Skip to content

Raise and resolve a non-conformity

Applies to
  • All users
  • Managers
  • Admins
Before you start
  • You have a finding from an audit, inspection, incident or review
  • Non-conformities is enabled for your workspace

The non-conformity register records findings — where something failed to meet a standard, procedure or requirement — surfaced by audits, inspections, incidents and reviews. Each finding gets a reference like NCR-0001 and carries its root-cause analysis, corrective actions and effectiveness check with it.

Find it under GovernanceNon-conformities.

The Non-conformities register listing findings with their reference, grade, corrective-action progress and lifecycle status.
  1. Go to Non-conformities and select Raise.
  2. Enter the Title and a Description of what was found and why it’s a non-conformity.
  3. Choose the Source — Internal audit, External audit, Certification audit, Inspection, Incident, Supplier review, Management review, Customer complaint or Self-identified.
  4. For an audit source, choose the Standard — ISO/IEC 27001:2022, ISO 45001:2018, ISO 22301:2019 or PCI-DSS v4.0.
  5. Add a Control reference if the finding cites a clause, such as A.8.24.
  6. Choose the Grade — Major, Minor or Observation.
  7. Set the Owner — leave it empty and it defaults to you.
  8. Save with Raise.
  1. Open the non-conformity and go to Root cause analysis.
  2. Choose the Methodology — 5 Whys, Fishbone, 8D or Narrative.
  3. Write the Root cause — the underlying reason the finding occurred.
  4. Add any Contributing factors — up to 20.
  5. Save with Save root cause.

Recording the root cause on a freshly-raised finding moves it to Under analysis. You can edit the analysis later.

Add a corrective action with a Description, the person it’s Assigned to and a Due date that is today or later. Adding the first one moves the finding to Corrective action.

Each action runs OpenIn progressCompletedVerified, and flips to Overdue once its due date passes without being resolved. Cancel action retires one that no longer applies. An action counts as resolved once it is Completed, Verified or Cancelled, and the panel header tracks how many of the total are resolved.

Once every corrective action is resolved, verify that the fix actually held.

  1. Go to Effectiveness verification.
  2. Choose the Result — Effective, Partially effective or Ineffective.
  3. Record the Evidence that confirms it.
  4. Save with Record verification.

A verdict of Effective clears the finding to close. Partially effective or Ineffective loops it back for another round of corrective action — it can’t be closed until effectiveness is confirmed.

An effectiveness review falls due 30 days after the last corrective action is resolved; the Review due sort brings the ones waiting on you to the top.

Move the finding to Closed and give a Reason — closing always requires one. An Observation closes freely. A Major or Minor finding needs every corrective action resolved and effectiveness verified as Effective first; until then the Close button explains what’s outstanding.

A closed finding can be reopened back to Corrective action if new information arrives.

A non-conformity raised automatically from an Incident, Audit, Management review or Supplier review carries a link back to its source, shown under Linked records. These deep-links open once that module ships.

Raised → Under analysis → Corrective action → Effectiveness review → Closed. An observation that needs no formal follow-up can close without the middle steps.

Reports covers open findings grouped by grade, source, standard or owner, your closure rate, the average time to close by grade, and recurring root causes — over a 30, 90 or 365-day window. Export the register itself with Export CSV or Export PDF.