Guide 13 min read

Handling Nonconformities Without Overcomplicating Your QMS

J

Jared Clark

August 12, 2026

Why Nonconformity Systems Get Heavy

Most quality systems don't start out overcomplicated. They get that way one audit finding at a time. An auditor flags a missed root cause analysis, so the next revision of the procedure adds a mandatory fishbone diagram for every nonconformity. A client complaint slips through, so someone adds a second approval signature. Three years later, a scratched label on a single carton triggers the same eight-step CAPA form as a failed sterility test, and the quality team spends more time filling out paperwork than fixing anything.

I've walked into that exact situation more times than I can count across food, cosmetics, dietary supplements, and medical device clients. The system isn't broken because people don't care. It's broken because nobody ever went back and asked whether the process still matched the risk. In my view, that's the whole game with nonconformities: matching the response to the actual stakes, not to the worst-case template someone built after one bad finding.

ISO 9000:2015 clause 3.6.9 defines a nonconformity plainly, as the non-fulfillment of a requirement. That's it. Nothing in that definition says every nonconformity deserves a root cause investigation, a cross-functional review board, and a 30-day closure deadline. Those are choices your system makes, and they're choices you can make proportionally instead of uniformly.

What a Nonconformity Actually Is — and Isn't

A nonconformity is a gap between what your documented requirement says and what actually happened. It can be:

  • A product or lot that fails a specification
  • A process step performed out of sequence or by an untrained operator
  • A missing record, an expired calibration, an unsigned batch record line
  • An audit finding against your own procedure or an external standard

It is not, by itself, a crisis. Severity and recurrence are separate questions from "did this happen." A single missed initial on a cleaning log is a nonconformity. So is a shipped lot that fails a critical safety test. Treating both the same way is where systems start to buckle under their own weight.

ISO 9001:2015 clause 10.2 lays out what's actually required when a nonconformity occurs, and it's shorter than most procedures make it look: react to the nonconformity (correct it, deal with the consequences), evaluate whether corrective action is needed to prevent recurrence, implement any action needed, and review whether that action worked. The standard also expects you to update risks and opportunities identified during planning and to make changes to the QMS itself if the situation calls for it. Four moves. Not four forms, four moves.

The Overcomplication Trap

The pattern I see most often has three ingredients, usually stacked on top of each other over successive audit cycles.

Every nonconformity gets the same weight. A minor labeling typo and a batch that failed release testing route through an identical workflow with identical fields, identical sign-offs, and identical documentation depth. When the form doesn't distinguish severity, people either skip fields to save time (creating a compliance gap) or fill them out mechanically without real analysis (creating a paper compliance gap, which is worse because it looks compliant).

Root cause analysis becomes a ritual instead of a tool. I've reviewed CAPA files where the "root cause" field reads "human error" for a dozen unrelated events across two years. Nobody believes that's the actual cause. It's there because the form requires an entry and nobody built in a way to say "this was isolated, low-risk, and corrected at the point of occurrence" without triggering a full investigation.

Closure requires more signatures than the decision warrants. I've seen quality systems where closing a CAPA for a training miss requires the same four-person sign-off chain as closing one for a recall-adjacent event. When the approval burden doesn't scale with risk, people either delay low-risk closures indefinitely or route everything through the fast lane, including things that shouldn't be fast.

None of this is caused by bad intentions. It's caused by a system built defensively, one finding at a time, without anyone stepping back to redesign the whole thing around risk. The fix isn't more rigor. It's rigor in the right place and less friction everywhere else.

Right-Size the Response with a Tiering Model

The most durable fix I've implemented across clients is a simple severity tier built directly into the nonconformity procedure, so the tier — not habit, not who happened to notice it — decides how much process the nonconformity gets.

A workable three-tier model looks like this:

Tier 1 — Correction only. Isolated, low-risk, no product or safety impact, obvious and immediate fix (re-training a single operator, correcting a data entry error, replacing a scratched label). Document what happened and what was done. No formal root cause investigation required. Closed at the point of occurrence, often same day.

Tier 2 — Correction plus root cause, no full CAPA. Recurring pattern within a defined window, or moderate impact that stopped short of the customer or the market. Requires an actual root cause method proportional to the complexity, not the maximum available. A simple "5 whys" is enough for most Tier 2 events. Document the fix and verify it worked at the next occurrence or the next scheduled check.

