ConfirmedISO 9001:2026 publishes 16 September 2026. FDIS approved 7 August 2026.What it means →
← All insights

Internal Auditing

How to write an ISO 9001 audit nonconformity that won't get thrown out

16 August 2026

A closing meeting is a bad place to discover your finding is opinion. The process owner asks "where does it say that?", the quality manager asks "is this really a nonconformity?", and ten minutes later a real gap has been bargained down to an observation. The standard did not fail you. The write-up did.

This is a working method for writing an internal-audit nonconformity that survives that room: lock it to a requirement, pin it to evidence, then state the gap in one clean sentence. The same three parts are what a certification-body auditor uses, they are what the free Internal Auditor course teaches in its findings module, and they are what Qlause Audit Manager is built to capture.

A nonconformity is not a vibe, a lecture, or a to-do list. It is a requirement that was not fulfilled, shown with evidence a second person can check.

What a nonconformity actually is

ISO 9000 defines a nonconformity as the non-fulfilment of a requirement. That is the whole definition. A requirement can come from the standard (ISO 9001, IATF 16949 and the rest), from your own documented information, from a customer, or from law. If you cannot point to one of those, you do not have a nonconformity. You have a comment.

The distinction matters because the job of the finding is not to sound sharp. It is to drive corrective action — finding and removing the cause — rather than a one-off correction that only patches the example you happened to see. Write the finding around the specific micrometer on the bench and someone will label it and stop. Write it around the requirement that measuring equipment must be identified and calibrated, and the organisation has to look at the process that let an unidentified gauge onto the line. Clause 10.2 — and IATF 16949's 10.2.3 on problem solving — want the cause, not the sticker.

The ISO 9001 Auditing Practices Group's paper Documenting a Nonconformity makes the same point from the auditor's side: the record has to be clear enough that someone who was not in the room can understand what failed, against what, and why it matters. If they cannot, the finding will be argued, diluted, or quietly closed against the symptom.

The three parts that make a finding hold

Trainers teach this under a few labels. Some split it into four fields — process, requirement, statement, evidence — and if that is how you were trained, keep it: the process simply moves into the evidence line, which should say where you were standing anyway. The version that travels best, and maps straight onto a clause-locked finding, is three fields:

  1. Requirement — the exact "shall", quoted from your licensed copy, with the clause number.
  2. Evidence — what you saw: numbered, dated, named, and checkable.
  3. Statement — one negative sentence that restates the requirement as not fulfilled. No "shall". No evidence stuffed into it.

Write them in that order even if your form prints them differently. Requirement first stops you inventing a gap. Evidence second stops you writing an essay. Statement last is the sentence corrective action has to answer.

1. Requirement — quote it, don't paraphrase it

Open the standard or the procedure and copy the words into your finding. Put the clause number and title on the line above. If the paragraph is long, keep the sentence that was actually broken and mark the cuts with an ellipsis. (Quoting the standard inside your own audit record is what a licensed copy is for; reproducing it in public is not, which is why this article describes clauses in its own words.)

A requirement you cannot quote is not a requirement you can raise. "The spirit of the clause" and "good practice" are not audit criteria. Neither is "I would have done it differently."

Where the gap is against your own procedure, quote that paragraph — and still tie the finding back to a clause in the standard. That is how you trend findings later, and it is how you stop a clever process owner arguing that "our procedure isn't the standard." The common trap: ISO 9001 never says, in so many words, "follow your procedures." When people are not following a published procedure, the cleanest hook is usually clause 8.1 — sub-point (d) if the process was not run to its own criteria, sub-point (e) if the records cannot show it was carried out as planned. You can still note the process clause (8.4 for purchasing, 7.5 for documents, 9.2 for internal audit) as a secondary reference for trending.

Work from the evidence backwards, and the clause almost picks itself:

  1. What requirement was in play when you saw the gap — a shall in the standard, a shall in your procedure, a customer requirement, a legal one?
  2. Quote that requirement. If it is your procedure, also pick the ISO or IATF clause the procedure exists to satisfy.
  3. If two clauses both fit, lock the finding to the one the evidence actually breaks and mention the other as related. Do not write one finding against both as if they were the same requirement.
  4. If you cannot find a clause, you do not have a nonconformity. Write an observation, or keep looking.

If you are not sure which clause the evidence breaks, search it in the Clause Explorer before you write the statement — plain-language intent, what auditors look for, evidence examples and the common NCs for 213 clauses across ISO 9001, ISO 14001, ISO 45001, ISO 22000 and IATF 16949. Locking the wrong clause is how findings get thrown out: not because the gap was imaginary, but because you cited a requirement the evidence does not touch.

