Published: 24 April 2026 | Reading time: 15 minutes | Category: ISO 45001 Maintenance

ISO 45001 Nonconformity and Corrective Action: A Step-by-Step Guide

A worker is injured because a guard was missing from equipment. You investigate and conclude: “Worker didn’t follow procedure.” You discipline the worker and move on.

A week later, a near-miss in the same area. You investigate again. “Same worker, same guard missing.” You’re puzzled — you already addressed this.

You’ve made a critical error: you treated the proximate cause as the root cause. The worker didn’t invent guard removal. Something made that control ineffective. Until you understand what, you’ll never solve the problem.

Nonconformity and corrective action under ISO 45001 Clause 10.2 is about breaking this cycle. It’s a systematic process for detecting failures, understanding why they occurred, and implementing actions that prevent recurrence — not just in one area, but system-wide.

Most organisations fail at corrective action because they stop too early in the investigation. They find an easy answer and call it done. Auditors can tell. They’ll ask: “What was the root cause?” You’ll cite the worker’s action. The auditor will follow up: “Why did the worker do that?” If you don’t have a systemic answer, your CAPA fails credibility.

This article walks you through what nonconformity means, the corrective action process, root cause analysis tools, and how to verify that your actions actually prevent recurrence.

Defining Nonconformity

A nonconformity is a failure to meet a requirement. The requirement could be:

  • A requirement of ISO 45001 itself: You don’t have documented information required by the standard; you haven’t conducted management review; your audit schedule isn’t being followed.
  • A requirement in your documented system: Your procedure says inspections happen weekly, but they’re happening monthly; your hazard register says a control is in place, but it’s not; your training schedule says competency assessments happen annually, but they don’t.
  • A legal or regulatory requirement: A regulation mandates certain PPE or engineering controls, and you’re not complying.
  • A requirement that emerges from your context: You identified a significant hazard and planned a control, but the control isn’t working.

Not all nonconformities are equal. Some indicate a failed control that created hazard exposure. Others indicate documentation that’s out of step with practice. Your corrective action process should distinguish severity and respond proportionately.

A worker didn’t document a near-miss (minor nonconformity of your procedure) is handled differently than a hazard control was bypassed for a week (major nonconformity creating exposure).

Sources of Nonconformity Detection

Where do nonconformities come from? Everywhere. That’s the point — your system should have multiple ways of surfacing problems:

Internal audit (Clause 9.2): This is the primary source. Auditors deliberately look for gaps between requirements and reality. Audit findings often identify nonconformities.

Incident investigation (Clause 10.2): An incident reveals that a control failed or didn’t exist. The incident itself is not a nonconformity, but the control failure usually is.

Inspection and monitoring (Clause 9.1): Your routine monitoring might reveal that a control is not functioning. A safety inspection discovers a hazard isn’t controlled as designed.

Worker reports: A worker reports a hazard. Investigation shows it should have been identified in your hazard assessment but wasn’t (nonconformity of HIRA). Or a worker reports that a procedure isn’t being followed (nonconformity of procedure compliance).

Regulatory inspection: A regulator identifies a legal non-compliance. This is a nonconformity of your system’s legal compliance controls.

Management review (Clause 9.3): Management might identify a pattern (multiple similar incidents, repeated audit findings) that indicates a systemic nonconformity.

A mature system has active mechanisms for surfacing nonconformities, rather than waiting for them to surface accidentally. Workers know they can report issues without retaliation. Auditors are rigorous. Managers regularly ask: “What are we missing?”

The 6-Step Corrective Action Process

Once a nonconformity is identified, follow a structured process. This is not optional — ISO 45001 requires systematic corrective action.

Step 1: React and Contain the Immediate Issue

If the nonconformity represents an active hazard, stop it. Shut down equipment if a guard is missing. Withdraw a defective PPE item. Restrict access to a hazardous area. Your first action is containment, not investigation.

This is often missed in formalised corrective action processes. You want to investigate properly, but sometimes you need to act immediately to prevent an incident.

