No certification audit ends with a perfect score. Auditors expect to raise ISO 27001 nonconformities, and organizations that understand this prepare differently: they focus less on appearing flawless and more on avoiding the findings that delay certification, consume remediation budgets, and signal deeper problems in the management system.
ISO 27001 nonconformities are those findings. A nonconformity is issued when the auditor finds evidence that a requirement is not being met, whether that requirement comes from the standard itself, from the organization's own documented policies, or from contractual commitments. Some are isolated lapses corrected in days. Others block certification entirely until resolved and verified.
This guide explains what nonconformities are, the difference between major and minor findings, the most common ISO 27001 nonconformities auditors raise, the root causes behind them, and the practices that keep them out of your audit report.
Concern
ISO 27001 nonconformities are the single largest cause of delayed certifications and extended audit cycles. A major finding blocks certification until it is resolved and verified, often requiring a follow-up audit weeks or months later. Minor findings left uncorrected escalate: an unresolved minor from a previous audit is typically upgraded to a major at the next one, and repeated minors against the same requirement signal systemic failure.
Overview
Nonconformities in ISO 27001 fall into two types. A major nonconformity is a systemic failure or complete absence of a required element, such as no internal audit or a risk assessment process that exists only on paper. A minor nonconformity is an isolated lapse in an otherwise functioning process. The most common findings cluster around risk assessment, access control, internal audits, management review, documentation currency, and corrective action follow-through.
Solution
Most ISO 27001 nonconformities are preventable. Organizations that run a gap assessment before certification, complete a full internal audit and management review cycle, keep documentation aligned with real operations, apply genuine root cause analysis to every finding, and track corrective actions to verified closure consistently enter audits with few findings and close them quickly.
What Is a Nonconformity in ISO 27001?
What is a nonconformity? A nonconformity is the failure to fulfill a requirement. In an ISO 27001 audit, that means the auditor has found objective evidence that the organization is not meeting a clause of the standard, is not following its own documented policies and procedures, or is not honoring security commitments made to customers or regulators.
Nonconformities in ISO 27001 are always tied to a specific requirement. When one is raised, the auditor documents four things: a description of the issue, the objective evidence supporting it, a reference to the exact requirement not met, such as one of the ISO 27001 clauses or an Annex A control; and a summary of what fulfillment would require. This structure matters because it makes every finding traceable and actionable rather than a matter of auditor opinion.
It is also worth distinguishing ISO 27001 nonconformities from opportunities for improvement. An OFI is an auditor's suggestion: a process that works but could work better. Corrective action on an OFI is recommended, not required. A nonconformity, by contrast, obligates a response. Ignoring one puts certification at risk.
Types of Nonconformities in ISO 27001: Major and Minor
There are two types of non-conformities in ISO 27001: major and minor. All ISO 27001 nonconformities carry an obligation to respond, but the distinction rests on severity and system impact, and it determines what happens next in the certification process.
Major Nonconformities
A major nonconformity is a systemic failure or the complete absence of a required element of the management system. Examples drawn from real audits include an internal audit that was never performed, a risk assessment process that is documented but not followed, disaster recovery tests claimed but never conducted, and policies that exist but that no one follows. Major ISO 27001 nonconformities block certification: the certificate cannot be issued, or an existing certificate can be suspended, until the finding is resolved and the resolution is verified by the auditor, often through a follow-up assessment.
Minor Nonconformities
Minor ISO 27001 nonconformities are isolated lapses in otherwise functioning processes: a single terminated employee whose account was not disabled on time, one overdue security training session, and a policy document past its review date. Certification can proceed with minor findings, provided the organization submits an acceptable corrective action plan. Certification bodies typically require the nonconformity report within around 14 days of the audit closing and evidence of correction within around 30 days.
How Minor Findings Escalate
The escalation rules are where many organizations get caught. A minor finding that is not corrected within the agreed timeline is normally upgraded to a major at the next audit. Multiple minor findings against the same requirement are treated as evidence of systemic failure and can be consolidated into a major. This is why experienced practitioners treat every finding, whatever its classification, as a commitment with a deadline. ISO 27001 nonconformities do not age well.
ISO 27001 Noncompliance: The Cost of Ignoring Findings
Sustained ISO 27001 noncompliance carries consequences beyond a difficult audit. Unresolved findings at a surveillance audit can lead to certificate suspension or withdrawal, which many customer contracts treat as a breach event. Enterprise buyers increasingly ask for audit findings and their closure status during due diligence, and a pattern of repeat findings tells them the management system is not genuinely operating. The commercial cost of losing a certificate almost always exceeds the cost of fixing the findings that threatened it.
The Most Common ISO 27001 Nonconformities
Certification bodies and lead auditors report a remarkably consistent pattern in the ISO 27001 non conformities they raise. The following eight ISO 27001 non conformities account for the majority of audit reports.
-
Incomplete or Outdated Risk Assessment
The methodology is unclear, criteria for likelihood and impact are inconsistent, or the assessment has not been reviewed after significant business or technology changes. Weak risk assessment often cascades into major findings because every control decision depends on it.
