Can You Fail an ISO 27001 Audit? Major vs. Minor Nonconformities Explained

Can You Fail an ISO 27001 Audit? Major vs. Minor Nonconformities Explained
Short answer: yes, you can fail. But the word auditors use isn't "fail." It's "major nonconformity." And the difference between that and a minor one determines whether you walk out with a certificate or walk back in three months later.
What is a nonconformity?
A nonconformity is a gap. Your auditor found evidence that a requirement isn't being met.
That requirement can come from three places: the ISO 27001 standard itself, your own documented policies, or a contractual commitment you've made to a third party. If your ISMS says you do something and you don't, that's a nonconformity. If the standard requires a process and you haven't built one, that's also a nonconformity.
Every organization that goes through certification gets at least a few. The question isn't whether you'll receive findings. It's how severe they are.
What's the difference between major and minor?
A minor nonconformity is an isolated lapse. One missed step. One outdated document. One access review that slipped past its due date. Your system works; it just didn't work perfectly in this specific instance.
Minor findings require corrective action, but they don't block certification. Your auditor will note them, you'll submit a corrective action plan, and the process moves forward. Two to five minor nonconformities are typical for an initial certification audit. That's normal. A major nonconformity is systemic. It means a required element of your ISMS is missing entirely or broken at a fundamental level. No risk assessment. No internal audit. An access control policy that exists on paper but has zero evidence of execution.
A major nonconformity stops certification. Full stop. Your certificate cannot be issued until the finding is resolved and verified by the auditor. Certification bodies typically allow 30 to 90 days for remediation, followed by a verification review.
Cloudsapio can help you
prepare for the ISO 27001
certificate in 4 - 8 weeks.
What are the most common findings?
Five areas account for the bulk of audit findings:
- Risk assessment gaps. This is the single most common nonconformity. Auditors see risk assessments copy-pasted from templates that don't reflect the organization's actual environment. Or assessments that were completed once and never updated after significant changes. ISO 27001 requires a living risk assessment tied to your real operations. A static spreadsheet from onboarding doesn't satisfy the requirement.
- Missing or incomplete internal audits. You need to audit your own ISMS before your certification body does. Many organizations skip this step or run a superficial review that doesn't cover the full scope. If your internal audit didn't examine every clause, the external auditor will flag it.
- Management review gaps. The standard requires top management to review the ISMS at planned intervals. Auditors look for documented evidence: meeting minutes, decisions, action items. A verbal confirmation that leadership "is aware" doesn't count.
- Access control failures. Dormant accounts still active. Terminated employees with live credentials. No evidence of periodic access reviews. These are straightforward to fix but easy to overlook if your offboarding process isn't connected to your identity provider.
- Documentation drift. Policies say one thing, operations do another. Version control is missing. Documents reference processes that changed six months ago. The gap between what's written and what's practiced is where nonconformities live.
Can a minor become a major?
Yes. A minor nonconformity that isn't corrected within the agreed timeframe automatically becomes a major at the next audit. Multiple related minor findings against the same requirement can also be reclassified as a major, because a pattern of isolated lapses starts looking systemic.
- The practical takeaway: treat every minor seriously. Close it within the corrective action window. Document the root cause, the fix, and the evidence that the fix worked. An unresolved minor from a surveillance audit is one of the fastest paths to a suspended certificate.
What about observations?
Auditors also issue observations, sometimes called opportunities for improvement. These are areas that could be stronger but don't violate a requirement. No action is required. No corrective action plan is expected.
Observations are free advice from someone who audits dozens of organizations a year. Ignore them at your own risk — they often preview where a minor nonconformity will appear at the next surveillance audit.
How do I avoid a major nonconformity?
- Run a gap assessment before your certification audit. Map your ISMS against every clause in ISO 27001 (clauses 4 through 10). Identify what's missing before the auditor does. This single step eliminates most major findings.
- Complete a full internal audit cycle. Cover the entire scope. Document findings. Issue corrective actions. Close them with evidence. Your external auditor will ask to see this.
- Hold a documented management review. Schedule it. Record it. Capture inputs, outputs, decisions, and action items. Make sure the attendee list includes actual senior leadership.
- Keep documentation current. Every policy should reflect what you're doing today. If a process changed, update the document. Version-control everything. Auditors compare what's written to what's observed — and the gap is where findings come from.
- Connect your systems. When your identity provider, HRIS, and cloud environment feed into a compliance platform, evidence collection is continuous. You're not scrambling to produce screenshots the week before the audit. You're showing months of automated monitoring data.
So, can you actually fail?
When do I set up my Trust Center?
You can't receive a certificate if you have an open major nonconformity. In that sense, yes, you can fail. But it's not permanent. You get a remediation window; you fix the issue, the auditor verifies it, and certification proceeds.
The organizations that truly fail are the ones that don't prepare. No internal audit. No gap assessment. Policies that haven't been updated since they were generated. A risk register that lists "data breach" as a single line item with no treatment plan.
Zero major nonconformities are expected for a well-prepared organization. A handful of minors is standard. Some observations are healthy.
The bottom line: ISO 27001 audits aren't pass/fail exams. They're structured evaluations with clearly defined categories of findings. Know the difference between major and minor, close your gaps before the auditor arrives, and treat every finding — even observations — as a signal worth acting on. The certificate is on the other side of preparation, not perfection.
Cloudsapio can help you with:
Ready to move faster?
Too much to do,
too important to ignore.
Start with a 30-minute discovery call. If we're not the right fit, we'll tell you and point you in the right direction. If we are, we'll leave the call with a clear plan to get you up and running.

