Nonconformance Report (NCR) Template
Three-page nonconformance report: identification, where and how it was found, evidence, containment, a severity class, a five-step why-chain, corrective and preventive actions with owners and dates, an effectiveness check and closure sign-off. Its order follows ISO 9001:2015 clause 10.2 (clause number and title only; not reviewed by ISO).
What's inside
- Identification — NCR number, date raised, raised by, site, process, item affected, lot or serial, and the source: internal process, supplier material, customer complaint, audit or other
- Where and how it was detected — stage found, date and time, found by, how found, and the requirement that was not met
- Description and evidence — what was found against what was required, quantity affected and checked, extent checked, evidence attached and where it is kept
- Containment and disposition — immediate actions with owner and date; use as is, rework, repair, scrap, return to supplier or re-grade; who authorised it; whether the customer was told
- Severity and classification — minor, major or critical (defined in your own procedure), the reason, a provisional cause category, first time or repeat, similar nonconformities elsewhere
- Root-cause analysis — problem statement, five why rows each with its evidence and a confirmed box, method used, root cause, and why it was not detected earlier
- Corrective and preventive action — numbered actions with type, owner, due and done dates; documents to update; where else the action was applied
- Effectiveness verification — check date, verifier, method, the result that counts as effective, the result found, effective yes or no
- Closure and sign-off — raised by, action owner, quality representative and approver, date closed, where the records are kept
What requires or shapes this record
No law prescribes a nonconformance report. The requirement behind it sits in a quality management system standard: when something fails a requirement, deal with it, find out why, act on the cause, check that the action worked and keep the record. In a certified system the report is the record an auditor samples. The clauses below shaped the form; the last entry is an edition note to read before you quote a clause number.
- ISO 9001:2015, clause 10.2 (Nonconformity and corrective action)
The clause covers what an organisation does once something has not met a requirement, complaints included: control and correct it, deal with the consequences, decide whether the cause has to be removed, analyse and find the cause, check whether similar problems exist or could arise, carry out the action, review whether it worked, and update risks and opportunities or the management system where needed. Sections 4, 6, 7 and 8 of the form follow that order, and section 5 asks the similar-problems question. The standard asks for records of the nonconformity, the actions and their results; section 9 says where they are kept.
- ISO 9001:2015, clause 8.7 (Control of nonconforming outputs)
The neighbouring clause concerns the item, product or service itself: outputs that fail a requirement are identified and controlled so that they are not used or delivered by mistake. Section 4's disposition choices and its authorisation line are where this shows up. Clause 10.2 is about the cause and clause 8.7 about the item, so one report can hold both without mixing them.
- ISO 9001:2026 (current edition) and the withdrawn 2015 edition
ISO's catalogue, opened on 3 October 2026, lists ISO 9001:2026 as published (edition 6) and shows the 2015 edition as withdrawn and replaced. The clause numbers cited here are the 2015 ones because the form was built against them. The 2026 numbering was not reviewed, so check the numbers against the edition your certificate or audit uses. ISO's text is not reproduced on this page.
Each source checked on 3 October 2026. Not legal advice; check the text in force for your site.
Field by field
Severity is three tick boxes, not a formula, because the definitions of minor, major and critical belong in your own procedure; the form asks for the reason so that the choice is on the record. Anything your customer or contract requires beyond this form, such as a response time or a specific report format, is yours to add.
- NCR number and date raised
- Why: A unique number lets actions, customer replies and audit samples point at one report. The date raised starts the clock for containment and for the closure target.
- Common mistake: Reusing a number for a second lot of the same defect, so the two cannot be told apart in a trend.
- Source of the report
- Why: Internal, supplier, customer and audit reports usually have different owners and are counted separately.
- Common mistake: Ticking Other for a complaint that reached the business through sales, so it never appears in the complaint count.
- Stage where found, and how
- Why: The stage shows how far the problem travelled before anyone caught it, which feeds the question in section 6 of why it was not found earlier.
- Common mistake: Recording where the report was typed rather than where the item was found.
- Requirement not met
- Why: A nonconformity is a gap against a stated requirement. Naming the specification, drawing, procedure or order clause and its revision keeps the report from becoming a matter of opinion.
- Common mistake: "Poor finish" with no document behind it, so nobody can say what conforming looks like.
