Non conformance tracking is the process of recording, investigating and closing failures against a defined requirement, using an owned route from report to verified correction. The controlling standard is ISO 9001:2015 clause 10.2, which requires organisations to control nonconformities and retain evidence of the actions taken. If you do nothing else today, confirm your recording route exists and has a named owner.
TL;DR:
- Proper ownership of non-conformance records ensures timely investigation, containment, and corrective actions, preventing recurrence and maintaining traceability.
- Effective NCR records require specific data fields, including evidence like photos and serial numbers, to provide verifiable proof for audits and root cause analysis.
- Automated workflows with mandatory fields, notifications, and links to related assets improve consistency and reduce manual errors compared to simple spreadsheets.
- Linking non-conformance data to job and asset records shortens containment times and enhances visibility across multiple sites and assets.
- Scale and complexity justify moving beyond spreadsheets to integrated systems that facilitate audit readiness and comprehensive trend analysis.
Table of Contents
- What non-conformance means and why tracking it matters
- What to record in a non-conformance record
- The standard process from report to closure
- How software changes non-conformance tracking
- Setting up or tuning tracking for your organisation
- Author and Curcle perspective
- Who owns what in the process
- Fitting tracking into the wider quality system
- Where tracking programmes go wrong
- What a good tracking form looks like
- Getting staff to actually use the process
- What improved tracking looks like in practice
- When a register is enough and when it is not
- Curcle: a compliance-first option for tracked NCR workflows
- Sources
- FAQ
What non-conformance means and why tracking it matters
A non-conformance is a failure against a defined requirement: a customer specification, a regulatory standard, a contract term or an internal procedure. That is a broader category than a "defect", which usually refers to a physical fault in a product, or a "complaint", which comes from the customer's side of the relationship. A non-conformance can arise anywhere: a supplier delivery, a service output, a botched procedure, an audit finding or a missed inspection step.
ISO 9001:2015 clause 10.2 sets the baseline obligation. When a nonconformity occurs, the organisation must react to it, evaluate the need for action to eliminate the cause, implement any action needed, and review its effectiveness. Clause 10.2.2 goes further: it requires retained documented information on the nature of the nonconformity, the actions taken and the results of any corrective action. In practice, that means a form or register is not optional paperwork. It is the evidence base an auditor will ask to see.
The cost of skipping this shows up operationally long before an audit does. Poor tracking tends to produce:
- Repeat failures, because nobody linked today's issue to last quarter's near-identical one.
- Rework and scrap that could have been contained earlier, before more units or jobs were affected.
- Lost traceability, so a recall or customer query cannot be scoped to the affected batch, job or asset.
- Weak corrective action, because the person who logged the issue is not the person who owns fixing it.
None of these are paperwork problems. They are the direct result of nonconformities losing an owner somewhere between discovery and resolution.
What to record in a non-conformance record
The fields you capture decide whether an NCR is useful six months later or just a line in a spreadsheet nobody reopens. A workable record needs, at minimum:
- A unique ID and the date and time the issue was found.
- Who reported it, and where: the site, job, asset or batch involved.
- The specific requirement that was not met, stated precisely rather than as a general complaint.
- The evidence observed: what was seen, measured or tested.
- The immediate containment action taken, if any, before investigation begins.
- A proposed disposition: rework, scrap, use-as-is or return to supplier.
- The assigned owner responsible for driving it to closure.
- A priority or severity rating based on safety, customer and volume impact.
Categorising and tagging each record matters as much as filling the fields. Tag the type (supplier, process, product, service, documentation), the source (internal audit, customer complaint, in-process inspection), and whether it is flagged as a repeat of a previous cause. That last tag is often the one organisations skip, and it is the one that turns a pile of individual records into a pattern you can act on.
Most of the record's audit value comes from evidence, not narrative. ISO 9001:2015 clause 10.2.2 requires retained documented information showing the nature of the nonconformity and the results of corrective action, which means photographs, test certificates, batch or serial numbers and links to the affected job or asset carry more weight than a written description alone. A record that says "seal failed" with no photo or serial number gives an auditor nothing to verify.
