What to do when your internal audit reveals nonconformities — turning findings into genuine improvement.
Updated 6 Mar 2026
First: This Is Normal
Finding nonconformities in an internal audit is not failure — it's the system working. An internal audit that finds nothing is actually more suspicious to certification auditors.
Step-by-Step Response
1. Classify the Finding
•Major nonconformity A requirement is completely unmet or there's systematic failure
•Minor nonconformity Partial compliance or isolated gap
•Observation Not a nonconformity but an improvement opportunity
2. Document Clearly
For each finding, record:
•What was found (objective evidence)
•Which ISO 27001 clause or Annex A control is affected
•Classification (major/minor/observation)
•Date and auditor name
3. Root Cause Analysis
Don't just fix the symptom. Ask why the nonconformity occurred:
•Was the procedure unclear?
•Was training insufficient?
•Was the control poorly designed?
•Was there a resource constraint?
•Was there a process change that wasn't reflected in documentation?
Use simple techniques: 5 Whys, fishbone diagram, or just structured discussion.
4. Define Corrective Actions
For each root cause, define:
•What action will address it
•Who is responsible
•Target completion date
•How you'll verify effectiveness
5. Implement and Track
•Log corrective actions in your ISMS (not a separate spreadsheet)
•Monitor progress at regular intervals
•Don't let actions go stale
6. Verify Effectiveness
After implementation, check:
•Has the root cause been addressed?
•Is there evidence of improvement?
•Has the fix created any new issues?
•Can this finding recur?
What Auditors Want to See
•A track record of honest internal audit findings
•Root cause analysis (not just surface-level fixes)
•Corrective actions completed within reasonable timeframes
•Evidence of effectiveness verification
•Trends being analysed and systemic issues addressed
Pro Tip
Keep your corrective action register active and visible. It should be a living document reviewed in every management review — not a dusty spreadsheet pulled out before external audits.
Related Modules
Corrective Actions
Standard Controls
Calendar
Related Controls / Clauses
9.2
10.1
10.2
26 practitioner guides — included free with your workspace
27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.