- Description and evidence
- Why: Facts and measurements let a reader who was not there follow it, and the evidence references let a reviewer open the same photos or records.
- Common mistake: Putting the cause into the description ("operator was careless") before any analysis has been done.
- Quantity affected and quantity checked
- Why: Separates the items known to be bad from the items inspected. The gap between them is the extent still to be checked and drives the containment decision.
- Common mistake: Entering only the number rejected, so the lots nobody has inspected yet are invisible.
- Containment and disposition
- Why: Containment stops more affected items reaching the customer or the next process while the cause is unknown. Disposition says what happens to the items already affected.
- Common mistake: Choosing use as is with no named authoriser and no record of a customer concession.
- Severity class and reason
- Why: The class decides who signs and how fast the cause work must finish. Writing the reason makes two raisers classify the same defect alike.
- Common mistake: Choosing the class by who will read the report rather than by the effect on fitness for use, safety, or a legal or contract requirement.
- Cause category and repeat flag
- Why: A provisional category and the earlier NCR numbers let a reviewer see whether the same cause keeps returning.
- Common mistake: Leaving the repeat box empty because the earlier report sits in another site's system.
- Why-chain, evidence and confirmed box
- Why: Each answer gets the evidence that confirms it. A step with no evidence is a hypothesis to test, not a finding.
- Common mistake: Stopping at "operator error" or "procedure not followed". The chain should end at something the organisation can change, such as a missing check, an unclear instruction or an unguarded machine.
- Root cause, and why it was not detected earlier
- Why: Two questions: why it happened, and why the controls did not catch it. The second often produces the cheaper fix.
- Common mistake: Naming a person as the root cause.
- Corrective and preventive action table
- Why: The type column separates fixing this instance from stopping a repeat or stopping it elsewhere. Every action has an owner and a due date.
- Common mistake: Actions that restate the problem ("be more careful") or that are only retraining, with no change to the process.
- Effectiveness verification
- Why: Writing down the result that will count as effective before the check means the check can fail. A re-check after the action is the only evidence that it worked.
- Common mistake: Closing the report when the action is finished instead of when the check shows the problem has stopped.
- Closure sign-off
- Why: Four roles, including a quality representative who did not own the actions, show that someone independent looked at the check.
- Common mistake: Closing with the action owner as the only signature.
Worked example
IllustrativeHardness out of limit on a batch of brackets (invented plant and supplier)
| Section | Entry |
|---|---|
| 1 Identification | NCR-2026-117, raised 9 March by the incoming inspector. Steel bracket B-204 revision C, lot 5521, from an outside heat-treatment supplier. Source: incoming supplier material. |
| 2 Detection | Found at incoming inspection, 10:15, by a hardness test on a sample. Requirement not met: drawing B-204 revision C, hardness 38 to 44 HRC. |
| 3 Description | Three of 8 brackets tested read 33 to 35 HRC. Lot size 1,200; the other 1,192 not yet tested. Test sheet and photos filed under the NCR number. |
| 4 Containment | Lot moved to the red-tag hold area the same day. Two earlier lots from the same supplier found in stock and sampled the next day. Disposition after a full hardness test: return failed items for re-treatment; authorised by the quality manager. |
| 5 Severity | Major: soft brackets may wear early; no safety function. First occurrence for this supplier and part. |
| 6 Why-chain | Why soft? The furnace load exceeded the cycle sheet. Why? Two loads were combined to meet a delivery date. Why? The cycle sheet sets no maximum load (confirmed from the supplier's furnace log). Root cause: no load limit in the cycle sheet. Not detected earlier because our receiving plan tests hardness on first lots only. |
| 7 Actions | 1 Supplier adds a maximum load to the cycle sheet (supplier quality contact, 28 March). 2 Hardness sample on every lot of B-204 for six lots (inspection lead, 16 March). 3 Add the control requirement to the supplier agreement (purchasing, 30 April). |
| 8 Verification | Due 30 May. Effective if all six lots pass with no out-of-limit sample. Result: six lots passed. Effective: yes. |
| 9 Closure | Signed by the inspector, the supplier quality contact, the quality representative and the quality manager; closed 2 June; records in the quality folder. |
The test for effectiveness was written before the actions were finished, so it could have failed. Had one of the six lots been out of limit, the report would have stayed open with a new action.
