Industry

Writing a Non-Conformity That Closes the First Time: 20 Real Examples

Igera Solutions Team
September 18, 2026
8 min read
Writing a Non-Conformity That Closes the First Time: 20 Real Examples
🎧 Listen with AI Voice

2-minute executive summary

⚡ Quick Answer in 30s

Write non-conformity reports and corrective actions that pass first re-verification: root-cause methods, objective evidence, and 20 before/after examples.

✓ Citing current regulationsSee detailed guide below ↓

Audit series · Non-conformity writing

Writing a Non-Conformity That Closes the First Time: 20 Real Examples

A non-conformity closes on the first re-verification when the report ties a specific piece of objective evidence to a verified root cause and to a corrective action that measurably removes it. Vague wording — "training records incomplete," "improve calibration control" — is the single biggest reason NCs bounce back at surveillance. This guide shows the difference in practice, with 20 illustrative before/after pairs across the clauses auditors flag most often: document control, calibration, training, corrective action itself, and more.

A closed NC and a re-opened NC often describe the exact same problem

What separates them is rarely the corrective action itself — it's whether the original report named the requirement, the objective evidence, and a root cause specific enough that someone else could verify it was actually removed. Everything below is illustrative, built from common patterns seen across QMS, EMS and OH&S audits — not real client records.

Why NCs bounce back: the anatomy of a weak report

A non-conformity report exists to do three things: state what requirement wasn't met, point to the objective evidence that proves it, and give whoever verifies the corrective action enough to check that the root cause is actually gone. When any one of those three is missing, the auditor — or the internal quality manager doing the follow-up — has nothing solid to re-verify against, and a weak closure gets reopened.

The pattern repeats across standards. In a 9001 audit it's a calibration record; in 14001 it's a discharge threshold; in 45001 it's a near-miss that never got a root cause. The structure of a good NC is identical regardless of which clause it sits under:

The five elements a closable NC always has

  1. The requirement: the exact clause, procedure, or specification not met — quoted or referenced precisely, not paraphrased.
  2. The objective evidence: the record, observation, or data point that demonstrates the gap (document ID, date, sample size, measurement).
  3. The immediate correction: what was done right away to contain the problem, separate from the root cause fix.
  4. The root cause: reached through a structured method (5 Whys, fishbone), not the first plausible explanation.
  5. The effectiveness check: a defined, dated method for proving the root cause is gone — not just that the action was carried out.

Root cause analysis: 5 Whys and fishbone, used correctly

5 Whys: stop at a cause you can act on, not the first excuse

The most common failure in 5 Whys isn't asking too few questions — it's stopping at an answer that blames a person rather than a system. "The operator forgot" is not a root cause; it's a symptom of a missing control. A usable root cause always points to something the organization can fix: a procedure gap, a missing check, an unclear responsibility.

Illustrative example — 5 Whys done right

Problem: A pressure gauge used for a safety-critical check was found 11 days past its calibration due date.

Why 1? The calibration reminder wasn't triggered before the due date.

Why 2? The gauge wasn't listed in the calibration master register.

Why 3? It was purchased as a spare eight months ago and put into service without being added to the register.

Why 4? The procedure for bringing spare equipment into service has no step requiring register entry before first use.

Root cause: The equipment commissioning procedure (QP-07) does not require register entry as a precondition for putting measuring equipment into service.

Fishbone (Ishikawa): use it before 5 Whys, not instead of it

A fishbone diagram sorts candidate causes into categories — commonly people, machine, method, material, environment, measurement — so the team doesn't fixate on the first explanation someone offers. It's a brainstorming structure, not a root-cause method on its own: once the categories surface two or three plausible branches, run 5 Whys on each branch to confirm which one is actually driving the failure, rather than assuming the most visible cause is the real one.

20 before/after examples, by clause area

Each pair below shows a vague NC an auditor would likely reject or reopen, next to a version specific enough to close. The pattern to notice: the "after" version always names a document, a date, a quantity, or a measurable threshold — something a second person could go and check without asking the original auditor what they meant.

