Why Grading Nonconformities Has Always Been Contested Territory
Ask ten auditors how they classify a nonconformity and you will likely get ten slightly different answers. The line between major and minor has always involved judgement, and that judgement has not always been consistent. Some auditors grade by severity of the evidence in front of them. Others grade by the potential consequences of the gap. Others still follow informal rules of thumb passed down through training programmes that were written well before the current edition of ISO 19011 existed.
On this page
ISO 19011:2026 does not remove that judgement. What it does is give auditors a clearer framework for exercising it. The 2026 edition tightens the guidance around how findings should be classified, communicated, and reported, and it places greater weight on the auditor explaining the reasoning behind a grading decision rather than simply labelling something major or minor and moving on.
This article walks through what has changed, what it means in practice, and how auditors should adjust their approach when classifying findings under the new edition. If you want a solid grounding in the underlying terminology before reading further, the post on what is a nonconformity is a good starting point.
What ISO 19011:2026 Actually Says About Grading
The 2026 edition of ISO 19011 does not introduce a rigid scoring matrix for nonconformities. It is a guidance standard, not a requirements standard, so it cannot mandate a particular grading system. What it does is expand the guidance on how audit findings should be evaluated, documented, and presented, and it makes clear that the grading of a nonconformity should be supported by the evidence gathered, not by instinct alone.
Several specific shifts are worth understanding.
Greater Emphasis on Evidence Linkage
Under the 2026 edition, the expectation is that every grading decision connects directly to the evidence collected during the audit. If an auditor grades a finding as major, the nonconformity report should make it apparent why that grading was reached. The evidence should speak to the extent of the failure, the breadth of its impact, and whether the management system has demonstrated any capacity to detect or correct the issue on its own.
This is not entirely new, but the 2026 edition makes it more explicit. Auditors who have been writing nonconformity reports that state a finding is major without explaining the basis for that conclusion will need to adjust. The report should show the reasoning, not just announce the result.
Risk Context Is Now Central to Grading
The 2026 edition reinforces the risk based approach to auditing throughout the guidance, and this flows directly into how findings are graded. A nonconformity that exists in a low risk process with limited consequences for the customer or the system is unlikely to warrant a major classification even if it represents a clear departure from the requirement. Conversely, a single instance of non compliance in a critical control can absolutely justify a major finding if the evidence shows that the control failure creates meaningful exposure.
Auditors are expected to apply their knowledge of the auditee's context, the nature of the process being audited, and the potential consequences of the gap when deciding how to classify a finding. This is consistent with the broader changes in ISO 19011:2026 around risk based audit planning and execution, which are discussed in the post on ISO 19011:2026 Is Here: What Changed from the 2018 Edition.
Closing Meeting Obligations Are Tighter
One of the more practical changes in the 2026 edition relates to how nonconformities are communicated at the closing meeting. The guidance now makes it clear that the grading assigned to a finding should be explained to the auditee at the closing meeting, not simply announced. If a finding is graded as major, the auditor should be prepared to walk through the evidence and the reasoning. The auditee should leave the closing meeting understanding why the finding was classified the way it was, not just that it was.
This change reflects a broader theme in the 2026 edition around transparency and fair presentation. Audit findings, including their grades, should be communicated in a way that the auditee can act on them. Ambiguity at the closing meeting creates disputes later and undermines the corrective action process.
Exemplar Global Recognised Training ProviderRTP No. 310970The Major and Minor Distinction: What It Means and Why It Matters
The distinction between major and minor nonconformities is not defined in ISO 19011 itself. ISO 19011 is a guidance standard for managing and conducting audits. The major and minor classification system is used by certification bodies under the requirements of ISO/IEC 17021, and it has practical consequences for whether an organisation retains its certification, requires a follow up audit, or needs to submit documented evidence of correction before the certificate can be maintained.
For internal auditors, the grading system is less formally governed but no less important. A major finding in an internal audit signals that the management system has a significant gap that needs priority attention. A minor finding signals a contained problem that still requires corrective action but does not represent a systemic failure. Getting the grading right matters because it shapes how management responds and how resources are allocated to corrective action.
What Makes a Nonconformity Major
A nonconformity is generally considered major when one or more of the following conditions apply.
- The requirement has not been implemented at all, rather than being implemented imperfectly.
