Preparing for an ISO 9001 audit: the 10 most common nonconformities and how to prevent them

By the time a lead auditor sits down for the closing meeting, most of the findings could have been written before the opening one. After enough Stage 2 and recertification audits, the same small set of nonconformities surfaces again and again, across sectors and across company sizes. They are rarely exotic. They cluster in a few clauses of ISO 9001:2015, and they tend to share one root cause: a system that was written to look correct rather than built to run. Once you know where auditors actually look, preparation stops being a fire drill and becomes a calm review of evidence you should already have.
Minor, major, and what the auditor is really testing
An auditor is not marking your manual. They are testing whether the system does what it says, by pulling a thread and following it: a customer complaint traced forward to its corrective action, or a shipped order traced back through inspection, calibration and operator competence. What they write up depends on what the thread reveals.
A minor nonconformity is an isolated lapse against a requirement of ISO 9001, something that slipped rather than something that is absent. A major is different in kind: a requirement missing altogether, a process that has broken down, or evidence that the management system cannot reliably deliver a conforming product or service. A major normally holds up the certification decision until your corrective action is accepted, while a minor comes with a defined window to respond. Opportunities for improvement are neither, though they are often next year's finding in a politer form. The point of preparation is not a clean three-day performance. It is a system that keeps its shape when someone pulls hard on a thread.
Where the findings cluster
The ten below account for the bulk of what gets written up in a typical surveillance or recertification audit. They fall into four groups: the management engine that is supposed to drive improvement, the sense of direction set by objectives and risk, the daily reality on the floor, and the records and product at the end of the line. The table maps each one to its clause and to the move that prevents it.
The management engine: where most majors are born
1. Corrective actions that treat symptoms, not causes (Clause 10.2)
This is the finding behind half of the others. The corrective-action register fills with entries like operator retrained or reminded the team, with no analysis of why the problem happened and no check that the fix held. ISO 9001 asks you to react to the nonconformity, then determine its cause, then act so it does not recur, then confirm the action worked. Prevent it by separating the immediate correction from the corrective action, recording a real root cause, and adding an effectiveness review a sensible interval later. An empty effectiveness column is what turns one minor into a repeat finding.
2. Internal audits run as a pre-assessment formality (Clause 9.2)
A single internal audit, carried out two weeks before the certification body arrives, by someone reviewing their own department, satisfies nobody. The expectation is a planned programme that covers every process and clause across the cycle, weighted by importance and past results, conducted by people independent of the work they examine. Prevent the finding by spreading audits through the year, rotating auditors so impartiality is visible, and treating internal findings with the same seriousness as external ones. An internal audit that never raises anything is itself a red flag.
3. Management reviews missing their required inputs (Clause 9.3)
Minutes that read the system is working well, no actions required rarely survive scrutiny. The review has a defined set of inputs, including the status of actions from previous reviews, changes in external and internal issues, performance trends, audit results, supplier performance, the adequacy of resources and the effectiveness of actions taken on risk. Prevent the finding by building the agenda directly from those inputs and recording outputs as decisions: what will change, who owns it, what resource is committed. A review that produces no decisions has not really happened.
Direction: objectives and risk that live only on paper
4. Quality objectives that cannot be measured or were never deployed (Clause 6.2)
Improve customer satisfaction is an intention, not an objective. The standard wants objectives that are measurable, monitored and supported by a plan: what will be done, with what resources, by whom, when, and how the result will be evaluated. The common gap is objectives set at the top that never reach the functions that influence them. Prevent it by giving every objective a metric and an owner, cascading them to the relevant departments, and reviewing progress at management review rather than rediscovering them the week before the audit.
5. A risk register disconnected from context (Clauses 4.1, 4.2, 6.1)
Many organisations complete the context analysis and the interested-parties list once, at implementation, then freeze them. The risks and opportunities register sits alongside, untouched, with no link to either the context or the actual process risks, and no evidence that the planned actions were taken or evaluated. Prevent the finding by revisiting context when something real changes, a new market, a new regulation, a major customer, and by tracing each significant risk through to an action and a result. Risk-based thinking is judged by what you did about the risk, not by the existence of a spreadsheet.
