ISO 27001 Clause 10.2 requires organisations to handle nonconformities by taking corrective actions. The Nonconformity Register centralises all nonconformities and their resolution.

Logging a nonconformity

Go to ISO 27001 → Nonconformities and click Add Nonconformity.

FieldDescription
TitleBrief description of the nonconformity
SeverityMajor or Minor
SourceWhere it was found: Internal audit, External audit, Incident, Management review, etc.
Root CauseAnalysis of why the nonconformity occurred
Corrective ActionWhat action will be taken to prevent recurrence
Due DateDeadline for completing the corrective action
StatusOpenIn ProgressClosed
💡
Auditors will check that nonconformities are addressed with true corrective actions (preventing recurrence), not just corrections (fixing the immediate issue).