Risk Management

Corrective Action and Nonconformity Policy

A corrective action and nonconformity policy template defining how nonconformities are recorded, root-caused, corrected and verified, aligned to ISO 27001, SOC 2.

14-20 pages|Updated 2026-09-12|2 frameworks
Aligned to:
ISO 27001
SOC 2

What's Included

1. Purpose & Scope

Objective and what counts as a nonconformity.

Policy ObjectiveDefinitionsRoles and Responsibilities

2. Identification & Recording

Capturing the issue.

Sources of NonconformityRecording RequirementsInitial Classification

3. Immediate Correction

Containing the effect before fixing the cause.

ContainmentImpact AssessmentInterim Controls

4. Root Cause Analysis

Fixing the cause rather than the symptom.

Analysis MethodContributing FactorsSystemic Review

5. Corrective Action

The change that prevents recurrence.

Action DefinitionOwnership and DeadlineResource Approval

6. Verification & Closure

Proof it worked.

Effectiveness VerificationClosure CriteriaOverdue Escalation

7. Records & Review

Evidence and cadence.

Nonconformity RegisterTrend AnalysisAnnual Policy Review

Frequently Asked Questions

What should a corrective action and nonconformity policy include?

A comprehensive corrective action and nonconformity policy should include purpose & scope, identification & recording, immediate correction, root cause analysis, and more. This template covers 7 key sections aligned to ISO 27001, SOC 2 requirements.

Which frameworks require a risk management policy?

Major frameworks requiring risk management policies include ISO 27001, SOC 2. This template maps directly to their control requirements, making it easier to demonstrate compliance across multiple standards.

How often should a corrective action and nonconformity policy be reviewed?

Best practice is to review your corrective action and nonconformity policy at least annually, or whenever significant changes occur in your organisation, technology environment, or regulatory landscape. Most frameworks including ISO 27001 and NIST CSF require documented policy review cycles.

Build Your Compliance Programme

Pair this policy template with our compliance platform to map controls across 686+ frameworks, run self-assessments, and get AI-powered compliance advisory.

Get Started Free →

Free forever — no credit card required