A nonconformance is one of the most important events in any quality system — the moment something fails to meet a requirement. Handle it well, and it becomes a source of improvement; handle it badly, and it becomes a recall, an audit finding, or a warning letter. Yet many organizations still treat nonconformance as paperwork to be filed rather than a signal to be acted on, and miss where most nonconformances actually begin: at the point of measurement.
This guide explains what a nonconformance is, its types and causes, the management process and the nonconformance report (NCR), the standards that require it, and how to catch and prevent nonconformances before they reach the customer.
| What is a nonconformance?
A nonconformance is any failure of a product, process, service, or system to meet a specified requirement — an internal procedure, a customer specification, or a regulatory rule. It is closely related to a nonconformity (the ISO term), a deviation (a departure from an approved procedure), and a defect (a physical flaw), and often surfaces as an OOS (out-of-specification) result or an OOT (out-of-tolerance) instrument. Every nonconformance must be identified, documented, and controlled through a defined process. |
Nonconformance: Types, Causes, Process & How to Prevent It

What Is a Nonconformance?
A nonconformance (also written non-conformance, or nonconformity in ISO language) is a failure to meet a defined requirement. The requirement may be internal — a standard operating procedure or a product specification — or external, such as a regulatory rule. It is distinct from a few related terms worth keeping straight: a deviation is a planned or unplanned departure from an approved procedure; a defect is a physical or functional flaw in a product; and noncompliance is the broader failure to meet a legal or regulatory obligation. In testing and calibration contexts, nonconformances frequently appear as an out-of-specification (OOS) test result or an out-of-tolerance (OOT) instrument.
Types of Nonconformance
Nonconformances are classified by severity and risk, which determines how far they must be escalated and investigated:
| Type | Definition | Example |
| Minor | Low-risk, isolated issue with no impact on safety or compliance | A missing signature on a training record |
| Major | A significant failure signalling a process or system breakdown | A validated process step omitted in production |
| Critical | A severe failure risking safety, product integrity, or compliance | Nonconforming product released without approval |
Common Causes
- Human error: mistakes such as incorrect data entry, skipped steps, or mislabeling, often from inadequate training.
- Process deficiencies: inadequately defined or controlled processes, or missing in-process controls.
- Equipment and calibration: malfunctioning, unqualified, or poorly calibrated equipment — an uncalibrated scale producing inaccurate weights is a classic example.
- Material quality: incoming materials or components that fail to meet specification.
- Documentation gaps: missing, incomplete, or outdated records that break traceability.
- Suppliers and environment: suppliers not meeting specifications or quality agreements; and environmental excursions such as temperature or cleanroom failures.
The Nonconformance Management Process
A robust process follows a structured, risk-based sequence from detection to closure:
| Step | Purpose |
| 1. Identification & reporting | Detect and formally raise the nonconformance. |
| 2. Documentation | Record it in a controlled NCR with full detail. |
| 3. Containment & segregation | Quarantine the affected product to prevent further use. |
| 4. Initial assessment | Gauge severity, scope, and immediate risk. |
| 5. Investigation (RCA) | Find the root cause using tools like 5 Whys or Fishbone. |
| 6. Impact evaluation | Assess effect on product, batches, and compliance. |
| 7. Classification | Confirm minor, major, or critical. |
| 8. Disposition | Decide: reject, rework, regrade, or accept by concession. |
| 9. CAPA | Correct the root cause and prevent recurrence. |
| 10. Effectiveness check & closure | Verify the fix worked, then close with QA approval. |
The Nonconformance Report (NCR)
The nonconformance report is the controlled document at the centre of the process. A good NCR captures a clear factual description of the issue, a unique NCR number for traceability, the specific requirement or specification that was not met, containment actions taken, the impact (bracketing) assessment, the product disposition, the root cause, and the corrective and preventive actions. It serves as objective evidence during inspections and feeds directly into CAPA, trend analysis, and management review. Written well, it tells the complete story of an issue from detection to resolution.
The Measurement Root of Nonconformance
A significant portion of nonconformances arises at the measurement stage, where out-of-specification test results and out-of-tolerance instruments are critical issues. Uncalibrated or drifting instruments can produce unreliable outputs, leading to both false positives and negatives. Calibration serves as a key detection method; when an instrument is found out of tolerance, all measurements since its last calibration can be deemed questionable, necessitating a reverse-traceability assessment. Recognizing a calibration out-of-tolerance event as a formal nonconformance distinguishes a mature quality system from a reactive one.