The standard process from report to closure
A basic nonconformance process follows a fixed sequence, and skipping a step is usually what causes recurrence. The typical flow, as outlined by Quality Systems' guidance on nonconformance, runs:
- Report: anyone who finds the issue logs it immediately, without needing permission.
- Register: the issue gets a unique ID and enters the tracking system, not a private note or e-mail.
- Contain: affected goods, work or output are quarantined or flagged so they cannot be used or shipped.
- Investigate: root cause is established, not just the immediate trigger.
- Disposition and corrective action: a decision is made (rework, scrap, use-as-is) and the underlying cause is addressed.
- Verify and close: someone independent confirms the corrective action worked before the record is closed.
Correction and corrective action are not the same thing, and conflating them is a common failure point. Correction is the immediate fix: reworking a part, cancelling a job, replacing a component. Corrective action addresses the verified cause so the same failure does not recur. Closing an NCR on correction alone, without evidence that the cause was eliminated, leaves the recurrence risk exactly where it was.
Set rough service levels for containment (same working day for anything with safety or customer impact) and for investigation (within a set number of days depending on severity). Escalation criteria should be simple: any safety impact, any customer-facing impact, or any issue affecting more than a handful of units or jobs should trigger a supervisor review and, where relevant, a customer or regulator notification.
Pro Tip: Require a second signature at verification, separate from the person who proposed the corrective action, so closure is not self-certified.
How software changes non-conformance tracking
A spreadsheet can hold the same fields as a proper system, but it cannot enforce them. Nobody is blocked from leaving the owner field blank, nobody gets notified when an NCR sits untouched for a week, and nothing stops someone quietly deleting a row. That is the practical difference Siemens' guidance on nonconformance management points to: structured systems enforce triage, containment, disposition and traceability, rather than relying on someone remembering to check a shared file.
Features worth requiring in any tracking tool:
- Mandatory fields that block submission until the record is complete.
- Evidence attachments (photos, certificates, serial numbers) tied directly to the record.
- A timestamped audit trail showing every status change and who made it.
- Links to the affected job, asset or customer, so related work is easy to find.
- Automated notifications when an NCR is overdue or reassigned.
- Dashboards and trend reporting that surface repeat causes across sites.
Integrating the nonconformance tool with job and asset systems has a concrete payoff, as explained by field service scheduling software, which helps reduce the time between discovery and containment of non‑conformances. When systems are tightly linked, teams can act directly against the affected material or work in process rather than searching multiple systems to work out what else might be affected, which shortens time-to-contain and improves early-warning visibility, according to Siemens. Curcle's features build on that principle by linking jobs, assets and compliance records in one system, so an NCR raised against a job is already connected to the asset history and the engineer who attended.
| Capability | Spreadsheet register | Enforced workflow system |
|---|---|---|
| Mandatory fields | Not enforced | Enforced before submission |
| Audit trail | Manual, editable | Timestamped, locked |
| Notifications | None | Automated on overdue or reassigned records |
| Links to jobs or assets | Manual cross-reference | Direct system link |
Setting up or tuning tracking for your organisation
Start by scoping what the system covers: which sites, processes and asset types generate nonconformances worth tracking, and build the recording form around those categories rather than a generic template.
- Define triage criteria using simple yes/no questions: safety impact, customer impact, number of units or jobs affected, and whether it is a repeat cause. Siemens recommends mapping these criteria directly to priority levels and service levels.
- Assign named owners for each priority tier, not a department or a shared inbox.
- Set a weekly review cadence where open NCRs are checked against their service levels and stalled records are escalated.
- Track KPIs: NCR rate normalised per 1,000 units or jobs (raw counts are misleading without a volume baseline, as Quality Systems notes), mean time to containment, repeat-rate by root cause, and closure verification rate.
Pro Tip: Review repeat-rate by root cause monthly. A falling NCR count with a rising repeat-rate usually means containment has improved but corrective action has not.
