Skip to main content

Standard

Closing a Major Nonconformity Before the Surveillance Audit

A practitioner's guide to closing a major nonconformity raised against an ISO/IEC 42001 management system: who owns the fix, what the certification body decides, the five parts of an acceptable response, the evidence pack, and the mistakes that turn a process failure into an integrity problem.

Closing a Major Nonconformity Before the Surveillance Audit

The audit report arrives a week or so after the auditor has left. Most of it is unremarkable. On page four there is one finding classified Major: your Statement of Applicability declares a set of Annex A controls applicable, and for three of them the auditor found no implemented control, no named owner and no records. The covering email names a date for your written response, and the surveillance audit is already in the calendar.

A major nonconformity is not a larger minor. It puts the certificate at risk, and the surveillance date rarely moves. What happens between the report and that date is a defined sequence, and more constrained than first-time recipients expect.

What "major" means, and who decided it

Certification bodies operating an ISO/IEC 42001 scheme are themselves accredited against ISO/IEC 17021-1, which governs how nonconformities are classified and closed. Broadly, a finding is major where a required element of the management system is absent or has broken down, where a pattern of lapses against one clause shows systemic failure, or where it raises significant doubt that the system will achieve its intended outcomes.

That classification is the body's decision, not yours. If you believe it is wrong, every accredited body operates a documented appeals process — use it formally and in writing. But assume the clock keeps running during an appeal unless the body confirms otherwise.

The timescales are also the body's. ISO/IEC 17021-1 requires time limits to be set for correction and corrective action, and requires the body to verify effectiveness; the number of days, whether verification is documentary or by a special on-site visit, and whether that visit is chargeable are set by each body's own procedure. How your body applies its rules to a major raised at surveillance, including whether suspension is on the table, is its procedure to state. Ask for it in writing on day one rather than inferring it.

Who is responsible for closing it

The organisation is. Not the auditor, not the certification body, not your consultant. The body classifies the finding, sets the deadline and decides whether the closure evidence is acceptable. It cannot design your fix: impartiality requirements in ISO/IEC 17021-1 prohibit a certification body from providing management system consultancy to a client it certifies. Asking your auditor "would this satisfy you?" invites a non-answer. Ask instead about process facts: format, deadline, verification method.

Inside the organisation, responsibility splits three ways. Top management holds accountability for the AI management system under the leadership clause, and a genuine major almost always needs a decision only it can make: budget, headcount, or pausing a deployment. The process owner whose process failed should own the corrective action, not the AIMS or compliance manager by default — compliance coordinates the pack and the relationship with the body. Verification of effectiveness should then be done by someone independent of whoever implemented the fix; internal audit is the natural home. If the last audit cycle missed this, that gap is a separate finding to raise against yourself.

Two boundaries are commonly blurred. First, if the failure also involves personal data, your data protection obligations run on their own clock and to a different body: under UK and EU GDPR the controller notifies the supervisory authority within 72 hours where the threshold is met, and a processor notifies the controller without undue delay. Penalties of up to 4% of global annual turnover attach to the responsible party, and certification status is irrelevant to that duty. Second, ISO/IEC 42001 certification does not confer presumption of conformity with the EU AI Act — harmonised standards for the Act are still in development, and ISO/IEC 42001 is not one of them. Your duties as a provider or deployer are unchanged by holding a certificate or receiving a nonconformity, as is the exposure of up to 7% of global annual turnover for prohibited practices and up to 3% for most other obligations.

The five parts of a response the auditor will look for

ISO/IEC 42001's nonconformity and corrective action clause (10.2) sets the shape of an acceptable response.

ElementWhat it meansEvidence that satisfiesWhere it goes wrong
CorrectionFixing the instance foundThe updated record or control, datedSubmitted as if it were the whole answer
ConsequencesDealing with what the failure causedAssessment of affected systems, users, decisions or dataSkipped; treated as a paperwork issue
Cause analysisWhy the system permitted itTraceable analysis reaching a controllable causeStops at "human error" or "resourcing"
Extent of conditionWhether similar failures exist elsewhereDocumented check across other systems or teamsNever done, so the fix looks narrow
EffectivenessProof the change works in operationRecords generated after the change, over more than one cycleAsserted from the plan, not from output

The evidence pack

Assemble one indexed pack, not a stream of attachments. It should contain:

  • The nonconformity as written by the auditor, quoted verbatim, with its clause reference.
  • The correction, with dated before-and-after evidence.
  • The cause analysis: method, people involved, and a cause you can act on.
  • The extent-of-condition review: scope searched and what was found, including "nothing further" if that is honest.
  • The corrective action plan: each action with one named owner, a due date and a status.
  • Consequent changes to the management system: Statement of Applicability, risk treatment, impact assessment, procedures, training records.
  • Effectiveness evidence: operational records produced after implementation, plus the independent verification note and who signed it.
  • The management review or governance minute where the finding and plan were considered, and an updated internal audit plan showing when the area will be re-audited.

Where these responses usually fail

The most common failure is submitting a correction as a corrective action. Updating the Statement of Applicability repairs the document; it says nothing about why it drifted out of line with reality and nobody noticed.

The second is a cause analysis that ends at a person. "Human error" is not a cause you can control; "the control had no owner because ownership was never assigned when the system moved from pilot to production" is. The third is silence on extent of condition — if three controls lacked owners in one business unit, the auditor's first question at surveillance is what you found in the others.

The fourth is the most damaging: retrospectively dated documents, or procedures reissued to look as though they had always existed. Version histories and ticket timestamps make it visible, and it converts a process failure into an integrity failure. A related trap is over-correcting: an elaborate procedure nobody follows creates a new requirement you can be audited against next time.

Limits, and when to take advice

The binding detail — deadlines, formats, whether a special visit is required, whether suspension applies — comes from your certification body's own accredited procedure and your contract with it, and practice varies between bodies. Treat their written answer as authoritative over any general guidance, including this.

Take specialist advice where the failure touches more than the certificate: personal data, safety, employment or credit decisions, or any regulated activity. There the certification timetable is the least important clock running, and what you write for the body may be disclosable elsewhere. Take legal advice before you write it.

Finally, if the honest position is that the control cannot be operating effectively before the surveillance date, say so with a dated plan rather than an optimistic claim. Bodies have options — extension, a special visit, a scope change, suspension — and every one is better handled in advance than discovered by an auditor who finds the same failure twice.

  • ISO 42001
  • nonconformity
  • corrective action
  • certification audit
  • internal audit

More guides

Start Free AI Compliance Review