ISO corrective actions and non-conformances explained
Three words that get used interchangeably and shouldn't be: non-conformance, correction and corrective action. Getting them straight is the difference between a system that fixes problems and one that keeps repeating them.
The three terms
Non-conformance (NC)
A failure to meet a requirement — of the standard, of your own procedures, or of a legal or customer requirement. It is the finding: something is not as it should be.
Correction
The immediate fix to the specific problem — containing or putting right what went wrong right now. Important, but on its own it does not stop it happening again.
Corrective action
Action to remove the root cause so the non-conformance does not recur. This is what the standard actually requires beyond the immediate correction — dealing with the why, not just the what.
The loop, from finding to closure
A non-conformance — from an internal audit, an external audit, an incident or a complaint — should run through the same loop: contain it (correction), analyse the root cause, decide and implement the corrective action with an owner and a date, then verify the action was effective before closing it. Verification is the step most systems miss: an action marked "done" is not the same as a problem that has actually stopped recurring.
This is the engine of continual improvement, and it is common to every ISO management-system standard. Running it in one place — so findings, actions, owners, due dates and evidence of closure all live together — is exactly what compliance audit software does, feeding your wider ISO compliance system.
Close every finding, provably
Turn non-conformances into owned, dated corrective actions and track them to verified closure — with the audit trail an assessor expects.
Compliance audit software →FAQs
What's the difference between a correction and a corrective action?
A correction fixes the immediate problem (clean up the spill, re-issue the wrong document). A corrective action removes the underlying cause so it does not happen again (find why the wrong version was in use and fix the document-control gap). ISO requires both where appropriate, but the corrective action is the part people skip.
What is the difference between a minor and a major non-conformance?
Broadly, a minor non-conformance is an isolated lapse that does not undermine the system; a major non-conformance is a systemic failure, a total absence of a required process, or something that raises serious doubt the system can deliver. In practice, most certification schemes require a major non-conformance to be resolved (or a corrective-action plan accepted) before the certificate is granted or continued — though the exact handling is set by the certification scheme rather than by the standard itself.
Do all non-conformances need root-cause analysis?
The standard expects you to evaluate the need to eliminate the cause so it does not recur, proportionate to the effect. Minor, one-off issues may need a light touch; recurring or significant ones need genuine root-cause analysis, not a box-tick.
Related: ISO internal audit checklist, preparing for a certification audit, and what is an IMS.