Compliance & Governance

Non-Conformance Classification: Critical, Major, Minor, and Observation

A finding without severity is just a complaint. Consistent classification lets a 200-item audit compress into a mental model: what must be fixed, what should be, and what simply warrants watching.

ODD-IT Compliance & Audit Practice 2026-06-05 2 min read

Every audit generates findings. The difference between an effective program and a ceremonial one is what happens to a finding after the audit closes - and that pipeline starts with how the finding is classified at the point of capture.

The four buckets

Standard practice classifies non-conformances into four severities. Critical: an immediate threat to people, legal standing, or business continuity - a missing fire suppression system, a breached isolation protocol, a failed regulatory checkpoint. Major: a systematic failure that degrades the process - a calibration program operating with no schedule, an entire location out of compliance on one checklist family. Minor: a local, isolatable gap - one extinguished label faded, one log inconsistently maintained. Observation: a risk, trend, or improvement opportunity without a current violation - the professional opinion of the auditor, captured formally instead of lost in a hallway conversation.

Why severity must be captured at the item

Classification belongs to the checklist item itself, not to a post-audit triage meeting. When the conformance answer carries its severity natively - Compliant, Non-Compliant Critical, Major, Minor, Observation, N/A - the breakdown falls out of the data automatically. The report summarizes severity distribution without re-reading a single finding. And auto-fail rules can key off severity: any Critical fails the audit regardless of score, while a Minor alone never does.

Routing consequences by severity

Severity should drive the corrective action pipeline: Critical findings escalate immediately with short due dates and visible attention; Major findings generate tracked corrective actions to close; Minor and Observations follow at the program's chosen pace. Mature programs also weight scoring by severity - the classification feeding both the score and the follow-up, so risk and response stay aligned.

The discipline is a definition

The hard part is not the buckets; it is teaching everyone to use the same bucket for the same fact. A shared definition - written into the template guidance, drilled in auditor training, applied consistently in review - is what makes severity distributions comparable across sites and months. Once consistent, one number becomes meaningful: the count of Criticals at a site, and its trend, tells management more than a hundred free-text findings.

Classify once, at the point of capture, with definitions everyone understands - and the entire downstream machinery - scoring, escalation, corrective actions, analytics - runs on rails.

non-conformance classification corrective actions

Keep reading

Compliance & Governance 2 min read

Finding Aging: The Metric Most Audit Programs Ignore

You know what you found last quarter - do you know what is still open from last year? Finding aging exposes the honest health of an audit program better than any conformance score.

2026-04-02 Read

Ready to run better audits?

Build checklists, inspect offline, and track corrective actions to closure - all in one platform.