Conformity Assessment, Certification & Assurance
Nonconformity
A documented failure to fulfil a specified requirement, supported by objective evidence and a clear statement linking that evidence to the requirement.
Expert review openNo editor-accepted expert review yetDefinition
A documented failure to fulfil a specified requirement, supported by objective evidence and a clear statement linking that evidence to the requirement.
Overview
“A non-conformity is not a judgement that something feels wrong; it is a demonstrated gap between evidence and a requirement. ”
Non-conformity gives assurance work its discipline. Without it, an audit can become a collection of impressions: good practice, concern, risk, opportunity or unease. Those observations may be useful, but a formal non-conformity requires something more exact. A requirement exists, evidence shows that it was not fulfilled, and the finding states the gap clearly.
ISO 9000 defines nonconformity as the non-fulfilment of a requirement. ISO and IAF auditing guidance explains that a well-documented finding contains three elements: the audit evidence, the specific requirement and the statement of non-conformity. If any element is missing, the finding becomes difficult to understand, challenge or correct.
Consider a scheme requiring pesticide applications to record product, date, rate, plot and applicator. An auditor finds ten records without the rate applied.
The evidence is the incomplete records. The requirement is the specified record content. The non-conformity is the failure to record the application rate. Saying record keeping is weak is not precise enough. Saying pesticide use is unsafe goes beyond the evidence unless other facts support it. This precision protects both accountability and fairness.
An organisation should not receive a formal finding merely because an auditor dislikes a practice. Equally, an auditor should not soften a clear failure into an observation because the client is cooperative or the consequence is inconvenient. The requirement provides the common reference point. Requirements can come from standards, law, contracts, procedures, permits or commitments made by the organisation.
Their source should be explicit.
A policy that says the organisation seeks to promote safe work may be too vague to audit as a requirement. A procedure requiring protective equipment during specified tasks is testable. Better requirements create better assurance. Classification adds another layer. Schemes often use terms such as major, minor, critical or systemic, but these categories are not universal.
Their meaning should be defined by the scheme and linked to severity, scope, recurrence, control failure or risk. A missing signature and a concealed case of forced labour should not enter the same response pathway merely because both are technically non-conformities. Absence of evidence requires care.
If a requirement demands a record and the record is absent, the missing record can itself demonstrate non-conformity. If no record is required, the absence of documentation may not prove that an activity did not occur. Auditors should distinguish no evidence was available from evidence showed the requirement was not fulfilled. A finding also needs appropriate scale.
One incomplete record may indicate an isolated error. Similar errors across farms, teams or months may reveal a system failure. Conversely, auditors should not infer a systemic cause from one incident without examining the control. The statement records what is supported; root-cause analysis follows. Non-conformity is sometimes treated as failure in a moral sense. That can encourage concealment.
Mature systems expect findings because requirements, operations and contexts are imperfect. The relevant test is whether findings are detected, reported honestly, corrected, analysed and prevented from recurring. A scheme with no findings may have exceptional performance, weak criteria or an assurance process unwilling to see.
The discipline is to make findings reproducible. A knowledgeable person who was not present should be able to read the evidence, requirement and statement and understand why the conclusion follows. Clear findings reduce argument about wording and focus attention on the response that matters.
Practical application
Require every non-conformity record to identify evidence, source and clause of the requirement, affected scope, date and a concise statement of the gap. Define classification rules and escalation thresholds before audits begin. Separate formal findings from observations and improvement opportunities. Review finding quality as part of auditor calibration.
Analyse recurrence, distribution and severity across the system. Allow factual challenge and appeal without pressuring auditors to dilute supported findings.
Why it matters
Non-conformities turn assurance from opinion into an accountable comparison between evidence and obligation. Their quality determines whether organisations can understand the problem, analyse its cause and demonstrate an effective response.
Common misconception
A non-conformity is often treated as any undesirable condition or risk. Risk may justify investigation, but a formal non-conformity requires a specified requirement that has not been fulfilled. The finding should not claim more than the evidence demonstrates.
Connections
Audit produces findings from evidence and criteria. Corrective Action addresses causes after a non-conformity is established. Complaints and Appeals provide routes to challenge conduct or decisions, while Due Diligence may require action on serious harm even where no certification requirement has been breached.
A question worth asking
Could an independent reader reconstruct every non-conformity in your system from the requirement, evidence and statement alone - or does the finding depend on the auditor's unrecorded judgement?
Selected references
ISO 9000:2026. Quality Management - Fundamentals and Vocabulary. ISO and IAF. 2016. ISO 9001 Auditing Practices Group Guidance on Documenting a Nonconformity. ISO and IAF. 2016. ISO 9001 Auditing Practices Group Guidance on Review and Closing of Nonconformities. ISO 19011:2026. Guidelines for Auditing Management Systems. ISEAL Alliance. 2018. Assuring Compliance with Social and Environmental Standards, Version 2. 0.
Review
Public comments appear only after editor acceptance. Draft comments stay in the review queue.
Reviewers choose the definition or an overview paragraph, leave a comment or replacement, and attach evidence or a source link.
Editors compare reviewer cards side by side. AI may help find agreement, conflicts, unsupported claims and possible source issues.
Only an editor-accepted synthesis changes the public page. Reviewer identities are shown only with consent and verification.
Submitted reviews stay private until accepted.
Loading verified endorsements… Endorsements are not votes and never determine publication.
Endorse this definition
Endorse the exact version shown here. This is not a vote, and publication remains an editorial decision.
Review board
Comment on a specific line. Each reviewer stays separate until an editor accepts a merged draft.
Each person comments on the definition or overview in their own draft card, with role, evidence and suggested wording kept together.
AI can compare comments against the current text, flag conflicting claims, surface missing evidence and identify where reviewers agree.
An editor merges compatible suggestions into a draft change, checks sources, records disagreements and decides what can be published.