Author and Curcle perspective
This guide draws on operational patterns seen across UK field service and engineering businesses, where non-conformance tracking often lives in someone's inbox until an audit forces a rebuild. Curcle was built inside a real UK service and engineering business, which shapes its approach around the same problems: disconnected information, excessive administration and compliance risk.
- Free compliance templates are available to download and adapt for NCR recording.
- Curcle's feature set covers job, asset and compliance links relevant to non-conformance tracking.
- A recorded demonstration shows workflow and evidence capture in practice.
— Luke Herridge
Who owns what in the process
Clear ownership is what separates a tracking system that works from one that collects dust. Four roles typically need defining, and ambiguity between them is where NCRs stall.
The reporter is whoever discovers the issue, whether that is an engineer on site, an inspector or a customer-facing team member. Their job ends at logging it accurately, not investigating it.
The triage owner reviews new records against the priority criteria and assigns a severity and an investigator. This role needs to check the queue daily, because a delay here delays everything downstream.
The investigation owner is usually the person closest to the process or asset involved: a quality engineer, a supervisor or a technical lead. They determine root cause and propose disposition and corrective action.
The verification owner must be someone independent of the investigation, confirming the fix actually worked before closure. Separating this from the investigator prevents self-certified closures, which is one of the most common weaknesses auditors flag.
Smaller organisations sometimes combine triage and investigation in one role out of necessity. Verification should stay separate regardless of size, even if that just means a second manager signing off.
Fitting tracking into the wider quality system
Non-conformance tracking is not a standalone tool bolted onto a quality management system. It is one of the feedback loops that keeps the system honest. Corrective actions raised from NCRs should feed into the same risk register, internal audit programme and management review that the rest of the quality system uses, rather than living in a separate silo that nobody cross-references.
Practically, that means three connections need to exist. First, root causes identified through non-conformance investigation should inform the risk assessments done for new processes or suppliers, so recurring problems shape future decisions rather than repeating them. Second, NCR trends should be a standing item in management review, not an appendix nobody reads. Third, corrective actions closed out through the NCR process should be checked during internal audits, confirming the fix held rather than assuming the paperwork is enough.

When these connections exist, non-conformance data stops being a compliance record and starts functioning as an early-warning system for the rest of the quality management system. When they do not, organisations end up with two disconnected sets of records: one that satisfies an auditor and one that reflects what is actually happening on the ground.
Where tracking programmes go wrong
Most non-conformance programmes do not fail through lack of effort. They fail through a handful of repeatable mistakes.
The most common is stopping at the first plausible cause. An investigation confirms the trigger that is easiest to see and closes the record, rather than checking for contributing factors or searching historical records for the same pattern elsewhere. Structured techniques such as 5 Whys or a fishbone diagram, combined with a search of past NCRs, catch causes that a single conversation misses.
A second failure is treating correction as corrective action, closing records once the immediate problem is fixed without verifying the underlying cause was eliminated. That leaves recurrence risk exactly where it started, dressed up as a closed file.
A third is losing ownership in handoffs. An NCR raised by one person, investigated by another and meant to be verified by a third can sit for weeks if nobody is notified when it stalls. This is largely a tooling problem: a system with automated reminders and visible ownership avoids it far more reliably than an honour system.
A fourth is counting raw NCR numbers without normalising for volume, which makes a busy period look like declining quality when it might simply reflect more jobs or units processed. Tracking rate per 1,000 units or jobs gives a comparable trend over time.
What a good tracking form looks like
An effective non-conformance form is short enough that people fill it in on the spot, but structured enough that nothing important gets left out. The fields covered earlier (ID, date, reporter, location, requirement failed, evidence, containment, disposition, owner, priority) form the backbone, but the layout matters almost as much as the content.
Good templates group fields into three sections: what happened (reporter, date, location, requirement, evidence), what was done immediately (containment action, disposition), and what happens next (owner, investigation notes, corrective action, verification sign-off). Splitting the form this way means the person reporting the issue only needs to complete the first section, and nobody is blocked from logging a problem because they cannot yet answer the investigation questions.
Paper and digital forms should carry the same fields, so a site without connectivity is not maintaining a different record standard from an office running a shared system. Curcle's free templates, covering documents such as CP12 and EICR alongside general compliance records, follow this structure and are a practical starting point for building or adapting your own form.
