ISO 27001 Clause 10.2: Nonconformity and Corrective Action
Identify and address Nonconformities in your ISMS to improve information security, according to ISO 27001 clause 10.2.

Identify and address Nonconformities in your ISMS to improve information security, according to ISO 27001 clause 10.2.

ISO 27001 is an international standard that outlines the requirements for an information security management system (ISMS). An ISMS is a framework for managing information security risks and protecting information assets.
Clause 10.2 of ISO 27001 requires organisations to identify, investigate, and resolve nonconformities. A nonconformity is a departure from the requirements of the ISMS.
This article will discuss the requirements of ISO 27001 clause 10.2 and provide guidance on how to implement a nonconformity and corrective action process in order to achieve or maintain an ISO 27001 certification.
Nonconformities can be identified through a variety of means, such as internal audits, management reviews, and external audits. Once a nonconformity has been identified, the organisation should investigate it to determine the root cause and any potential impact on information security.
The difference between minor nonconformities and major nonconformities is the severity of the impact on the organisation's information security management system.
Minor nonconformities are those that do not have a significant impact on the effectiveness of the ISMS. They may be isolated incidents or one-off occurrences. Minor nonconformities can be dealt with relatively quickly and easily, and they do not necessarily require immediate corrective action.
Major nonconformities, on the other hand, are those that have a significant impact on the effectiveness of the ISMS. They may be systemic problems that could lead to serious information security risks. Major nonconformities require immediate corrective action to mitigate the risk and prevent further problems.
It is important to note that the severity of a nonconformity can vary depending on the specific circumstances of the organisation.
Organisations should have a process in place for identifying, reporting, and resolving both minor and major nonconformities. This process should be documented and communicated to all employees.
By promptly addressing nonconformities, organisations can help to improve the overall effectiveness of their ISMS and protect their information assets.
Here is a table that summarizes the key differences between minor and major nonconformities:
|
Characteristic |
Minor nonconformity |
Major nonconformity |
|
Severity of impact |
Does not have a significant impact on the effectiveness of the ISMS. |
Has a significant impact on the effectiveness of the ISMS. |
|
Likelihood of occurrence |
Isolated incident or one-off occurrence. |
Systemic problem that could lead to serious information security risks. |
|
Time to resolution |
Relatively quick and easy. |
Immediate corrective action required. |
|
Impact on certification |
May not affect certification. |
May affect certification. |
It is important to note that the severity of a nonconformity can vary depending on the specific circumstances of the organisation. For example, a minor nonconformity for one organisation could be a major nonconformity for another organisation.
Here are some examples of minor and major nonconformities:
Organisations should have a process in place for identifying, reporting, and resolving both minor and major nonconformities. This process should be documented and communicated to all employees.
By promptly addressing nonconformities, organisations can help to improve the overall effectiveness of their ISMS and protect their information assets.
Once the root cause of a nonconformity has been determined, the organisation should take corrective action to eliminate the cause and prevent it from happening again. Corrective action may involve changing policies and procedures, training employees, or implementing new security controls.
The following is a general overview of the nonconformity and corrective action process:

