+31 (0)73 - 220 2000 | info@brandcompliance.com
English
  • Dutch
  • English
  • Beglië
  • Dutch
  • English
  • Beglië
Brand Compliance
  • Certify
    • ISO 9001
    • ISO 22301 (BCM)
    • ISO 19770-1 (IT-assets)
    • ISO 27001
    • ISO 27017 and ISO 27018
    • BIO
    • ISO 27701 (Privacy)
    • NEN 7510
  • IT Assurance
    • SOC 2
  • Vacancies
  • Knowledge base
  • BC Academy
Contact
  • Information security
    • ISO 19770-1
    • ISO 27001
    • ISO 27017 and ISO 27018
    • ISO 27799
    • BIO
    • NEN 7510
    • SOC 2
    • ISAE 3402
  • Privacy
    • Whitepaper BC 5701
    • AVG standard BC 5701:2023 NL
    • GDPR standard BC 5701:2023 EN
    • GDPR standard BC 5701:2024 EN
    • BC 5701
    • ISO 27701
  • Quality
    • ISO 9001
    • ISO 14001
    • ISO 22301
  • Knowledge base
  • News
  • Academy
    • NIS2 training course
    • ISO 27001 training courses
    • BC 5701 training courses
  • About us
    • Start your certification journey
    • Accreditations
    • Compliment, complaint or tip
    • Privacy Statement
    • Vacancies
    • Contact

Certification process

10
  • Checklist certification
  • Do you have your first audit soon?
  • How long does ISO certification take?
  • What is a certification cycle?
  • Applying for a certification process
  • Initial audit Stage 1
  • Initial audit Stage 2
  • Nonconformities management system
  • Certificate suspended or revoked? This is how you solve it!
  • Transfer of certification

BC 5701

5
  • BC 5701 certification: where do you start?
  • Your record of processing activities and the GDPR
  • Your Data Protection Officer and the GDPR
  • Checklist for your BC 5701 certification
  • Data breach: What is it and how do you prevent it?

General

9
  • SOC 2 or ISAE 3402: which standard suits your organization?
  • The Traffic Light Protocol (TLP): what does it mean for you?
  • The Brand Compliance glossary
  • What is a management system?
  • Internal or external audit?
  • Find out more about internal audits
  • Tips to describe a proper scope
  • Accreditation versus certification
  • The use of certification logos

ISO 27001:2022

3
  • Operational Capabilities: The Backbone of Information Security
  • ISO 27001:2022 – FAQ transition
  • ISO 27001:2022 – Transition process

Whitepapers

2
  • Whitepaper management system audits
  • Whitepaper GDPR Certification Standard and Criteria BC 5701

Best practices

3
  • Mastering GDPR compliance: best practices
  • Excelling in information security: best practices
  • Quality Management: best practices for success

NEN 7510

4
  • Transition to NEN 7510-1:2024
  • NEN 7510 without healthcare institution?
  • How to expand with NEN 7510
  • The differences between ISO 27001 and NEN 7510

NIS2 Directive

2
  • NIS2 liability
  • NIS2 & the Belgian CyberFundamentals
View Categories

Nonconformities management system

3 min. leestijd

afwijkingenNonconformities audit

A nonconformity can be detected from various sources. It often comes from an internal audit or from an audit by a certification body, such as Brand Compliance. But a nonconformity can also arise from an internal/external signal or from a complaint.

Types of nonconformities

Nonconformities come in two categories, with the nonconformity definition below:

Major nonconformity

Failure to meet a requirement that affects the management system’s ability to achieve its intended results.
* For example, when no internal audits or a management review have been performed.

Minor nonconformity

Failure to meet a requirement that does not affect the management system’s ability to achieve the intended results.
* Consider, for example, the use of an incorrect version of a document.

Resolving nonconformities

It is important that a nonconformity within the management system is solved properly and adequately. Dealing with nonconformities can be done in different ways. It is important that the method matches the standard against which you want to be certified. There are a number of points for attention that must be followed in order to arrive at a thorough handling of the nonconformity.

We list the points of attention for you:

    • Determine cause and extent
      There are several methods to find out the cause of the abnormality. The most well-known methods that can be used are, for example, the Ishikawa-diagram or the 5 times why method.
    • Correction on the nonconformity
      If the extent of the nonconformity is known, a correction can be made. In fact, this restores everything that went wrong (in the past).
    • Take corrective actions
      To prevent recurrence, so-called ‘corrective actions’ must be taken to remove the identified cause.
    • Verification
      After the corrective actions have been taken, it must be checked whether the actions have worked. If the nonconformity no longer occurs under the same circumstances, the corrective actions taken have worked and the nonconformity can be closed. If the corrective actions have not worked sufficiently, you may not have identified the correct root cause.

Terms

In the closing meeting of the audit, any nonconformities that the Lead Auditor has found during the audit will be communicated to you. You will receive a nonconformity form that you must complete. This nonconformity form must be submitted to the Lead Auditor within a specified period, for both major and minor nonconformities.

Of course, you are allowed to handle the nonconformities faster than the agreed terms. For example, you would like to receive your certificate as soon as possible? Then you can speed up the process of solving the nonconformities and submit the forms earlier. Agree with your auditor about the options for assessing your forms.

Finalizing nonconformities

For a minor nonconformity, you should initially provide a plan of action. You must analyze the cause of deviations and describe which specific corrections and corrective measures you have applied or have planned to apply, in order to eliminate the deviations found within the specified period.

The auditor will review the corrections, identified causes and corrective actions you have submitted to determine whether they are acceptable. The effectiveness of corrections and corrective actions will be verified by the auditor at the latest during the next audit.

For a major nonconformity, you must complete all steps, including verification, before the auditor verifies the effectiveness of corrections and corrective actions. This process must be completed in full for a major nonconformity before certification can be proceeded with.

Share This Article :
  • Facebook
  • X
  • LinkedIn
Updated on 29 March 2023
Initial audit Stage 2Certificate suspended or revoked? This is how you solve it!

Accreditation

RvA C548Brand Compliance B.V. has accreditation (C548) to certify ISO 27001, ISO 27701 NEN 7510 and ISO 9001 scope 33 information technology and 35 other services.

Brand Compliance B.V.

Hambakenwetering 8D2
5231 DC ‘s-Hertogenbosch

+31 (0)73 220 2000
info@brandcompliance.com

Chamber of Commerce nr.: 32101659
VAT nr.: NL8130.78.854.B01

Brand Compliance Belgie B.V.

Uitbreidingstraat 66
2600 Berchem (Antwerpen)

+32 (0)14 48 0730
be-info@brandcompliance.com

VAT nr.: BE0735.675.516

Brand Compliance Nordics AB

Vasagatan 16 2 TR
111 20 Stockholm

+31 (0)73 220 2015
info@brandcompliance.com

Org.nr: 559238-1387

© Copyright 2025 Brand Compliance