The floor: people, equipment, and the supply base
6. Measuring equipment without calibration or traceability (Clause 7.1.5)
On the shop floor the auditor will pick a gauge and ask for its calibration status. Common findings are expired calibration, no traceability to a national or international standard, no identification of calibration state, and, most seriously, no action taken when an instrument is found out of tolerance. The standard expects you to assess the validity of earlier measurements in that case. Prevent the finding with a calibration schedule, clear status labelling, retained certificates that show traceability, and a defined response when equipment fails, including how affected product is reviewed.
7. Competence defined, awareness missing (Clauses 7.2, 7.3)
Competence files can look complete while the people doing the work cannot say what the quality policy means for them or what happens if they ignore a procedure. Clause 7.2 wants competence based on education, training or experience for roles that affect performance, with the effectiveness of any training evaluated. Clause 7.3 wants genuine awareness on the floor. Prevent the finding by defining competence per role, evidencing it, and making awareness real through short toolbox briefings rather than a signed attendance sheet nobody remembers.
8. Suppliers approved once and never re-evaluated (Clause 8.4)
External providers shape your output, so auditors look hard at how you control them. The usual gaps are an approved-supplier list with no criteria behind it, no record of monitoring performance, no re-evaluation, and outsourced processes treated as if they were outside the system. Prevent the finding by setting selection and evaluation criteria, monitoring delivery and quality against them, re-evaluating on a defined cycle, and controlling any outsourced process that affects conformity as tightly as if it ran in-house.
Records and product: the lapses that are easiest to fix
9. Obsolete documents in use at the point of work (Clause 7.5)
An out-of-date work instruction taped to a machine, an uncontrolled copy in a drawer, a form with no revision number: these are the quickest findings an auditor can write and the easiest to prevent. The standard expects documented information to be controlled, current and available where the work is done. Prevent the finding with version control, removal of superseded copies from the point of use, and a quick check that what people actually follow matches what the system says they should.
10. Nonconforming output and broken traceability (Clauses 8.7, 8.5.2)
When something goes wrong with product, the auditor wants to see that it was identified, segregated where needed, and dealt with by correction, concession or scrapping, with the decision recorded. Where traceability is required, they want to follow a batch in both directions. Common findings are nonconforming material left unmarked next to good stock, concessions granted without record, and traceability that breaks at one handover. Prevent it by defining how nonconforming output is identified and controlled, recording every disposition, and testing your traceability before the auditor does.
The corrective-action pattern that actually closes a finding
Almost every item above is closed the same way, and getting that method right is the single highest-value thing you can prepare. Start with containment, the immediate correction that stops the bleeding. Then find the real cause, using a simple discipline such as five whys or a cause-and-effect diagram, and resist stopping at human error, which is usually a symptom of a weak process. Act on the cause, not the symptom. After enough time has passed for the change to be tested in practice, verify that it worked, and record that verification. Finally, ask whether the same cause could be producing problems elsewhere and extend the action if it can. A corrective-action register whose effectiveness column is actually filled in is the clearest signal an auditor gets that the system is alive.
Turning preparation into a habit
The organisations that find audits unremarkable are not the ones with the thickest manuals. They are the ones that run internal audits and management review on a real cycle, keep the corrective-action loop honest, and treat the certificate as the byproduct of a working system rather than the prize. If you are building or rebuilding that system, the ISO 9001 certification service page is the place to start. If you already run more than one standard, the same ten findings tend to repeat across environmental and health-and-safety audits too, which is why many firms move to integrated management system certification and audit them together rather than three times over.
Picked for You
Related Articles

The IVDR transition: new duties for in-vitro diagnostic devices
Read More →
Carbon footprint: organisational (ISO 14064) vs product (ISO 14067)
Read More →