Step 2: Review and Document the Nonconformity

Document what happened. When was it discovered? By whom? What exactly doesn’t conform? What requirement was violated? Who were the people affected (or who could have been affected)?

Assess severity: Is this a low-risk procedural gap (documentation out of date) or a high-risk control failure (a hazard was left uncontrolled)? Severity drives how fast you’ll move through subsequent steps and how deeply you’ll investigate.

Create a nonconformity record. This becomes your formal tracking mechanism.

Step 3: Investigate and Determine Root Cause

This is where most organisations fail. The proximate cause (what immediately caused the failure) is obvious and useless. You need the root cause (the systemic failure that made the proximate cause possible).

Example: A worker was injured when a guard was missing.

  • Proximate cause: The worker removed the guard to speed up the task.
  • Root causes: The guard design slowed the process (engineering failure). The worker was under production pressure and was trained that speed matters more than following procedure (cultural failure). Supervision wasn’t checking whether the guard was in place (control failure). Nobody investigated the first time the guard was removed last month (learning failure).

Use structured tools to push beyond the obvious.

Step 4: Evaluate Whether Similar Nonconformities Exist

This is critical and often skipped. If a hazard control failed in Department A, does it work differently in Department B? If a procedure was misunderstood in one team, others probably misunderstood it too. If a documented requirement wasn’t met in one place, how many other places are the same?

Your investigation should explicitly ask: “Could this happen elsewhere?” If the answer is yes, you investigate those areas immediately. This prevents discovering the same nonconformity three times.

Step 5: Implement Corrective Action

Design an action that addresses the root cause, not the symptom. If root cause was engineering (guard was inefficient), the corrective action might be redesign the guard or the process. If root cause was training, revise training and competency verification. If root cause was supervision, strengthen supervision and introduce checks.

Assign ownership. Set a target completion date. Define what success looks like (how will you know the action worked?).

Consider whether preventive action is also needed. Corrective action fixes this nonconformity. Preventive action might address similar potential nonconformities elsewhere in your system.

Step 6: Verify Effectiveness

After a reasonable period (typically 2-4 weeks, depending on the nature of the action), verify that the action actually worked. This isn’t assumption; it’s evidence.

How do you verify?

  • Inspect to confirm the control is in place and functioning
  • Review monitoring data to see if the pattern has changed
  • Interview workers to confirm they understand the new procedure
  • Check that no similar incidents have occurred

Document your verification. If the action didn’t fully work, cycle back to Step 3 and dig deeper.

Root Cause Analysis Tools

Structured tools force rigorous thinking and prevent premature closure. Here are three that work well:

The 5 Whys

Ask “why” repeatedly, at least five times, to move beyond proximate cause to root cause.

Example:
Q1: Why was the guard missing? A: Worker removed it.
Q2: Why did the worker remove it? A: It slowed down the process.
Q3: Why was speed more important than the guard? A: Supervisor was pushing to meet production targets.
Q4: Why was the production target prioritised over safety? A: No mechanism to surface competing demands to management.
Q5: Why didn’t management know about this conflict? A: Supervisor didn’t report it, and nobody asked.

Now you’ve moved from “worker removed guard” to “system didn’t surface production vs. safety conflicts.” That’s a root cause you can address.

Fishbone Diagram (Ishikawa)

Map all contributing factors across categories: People, Process, Equipment, Environment, Management, Measurement.

Example for a near-miss:
People: Worker wasn’t trained; new hire; didn’t understand hazard.
Process: Procedure existed but was unclear; no verification that worker understood.
Equipment: Guard design is inconvenient; workers often remove it.
Environment: High noise made communication difficult; worker couldn’t hear warning.
Management: No regular inspection to verify control is in place; no follow-up on previous near-misses.
Measurement: No leading indicators tracked whether guards stay in place.

This forces you to look beyond the obvious and identify systemic factors. Corrective action addresses multiple factors, not just one.

Fault Tree Analysis

Work backward from the failure. What conditions had to be true for this incident to occur?

Example: Incident occurred (the top of the tree)

  • This required: hazard exposure AND insufficient protection.
  • Hazard exposure required: person in hazard zone AND hazard activated.
  • Insufficient protection required: guard absent OR guard failed OR guard bypassed.

