No certification audit ends with a perfect score. Auditors expect to raise ISO 27001 nonconformities, and organizations that understand this prepare differently: they focus less on appearing flawless and more on avoiding the findings that delay certification, consume remediation budgets, and signal deeper problems in the management system.

ISO 27001 nonconformities are those findings. A nonconformity is issued when the auditor finds evidence that a requirement is not being met, whether that requirement comes from the standard itself, from the organization's own documented policies, or from contractual commitments. Some are isolated lapses corrected in days. Others block certification entirely until resolved and verified.

This guide explains what nonconformities are, the difference between major and minor findings, the most common ISO 27001 nonconformities auditors raise, the root causes behind them, and the practices that keep them out of your audit report.

Schedule a Meeting with CertPro
TL;DR

Concern

ISO 27001 nonconformities are the single largest cause of delayed certifications and extended audit cycles. A major finding blocks certification until it is resolved and verified, often requiring a follow-up audit weeks or months later. Minor findings left uncorrected escalate: an unresolved minor from a previous audit is typically upgraded to a major at the next one, and repeated minors against the same requirement signal systemic failure.

Overview

Nonconformities in ISO 27001 fall into two types. A major nonconformity is a systemic failure or complete absence of a required element, such as no internal audit or a risk assessment process that exists only on paper. A minor nonconformity is an isolated lapse in an otherwise functioning process. The most common findings cluster around risk assessment, access control, internal audits, management review, documentation currency, and corrective action follow-through.

Solution

Most ISO 27001 nonconformities are preventable. Organizations that run a gap assessment before certification, complete a full internal audit and management review cycle, keep documentation aligned with real operations, apply genuine root cause analysis to every finding, and track corrective actions to verified closure consistently enter audits with few findings and close them quickly.

What Is a Nonconformity in ISO 27001?

What is a nonconformity? A nonconformity is the failure to fulfill a requirement. In an ISO 27001 audit, that means the auditor has found objective evidence that the organization is not meeting a clause of the standard, is not following its own documented policies and procedures, or is not honoring security commitments made to customers or regulators.

Nonconformities in ISO 27001 are always tied to a specific requirement. When one is raised, the auditor documents four things: a description of the issue, the objective evidence supporting it, a reference to the exact requirement not met, such as one of the ISO 27001 clauses or an Annex A control; and a summary of what fulfillment would require. This structure matters because it makes every finding traceable and actionable rather than a matter of auditor opinion.

It is also worth distinguishing ISO 27001 nonconformities from opportunities for improvement. An OFI is an auditor's suggestion: a process that works but could work better. Corrective action on an OFI is recommended, not required. A nonconformity, by contrast, obligates a response. Ignoring one puts certification at risk.

Types of Nonconformities in ISO 27001: Major and Minor

There are two types of non-conformities in ISO 27001: major and minor. All ISO 27001 nonconformities carry an obligation to respond, but the distinction rests on severity and system impact, and it determines what happens next in the certification process.

Major Nonconformities

A major nonconformity is a systemic failure or the complete absence of a required element of the management system. Examples drawn from real audits include an internal audit that was never performed, a risk assessment process that is documented but not followed, disaster recovery tests claimed but never conducted, and policies that exist but that no one follows. Major ISO 27001 nonconformities block certification: the certificate cannot be issued, or an existing certificate can be suspended, until the finding is resolved and the resolution is verified by the auditor, often through a follow-up assessment.

Minor Nonconformities

Minor ISO 27001 nonconformities are isolated lapses in otherwise functioning processes: a single terminated employee whose account was not disabled on time, one overdue security training session, and a policy document past its review date. Certification can proceed with minor findings, provided the organization submits an acceptable corrective action plan. Certification bodies typically require the nonconformity report within around 14 days of the audit closing and evidence of correction within around 30 days.

