---
id: KB-IC-002
url: https://app.codecontract.io/help/reports-and-quality/recording-a-non-conformity
idioma: en
categoria: informes-y-calidad
subcategoria: calidad
audiencia: usuario
nivel: intermedio
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-CF-003, KB-CS-007, KB-IC-019]
citadoPor: [KB-IC-004, KB-IC-005, KB-IC-007, KB-IC-009, KB-IC-012]
---

# Recording a non-conformity

_What went wrong, what was done, and how to prove it later._

**Responde a:** record a non-conformity · quality incident management · corrective actions iso · auditor asks for non-conformities

A non-conformity is not a failure to hide: it is proof the system detects things. What an auditor views badly is not that they exist — it is that none are recorded, or that they are all still open.

## What you must be able to show

1. **What happened and when it was detected** — With dates. The gap between occurring and being detected is itself an indicator.
2. **What was done immediately** — The correction: stopping the batch, redoing the work, telling the client.
3. **Why it happened** — The cause, not the culprit. A record that names people stops being filled in.
4. **What was changed to prevent recurrence** — The corrective action, with an owner and a date.
5. **Whether it worked** — The closure. Without it, the non-conformity stays open forever.

> [!IMPORTANT]
> The step most often skipped is the last. A register full of non-conformities open for two years is worse than none: it demonstrates that things are detected and not corrected, which is the opposite of what it was meant to show.

## What is worth attaching

**En corto**

- Photos or documents from the time, certified if they may be disputed.
- The communication to the client or supplier, if there was one.
- Evidence that the corrective action was carried out.

> [!WARNING]
> If the non-conformity affects a client or a third party, telling them is part of the correction and often has deadlines. Do not leave it until everything is analysed.

> [!NOTE]
> Write the cause in a sentence that names nobody. "The procedure did not say who reviewed it" can be fixed; "Juan missed it" cannot.

**Does it serve for an ISO audit?**

It is exactly the register asked for, with its dates and evidence.

**What about ones that come to nothing?**

Close them noting no action was required. Closing is part of the record.

**Who should be able to raise them?**

The more people the better. A non-conformity only a manager can raise goes unraised.

## Ejemplos

**An auditor asks for the non-conformity register and finds thirty open for two years.**

- Closes those no longer applicable, noting why
- Assigns an owner and date to the five real ones

→ The register turns from evidence against them into what shows the system works.

**A non-conformity is noted in an email and three months later nobody knows if it closed.**

- Records it in the file with an owner and a date
- Notes what action was agreed and by when
- Checks monthly which ones are still open

→ The non-conformity stops living in an inbox and either closes or explains why not.

**It is recorded without saying what caused it.**

- Notes the cause alongside the fact

→ The analysis starts from something.

**They all get closed the day before the audit.**

- Reviews them on their own cadence

→ Closing means something.

**The same non-conformity repeats and nobody notices.**

- Checks the history by type

→ The pattern shows and the cause gets tackled.

**An auditor asks for the history and it has to be reconstructed.**

- Checks the record with its dates

→ It is handed over without reassembling anything.
