Classifying Nonconformities: Major, Minor, and Observation
Learn how certification audits classify findings into major nonconformity, minor nonconformity, and observation — and why this classification, not just the finding itself, is what actually determines the consequences for certification.
Learning Objectives
- → Define major nonconformity, minor nonconformity, and observation
- → Explain how classification, not just the underlying finding, drives certification consequences
- → Distinguish a systemic failure from an isolated lapse when classifying a finding
- → Reclassify a finding correctly when new evidence changes its severity
Lesson 7 covered how to reach a defensible finding. This lesson covers the step immediately after: once a finding is determined to be a nonconformity, how severely is it classified — and why that classification decision carries as much weight as the finding itself.
The three classification levels
- Major nonconformity — a nonconformity that raises significant doubt about the ISMS's capability to achieve its intended outcomes, or a systemic failure (a pattern rather than an isolated instance), or the absence of a required element of the standard entirely (e.g., no risk assessment methodology exists at all).
- Minor nonconformity — a nonconformity that doesn't raise that level of doubt: typically an isolated lapse in an otherwise generally effective process, or a partial gap that doesn't undermine the system as a whole.
- Observation — not a nonconformity at all, but a noted opportunity for improvement, or an early warning sign of a potential future nonconformity if left unaddressed (e.g., a control that currently conforms but shows early signs of process fatigue).
Why classification, not just the finding, drives consequences
This is the single most consequential idea in this lesson: two findings that sound similar on the surface can have completely different certification outcomes depending on classification. A major nonconformity typically blocks certification (or, for a surveillance audit, can suspend an existing certificate) until a corrective action is verified — often requiring a focused follow-up visit. A minor nonconformity typically does not block certification; it requires a documented corrective action plan with a commitment date, verified at the next scheduled audit. Getting this classification wrong in either direction has real consequences: over-classifying an isolated lapse as major imposes an unnecessary business cost and delay; under-classifying a systemic failure as minor lets a genuinely serious ISMS gap through without triggering the scrutiny it needs.
Systemic vs. isolated: the key classification question
The central question when classifying a nonconformity is usually: is this an isolated lapse, or does it indicate the underlying process itself is broken? A single missed access review out of 40, promptly caught and corrected once found, in an organization with an otherwise consistent access review history, points toward an isolated lapse — likely minor. Forty missed access reviews out of 40, or a complete absence of any access review process at all, points toward a systemic failure — likely major. The same underlying control (access reviews) can produce either classification depending on the pattern the evidence actually reveals — which is exactly why Lesson 7's discipline of gathering a properly sized, representative sample matters so much: an undersized sample can make a systemic failure look like an isolated lapse, or vice versa.
Reclassifying when new evidence emerges
Classification isn't necessarily fixed the moment a finding is first identified — if additional evidence gathered later in the audit reveals that what looked like an isolated lapse is actually part of a broader pattern (or vice versa), the classification should be revised accordingly, with the reasoning for the change documented. An auditor who classifies early and then doesn't revisit that classification as more evidence comes in risks a final report that doesn't reflect the full picture the audit actually uncovered.
A common classification mistake
Classifying based on how embarrassing or how technically severe a finding sounds, rather than on the systemic-vs-isolated question and the actual criteria for each level, is a common error. A finding involving sensitive-sounding language ("customer data exposure risk identified") can trigger an instinct to classify it major regardless of whether it's actually a systemic gap or a one-off, promptly-corrected lapse — and the reverse is just as much a risk, where a mundane-sounding finding masks a genuinely systemic gap. The classification decision should trace back to the same evidence-based discipline established in Lesson 7, not to how a finding happens to read on the page.
Two findings both concern the same control (8.16 monitoring): Finding A: 1 out of 24 sampled months had no evidence of alert review, promptly explained as a one-time staffing gap during a public holiday, with all other months showing consistent review. Finding B: 0 out of 24 sampled months showed any evidence of alert review ever occurring. Classify each and justify using this lesson's systemic-vs-isolated question.
How should Finding B be classified, and why, compared to Finding A?
A certification body auditor tells a client: 'This is only a minor nonconformity, so don't worry, it won't affect certification timing at all — you can just fix it whenever.' Using this lesson's reasoning, what part of this statement is inaccurate?
What part of the statement 'you can just fix it whenever' is inaccurate for a minor nonconformity?
An auditor initially classifies a finding about incomplete supplier risk assessments as minor, based on 2 sampled suppliers. Later in the same audit, an additional sample of 8 more suppliers reveals that 7 of the 10 total sampled had no risk assessment on file at all. Using this lesson's reasoning, explain what the auditor should do.
What should the auditor do once the expanded sample reveals this broader pattern?