ISO 9001 Non Conformance Report Template: A Practical Guide

By Brian Crocker · Published 26 July 2026

Every nonconformity your QMS produces is either an opportunity to improve or a liability waiting to surface in your next certification audit. ISO 9001 Clause 10.2 tells you what to do when something goes wrong. Your non conformance report (NCR) is the documented evidence that you did it.

This guide covers what an effective NCR contains, how to structure root cause analysis, and how to close corrective actions in a way that satisfies both your business and your auditor.

What Clause 10.2 requires

ISO 9001:2015 Clause 10.2 requires that when a nonconformity occurs — whether from a complaint, an internal audit finding, a process failure, or a product defect — you must:

  1. React: control and correct the nonconformity, deal with the consequences
  2. Evaluate the need for corrective action by reviewing and analysing the nonconformity, establishing the cause(s), and determining if similar nonconformities exist or could occur elsewhere
  3. Implement any actions needed, then review effectiveness
  4. Update risks and opportunities if needed
  5. Make changes to the QMS if necessary

Documented information is required as evidence of: the nature of the nonconformities, actions taken, and results of corrective actions (Clause 10.2.2).

Two important distinctions: a correction fixes the immediate problem (rework a defective product, recall a wrong delivery). A corrective action addresses the root cause so the problem does not recur. Both are required; auditors check both.

When to raise an NCR

An NCR should be raised whenever you identify a failure to meet a specified requirement. This includes:

  • Customer complaints — a delivered product or service did not meet agreed specification
  • Internal audit findings — process or product does not conform to documented procedure or standard requirement
  • Process failures — output does not meet defined acceptance criteria
  • Supplier failures — incoming goods or services do not meet purchase specification
  • Regulatory nonconformities — failure to meet a legal or contractual requirement

Some businesses set a threshold — for example, only raising a formal NCR for issues above a certain cost or frequency. This is acceptable, provided the threshold is documented and consistently applied. Auditors become suspicious when a business has zero NCRs over 12 months — either the QMS is exceptionally well-run, or problems are being masked.

NCR template structure

A well-structured non conformance report has six sections:

Section 1: Identification

Field Content
NCR reference number Unique identifier (e.g. NCR-2026-047)
Date raised Date the nonconformity was identified
Raised by Name and role
Source Internal audit / customer complaint / process check / supplier issue
Relevant clause ISO 9001 clause and/or internal procedure reference
Product / process affected Specific product, service, process, or department

Section 2: Description of the nonconformity

State exactly what was found. Be specific: what, where, when, how many.

Weak: "Quality checks not performed." Strong: "Final inspection records missing for batch #A2047 (12 units, despatched 2026-06-15). Clause 8.6 requires signed inspection evidence before release. 3 of 12 units returned by customer on 2026-06-22 with dimensional failures."

Attach evidence: photos, data records, audit checklists, complaint correspondence.

Section 3: Immediate correction

What was done to fix the immediate problem?

  • Product recalled / reworked / scrapped / concession granted?
  • Customer informed / credit issued / replacement despatched?
  • Process stopped pending investigation?

Record the disposition decision and who authorised it. If a concession (accepting nonconforming output "as is") was granted, it must be documented and — for regulated products or contractual requirements — may need customer or client sign-off.

Section 4: Root cause analysis

This is the section most NCRs get wrong. Identifying the symptom as the cause produces corrective actions that do not prevent recurrence.

5-Why method — effective for simple process failures:

  • Why did the defect occur? Final inspection was not completed.
  • Why? Inspector was off sick and no cover was arranged.
  • Why? No cross-training procedure for inspection roles.
  • Why? Training plan only covers primary role assignments.
  • Why? Training plan template has no section for backup role competencies.

Root cause: training plan does not capture backup role requirements.

Ishikawa (fishbone) analysis — useful for complex failures with multiple contributing factors across people, process, equipment, environment, materials, and measurement.

Document the method used, the cause chain, and the identified root cause(s). Your auditor will check that the corrective action targets the root cause, not just the symptom.

Section 5: Corrective action plan

For each root cause, define:

Field Content
Action description What will be done
Responsible owner Named individual
Target completion date Specific date, not "ASAP"
Evidence required What will demonstrate completion

Actions must be appropriate to the effect of the nonconformity. Clause 10.2.1 states this directly, in a standalone requirement after the lettered list: "Corrective actions shall be appropriate to the effects of the nonconformities encountered." A minor administrative error does not require a complete QMS overhaul. A product failure that injured a customer does.

Section 6: Verification of effectiveness

After the corrective action completion date, a second person (or your next internal audit) must verify:

  • Action was completed as planned
  • Root cause has been eliminated (or controlled)
  • The same nonconformity has not recurred

Record the verification: who checked, what evidence was reviewed, outcome. If the corrective action proved ineffective, raise a new NCR or extend the existing one with revised analysis.

Mark the NCR as closed only when effectiveness has been verified.

Tracking open NCRs

Your corrective action log should be a live document reviewed at management reviews (Clause 9.3.2 requires management review inputs to include nonconformities and corrective actions). Minimum log columns:

| NCR ref | Date raised | Source | Summary | Root cause | Corrective action | Owner | Target date | Status | Closed date |

Export or summarise this at each management review. Your certification auditor will ask to see it.

Common NCR mistakes

Confusing correction with corrective action. Fixing the product and closing the NCR without addressing root cause means the problem will recur — and your auditor will notice the pattern.

Vague root cause. "Human error" is not a root cause. Human error is a symptom. What process, training gap, or system failure made the error easy to commit?

No closure verification. An NCR marked "closed" with no effectiveness check is a finding in itself. Clause 10.2.1 d) requires you to review the effectiveness of any corrective action taken before declaring the action complete.

Missing records. Corrective actions taken verbally and never documented. Evidence must exist: photos, updated procedure, training records, retested product data.

Chronically open NCRs. An NCR still open 6 months after the target date signals that either the action is too ambitious or nobody is accountable. Escalate to management review before your certification audit — auditors spot overdue items immediately.

How NCRs connect to the rest of your QMS

Well-managed NCRs feed other parts of your QMS:

  • Risk register (Clause 6.1): recurring NCRs indicate an underrated risk — update your risk assessment
  • Objectives (Clause 6.2): NCR trend data informs improvement targets ("reduce complaint rate from 4.1% to 2.5%")
  • Management review (Clause 9.3): NCR status and trend is a mandatory input
  • Internal audits (Clause 9.2): process areas with high NCR rates should be prioritised in your internal audit schedule
  • Document control (Clause 7.5): if a corrective action changes a procedure, document control rules apply — version control, review, approval

The businesses that benefit most from their QMS treat NCRs as early warning signals, not compliance obligations. A spike in supplier NCRs often predicts a customer complaint 4–6 weeks later if left unaddressed.

ISO 27001 parallel

If you run an ISMS alongside your QMS, ISO 27001 Clause 10.2 has an identical structure and requirement. Information security nonconformities — access control failures, policy breaches, incident handling gaps found in internal audits — follow the same NCR process. Many SMBs use a single NCR template covering both standards, with a "standard reference" field to distinguish QMS from ISMS findings.

See also: ISO 9001 Risk Assessment Template for context on how NCR trends feed back into your risk register.

This article is for general informational purposes only and does not constitute legal, regulatory, or professional compliance advice. ISO certification requirements vary by scope, sector, and certification body. Always verify requirements with your UKAS-accredited certification body or a qualified consultant before making compliance decisions.

ClauseWise is coming soon

Generate your ISO 9001 and ISO 27001 documentation without consultant fees.