Skip to content

Nonconformities

Last checked on

This is where you record something that did not go as agreed and follow it through: the immediate correction, the root cause, the corrective actions and the check on whether they worked.

Why this protects your organisation

A mistake you only patch up tends to come back. You prevent a repeat by finding and removing the cause, and then checking that it worked. That is exactly what customers and auditors look for: not whether something went wrong, but whether you did something about it that holds. ISO 27001 sets this out in clause 10.2.

Steps

  1. Open Nonconformities in the Improve group and click New nonconformity.
  2. Describe the problem under What went wrong, choose where it came from under Found through, fill in the date and owner and click Create.
  3. Under Correction, record what you did straight away to limit the consequences, and when.
  4. Under Cause, describe why it happened.
  5. Add the corrective actions as tasks under Corrective actions, with Create task or Link existing task.
  6. Once the tasks are done, fill in the date, outcome and method under Check whether it worked.
  7. If the outcome is Effective, click Close.

Four steps

The form follows the order in which you deal with a nonconformity.

  1. What went wrong: a short title, a description, when it was found and who owns it. Under Found through you choose Internal audit, External audit, Incident, Complaint or Own observation.
  2. Correction: what you did immediately to limit the consequences, such as blocking an account or restoring a file.
  3. Cause: why it could happen. The sharper the cause, the more targeted the actions.
  4. Check whether it worked: once the corrective actions are done, you check whether the cause is really gone. You record when you checked, the Outcome and How you checked it.

Where it stands

The Where it stands column in the list shows the next step for each nonconformity: Needs a correction, Needs a cause, Check whether it worked, Not effective yet, Ready to close or Closed. You can also filter by Found through.

Closing

Closing records who closed the nonconformity and when. After that it stays readable, with everything you recorded, but it can no longer be changed.

A nonconformity can also start from an incident or a finding in an internal audit. Trustbird then fills in what is already known.

If it does not work

The Close button does not appear

You can only close a nonconformity once Check whether it worked has a date and the outcome Effective. If the outcome was Not effective, add further corrective actions and check again.

My closed nonconformities have disappeared

The list shows open nonconformities by default. Set the Status filter to Closed to see them. A closed nonconformity can be viewed but no longer changed or deleted.

I get an error on Checked on or Outcome

Those two fields belong together. Fill in one and the other becomes required.

I cannot create a nonconformity

Owners and members can create, update and close nonconformities. An advisor needs edit rights for the Improvement module. Only an owner or member can delete one, and only while it is still open.

Screens this is about

  • Nonconformities

Read next