ISO 27001

ISO 27001 nonconformities: major vs minor, with worked examples

Whether a finding is major or minor decides whether you get certified on schedule. The difference is about the management system, not the size of the mistake.

Short answer

In ISO 27001 certification audits, a major nonconformity is one that affects the management system's ability to achieve its intended results, such as a required process missing or not working. A minor nonconformity is an isolated lapse that does not. Certification bodies define both in ISO/IEC 17021-1, and a major must be corrected before a certificate is issued or kept.

Key takeaways

  • Major: a requirement not met in a way that undermines the ISMS, or doubt that it is effective.
  • Minor: a lapse that does not affect the ISMS's ability to achieve its results.
  • Several related minors in one area can be raised as a major.
  • Every nonconformity needs a correction, a root cause and a corrective action.

Where the definitions come from

ISO 27001 itself does not grade nonconformities. The grading comes from ISO/IEC 17021-1, the standard certification bodies follow. A major nonconformity affects the capability of the management system to achieve its intended results. A minor nonconformity does not.

Worked examples

FindingGradeWhy
No internal audit has been carried out since the last certification auditMajorClause [[9.2|Internal audit]] is not being met at all
Management review has never considered ISMS performanceMajorA required input to [[9.3|Management review]] is missing, so the ISMS is not steered
One leaver's account was disabled five days lateMinorAn isolated lapse in [[5.18|Access rights]]; the process works
Access reviews missed in three of four quarters and never escalatedMajorThe control has broken down, not lapsed
The Statement of Applicability omits the justification for one excluded controlMinorDocumentation gap; the risk treatment decision exists

What each grade means for certification

  • Major: the certification body will not issue or continue the certificate until the correction and corrective action are accepted, and it may need to verify them on site.
  • Minor: you submit a correction and corrective action plan, and the auditor checks its effectiveness at the next audit.
  • Opportunities for improvement are not nonconformities and do not need a response, though a good auditor will ask what you did with them.

Writing a nonconformity that can be closed

A good finding states three things: the requirement, the evidence and what is missing. For example: 'Clause 9.2 requires internal audits at planned intervals. The audit programme shows audits planned for Q1 and Q3; no Q3 audit record exists and no reschedule was approved.' Anyone can see what closes it.

Checklist

Responding to a nonconformity

0 of 6 done

Frequently asked questions

What is a major nonconformity in ISO 27001?

A nonconformity that affects the capability of the information security management system to achieve its intended results, as defined in ISO/IEC 17021-1, for example a required process such as internal audit not being performed.

Can minor nonconformities become a major?

Yes. Several minor nonconformities with the same cause or in the same area can show a systemic breakdown and be raised as a major.

Sources

  1. ISO/IEC 17021-1:2015 Conformity assessment: requirements for bodies providing audit and certification of management systems, ISO
  2. ISO/IEC 27001:2022 Information security management systems, ISO