Exemplar Global Certified Courses from USD 119. Ending Soon!

Nonconformity and Corrective Action: How Clause 10.2 Works

AW

Team @ Audit Workshop

14 min read
Nonconformity and Corrective Action: How Clause 10.2 Works

Why Clause 10.2 Matters More Than Most People Think

Clause 10.2 appears in every major ISO management system standard. ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 42001 all contain it, worded almost identically because they share the same harmonised structure. The clause covers nonconformity and corrective action, which sounds straightforward until you watch organisations repeatedly get it wrong.

The most common failure is not a lack of paperwork. Organisations generally have corrective action registers, forms, and tracking spreadsheets. The failure is in the thinking. People confuse fixing the immediate problem with actually investigating why it happened. They close corrective actions without checking whether the fix actually worked. They treat Clause 10.2 as a compliance box to tick rather than a mechanism for genuine improvement.

This article walks through what Clause 10.2 actually requires, how it works in practice across different ISO standards, and what auditors look for when they assess whether your corrective action process is functioning or just filling space in a register.

What the Clause Actually Says

The wording of Clause 10.2 is consistent across the harmonised ISO standards. When a nonconformity occurs, the organisation must:

  • React to the nonconformity and take action to control and correct it, and deal with the consequences
  • Evaluate the need for action to eliminate the causes of the nonconformity, so that it does not recur or occur elsewhere
  • Implement any action needed
  • Review the effectiveness of any corrective action taken
  • Update risks and opportunities determined during planning, if necessary
  • Make changes to the management system, if necessary

The clause also requires that corrective actions be appropriate to the effects of the nonconformities encountered, and that the organisation retain documented information as evidence of the nature of the nonconformities, actions taken, and results of corrective action.

That is the full requirement. It is not complicated on paper. The difficulty is in execution, particularly around root cause analysis and effectiveness review, which most organisations handle poorly.

The Difference Between Correction and Corrective Action

This distinction trips up a lot of practitioners, and it matters enormously when an auditor is reviewing your records. A correction is the immediate fix. You quarantine the nonconforming product, re-train the operator, update the record, restore the system access. You deal with the thing that went wrong right now.

A corrective action is what you do to prevent recurrence. It addresses the cause, not the symptom. If a batch of product was released without final inspection because the inspector was absent and no one covered the role, the correction is to quarantine the batch and inspect it. The corrective action investigates why there was no cover arrangement, whether the procedure requires one, whether this has happened before, and what systemic change will prevent it from happening again.

Many organisations document corrections and call them corrective actions. Auditors see this constantly. The register shows the nonconformity, shows a fix, and shows a close out date. But there is no root cause analysis, no systemic action, and no effectiveness check. That is a nonconformity in itself, and it is one of the most common findings raised under Clause 10.2.

For a deeper look at how this distinction plays out in practice, the article on Correction vs Corrective Action: Why Auditors Care is worth reading before your next audit.

Root Cause Analysis: The Step Most Organisations Skip

Clause 10.2 requires organisations to evaluate the need for action to eliminate causes. That evaluation must include root cause analysis when the nonconformity is significant enough to warrant it. The standard does not prescribe a specific method, but auditors expect to see a genuine investigation, not a one-line explanation.

The most widely used tools are the 5 Whys and the fishbone diagram. The 5 Whys approach involves asking why the problem occurred, then asking why that happened, continuing until you reach an underlying systemic cause rather than a surface description. The fishbone diagram maps potential causes across categories such as people, process, equipment, materials, environment, and management, which is useful for more complex nonconformities where multiple factors may be contributing.

In practice, root cause analysis quality varies enormously. Here are examples of what good and poor root cause documentation looks like.

Poor Root Cause Analysis

Nonconformity: Internal audit records not retained for the required period.

Root cause documented: Records were not saved correctly.

This tells you nothing. It describes the problem again in different words. There is no investigation into why records were not saved, whether the procedure was unclear, whether responsibility was assigned, or whether the system for storing records is inadequate.

Adequate Root Cause Analysis

Nonconformity: Internal audit records not retained for the required period.

Root cause documented: The procedure for document control assigns responsibility for saving audit records to the internal auditor completing the audit. However, the procedure does not specify where records are to be saved, and two of the three internal auditors were storing records in personal folders on local drives rather than the shared document management system. When one auditor left the organisation, those records were deleted with their account. The root cause is an incomplete procedure that does not specify storage location or format, combined with no verification step to confirm records have been filed correctly.

That is a root cause analysis. It identifies the systemic failure, not just the symptom. The corrective action that follows should address the procedure gap and introduce a verification step, not just remind auditors to save their files properly.

