Nonconformity and Corrective Action Management

The NCR Process as Quality Intelligence

Nonconformity data is the richest quality intelligence an organization produces. Every nonconformity — whether caught internally or reported by a customer — is a signal that a process did not work as intended. Organizations that capture and analyze all nonconformities systematically improve faster than those that treat failures as isolated incidents. The cultural prerequisite is: nonconformities are not evidence of blame; they are improvement opportunities. When staff fear punishment for reporting failures, they hide them, and the organization loses visibility into quality problems. An effective QMS creates a culture where reporting nonconformities is valued and safe.

 

Sources of Nonconformities

NC SourceDescriptionVolume ExpectationTypical Root Cause Category
Customer complaintsCustomer-reported failures in delivered products/servicesLow volume, high significanceProcess gaps, competence issues, requirements misunderstanding
Internal audit findingsNCs found during planned QMS auditsMedium volumeProcedure non-adherence, documentation gaps, awareness issues
Process monitoringNCs found through in-process inspection and monitoringVariable by sectorProcess variation, equipment, material quality
Management reviewSystemic underperformance identified at reviewLow volumeResource gaps, strategic misalignment
Supplier failuresNon-conforming goods or services from external providersVariableSupplier QMS gaps, specification clarity

 

The NCR Process Flow

StepRequired OutputTimeframeCommon Failure
ContainImmediate corrective action to fix the specific instanceSame daySkipped — CA started without containment
DocumentNCR record opened with description, scope, evidence24 hoursVerbal only, no record
Root causeWritten RCA using appropriate method5–10 business daysSuperficial RCA, symptom identified not cause
CA planSpecific actions, owners, dates5 business days from RCANo plan, or plan identical to correction
ImplementationActions completed as plannedPer CA planActions planned but not completed on time
EffectivenessMonitoring confirms NC has not recurred30–90 days post-implementationNever done

 

Root Cause Analysis Methods

Several RCA methods are available; choose the method proportionate to the nonconformity severity. Five Whys is simple and fast — asking "why?" repeatedly until you reach the root cause. It works well for straightforward NCs with one primary cause. Fishbone (Ishikawa) diagram is a structured visual method showing potential cause categories (People, Process, Equipment, Materials, Environment, Measurement) and how they might contribute to the effect. It is good for complex NCs with multiple contributing factors. The 8D method (Eight Disciplines of Problem Solving) is comprehensive and structured, with eight defined steps: define the problem, contain the issue, identify root cause, develop corrective actions, implement, verify effectiveness, prevent recurrence, and close. The 8D method is standard in automotive and aerospace industries and is proportionate to significant customer-facing failures. The critical principle: the RCA must be rigorous enough to identify the true root cause, not just the obvious symptom.

 

5 Whys Example

Example RCA for a delivery delay nonconformity: Why was the order shipped late? Because production was delayed. Why was production delayed? Because a critical component was received late from the supplier. Why was the component late? Because the supplier was not notified of the delivery date change when the customer moved up the delivery deadline. Why was the supplier not notified? Because there is no procedure for notifying suppliers when delivery dates change. Root cause: No change control procedure. Corrective action: Implement change control procedure with mandatory supplier notification requirement. This RCA identifies a system gap, not a person error, and the CA addresses the system gap.

 

Corrective Action Design

The corrective action must address the identified root cause, not the symptoms. The test: if the root cause is as identified, will this CA prevent recurrence? If your RCA identifies that "the operator made an error," the CA of "retrain the operator" may fix that one person's error but does not prevent the next operator from making the same error. Better: "The process requires precision but has no control to catch errors — implement a verification step and train all operators." CAs often contain multiple sub-actions: address the immediate problem, add process controls, improve training, update documentation, communicate the change. Each sub-action must have an owner, a due date, and success criteria. The CA plan is documented in the NCR record.

 

Effectiveness Verification

Effectiveness verification is mandatory, not optional. ISO 9001 explicitly requires organizations to review the effectiveness of corrective actions taken. This means going back after the CA is implemented and checking whether the nonconformity has ceased to recur. For a delivery delay, you would monitor actual delivery performance for the next 5–10 deliveries under the new process, confirm that delays have ceased, and document the verification. The timeframe for effectiveness verification depends on the frequency of the relevant activity: monthly for processes that occur daily; quarterly for processes that occur weekly; once per year for processes that occur infrequently. Without effectiveness verification records, your CA process is incomplete regardless of how good your RCA and CA planning are.

KEY IDEAThe corrective action must address the identified root cause, not the specific instance of nonconformance. If the root cause is "no procedure exists for this activity," the corrective action is "develop and implement a procedure" — not "retrain the operator who made the error." Address the system, not the person, and you prevent recurrence system-wide.
IMPORTANTEffectiveness verification is mandatory, not optional. ISO 9001 explicitly requires organizations to review the effectiveness of corrective actions taken. This means going back after the CA is implemented and checking whether the nonconformity has ceased to recur. Without effectiveness verification records, your CA process is incomplete regardless of how good your RCA and CA planning are.
BITLION INSIGHTThe corrective action register is one of the most powerful continuous improvement tools available to a QMS. Organizations that analyze their CA register monthly — looking for patterns in root causes, processes with disproportionate NC rates, and CAs that are not being closed — generate improvement insights that no other management tool produces. Build CA register analysis into the monthly quality reporting cycle.