How Minor Findings Escalate

The escalation rules are where many organizations get caught. A minor finding that is not corrected within the agreed timeline is normally upgraded to a major at the next audit. Multiple minor findings against the same requirement are treated as evidence of systemic failure and can be consolidated into a major. This is why experienced practitioners treat every finding, whatever its classification, as a commitment with a deadline. ISO 27001 nonconformities do not age well.

ISO 27001 Noncompliance: The Cost of Ignoring Findings

Sustained ISO 27001 noncompliance carries consequences beyond a difficult audit. Unresolved findings at a surveillance audit can lead to certificate suspension or withdrawal, which many customer contracts treat as a breach event. Enterprise buyers increasingly ask for audit findings and their closure status during due diligence, and a pattern of repeat findings tells them the management system is not genuinely operating. The commercial cost of losing a certificate almost always exceeds the cost of fixing the findings that threatened it.

The Most Common ISO 27001 Nonconformities

The Most Common ISO 27001 Nonconformities
The Most Common ISO 27001 Nonconformities

Certification bodies and lead auditors report a remarkably consistent pattern in the ISO 27001 non conformities they raise. The following eight ISO 27001 non conformities account for the majority of audit reports.

  • Incomplete or Outdated Risk Assessment

    The methodology is unclear, criteria for likelihood and impact are inconsistent, or the assessment has not been reviewed after significant business or technology changes. Weak risk assessment often cascades into major findings because every control decision depends on it.

  • Access Control Lapses

    Accounts of departed employees left active, access not adjusted when staff change roles, third-party and temporary access unmanaged, and privileged access unmonitored. Auditors sample leavers and movers specifically because this is where failures concentrate.

  • Internal Audit Gaps

    No internal audit performed before Stage 2, audit programs that do not cover all processes and controls in scope, or auditors who lack independence from the areas they audit.

  • Management Review Deficiencies

    Reviews that skip required inputs, produce no decisions, or generate identical minutes every cycle. Auditors read these records as a direct measure of leadership commitment.

  • Documentation Gaps

    Copy-paste template policies describing processes the organization does not run. Auditors verify documents against practice, and mismatches generate findings on both sides.

  • Statement of Applicability Inconsistencies

    Controls marked implemented that are not, exclusions without credible justification, or an SoA version that contradicts the scope document.

  • Untested Mitigation Plans

    Business continuity and disaster recovery documentation that has never been exercised. A plan without a test record is treated as an unverified claim.

Most of these findings map to a small set of clauses and controls: Clause 6 planning, Clause 9 performance evaluation, Clause 10 improvement, and the access, asset, and supplier controls within the 93 Annex A controls of ISO 27001:2022. Organizations that concentrate readiness effort on these areas eliminate the majority of their exposure to ISO 27001 non conformities before the auditor arrives.

What Are the Common Causes of ISO 27001 Nonconformity in Audits

The common causes of ISO 27001 non conformity in audits are organizational rather than technical, which is why ISO 27001 non conformities recur when only the technical symptom is fixed: treating certification as a one-time project, documentation written for the auditor instead of the business, unclear control ownership, audit-month scrambles replacing continuous operation, and root cause analysis that stops at the first convenient answer.

The project mindset. Teams build the management system for the certification date, then disband. Controls decay, reviews lapse, and by the first surveillance audit the system reflects last year's organization. ISO 27001 assumes continual operation, and auditors test for it.

Borrowed documentation. Template policies save time but describe someone else's company. When the access policy names a review process that does not exist, the auditor raises two findings at once: the process gap and the unreliable documentation.

Unowned controls. When no named individual is accountable for a control, evidence stops accumulating and nobody notices until the audit. Ownership gaps are invisible in a policy review and obvious in operational sampling.

Shallow root cause analysis. Fixing the broken backup without asking why monitoring never flagged it guarantees the finding returns. Auditors reviewing Clause 10.2 evidence look specifically for whether corrective actions address causes or symptoms, and repeat ISO 27001 non conformities are the strongest signal they read.

