Why Getting the Classification Right Matters
One of the most consequential decisions an auditor makes during any audit is how to classify a finding. Get it wrong and you either alarm an auditee unnecessarily, or you understate something that genuinely needs fixing. Neither outcome serves anyone well.
On this page
The three main finding types you will use across ISO 9001, ISO 14001 and ISO 45001 audits are nonconformity (NC), opportunity for improvement (OFI), and observation. Each has a distinct meaning, a different level of urgency, and a different expectation attached to it. This article walks through each classification in practical terms, with examples drawn from real audit situations, so you can apply them with confidence rather than guessing.
If you want a deeper look at the distinction between findings and nonconformities at a conceptual level, this article on audit findings versus observations versus nonconformities covers the terminology in detail. Here we focus on the practical skill of making the call on the day.
Nonconformity: When a Requirement Is Not Being Met
A nonconformity exists when objective evidence shows that a requirement is not being fulfilled. That requirement can come from the standard itself, from the organisation's own documented procedures, from a legal obligation referenced in the system, or from a customer specification the organisation has committed to meet.
The key word is requirement. If there is no requirement being breached, you do not have a nonconformity. This sounds obvious, but it is one of the most common mistakes auditors make, particularly those who are newer to the role. They see something they personally disagree with, or something that looks inefficient, and they want to raise it as a nonconformity. Unless you can point to a specific requirement that is not being met, you cannot call it an NC.
Major vs Minor Nonconformity
Nonconformities are further divided into major and minor. Understanding this distinction is critical because a major nonconformity at a certification audit can prevent or suspend certification, while a minor nonconformity requires a corrective action response but does not block the certificate.
A major nonconformity typically exists where:
- A requirement of the standard is completely absent from the system
- There is a systemic failure across multiple instances or processes
- The failure creates a significant risk to the intended outcomes of the management system
- A previously raised minor nonconformity has not been addressed and has escalated
A minor nonconformity is an isolated lapse, a single instance of non-fulfilment, or a partial gap where the overall process exists but has broken down in a specific area.
For example, imagine you are auditing a construction company's ISO 45001 system. You review the hazard identification records and find that one work area has not had a hazard assessment completed in over 18 months, despite the procedure requiring annual reviews. That is a minor nonconformity. If you then discover that hazard assessments have not been completed for any work area across the entire organisation, that is a major nonconformity. The difference is systemic failure versus isolated lapse.
Writing a Nonconformity Statement
A well-written nonconformity statement has three elements: the requirement that is not being met, the objective evidence that demonstrates the gap, and a clear statement of what was found. You do not need to prescribe the fix. That is the auditee's job through the corrective action process.
A poorly written NC might say: The training records are not adequate. That tells the auditee almost nothing. A properly written NC says: Clause 7.2 of ISO 9001:2015 requires the organisation to retain documented information as evidence of competence. During the audit of the production department, training records could not be produced for three of five operators performing critical welding operations. Records for the remaining two operators were present but undated.
Specificity is what gives a nonconformity report its credibility and usefulness. For more guidance on this, this article on writing nonconformities that hold up goes into the structure and language in detail.
Exemplar Global Recognised Training ProviderRTP No. 310970Opportunity for Improvement: Raising It Without Requiring It
An opportunity for improvement, often abbreviated to OFI, is a finding that identifies where the system could be enhanced, but where no specific requirement is being breached. You are not raising a nonconformity. You are offering a professional observation that something could be done better.
OFIs are entirely voluntary for the auditee to act on. You cannot require corrective action against an OFI, and you cannot follow up on it as though it were an NC. This is an important boundary that some auditors blur, particularly internal auditors who have a vested interest in seeing improvements made.
