─────────────────────────┐ ┌─────────────────────────┐ ┌─────────────────────────┐
│ Certification CANNOT be │ │ Certification CAN be │ │ Discretionary action │
│ granted or maintained. │ │ recommended; CAP review │ │ by auditee; no formal │
│ Mandatory ON-SITE audit │ │ via desktop or next │ │ corrective action plan │
│ verification required. │ │ surveillance audit. │ │ required. │
└─────────────────────────┘ └─────────────────────────┘ └─────────────────────────┘
2. Major Nonconformities: Definitions and Thresholds
Under ISO/IEC 17021-1 Clause 9.4.5.3, a Major Nonconformity is defined by several distinct conditions, any one of which mandates this classification:
The Six Criteria for a Major Nonconformity
- Total Absence of a Requirement: The complete failure of the organization to address, document, or implement one or more mandatory clauses of ISO 45001:2018 (e.g., no worker consultation process established under Clause 5.4, no internal audit program planned or executed under Clause 9.2, or total absence of legal compliance evaluation under Clause 9.1.2).
- Systemic Failure of Implementation: A widespread breakdown across multiple departments, operating shifts, or physical sites indicating that a required process exists on paper but is systematically ignored in practice (e.g., risk assessments are documented, but across 10 departments evaluated, none of the identified operational controls are implemented).
- Significant Doubt Regarding System Effectiveness: A situation that raises significant doubt about the ability of the OH&S management system to achieve its intended outcomes: preventing work-related injury and ill health, fulfilling compliance obligations, and achieving OH&S objectives.
- Direct, Imminent, or High Risk to Worker Safety: Any condition or activity observed during the audit that exposes workers to direct, immediate danger of death, permanent disability, or acute occupational illness (e.g., workers entering an unventilated, untested confined space containing toxic gas; workers operating high-tonnage stamping presses with disabled light-curtain safety interlocks).
- Unresolved Prior Minor Nonconformity: The failure of the organization to effectively implement corrective actions to address a minor nonconformity identified during a previous certification or surveillance audit. Persistent, uncorrected minor issues indicate systemic breakdown in Clause 10.2.
- Unauthorized Scope Exclusion: An attempt by the organization to unilaterally exclude operational processes, high-hazard facilities, or worker categories from the OH&S management system scope (Clause 4.3) without contractual or technical justification.
Certification Impact of a Major Nonconformity
- Initial Certification: Certification cannot be granted until the major nonconformity has been corrected, its root cause eliminated, and the effectiveness of the corrective action verified.
- Surveillance or Recertification: Existing certification is placed at risk of suspension or withdrawal unless immediate correction and an approved corrective action plan are submitted within strict timeframes (typically 30 days).
- Mandatory On-Site Verification: Under ISO/IEC 17021-1, a Major Nonconformity involving operational controls, high-risk physical hazards, or widespread implementation failures cannot be closed via desktop document review. The certification body must conduct an on-site special follow-up audit to physically verify corrective action implementation before certification can proceed.
3. Minor Nonconformities: Definitions and Thresholds
A Minor Nonconformity is an isolated lapse, sporadic oversight, or single failure to implement a specific requirement that does not compromise the overall integrity of the management system or raise doubt about its ability to achieve its intended outcomes.
Characteristics of Minor Nonconformities
- Isolated in Scope: The failure is limited in occurrence and not indicative of a systemic breakdown across the facility or organization.
- Low Immediate Risk: The oversight does not expose workers to imminent high danger of death, severe injury, or chronic occupational disease.
- System Integrity Maintained: The overall management system process is established, active, and functioning effectively, with only a discrete implementation gap.
Typical Minor Nonconformity Examples
- Inspection Tags: In a manufacturing plant with 250 portable fire extinguishers, 2 units in an exterior warehouse had monthly inspection tags that were not initialed for the previous month, while all other units across the plant were fully inspected and documented.
- Training Records: In a department of 45 certified overhead crane operators, 1 newly hired operator had completed all classroom and practical training, but the HR department had not yet uploaded the signed practical evaluation sheet into the central database.
- Audit Scheduling: An organization completed all required internal audits across all clauses, but the final audit of the shipping department was completed 10 days after the deadline specified in the internal annual audit calendar due to an unexpected production shutdown.
