Glossary Term

Nonconformance

A requirement not met — the segregation, disposition, and escalation discipline that follows.

Nonconformance and deviation get used interchangeably and mean different things. Getting the distinction right is the difference between a clean investigation and a confused one.

Nonconformance handling showing a flagged product item with three disposition paths — rework, use-as-is, and reject — and a CAPA scroll
On this page
  1. Definition
  2. Why It Matters
  3. Regulatory Context
  4. In Practice
  5. Key Controls
  6. Complere Approach
  7. Related Terms

What a nonconformance is

A nonconformance (or nonconformity) is the non-fulfilment of a requirement — a product, material, process, or record that does not meet its specification, procedure, or regulatory expectation. The classic case is nonconforming material: a component, in-process material, or finished unit that fails a spec and must be dispositioned — for example use-as-is (concession), rework, regrade, or reject (see the five disposition options below).

In device GMP it is anchored in 21 CFR §820.90 (control of nonconforming product) and ISO 13485 §8.3; the FDA QMSR (effective 2 February 2026) carries the same expectation through the ISO clause. The defining features are consistent: identify it against the specific requirement it failed, segregate it so it can't be used unintentionally, document the disposition decision with justification, and decide whether a CAPA is warranted for the underlying cause.

The term sits within a family of overlapping concepts — deviation, nonconformance, defect, out-of-specification, quality event — that different quality systems slice differently. What matters is not the label but that your QMS defines the boundaries clearly and routes each event type consistently, because the routing determines the rigour applied.

Nonconformance vs Deviation vs Out-of-Specification

DimensionNonconformanceDeviationOut-of-Specification
Primary scopeProduct, process, system failing to meet requirementDeparture from approved procedureLab result outside specification
Authoritative referenceISO 13485 §8.3, 21 CFR §820.90EU GMP Ch.1 §1.4(xiv), 21 CFR §211.100FDA OOS Guidance 2006, 21 CFR §211.165(f)
Industry primarily affectedMedical device (most prominent)Pharmaceutical (most prominent)Pharma QC labs
Segregation requiredYes — physical + systemicSometimes — if material affectedYes — affected lot held
Investigation depthRisk-scaled per §8.3.1 / §820.90(b)Justification required; planned dev. needs prospective approvalTwo-phase — lab then full
Disposition optionsReject / rework / accept-by-concession / regrade / releaseContinue with rationale or hold materialRelease / reject / further investigation
Nonconformance vs deviation

A deviation is a departure from an approved procedure or process — often caught as it happens, and the dominant term in pharma GMP. A nonconformance is a requirement not met, classically about product or material against a spec — the ISO and device-industry vocabulary. They overlap heavily, the terms blur in practice, and the healthy answer is that your QMS defines which is which and applies the right process to each — not that you pick the 'correct' word.

Why the distinction is worth getting right

Mislabelling drives bad routing, and bad routing is where quality systems leak. Call a genuine process deviation a 'nonconformance' and you may skip the root-cause investigation it needed, treating a systemic problem as a one-off material disposition. Treat every nonconforming unit as a full deviation investigation and you bury the quality unit in process, slowing release and breeding shortcuts. Inspectors notice both patterns.

Control of nonconforming product (§820.90) and review/disposition decisions are recurring inspection topics, and the findings cluster around predictable gaps: nonconforming material not segregated, so it risks unintended use; use-as-is dispositions granted without adequate justification or the right authority; rework performed without a procedure or without re-inspection; and — the systemic one — repeated nonconformities of the same type never escalated to a CAPA, so the cause is never addressed and the disposition treadmill runs forever.

The healthy pattern is a defined intake that classifies the event, applies proportionate rigour, records the disposition with justification and the approving authority, and escalates to CAPA when the cause — not just the instance — needs systemic action. Trend analysis across nonconformities is itself an expectation: a string of individually-dispositioned events that are never read together is a missed signal.

Inspector perspective: “Show me the last five nonconformances for [named product family]. For each, show me the disposition decision and the rationale for whether or not it escalated to CAPA. Then show me the most recent CAPA that originated from a nonconformance and walk me through the effectiveness check.” The records together let the inspector confirm that nonconformances are being detected, dispositioned with documented rationale, and escalated appropriately — and that CAPAs born from nonconformances reach effectiveness verification. A pattern of dispositions without CAPA escalation despite recurrence is the most-commonly-found deficiency.

Where the requirements live

The regulatory framework spans device, drug, and ISO standards:

  • 21 CFR §820.90(a) — control of nonconforming product: identification, documentation, evaluation, segregation, and disposition
  • 21 CFR §820.90(b) — nonconformity review and disposition; evaluation shall include the need for an investigation
  • ISO 13485:2016 §8.3.1 — general nonconforming-product control framework
  • ISO 13485:2016 §8.3.2-§8.3.4 — actions before/after delivery, rework processes, regulatory-authority notification for reportable events
  • 21 CFR §211.192 — investigation of unexplained discrepancies and batch/component failure to meet specifications
  • 21 CFR §211.165(f) — failure of drug products to meet specifications
  • EU GMP Chapter 5 §5.62-§5.65 — handling of rejected and recovered materials
  • EU GMP Chapter 8 — complaints and product recall, intersecting with post-distribution nonconformance handling
  • ISO 9001:2015 §8.7 — control of nonconforming outputs (general QMS framework)
  • ICH Q9(R1) Quality Risk Management — framework for proportioning investigation depth and escalation criteria to risk
  • ICH Q10 §3.2.2 — CAPA system requirements that interface with nonconformance handling
  • FDA OOS Guidance (2006) — two-phase laboratory-then-full investigation framework

From detection to disposition

A workable nonconformance flow runs from detection to closure with a record at every step:

Detect and describe. Capture the nonconformity against the specific requirement it failed — not a vague “material rejected,” but which spec, which limit, what was observed, when, by whom, and which lots/units are potentially affected. Vague descriptions undermine every downstream decision.