When to Raise an OFI
An OFI is appropriate when:
- A process is technically conforming but clearly inefficient or fragile
- The organisation is meeting the minimum requirement but missing an obvious enhancement
- You observe a practice in one area that would benefit another area if shared
- Trends in data suggest a future problem that has not yet become a nonconformity
Consider this scenario. You are auditing an ISO 14001 system for a manufacturing plant. The organisation has a legal register and it is being reviewed annually as required. However, you notice that the register is a static spreadsheet with no links to the actual legislative sources, and the person responsible for maintaining it has no formal process for identifying new legislative updates between annual reviews. There is no nonconformity here because the annual review is happening. But there is a genuine risk that changes to environmental legislation will be missed between reviews. That is a well-founded OFI.
How to Word an OFI
OFIs should be framed constructively. You are not criticising. You are suggesting. Use language that acknowledges the current conforming state before identifying the potential enhancement.
A strong OFI might read: The organisation currently conducts an annual review of its compliance obligations register, which meets the requirements of Clause 6.1.3. It may be beneficial to establish a process for monitoring legislative updates on a more frequent basis, such as through subscription to regulatory alert services, to reduce the risk of changes being missed between scheduled reviews.
Notice that this OFI does not imply the organisation is doing anything wrong. It points to a practical improvement without creating alarm or obligation.
Observation: The Middle Ground
The term observation is used differently by different auditors and different certification bodies, which is a source of genuine confusion in the profession. In some audit programmes, observation is used as a classification in its own right. In others, it is used loosely to mean anything the auditor noticed during the audit, including NCs and OFIs.
For the purposes of this article, we treat observation as a formal finding classification that sits between a nonconformity and an OFI. It typically refers to a situation where:
- There is a concern about a trend or direction, but insufficient evidence yet to raise a nonconformity
- Something is borderline, and the auditor wants to flag it without formally classifying it as an NC
- A previously raised finding is showing early signs of recurrence
- A process is technically meeting requirements but in a way that carries visible risk
Observations in Certification Audits
In the context of third party certification audits, observations are sometimes used by certification bodies as a way of flagging concerns that do not yet meet the threshold for a nonconformity but warrant attention at the next surveillance audit. They serve as an early warning signal. The auditee is not required to raise a corrective action, but they would be wise to take the observation seriously because the same auditor may look at it again in 12 months.
In internal audits, observations can be particularly useful when you want to put something on the radar without triggering a formal corrective action process that the organisation may not have capacity to manage at that moment. Used well, they are a professional and proportionate tool. Used carelessly, they become a dumping ground for findings the auditor is not confident enough to classify properly.
The Observation Trap
The trap with observations is using them to avoid making a difficult call. Some auditors raise an observation when they know they should be raising a nonconformity, but they are concerned about the auditee's reaction, or they are not confident enough in their evidence. This is a failure of professional integrity.
If you have objective evidence that a requirement is not being met, you raise a nonconformity. If you do not have that evidence, you either gather more or you do not raise a finding at all. Downgrading a genuine NC to an observation because it feels more comfortable is a disservice to the auditee and undermines the value of the audit.
Applying the Three Classifications in Practice
The following scenarios illustrate how the same general area can produce different classifications depending on what the evidence actually shows.
Scenario One: Competence Records
You are auditing the training function of a medium sized engineering firm against ISO 9001.
- NC scenario: The procedure requires competence assessments to be completed within 30 days of a new employee starting. You review records for six employees hired in the past six months and find that four have no competence assessment on file at all. This is a minor nonconformity against Clause 7.2.
- OFI scenario: All six employees have competence assessments on file and completed within the required timeframe. However, the assessments are a simple sign-off sheet with no evidence of how competence was evaluated. The process is technically meeting the documented requirement, but the quality of the evidence is weak. This is an OFI suggesting a more structured evaluation methodology.
- Observation scenario: Five of the six employees have assessments completed on time. One assessment was completed 45 days after the start date, which is outside the 30-day requirement. However, the employee in question was on approved leave for 10 of those days, and the procedure does not address how leave periods affect the timeline. You note this as an observation, flagging the ambiguity in the procedure for management to consider.
Scenario Two: Emergency Preparedness Under ISO 14001
- NC scenario: The organisation has identified a chemical spill as a potential environmental emergency and documented a response procedure. However, the procedure has never been tested and there is no record of any drill or exercise in the past three years. Clause 8.2 requires the organisation to test its emergency response procedures where practicable. This is a nonconformity.