Map it out visually. See which combinations of factors led to the incident. This reveals both how the incident occurred and where you could have prevented it.

Recording and Tracking Nonconformities

You need a central nonconformity register that tracks each issue from identification through verification of effectiveness.

Essential fields:

  • Nonconformity ID (NC-2026-001)
  • Date identified
  • Description of what doesn’t conform
  • Requirement that was violated (ISO 45001 clause and/or your procedure)
  • Source (audit, incident, inspection, etc.)
  • Severity (high/medium/low)
  • Root cause analysis summary
  • Corrective action description
  • Owner
  • Target completion date
  • Actual completion date
  • Verification method and results
  • Status (open, closed, verified)

Use a shared tracker (spreadsheet or dedicated software) that’s visible to management. At management review, review the register: How many nonconformities are open? How long have they been open? Any that are overdue? Are there patterns?

Tracking creates accountability. When everyone knows the register is reviewed monthly, action ownership becomes real.

Common Corrective Action Failures

Failure 1: Blaming the Worker

A worker circumvented a control. You conclude the root cause is the worker’s carelessness and discipline them. You miss that the control itself creates a barrier to safe work, or that supervision was absent, or that the worker wasn’t trained. The worker is part of the picture, but not the cause.

Fix: Discipline might be appropriate if the worker knowingly violated a clear, understood, feasible procedure. But that’s separate from root cause analysis. Investigate why the worker did what they did.

Failure 2: Stopping at Proximate Cause

You investigate until you find an obvious explanation (“They didn’t follow procedure”) and stop. You never ask why the procedure wasn’t followed.

Fix: Use the 5 Whys or another structured tool. Push for at least one more layer of causation. Systemic causes are usually several layers deep.

Failure 3: No Evaluation for Similar Nonconformities

A control failed in one area. You fix it there. Three months later, the same control fails elsewhere. You investigate again as if it’s a new problem.

Fix: When investigating nonconformity, explicitly ask: “Could this happen elsewhere?” Then check. This prevents repeating the same cycle of discovery and correction.

Failure 4: Actions Without Verification

You implement a corrective action and assume it worked. You never check. Six months later, the same issue re-emerges, and nobody notices until the next audit.

Fix: Schedule verification within 2-4 weeks of action implementation. Document the verification (what you checked, what you found, what evidence you gathered). Only close the nonconformity after verification shows the action is effective.

Failure 5: Corrective Actions That Are Cosmetic

Root cause was cultural (production pressure overrides safety), but corrective action is procedural (revise the procedure). The procedure gets revised but nobody’s behaviour changes because the underlying pressure is still there.

Fix: Match the intervention to the cause. If it’s cultural, you need cultural change — training, leadership modelling, incentive realignment. If it’s engineering, you need design change. If it’s process, you need process change. Don’t expect a procedure revision to fix a culture problem.

Linking Corrective Action to Continual Improvement

Corrective action is reactive — you respond to a nonconformity. Continual improvement is proactive — you improve before failures occur. But they’re connected.

Patterns in nonconformities suggest improvement opportunities. If your nonconformity register shows that five incidents in the past year involved workers bypassing controls, that’s a signal that your control design process is flawed. It’s not just five incidents to correct; it’s a systemic improvement opportunity.

At management review, ask: “What does our nonconformity data tell us about how we should improve our system?” This converts defensive correction into strategic improvement.

What Auditors Look For

Certification auditors examine your corrective action process carefully. Here’s what they’ll assess:

Responsiveness: When nonconformities are identified, do you act on them, or do they sit open? High-risk nonconformities should be addressed within days or weeks. Low-risk can be slower, but nothing should sit open indefinitely.

Root cause quality: Auditors will read your RCA and ask themselves: Does this make sense? Is it credible? Or is it superficial? They might challenge: “The root cause you identified is the worker’s action. But why did the worker do that?” If you don’t have a systemic answer, they’ll rate the RCA as inadequate.