How Corrective Actions Should Be Scoped

Clause 10.2 specifies that corrective actions must be appropriate to the effects of the nonconformities encountered. This is an important calibration requirement. Not every nonconformity warrants a full root cause investigation and system overhaul. A minor administrative error with no safety or quality consequence needs a proportionate response. A major nonconformity that could result in product recall, regulatory breach, or serious injury warrants a thorough investigation and significant corrective action.

Auditors assess proportionality. If an organisation responds to a minor filing error with a ten page root cause analysis and a system redesign, that is disproportionate. If they respond to a serious nonconformity with a one-line fix and no investigation, that is inadequate. Both represent poor application of Clause 10.2.

When grading nonconformities and deciding on corrective action scope, consider the actual or potential impact on the customer, worker, environment, or information security, depending on which standard applies. Consider whether the nonconformity is isolated or systemic. Consider whether it has occurred before. These factors should inform how deeply you investigate and how broadly you apply the corrective action.

Effectiveness Review: The Step That Gets Skipped

After implementing a corrective action, Clause 10.2 requires the organisation to review the effectiveness of the action taken. This is the step most organisations skip, and auditors know it.

Effectiveness review means going back after a defined period and checking whether the corrective action actually worked. Did the problem recur? Did the systemic cause get addressed? Is the new control working as intended? If the corrective action was to update a procedure and train staff, the effectiveness review should check whether the procedure is being followed, not just whether the training occurred.

Common failures in effectiveness review include:

  • Closing the corrective action as effective on the same day the action was implemented, with no time allowed for verification
  • Marking actions as effective based on completion of the action rather than evidence that the problem did not recur
  • No documented evidence of the effectiveness check at all
  • The same person who raised the nonconformity closing it as effective without independent verification

A practical approach is to set a review date at least one cycle after the corrective action is implemented. If the nonconformity involved a monthly process, review effectiveness after the next monthly cycle. If it involved an annual activity, plan a follow up before the next occurrence. Document what you checked, what evidence you reviewed, and your conclusion.

Clause 10.2 Across Different ISO Standards

The core requirement is the same across standards, but the context changes what nonconformities look like and what corrective actions are appropriate.

ISO 9001 Quality Management

In a quality context, nonconformities typically arise from product or service failures, process deviations, customer complaints, or internal audit findings. Corrective actions often involve process redesign, supplier controls, competence improvements, or changes to inspection and testing arrangements. The link between corrective action and risk based thinking is important here. Clause 10.2 specifically requires updating risks and opportunities if necessary, which means a significant quality nonconformity should feed back into your risk register.

ISO 14001 Environmental Management

Environmental nonconformities often involve compliance failures, spills, incorrect waste disposal, or failure to meet permit conditions. The consequences can extend beyond the organisation to regulators and affected communities, which increases the stakes for thorough corrective action. The Nonconformity and Corrective Action: Clause 10.2 of ISO 14001:2026 Explained article covers the specific requirements under the updated standard.

ISO 45001 Occupational Health and Safety

Under ISO 45001, Clause 10.2 is closely linked to incident investigation. When an incident occurs, including near misses, the organisation must investigate, determine root causes, and implement corrective actions to prevent recurrence. The clause also requires worker participation in the corrective action process, which is a distinctive requirement in the safety standard. Auditors will check whether workers were involved in investigating incidents that affected them, not just whether management completed a form.

ISO 27001 Information Security

In an ISMS context, nonconformities often arise from security incidents, failed controls, audit findings, or vulnerabilities identified during risk assessment. Corrective actions may involve technical controls, access management changes, policy updates, or training. The effectiveness review is particularly important here because information security threats evolve. A corrective action that was effective six months ago may no longer be adequate if the threat landscape has changed.

What Auditors Check When They Assess Clause 10.2

When an auditor reviews your corrective action process, they are looking for evidence across several dimensions.

Volume and Pattern of Nonconformities

Auditors look at the corrective action register to understand what nonconformities the organisation has raised over the past year. A register with very few entries is suspicious. Either the organisation has no internal audit programme, no customer complaint process, or no mechanism for staff to raise issues, or nonconformities are being suppressed. A healthy organisation raises nonconformities regularly because it has functioning systems for identifying them.

Quality of Root Cause Analysis

Auditors sample corrective action records and read the root cause analysis. They are looking for genuine investigation, not surface descriptions. They will ask questions like: How did you determine this was the root cause? What evidence did you review? Did you consider whether this could be happening in other areas?

Appropriateness of Actions Taken

Does the corrective action actually address the root cause? If the root cause was an inadequate procedure, did they update the procedure? If the root cause was a training gap, did they train the right people? Auditors check whether the action taken is logically connected to the cause identified.