- OFI scenario: Emergency drills are conducted annually and records are maintained. However, the post-drill review does not capture lessons learned in a structured way, and there is no evidence that findings from drills have ever been fed back into procedure updates. The requirement is being met, but the feedback loop is weak. This is an OFI.
- Observation scenario: Drills are conducted and documented. The most recent drill identified a gap in the location of spill kits in one area of the site. The corrective action was raised and closed. However, during your site walk you notice the spill kit in that area is now expired. The corrective action was completed, but the issue appears to be recurring. You raise an observation noting the pattern.
Common Mistakes When Classifying Findings
Even experienced auditors make classification errors. Here are the most common ones to watch for.
Raising NCs Without a Specific Requirement
Every nonconformity must be anchored to a specific clause, procedure, or documented requirement. If you cannot identify the requirement that is being breached, you do not have an NC. Vague statements like the system is not effective or the process needs improvement are not nonconformities. They might be OFIs, but they need to be grounded in evidence and framed appropriately.
Confusing OFIs With NCs
The opposite problem also occurs. Some auditors are reluctant to raise nonconformities and instead soften everything into OFIs. This is particularly common in internal audits where the auditor has a collegial relationship with the auditee. If the evidence supports an NC, raise it. Softening a genuine nonconformity into an OFI does not help the organisation improve. It obscures the real state of the system.
Over-Classifying Minor Issues
Not everything needs to be a finding. If you notice a minor administrative inconsistency that has no real impact on the system, consider whether it warrants formal classification at all. Raising large numbers of minor findings can dilute the impact of the ones that genuinely matter. Audit reports that list 30 OFIs tend to get ignored. Reports that contain three well-targeted NCs and two substantive OFIs tend to drive real action.
Failing to Distinguish Between Systemic and Isolated Issues
When you find a gap, ask yourself whether it is a one-off or whether it reflects a broader pattern. A single missing record is usually a minor NC. The same missing record across 15 files is a systemic failure that warrants a major NC or at least a stronger minor NC with a note about the systemic nature of the issue. Sampling is the tool that helps you make this determination. Understanding audit sampling techniques is essential for drawing defensible conclusions about the scope of a finding.
Exemplar Global Recognised Training ProviderRTP No. 310970Grading Findings in the Audit Report
Once you have classified your findings during the audit, they need to be communicated clearly in the audit report. Each finding should be presented with its classification, the evidence on which it is based, and the specific requirement it relates to (for NCs) or the rationale for the suggestion (for OFIs and observations).
The closing meeting is where you present findings to the auditee before the formal report is issued. This is an important step because it gives the auditee the opportunity to clarify any factual errors in your evidence before the finding is formalised. It is not an opportunity for the auditee to negotiate away a valid nonconformity, but it is a professional courtesy that improves the accuracy of the final report.
For a structured approach to presenting findings without creating unnecessary conflict, this article on grading nonconformities including major, minor and the grey zone provides additional guidance on the judgement calls involved.
Building Classification Confidence Over Time
Classification confidence comes with practice and reflection. After every audit, review your findings and ask yourself whether you made the right calls. Were there situations where you raised an OFI but, on reflection, there was actually a requirement being breached? Were there NCs that, in hindsight, were isolated incidents you elevated too quickly?
Peer review is also valuable. If you work with other auditors, discuss borderline cases. There is rarely one definitive answer in a grey-zone situation, but talking through the reasoning helps you develop a more consistent and defensible approach.
If you are working towards auditor certification or looking to sharpen your classification skills in a structured training environment, the internal auditor and lead auditor courses at Audit Workshop cover finding classification in depth, with practical exercises that reflect the kinds of borderline situations you will encounter on real audits. The training is built by practitioners who have conducted hundreds of certification audits across Australia and internationally, so the guidance is grounded in what actually happens in the field, not just what the textbooks say.













