Nonconformity in OSH

A non-conformity in occupational health and safety (OSH) is the failure to meet a requirement applicable to the management or conditions of safety and health at work. Accurately identifying it allows for corrective action, investigation into why it occurred, and verification that the actions taken prevent its recurrence.

In short

A nonconformity requires an identifiable requirement and evidence of noncompliance. Correction resolves the detected situation; corrective action addresses its root causes. Closure should include a proportionate verification of effectiveness.

Content
  1. What is a non-conformity in OSH
  2. How to write a verifiable finding
  3. Correction and corrective action
  4. Immediate treatment and prioritization
  5. Investigation of causes and action plan
  6. Practical example
  7. Verification of effectiveness and closure
  8. Relationship with audits and preventive obligations
  9. Related concepts
  10. On the blog
  11. References

AZ Dictionary →

What is a non-conformity in OSH

Nonconformity occurs when an observed situation does not meet an applicable requirement. The requirement may originate from regulations, an approved procedure, a relevant contractual commitment, or the management system. To accurately describe it, it is necessary to distinguish between what is required, what is observed, and the difference between the two.

Not every suggestion for improvement constitutes a nonconformity. A personal preference of the auditor, without supporting documentation, is insufficient to formulate one. Likewise, the fact that a deficiency is not labeled as such on a form does not diminish its importance in preventing harm. If there is a risk to people, it must be managed according to its severity and urgency, regardless of the administrative name of the finding.

How to write a verifiable finding

A useful description identifies the process or location, the evidence, and the unmet requirement. Avoid vague phrases like “lack of a preventive culture” or “the documentation is incorrect.” These expressions don’t clarify what was checked or what changes would resolve the problem. The description should be understandable to someone else without having participated in the visit.

For example, if a procedure requires checking a control before the start of a shift, and there is no evidence of this check in the reviewed operations, the scope of the sample and the observations are documented. It is not automatically concluded that the entire organization is always non-compliant. Nor should the lack of a record be confused with the actual absence of an activity without verification.

Correction and corrective action

Correction addresses the detected situation: restoring protection, replacing an obsolete document, or completing an omitted verification. Corrective action aim to prevent recurrence by changing the causes that allowed the failure. Both may be necessary, but they are not interchangeable.

If an outdated document remains in use, removing that copy corrects the issue. Reviewing the distribution system, print permissions, and removing previous versions may constitute corrective action. Simply reminding staff to be careful does not explain why the system allowed an incorrect instruction to remain in use.

Immediate treatment and prioritization

The first decision is to determine whether an exposure exists that requires immediate intervention. Recording the finding should not delay protecting people. Interim measures need to be appropriate to the risk, communicated to those implementing them, and maintained until the intended solution is effective. They must not become indefinite.

Internal classification by severity can help allocate resources, provided criteria are defined. Categories like “major” or “minor” should not be given legal standing when they originate from an internal procedure or certification. An apparently documentary nonconformity can have significant consequences if it affects a critical operation.

Investigation of causes and action plan

The investigation examines how the nonconformity occurred and what conditions contributed to it. Design, resources, coordination, competence, workload, and management controls are all considered. Root cause analysis requires evidence and corroboration with the people involved; it is not about choosing the most convenient explanation or always ending with “human error.”

The plan identifies specific actions, responsible parties with the capacity to implement them, resources, and deadlines. It also establishes how the outcome will be verified. When there are shared causes across several centers, it is advisable to review their scope before closing only the local case. The same procedural weakness may have produced different situations in other areas.

Practical example

A review reveals that the instruction available to a team member does not reflect a recent process change. The company checks which operations have been performed, monitors the situation, and provides the updated instruction. It then investigates how the change was communicated and why the workstation copy was left out of the update process.

The analysis shows that the distribution point list did not include that area. Document control is updated, the other points are reviewed, and a verification process is assigned for future changes. Subsequent verification confirms that people are accessing the correct version and that old copies are identified and removed. Closure is based on these results, not solely on having sent an email.

Verification of effectiveness and closure

Effectiveness is verified after the action has had a chance to function. The timeframe and method depend on the risk and frequency of the activity. It may be necessary to observe several shifts, review a sample of operations, or repeat a measurement. The verifier must be competent and sufficiently independent from the execution of the action.

If the problem recurs, the causal hypothesis, the implementation, and the appropriateness of the measure must be reviewed. A premature administrative closure may mask outstanding risks. It is advisable to maintain records that distinguish between proposed, executed, and verified actions, and to retain the reasons for extending a deadline or changing the solution.

Relationship with audits and preventive obligations

Nonconformities can be detected during an occupational health and safety (OSH) audit, an internal inspection, an incident investigation, or in daily operations. Addressing them is part of improving the system. In Spain, the obligations to assess risks, plan, and review prevention are established in Law 31/1995 and the Regulations for Prevention Services.

The internal procedure does not replace the communications, actions, or responsibilities that may arise from a specific event. It is necessary to maintain an accurate description, relevant evidence, and decisions made, while protecting personal information. The preventive purpose is to restore control and learn from the failure, not to generate a favorable statistic of closed cases.

Related concepts

On the blog

References

  1. Official State Gazette. Law 31/1995, on Occupational Risk Prevention. Consolidated text. Official source
  2. Official State Gazette. Royal Decree 39/1997, Regulations for Prevention Services. Consolidated text. Official source
  3. Occupational Safety and Health Administration. Recommended Practices for Safety and Health Programs: Program Evaluation and Improvement. Official source

Editorial information

Publication date: October 10, 2026.

Editorial Manager: Sabentis Editorial Team.

Author: Pablo Rodríguez LinkedIn

Executive Vice President of the ORP International Foundation and Chief Financial Officer of Sabentis.

Request a Demo

Discover all that Sabentis can do for your organization.

Try Sabentis

request a demo
stars 5
GetApp Software Advice Capterra