ISO 27001
Internal Audit
Finding Classification

Major vs Minor Nonconformity: How to Classify ISO 27001 Internal Audit Findings

Learn how to classify ISO 27001 internal audit findings as major nonconformities, minor nonconformities, observations, evidence gaps, management attention items, or opportunities for improvement before certification.

Quick Answer

What is the difference between a major and minor nonconformity in ISO 27001?

An ISO 27001 major nonconformity usually shows a serious failure, missing required process, systemic breakdown, repeated issue, or high-risk gap that may affect ISMS effectiveness.

An ISO 27001 minor nonconformity usually shows a limited gap where a requirement is partially implemented but not fully met.

The audit test is simple: classify findings based on requirement, evidence, risk, scope, repeat nature, control impact, and certification readiness.

Not Every Audit Finding Is Equal

Not every ISO 27001 internal audit finding is equal.

Some findings show a serious breakdown in the ISMS.

Some findings show a limited gap in one control.

Some findings are evidence weaknesses.

Some findings are early warning signs or improvement opportunities.

Practical rule: finding classification turns audit results into priorities.

Why Classification Matters

If every finding is treated the same, leadership cannot prioritize.

A missing approval date is not the same as no internal audit program.

A single late access review is not the same as no access review process.

A weak vendor review note is not the same as no supplier risk management process.

Classification helps teams decide what needs urgent action, root cause analysis, leadership involvement, corrective action, or simple improvement.

The strongest classification question is not “Is this bad?” It is “How serious is the gap, how much of the ISMS does it affect, what risk does it create, and what action is needed?”

Quick Classification Snapshot

Finding Type What It Usually Means Typical Action
Major Nonconformity Serious failure, missing process, systemic issue, high-risk breakdown, or repeat failure. Immediate correction, root cause analysis, corrective action, leadership oversight.
Minor Nonconformity Requirement is partially met, but a limited gap exists. Correct the issue, address root cause, verify closure.
Observation Potential weakness or early warning sign. Monitor, assess risk, improve before it becomes a finding.
Opportunity for Improvement Control works, but can be improved. Optional improvement or planned enhancement.
Evidence Gap Evidence is missing, incomplete, outdated, or not traceable. Provide evidence, improve evidence process, verify.
Management Attention Item Issue needs leadership decision, resource support, risk acceptance, or escalation. Leadership review and documented decision.

What Is a Nonconformity?

A nonconformity means a requirement has not been met.

That requirement may come from ISO 27001, the Statement of Applicability, a policy, a procedure, a contract, or a previous corrective action.

ISO 27001 clause.
Annex A control decision.
Statement of Applicability.
Risk treatment plan.
Approved policy or procedure.
Legal or contractual obligation.

Practical rule: do not call a finding a nonconformity unless there is a clear requirement that was not met.

Major vs Minor Nonconformity: The Simple Difference

Major Nonconformity

A major nonconformity usually means the ISMS has a serious problem.

It may show a missing process, systemic failure, high-risk control breakdown, repeated issue, or management system weakness.

Minor Nonconformity

A minor nonconformity usually means the requirement is partially implemented.

The process exists, but one part is missing, inconsistent, outdated, incomplete, or weakly evidenced.

Practical rule: major findings question whether the system is working. Minor findings show the system needs correction.

When to Classify a Finding as Major

A finding may be major when it threatens ISMS effectiveness, certification readiness, or leadership confidence.

Required process missing.
No internal audit program, risk assessment method, SoA, or management review exists.
Process exists only on paper.
The plan exists, but roles, logs, tests, and owner knowledge are missing.
Gap is systemic.
The issue affects multiple systems, teams, periods, or controls.
Gap creates high risk.
Privileged access, terminated users, sensitive data, or critical vendors are affected.
Issue is repeated.
The same issue was closed before but returned because root cause was not fixed.
Leadership oversight is missing.
Risk acceptance, management review, or escalation is informal or absent.

Major Nonconformity Examples

Example Why It May Be Major
No internal audit program exists for the current audit cycle. Internal audit is a core ISMS performance evaluation activity.
Risk register has not been updated after major cloud and AI changes. Control selection, treatment planning, and SoA decisions may be unreliable.
No management review has been performed. Leadership oversight and continual improvement cannot be demonstrated.
No access reviews exist for critical systems or privileged accounts. This suggests a systemic access governance failure.
Corrective actions were closed without root cause, evidence, or verification. The improvement process may not be operating effectively.

When to Classify a Finding as Minor

A finding may be minor when the process exists and generally works, but a limited gap is found.

One sample failed, but the process mostly works.
Evidence is incomplete for one area.
A review was late but completed.
Approval exists, but version detail is unclear.
One vendor review lacks notes.
One corrective action lacks complete closure evidence.

Practical rule: a minor nonconformity means the organization needs correction, but the broader process still exists.

