ISO 27001 Clause 10.2: Nonconformity and Corrective Action

· 7 min read · Lyudmil Arkov

Clause 10.2 defines what your organization does when something in the ISMS goes wrong. A nonconformity is any failure to meet a requirement - a control that is not working, a procedure nobody follows, an obligation missed. Clause 10.2 requires you not just to fix the immediate problem but to understand why it happened and stop it recurring. This is the machinery that turns mistakes into a stronger management system, and it is the direct partner of continual improvement under Clause 10.1. Handled well, corrective action is one of the clearest demonstrations that your ISMS actually learns.

What the clause requires

ISO 27001:2022 Clause 10.2 sets out a defined sequence. When a nonconformity occurs, the organization shall:

  1. React to the nonconformity and, as applicable, take action to control and correct it, and deal with the consequences
  2. Evaluate the need for action to eliminate the causes so it does not recur or occur elsewhere, by: reviewing the nonconformity; determining its causes; and determining whether similar nonconformities exist or could potentially occur
  3. Implement any action needed
  4. Review the effectiveness of any corrective action taken
  5. Make changes to the ISMS if necessary

Corrective actions must be appropriate to the effects of the nonconformities encountered. The organization must retain documented information as evidence of the nature of the nonconformities and any subsequent actions taken, and of the results of any corrective action.

The clause draws a distinction that trips up many organizations. Correction (step 1) fixes the immediate problem. Corrective action (steps 2 to 5) removes the cause so it does not happen again. Doing only the first is the most common way to fail this clause.

How to implement nonconformity and corrective action

Know where nonconformities come from

Nonconformities are not only found in audits. Legitimate sources include: internal audit findings, external audit findings, security incidents, monitoring and measurement results that breach a threshold, management review observations, staff reports, and customer or regulator feedback. A healthy ISMS captures nonconformities from all of these, not just the annual audit.

Separate correction from corrective action

For every nonconformity, do both, and record them separately:

  • Correction - the immediate fix. A former employee still has access, so you revoke it today.
  • Corrective action - the cause removal. Why did access persist? The offboarding checklist has no step to revoke SaaS access, so you add the step, assign an owner, and verify it works.

If you only revoke the one account, the same gap produces the next orphaned account. Auditors specifically probe whether you went past correction to cause.

Do root cause analysis honestly

Determining the cause (step 2) is where the value lives. Simple techniques are enough for most organizations - the “5 Whys” is a common one: keep asking why until you reach a cause you can actually eliminate, usually a process, resource, or awareness gap rather than “human error.” “The employee forgot” is rarely a root cause; “there is no procedure that would have caught the omission” usually is.

Then ask the clause’s other question: do similar nonconformities exist elsewhere, or could they? If one team’s offboarding missed SaaS access, check the others. This “occur elsewhere” test is a requirement, not an optional extra.

Make the action proportionate

Corrective actions must be appropriate to the effects. A minor documentation error does not need a company-wide programme; a control failure that exposed customer data does. Over-engineering trivial findings wastes effort and buries real issues; under-reacting to serious ones is a nonconformity in itself.

Verify effectiveness before closing

Step 4 is non-negotiable and frequently skipped: after implementing the action, confirm it worked. Reviewing effectiveness means checking, after a suitable interval, that the nonconformity has not recurred and the cause is genuinely gone - for example, sampling the next few offboardings to confirm SaaS access is now revoked every time. Only then do you close the item, recording the evidence.

Log everything in a corrective action register

A single corrective action or nonconformity register - sometimes loosely called a CAPA log, though ISO 27001 has no preventive-action clause and relies on risk-based thinking instead - gives you the documented evidence the clause requires. For each entry track: description, source, date raised, severity, immediate correction, root cause, corrective action, owner, due date, status, effectiveness verification, and closure date. This is the artefact auditors ask for, and it feeds trend data into monitoring and management review.

Connecting 10.2 to the rest of your ISMS

Clause 10.1 connection. Continual improvement is the goal; corrective action is one mechanism that serves it by permanently removing weaknesses. In 2022 the two swapped order, putting improvement first and correction second.

Clause 9.2 connection. Internal audit is a primary source of nonconformities. Every audit finding should flow into the corrective action process and be tracked to closure.

Clause 9.1 connection. Monitoring and measurement thresholds that are breached can raise nonconformities, and corrective-action trends are themselves a metric worth watching.

Clause 9.3 connection. Trends in nonconformities and corrective actions are a required input to management review, where systemic issues get leadership attention and resources.

Clause 6.1 connection. A recurring nonconformity may reveal that a risk was underestimated or a treatment was inadequate, feeding back into risk assessment and treatment.

What auditors check

Correction and corrective action, both present. Auditors sample nonconformities and check you did more than patch the symptom. Evidence of root cause and cause-elimination is what they want to see, not just the immediate fix.

Genuine root cause. They test the quality of the analysis. “Human error” with no deeper cause, or a corrective action that does not actually address the stated cause, gets challenged.

The “occur elsewhere” check. Auditors look for evidence you considered whether similar nonconformities exist in other areas, as the clause requires.

Effectiveness verification. They check that closed items were verified as effective, not just marked done. An item closed the same day it was raised, with no verification, is a red flag.

Proportionality and timeliness. Actions should match the severity of the issue and be closed within reasonable, tracked timeframes. A register full of overdue actions signals a process that does not work.

Complete records. The documented evidence - nature of nonconformities, actions taken, and results - must exist. Corrective action done informally but never recorded cannot be evidenced.

Common mistakes to avoid

Correcting without corrective action. The defining failure of this clause: fixing the instance and never removing the cause, so the same problem returns. Always go past the symptom.

Shallow root cause. Stopping at “someone made a mistake” avoids the real, fixable cause. Push until you reach a process, resource, or awareness gap you can change.

Skipping the effectiveness check. Closing actions without verifying they worked means you never know if the cause is gone. Build in a verification step before closure.

Ignoring the “occur elsewhere” test. Fixing one team’s gap while identical gaps sit untouched in three others is an incomplete corrective action and a likely repeat finding.

Disproportionate response. Treating every trivial finding with a heavyweight process, or waving through a serious one, both draw scrutiny. Match the action to the effect.

No register, or an overdue one. Handling nonconformities in scattered emails leaves no evidence, and a register full of stale open actions is arguably worse than none - it documents known problems you failed to close.

How 27kay can help

We help organizations build a corrective action process that genuinely removes weaknesses and produces clean audit evidence. As part of ISO 27001 implementation, we set up a practical nonconformity and corrective action register, coach teams through honest root cause analysis, and make sure effectiveness gets verified before anything is closed. We also surface nonconformities independently through our internal audit service. For the full picture, see our ISO 27001 knowledge hub.

Carrying open findings you are not sure how to close properly? Get in touch - we will help you get to real root causes and clear them before your next audit.