2. Evidence — something a second auditor could find again

Evidence is not "operators seemed unsure" or "the area was messy." It is a fact with enough handles that someone else can walk back to it:

  • document number, revision and date
  • gauge or asset number
  • part number, operation, line, shift
  • what you asked, and what was answered
  • what was not there when it should have been (and where you looked)

One strong piece of evidence can support a finding. Two or three from the same process, same shift, same control turn a lucky sample into a pattern. Do not pad: a shopping list of unrelated misses is not thoroughness, it is several findings glued together, and the owner will pick the easiest one to close.

Names are fine when they identify a role or a record ("the operator at OP20", "training file for employee 4412"). The finding is never about the person. If your evidence only works as blame, you are not finished looking.

3. Statement — the requirement, said in the negative

The statement is one complete sentence. It contains no "shall", and it contains none of the evidence.

Weak: "A 0–25 mm micrometer on line A had no calibration label." That sentence will get the label printed. It will not get the calibration process fixed.

Strong: "Measuring equipment in use was not identified so that its calibration status could be determined." Now the question for 5-Why is the right one: why is the identification process not working? Labelling that one micrometer is correction. The statement is what corrective action has to close.

A useful test: if you deleted the evidence block, would the statement still name a broken requirement? If not, you wrote a diary entry.

A finding that would get thrown out — and the same one written properly

The scene. Internal audit of production, day shift, line A. The operator at OP20 is checking special characteristic A on part 12345 with a 0–25 mm micrometer. No identification, no calibration label. The operator says the gauge was on the bench at the start of the shift and they assumed it was good to use. The calibration register has no entry for it.

Thrown out

Calibration is a problem in production. Operators should take more care with gauges. Improve awareness of the calibration procedure.

Why it dies in the closing meeting:

  • no clause, so anyone can say "where does it say that?"
  • "should" and "improve" are advice, not a finding
  • it blames the operator
  • there is nothing specific enough to contain, and nothing systemic enough to correct

The same evidence, written so it holds

Requirement. ISO 9001:2015, 7.1.5.2 Measurement traceability — unchanged in substance in the 2026 edition (see 7.1.5). In plain terms: where traceability is required, or is needed for confidence in the results, measuring equipment has to be calibrated or verified against traceable standards at set intervals or before use, and identified so that its calibration status can be determined. In your NCR, paste the actual sentence from your licensed copy. IATF shops: add 7.1.5.2.1 for the missing calibration record.

Evidence. At 09:40 on 12 August 2026, the operator at OP20 on line A was using a 0–25 mm Acme micrometer (no asset number visible) to check special characteristic A on part 12345. The instrument carried no identification or calibration label. The operator stated the micrometer was on the bench at the start of the shift and they assumed it was fit for use. The Calibration & Equipment Register (FM-019, Rev 6) has no record of this instrument.

Statement. Measuring equipment used to verify a special characteristic was not under calibration control: it was not identified so that its status could be determined, and there was no evidence it had been calibrated or verified.

The statement covers both halves of what the evidence shows. A statement about identification alone could be closed with a "status: uncalibrated" sticker on the gauge — exactly the loophole you are trying to shut. It is still one finding: one control (calibration control of measuring equipment) with two symptoms, not two unrelated problems. And the operator is in the evidence because that is where you found it; they are not in the statement, because they are not the requirement that failed.

Major or minor — grade the system, not the story

Once the three parts are solid, decide severity. Major and minor are about the system, not your mood.

  • Minor: a requirement was not fulfilled, but the process around it still works. Isolated, contained, no evidence the system is blind. A single unlabelled gauge inside a calibration process that otherwise knows every instrument is usually here.
  • Major: the process itself cannot meet the requirement — a total breakdown, or a pattern that means you cannot trust the output. Customer risk, legal risk, or a failure of a core QMS process (internal audit, management review, control of nonconforming output) usually belongs here. A calibration process that cannot tell current from overdue across the shop is major.
  • Observation / OFI: no broken shall. Useful, optional, and the first thing a process owner will try to bargain a weak NC down to. Do not let them if a requirement was actually missed.

IATF shops should grade internal findings to the discipline they will meet from a certification body. Under the IATF Rules (6th Edition), a noncompliance that would probably result in the shipment of nonconforming product is a major on its own — so the gauge above, checking a special characteristic with unknown status, is a different conversation from the same gauge on a non-critical dimension. Grade after the statement is clean, not before, and if you cannot explain the grade in one sentence that refers to the system, you are not ready to issue it.

Six ways good evidence still becomes a bad finding

1. You cited a vibe. "Communication needs to improve" and "quality culture is weak" are not nonconformities until you can quote a requirement and show evidence. Culture and ethics will be auditable under ISO 9001:2026 clauses 5.1.1 and 7.3 — that is a different article, and it still needs the same three parts.

