20 before/after examples, by clause area
Each pair below shows a vague NC an auditor would likely reject or reopen, next to a version specific enough to close. The pattern to notice: the "after" version always names a document, a date, a quantity, or a measurable threshold — something a second person could go and check without asking the original auditor what they meant.
Document control
| # |
Vague (bounces back) |
Specific (closes) |
| 1 |
"Document control procedure not followed." |
"Work instruction WI-14 rev.2 (superseded 03/2026) was found active at Station 3 alongside rev.3; the obsolete copy was not stamped or withdrawn per DP-01 §6.2." |
| 2 |
"Some records were hard to find." |
"Retention records for incoming inspection (Jan-Mar 2026, 14 lots) could not be located within the shared drive folder specified in the document map; 3 of 14 were later found in an unlisted personal folder." |
| 3 |
"Version control needs improvement." |
"Drawing DWG-2201 exists in two active revisions (rev.4 in the ERP, rev.5 on the shop-floor printer share) with conflicting tolerance values on the same dimension." |
| 4 |
"External documents not controlled." |
"The supplier's material certificate template referenced in PQ-09 has not been reviewed since 2023; the register of external documents (ED-Reg) shows no review date field for this item." |
Calibration and measuring equipment
| # |
Vague (bounces back) |
Specific (closes) |
| 5 |
"Calibration overdue." |
"Micrometer MIC-018 (asset tag QM-118), due 04/02/2026, was found in use on 04/13/2026 with no calibration certificate for that interval; 6 production lots inspected with this gauge in the gap require impact assessment." |
| 6 |
"Gauges not labeled correctly." |
"4 of 22 torque wrenches sampled in the tool crib carry a calibration-due label but no corresponding entry in the calibration master list (Cal-List rev.9)." |
| 7 |
"Out-of-tolerance handling unclear." |
"Certificate CAL-2026-0341 for scale SC-04 shows an as-found reading 1.4% outside tolerance; there is no record of the impact assessment on product measured with SC-04 in the 60 days prior, as required by QP-11 §5.4." |
| 8 |
"New equipment not calibrated." |
"Digital caliper purchased 02/2026 (PO-3312) was placed into service on the incoming inspection bench without a baseline calibration certificate or register entry." |
Training and competence
| # |
Vague (bounces back) |
Specific (closes) |
| 9 |
"Training records incomplete." |
"2 of 5 operators performing final visual inspection (T. Rossi, hired 01/2026; M. Oduya, hired 02/2026) have no completed sign-off on WI-22, the visual acceptance criteria they are applying daily." |
| 10 |
"Competence not evaluated." |
"The competence matrix lists a 'welder — level 2' qualification requirement for Line C, but no evaluation method or passing criteria is defined for that level in TR-04." |
| 11 |
"Refresher training overdue." |
"Internal auditor competence refresher (required every 24 months per TR-11) is overdue by 5 months for 2 of 6 active internal auditors; both conducted audits during that window." |
| 12 |
"New hire training gap." |
"Employee onboarded 03/03/2026 was assigned solo forklift operation on 03/10/2026; the site's LOTO and forklift induction (HS-06) was not completed until 03/21/2026, 11 days after unsupervised operation began." |
Corrective action itself
| # |
Vague (bounces back) |
Specific (closes) |
| 13 |
"Corrective actions closed without checking they worked." |
"Of 9 corrective actions closed in Q1 2026, 6 show a completion date but no effectiveness-verification record, in breach of the two-step closure defined in QP-13 §4." |
| 14 |
"Root cause not investigated properly." |
"CA-2026-004 lists 'operator error' as root cause with no supporting analysis; the same failure mode (missing rivet) recurred twice in the following 6 weeks on the same line." |
| 15 |
"Recurring nonconformities not linked." |
"NC-2026-011 and NC-2026-029 both describe mislabeled finished-goods pallets from the same packing station, 7 weeks apart; the second NC does not reference or reassess the first corrective action." |
Environmental (EMS) and health & safety (OH&S)
| # |
Vague (bounces back) |
Specific (closes) |
| 16 |