Systemic assessment: Did you ask whether similar nonconformities exist elsewhere? If you didn’t, auditors might. They might find the same issue in a different area and conclude your corrective action process doesn’t adequately look for systemic patterns.

Effectiveness verification: Can you show evidence that the corrective action actually worked? Documentation of verification, monitoring data before/after the action, follow-up observation of controls in place?

Closure discipline: Do you close nonconformities prematurely (before verification is complete), or do you properly track through the entire cycle? Premature closure suggests the process lacks rigour.

Building a Mature Corrective Action Culture

Mature organisations see nonconformities and corrective action not as failures but as opportunities to learn. Workers report issues confidently because they know the focus will be on fixing systems, not blaming people. Managers see nonconformity investigation as a strategic tool for understanding gaps.

This starts with how you talk about nonconformities. If leadership frames them as problems that expose carelessness, people hide them. If leadership frames them as intelligence that improves the system, people surface them. The difference in reporting rates is dramatic.

Practical Checklist: Strong Corrective Action

  • Maintain a central nonconformity register with all required fields
  • When a nonconformity is identified, immediately document it (don’t wait)
  • For high-risk nonconformities, react and contain before investigation
  • Use structured RCA tools (5 Whys, fishbone, or fault tree) — don’t rely on intuition
  • Explicitly evaluate whether similar nonconformities exist elsewhere
  • Assign clear ownership and target dates for corrective actions
  • Define how you’ll verify the action was effective
  • Within 2-4 weeks of action implementation, perform verification
  • Document verification findings and only close when effectiveness is proven
  • At management review, analyse nonconformity patterns for improvement opportunities
  • Train all managers on root cause analysis — don’t leave it to Safety Manager alone

Need help building stronger nonconformity and corrective action processes? Our consultants can review your current approach, train your team in RCA techniques, and help you move from reactive correction to proactive system improvement. Get in touch.

FAQ: Corrective Action in Practice

1. What’s the difference between a nonconformity and an observation?
A nonconformity is a failure to meet a specific requirement of ISO 45001 or your documented system. An observation is a finding that doesn’t violate a requirement but suggests an opportunity for improvement (e.g., “Your process works, but it could be more efficient”). Only nonconformities require corrective action. Observations are nice-to-address improvements.

2. If a worker is blamed in the RCA, do we still need to take systemic action?
Yes. Even if a worker’s action was the proximate cause, ask why the worker did it. The systemic causes are usually upstream: the procedure was unclear, the control was inconvenient, supervision was absent, or training was inadequate. Address both the worker accountability (if appropriate) and the systemic failure. The systemic failure is your corrective action.

3. How long should we allow for corrective action completion?
Depend on severity. High-risk nonconformities (active hazard exposure) should be acted on within days or weeks. Medium-risk can take weeks to months. Low-risk procedural issues can take longer. But nothing should stay open indefinitely. Set a target date and track progress. If an action can’t be completed, make a conscious decision to reschedule or close with accepted risk.

4. What if our root cause analysis doesn’t point to an obvious action?
This actually signals good RCA — you’ve dug deep enough to find complexity. Now the work is designing an action that addresses the systemic failure. It might require multiple interventions (training AND process redesign AND supervision changes). Document this. The corrective action becomes multi-faceted, not single-intervention.

5. Can we close a nonconformity if the corrective action isn’t fully complete?
No. A nonconformity should stay open until the corrective action is implemented AND verified as effective. Once verification confirms the action worked, you can close. If verification shows it didn’t fully work, reopen and cycle through RCA again. Closing prematurely signals a weak process.

6. What if an incident investigation identifies multiple potential root causes?
This is common and healthy. Document all potential causes, then assess which are most significant or most likely. Your corrective action plan might address multiple causes (e.g., redesign the control AND revise training AND strengthen supervision). This is more robust than picking one cause and ignoring others.

7. How do we prevent the same nonconformity type from recurring elsewhere?
Make systemic evaluation explicit: “Could this happen elsewhere in our organisation?” If yes, investigate those areas immediately rather than waiting for the problem to surface there. This proactive approach prevents repeating the same discovery-correction cycle multiple times.