What will you find in this article?
Most organizations know how to document nonconformities. The problem arises later: as the list grows, everything seems urgent, and no one is sure where to start. A one-time deviation in a document record ends up competing for the same resources as a nonconformity involving legal or systemic risk. And when everything is a priority, nothing really is.
This article explains how to prioritize nonconformities so that efforts are focused where there is a real risk: classify them properly, apply the correct risk-based prioritization, and measure the system’s effectiveness using a few useful indicators.
What Is a Nonconformity (and Why the Name Matters Less Than the Criteria)
Under the ISO standards—9001 for quality, 14001 for the environment, and 45001 for occupational health and safety—a nonconformity is a failure to meet a requirement. That requirement may stem from the standard itself, applicable legislation, a customer, or the organization’s internal procedures.

It’s important to clarify the terminology, because it’s a constant source of confusion. Depending on the industry and each company’s culture, the same thing is referred to in different ways:
- Nonconformity: the formal term used in ISO standards.
- Anomaly: Common in industrial and operational environments.
- Deviation: Common in pharmaceutical quality control and process control.
- Finding: typical of audit terminology.
These are labels for the same underlying concept: something isn’t meeting expectations, and it needs to be addressed. What matters isn’t what you call it, but rather that you have a consistent set of criteria for classifying, prioritizing, and resolving it. A system where each department uses its own terminology and its own scale ultimately leads to fragmentation: data that cannot be aggregated or compared.

Types of Nonconformity
Before prioritizing, you must classify. Classification by type describes the intrinsic severity of the noncompliance and is the most widely used method:
- Major nonconformity: a serious nonconformity that affects the management system’s ability to achieve its objective. It typically involves legal risk, the complete absence of a required process, or a recurring systemic failure.
- Minor nonconformity: an isolated instance of noncompliance that does not compromise the system as a whole, but that must be corrected.
- Note: A situation that does not yet constitute a violation, but could lead to one if it is not addressed.
- Opportunity for improvement: There is no non-compliance; there is room to do things better.
Distinguishing between these four levels alone helps you avoid the most common mistake: devoting the same amount of effort to an opportunity for improvement as to a more serious nonconformity. This is the first step if you’re wondering how to prioritize nonconformities effectively.

Classify according to three categories: origin, type, and cause
A robust classification goes beyond just the type. It spans three dimensions, and each one answers a different question:
1. By origin — Where did it come from? Internal audit, external audit, internal operations, regulatory inspection. Standardizing and limiting the source categories makes it possible to answer management questions such as, “How many nonconformities do external audits detect compared to those we detect ourselves?” That ratio, on its own, says a lot about the maturity of a management system.
2. Depending on the type—how serious is it? The four levels from the previous section (major, minor, observation, opportunity for improvement).
3. Depending on the cause—why did it happen? This is the aspect that is most often overlooked and yet provides the greatest value. It requires a closed catalog of root cause types—lack of operational control, human error, process failure, training deficiency, etc.—rather than a free-text field. Free-form text leads to inconsistency: a thousand ways to write the same thing and no data that can be aggregated. A closed list allows you to identify patterns: “40% of our nonconformities share the same root cause” is an actionable finding; “we have 300 nonconformities” is not.

How to Prioritize Nonconformities: By Risk, Not by Order of Receipt
This is where the leap in maturity comes in. Logging and categorizing issues is necessary, but not enough. Without a prioritization criteria, the team addresses issues based on how long they’ve been open or who’s shouting the loudest, completely overlooking prioritization by risk.
A simple and justifiable method is to cross-reference two of the above axes to determine a priority level:
Type of nonconformity × Cause = Priority Level
You assign a score to the severity of the issue and another to the criticality of the cause; the product of the two gives you a value that corresponds to one of four levels:
| Level | What does it mean? | Example |
|---|---|---|
| Review | High legal or systemic risk | Regulatory noncompliance with legal exposure |
| Sign Up | Significant structural risk | A procedural error that could happen again |
| Media | Controllable impact | Deviation that can be managed through standard operations |
| Cancel | One-time deviation | Isolated incident with no spread |
A concrete example: a major nonconformity whose root cause is a lack of operational control receives a high score on both axes. The result places it at the critical level, ahead of any observation or one-time deviation, no matter how old the latter may be. The criterion is no longer subjective but becomes traceable: anyone can understand why that nonconformity takes precedence.
The advantage of such a method is not mathematical accuracy—scores are merely conventions—but rather that it makes explicit and consistent a judgment that was previously implicit and variable. Everyone uses the same standard for risk prioritization.

What to Measure: Nonconformity KPIs That Provide Insight
Once they have been categorized and prioritized, just a few KPIs are enough to determine whether the system is working. It’s better to have three non-compliant KPIs that are actually monitored than fifteen that are ignored:
- Total open risk: the sum of the prioritization scores for all open nonconformities. It provides an aggregate snapshot of the organization’s exposure at a given point in time. If it rises, something is building up.
- Percentage of systemic nonconformities: what proportion is due to root causes (as opposed to isolated incidents). A high percentage indicates that you’re putting out fires instead of addressing the root cause.
- Open nonconformities past their deadline: the number that have exceeded the committed closure date. This is the most direct indicator of the system’s actual effectiveness; it measures whether action plans are actually implemented or merely documented.
Common Mistakes to Avoid
- Treat the record as the goal. Recording is not the same as managing. Recording is the starting point, not the goal.
- Free-text cause fields. They prevent you from adding data and identifying patterns. Catalog.
- Prioritize by seniority. The oldest nonconformity is not necessarily the most important one.
- Do not close the cycle. A nonconformity without an action plan that specifies who is responsible and by when is just a note—not a follow-up action.
- Don’t overload the dashboard. A few well-chosen and regularly reviewed KPIs are worth more than a dashboard that no one looks at.
In a nutshell
Managing nonconformities isn’t about logging them faster or closing them out before an audit. It’s about having a clear approach: classifying them by origin, type, and cause; prioritizing them based on actual risk using a rule that everyone applies consistently; and measuring effectiveness with a few metrics that are actually reviewed. With this approach, an overwhelming list becomes a sequence of justifiable decisions, and resources are directed where they matter most.
Frequently Asked Questions About Prioritizing Nonconformities
What is the difference between nonconformity, anomaly, and deviation?
These are terms for the same concept: failure to meet a requirement. “Nonconformity” is the formal term used in ISO standards; “anomaly” is commonly used in industrial settings; and “deviation” is used in pharmaceutical quality and process control. The important thing is to apply a consistent classification criterion, regardless of the label each organization uses.
What is the difference between a major nonconformity and a minor one?
A major nonconformity compromises the management system’s ability to achieve its objective—it typically involves legal risk, the absence of a required process, or a recurring systemic failure. A minor nonconformity is an isolated nonconformity that must be corrected but does not jeopardize the system as a whole.
How should nonconformities be prioritized?
One objective method involves cross-referencing the severity of the issue with the criticality of the root cause to establish a risk-based prioritization. This way , the order of action depends on the actual risk rather than on how long the issue has existed or on individual perceptions.
Which non-conformance KPIs are useful for measuring performance?
Three useful and sufficient metrics: the total risk of open nonconformities (based on their combined priority scores), the percentage of nonconformities with systemic causes, and the number of nonconformities closed past the deadline.








