Nonconformance and corrective action
Most corrective action processes stop at the fix and call it closed. That is why the same issue reappears next quarter with a new reference number. The two steps that make the difference are asking why it happened rather than what happened, and coming back later to check the fix actually worked.
- 1
Reporter records what was observed, when, where, and the immediate effect, in factual terms.
Reporter
Observation, not diagnosis. "Three units shipped without the final inspection stamp" is usable; "QC was careless" closes off the investigation before it starts.
- 2
Quality Manager assesses whether anything unsafe or non-conforming has reached or could reach a customer.
Quality Manager
Contained internally: go to step 4
Reached or could reach a customer: go to step 3
- 3
Quality Manager takes containment action: quarantine affected stock, halt the affected process, and notify whoever must be told.
Quality Manager
Containment comes before investigation. Stop the bleeding first, then find out why, and record what was contained and when.
Contained: go to step 4
- 4
Quality Manager assigns a single named Action Owner and a target date.
Quality Manager
One named owner. An action assigned to a team or a department is assigned to nobody.
- 5
Action Owner establishes the root cause, asking why until the answer is a process or system rather than a person.
Action Owner
If the answer is "someone forgot", keep going: why was forgetting possible, and why did nothing catch it? A cause you cannot design against is not a root cause.
- 6
Action Owner checks whether the same or a similar issue has been raised before.
Action Owner
Search the register before designing anything. A recurrence means the earlier corrective action failed, and repeating it will fail again.
First occurrence: go to step 7
Recurrence: go to step 11
- 7
Action Owner defines the corrective action that addresses the root cause, not just the instance.
Action Owner
Retraining one person is almost never a corrective action. If the process allowed the error, the process is what has to change.
- 8
Action Owner implements the action and updates every procedure, form, or check the change affects.
Action Owner
Timing: By the agreed target date
This is where corrective action connects to document control. A change that never reaches the written procedure has not really happened.
- 9
Quality Manager verifies after a defined interval that the issue has not recurred and the change is being followed as intended.
Quality Manager
Timing: At least 30 days after implementation
The effectiveness check is the step that separates a corrective action system from a logbook. Set the interval to something long enough for recurrence to be possible.
Effective: go to step 10
Not effective: go to step 5
- 10
Quality Manager closes the record with the root cause, the action taken, and the evidence of effectiveness.
Quality Manager
All three, or the record cannot answer anything useful later.
Closed: the procedure ends
- 11
Quality Manager escalates the recurrence, reviews why the previous action was ineffective, and treats that as the problem to solve.
Quality Manager
A recurrence is a failure of the corrective action process, not just of the process that failed. Escalating it is what stops the loop.
Escalated, reinvestigating: go to step 5
Change these before you use it
- Define your severity levels in step 2 with concrete criteria, since "could reach a customer" needs to mean something specific in your business.
- Set the effectiveness interval in step 9 per issue type. Thirty days suits a frequent process; a quarterly process needs at least two cycles.
- Name your actual register or tracking system, and make sure step 6 can actually be searched. An unsearchable register makes recurrence invisible.
- If you are certified to a standard, check the terminology it expects (nonconformity, corrective action, preventive action) and align the field names.
- This is a starting point, not certification or safety advice. Have it reviewed by whoever is accountable for your quality system.
This is a starting point, not compliance advice. It is written to be adapted, and a procedure that touches access, money, or customer data needs to match how your business actually operates and whatever rules apply to you. Use it as a first draft to edit, not a policy to adopt.
Make it yours in a couple of minutes
Rather than retyping this and editing it, describe your own version of the process out loud or click through it once, and get a first draft with your actual steps, roles, and systems in it. No account needed to see the result.
No account neededNo credit cardSee the whole SOP before you sign up