Minor Nonconformity Examples

Example Why It May Be Minor
One access review missed vendor accounts. The access review process exists, but scope needs correction.
Approval evidence is missing for one current policy version. The document control process exists, but the approval trail is incomplete.
Vendor review notes are incomplete for two records. The vendor process exists, but evidence quality is weak.
Restore test was completed but not fully documented. The activity occurred, but the evidence does not fully prove the result.
Management review minutes are missing one action owner. Management review exists, but action tracking needs improvement.

Need Help Classifying ISO 27001 Findings?

Canadian Cyber helps organizations classify ISO 27001 internal audit findings correctly and turn them into clear corrective actions.

We help teams separate major nonconformities, minor nonconformities, observations, evidence gaps, OFIs, and management attention items.

Observation vs Nonconformity

Not every concern should become a nonconformity.

An observation is usually an issue that may create risk later but does not clearly show that a requirement has failed.

Vendor review notes vary between departments, but required fields are present.
The access review process works, but the template could separate privileged users more clearly.
The policy review process is working, but reminders are manual.
The evidence library is usable, but metadata could improve audit readiness.

Opportunity for Improvement vs Nonconformity

An opportunity for improvement means the control is working.

However, there is a better way to manage it.

Automate policy review reminders in SharePoint.
Create a client-ready evidence view.
Add a risk heatmap to leadership reporting.
Add metadata for ISO clause, Annex A control, owner, and review date.

Practical rule: an OFI should not sound like a hidden nonconformity. It should be a useful improvement suggestion.

Evidence Gap vs Nonconformity

An evidence gap means the auditor cannot fully verify the control.

Sometimes an evidence gap becomes a nonconformity. Sometimes it remains an evidence request.

Evidence Gap How to Classify It
Missing approval date. Evidence gap or minor NC, depending on whether approval can be proven.
Broken evidence link. Usually evidence gap if the evidence exists elsewhere.
Old screenshot. Evidence gap if current evidence is available; NC if the control cannot be proven.
No review period listed. Evidence gap or minor NC, depending on the requirement.

Classification Decision Tree

Use this decision path when classifying ISO 27001 internal audit findings.

  1. Is there a clear requirement that was not met? If no, consider observation or OFI.
  2. Is the required process missing entirely? If yes, likely major.
  3. Is the issue systemic across controls, teams, systems, or periods? If yes, likely major.
  4. Does the issue create high risk or seriously affect certification readiness? If yes, consider major or high-risk minor.
  5. Is this a repeat finding that was not effectively corrected? If yes, consider major or repeat minor.
  6. Is the process mostly working with a limited gap? If yes, likely minor.
  7. Is the issue only a suggestion for improvement? If yes, classify as OFI.

Major vs Minor Classification Matrix

Factor Minor Nonconformity Major Nonconformity
Process exists. Yes, but incomplete. No, missing, or not operating.
Scope. Limited. Broad or systemic.
Risk level. Low to medium, sometimes high but contained. High or serious.
Evidence. Partial evidence exists. Evidence missing or unreliable across the area.
Certification impact. Manageable with correction. May threaten readiness.
Leadership involvement. May not need immediate leadership action. Usually needs leadership attention.

How to Classify Repeat Findings

Repeat findings need special attention.

A repeat minor may become major if it shows that the corrective action process is not effective.

Repeat Finding Questions

  • Was this issue found before?
  • Was it marked closed?
  • Was root cause addressed?
  • Was closure evidence verified?
  • Did the same issue appear again?
  • Was leadership aware?

How to Classify AI-Related Internal Audit Findings

AI governance is becoming more relevant in ISO 27001 internal audits.

AI tools can affect data handling, vendor risk, acceptable use, source code, support workflows, and incident response.

Possible Minor Finding

AI tools are inventoried, but one department has not documented approved use cases.

Possible Major Finding

AI tools are widely used with customer data, no approved use policy exists, no vendor review was performed, no risk entry exists, and leadership has not approved use boundaries.

Classification Examples by Audit Area

Area Minor Example Major Example
Vendor Risk One critical vendor review is missing a next review date. No vendor risk process exists and vendors with sensitive data are not reviewed.
Access Control One review missed contractor accounts. No critical system or privileged access reviews are performed.
Management Review One required input is not clearly documented. No management review was performed or decisions are not recorded.
Corrective Action One closure record lacks verification notes. Several findings were closed without root cause, evidence, or verification.

How to Write Classification Rationale

The audit report should explain why the finding was classified the way it was.

This prevents confusion and reduces arguments about severity.

Weak Rationale

“Classified as major because it is important.”

Strong Rationale

“Classified as major because access reviews were not performed for three critical systems, privileged accounts were not reviewed, and no evidence showed ownership or periodic review. This indicates a systemic access governance breakdown.”

Corrective Action Expectations by Classification

Classification Corrective Action Expectation
Major NC Immediate containment, root cause analysis, corrective action plan, leadership oversight, and verified closure.
Minor NC Correct the issue, address root cause, provide closure evidence, and verify.
Observation Assess risk, decide whether action is needed, and monitor.
OFI Consider improvement and prioritize if useful.
Evidence Gap Provide missing evidence or improve the evidence process.
Management Attention Item Leadership decision, documented action, risk acceptance, or resource approval.

