Deep Interpretation of ISO9001 Clauses (30) | 10.2 Nonconforming Products and Corrective Actions: A Complete Closed Loop for Correction and Prevention
1. Key Points of the Clause
ISO 9001:2015 Clause 10.2 is divided into two parts: 10.2.1 specifies actions, and 10.2.2 specifies evidence.
10.2.1 requires that: When nonconformities occur, including those arising from complaints, the organization shall a) address the nonconformity and, where applicable, take actions to control and correct the nonconformity and deal with its consequences; b) review and analyze the nonconformity, determine the cause of the nonconformity, and determine whether similar nonconformities exist or could occur, and evaluate whether actions are needed to eliminate the cause of the nonconformity to prevent recurrence or occurrence elsewhere; c) implement the required actions; d) review the effectiveness of the corrective actions taken; e) update the risks and opportunities determined during planning, if necessary; f) change the quality management system, if necessary. The final sentence is a restrictive requirement: corrective actions should be commensurate with the impact of the nonconformity.
10.2.2 requires the retention of documented information as evidence: the nature of the nonconformity and the subsequent actions taken, and the results of the corrective actions.
Another structural change often overlooked is that the 2015 version no longer has a separate clause for preventive actions (Clause 8.5.3 in the 2008 version has been removed). The preventive mindset is integrated into 6.1 Risk-based thinking and the third sub-item of 10.2.1 b).
2. Interpretation of Intent
First, correction and corrective actions are two different levels. a) is like stopping the bleeding—controlling the nonconformity, dealing with its consequences, and stopping the problem; b) to d) are about curing the disease—finding the cause, eliminating the cause, and verifying effectiveness. Completing a) and closing the case may look like the problem is "handled," but the same issue will likely reappear next month.
Second, the three sub-items of b) form a mandatory causal reasoning chain, with no steps to be skipped. Reviewing and analyzing the nonconformity is about gathering evidence, determining the cause is about identifying the root cause, and judging whether similar nonconformities could occur is about extrapolation. Many corrective action reports list "employee negligence" or "strengthen training" as the cause, which are conclusions, not causes. The true root cause should answer why the negligence was allowed to occur in that specific process.
Third, "whether similar nonconformities could occur" is the key point for prevention. This sub-item requires expanding the scope from the specific incident to a broader category of potential issues. This is the alternative design after the 2015 version removed the independent clause for preventive actions—prevention is not eliminated but transformed from "adding a measure after the fact" to "judging similar risks in advance."
Fourth, e) and f) push the endpoint from the field to the system. The true completion of corrective actions is not just the absence of problems in the field but the updating of the risk list, re-evaluation of control measures, and necessary revisions to documents and processes. If only the field is changed without updating the system, the problem will re-emerge in a different process or team.
Fifth, "commensurate" is a two-way red line. It prevents both overreaction to minor issues (e.g., using the eight-step method and holding numerous meetings) and underreaction to major nonconformities (e.g., simply stating "inspection has been strengthened"). The basis for judgment is the nature of the nonconformity, its scope of impact, whether it has reached the customer, and the likelihood of recurrence.
Sixth, the evidence requirement in 10.2.2 points to "reproducibility" rather than just "record-keeping." The nature of the nonconformity, the actions taken, and the results of the corrective actions should form a coherent narrative, not just a document that lacks logical analysis.
3. Implementation Practices
Step One: Categorize Before Acting. Set quantitative trigger conditions in the corrective action procedure: batch nonconformities, customer complaints and returns, repeated similar issues, serious nonconformities found during audits, and issues causing production stoppages or significant quality losses should trigger the full corrective action process. Single, occasional issues with controllable impacts should be handled through a simplified process and recorded. The categorization criteria should be documented to avoid "everyone reports, everything is relaxed."
Step Two: Use Structured Methods to Identify Causes. Require the responsible department to distinguish between direct causes, root causes, and causes of escape at three levels. Tools are not limited to the five whys, fishbone diagrams, and fault trees; the key is that conclusions are supported by factual data. Prohibit using "insufficient employee awareness" or "inadequate training" as the final root cause.