Tier 3 — Full CAPA. Regulatory impact, safety impact, customer complaint tied to a systemic issue, or repeat failure of a previously "corrected" Tier 2 item. This is where the full investigation, cross-functional review, effectiveness check with defined metrics, and extended monitoring period belong. This tier should be a minority of your total nonconformity volume — if it isn't, your tiering criteria are miscalibrated, not your process.

The tiering criteria themselves need to be written down and applied consistently, because an unwritten tiering system just relocates the inconsistency instead of removing it. Whoever logs the nonconformity should be able to apply the criteria in under a minute, without escalating the tiering decision itself into its own bottleneck.

What the Standards Actually Require

A lot of the bloat I see isn't required by any standard. It's inherited from a previous auditor's preference, a past corporate template, or plain caution that never got revisited. Here's what the major frameworks actually ask for, side by side.

Framework Nonconformity/CAPA Clause Separate Preventive Action Required? Effectiveness Check Required?
ISO 9001:2015 Clause 10.2 (Nonconformity and corrective action) No — folded into risk-based thinking (clause 6.1) Yes
ISO 13485:2016 Clause 8.5.2 (Corrective action) and 8.5.3 (Preventive action) Yes — kept as a distinct clause Yes
ISO 22000:2018 Clause 10.2 (Nonconformity and corrective action) No — aligned with the Annex SL structure used by ISO 9001 Yes
FDA 21 CFR 820.100 (current QSR) CAPA procedures, §820.100(a) Yes, listed as a distinct requirement Yes, §820.100(a)(4)
FDA QMSR (21 CFR Part 820, amended) Incorporates ISO 13485:2016 by reference Follows ISO 13485:2016 Follows ISO 13485:2016

That last row matters for any device manufacturer reading this. FDA published the Quality Management System Regulation final rule on January 31, 2024, replacing the current Part 820 requirements with an incorporation of ISO 13485:2016 by reference, with a compliance date of February 2, 2026. If your CAPA procedure is still written purely against the legacy QSR language, this is the year to reconcile it against ISO 13485:2016 clauses 8.5.2 and 8.5.3 directly, since that's the text your quality system will actually be measured against going forward.

For drug and dietary supplement manufacturers, the equivalent anchor isn't a CAPA clause at all — it's the deviation investigation requirement. 21 CFR 211.192 requires that any unexplained discrepancy or failure of a batch to meet its specifications be investigated, whether or not the batch has already been distributed. That single sentence is doing the same job as ISO 9001 clause 10.2, just written for a pharmaceutical GMP audience instead of a management-systems audience.

Building the Minimum Viable Workflow

Strip a nonconformity process down to what actually has to happen, and you get five steps. Everything else is optional scaffolding you add back only where risk justifies it.

  1. Identify and contain. Stop the immediate problem — quarantine the product, correct the record, pull the affected lot from the line. This happens regardless of tier.
  2. Tier it. Apply your written criteria. This should take a trained person under a minute.
  3. Correct. Fix the immediate instance. For Tier 1, this may be the entire process.
  4. Investigate proportionally, if the tier calls for it. Tier 2 gets a lightweight root cause tool. Tier 3 gets the full investigation.
  5. Verify and close. Confirm the fix actually worked, at a depth proportional to the tier, then close the record with a decision — not a checkbox — on whether the QMS itself needs to change.

If your current procedure has more mandatory steps than that for a Tier 1 event, you've built a system that treats every scratch like it might be a fracture. That's not thoroughness. It's an unexamined default that nobody has had the standing to question.

Root Cause Analysis Without the Theater

Root cause analysis is where I see the most wasted effort, because there's a widespread assumption that more formal equals more rigorous. A fishbone diagram, an Ishikawa exercise, and a formal five-why session all have their place, but their place is proportional to the complexity of the failure, not to how nervous the last audit made everyone.

A genuinely isolated, one-off event with an obvious proximate cause doesn't need a formal facilitated session. It needs someone to write down what actually happened and confirm there's no pattern behind it. A recurring failure with an unclear mechanism, on the other hand, deserves the real tool, done properly, with evidence attached rather than an assumption written down and called a conclusion.