2. You stacked three problems in one box. An unidentified gauge, a missing competence record and an out-of-date work instruction are three findings. Combined, the owner will close the easiest and call it done. Split them. Each statement gets its own clause and its own cause.

3. You wrote the evidence into the statement. Then corrective action aims at the example. Keep the micrometer in the evidence block. Keep the broken rule in the statement.

4. You picked the wrong clause. A procedure that is not followed is not automatically a 7.5 finding, and it is almost never a 4.1 finding. Quote the procedure paragraph, then hang the standard reference on 8.1 or the process clause the procedure serves. If a CB auditor invents a "shall" that is not in the text, the finding deserves to be thrown out — do not copy that habit internally.

5. You graded by how annoyed you were. Severity is a statement about the system. Write the statement first, then ask what the system can and cannot do.

6. You closed the door on correction. The statement should be wide enough that the owner has to look for other instances. The evidence should be tight enough that they can find this instance this afternoon. You need both. Evidence without a systemic statement produces a sticker. A systemic statement without evidence produces an argument.

Four checks before you issue it

Your statement is the problem statement for whatever method they use next — 5-Why, fishbone, or a full 8D. "Why was measuring equipment in use not identified?" is a question the system can answer. "Why was the operator careless?" is not. So, before you issue the finding:

  1. Can I point to the quoted shall?
  2. Can a second person find the evidence without me?
  3. Does the statement name the broken requirement, not the example?
  4. If they only fix the example, will I reject the closure?

If the answer to 4 is no, rewrite the statement. The free NC Writing Checklist below is these checks as a one-page form, with a blank requirement / evidence / statement block to write the finding in and the worked example filled in alongside.

Lock it before the argument starts

Findings get weaker in the hours after the audit: wording softens, the clause gets "simplified", someone edits the evidence so it sounds fairer. That is how a holdable NC becomes an observation before the report is issued. The practical habit is to write the three parts while you are still on the process, then freeze them. In Qlause Audit Manager that is the product: capture the finding against the exact clause, grade it, attach the evidence, and lock it. Locked findings are read-only, timestamped and tamper-evident. The closing meeting can still discuss containment and cause. It cannot quietly rewrite what was found. If you need the paper forms — NCR, corrective action request, audit report — they are in the ISO 9001 Documentation Toolkit.

Frequently asked questions

Can I raise a nonconformity against our own procedure only? Yes. Quote the procedure. Best practice is still to hang it on a standard clause as well — usually 8.1, plus the process clause for trending. A finding with no standard hook is harder to defend and harder to trend.

What is the difference between correction and corrective action? Correction fixes the instance — label the gauge, reprint the form. Corrective action removes the cause so it does not recur — fix the process that let an unidentified gauge reach the line. A well-written statement demands the second; a badly-written one is satisfied by the first.

How much evidence is enough? Enough that a sceptic can verify it, and enough that the owner can find the instance today. One clear miss can be a finding. A pattern is stronger. Unrelated misses are other findings.

Should the finding name the person? Name the role or the record, not the individual, and never in the statement. The evidence says where you found the gap; the statement says which requirement failed. If the finding only works as blame, you have not found the cause yet.

What if the process owner disagrees in the closing meeting? Walk the three parts. If they can show the requirement does not apply, or the evidence is wrong, withdraw or recast it. If they only dislike the conclusion, the finding stands. Disagreement is not a source of audit criteria.

Should I write opportunities for improvement in the same format? No. An OFI has no broken shall. Putting OFIs in the NC template trains people to treat real nonconformities as suggestions.

Does ISO 9001:2026 change how I write NCs? No. The method is the same. A few more shalls appear (culture and ethics, a sharper 6.1 and 6.3), so you will have new requirements to quote. You still need evidence, and you still need a statement that does not smuggle the example into the problem.

Interpretive guidance only — not a substitute for ISO 9001, IATF 16949, ISO 19011 or your licensed copy of the standard. Clause numbering follows ISO 9001:2015; the requirement discussed here is unchanged in substance in the 2026 edition, and we re-verify against the published text on 16 September 2026.

Get the free NC Writing Checklist (a one-page pre-issue check plus a blank requirement / evidence / statement form)

Free, instant download. We'll only email you the occasional practical quality update — no spam, unsubscribe anytime.

Put this into practice

The free Internal Auditor course (ISO 19011:2026) walks the whole audit — planning, interviewing, findings and grading, the closing meeting, follow-up — in eight video modules with quizzes and a certificate. Audit Manager is where the findings then live: captured against the clause, evidence attached, locked before the closing meeting, with automatic NC follow-up to closure.

Want to put this to work in your own system? The templates, toolkits and free masterclasses are built on the same guidance.

Browse templates