To prepare for the external audit, it is helpful to understand common areas, topics, and questions an auditor may ask or check. The following list gives an overview of potential areas auditors may check while validating clause 10.2 of ISO 27001:
Specifically, the auditor will check the following:
The auditor will also review the organisation's records of nonconformities and corrective actions.
Here are some additional questions that the auditor may ask:
By asking these questions and reviewing the organisation's records, the auditor can assess the effectiveness of the organisation's nonconformity and corrective action process. Therefore, preparing for these questions will facilitate the audit process and increases the chances of successfully passing the external ISO 27001 audit.
The nonconformity and corrective action process is an essential part of an ISMS. By identifying and resolving nonconformities, organisations can improve the effectiveness of their ISMS and reduce the risk of information security incidents.
Make sure that the process is well-defined and documented. This will help to ensure that all nonconformities are handled in a consistent manner.
Assign responsibility for each step of the process. This will help to ensure that nonconformities are resolved promptly and effectively.
Communicate the process to all employees. This will help to ensure that everyone is aware of their role in the process.
Monitor the effectiveness of the process. This will help to identify any areas for improvement.
By following these tips, organisations can implement a nonconformity and corrective action process that will help them to improve the security of their information assets.
A nonconformity happens when your ISMS doesn’t meet ISO 27001 requirements or your own defined processes.
This could include missing documentation, controls that aren’t implemented as described, incomplete risk assessments, or employees not following established procedures. Nonconformities may be identified during internal audits, external audits, or day-to-day operations.
The key factor is deviation from what the standard or your ISMS requires.
An incident is a security event, such as unauthorized access or data loss. A nonconformity relates to a failure in your management system.
For example, a phishing attack is an incident. If your organization failed to follow its incident response procedure, that becomes a nonconformity. Clause 10.2 focuses on fixing the management system gap, not just handling the event itself.
Both require action, but they address different layers of your security framework.
ISO 27001 doesn’t define a strict deadline. Instead, you must respond in a timely and proportionate way based on risk and impact.
High-risk issues typically require immediate containment and swift corrective action. Lower-risk gaps may follow a structured remediation plan with defined timelines. What matters most is that you document the issue, define root cause, implement action, and verify effectiveness.
Auditors look for accountability and follow-through.
Yes. Every identified nonconformity requires evaluation and appropriate action.
The scale of response may differ depending on severity. A minor documentation error won’t require the same level of remediation as a systemic control failure. However, ignoring smaller gaps can lead to recurring problems over time.
Clause 10.2 ensures that you address weaknesses early before they escalate.
After implementing corrective action, you must review whether it resolved the root cause.
This may involve follow-up audits, updated risk assessments, revised procedures, or performance monitoring. Simply closing a task isn’t enough. You need evidence that the issue won’t recur under normal operating conditions.
Effective corrective action strengthens your ISMS and supports continual improvement.
TISAX® is a registered trademark of the ENX Association. DataGuard is not affiliated with the ENX Association. We provide Software-as-a-Service and support for the assessment on TISAX® only. The ENX Association does not take any responsibility for any content shown on DataGuard's website.
All data provided is for information only, based on internal estimates. This information is not indicative of KPIs, and is not given with any warranties or guarantees, expressly stated or implied in relation to accuracy and reliability.
{
"@context": "https://schema.org",
"@graph": [
{
"@type": "Organization",
"@id": "www.dataguard.com#organization",
"name": "DataGuard",
"legalName": "DataCo GmbH",
"description": "DataGuard, the European leader in security and compliance software, is trusted by more than 4,000 organizations across 50+ countries. We help you identify and manage your security and compliance risks and fast-track your certifications and compliance by combining expert consultancy with AI-powered automation. Our purpose-built, all-in-one platform is developed with the experience of over 1.5 million total hours by a team of certified security and compliance experts.",
"foundingDate": "2018",
"taxID": "DE315880213",
"logo": "https://7759810.fs1.hubspotusercontent-na1.net/hubfs/7759810/DataGuardLogo.svg",
"url": "www.dataguard.com",
"email": "info@dataguard.de",
"telephone": "+49 89 452459 900",
"address": {
"@type": "PostalAddress",
"streetAddress": "Sandstrasse 33",
"addressLocality": "Munich",
"addressRegion": "Bavaria",
"postalCode": "80335",
"addressCountry": "Germany"
},
"sameAs": [
"https://www.linkedin.com/company/dataguard1/",
"https://www.youtube.com/channel/UCEQzPZ6sCBCj9cAoBvaLL6w",
"https://x.com/i/flow/login?redirect_after_login=%2FDataGuard_dg"
]
}
]
}✅ Organization schema markup for "DataGuard" has been injected into the document head.