Nonconformity
Definition
The ISO 27001 term for a finding that represents a failure to meet a requirement of the standard or the organisation's own ISMS. A major nonconformity indicates a systemic or severe control failure; a minor nonconformity indicates an isolated or less critical gap.
- Standard
- ISO/IEC 27001 (ISMS)
- Categories
- Major and minor
- Major nonconformity
- Systemic or severe control failure
- Minor nonconformity
- Isolated or less critical gap
Common questions
Who decides whether a finding is major or minor?+
The certification auditor makes that call during the audit, based on criteria such as whether the failure affects the whole ISMS or a single control, whether it is repeated, and whether it creates a real risk of a security incident.
What happens after a major nonconformity is raised?+
Certification is typically withheld or suspended until the organisation submits and the auditor verifies a corrective action addressing the root cause, whereas minor nonconformities are usually tracked for correction at the next surveillance audit.
Related terms
- Executive Summary
- The opening section of an audit report written for non-technical leadership. It states the audit scope, overall posture, the most material findings...
- Finding
- A discrete, evidence-backed statement that a specific control is absent, misconfigured, or insufficient. Each finding contains an issue statement, evidence, risk rating,...
- Management Response
- The audited organisation's formal reply to each finding, included in the report. It states whether the recommendation is accepted, rejected, or accepted...
- Observation
- A noted issue or improvement opportunity that does not constitute a formal finding because it lacks sufficient evidence or does not violate...
- Risk Rating
- A classification of a finding's severity, typically Critical, High, Medium, Low, or Informational, derived from a likelihood-by-impact matrix. The rating determines remediation...