Internal Audit Classification Checklist

Before Classifying

  • Identify the requirement.
  • Review the evidence.
  • Confirm the condition.
  • Assess scope.
  • Assess risk.

Classification Questions

  • Is a required process missing?
  • Is the issue systemic?
  • Is the issue high risk?
  • Is this a repeat finding?
  • Does leadership need to act?

After Classification

  • Write classification rationale.
  • Assign owner.
  • Define corrective action expectation.
  • Define closure evidence.
  • Track verification status.

Common Classification Mistakes

Classification should be based on evidence, not emotion.

Calling everything major.
Calling everything minor.
Classifying without criteria.
Ignoring repeat findings.
Ignoring scope and risk.
Confusing evidence gaps with control failure.

How SharePoint Can Help Classify Findings

A SharePoint ISMS workspace can standardize finding classification.

It can also connect classification to corrective action workflow, evidence, verification, and leadership reporting.

Major Nonconformities
Show urgent issues requiring leadership attention.
Minor Nonconformities
Track limited gaps and corrective actions.
Repeat Findings
Identify failed corrective actions.
Management Attention Items
Show decisions leadership must make.
Pending Verification
Track closure evidence review.
Certification Readiness Blockers
Show what must close before external audit.

Practical rule: classification should not live only in the audit report. It should drive the corrective action workflow.

Leadership Reporting for Major and Minor Findings

Leadership does not need every detail from every finding.

But leadership does need a clear readiness view.

Leadership Should See Why It Matters
Number of major and minor findings. Shows overall readiness pressure.
Repeat findings. Shows whether corrective actions are working.
High-risk themes. Shows where leadership should focus.
Certification blockers. Shows what must close before external audit.
Management decisions required. Shows where risk acceptance, resources, or deadlines are needed.

Senior Advisory Support

Canadian Cyber also provides senior advisory support for ISO 27001 finding classification, major and minor nonconformity review, corrective action tracking, SharePoint ISMS dashboards, management reporting, and vCISO guidance.

For senior cybersecurity, ISO 27001, audit readiness, and vCISO advisory support, you can review Waqar Mehboob’s profile.

View Waqar Mehboob’s Profile

How Canadian Cyber Helps

Canadian Cyber helps organizations classify ISO 27001 internal audit findings correctly and turn them into clear corrective actions.

We help teams understand what is major, what is minor, what needs leadership attention, and what must be fixed before certification.

ISO 27001 internal audit finding classification.
Major nonconformity review.
Minor nonconformity review.
Audit reporting support.
Corrective action planning.
Closure evidence definition.
SharePoint corrective action tracker setup.
Leadership readiness dashboards.

Frequently Asked Questions

What is a major nonconformity in ISO 27001?

A major nonconformity is usually a serious issue such as a missing required process, systemic failure, high-risk control breakdown, repeat unresolved issue, or significant gap affecting ISMS effectiveness.

What is a minor nonconformity in ISO 27001?

A minor nonconformity is usually a limited issue where a requirement is partially implemented, but evidence or execution is incomplete in a specific area.

Can a minor nonconformity become major?

Yes. A repeated minor finding, unresolved corrective action, high-risk impact, or pattern across multiple areas may become major.

What is the difference between an observation and a nonconformity?

A nonconformity means a requirement was not met. An observation is an issue or condition that may create risk later but does not clearly show that a requirement failed.

How should ISO 27001 findings be classified?

Findings should be classified based on criteria, evidence, risk, scope, repeat nature, process maturity, certification impact, and whether leadership action is needed.

Can SharePoint help track finding classification?

Yes. SharePoint can track finding type, risk level, classification rationale, evidence, owner, due date, corrective action, closure evidence, verification status, and leadership attention items.

Can Canadian Cyber help classify ISO 27001 findings?

Yes. Canadian Cyber helps organizations classify ISO 27001 internal audit findings, write clear reports, build corrective action trackers, and prepare certification readiness dashboards.

Takeaway

Finding classification is not just an audit label.

It is a management decision tool.

A major nonconformity tells the organization that something serious may be wrong with the ISMS.

A minor nonconformity tells the organization that a requirement is not fully met and needs correction.

An observation warns the organization before a weakness becomes a finding.

When findings are classified properly, teams know what to fix first, leadership knows what needs attention, and the organization moves closer to certification readiness.

Classify ISO 27001 Findings Before Certification

Canadian Cyber can help your organization classify major and minor findings, define corrective actions, prepare leadership summaries, and build SharePoint findings dashboards.

We support ISO 27001 internal audit reporting, findings classification, corrective action planning, SharePoint ISMS dashboards, evidence review, vCISO support, SOC 2 readiness, ISO 42001, ISO 27017, ISO 27018, and cybersecurity assessments.

Stay Connected With Canadian Cyber

Follow Canadian Cyber for practical guidance on ISO 27001 internal audits, major and minor nonconformities, audit findings, corrective action tracking, certification readiness, SharePoint ISMS, SOC 2 readiness, AI governance, and vCISO services.