-
Access Control Lapses
Accounts of departed employees left active, access not adjusted when staff change roles, third-party and temporary access unmanaged, and privileged access unmonitored. Auditors sample leavers and movers specifically because this is where failures concentrate.
-
Internal Audit Gaps
No internal audit performed before Stage 2, audit programs that do not cover all processes and controls in scope, or auditors who lack independence from the areas they audit.
-
Management Review Deficiencies
Reviews that skip required inputs, produce no decisions, or generate identical minutes every cycle. Auditors read these records as a direct measure of leadership commitment.
-
Documentation Gaps
Copy-paste template policies describing processes the organization does not run. Auditors verify documents against practice, and mismatches generate findings on both sides.
-
Statement of Applicability Inconsistencies
Controls marked implemented that are not, exclusions without credible justification, or an SoA version that contradicts the scope document.
-
Untested Mitigation Plans
Business continuity and disaster recovery documentation that has never been exercised. A plan without a test record is treated as an unverified claim.
Most of these findings map to a small set of clauses and controls: Clause 6 planning, Clause 9 performance evaluation, Clause 10 improvement, and the access, asset, and supplier controls within the 93 Annex A controls of ISO 27001:2022. Organizations that concentrate readiness effort on these areas eliminate the majority of their exposure to ISO 27001 non conformities before the auditor arrives.
What Are the Common Causes of ISO 27001 Nonconformity in Audits
The common causes of ISO 27001 non conformity in audits are organizational rather than technical, which is why ISO 27001 non conformities recur when only the technical symptom is fixed: treating certification as a one-time project, documentation written for the auditor instead of the business, unclear control ownership, audit-month scrambles replacing continuous operation, and root cause analysis that stops at the first convenient answer.
The project mindset. Teams build the management system for the certification date, then disband. Controls decay, reviews lapse, and by the first surveillance audit the system reflects last year's organization. ISO 27001 assumes continual operation, and auditors test for it.
Borrowed documentation. Template policies save time but describe someone else's company. When the access policy names a review process that does not exist, the auditor raises two findings at once: the process gap and the unreliable documentation.
Unowned controls. When no named individual is accountable for a control, evidence stops accumulating and nobody notices until the audit. Ownership gaps are invisible in a policy review and obvious in operational sampling.
Shallow root cause analysis. Fixing the broken backup without asking why monitoring never flagged it guarantees the finding returns. Auditors reviewing Clause 10.2 evidence look specifically for whether corrective actions address causes or symptoms, and repeat ISO 27001 non conformities are the strongest signal they read.
How to Avoid ISO 27001 Nonconformities
Avoiding ISO 27001 non conformities comes down to five practices, each of which addresses a cause identified above and produces evidence the auditor can verify.
Run a gap assessment before the certification body does. A structured ISO 27001 gap assessment conducted months before Stage 1 surfaces the same issues an auditor would find, while there is still time to fix them quietly. Treat its output as a corrective action register with owners and deadlines, not a report to file.
Complete a genuine internal audit and management review cycle. Certification bodies expect at least one full ISO 27001 internal audit and management review before Stage 2. Cover every process and control in scope, document findings honestly, and close them with evidence. An internal audit that found nothing convinces no one.
Keep documentation synchronized with operations. Review policies when the business changes, not just annually. Before any audit, walk each documented process with the team that runs it and fix mismatches in whichever direction is correct: update the document or restore the practice.
Apply structured root cause analysis to every finding. Use a defined method such as the five whys, push past human error to the process or resource gap beneath it, and record the analysis. The corrective action record should show correction, cause, action, and verification as separate steps.
Track every finding to verified closure. Maintain a single register for internal and external findings with owners, deadlines, and closure evidence. Nothing prevents repeat ISO 27001 non conformities more reliably than a closure process that verifies the fix actually worked before the item is marked complete.
Conclusion
ISO 27001 nonconformities are not a verdict on an organization's competence. They are the mechanism through which the standard enforces its requirements, and every certified organization encounters them over time. What distinguishes mature information security management systems is the response. Findings are corrected at the root, supported by objective evidence, and used to improve the effectiveness of the ISMS.
The pattern across common ISO 27001 nonconformities is consistent enough to act on. Keep the risk assessment current. Maintain disciplined access control. Perform internal audits objectively. Conduct meaningful management reviews. Address root causes rather than symptoms. Organizations that follow these practices typically enter certification audits with stronger evidence and a more effective management system.
At CertPro, we conduct independent ISO 27001 certification audits worldwide as a licensed CPA firm. Our auditors classify nonconformities based on objective evidence, document the applicable ISO/IEC 27001 requirements supporting each finding, and verify corrective actions before findings are closed. Whether your organization is undergoing an initial certification audit, surveillance audit, or recertification audit, our ISO 27001 audit engagements follow a structured, evidence-based methodology aligned with ISO/IEC 27001:2022 and ISO 19011.