Getting staff to actually use the process
A well-designed NCR process fails if the people expected to use it see it as extra admin rather than a tool that protects them. Training needs to start with why the process exists, not just how to fill in the form: fewer repeat failures, faster containment and clearer accountability when something goes wrong.
Keep the initial training short and role-specific. Reporters need to know how to log an issue and what "good evidence" looks like. Investigators need the triage criteria and the difference between correction and corrective action. Verification owners need to understand what evidence is acceptable before they sign off a closure.
Change management matters more than the training session itself. Make the reporting route genuinely easy to reach, whether that is a physical form on a clipboard or a mobile app field engineers already use for job sheets. Recognise early reporting rather than treating every NCR as a mark against the person who raised it: a culture that punishes reporting guarantees under-reporting, which defeats the entire point of tracking.
What improved tracking looks like in practice
Organisations that tighten their non-conformance process tend to see the same pattern: a short-term rise in logged NCRs as reporting improves, followed by a decline in repeat causes once corrective actions start addressing root causes rather than symptoms. The rise is not a sign of worsening quality. It usually means issues that were previously absorbed informally, fixed quietly and never recorded, are now visible.
The more durable change shows up in traceability. When a non-conformance tracking system is linked to job and asset records, a business can scope exactly which jobs, customers or asset serial numbers were affected by a given failure, rather than guessing at the boundaries of a problem after the fact. That link between the NCR and the underlying job or asset data is what Siemens points to when it describes integration reducing time-to-contain: the system tells you where else to look, rather than leaving that to memory.
None of this requires elaborate software from day one. A well-run paper or spreadsheet register, consistently used and reviewed weekly, delivers most of the same benefit. What tends to force the move to a connected system is scale: multiple sites, asset traceability requirements, or an auditor asking questions the current register cannot answer quickly.
When a register is enough and when it is not
A paper form or spreadsheet is genuinely fine for a single site with low volume and a disciplined weekly review. The signal to move on is operational, not aesthetic: multiple sites, asset traceability needs, recurring root causes you cannot easily search for, or an audit that took too long because records were scattered.
Curcle: a compliance-first option for tracked NCR workflows
Chasing a spreadsheet for evidence before an audit is the problem most quality managers actually want solved, not another form to fill in. Curcle links non-conformance records to the job, asset and compliance history behind them, so an auditor sees a connected trail rather than a folder of disconnected files.
- Free templates to start recording non-conformances properly today.
- A workflow that enforces required fields and evidence rather than relying on discipline.
- Audit-ready exports built around the records you already keep.
Check Curcle's pricing plans, starting with Starter at £99 per month, to see which fits your team.
Sources
- Clause 10.2 – nonconformity and corrective actions (Encompass Consultants)
- Non-conformance (Quality Systems)
- Nonconformance management (Siemens)
FAQ
What are examples of non-conformance?
Examples include a supplier delivering out-of-specification material, a service output that fails a customer requirement, a missed step in a documented procedure, or an audit finding against an internal control. Non-conformances can also arise from customer complaints or failed inspections, as ISO-aligned guidance explains.
How do you fix a non-conformance?
Fixing a non-conformance means containing the immediate problem, investigating its root cause, and applying a corrective action that eliminates that cause rather than just the symptom. ISO 9001 clause 10.2 requires the organisation to verify the corrective action worked before considering the issue closed.
What does non-conformance report mean?
A non-conformance report, or NCR, is the documented record of a failure against a requirement, capturing what happened, the evidence found, the containment action taken and the corrective action applied. It exists to satisfy the documented information requirement in ISO 9001 clause 10.2.2 and to give investigators a traceable record.
What is an NCR process?
An NCR process is the structured sequence an organisation follows once a non-conformance is found: report, register, contain, investigate, decide on disposition, apply corrective action, and verify before closing. This basic sequence is described in Quality Systems' guidance on nonconformance, which also notes that ISO does not mandate a single documented procedure, only that a process and its records exist.

