Nonconformance Found Outside the Audit Scope - Supplier Audit

GStough

Staff member
Super Moderator
#1
I'm wondering if anyone else has had this happen. During a supplier audit (which is not a full QMS audit), while interviewing and reviewing records for an element of the Standard (ISO 13485, in this case) that is part of the audit scope, you discover a nonconformance of an element that is NOT part of the audit scope. Do you write this as a nonconformance or, since that element was not part of the audit scope, do you write it as an opportunity for improvement (observation)?

I would love to hear your experiences....:)
 
Elsmar Forum Sponsor

Coury Ferguson

Moderator here to help
Staff member
Super Moderator
#2
Re: Nonconformance Found Outside the Audit Scope

Gidget,

In my opinion, if a NC is found, even though it might have been outside the scope (You can always find something within the scope to identify with) it should be written in my opinion. Why let something pass that could lead to any further unsatisfactory items within the Organization.

But, just my opinion.
 

GStough

Staff member
Super Moderator
#4
Re: Nonconformance Found Outside the Audit Scope

Gidget,

In my opinion, if a NC is found, even though it might have been outside the scope (You can always find something within the scope to identify with) it should be written in my opinion. Why let something pass that could lead to any further unsatisfactory items within the Organization.

But, just my opinion.
Thanks, Coury! That was my inclination, as well. :agree1::yes::cool:
 

Sidney Vianna

Post Responsibly
Staff member
Admin
#5
This being a second party audit, there are no cast in stone rules. If the deficiency found has a potential to impact the supplier ability to consistently deliver conforming products, yes, I would report the issue and tell the supplier that you expect corrective action to resolve it.

If this were a 3[sup]rd[/sup] party audit, I would react differently.
 

Paul Simpson

Trusted Information Resource
#6
Interesting question, Gidget. I'd answer 'it depends' on what the objective(s) of the audit are. If you are auditing a supplier then you may have one of more of the following:
  • Do they have the capability of complying with ISO 13485?
  • Can they produce products in accordance with your organizations / international standards?
  • Are they a supplier you want to work with?
The last of these brings in everything that you believe is relevant, IMHO.
 

Mark Meer

Trusted Information Resource
#7
If it's outside the scope, you don't write it up as a nonconformity.
...after all, what requirement are you going to cite that they are not conforming to?

That being said, certainly bring it to the attention of the organization - either in report as an opportunity for improvement, or communicated to some responsible party - so they can act on it if they deem necessary...
 

Big Jim

Super Moderator
#8
Re: Nonconformance Found Outside the Audit Scope

Only if it's Medical Device QMS related, EHS stuff nope
+1

In my opinion.

Generally, if you find a nonconformance during the course of an audit that pertains to the standard you are auditing to, it should be treated as a nonconformance.

Writing an observation or an opportunity for improvement would be considered a soft nonconformance and that is frowned on.

It is not unusual to stumble onto a nonconformance that is outside of the scope of the audit. They don't get a pass because it wasn't the main focus of the audit.

There is no reason for a 2nd party audit (supplier audit) to be treated differently. Doing so weakens the entire ISO scheme.
 

Paul Simpson

Trusted Information Resource
#9
Re: Nonconformance Found Outside the Audit Scope

Well, surprise, surprise, Jim and I are not completely aligned.;)

+1

In my opinion.

Generally, if you find a nonconformance during the course of an audit that pertains to the standard you are auditing to, it should be treated as a nonconformance.
Not all audits are conducted solely against standards. If you read ISO 19011 (latest draft) audits are carried out against audit criteria:
3.2 audit criteria
set of policies, procedures or requirements used as a reference against which audit evidence (3.3) is compared
So for any audit there are typically more documents in play than the standard (ISO 13485 in this case).

Writing an observation or an opportunity for improvement would be considered a soft nonconformance and that is frowned on.
You appear to be applying 3rd party criteria to a 2nd party audit. Nobody is going to frown on how a customer describes a finding on one of its suppliers.

It is not unusual to stumble onto a nonconformance that is outside of the scope of the audit. They don't get a pass because it wasn't the main focus of the audit.
Now in a second party audit I'd agree (in fact I did so below). For third party I'd disagree but wouldn't want to derail the discussion ;).

There is no reason for a 2nd party audit (supplier audit) to be treated differently. Doing so weakens the entire ISO scheme.
As above, I don't believe we should be transferring 3rd party expectations to 2nd party audits. I'm not sure what 'ISO scheme' can be weakened by this. :confused:
 

howste

Thaumaturge
Super Moderator
#10
Re: Nonconformance Found Outside the Audit Scope

Every audit has a client - the person (or organization) requesting the audit. They are the ones who define the rules and are the "customer" of the audit activities. If it's in the client's best interest to document a nonconformity, it should be documented. If it's not in their best interest, maybe not. In the case of a supplier audit the supplier may or may not have to respond to the nonconformity depending on what the contract (or other legal agreement) is between the customer and supplier.
 
