Procedure for the Management of Nonconformity¶
Purpose. Defines how Soon identifies, records, corrects and prevents recurrence of nonconformities, and drives continual improvement (ISO/IEC 27001:2022 clauses 10.1 and 10.2). Mandatory.
1. What is a nonconformity¶
A failure to meet a requirement — of ISO 27001, of Soon's own ISMS policies/procedures, or of legal/contractual obligations. Sources include: internal and external audits, incidents, monitoring results, supplier issues, staff reports, and management review.
- Major — a significant failure (e.g. a required control absent, or systemically not working).
- Minor — an isolated lapse that doesn't undermine the ISMS overall.
2. Procedure (10.2)¶
- Record the nonconformity in the Nonconformity & Corrective Action Log (ISMS-FORM-10-1): what, where, when, source, severity.
- Correct / contain — take immediate action to deal with the consequences.
- Analyse the cause — determine the root cause (not just the symptom); check whether similar nonconformities exist or could recur elsewhere.
- Decide corrective action — define action(s) to eliminate the root cause, with an owner and due date.
- Implement the corrective action.
- Verify effectiveness — confirm the action worked and the nonconformity has not recurred (typically reviewed at the next audit / management review).
- Update the ISMS — if needed, change risks, controls, the SoA, or documents.
- Close the entry in the log.
3. The log (record)¶
The CAPA log (ISMS-FORM-10-1) tracks every nonconformity through to closure: ID, date, source, description, severity, immediate correction, root cause, corrective action, owner, due date, verification, status. It is reviewed at management review and is key evidence of continual improvement for the auditor.
4. Roles¶
- ISM (Olaf) — maintains the log; ensures actions are assigned, tracked and verified.
- Action owners — implement corrective actions by the due date.
- Management review — oversees trends and the effectiveness of corrective action.
Related documents¶
- Procedure for Internal Audits (ISMS-DOC-09-2)
- Procedure for Management Reviews (ISMS-DOC-09-4)
- Incident Response Procedure
Change log¶
| Version | Date | Author | Comments |
|---|---|---|---|
| 0.1 | 2026-06-25 | Andrea Cardinali / ISMS | First draft — nonconformity sources, severity, root-cause corrective-action flow, CAPA log. |