The test I use with clients: if the "root cause" you wrote down wouldn't survive someone asking "how do you know that's actually why it happened," it's not a root cause. It's a guess with a form number attached. That's true whether the guess took five minutes or five hours to produce.

Common Mistakes That Add Weight Without Adding Value

  • Confusing documentation volume with investigation quality. A three-page CAPA with a copy-pasted root cause tells an auditor less than a half-page record with a specific, verifiable cause and a fix that was actually checked.
  • Skipping the effectiveness check. Corrective actions that are implemented but never verified to have worked are the single most common gap I find in mature systems. Clause 10.2 requires a review of the effectiveness of the action taken — not just its completion.
  • Letting closure metrics drive behavior. If your KPI is "CAPAs closed within 30 days," people will close CAPAs within 30 days, whether or not the underlying issue is actually resolved. Track effectiveness, not just cycle time.
  • Never trending Tier 1 events. Individually harmless corrections can reveal a systemic pattern in aggregate. A monthly or quarterly trend review of Tier 1 items is cheap insurance against missing the forest for the trees.
  • Treating the tiering criteria as permanent. Review them annually, or after any Tier 3 event that started life misclassified as Tier 1 or 2. That misclassification is itself useful data about where your thresholds are set wrong.

Where This Fits in Your Broader QMS

None of this works in isolation from the rest of your management system. Nonconformity handling is downstream of how you define requirements in the first place and how you assess risk during planning. If your risk assessment under clause 6.1 is thin, your nonconformity tiering will be thin too, because the two are supposed to talk to each other. I generally recommend clients revisit their nonconformity procedure at the same time they revisit their internal audit program, since a well-tiered CAPA process and a risk-based internal audit schedule tend to reinforce each other rather than compete for the same limited quality-team hours.

If you're rebuilding this alongside a broader ISO 9001 implementation or renewal, it's worth doing the tiering exercise as part of that larger effort rather than bolting it onto an existing procedure after the fact — our ISO 9001 consultant work usually starts exactly there. For device manufacturers working through the QMSR transition specifically, the CAPA rebuild against ISO 13485:2016 clauses 8.5.2 and 8.5.3 is one of the higher-leverage pieces of that project, and it's a topic our ISO 13485 consultant team handles regularly.

FAQ

Does every nonconformity require a formal root cause investigation? No. ISO 9001:2015 clause 10.2 requires you to evaluate the need for action to eliminate the cause, which means the standard itself contemplates that some nonconformities won't need one. A written tiering system that reserves formal root cause analysis for recurring or higher-impact events, while still documenting and correcting lower-tier events, satisfies the requirement without treating every event identically.

What's the difference between a correction and a corrective action? A correction fixes the immediate instance of the problem — the specific batch, the specific record, the specific error. A corrective action addresses the underlying cause so the problem doesn't happen again. ISO 9001:2015 clause 10.2 requires both when the situation calls for it: react (correction) and, where warranted, eliminate the cause (corrective action).

Is preventive action still a separate requirement? It depends on the standard. ISO 9001:2015 removed the standalone preventive action clause and folded that concept into risk-based thinking under clause 6.1. ISO 13485:2016 kept preventive action as its own clause, 8.5.3, distinct from corrective action in 8.5.2. Device manufacturers need both; most other ISO 9001-based systems only need the risk-based version.

How does the FDA's QMSR change affect existing CAPA procedures? The QMSR, finalized January 31, 2024 with a compliance date of February 2, 2026, replaces the current 21 CFR Part 820 quality system regulation text with an incorporation of ISO 13485:2016 by reference. CAPA procedures written purely against the legacy §820.100 language should be reconciled against ISO 13485:2016 clauses 8.5.2 and 8.5.3 before that compliance date.

How many nonconformities should end up as full CAPAs? There's no fixed percentage in any standard, but if a majority of your logged nonconformities are routing through a full CAPA process, that's usually a sign your tiering criteria are set too aggressively rather than a sign your operation has a genuine quality crisis. Full CAPA should be reserved for events with real regulatory, safety, or systemic significance.

Last updated: 2026-08-12

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.