What is an ISO 27001 Nonconformity?
An ISO 27001 nonconformity is any instance where your organization fails to meet a requirement of the ISO/IEC 27001 standard. Nonconformities can include gaps in controls, missing documentation, unaddressed risks, or failure to follow your own Information Security Management System (ISMS) procedures.
Nonconformities are typically uncovered during internal or external audits. Depending on severity, they are classified as major or minor. Addressing them through corrective action is essential to achieving certification.

ISO 27001 Nonconformity: Related Terms Explained
Major Nonconformity
A serious issue that compromises the effectiveness of the ISMS. Examples include missing an entire clause of the standard or failing to perform regular risk assessments. Major nonconformities can delay or revoke certification.
ISO 27001 Minor Nonconformity
This ia a smaller issue that still represents a deviation from ISO 27001 requirements. For instance, not updating a risk register on schedule or inconsistently following a documented procedure. These typically require correction but don’t halt certification on their own.
Corrective Action
A documented step taken to fix the root cause of a nonconformity and ensure it won’t recur. ISO 27001:2022 requires organizations to investigate, resolve, and verify the effectiveness of corrective actions.
Audit Finding
Any observation made during an ISO audit. Findings can include nonconformities, observations (potential risks or weak areas), or opportunities for improvement (OFIs).
Opportunity for Improvement (OFI)
Not a nonconformity, but a note from the auditor about something that could become a problem or that could be enhanced. Smart organizations act on OFIs to stay ahead.
Why Some Areas Get More Auditor Attention Than Others
Not all nonconformities are created equal, and not all controls get equal scrutiny.
Auditors don’t move line by line through ISO 27001 Annex A. They follow a risk-based approach, which means they prioritize areas based on:
- High-risk data or operations
- Recent system, personnel, or vendor changes
- Core controls like risk assessments, incident response, or access control
This approach means two things:
- You can’t hide behind surface-level compliance. Auditors will sense where risks live.
- You should be doing this same triage internally, before they get there.
If you’ve onboarded a third-party processor, migrated cloud environments, or changed leadership in the past 6 months, expect questions. And if your SoA or documentation isn’t up-to-date, that’s where ISO 27001 nonconformity identification often begins.
Common ISO 27001 Nonconformities

1. Missing or Weak Risk Assessments
Organizations are expected to identify, assess, and regularly update risks. Many are caught using one-off or outdated assessments with no clear tie to controls.
2. Poorly Maintained SoA (Statement of Applicability)
Excluding a control without justification? Leaving it marked “Not Applicable” with no explanation? Auditors flag this often, especially post-revision.
3. Shadow Vendors
Vendor risk is hot. If you’re using third-party processors without assessing their security posture or including them in risk treatment plans, it’s a major red flag.
4. Lack of Evidence for Internal Audits
Having an internal audit plan isn’t enough. You need to show records, follow-up actions, and who participated. No evidence = nonconformity.
5. Controls Without Proof of Implementation
Stating a control is “implemented” doesn’t fly. You need logs, policies, meeting notes, screenshots, or system reports to prove it.
Start Getting Value With
Centraleyes for Free
See for yourself how the Centraleyes platform exceeds anything an old GRC
system does and eliminates the need for manual processes and spreadsheets
to give you immediate value and run a full risk assessment in less than 30 days
What To Do in the Case of an ISO 27001 Nonconformity
ISO 27001 Clause 10.2 requires a structured approach to ISO 27001 nonconformity management:
- Log the Nonconformity. Record the issue clearly. What requirement was missed? Where? When?
- Investigate the Root Cause. Don’t just fix the symptom. Analyze why it happened, whether due to process gaps, unclear responsibilities, or system limitations.
- Plan Corrective Actions. Outline what steps you’ll take to address the ISO nonconformity and corrective action. Make sure to decide who will be responsible and when it will be resolved.
- Implement and Document: Take the actions, verify they worked, and log everything. This becomes part of your continual improvement evidence.
- Review During Management Review. Bring nonconformities and corrective actions to your next ISO 27001 management review meeting. Show leadership accountability.

Turn Nonconformities Into a Strength
Auditors don’t expect perfection. But they expect ownership. Organizations that:
- Show their ISMS evolves
- Treat findings as lessons
- Document progress transparently
…are more likely to pass, build trust, and strengthen their programs over time.
FAQ: ISO 27001 Nonconformities
Q: Can I still get certified with a nonconformity?
A: Yes, if it’s minor and corrected quickly. Major nonconformities may delay or prevent certification.
Q: Do I have to fix every OFI?
A: Not required, but strongly recommended. They help reduce risk and show you take audits seriously.
Q: What’s the timeline to fix an ISO 27001 nonconformity?
A: Typically 30–60 days, depending on your auditor. They’ll expect a documented corrective action plan.
Q: How many nonconformities are too many?
A: It depends on severity. A few ISO 27001 minor nonconformities with solid corrective actions? Usually fine. A major or pattern of neglect? That’s a problem.
Q: Can I argue with the auditor’s finding?
A: You can ask for clarification, but findings are generally final. Better to clarify the scope and intent during the audit itself.
Start Getting Value With
Centraleyes for Free
See for yourself how the Centraleyes platform exceeds anything an old GRC
system does and eliminates the need for manual processes and spreadsheets
to give you immediate value and run a full risk assessment in less than 30 days