How to Avoid ISO 27001 Nonconformities

Avoiding ISO 27001 non conformities comes down to five practices, each of which addresses a cause identified above and produces evidence the auditor can verify.

Run a gap assessment before the certification body does. A structured ISO 27001 gap assessment conducted months before Stage 1 surfaces the same issues an auditor would find, while there is still time to fix them quietly. Treat its output as a corrective action register with owners and deadlines, not a report to file.

Complete a genuine internal audit and management review cycle. Certification bodies expect at least one full ISO 27001 internal audit and management review before Stage 2. Cover every process and control in scope, document findings honestly, and close them with evidence. An internal audit that found nothing convinces no one.

Keep documentation synchronized with operations. Review policies when the business changes, not just annually. Before any audit, walk each documented process with the team that runs it and fix mismatches in whichever direction is correct: update the document or restore the practice.

Apply structured root cause analysis to every finding. Use a defined method such as the five whys, push past human error to the process or resource gap beneath it, and record the analysis. The corrective action record should show correction, cause, action, and verification as separate steps.

Track every finding to verified closure. Maintain a single register for internal and external findings with owners, deadlines, and closure evidence. Nothing prevents repeat ISO 27001 non conformities more reliably than a closure process that verifies the fix actually worked before the item is marked complete.

Conclusion

ISO 27001 nonconformities are not a verdict on an organization's competence. They are the mechanism through which the standard enforces its requirements, and every certified organization encounters them over time. What distinguishes mature information security management systems is the response. Findings are corrected at the root, supported by objective evidence, and used to improve the effectiveness of the ISMS.

The pattern across common ISO 27001 nonconformities is consistent enough to act on. Keep the risk assessment current. Maintain disciplined access control. Perform internal audits objectively. Conduct meaningful management reviews. Address root causes rather than symptoms. Organizations that follow these practices typically enter certification audits with stronger evidence and a more effective management system.

At CertPro, we conduct independent ISO 27001 certification audits worldwide as a licensed CPA firm. Our auditors classify nonconformities based on objective evidence, document the applicable ISO/IEC 27001 requirements supporting each finding, and verify corrective actions before findings are closed. Whether your organization is undergoing an initial certification audit, surveillance audit, or recertification audit, our ISO 27001 audit engagements follow a structured, evidence-based methodology aligned with ISO/IEC 27001:2022 and ISO 19011.

Frequently Asked Questions
A non conformity in ISO 27001 is the failure to fulfil a requirement, evidenced during an audit. The requirement can come from the standard's clauses, from Annex A controls the organization declared applicable, from its own documented policies, or from contractual security commitments. Each finding is documented with evidence, the exact requirement reference, and what fulfilment requires.
A major non conformity is a systemic failure or complete absence of a required element, and it blocks certification until resolved and verified by the auditor. A minor non conformity is an isolated lapse in a functioning process; certification can proceed with an accepted corrective action plan. Unresolved minors are typically escalated to majors at the next audit.
Yes, with minor findings. Certification can be granted alongside minor ISO 27001 non conformities if the organization submits an acceptable corrective action plan within the certification body's timeline, typically around 14 days, with evidence of correction following within about 30 days. Major findings must be fully resolved and verified before the certificate is issued.
The common causes of ISO 27001 non conformity in audits are a project mindset that lets the management system decay after certification, template documentation that does not match real operations, controls without named owners, missing internal audit or management review cycles, and corrective actions that fix symptoms instead of root causes.
Timelines vary by certification body, but a common pattern is a completed non conformity report with root cause and corrective action plan within 14 days of the audit close, and evidence of correction within 30 days. Major findings additionally require auditor verification, sometimes through a follow-up visit, before certification proceeds or continues.
Continued ISO 27001 non compliance after findings are raised leads to escalation: minors become majors, and unresolved majors result in certificate suspension or withdrawal. Beyond certification, the commercial effects are often larger, since many enterprise contracts require a valid certificate and treat suspension as grounds for review or termination.