Skip to content

Insights

The 10 most common ISO audit nonconformities — and how to prevent every one

Quality Gurus

  • Auditing
  • Certification
  • ISO 9001

Before founding QG, our lead consultant audited on behalf of accredited certification bodies across Egyptian, Argentine and Chinese supply chains. A pattern becomes obvious after enough audits: the same ten findings account for the overwhelming majority of nonconformities, across every standard — ISO 9001, 14001, 45001, 22000 alike. None of them is exotic. All of them are preventable.

Here they are, with the root cause and the fix for each.

1. Internal audits that don't cover the whole system

The finding: the audit programme skipped processes, clauses or sites, or the same checklist was reused unchanged for years. The root cause is treating internal audit as a compliance chore rather than a control. The fix: plan the audit programme against the full scope over the certification cycle, vary focus based on risk and previous results, and use auditors who are independent of the area they audit.

2. Corrective actions that fix the symptom, not the cause

Auditors read your corrective-action records closely, because they reveal whether the system actually learns. "Operator retrained" as the answer to every problem is the classic red flag — it means no root-cause analysis happened. The fix: use a genuine root-cause method for significant findings and record the analysis, not just the action.

3. Document control that lags reality

Obsolete forms still in use at workstations, two versions of a procedure in circulation, records signed against the wrong revision. This finding is almost universal in organisations that manage documents manually. The fix is less about software than discipline: one master list, one owner, and a rule that changes reach the point of use before they take effect.

4. Objectives without measurement

The standard requires measurable objectives and evidence of progress. What auditors frequently find is objectives written once, never measured, never reviewed. If your quality objectives haven't changed in three years and no data tracks them, expect a finding. The fix: fewer objectives, each with an owner, a number and a review rhythm.

5. Management review that is a formality

Ten-minute annual meetings producing identical minutes year after year. Management review is where the standard forces leadership engagement, and auditors treat weak reviews as a signal about the whole system. The fix: run it as a business review with the standard's required inputs on the agenda — audit results, performance data, resources, risks — and record real decisions.

6. Competence records that don't match assigned work

People doing work that affects quality (or safety, or food safety) without evidence of competence for that specific work. Training matrices help but are not the requirement — competence is. The fix: define competence per role, assess against it, and keep the evidence current as people move roles.

7. Supplier control on paper only

An approved supplier list exists, but suppliers were never evaluated, or performance is never reviewed, or purchases happen from suppliers not on the list. The fix: right-size the process — a small company needs a simple evaluation and an annual review, not a procurement bureaucracy — and then actually follow it.

8. Risk registers written once and abandoned

Since the 2015-generation standards, risk-based thinking is a core requirement. The common finding is a risk assessment produced during implementation and never revisited — even after incidents that plainly changed the risk picture. The fix: tie the risk review to management review and to change: new products, new sites, new equipment, new regulations.

9. Calibration and monitoring equipment gaps

Measuring equipment used for acceptance decisions with expired calibration, no calibration status, or no traceability. In food and manufacturing audits this is one of the fastest routes to a major nonconformity because it invalidates product-release decisions. The fix: a complete equipment register with status visible at the point of use.

10. Records that contradict the procedure

The deepest finding of all: the documented system describes one company, the records describe another. This is what happens when documentation is written to impress an auditor rather than to run the operation. It cannot be fixed the week before the audit. The fix is structural — build the system around how you actually work, then close the genuine gaps between current practice and the standard.

The finding nobody had two years ago

One addition since this list was first compiled, now appearing regularly across every standard. In February 2024 ISO issued Amendment 1:2024, adding climate-change wording to clauses 4.1 and 4.2 of more than thirty management system standards simultaneously — ISO 9001, 14001, 45001, 27001, 22000, 50001 and others. Clause 4.1 requires the organisation to determine whether climate change is a relevant issue; clause 4.2 notes that interested parties may have climate-related requirements.

It took effect immediately, with no transition period, and applies to certificates already held. The requirement is modest — consider the question, and be able to evidence that you did — but the finding is easy to attract, because most context analyses were written before 2024 and never revisited. If your context and interested-party analysis has no climate-change consideration recorded, that is a finding waiting to be written, and it takes an afternoon to close properly.

What majors and minors mean for your certificate

A minor nonconformity is an isolated lapse — you will be asked for a corrective-action plan, and the certificate proceeds. A major — a system element missing or systematically failing — blocks certification until it is closed and verified, which can mean a follow-up audit and months of delay. Most majors we see started life as minors that were closed cosmetically and recurred.

Practical steps

Audit your own system against this list before the certification body does. Read your last three internal audits and ask whether they would find any of the ten. Then read your corrective-action log and count how many actions are "retraining". If the honest answers are uncomfortable, a pre-external audit review — run by someone who has sat on the auditor's side of the table — costs a fraction of a failed certification audit.

Have a question we can answer?

Book a short discovery call to talk through your current systems, sector and target standards. We'll come back with clear, practical next steps.