Audit Findings: From the Finding to Evidence That It Worked
The finding is written, the action is assigned, the audit report has gone out. Fourteen months later the same observation appears in the next report — new date, same process, same cause statement, and the original action has carried the status “closed” for a year.
That is rarely a motivation problem. It is an evidence problem. The standard splits the obligations attached to a single finding across three separate clauses, and most organizations implement those three clauses in three separate systems.
Why findings stall — the structural reason
ISO 9001:2015 requires, in 9.2.2 e), that appropriate correction and corrective action be taken without undue delay [1]. What the standard does not govern — and cannot govern — is which record that happens in. The gap opens exactly there.
The usual sequence: the finding is born in the audit report, the action in the closing-meeting minutes or an email, implementation in the department’s own task list. The effectiveness check happens, if at all, during the next audit, run by someone who never saw the original yardstick. Four records, no link between them, four opportunities for the chain to break.
The economics are worse than they look. The American Society for Quality sorts quality-related costs into four categories: prevention, appraisal, internal failure and external failure [2]. An audit is appraisal cost — money already spent before the first finding is written. A finding that stalls makes that spend worthless and lets the defect migrate into the two expensive categories, while the audit effort is incurred again next year regardless.
Assessment: A percentage of sales revenue is widely quoted for this migration. It is not sourceable — ASQ’s own cost-of-quality page carries no percentage of sales at all, and the ranges circulating in the literature contradict one another. We publish no figure here on purpose. An invented number in a management report costs more credibility on the first follow-up question than it ever bought.
What the standard actually requires you to retain
The audit-relevant question is not whether you log findings. It is which records you can produce at the end. ISO 9001:2015 distributes that duty across three clauses that apply independently of each other [1]:
| Clause | What it requires | Where it breaks in practice |
|---|---|---|
| 9.2.2 f) | Retain evidence of the implementation of the audit programme and of the audit results | Only the audit report is produced. Evidence that the planned programme was actually carried out is missing — these are two things, not one |
| 10.2.1 d) | Review the effectiveness of any corrective action taken (an action requirement, not a retention requirement) | Status jumps from “implemented” to “closed” without anyone having named a criterion against which effectiveness could be measured |
| 10.2.2 a) | Retain evidence of the nature of the nonconformity and any subsequent actions taken | The finding is documented, the action lives in a different tool — the link exists only in one person’s memory |
| 10.2.2 b) | Retain evidence of the results of any corrective action | There is a closure date but no result. A date is not a result |
| 8.7.2 | Retain evidence about the nonconforming output itself: description, actions taken, concessions obtained, and the authority that decided | Treated as covered because a corrective action is already running — that is a different obligation |
The last row is where the wheat separates from the chaff. Clause 8.7 and clause 10.2 are not two views of one process. They are two obligations. Clause 8.7 sits in clause 8 (Operation): it controls the nonconforming output so it is not used or delivered unintentionally, and it decides that output’s fate — correction, segregation, containment, return, informing the customer, or acceptance under concession. Nowhere does 8.7 require cause analysis. Clause 10.2 sits in clause 10 (Improvement): it acts on the cause and demands the effectiveness review.
So a batch held at incoming inspection typically triggers both. Clause 8.7 decides what happens to the batch and records who authorized the concession; clause 10.2 asks why the inspection characteristics were never agreed with the supplier. Produce only one of the two records and the other requirement is unmet — even when the matter is, practically speaking, resolved.
One note on citation form, because it surfaces in audit discussions constantly: 9.2.1, 9.2.2, 10.2.1, 10.2.2, 8.7.1 and 8.7.2 carry no printed headings. Anyone quoting “9.2.2 Audit programme” is quoting a heading that does not exist.
Six stages that hold a finding together
Those three clauses imply a sequence that carries every finding from observation to demonstrated closure:
- Capture the finding. Observation, the requirement it fails against, and the evidence — three fields, not one. Without the clause or document reference, a finding is an opinion.
- Control the output (8.7). Where a specific product, batch or service is affected, its disposition is decided first and the deciding authority is recorded. This stage runs in parallel, not afterwards.
- Evaluate and classify. Severity, processes affected, whether it has been seen before. This is where you decide whether cause analysis is proportionate at all — 10.2.1 b) requires evaluating the need to eliminate causes, not automatically running the analysis.
- Determine the cause. Only now can correction be separated from corrective action. For chain depth, the 5-Why method with worked examples suits simple events, and the 8D report to VDA Band 8D suits customer complaints.
- Implement, and set the effectiveness yardstick now. The yardstick belongs here, not at the end: an observable quantity, a window, a sample. For example, the next thirty batch releases with no missing inspection characteristic, assessed three months after implementation.