Step Three: Measures Should Target the System, Not Individuals. Prioritize the measures list as follows: technical poka-yoke first, document and process revisions second, and training and reminders last. Clearly define the responsible person, completion date, and verification method for each measure. For changes involving design, process, suppliers, or inspection, follow the change control process simultaneously.
Step Four: Verify Effectiveness Using Data. Verification is not just asking "is it fixed?" but setting an observation period (e.g., three consecutive months or several batches) and comparing metrics such as defect rates, complaint numbers, and process capability with the baseline. If the issue recurs during the observation period, the measures are considered ineffective, and a new analysis is required.
Step Five: Update the System and Expand Horizontally. After verifying effectiveness, update relevant documented information and work instructions, assess whether the risk and opportunity list needs modification, and extend the conclusions to other production lines, processes, or suppliers with similar risks. Include the results in the management review input.
4. Auditor's Perspective
Common Finding One: Only Correction, No Corrective Actions. Records of rework, repair, sorting, and scrapping can be seen on-site, but when asked "why did this issue occur and how can it be prevented from recurring," no evidence of cause analysis or elimination of the cause is provided, indicating a lack of 10.2.1 b) to d).
Common Finding Two: Cause Analysis Stays at the Surface. Corrective action forms often state "operator did not follow the work instruction" or "the responsible person has been penalized and trained" without further questioning why the instructions were not followed or why the poka-yoke and supervision mechanisms failed, which is a typical case of insufficient root cause analysis.
Common Finding Three: Measures Without Verification or Unreliable Verification Methods. The measures section may list "strengthened inspections" or "increased sampling frequency," and the verification section may state "verified," but without verification times, verifiers, data comparisons, and observation periods, this is the easiest area for auditors to delve into.
Common Finding Four: Nonconformities from Customer Complaints Not Included in 10.2. The clause explicitly states "including those arising from complaints," but many companies close customer complaints within the customer service process without entering them into the corrective action system, leaving the root causes upstream unaddressed.
Common Finding Five: Risk and Opportunity Lists Not Updated After Corrective Actions. There is often no trace of e) and f) in the records, and the version dates of documented information remain unchanged before the corrective actions, creating a contradiction where "measures have been implemented, but documents have not been updated."
Common Misunderstanding One: Viewing corrective actions as merely filling out forms and archiving them, believing that having all the forms completes the task, while neglecting the independent requirement for effectiveness review. Common Misunderstanding Two: Interpreting the 2015 version as no longer requiring preventive actions, leading to the neglect of both the risk list in 6.1 and the "similar nonconformities" judgment in 10.2, thus breaking the entire preventive line. Common Misunderstanding Three: Applying the eight-step method to all nonconformities, making the process overly heavy and leading to superficial filling out of forms, which simultaneously reduces the quality of records and actual control levels.
5. Self-Inspection Checklist
- Does the corrective action procedure clearly define the quantitative conditions for triggering different levels of actions and specify the corresponding depth of analysis for each level?
- Does each corrective action record distinguish between correction (stopping the bleeding) and measures to eliminate the cause, and are the causes not conclusion-based statements like "negligence" or "inadequate training"?
- Have you assessed whether similar nonconformities exist or could occur, and have the conclusions been applied to other processes, production lines, or suppliers?
- Is the effectiveness of the measures supported by an observation period, verification indicators, and data comparisons, and is the verifier independent of the responsible person?
- After completing the corrective actions, have the relevant documented information, risk, and opportunity lists been updated, and have the results been included in the management review input?
Correction stops the problem, while corrective actions eliminate the cause.
Knowledge code: 2.1.1
Version: v20260928
Author: QTank QTank is dedicated to providing systematic knowledge, methodologies, and practical tools for quality management professionals, helping companies continuously improve their quality capabilities.