Certification Impact of a Minor Nonconformity
- Certification can be recommended or maintained, provided the organization submits a formal root cause analysis, correction, and corrective action plan within an agreed timeframe (typically 60 to 90 days).
- Verification of implementation can usually be conducted through a desktop review of documented information or during the next scheduled surveillance audit.
4. The Aggregation Rule: Escalating Minor Lapses to a Systemic Major NC
A vital skill tested on the PECB Lead Auditor exam is the aggregation rule. Isolated lapses, when viewed individually, might each appear to be minor nonconformities. However, when an auditor uncovers multiple related minor lapses across different departments, shifts, or operational processes, the lead auditor must evaluate whether they represent a systemic management breakdown.
The Pattern Recognition Process
Suppose during an audit of an aerospace components manufacturer, the audit team observes:
- In the chemical treatment shop: An expired calibration sticker on a pH meter (Clause 9.1.1).
- In the heat treatment bay: An uncalibrated thermocouple on an annealing furnace (Clause 9.1.1).
- In the paint spray booth: An uncalibrated differential pressure gauge across an air filtration bank (Clause 9.1.1).
- In the testing lab: An uncalibrated sound level meter used for area noise assessments (Clause 9.1.1).
If the lead auditor issues four separate minor nonconformities, the client will likely treat them as isolated maintenance errors. However, an expert lead auditor synthesizes these findings:
"The organization has failed to establish and maintain an effective calibration and maintenance control process for monitoring and measuring equipment across multiple operating facilities."
This constitutes a Major Nonconformity against Clause 9.1.1, as it demonstrates a systemic breakdown in the organization's ability to ensure valid, reliable monitoring data.
5. Opportunities for Improvement (OFIs) & The Anti-Consultancy Boundary
An Opportunity for Improvement (OFI) (sometimes called an Observation) is an audit finding where the organization's current practice satisfies the formal requirements of ISO 45001, but the auditor identifies a potential vulnerability, operational inefficiency, or emerging risk that could deteriorate into a nonconformity in the future if left unaddressed.
Purpose of OFIs
OFIs stimulate continual improvement (Clause 10.3) by highlighting weak practices or opportunities for optimization. The auditee is not obligated to submit a formal corrective action plan or implement changes in response to an OFI; action is entirely discretionary.
The Strict Prohibition on Management Consultancy (ISO/IEC 17021-1 Clause 5.2.5)
Under ISO/IEC 17021-1 Clause 5.2.5, certification bodies and auditors are strictly prohibited from providing management system consultancy. An auditor evaluates what conforms or does not conform; an auditor must never prescribe how the organization should resolve an issue.
| Permissible Audit Practice (Conformity Assessment) | Prohibited Consultancy (ISO/IEC 17021-1 Violation) |
|---|---|
| Citing that an internal audit checklist does not evaluate worker participation under Clause 5.4. | Designing a customized worker participation survey or drafting an internal audit checklist for the client. |
| Recording an OFI that paper-based SDS binders may become outdated when new chemicals arrive. | Recommending that the client purchase a specific commercial chemical management software platform. |
| Identifying that near-miss reporting rates are low among night-shift contractors. | Designing a safety incentive scheme or drafting a contractor reward policy for the auditee. |
| Explaining the intent and normative structure of ISO 45001 Clause 8.1.2 (Hierarchy of Controls). | Recommending a specific brand of local exhaust ventilation hood or engineering contractor. |
Exam Watchpoint: Exam questions frequently tempt candidates with scenarios where an auditor "kindly provides a template" or "recommends a reliable software vendor" to help an auditee close a gap. This is strictly prohibited consultancy and represents an automatic exam failure.