- Review effectiveness and close (10.2.1 d), 10.2.2 b)). The review runs against the yardstick set in stage 5. That result — and only that result — is the evidence 10.2.2 b) asks for.
The ordering is not cosmetic. If the yardstick is chosen at closure, you will always find one the action looks effective against.
Major and minor nonconformity: where the terms really come from
Here a common assumption needs correcting. Major and minor nonconformity are widely treated as certification-body house style — auditor discretion, in other words. They are not.
Both are defined terms in ISO/IEC 17021-1:2015, the standard for bodies that audit and certify management systems. Clause 3.12 defines a major nonconformity as one that “affects the capability of the management system to achieve the intended results”. Clause 3.13 defines a minor nonconformity as its mirror image: one that does not affect that capability [3].
That gives you a nameable criterion — arguable on the merits, not on taste. Two consequences follow.
First, a note to 3.12 records that several minor nonconformities against the same requirement can demonstrate a systemic failure and may therefore together constitute a major one [3]. Carrying the same point as a minor across three cycles is not harmless residual risk; it is assembling the argument for an upgrade on the auditor’s behalf. Which is exactly why a history kept per requirement — rather than per audit year — is the most useful report in findings management.
Second, the definition governs certification audits. For your internal audit you may set your own classification; ISO 9001 prescribes none. But if you use the words major and minor, use them with this definition, or internal and external assessments will talk past each other. How the grading then plays out — major nonconformities closed before the certification decision, minor ones requiring a reviewed corrective action plan — is covered in the article on the external audit process and preparation.
What the regulated world shows
How stubborn this gap is can be measured in one domain where a regulator logs every inspection: the US Food and Drug Administration publishes its inspection observations as a dataset per fiscal year.
Across inspections in FDA fiscal year 2025 — those ending between 1 October 2024 and 30 September 2025 — the most-cited device observation was 21 CFR 820.100(a), CAPA procedures not adequately established: rank 1, with 279 citations. Together with 820.100(b), the documentation requirement, the two accounted for 342 citations, or 12.9 percent of all 2,660 device citations that year. Fiscal year 2024 shows the same picture at rank 1 with 254 citations, so this is not a single-year artefact [4].
The provision itself no longer exists in that form. Through the final rule Medical Devices; Quality System Regulation Amendments (89 FR 7496, published 2 February 2024, effective 2 February 2026), the FDA rebuilt Part 820 into the Quality Management System Regulation: subparts C through O are reserved, § 820.100 is gone, § 820.7(b) incorporates ISO 13485:2016 by reference, and § 820.10(a) requires a documented quality management system meeting that standard’s applicable requirements [5]. The figures above therefore describe a period lying entirely before that date, under the regulation as it then stood.
What is worth noticing is what did not happen: the requirement did not disappear, it moved into a standard — ISO 13485 handles corrective and preventive action in 8.5.2 and 8.5.3. That is this article’s own point in miniature. The discipline decides the outcome, not the drawer it is filed in.
Two caveats are mandatory. The FDA states that these spreadsheets are not a comprehensive listing of all inspectional observations and that not every FDA-483 is generated by the systems behind them [4]. More importantly: this is US medical device regulation, not ISO 9001. Nothing follows from this data for your ISO 9001 certification, and it says nothing about certification audits.
What it does show is a cross-industry pattern. Where a regulator inspects systematically over many years, the weak point is not detecting problems — it is the defined, demonstrable procedure behind closing them. ISO 9001 encodes that same shift, from detecting to demonstrating, in 10.2.2, just without the enforcement teeth. The origin of the term CAPA and the rebuild of the US regulation are covered in the article on the CAPA process and what clause 10.2 requires.
The link into management review (9.3.2)
The findings lifecycle does not end when the last action closes. It ends one level up. ISO 9001:2015 lists the inputs to management review in 9.3.2, and 9.3.2 c) explicitly includes audit results as well as nonconformities and corrective actions [1]. That is the normative anchor for findings reaching top management — as an input, not as an appendix.
A second common claim falls at the same spot. ISO 9001:2015 does not require an annual management review. Clause 9.3.1 says at planned intervals, and the words annual and yearly do not occur anywhere in the standard’s text [1]. The interval is your decision, and you have to be able to justify it. Nothing more.
In practice, management review needs three numbers out of findings management that no status list yields on its own: how many findings closed with a documented effectiveness review, how many are open past their due date, and which requirements recur. The third is the only one that says anything about the system rather than about the quality department’s workload. How that analysis feeds back into planning is covered in the guide to audit programme planning; for capturing findings during the audit itself, the internal audit checklist for ISO 9001 is the more practical starting point. Which fields make that analysis possible in the first place is covered in from audit to management review, and what clause 9.3 requires as inputs and outputs in management review under clause 9.3.