Document control

# Vague (bounces back) Specific (closes)
1 "Document control procedure not followed." "Work instruction WI-14 rev.2 (superseded 03/2026) was found active at Station 3 alongside rev.3; the obsolete copy was not stamped or withdrawn per DP-01 §6.2."
2 "Some records were hard to find." "Retention records for incoming inspection (Jan-Mar 2026, 14 lots) could not be located within the shared drive folder specified in the document map; 3 of 14 were later found in an unlisted personal folder."
3 "Version control needs improvement." "Drawing DWG-2201 exists in two active revisions (rev.4 in the ERP, rev.5 on the shop-floor printer share) with conflicting tolerance values on the same dimension."
4 "External documents not controlled." "The supplier's material certificate template referenced in PQ-09 has not been reviewed since 2023; the register of external documents (ED-Reg) shows no review date field for this item."

Calibration and measuring equipment

# Vague (bounces back) Specific (closes)
5 "Calibration overdue." "Micrometer MIC-018 (asset tag QM-118), due 04/02/2026, was found in use on 04/13/2026 with no calibration certificate for that interval; 6 production lots inspected with this gauge in the gap require impact assessment."
6 "Gauges not labeled correctly." "4 of 22 torque wrenches sampled in the tool crib carry a calibration-due label but no corresponding entry in the calibration master list (Cal-List rev.9)."
7 "Out-of-tolerance handling unclear." "Certificate CAL-2026-0341 for scale SC-04 shows an as-found reading 1.4% outside tolerance; there is no record of the impact assessment on product measured with SC-04 in the 60 days prior, as required by QP-11 §5.4."
8 "New equipment not calibrated." "Digital caliper purchased 02/2026 (PO-3312) was placed into service on the incoming inspection bench without a baseline calibration certificate or register entry."

Training and competence

# Vague (bounces back) Specific (closes)
9 "Training records incomplete." "2 of 5 operators performing final visual inspection (T. Rossi, hired 01/2026; M. Oduya, hired 02/2026) have no completed sign-off on WI-22, the visual acceptance criteria they are applying daily."
10 "Competence not evaluated." "The competence matrix lists a 'welder — level 2' qualification requirement for Line C, but no evaluation method or passing criteria is defined for that level in TR-04."
11 "Refresher training overdue." "Internal auditor competence refresher (required every 24 months per TR-11) is overdue by 5 months for 2 of 6 active internal auditors; both conducted audits during that window."
12 "New hire training gap." "Employee onboarded 03/03/2026 was assigned solo forklift operation on 03/10/2026; the site's LOTO and forklift induction (HS-06) was not completed until 03/21/2026, 11 days after unsupervised operation began."

Corrective action itself

# Vague (bounces back) Specific (closes)
13 "Corrective actions closed without checking they worked." "Of 9 corrective actions closed in Q1 2026, 6 show a completion date but no effectiveness-verification record, in breach of the two-step closure defined in QP-13 §4."
14 "Root cause not investigated properly." "CA-2026-004 lists 'operator error' as root cause with no supporting analysis; the same failure mode (missing rivet) recurred twice in the following 6 weeks on the same line."
15 "Recurring nonconformities not linked." "NC-2026-011 and NC-2026-029 both describe mislabeled finished-goods pallets from the same packing station, 7 weeks apart; the second NC does not reference or reassess the first corrective action."

Environmental (EMS) and health & safety (OH&S)

# Vague (bounces back) Specific (closes)
16 "Waste segregation not managed well." "Solvent-contaminated rags (hazardous waste per the site's aspects register) were found in the general waste skip on the loading dock on 3 separate spot checks in March 2026."
17 "Emergency procedure not tested." "The spill-response drill scheduled annually per EP-02 has no record for 2025; the last documented drill is dated 11/2023."
18 "Near-misses under-reported." "Interviews with 4 warehouse staff surfaced 2 near-misses involving forklift-pedestrian interaction in the last 3 months, neither entered in the near-miss log (HS-Log), which shows zero entries for that period."
19 "PPE compliance an issue." "On the floor walk-through, 3 of 12 employees in the cutting area were not wearing the cut-resistant gloves specified for that task in the risk assessment (RA-09, rev.3)."
20 "Legal register not up to date." "The legal and other requirements register (LR-01) has no entry for a permit condition that changed in the site's water-discharge permit renewed 6 months ago; the associated monitoring frequency in the register still reflects the old condition."

