· Guide · 8 min read
Major vs Minor ISO 27001 Nonconformities Explained
Learn how ISO 27001 audit findings are graded, what major and minor nonconformities mean, and how to build defensible corrective-action evidence.
Major and minor nonconformities are not simply “large” and “small” mistakes. The grade reflects what the evidence says about the information security management system (ISMS): whether a requirement has not been met, how broadly the failure reaches and how much doubt it creates about the system’s ability to achieve intended outcomes.
The certification body applies its documented grading and decision processes. AuditPrepared examples can help teams reason about likely significance, but they cannot predict or override an auditor’s classification.
This guide explains how to interpret findings, challenge factual errors appropriately and produce corrective-action evidence that addresses the system rather than only the sample.
Start with the definition of a nonconformity
A nonconformity exists when an applicable requirement is not fulfilled. The criterion might come from ISO 27001, the organisation’s own ISMS, a legal or contractual obligation incorporated into the system, or another requirement included in the audit scope.
An auditor should link the finding to:
- the precise criterion used;
- objective evidence from records, interviews, observation or systems;
- the condition that does not meet the criterion; and
- enough context to understand the extent and significance.
A preference is not a requirement. If an auditor recommends a different tool, document layout or control design, ask which agreed criterion requires it. A useful improvement suggestion can remain valuable without being recorded as a nonconformity.
ISO 19011:2026 provides current guidance on management-system auditing, evidence and conclusions. Certification bodies operate under additional conformity-assessment requirements and their own controlled methods.
What generally makes a finding major
A major nonconformity normally indicates a serious or systemic failure: an essential requirement is absent, a process is not implemented, multiple related failures show a breakdown, or the evidence creates significant doubt that the ISMS can achieve its intended outcomes.
Examples that may support major grading include:
- no functioning internal audit programme across the certification scope;
- no management review of the ISMS;
- risk assessment and treatment not operating as defined;
- widespread failure to perform a critical control selected for significant risks;
- repeated minor issues that collectively demonstrate loss of process control;
- failure to correct a previous nonconformity effectively; or
- evidence deliberately misrepresented to the audit team.
Context matters. A missing access review for one low-risk account is different from an entire privileged-access population that has never been reviewed. An isolated late approval is different from a workflow that permits production access without authorisation.
What generally makes a finding minor
A minor nonconformity is still a failure to meet a requirement, but the available evidence does not indicate a complete or systemic breakdown. The process may exist and operate, with a limited lapse, isolated exception or narrow weakness.
Examples may include:
- one overdue competence review in an otherwise current population;
- an isolated record that lacks a required approval while surrounding samples are complete;
- one internal audit report missing a defined distribution record;
- a local procedure that is outdated but the current process is otherwise controlled; or
- a limited failure to follow the organisation’s approved method.
“Minor” does not mean optional. The organisation must address the finding through the certification body’s process and demonstrate that the response is proportionate and effective.
A practical grading lens
Audit teams commonly consider several connected factors. The following is AuditPrepared guidance, not a substitute for a certification body’s rules.
| Factor | Questions that clarify significance |
|---|---|
| Requirement | Is the requirement entirely absent or partly unmet? |
| Extent | Is the issue isolated, repeated across samples or present across the scope? |
| Risk | Could the failure materially affect confidentiality, integrity, availability or ISMS outcomes? |
| Process control | Does management know about the issue and control exceptions? |
| History | Is it new, recurring or an ineffective response to an earlier finding? |
| Evidence reliability | Can the organisation demonstrate operation, or is the conclusion based only on intention? |
Do not turn this table into a points formula. Grading requires judgement across the complete evidence set.
Pass, minor and major examples
Privileged access review
Pass: The complete administrator population was reconciled to the review record. Selected approvals, removals and exceptions were current, and review actions were traceable to closure.
Possible minor: One of 25 sampled accounts lacked evidence of the reviewer’s sign-off. The account was appropriate, other samples were complete and the process owner could show a controlled workflow.
Possible major: The organisation had defined quarterly privileged-access reviews, but none had been completed for two cycles across production platforms. Several former administrators remained enabled and management had no reliable population.
Internal audit
Pass: The risk-based programme covered the defined ISMS scope, competent and impartial auditors performed the work, findings were supported and actions were tracked.
Possible minor: One completed audit was issued later than the programme required, with no evidence that the delay affected coverage or follow-up.