Regulatory and Standards Requirements
| Standard / Regulation | Nonconformance requirement |
| ISO 9001:2015 | Clause 8.7 controls nonconforming outputs; Clause 10.2 requires documenting nonconformities and corrective action. |
| ISO 13485:2016 | Clause 8.3 requires control of nonconforming product; Clause 8.5 requires root-cause corrective action. |
| FDA 21 CFR Part 820 | US device quality system (now aligned with ISO 13485 under the FDA QMSR) — control of nonconforming product. |
| FDA 21 CFR Part 211.192 | cGMP for finished pharmaceuticals — thorough investigation of batch discrepancies and failures. |
| EU GMP / ICH Q10 | Deviations investigated to root cause with CAPA; nonconformance handled within the pharmaceutical quality system. |
The Cost of Conformance vs Nonconformance
Every quality budget balances two figures. The cost of conformance is proactive — quality planning, training, and appraisal activities such as calibration, audits, and release testing that prevent problems. The cost of nonconformance is reactive — the scrap, rework, and failed-batch investigations you pay internally, plus the recalls, regulatory action, and reputational damage you pay externally. Prevention is almost always cheaper than failure, which is why investment in calibration, validation, and robust quality processes pays back many times over.
How to Prevent Nonconformances
- Control measurement and process: keep instruments calibrated and traceable, and validate processes and equipment so measurements can be trusted.
- Strengthen people and procedures: maintain role-based training and controlled, current SOPs under change control.
- Manage inputs and environment: qualify suppliers, control incoming materials, and monitor environmental conditions.
- Learn from data: trend nonconformances, run internal audits, and use CAPA to fix root causes before they recur.
How Zeptac Helps
Zeptac is a SaaS platform for the Testing, Inspection, Calibration, Certification, and Validation industry, and it addresses nonconformance where much of it originates — the measurement layer:
- Out-of-tolerance workflow: CalTac flags out-of-tolerance instruments, drives the reverse-traceability impact assessment, and turns a calibration OOT into a controlled nonconformance rather than a lost note.
- OOS handling: TestTac manages out-of-specification results in testing laboratories with the investigation and records regulators expect.
- Validation control: ValTac keeps processes and systems validated, closing a major source of nonconformances before they occur.
- Compliant records: audit trails, electronic signatures, and ALCOA+ records aligned to 21 CFR Part 11 and EU GMP Annex 11 keep every NCR inspection-ready and linkable to CAPA.
The result is a quality system that catches nonconformances at the source and proves it handled them correctly.
Conclusion
A nonconformance is a signal, not a failure of character — the point where reality diverges from requirement. Classify it by risk, work it through a disciplined process from containment to CAPA, and document it in a clean NCR. But the organizations that stay ahead go one step further: they recognise that most nonconformances are born at the point of measurement, keep their instruments calibrated and their processes validated, and feed every out-of-tolerance and out-of-specification event into the same controlled system. Do that, and nonconformances stop surprising you and start improving you.
| Catch nonconformances where they start
Looking to digitize calibration, testing, and validation so you catch nonconformances at the source? Zeptac’s CalTac, TestTac, and ValTac platforms turn out-of-tolerance and out-of-specification events into controlled, audit-ready records linked to CAPA. Contact our team today to schedule a free demo. |
Frequently Asked Questions
Q1.What is a nonconformance?
A nonconformance is any failure of a product, process, service, or system to meet a specified requirement — whether an internal procedure, a customer specification, or a regulatory rule. It must be identified, documented, and controlled through a defined process to maintain quality and compliance.
Q2.What is the difference between a nonconformance and a deviation?
A nonconformance is a failure to meet a requirement, discovered after the fact. A deviation is a planned or unplanned departure from an approved procedure, common in GMP environments. Deviations are generally treated as a subset of nonconformances within the quality system.
Q3. What are the types of nonconformance?
Nonconformances are usually classified as minor (low-risk, isolated), major (a significant process or system failure), and critical (a severe issue risking safety, product integrity, or compliance). The classification determines the level of investigation and whether formal CAPA is required.
Q4. What is a nonconformance report (NCR)?
A nonconformance report is the controlled document that records, tracks, and resolves a nonconformance. It captures the description, the requirement not met, containment, impact, root cause, and corrective and preventive actions, and serves as objective evidence during audits.
Q5. What is the difference between nonconformance and CAPA?
A nonconformance is the event — something failed to meet a requirement. CAPA (Corrective and Preventive Action) is the response that eliminates the root cause and prevents recurrence. Not every minor nonconformance needs a full CAPA, but major and critical ones typically do.
Q6. What causes nonconformances?
Common causes include human error, process deficiencies, poorly calibrated or unqualified equipment, substandard materials, documentation gaps, supplier failures, and environmental excursions. Uncalibrated instruments are a frequent and often-overlooked cause because they corrupt the measurements that quality decisions rely on.
Q7. Which standards require nonconformance control?
ISO 9001:2015 (clauses 8.7 and 10.2), ISO 13485:2016 (clause 8.3), FDA 21 CFR Part 820 and Part 211.192, EU GMP, and ICH Q10 all require organizations to identify, control, investigate, and correct nonconformances.