Effectiveness Review Evidence

Auditors look for documented evidence that effectiveness was checked after implementation. They check the timing of the review and whether it was genuinely independent. They may ask: How do you know this corrective action worked? What did you check?

Trends and Management Review

Corrective action data should feed into management review. Auditors check whether trends in nonconformities are being analysed and whether that analysis is informing management decisions. If the same type of nonconformity keeps appearing in different departments, that is a systemic issue that management needs to address.

Building a Corrective Action Process That Actually Works

The mechanics of a good corrective action process are not complicated. What makes the difference is discipline in execution.

First, make it easy to raise nonconformities. If your process requires three approvals before someone can log a corrective action, you will get fewer nonconformities, not fewer problems. The barrier to raising issues should be low.

Second, assign clear ownership. Every corrective action needs a named person responsible for investigation, implementation, and effectiveness review. Shared ownership means no ownership.

Third, set realistic target dates. A corrective action closed two days after it was raised, with a root cause analysis and effectiveness review completed in that window, is almost certainly not genuine. Allow enough time for proper investigation and for the corrective action to be implemented and verified.

Fourth, build in an independent effectiveness check. The person who implemented the corrective action should not be the sole judge of whether it worked. Internal auditors, quality managers, or line managers from other areas can provide a more objective assessment.

Fifth, use the data. Your corrective action register is a source of intelligence about where your management system is weak. Analyse it by process, by department, by type of nonconformity. Look for patterns. Present that analysis at management review and use it to prioritise improvement efforts.

If you want to strengthen your ability to raise nonconformities that hold up to scrutiny, the article on How to Write Nonconformities That Hold Up covers the practical side of documenting findings in a way that drives genuine corrective action.

Common Clause 10.2 Nonconformities Raised by External Auditors

Based on real audit experience across multiple standards and industries, the following are the most frequently raised nonconformities against Clause 10.2.

  • Corrective actions closed without documented root cause analysis
  • Root cause analysis that describes the symptom rather than the systemic cause
  • No documented evidence of effectiveness review
  • Effectiveness review completed on the same day as implementation with no verification period
  • Corrective actions not linked to risks and opportunities in the management system
  • The same nonconformity recurring because the corrective action addressed the symptom only
  • Corrective action register not reviewed at management review
  • No corrective actions raised despite evidence of recurring problems in audit records and customer complaints

If you are preparing for a certification or surveillance audit, reviewing your corrective action register against these criteria before the auditor arrives is time well spent. The article on Auditing Corrective Action and Root Cause Under Clause 10.2 provides an auditor perspective on exactly what gets examined.

Training That Builds Real Corrective Action Competence

Understanding Clause 10.2 at a conceptual level is straightforward. Applying it consistently, especially the root cause analysis and effectiveness review components, requires practice and feedback. This is one of the areas where good auditor training makes a tangible difference.

At Audit Workshop, our internal auditor and lead auditor courses cover Clause 10.2 in practical depth. Participants work through real corrective action scenarios, practise root cause analysis using structured methods, and learn how to assess effectiveness review evidence. The training is built on over 14 years of actual audit experience across hundreds of certification audits, which means the examples and exercises reflect what happens in real organisations, not just what the standard says in theory.

Whether you are a quality manager building a corrective action process for the first time, an internal auditor learning to assess whether corrective actions are genuine, or a lead auditor preparing to evaluate Clause 10.2 conformity on a certification audit, the practical skills developed in structured training will sharpen your judgement significantly. Explore the available courses at Audit Workshop and find the level that fits where you are in your auditing career.

Frequently Asked Questions

A correction is the immediate action taken to fix a nonconformity, such as quarantining a defective product or restoring a system to working order. A corrective action goes further by investigating the root cause of the nonconformity and implementing changes to prevent it from recurring. Clause 10.2 requires both, and auditors will look for evidence that root cause analysis was conducted and that the action taken addresses the cause rather than just the immediate problem.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2026 Lead Auditor Training Course
Launching on 22 Sept 20265+ enrolled
View Details
Exemplar Global certified
ISO 9001:2026 Lead Auditor Training Course badge
ISO 9001:2026 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 299USD 789
ISO 45001:2018 Lead Auditor Training Course
15+ enrolled
View Details
Exemplar Global certified
ISO 45001:2018 Lead Auditor Training Course badge
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
ISO 14001:2026 Lead Auditor Training Course
10+ enrolled
View Details
Exemplar Global certified
ISO 14001:2026 Lead Auditor Training Course badge
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Digital badges and a certificate
  • Access to webinars, events, and online resources

Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Instant Certificate

Download your digital certificate the moment you complete the course.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.