"Waste segregation not managed well." |
"Solvent-contaminated rags (hazardous waste per the site's aspects register) were found in the general waste skip on the loading dock on 3 separate spot checks in March 2026." |
| 17 |
"Emergency procedure not tested." |
"The spill-response drill scheduled annually per EP-02 has no record for 2025; the last documented drill is dated 11/2023." |
| 18 |
"Near-misses under-reported." |
"Interviews with 4 warehouse staff surfaced 2 near-misses involving forklift-pedestrian interaction in the last 3 months, neither entered in the near-miss log (HS-Log), which shows zero entries for that period." |
| 19 |
"PPE compliance an issue." |
"On the floor walk-through, 3 of 12 employees in the cutting area were not wearing the cut-resistant gloves specified for that task in the risk assessment (RA-09, rev.3)." |
| 20 |
"Legal register not up to date." |
"The legal and other requirements register (LR-01) has no entry for a permit condition that changed in the site's water-discharge permit renewed 6 months ago; the associated monitoring frequency in the register still reflects the old condition." |
A recurring error in NC write-ups is treating the containment step as if it were the fix. Reworking the defective part, quarantining a batch, or sending someone home to get the right PPE are corrections — they deal with the specific instance in front of you. They don't touch the root cause, so they don't belong in the "corrective action" field on their own.
In summary:
- Correction: fixes this instance. Scrap the part, retrain this one operator, relabel this one pallet. Fast, necessary, but not sufficient on its own.
- Corrective action: removes the root cause so the failure mode can't recur — update the procedure, add a control step, change the register requirement.
A closable NC report keeps these in separate fields with separate evidence, and the effectiveness check is written against the corrective action, never against the correction.
Practical impact: what a weak NC actually costs
A reopened NC at surveillance rarely stays a minor finding. Auditors read a recurrence as evidence that the corrective action process itself isn't working, and a pattern of that across two audit cycles is a common route to escalation. Beyond the audit outcome, vague NCs quietly waste the time of whoever has to reconstruct, months later, what "training records incomplete" was actually supposed to mean — usually the same person who wrote it, now trying to remember which employee, which date, which document.
- Naming the fix before finding the cause. Jumping straight to "retrain the operator" skips the 5 Whys step that would show whether the real gap is a missing control, not a knowledge gap.
- Citing a general impression instead of evidence. "Calibration seems disorganized" isn't evidence; "6 of 22 gauges sampled had no register entry" is.
- Closing on completion, not on effectiveness. An action can be fully implemented and still not have solved the problem — the verification step exists precisely to catch that.
- Writing the root cause as a person's name. "Because J. Martín forgot" is not actionable; it also tends to make people defensive instead of forthcoming with information next time.
- Reusing last year's wording. Copy-pasted NC language is often the first thing an experienced auditor notices, and it's a fast way to lose credibility on an otherwise sound finding.
Where this fits in the audit cycle
Writing a closable NC is one piece of a bigger sequence: preparing for the audit, understanding what auditors actually check at Stage 1 versus Stage 2, building an internal audit checklist that catches these gaps before an external auditor does, and running the surveillance cycle without collecting a major finding. IgeraSolutions maintains a clause-by-clause breakdown for each of the major standards — ISO 9001, 14001, 45001, 50001 and 27001 — walking through what each clause requires in practical terms; this article assumes that baseline and focuses specifically on the writing itself.
// Igera demo — Finding objective evidence without a management system
Quality Manager: Which calibration certificates expired in the last 90 days, and what equipment do they cover?