Thread starter Similar threads Forum Replies Date
GStough Pushback on a Nonconformance Found in a Supplier Audit General Auditing Discussions 22
S External Auditor Findings when an Internal Audit found a Nonconformance Yesterday Document Control Systems, Procedures, Forms and Templates 11
J External Nonconformance Not Corrected - Audited same area and found same problem IATF 16949 - Automotive Quality Systems Standard 9
M What happens if a Major or Minor Nonconformance is found during Surveillance Audit ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 4
J Boeing CFO got caught - Why wasn't a nonconformance found here? Nonconformance and Corrective Action 2
M Major/Minor Nonconformity - Nonconformance from last audit found again Nonconformance and Corrective Action 15
T Internal Nonconformance procedure thoughts (AS9100) AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 6
C NCR (Nonconformance System) Software Nonconformance and Corrective Action 7
L How to deal with an ISO 13485 Supplier Audit nonconformance ISO 13485:2016 - Medical Device Quality Management Systems 17
E When to generate a nonconformance report ISO 13485:2016 - Medical Device Quality Management Systems 6
K Counterfeit parts prevention - Audit Nonconformance - AS9100 8.2.2 AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 25
qualprod When to write up a nonconformance and require a NCR - We produce labels ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 14
PhilM Nonconformance report, Customer complaint investigations and RMAs ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 8
M Medical Device Directive - Seeking common nonconformance write up scenarios CE Marking (Conformité Européene) / CB Scheme 2
CPhelan Nonconformance opened as incorrect expiration date placed on received product. Escalate to CAPA? Nonconformance and Corrective Action 4
qualprod Ineffective follow up of people performance - Audit Nonconformance ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 9
Q AS9120 7.5.3.2 Control of Documented Information - Audit Nonconformance AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 20
qualprod Criteria to raise a Nonconformance based on KPI values ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 39
L AS9100 D- Handling Nonconformance Documentation for an organization that outsources most of the work. AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 11
G Timing allowed by IATF to close a Remote Site Minor Nonconformance IATF 16949 - Automotive Quality Systems Standard 2
R Visually impacting graphics for Nonconformance status metrics for Management Report Nonconformance and Corrective Action 5
J ISO 13485 Audit Nonconformance written against 6.3 Infrastructure ISO 13485:2016 - Medical Device Quality Management Systems 25
PastorBee13 IATF 16949 Audit Nonconformance Responses per 5.1.1.2 - Format IATF 16949 - Automotive Quality Systems Standard 11
A What ISO 9001:2015 clause could be used to write nonconformance for not updating licensed driver list? General Auditing Discussions 8
S Nonconformance to a Note in ISO13485 clause 6.2 Human Resources Effectiveness ISO 13485:2016 - Medical Device Quality Management Systems 13
A API Spec Q1 9th Edition - 12 month Internal Audit Schedule Audit Nonconformance Oil and Gas Industry Standards and Regulations 10
A Where are the rules for when a repeat minor nonconformance becomes a major? IATF 16949 - Automotive Quality Systems Standard 36
R ISO 9001:2015 9.3 - Required inputs to the management review - Audit Nonconformance Manufacturing and Related Processes 14
K Which clause would best fit this Nonconformance? (Supplier Related) Internal Auditing 2
W Minor Audit Nonconformance Against Determining the scope of QMS IATF 16949 - Automotive Quality Systems Standard 12
J IATF 16949 registration - Major Nonconformance Finding IATF 16949 - Automotive Quality Systems Standard 9
Ajit Basrur Are inputs to the nonconformance process required to be identified? Nonconformance and Corrective Action 21
N Responding to NADCAP nonconformance - Control of External Documents AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 5
P Examples of Nonconformance, Corrective Action Requests, and Root Cause Analysis Nonconformance and Corrective Action 2
qualprod Should I initiate CAPA for a nonconformance not recorded? Nonconformance and Corrective Action 25
K Nonconformance on training - Not following own processes (IATF 16949) Internal Auditing 14
J Audit opportunity for improvement raised to nonconformance months after the audit General Auditing Discussions 7
K NCR or CA? We're taking any issue we have and saying its a nonconformance Nonconformance and Corrective Action 11
R Closing out an API/ISO QMS Audit Nonconformance - Magnetic Particle Examination Inspection, Prints (Drawings), Testing, Sampling and Related Topics 5
Q Nonconformance Raw Material Treatment in ISO 9001 ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 3
C Recurring Nonconformance - Missing Deadline for Closing a Corrective Action Problem Solving, Root Cause Fault and Failure Analysis 14
N Laboratory Audit Nonconformance - Maintenance of Standards ISO 17025 related Discussions 10
K Internal Auditing a previous Nonconformance? Internal Auditing 19
D Interpretation of new IAQG ruling - Audit duration for nonconformance verification AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 7
Q Customer Complaint Vs. Nonconformance - CAPA SYSTEM Customer Complaints 2
D Nonconformance on document control - Unapproved document on production server Document Control Systems, Procedures, Forms and Templates 4
P Ratio of Supplier with a nonconformance vs. Supplier without a nonconfomance Supplier Quality Assurance and other Supplier Issues 10
W Nonconformance Recurrence Response Help General Auditing Discussions 4
dubrizo If Quality Objectives are not known to employees, is it a Nonconformance? General Auditing Discussions 7
xfngrs Automotive Industry Nonconformance Database wanted - Preferably SharePoint based Quality Assurance and Compliance Software Tools and Solutions 5

Similar threads

Top Bottom