Clause 10.2 Nonconformity and corrective action
Clause 10.2 in ISO 27001:2022 (ISO/IEC 27001:2022). All ISO 27001:2022 controls held. Open ISO 27001:2022 on the standards site.
The control as we hold it
Nonconformity and corrective action. If a nonconformity arises, the organization must respond to it and, as applicable, act to control and correct it and handle what follows from it; evaluate whether action is needed to remove its causes so it does not recur or arise elsewhere, by reviewing it, finding its causes and checking whether similar nonconformities exist or could occur; implement any action needed; review how effective the corrective action was; and change the ISMS if necessary. Corrective actions must suit the effects of the nonconformities. Documented information must be available as evidence of the nature of nonconformities, the actions taken and the results of corrective action.
Reviewed and closest counterparts in the other frameworks
We hold no cross-framework row for Clause 10.2 yet. The reviewed pairs page lists the released pairs and their coverage.
What an auditor commonly asks for
General guidance for this control area (domain: Clause 10), in our words, not a statement of the standard and not binding on an assessor.
- A nonconformity and corrective action register with description, containment, cause analysis, actions and outcome
- Root cause analyses and checks for similar nonconformities elsewhere
- Effectiveness reviews of completed corrective actions
- Resulting ISMS changes where needed