Nonconformity and corrective action procedure
How a failure to follow a document, an audit finding or an incident lesson becomes a recorded action with an owner and a closure.
How the register reads it
| Also called | CAPA, nonconformance procedure |
|---|---|
| Family | Governance and the management system |
| Document type | Procedure. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Expected owner | The information security lead (CISO or ISMS manager). |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | ISO 27001 or ISO 27701 or ISO 22301 is ticked and no line resolves to it. |
| Template | Corrective action policy. |
Which standards require it, and what each expects it to contain
3 requiring clauses, 3 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. A clause marked named is one of ISO/IEC 27001:2022's management clauses (4 to 10), named with its title and not quoted here.
ISO/IEC 27001:2022
Named, not quoted: 10.2named Nonconformity and corrective action.
ISO/IEC 27701:2025
ISO 27701 10.2 Nonconformity and corrective actionWhen a nonconformity occurs the organization shall react to it and, as applicable, take action to control and correct it and deal with the consequences; evaluate the need for action to eliminate the causes of the nonconformity so that it does not recur or occur elsewhere, by reviewing the nonconformity, determining its causes and determining whether similar nonconformities exist or could potentially occur; implement any action needed; review the effectiveness of any corrective action taken; and make changes to the PIMS if necessary. Corrective actions shall be appropriate to the effects of the nonconformities encountered, and the organization shall retain documented information as evidence of the nature of the nonconformities and any subsequent actions taken, and of the results of any corrective action.
Common gap: Corrections applied without a cause analysis
Source: ISO/IEC 27701:2025
ISO 22301:2019
ISO 22301 10.1 Nonconformity and corrective actionDetermine opportunities for improvement and implement the actions needed to achieve the intended BCMS outcomes; when a nonconformity occurs, react to it and deal with its consequences, evaluate whether action is needed to eliminate the cause by reviewing the nonconformity, determining its causes and checking whether similar ones exist or could occur, implement whatever action is needed, review the effectiveness of the corrective action, and change the BCMS if necessary, with corrective action proportionate to the effects encountered and documented evidence retained of the nature of the nonconformities, the actions taken and the results.
Common gap: Correction recorded as corrective action, with the cause never examined
Source: ISO 22301:2019
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a register