Looking ahead, the coming edition shifts the emphasis in documented information further towards evidence of implementation and effectiveness, which makes the break described here more exposed, not less — see the overview of the changes in ISO 9001:2026.
What a tool has to do here
qportal carries the finding, the action and the effectiveness review as one record with a status history rather than as separate entries in separate lists — ownership and due date attached to the finding itself, and a history per requirement that makes recurring points visible. Tracking actions through to demonstrated closure is described on the page for actions and CAPA, and the full path of a finding in the findings lifecycle documentation.
Conclusion
The weakest point in findings management is neither the capture nor the action. It is the moment a finding changes record.
As long as the 8.7 disposition, the cause analysis, the action and the effectiveness review live in four tools, the evidence required by 10.2.2 is a reconstruction job — somebody assembles it by hand before the audit, which is exactly why it only comes into existence there. Hold them in one record and the evidence is a by-product of the work.
If you change one thing, change this: set the effectiveness criterion when you decide the action, not when you close it. Everything else follows from that.
Sources
- ISO 9001:2015, Quality management systems — Requirements. International Organization for Standardization, Geneva; consulted in the bilingual edition DIN EN ISO 9001:2015-11, Beuth Verlag, Berlin. (Clauses 8.7.1, 8.7.2, 9.2.2, 9.3.1, 9.3.2, 10.2.1, 10.2.2)
- American Society for Quality (ASQ): What is Cost of Quality (COQ)? https://asq.org/quality-resources/cost-of-quality (accessed 2026-08-27)
- ISO/IEC 17021-1:2015, Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1: Requirements. Edition 1, 2015-06, ISO/CASCO. Clauses 3.12 and 3.13, freely readable in the ISO Online Browsing Platform. https://www.iso.org/obp/ui/en/#!iso:std:iso-iec:17021:-1:ed-1:v1:en (accessed 2026-08-27)
- U.S. Food and Drug Administration, Office of Inspections and Investigations: Inspection Observations. Content current as of 2025-12-16, “FY 2025 Excel File”, Devices worksheet; comparison figures from the FY 2024 file. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/inspection-references/inspection-observations (accessed 2026-08-27)
- U.S. Food and Drug Administration: Medical Devices; Quality System Regulation Amendments. Final rule, 89 FR 7496, published 2024-02-02, effective 2026-02-02. Current text of 21 CFR Part 820 (Quality Management System Regulation), issue of 2026-08-25, in the Electronic Code of Federal Regulations. https://www.ecfr.gov/current/title-21/chapter-I/subchapter-H/part-820 (accessed 2026-08-27)
Consultancy, certification-body and content-marketing pages are not cited. Normative text is copyrighted; requirements are paraphrased here with a clause reference. Where this text goes beyond the sourced evidence, it is marked as an assessment.
Frequently asked questions
- What records does ISO 9001 require for audit findings?
- Two retention obligations interlock. Clause 9.2.2 f) requires evidence of the implementation of the audit programme and of the audit results — both, not just the audit report. Clause 10.2.2 separately requires evidence of the nature of the nonconformity and any subsequent actions taken, plus the results of any corrective action. A list of logged findings satisfies neither one completely.
- What is the difference between clause 8.7 and clause 10.2?
- Clause 8.7 controls the nonconforming output itself: segregate it, contain it, return it, inform the customer, or accept it under concession. It requires no cause analysis. Clause 10.2 acts on the cause and requires a review of effectiveness. One event usually triggers both, and 8.7.2 and 10.2.2 are two independent retention obligations, not two views of the same record.
- Who decides whether a nonconformity is major or minor?
- Not the certification body by house style. Major and minor nonconformity are defined terms in ISO/IEC 17021-1:2015, clauses 3.12 and 3.13. The stated criterion is whether the nonconformity affects the capability of the management system to achieve the intended results. Several minor nonconformities against the same requirement can demonstrate a systemic failure and together constitute a major one.
- Does every corrective action need an effectiveness review?
- Yes. ISO 9001:2015 clause 10.2.1 d) requires a review of the effectiveness of any corrective action taken. The standard names no deadline, no method and no sample size — the organization sets those. The review only becomes demonstrable if the effectiveness criterion is fixed when the action is decided, rather than looked for when the action is closed.
- Do audit findings have to go into management review?
- Yes. ISO 9001:2015 clause 9.3.2 c) lists audit results and nonconformities and corrective actions explicitly among the inputs to management review. The standard does not require an annual review: clause 9.3.1 says at planned intervals, and the words annual and yearly appear nowhere in the standard's text.