6. Comprehensive Comparison Matrix: Major NC vs. Minor NC vs. OFI
| Dimension | Major Nonconformity | Minor Nonconformity | Opportunity for Improvement (OFI) |
|---|---|---|---|
| Normative Reference | ISO/IEC 17021-1 Clause 9.4.5.3 | ISO/IEC 17021-1 Clause 9.4.5.3 | ISO 19011:2018 Clause 6.4.8 |
| Core Definition | Systemic breakdown, clause absence, doubt on MS outcomes, or imminent high risk. | Isolated implementation lapse; system integrity remains intact; low risk. | Conforming practice with room for optimization or future risk mitigation. |
| Impact on Intended Outcomes | Severely undermines the MS ability to prevent injury and ill health. | Does not impair the overall ability of the MS to achieve intended outcomes. | Has no negative impact; potential to enhance intended outcomes. |
| Worker Risk Level | Direct, imminent, or high risk of death, severe injury, or acute illness. | Minimal or indirect risk; isolated technical or administrative lapse. | No noncompliance; risk is controlled but could be optimized. |
| Certification Recommendation | CANNOT recommend initial certification, renewal, or maintenance. | CAN recommend certification, subject to approved corrective action plan. | No impact on certification decision; action is discretionary. |
| Verification Method | Mandatory ON-SITE follow-up audit required before closure. | Desktop review of records or verification at next scheduled audit. | Reviewed informally at next audit; no verification required. |
| Auditee Mandatory Action | Root cause analysis, immediate containment, and full corrective action plan. | Root cause analysis, correction, and corrective action plan. | Discretionary review; no formal response or CAP submission required. |
7. Real-World Audit Scenario: The Over-Pressurized Autoclave
Audit Context: During an on-site Stage 2 certification audit of a biomedical sterilization facility, an auditor investigates the maintenance and operation of four high-pressure steam autoclaves.
Audit Investigation & Evidence Gathered:
- Finding A: On Autoclave #4, the primary safety relief valve had been removed for repairs three days prior, and a solid blind flange was installed in its place. The operating pressure gauge was pegged at its maximum limit of 4.5 bar (rated design maximum is 3.0 bar). The operator on duty stated that the pressure relief valve kept weeping steam, so the maintenance lead bolted a blanking flange over the outlet to avoid shutting down the sterilization cycle.
- Finding B: On Autoclave #1, the annual external inspection certificate for the digital temperature recorder was current, but the laminated pre-operational inspection checklist hanging on the machine frame was Revision 2, whereas the document control master list showed Revision 3 had been issued two weeks earlier (the only change between revisions was updating the company logo).
Lead Auditor Grading Determination:
- Grading Finding A: MAJOR NONCONFORMITY against Clause 8.1.1 (Operational Control) and Clause 8.1.2 (Hierarchy of Controls). Bypassing a safety relief valve and operating a pressurized vessel 50% above its rated design limit creates an imminent, catastrophic explosion hazard presenting direct risk of worker fatalities. This represents a total operational failure with immediate life-threatening risk.
- Grading Finding B: MINOR NONCONFORMITY against Clause 7.5.3 (Control of Documented Information). The physical inspection was conducted, the machine was operating safely, and the obsolete checklist revision was an isolated administrative oversight that did not alter inspection parameters or compromise worker health and safety.
8. Common Exam Traps & Candidate Errors
- Trap 1: Downgrading Major Nonconformities to "Be Helpful." Candidates often argue that if an auditee promises to fix an imminent danger immediately, the auditor should grade it as a Minor NC to avoid delaying certification. An auditor cannot bargain away standard requirements. An imminent hazard or systemic breakdown is always a Major NC regardless of auditee promises.
- Trap 2: Elevating Pure Clerical Errors to Major NCs. An auditor who grades an isolated typo or single late meeting minute as a Major Nonconformity demonstrates poor professional judgment. Unless an administrative error leads to uncontrolled high risk or systemic failure, it is a Minor NC.
- Trap 3: Prescribing Solutions in OFI Reports. Writing an OFI such as: "The company should hire ABC Consulting to install automated vibration monitors on motor bearings." This violates ISO/IEC 17021-1 impartiality rules. An OFI must describe the observation neutrally without prescribing solutions.
- Trap 4: Overlooking the Aggregation Rule. Treating five separate instances of missing PPE across five independent workshops as five separate minor nonconformities instead of aggregating them into a single systemic Major Nonconformity under Clause 8.1.2.
Under ISO/IEC 17021-1 Clause 9.4.5, which condition mandates that an audit finding be classified as a Major Nonconformity rather than a Minor Nonconformity?
During an on-site audit of a high-hazard manufacturing facility, an audit team uncovers eight separate instances across four production bays where pre-use crane safety checklists were not completed, and three overhead cranes operated with damaged hoist wire ropes. How should the lead auditor structure the audit finding?
An auditor drafting an audit report notes that the auditee's chemical inventory register is maintained manually on paper binders, which occasionally causes delays in locating Safety Data Sheets (SDS). How should the auditor handle this observation under ISO/IEC 17021-1 impartiality requirements?