Possible major: The organisation presented an audit schedule but had not performed an internal audit before the certification assessment, leaving the ISMS unevaluated against its planned arrangements.
Corrective action
Pass: The organisation corrected the sampled issue, evaluated cause and extent, implemented system-level action and confirmed effectiveness through later evidence.
Possible minor: One action effectiveness review was completed but not approved by the role required in the organisation’s process.
Possible major: Several previous findings were closed by rewriting procedures, yet the same operating failures recurred and no cause or extent analysis had been performed.
Why one sample can reveal a wider failure
An auditor reports what was observed, but the organisation must determine extent. If one terminated user’s access remains active, the correction is to disable that account. The response should also ask whether other leavers, connected systems or periods are affected.
Useful extent work includes:
- defining the relevant population;
- testing the complete population where feasible or selecting a justified broader sample;
- checking adjacent processes and systems;
- identifying when the failure began;
- evaluating whether existing monitoring should have detected it; and
- documenting the risk and any immediate containment.
The implementation-versus-operating-evidence guide explains why a revised procedure cannot by itself prove that the corrected process now works.
Build a defensible corrective-action response
A strong response separates four elements.
Correction
Fix the observed condition: complete the missed review, remove access, approve the record or issue the delayed report. Record who acted, when and how completion was verified.
Cause analysis
Identify why the system allowed the failure. “Human error” is rarely sufficient. Ask about unclear ownership, unsuitable workflow design, incomplete populations, capacity, competing approvals, poor monitoring or changes that were not incorporated.
Corrective action
Change the process so the cause is controlled. This may involve clearer ownership, automated population feeds, revised approval routes, competence development, monitoring or escalation. Select action based on cause rather than choosing documentation by default.
Effectiveness evaluation
Define what evidence will show the action works, when it can reasonably be evaluated and who will approve closure. Evidence might include two completed review cycles, a reconciled population, closed exceptions and trend results.
Use the ISO 27001 evidence register guide to connect each action to reliable implementation and operating records.
How to respond during the audit
If you disagree with a finding, remain factual. Ask the auditor to identify the criterion, affected scope and evidence. Provide relevant contrary evidence promptly. Correct misunderstandings about systems, dates or populations before the closing meeting.
Do not pressure the auditor to downgrade a supported finding because of commercial deadlines. Grading is part of the certification body’s independent process. Equally, do not accept vague wording that your team cannot act on. A finding should be clear enough to investigate.
ISO explains that it does not perform certification; independent certification bodies do. Confirm grading definitions, response deadlines and certification consequences with your selected body rather than relying on generic web summaries.
Ownership and escalation
The process owner should lead correction and cause analysis. The ISMS manager coordinates consistency and evidence. Risk owners assess exposure and interim controls. Top management becomes involved when the finding indicates system failure, material risk or resource constraints. Internal audit can independently evaluate effectiveness but should not approve its own remedial design.
For major findings, establish executive visibility without turning the response into blame. Rapid containment matters, but rushed closure evidence can create another failure at the next assessment.
Common response mistakes
Weak responses often:
- correct only the auditor’s sample;
- state “staff reminded” without analysing the process;
- rewrite a policy without testing operation;
- select a cause that cannot be supported by evidence;
- close an action before enough time has passed;
- omit affected locations or systems from extent review; or
- treat a minor grade as too insignificant to monitor.
Run the ISO 27001 readiness checker to identify requirement areas that may need deeper evidence review, while recognising that a self-assessment cannot grade certification findings.
Prepare before the next audit
Review previous internal, supplier and certification findings together. Look for recurring themes such as ownership, evidence retention, population completeness or ineffective follow-up. Sample closed actions and verify that operating evidence still exists.
The clause explainer can help process owners understand the management-system purpose behind a finding without reproducing ISO text.
The practical conclusion
The difference between major and minor is the significance of the demonstrated system failure, not the number of words in the report. The certification body makes the formal classification using its controlled rules and complete audit evidence.
Your best response is the same for either grade: confirm the criterion and facts, contain immediate risk, analyse cause and extent, implement proportionate action and retain evidence that the process now operates. That approach protects both certification and the actual effectiveness of the ISMS.
The subject perspective was informed by Advisera’s discussion of major and minor certification findings, with current audit and certification roles checked against ISO sources.