Skip to main content

Corrective Measures

Actions to remove causes of identified non-conformities and prevent recurrence.

A corrective measure, in ISO terms a corrective action, removes the cause of a non-conformity or incident so that it does not happen again. It is not the same as fixing the problem itself. ISO 9000 separates the two: a correction eliminates the non-conformity you found, and a corrective action eliminates its cause.

An example. An internal audit finds that three people who left last quarter still have access to the CRM. Removing their accounts is the correction. Finding that the leaver process never notifies IT, and changing it so that it does, is the corrective action. Checking three months later that everyone who left since then lost access on time is how you show it worked.

What ISO 27001 requires

Clause 10.2 requires you to react to a non-conformity and to evaluate whether action is needed to remove its cause: review it, determine the cause, and check whether similar non-conformities exist or could occur. Then implement the action, review its effectiveness, and change the management system if necessary. Corrective actions have to be appropriate to the effects of the non-conformity, and you keep documented evidence of what happened, what you did and the result.

Corrective or preventive

Older editions also had a separate requirement for preventive action, taken before anything went wrong. ISO 27001:2013 and ISO 9001:2015 dropped it, because the risk assessment now does that job: preventing a problem that has not happened yet is risk treatment, and removing the cause of one that has is corrective action.

Frequently asked questions

What is the difference between a correction and a corrective action?
A correction fixes the problem you found; a corrective action removes its cause so that it does not happen again. ISO 9000 defines both, and ISO 27001 clause 10.2 asks for the correction and, where the evaluation shows it is needed, a corrective action.
What does ISO 27001 require for corrective actions?
Clause 10.2: react to the non-conformity, determine its cause, check whether similar ones exist or could occur, implement the action, review its effectiveness, and keep documented evidence of the non-conformity, the action and the result.
Is preventive action still required?
Not as a separate requirement. ISO 27001:2013 and ISO 9001:2015 dropped it; preventing problems that have not happened yet is handled by risk assessment and risk treatment.