Confusing spreadsheet used for audit

Blog

How to Close Audit Non-Conformances Properly

Raising a non-conformance is only the beginning of the process.
The real value of an audit comes from making sure that each non-conformance is understood, assigned, acted on, evidenced, verified and properly closed.

That sounds straightforward, but closure is one of the areas where audit processes often become inconsistent.

An action may be marked as complete even though the original issue has not been fully addressed. Evidence may be missing. A deadline may be changed without explanation. The same non-conformance may then appear again at the next audit.

A structured closure process helps prevent this by making it clear what needs to happen before an issue can genuinely be considered closed.

Read more about what is involved in audit management.

What Is an Audit Non-Conformance?

Non conformances are classed as a type of audit finding - these can range from observations though to non-conformances  and won't always require a formal close out unless they fall into the non-conformance category.

An audit non-conformance is a formal record of a situation where a requirement, procedure, standard or expected condition has not been met.

A useful non-conformance record should normally make clear:

  • what the non-conformance is
  • where it was identified
  • which requirement has not been met
  • what evidence supports the non-conformance
  • how significant the issue is
  • who is responsible for responding

The purpose is not simply to record that something went wrong.
It should create a clear starting point for corrective action and eventual verification of closure.

Critical, Major and Minor Non-Conformances

Not every non-conformance has the same significance.
For example Pisys Audits supports the categorisation of non-conformances as:

  • Critical
  • Major
  • Minor

These categories allow organisations to distinguish between different levels of non-conformance and prioritise their response accordingly.
The precise definitions of critical, major and minor should be determined by the organisation's own audit procedures, standards and risk criteria.

What matters is that the classification is applied consistently.

The category may influence:

  • the urgency of the response
  • who needs to be informed
  • the target completion date
  • the level of evidence required
  • whether escalation is needed
  • who is authorised to approve closure

A consistent classification process also makes management reporting more useful because non-conformances can be reviewed by severity rather than simply counted together.

What Is Required to Close a Non-Conformance?

A non-conformance should not normally be closed simply because someone has said that the work is complete.

A proper closure process should demonstrate that the issue has been dealt with satisfactorily.

This typically requires:

  • a clear corrective action
  • an identified action owner
  • a target completion date
  • evidence that the action has been completed
  • review or verification of the evidence
  • confirmation that the original non-conformance has been addressed
  • formal approval of closure where required

The level of control may vary according to the severity of the non-conformance.
A critical non-conformance may require a much more rigorous response than a minor one, but both should still have a clear and auditable path to closure.

Step 1: Define the Non-Conformance Clearly

Poorly written non-conformances are difficult to close because it is not clear what problem needs to be resolved.

A non-conformance should describe the issue precisely enough that someone who was not present during the audit can understand it.

A weak description might say:
"Training records are not satisfactory."

A clearer description would identify:

  • which records were reviewed
  • what information was missing
  • which requirement applied
  • where the issue was identified

This gives the action owner a much clearer basis for responding.

Step 2: Assign the Corrective Action

Once the non-conformance has been raised, one or more corrective actions may be required.

The action should describe what needs to happen to address the issue.
It should have a clearly identified owner.

Without clear ownership, responsibility can easily become ambiguous.

A good corrective action should normally include:

  • a specific action
  • an action owner
  • a due date
  • the non-conformance it relates to
  • the evidence required for completion

Where several actions are needed, they should be tracked separately rather than combined into one vague task.

Step 3: Set a Realistic Due Date

Every non-conformance should have a clear target for response and closure.
The timeframe may depend on:

  • the severity of the non-conformance
  • the complexity of the corrective action
  • operational constraints
  • the availability of resources
  • the risk associated with leaving the issue open

Due dates should be realistic, but they should not simply be extended repeatedly to prevent an action appearing overdue.
Where a deadline changes, the reason should be recorded so that the audit trail remains clear.

Step 4: Provide Evidence of Completion

Evidence is one of the most important parts of non-conformance closure.

An action owner may say that the work has been completed, but the reviewer needs something objective to support that statement.
Depending on the issue, suitable evidence might include:

  • photographs
  • revised procedures
  • updated training records
  • inspection reports
  • maintenance records
  • certificates
  • system screenshots
  • test results
  • approvals
  • completed forms

The evidence should relate directly to the corrective action and the original non-conformance.
Simply uploading a document is not enough if that document does not demonstrate that the issue has actually been addressed.

Completion Issues

One of the most important controls in non-conformance management is separating completion from closure.

An action owner may complete the work and submit evidence.
At that point, the action may be complete.

The non-conformance itself may still need to be reviewed before it can be closed.
The reviewer may need to confirm:

  • that the action was completed as described
  • that the evidence is sufficient
  • that the action addresses the original non-conformance
  • that no important part of the issue remains unresolved
  • that the action has not created another issue

This distinction prevents non-conformances being closed simply because a checkbox has been updated.

Step 5: Verify the Corrective Action

Verification is the point where someone reviews the corrective action and the supporting evidence.
The purpose is to establish whether the response is adequate.

The reviewer may:

  • accept the evidence
  • request additional evidence
  • return the action for further work
  • approve the action for closure

For more significant non-conformances, verification may also involve a follow-up inspection, review or audit.
The important point is that closure should be based on evidence rather than assumption.

