Sendabrief logoSendabrief
Free template

Nonconformance and corrective action

Most corrective action processes stop at the fix and call it closed. That is why the same issue reappears next quarter with a new reference number. The two steps that make the difference are asking why it happened rather than what happened, and coming back later to check the fix actually worked.

Download as Word (.docx) 11 stepsNo email, no signup. 11 steps, editable in Word or Google Docs.
Trigger

When a nonconformance is identified: a customer complaint, an internal check failure, an audit finding, or a repeated incident.

Roles involved
ReporterQuality ManagerAction Owner
Review cadence

Annually, and after any recurrence that reached a customer. A recurrence is direct evidence this procedure needs work.

  1. 1

    Reporter records what was observed, when, where, and the immediate effect, in factual terms.

    Reporter

    Observation, not diagnosis. "Three units shipped without the final inspection stamp" is usable; "QC was careless" closes off the investigation before it starts.

  2. 2

    Quality Manager assesses whether anything unsafe or non-conforming has reached or could reach a customer.

    Quality Manager

    Contained internally: go to step 4

    Reached or could reach a customer: go to step 3

  3. 3

    Quality Manager takes containment action: quarantine affected stock, halt the affected process, and notify whoever must be told.

    Quality Manager

    Containment comes before investigation. Stop the bleeding first, then find out why, and record what was contained and when.

    Contained: go to step 4

  4. 4

    Quality Manager assigns a single named Action Owner and a target date.

    Quality Manager

    One named owner. An action assigned to a team or a department is assigned to nobody.

  5. 5

    Action Owner establishes the root cause, asking why until the answer is a process or system rather than a person.

    Action Owner

    If the answer is "someone forgot", keep going: why was forgetting possible, and why did nothing catch it? A cause you cannot design against is not a root cause.

  6. 6

    Action Owner checks whether the same or a similar issue has been raised before.

    Action Owner

    Search the register before designing anything. A recurrence means the earlier corrective action failed, and repeating it will fail again.

    First occurrence: go to step 7

    Recurrence: go to step 11

  7. 7

    Action Owner defines the corrective action that addresses the root cause, not just the instance.

    Action Owner

    Retraining one person is almost never a corrective action. If the process allowed the error, the process is what has to change.

  8. 8

    Action Owner implements the action and updates every procedure, form, or check the change affects.

    Action Owner

    Timing: By the agreed target date

    This is where corrective action connects to document control. A change that never reaches the written procedure has not really happened.

  9. 9

    Quality Manager verifies after a defined interval that the issue has not recurred and the change is being followed as intended.

    Quality Manager

    Timing: At least 30 days after implementation

    The effectiveness check is the step that separates a corrective action system from a logbook. Set the interval to something long enough for recurrence to be possible.

    Effective: go to step 10

    Not effective: go to step 5

  10. 10

    Quality Manager closes the record with the root cause, the action taken, and the evidence of effectiveness.

    Quality Manager

    All three, or the record cannot answer anything useful later.

    Closed: the procedure ends

  11. 11

    Quality Manager escalates the recurrence, reviews why the previous action was ineffective, and treats that as the problem to solve.

    Quality Manager

    A recurrence is a failure of the corrective action process, not just of the process that failed. Escalating it is what stops the loop.

    Escalated, reinvestigating: go to step 5

Change these before you use it

  • Define your severity levels in step 2 with concrete criteria, since "could reach a customer" needs to mean something specific in your business.
  • Set the effectiveness interval in step 9 per issue type. Thirty days suits a frequent process; a quarterly process needs at least two cycles.
  • Name your actual register or tracking system, and make sure step 6 can actually be searched. An unsearchable register makes recurrence invisible.
  • If you are certified to a standard, check the terminology it expects (nonconformity, corrective action, preventive action) and align the field names.
  • This is a starting point, not certification or safety advice. Have it reviewed by whoever is accountable for your quality system.

This is a starting point, not compliance advice. It is written to be adapted, and a procedure that touches access, money, or customer data needs to match how your business actually operates and whatever rules apply to you. Use it as a first draft to edit, not a policy to adopt.

Make it yours in a couple of minutes

Rather than retyping this and editing it, describe your own version of the process out loud or click through it once, and get a first draft with your actual steps, roles, and systems in it. No account needed to see the result.

No account neededNo credit cardSee the whole SOP before you sign up