Nonconformities & CAPA
Log a nonconformity, find its root cause, correct it, and verify the fix worked before you close it, the ISO 27001 / 9001 Clause 10 loop.
| Nonconformity | Source | Severity | Action | Status |
|---|---|---|---|---|
| Missing supplier records | Internal audit | Major | Corrective action | Open |
| Uncontrolled document | Internal audit | Minor | Root cause done | In progress |
| Late management review | Management review | Minor | Scheduled | Open |
| Calibration overdue | Process check | Major | Corrective action | Overdue |
Finding a gap is only half the job. Proving you fixed it is the rest. Keel turns a nonconformity into a tracked loop the way ISO 27001 and ISO 9001 Clause 10 expect: capture what went wrong, analyze the root cause, assign corrective actions, and, critically, verify the fix actually worked before the record can close. It’s the hub your internal audits and security incidents feed into.
Corrective action falls apart in a spreadsheet
An auditor flags a nonconformity, someone notes it, and weeks later nobody’s sure whether it was really fixed, or whether the fix held. Without a root-cause step and an effectiveness check, “closed” means “we stopped talking about it,” which is exactly what an auditor probes.
What nonconformities & capa does
Log from any source
Capture a nonconformity from an internal audit finding, a security incident, a risk, or a failed control, with severity (observation / minor / major), an owner, and a due date.
Guided root-cause analysis
Work the root cause with a guided 5 Whys or Fishbone (cause-and-effect) method, so closure addresses why it happened, not just the symptom. The method and analysis are recorded on the nonconformity.
Corrective actions with owners
Break the fix into concrete corrective actions, each with an owner and due date, and track them to done, so remediation has a clear path from “found” to “fixed.”
An effectiveness gate before closure
A nonconformity can’t be closed until you’ve recorded how you verified the corrective action worked and confirmed it, the Clause 10 effectiveness check, enforced by the workflow rather than left to a checkbox.
A clear lifecycle
Each nonconformity moves through open → root cause → corrective action → verifying → closed, with a register that shows what’s open, in progress, overdue, and done at a glance.
Why it matters
- Turn audit findings and incidents into tracked corrective action, not notes
- Address root causes with a guided 5 Whys / Fishbone, not guesses
- Prove the fix worked with a required effectiveness check before closing
- Give an auditor a defensible Clause 10 record on demand
Get audit-ready, and prove it
Nonconformities & CAPA is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.
Start freeFrequently asked questions
What is CAPA?
Corrective and preventive action: the process of logging a nonconformity, finding its root cause, acting to correct it, and verifying the action was effective. ISO 27001 and ISO 9001 Clause 10 require it, and auditors check that closure is backed by an effectiveness check.
What root-cause methods are supported?
A guided 5 Whys and a Fishbone (cause-and-effect) framework across the common categories: People, Process, Technology, Environment, Management, Measurement. You record the method and the analysis on the nonconformity.
Why can’t I close a nonconformity immediately?
Because Clause 10 asks you to confirm the corrective action was effective. Keel requires you to record how you verified effectiveness and confirm it before the record can be closed, so “closed” is defensible.
Where do nonconformities come from?
You can log them directly, and they’re designed to be fed by internal audits and the security incident register, both of which route their findings into a corrective-action record here.
Related features: Controls & crosswalk · Tasks & remediation · Statement of Applicability
Works with: ISO/IEC 27001 · ISO 9001