- The failure is systemic, meaning it appears across multiple instances, locations, or processes rather than being isolated to a single occurrence.
- The failure undermines the ability of the management system to achieve its intended outcomes.
- The failure has resulted in, or creates significant risk of, a serious consequence such as a safety incident, a legal breach, or a product or service failure reaching the customer.
- A previously identified nonconformity has not been effectively addressed and the same failure has recurred.
None of these criteria operate in isolation. An auditor needs to weigh the evidence and apply judgement. A single missing record is almost never major on its own. The same missing record in a regulated process where that record is the only mechanism for demonstrating legal compliance is a different matter entirely.
What Makes a Nonconformity Minor
A minor nonconformity is a departure from a requirement that is isolated, contained, and does not undermine the overall functioning of the management system. The requirement exists and is generally being met. The failure is an exception rather than a pattern.
Minor findings still require corrective action. The distinction is not that minor findings can be ignored. It is that the corrective action can be proportionate to the scale of the problem, and the finding does not create an immediate barrier to certification or recertification.
The Grey Zone Between Major and Minor
The most difficult grading decisions sit in the space between clear major and clear minor. A finding that involves three or four instances of the same failure across different parts of the business might be borderline. A finding that relates to a documented procedure that exists but is not being followed in one department raises questions about whether this is a local anomaly or an indication of a wider cultural issue.
The 2026 edition of ISO 19011 provides more guidance on how to reason through these situations. The key is to gather enough evidence to make an informed judgement rather than defaulting to the lesser classification to avoid conflict. If the evidence suggests a pattern, the auditor should say so and grade accordingly. If the evidence is genuinely insufficient to determine whether a failure is isolated or systemic, that is a signal to gather more evidence before the closing meeting rather than to guess.
The post on Grading Nonconformities: Major, Minor and the Grey Zone covers this territory in more depth and is worth reading alongside this article.
How the 2026 Edition Changes the Auditor's Practical Approach
The changes in ISO 19011:2026 around nonconformity grading are not so much a rewrite of the rules as a tightening of expectations around how auditors document and communicate their reasoning. Here is what that looks like in practice.
During the Audit: Build the Case Before You Grade
Under the 2026 edition, auditors should resist the temptation to assign a grade mentally before they have finished gathering evidence. It is common for experienced auditors to form an initial impression of a finding early in the audit and then look for confirmation. The problem is that this approach can lead to premature grading that does not reflect the full picture.
A better approach is to note the potential finding, continue gathering evidence across the relevant process, and then assess the grade once the evidence base is complete. This is particularly important for findings that might be major. The consequences of incorrectly grading a finding as major are significant for the auditee. The consequences of incorrectly grading a major finding as minor are significant for the integrity of the audit.
In the Nonconformity Report: Show Your Reasoning
The nonconformity report should do more than state what was found and what requirement was not met. Under the expectations of the 2026 edition, it should also make clear why the finding was graded the way it was. This does not need to be lengthy. A sentence or two explaining that the finding was graded as major because the failure was observed across four separate work orders and no detection mechanism exists within the process is sufficient. What is not sufficient is simply writing major in the grade field with no further explanation.
For auditors who want to sharpen their nonconformity report writing, the post on Writing Nonconformance Reports That Actually Drive Change covers the practical elements of structuring a finding that holds up to scrutiny and drives genuine corrective action.
At the Closing Meeting: Explain, Do Not Just Announce
The closing meeting is where grading decisions become real for the auditee. Under the 2026 edition, the expectation is that the auditor explains the basis for each grading, particularly for major findings. This means being prepared to walk through the evidence, describe the pattern observed, and explain why the failure rises to the level of major rather than minor.
This requires preparation. Auditors should have their evidence notes organised before the closing meeting so they can speak to the basis of each finding clearly and confidently. Auditees who understand why a finding was graded the way it was are far more likely to engage constructively with the corrective action process. Auditees who feel a grading was arbitrary are more likely to dispute it.
When the Auditee Disagrees: Holding Your Ground on Evidence
One of the more uncomfortable situations in auditing is when an auditee disputes a grading. This happens most often with major findings, where the consequences for certification are significant. The 2026 edition does not change the fundamental principle here. The grading should be based on evidence, and if the evidence supports a major classification, the auditor should be able to defend that position by reference to the evidence rather than by assertion.