Immediate correction vs. corrective action: don't confuse the two

A recurring error in NC write-ups is treating the containment step as if it were the fix. Reworking the defective part, quarantining a batch, or sending someone home to get the right PPE are corrections — they deal with the specific instance in front of you. They don't touch the root cause, so they don't belong in the "corrective action" field on their own.

In summary:

  • Correction: fixes this instance. Scrap the part, retrain this one operator, relabel this one pallet. Fast, necessary, but not sufficient on its own.
  • Corrective action: removes the root cause so the failure mode can't recur — update the procedure, add a control step, change the register requirement.

A closable NC report keeps these in separate fields with separate evidence, and the effectiveness check is written against the corrective action, never against the correction.

Practical impact: what a weak NC actually costs

A reopened NC at surveillance rarely stays a minor finding. Auditors read a recurrence as evidence that the corrective action process itself isn't working, and a pattern of that across two audit cycles is a common route to escalation. Beyond the audit outcome, vague NCs quietly waste the time of whoever has to reconstruct, months later, what "training records incomplete" was actually supposed to mean — usually the same person who wrote it, now trying to remember which employee, which date, which document.

Common mistakes when writing non-conformities

  • Naming the fix before finding the cause. Jumping straight to "retrain the operator" skips the 5 Whys step that would show whether the real gap is a missing control, not a knowledge gap.
  • Citing a general impression instead of evidence. "Calibration seems disorganized" isn't evidence; "6 of 22 gauges sampled had no register entry" is.
  • Closing on completion, not on effectiveness. An action can be fully implemented and still not have solved the problem — the verification step exists precisely to catch that.
  • Writing the root cause as a person's name. "Because J. Martín forgot" is not actionable; it also tends to make people defensive instead of forthcoming with information next time.
  • Reusing last year's wording. Copy-pasted NC language is often the first thing an experienced auditor notices, and it's a fast way to lose credibility on an otherwise sound finding.

Where this fits in the audit cycle

Writing a closable NC is one piece of a bigger sequence: preparing for the audit, understanding what auditors actually check at Stage 1 versus Stage 2, building an internal audit checklist that catches these gaps before an external auditor does, and running the surveillance cycle without collecting a major finding. IgeraSolutions maintains a clause-by-clause breakdown for each of the major standards — ISO 9001, 14001, 45001, 50001 and 27001 — walking through what each clause requires in practical terms; this article assumes that baseline and focuses specifically on the writing itself.

// Igera demo — Finding objective evidence without a management system

Quality Manager: Which calibration certificates expired in the last 90 days, and what equipment do they cover?

Igera: 3 certificates expired in the last 90 days. CAL-2026-0198 (torque wrench TW-07, expired 02/14/2026, no renewal on file). CAL-2026-0204 (digital scale SC-11, expired 03/02/2026, renewal certificate CAL-2026-0231 issued 03/09/2026 — 7-day gap). CAL-2026-0210 (pressure gauge PG-03, expired 03/28/2026, no renewal on file). Source: calibration certificates folder, Q1 2026.

Quality Manager: Draft the objective evidence line for an NC covering the two gauges with no renewal.

Igera: Suggested wording: "Torque wrench TW-07 (cal. due 02/14/2026) and pressure gauge PG-03 (cal. due 03/28/2026) have no renewal certificate on file as of this review; both remain listed as active in the equipment register with no restricted-use flag." Source: certificates folder + equipment register, cross-checked today.

Frequently asked questions about writing non-conformities

How long should a non-conformity write-up be?

Long enough to be unambiguous, no longer. In practice this is usually 2-4 sentences for the finding itself: the requirement, the evidence, and the scope (how many units, records, or instances). Padding it with general commentary about the process doesn't make it stronger — specificity does. The root cause analysis and corrective action plan can run longer, since they need to show the reasoning, but the NC statement itself should stay tight.

Who should write the non-conformity — the auditor or the auditee?

The finding statement (what was observed, against which requirement) is the auditor's responsibility, internal or external. The root cause analysis, corrective action plan, and effectiveness verification are the auditee's — that's where the quality team's own investigation and 5 Whys or fishbone work happens. Auditors who write the root cause for the auditee are doing the auditee's job, and it tends to produce corrective actions the organization doesn't fully own.