When a spreadsheet stops being enough
A folder of NCR forms works while one site raises a few reports a month. It stops working when reports must be counted by cause, supplier or product, when the same people own actions from many reports, and when an auditor asks for every open NCR older than 30 days and how long closure usually takes.
A software record routes each report to an owner by source, links corrective actions to the report that raised them, keeps evidence with the report and reminds before a due date. In a demo, ask to see a report reopened after a failed effectiveness check and what its history then shows. The list below applies the same tag-and-sourced-capability rule as the corrective action guide.
Same rule for every product: tagged “CAPA Management”, with a sourced nonconformance or CAPA capability in its record, or one the vendor stated to us, labelled as vendor-stated. Documented and conditional capabilities qualify; check the linked scope before treating a module as included.
Tekmon pays for a sponsored placement (above); its place in this list follows the same rule as every entry. How lists are ordered
EHS Insight · Quality management and CAPA · Documented
Vendor source · Profile checked
EASE · EASE IQ camera and AI detection · Conditional
Vendor source · Profile checked
Effivity · Nonconformity to corrective action · Documented
Vendor source · Profile checked
Q-Hub · CAPA workflows · Documented
Vendor source · Profile checked
SimplerQMS · CAPA follow-up · Documented
Vendor source · Profile checked
Synergi Life (DNV) · Quality management and CAPA · Documented
Vendor source · Profile checked
Tekmon · Cross-discipline quality and safety CAPA · Documented
Vendor source · Profile checked
1factory · NCR, CAPA, SCAR and complaint workflows · Conditional
Vendor source · Profile checked
Cority · Audit planning and finding follow-up · Documented
Vendor source · Profile checked
Enablon · Integrated quality, incident, nonconformance and CAPA management · Documented
Vendor source · Profile checked
Greenlight Guru · CAPA, nonconformance and complaint workflows · Documented
Vendor source · Profile checked
HSI Donesafe · Quality and supplier management · Documented
Vendor source · Profile checked
Intellect QMS · NCR to CAPA with AI root cause · Documented
Vendor source · Profile checked
isoTracker · CAPA and root cause analysis · Documented
Vendor source · Profile checked
myosh · Quality nonconformance, CAPA and sign-off · Documented
Vendor source · Profile checked
qmsWrapper · Quality events, CAPA and nonconformance · Documented
Vendor source · Profile checked
QT9 QMS · Audit scheduling, review and CAPA linkage · Documented
Vendor source · Profile checked
Quentic · Audit planning, findings and corrective actions · Documented
Vendor source · Profile checked
Scilife · CAPA lifecycle and effectiveness checks · Documented
Vendor source · Profile checked
SoftExpert · Nonconformities, root cause and corrective actions · Documented
Vendor source · Profile checked
AssurX · CAPA tracking · Documented
Vendor source · Profile checked
BizzMine · CAPA across quality and EHS events · Documented
Vendor source · Profile checked
Dot Compliance · Complaint intake to CAPA · Documented
Vendor source · Profile checked
ecoPortal · Quality management and nonconformance · Documented
Vendor source · Profile checked
EHS Hero · Audits and inspections · Documented
Vendor source · Profile checked
MasterControl · CAPA routing · Documented
Vendor source · Profile checked
Notify Technology · Audits, inspections and checklists · Documented
Vendor source · Profile checked
Octave Reliance · Nonconformance application · Documented
Vendor source · Profile checked
Qualio · CAPA and nonconformance workflows · Documented
Vendor source · Profile checked
Qualityze · CAPA effectiveness check · Documented
Vendor source · Profile checked
TrackWise Digital (Honeywell) · Linked quality processes · Documented
Vendor source · Profile checked
VisiumKMS · Corrective action tracking · Documented
Vendor source · Profile checked
ZenQMS · Issues and CAPA · Documented
Vendor source · Profile checked
All 33 matching profiles are shown. Documentation review, not hands-on testing or a claim of compliance.
Related guides
- Incident Investigation Best Practices: Root Cause to Action
Article on incident investigation.
- Quality Inspection Software: Checklists, Measurements, Sampling
Software guide on quality inspection.
- Change Control Software for Regulated Quality Systems
Software guide on change control.