Clause 10.2 of ISO 9001:2015 governs how organizations respond to nonconformities and implement corrective actions. Every nonconformity — whether from customer complaints, audit findings, process deviations, or supplier issues — is an opportunity for improvement. The 2015 revision eliminated the separate preventive action clause, integrating prevention into risk-based thinking throughout the standard.
What the Standard Requires
When a nonconformity occurs, the organization must react to the nonconformity (take action to control and correct it and deal with consequences), evaluate the need for action to eliminate the cause(s) so it does not recur or occur elsewhere (by reviewing and analyzing the nonconformity, determining the causes, and determining if similar nonconformities exist or could potentially occur), implement any action needed, review the effectiveness of corrective action taken, and update risks and opportunities if necessary and make changes to the QMS if necessary.
Best Practices
- Use nonconformity management software for consistent reporting and tracking
- Apply root cause analysis (5 Why, fishbone, fault tree) to determine true causes
- Focus on systemic causes, not individual blame
- Set deadlines for corrective actions and track completion
- Verify effectiveness of corrective actions after implementation
- Share lessons learned to prevent similar nonconformities elsewhere
- Analyze nonconformity trends to identify systemic issues
Common Pitfalls
- Stopping at the immediate cause rather than digging to root causes
- Not verifying corrective action effectiveness after implementation
- Failing to analyze trends across nonconformities to find systemic issues
- Treating corrective action as a paperwork exercise rather than a genuine improvement process
Frequently Asked Questions
What is the difference between correction and corrective action in ISO 9001?
A correction is an action to eliminate a detected nonconformity (fix the immediate problem). A corrective action is an action to eliminate the root cause of a nonconformity to prevent recurrence. ISO 9001:2015 requires both: immediate correction and root cause-based corrective action.
Does ISO 9001:2015 require preventive action?
ISO 9001:2015 eliminated the separate preventive action clause. Instead, the concept of prevention is addressed through risk-based thinking throughout the standard (Clause 6.1). Organizations address risks and opportunities proactively rather than through a standalone preventive action process.
What root cause analysis methods are recommended?
ISO 9001 does not prescribe specific methods. Common approaches include 5 Why analysis, fishbone (Ishikawa) diagrams, fault tree analysis, and Pareto analysis. The key is determining the actual root cause rather than stopping at the immediate cause.
Related Ecesis Solutions
Document Management
Version-controlled procedures and records
Audits & Inspections
Schedule, conduct, and track audit findings
Nonconformity Tracking
Report, investigate, and resolve nonconformities
Training Management
Track competence requirements and records
Change Management
Structured review of planned changes
Compliance Obligations
Track requirements and evaluation schedules
ISO 9001 Software for Corrective Action
Ecesis Incident Management standardizes nonconformity reporting, root cause investigation, and corrective action tracking through to effectiveness verification.


