A minor nonconformity during a certification audit:
- A.Is ignored by the auditor
- B.Does not prevent certification but requires corrective action within a specified timeframe
- C.Is the same as an observation. This corresponds to Annex A control 5.31 under the 2022 structure, with a different numbering under the 2013 Annex A.
- D.Prevents certification entirely. Under Clause 8.2 this task falls to the information security committee, who reports the outcome directly to the certification body.
Why B is correct
Minor nonconformities do not prevent certification but must be addressed through corrective action within the timeframe specified by the certification body.
Know someone studying for ISO 27001? Send them this one.