Step 6: Confirm the Non-Conformance Has Been Addressed

Corrective action does not always mean that the underlying non-conformance has been resolved.

For example, an audit may identify repeated failures to carry out an inspection.

Completing one overdue inspection might address the immediate problem, but it may not address the process failure that caused inspections to be missed.
Before closure, it may therefore be necessary to consider:

  • whether the immediate issue has been corrected
  • whether the cause of the issue has been addressed
  • whether the corrective action is likely to prevent recurrence

The level of investigation required will depend on the nature and significance of the non-conformance.

Step 7: Approve and Record Closure

Once the non-conformance has been satisfactorily addressed, closure should be recorded.
The closure record should make it clear:

  • what action was taken
  • what evidence was reviewed
  • who verified the response
  • who approved closure
  • when the non-conformance was closed

This creates a complete history that can be reviewed later if the same issue appears again.

Why Non-Conformances Remain Open

There are several common reasons why non-conformances become overdue or difficult to close.
These include:

  • unclear corrective actions
  • no clear owner
  • unrealistic due dates
  • missing evidence
  • actions being managed by email
  • lack of reminders
  • unclear approval responsibility
  • several actions being combined into one
  • poor visibility of overdue items

In many cases, the issue is not unwillingness to complete the action.
It is that the process itself does not provide enough structure or visibility.

Why Non-Conformances Reappear

A recurring non-conformance can be a sign that an earlier action did not fully address the problem.
This may happen where:

  • the immediate symptom was corrected but the underlying cause was not
  • the corrective action was too narrow
  • the action was not implemented consistently
  • verification was weak
  • the issue was closed before sufficient evidence was available

Repeat non-conformances are particularly useful for management because they may indicate a wider process weakness rather than a single isolated failure.

Tracking Critical, Major and Minor Non-Conformances

Categorising non-conformances by severity becomes especially useful when management needs to prioritise attention.
A central system can make it easier to see:

  • how many critical non-conformances remain open
  • which major non-conformances are overdue
  • how many minor non-conformances are awaiting evidence
  • which items are awaiting verification
  • which areas generate repeated non-conformances
  • how long different categories typically remain open

This provides a much clearer picture than simply reporting the total number of open actions.

Managing Non-Conformances Across Multiple Sites

Non-conformance management becomes more difficult where audits are conducted across several locations.

Different sites may use different spreadsheets, naming conventions or local processes.
This makes it harder to maintain consistency.

A common workflow can help standardise:

  • classification
  • ownership
  • due dates
  • evidence requirements
  • approval
  • closure

It also makes it easier to identify recurring issues across different parts of the organisation.

Using Audit Software to Manage Non-Conformance Closure

Audit management software can help control the non-conformance lifecycle by keeping the relevant information together.

Rather than managing issues across spreadsheets, emails and shared folders, the process can be managed in one system.

Typical capabilities include:

  • recording non-conformances
  • categorising them as critical, major or minor
  • assigning corrective actions
  • setting due dates
  • tracking status
  • sending reminders
  • uploading evidence
  • reviewing corrective actions
  • approving closure
  • maintaining an audit trail

Pisys Audits is designed to support this process by linking audits, non-conformances, corrective actions, evidence and closure within a controlled workflow.

How Non-Conformance Closure Fits Into Audit Management

Non-conformance closure is only one part of the wider audit management process.
A complete audit management system may also include:

  • audit planning
  • audit scheduling
  • checklists
  • audit templates
  • non-conformance management
  • corrective actions
  • evidence
  • verification
  • reporting
  • audit trails

For a broader overview of the complete process, see our guide to what audit management is and how audits, non-conformances and corrective actions can be managed together.

What Effective Non-Conformance Closure Looks Like

A well-managed non-conformance should have a clear history from identification through to closure.
Someone reviewing it later should be able to see:

  • what went wrong
  • how serious it was considered
  • who was responsible for correcting it
  • what action was taken
  • what evidence was provided
  • who verified the response
  • when the non-conformance was closed

If those questions can be answered easily, the organisation has a much stronger basis for demonstrating that the issue was properly managed.

Frequently Asked Questions

What is an audit non-conformance?

An audit non-conformance is a record of where a requirement, procedure, standard or expected condition has not been met during an audit or inspection.

What are critical, major and minor non-conformances?

Critical, major and minor are categories used to distinguish non-conformances by significance. The precise definition of each category should follow the organisation's own procedures, standards and risk criteria.

What is needed to close a non-conformance?

A non-conformance normally requires a defined corrective action, an owner, supporting evidence, verification that the action has addressed the issue and formal closure where required.

Is completing an action the same as closing a non-conformance?

No. An action may be completed by the action owner, but the non-conformance may still require review, evidence verification and approval before it can be formally closed.

What evidence can be used to close a non-conformance?

Evidence may include photographs, revised procedures, training records, inspection reports, maintenance records, certificates, test results, screenshots or other records demonstrating that the corrective action has been completed.

Why do non-conformances sometimes recur?

Non-conformances may recur where the original corrective action addressed only the immediate symptom, was not implemented consistently or was closed without sufficient verification of its effectiveness.

Scroll to top
Pisys Limited | HSE Software
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.