If the auditee presents additional evidence during the closing meeting that genuinely changes the picture, the auditor should be willing to reconsider. That is not weakness. That is fair presentation, which is one of the core principles of auditing under ISO 19011. What the auditor should not do is change a grading simply because the auditee is unhappy about it. The grade should follow the evidence, not the auditee's preference.
Grading Nonconformities in Internal Audits Versus Certification Audits
The grading framework operates differently depending on the type of audit. In a certification audit conducted by a third party certification body, the major and minor classification has formal consequences governed by ISO/IEC 17021. A major nonconformity typically means the organisation cannot be recommended for certification or continuation of certification until the finding is closed out to the satisfaction of the certification body.
In an internal audit, the classification system is less formally governed but should still be applied consistently. Internal auditors should use the same underlying logic: is this an isolated failure or a systemic one? Does it undermine the intended outcomes of the management system? Is there a pattern across multiple instances or locations?
The value of applying a consistent grading framework in internal audits is that it helps management prioritise corrective action. If everything is called a major finding, the classification loses meaning. If auditors consistently undergrade to avoid difficult conversations, the internal audit programme fails in its purpose of identifying genuine gaps before they become certification problems.
Exemplar Global Recognised Training ProviderRTP No. 310970Practical Examples of Grading Decisions Under the 2026 Approach
Example One: Training Records
An auditor reviewing competence records finds that two out of eighteen operators in a production area do not have documented evidence of completing the mandatory induction training. The procedure requires all operators to complete induction before working unsupervised. Both operators have been working unsupervised for several months.
Under the 2026 approach, the auditor would consider whether this is isolated or systemic. Two out of eighteen is not a pattern across the whole workforce, but both operators have been working in violation of the procedure for an extended period with no detection by the management system. The auditor might grade this as minor if the rest of the records are in order and there is a clear mechanism for monitoring compliance that simply failed in these two cases. Alternatively, if the monitoring mechanism does not exist or has not been operating, the finding may warrant a major classification because the control is not functioning as intended.
Example Two: Internal Audit Programme
An auditor conducting a certification audit finds that the organisation has not completed any internal audits in the previous twelve months. The management system documentation includes an internal audit procedure and a schedule, but the schedule has not been followed. No audits have been conducted, no records exist, and no explanation has been provided for the failure to implement the programme.
This is almost certainly a major nonconformity. The requirement to conduct internal audits is fundamental to the functioning of a management system. The complete absence of internal audit activity is not an isolated failure. It is a systemic failure of a core requirement. The grading is straightforward, and the evidence is unambiguous.
Example Three: Documented Information
An auditor finds that one version of a work instruction has not been updated to reflect a process change that was implemented three months ago. The updated process is being followed correctly by all operators. The document control register shows the document is due for review. The change was communicated verbally but the document was not formally revised and reissued.
This is most likely a minor nonconformity. The process is being performed correctly. The failure is in the document control system, not in the process itself. The risk to product or service quality is low. The corrective action is straightforward: update the document, reissue it, and check whether other documents affected by the same process change also need updating.
What Auditors Should Do Now
If you are an internal auditor or a lead auditor conducting certification audits, the practical adjustments required by ISO 19011:2026 in relation to nonconformity grading are not dramatic. They are a sharpening of existing good practice rather than a wholesale change of approach.
Review your nonconformity report template and make sure it has a field for recording the basis of the grading decision, not just the grade itself. Practise articulating the reasoning for major classifications out loud before the closing meeting. Build the habit of gathering enough evidence to support a grading before you commit to it in writing. And when you present findings at the closing meeting, explain the reasoning rather than just announcing the outcome.
These habits are consistent with what the 2026 edition expects and with what good auditors have always done. The difference is that the 2026 edition makes these expectations explicit rather than leaving them to individual interpretation.
If you are looking to build or refresh your auditing skills with training that reflects the current edition of ISO 19011, Audit Workshop offers Lead Auditor and Internal Auditor courses across ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 42001, and other standards. The courses are designed by practising auditors and grounded in real audit scenarios, including the kind of grading decisions and closing meeting challenges that come up in every audit programme. You can explore the available courses at auditworkshop.com.