What counts as objective evidence if the finding is about a behavior, not a document?

Direct observation counts, provided it's recorded precisely: date, time, location, who observed it, and exactly what was seen — "3 of 12 employees observed without required gloves during the 10:15am floor walk on 03/14/2026" rather than "PPE compliance issues noted." Interview statements also count as evidence when attributed and dated, though they typically carry less weight alone than a document or direct observation and are strongest when they corroborate a record-based finding.

Can a corrective action be "we'll be more careful" or "we reminded the team"?

Not as a stand-alone corrective action. A verbal reminder can be a valid immediate correction, but it rarely addresses a systemic root cause and almost never survives an effectiveness check, because there's no way to verify it actually changed behavior over time. A closable corrective action usually changes something structural: a procedure, a check, a form, a training requirement, an alert — something that exists independently of any one person remembering.

How does effectiveness verification differ from just closing the action on time?

Closing on time confirms the action was implemented — the procedure was updated, the training happened, the equipment was fixed. Effectiveness verification confirms the problem the NC described hasn't recurred, checked after enough time has passed for the fix to be tested under real conditions. A common approach is to define, at the time the corrective action is planned, both the verification method (a follow-up audit, a data review, a spot check) and a minimum observation window before that method is applied.

Should a non-conformity always trigger a formal 5 Whys or 8D?

No — the depth of analysis should match the significance and impact of the finding. A one-off, low-impact nonconformity with an obvious, verifiable cause may only need a brief root cause statement. A recurring issue, a customer-facing failure, or anything with safety or regulatory implications warrants a structured method like 5 Whys or, for more complex cases, 8D with a cross-functional team. Applying full 8D rigor to every minor slip tends to slow the system down without adding real value.

Does a good non-conformity report guarantee the auditor won't reopen it?

No report guarantees anything on its own — the underlying corrective action still has to actually work. What a well-written NC does is give the auditor everything needed to make a fair judgment on the first pass, rather than forcing a follow-up request for missing information, which is itself often what pushes a finding into a second review cycle.

This article is informational and does not constitute legal, regulatory, or certification advice. Non-conformity handling requirements and acceptable evidence standards can vary by certification body and by the specific standard's current revision — confirm the specifics that apply to your certificate with your certification body or a qualified auditor before finalizing internal procedures.

Chasing down objective evidence across folders, emails and spreadsheets?

Igera's AI reads your company's own procedures, registers and records, and answers questions citing the exact document and clause behind each answer — evidence you can put straight into an NC report.

See how Igera helps with audits

IgeraSolutions Audit Team · Part of Program 1: Audits, tying together the clause-by-clause guides for ISO 9001, 14001, 45001, 50001 and 27001.

#how to write a non-conformity report#corrective action root cause analysis#5 whys non-conformity example#ISO audit non-conformity examples#closing corrective action effectiveness verification#nonconformity vs corrective action#internal audit finding wording#ISO 9001 non-conformity report#Abweichung ISO Audit#Non-Conformity Bericht schreiben#Korrekturmaßnahme Grundursache#5-Why-Methode Qualitätsmanagement#Ishikawa-Diagramm Ursachenanalyse#Kalibrierung Abweichung Beispiel#ISO 9001 Audit Checkliste#Wirksamkeitsprüfung Korrekturmaßnahme

Ask this article

IA 2026

Igera's AI answers questions citing the facts and regulations in this article

2 of 2 free queries

Suggested questions (click to test):

Diagnóstico Interactivo 60s

Technical Compliance & Industrial Operations Diagnostic

Analyze speed of access to regulations (CTE, OSH, CE) in your plant or jobsite

Pregunta 1 de 3

How do technicians and operators access safety protocols and manuals?

Was this article helpful?

⚙️IgeraIndustriaOperations Template
GUÍA DESCARGABLE (TXT)

Preventive Maintenance & ISO 9001/45001 Industrial Checklist

Floor inspection template for machine operations, failure tracking and unplanned downtime reduction.

  • Shift inspection standardization for plant operators
  • Up to 40% faster anomaly response times
  • Full traceability for ISO audits and HSE compliance

Instant download · No card · 100% spam-free

Share this article

Help spread knowledge by sharing this content with your network