Igera: 3 certificates expired in the last 90 days. CAL-2026-0198 (torque wrench TW-07, expired 02/14/2026, no renewal on file). CAL-2026-0204 (digital scale SC-11, expired 03/02/2026, renewal certificate CAL-2026-0231 issued 03/09/2026 — 7-day gap). CAL-2026-0210 (pressure gauge PG-03, expired 03/28/2026, no renewal on file). Source: calibration certificates folder, Q1 2026.
Quality Manager: Draft the objective evidence line for an NC covering the two gauges with no renewal.
Igera: Suggested wording: "Torque wrench TW-07 (cal. due 02/14/2026) and pressure gauge PG-03 (cal. due 03/28/2026) have no renewal certificate on file as of this review; both remain listed as active in the equipment register with no restricted-use flag." Source: certificates folder + equipment register, cross-checked today.
Long enough to be unambiguous, no longer. In practice this is usually 2-4 sentences for the finding itself: the requirement, the evidence, and the scope (how many units, records, or instances). Padding it with general commentary about the process doesn't make it stronger — specificity does. The root cause analysis and corrective action plan can run longer, since they need to show the reasoning, but the NC statement itself should stay tight.
The finding statement (what was observed, against which requirement) is the auditor's responsibility, internal or external. The root cause analysis, corrective action plan, and effectiveness verification are the auditee's — that's where the quality team's own investigation and 5 Whys or fishbone work happens. Auditors who write the root cause for the auditee are doing the auditee's job, and it tends to produce corrective actions the organization doesn't fully own.
What counts as objective evidence if the finding is about a behavior, not a document?
Direct observation counts, provided it's recorded precisely: date, time, location, who observed it, and exactly what was seen — "3 of 12 employees observed without required gloves during the 10:15am floor walk on 03/14/2026" rather than "PPE compliance issues noted." Interview statements also count as evidence when attributed and dated, though they typically carry less weight alone than a document or direct observation and are strongest when they corroborate a record-based finding.
Can a corrective action be "we'll be more careful" or "we reminded the team"?
Not as a stand-alone corrective action. A verbal reminder can be a valid immediate correction, but it rarely addresses a systemic root cause and almost never survives an effectiveness check, because there's no way to verify it actually changed behavior over time. A closable corrective action usually changes something structural: a procedure, a check, a form, a training requirement, an alert — something that exists independently of any one person remembering.
How does effectiveness verification differ from just closing the action on time?
Closing on time confirms the action was implemented — the procedure was updated, the training happened, the equipment was fixed. Effectiveness verification confirms the problem the NC described hasn't recurred, checked after enough time has passed for the fix to be tested under real conditions. A common approach is to define, at the time the corrective action is planned, both the verification method (a follow-up audit, a data review, a spot check) and a minimum observation window before that method is applied.
No — the depth of analysis should match the significance and impact of the finding. A one-off, low-impact nonconformity with an obvious, verifiable cause may only need a brief root cause statement. A recurring issue, a customer-facing failure, or anything with safety or regulatory implications warrants a structured method like 5 Whys or, for more complex cases, 8D with a cross-functional team. Applying full 8D rigor to every minor slip tends to slow the system down without adding real value.
No report guarantees anything on its own — the underlying corrective action still has to actually work. What a well-written NC does is give the auditor everything needed to make a fair judgment on the first pass, rather than forcing a follow-up request for missing information, which is itself often what pushes a finding into a second review cycle.
This article is informational and does not constitute legal, regulatory, or certification advice. Non-conformity handling requirements and acceptable evidence standards can vary by certification body and by the specific standard's current revision — confirm the specifics that apply to your certificate with your certification body or a qualified auditor before finalizing internal procedures.
Chasing down objective evidence across folders, emails and spreadsheets?
Igera's AI reads your company's own procedures, registers and records, and answers questions citing the exact document and clause behind each answer — evidence you can put straight into an NC report.
See how Igera helps with audits
IgeraSolutions Audit Team · Part of Program 1: Audits, tying together the clause-by-clause guides for ISO 9001, 14001, 45001, 50001 and 27001.