Segregate. Flag or physically separate the affected material or record so it cannot be used or shipped unintentionally while under evaluation. Segregation needs both physical (material in a designated hold area) and systemic (inventory-system block) components. Unsegregated nonconforming product is a top finding.

Assess impact. One unit, a batch, or a trend? Does it affect other lots, products, or sites that share the cause? The impact assessment scopes the response and is performed by Quality with input from the originating function, reviewed against escalation criteria before disposition.

Disposition with justification. Use-as-is (with a documented concession and the right authority), rework (to a procedure, with re-inspection), repair, scrap, regrade, or return. Record the decision, the rationale, and who approved it. Release dispositions that reverse the original detection get the deepest inspector scrutiny.

Decide on CAPA. Determine whether the underlying cause needs systemic correction or prevention. A correctly-dispositioned one-off may not; a recurring or systemic nonconformance should escalate, with the judgement documented either way. And periodically, trend the nonconformities to surface the patterns single events hide — by product, process step, supplier, failure mode.

What strong nonconformance handling shares

Programs that handle nonconformities cleanly — and pass inspection on §820.90 / §8.3 — share these controls:

The disposition that should have been a CAPA

The most expensive nonconformance pattern is the one handled perfectly, every time, forever — each instance correctly identified, segregated, and dispositioned, but never escalated to address why it keeps happening. Inspectors read the trend the quality unit didn't. Defined escalation criteria, plus a periodic trend review, are what turn a disposition treadmill into a closed loop.

  • Defined intake and classification — clear boundaries between deviation, nonconformance, OOS, and complaint, with consistent routing
  • Enforced segregation — nonconforming material flagged AND systemically blocked, so unintended use is prevented not just discouraged
  • Requirement-specific descriptions — every nonconformity stated against the spec or procedure it failed
  • Authority-gated dispositions — use-as-is and concessions require the right role to approve, with justification
  • Procedure-controlled rework — rework to a defined procedure with re-inspection and records
  • CAPA escalation criteria — defined rules for when an instance becomes a systemic action, applied consistently
  • Trend analysis — nonconformities read together on a cadence, not only handled one at a time
  • Full traceability — each event linked to its material/batch, its disposition, and any resulting CAPA
  • Effectiveness verification on CAPAs — closing the loop between detection and demonstrated improvement
  • Periodic management review of the programme itself — escalation rate, disposition pattern, defensibility

How Complere handles nonconformities

Complere's quality-event framework handles nonconformance, deviation, and OOS as distinct workflow types with shared infrastructure for evidence capture, approval routing, escalation, and CAPA linkage. The taxonomy is configurable — firms operating in pharma-only, device-only, or combined scopes can set the workflow types and routing rules that match their regulatory landscape.

The nonconformance workflow captures: detection record with evidence attachments, segregation record with named location and quantity, assessment record with multi-role review, disposition decision with named approver and electronic signature, and the CAPA-escalation determination with documented rationale. Each stage carries the immutable, time-stamped audit trail — database-enforced — attached to every Complere record — the evidence chain an inspector traces.

CAPA escalation is a recorded decision point in the workflow: when the review criteria are met — for example a recurring failure mode, or a severity threshold that warrants QA review — a CAPA is created with linkage back to the originating nonconformance. The CAPA then drives root-cause investigation, corrective action, preventive action, and effectiveness check — closing the loop the inspector wants to see.

Trending views aggregate quality-event data for management review and ICH Q10 §3.2.2 effectiveness review. What Complere does not currently provide is real-time inventory segregation tied to an external WMS — the systemic segregation block lives in the operational system (ERP/WMS), with the nonconformance record in Complere holding the QA decision and approval evidence. Firms with substantial inventory scope typically integrate Complere with their ERP/WMS so the QA hold flag triggers the inventory-system block automatically.

Frequently asked questions

Common questions about Nonconformance sourced from regulatory references and inspection patterns.

What criteria determine whether a nonconformance escalates to CAPA?

Four criteria commonly drive escalation: (1) recurrence — same failure mode seen before within a defined window (typically 90 or 180 days); (2) severity — high-risk implications for patient/user safety, product quality, or regulatory compliance; (3) scope — affects a large quantity, multiple lots, or a systemic process element; (4) trend — multiple low-severity events of similar type aggregate into a pattern. ISO 13485 §8.3.1 and 21 CFR §820.100 interface here: the assessment must determine the need for further investigation.

What does the segregation requirement actually require operationally?

Segregation under ISO 13485 §8.3.1 and 21 CFR §820.90(a) requires both physical segregation (material moved to a designated QA hold zone, tagged) and systemic segregation (inventory status in ERP/MES blocked from picking, shipping, or production use). Physical-only is brittle — staff can still pick from a labelled bin if the system shows availability. Systemic-only is brittle — overrides and bugs release holds. Inspectors confirm both by reviewing the segregation record alongside inventory transactions for the affected lot.

What disposition options are available, and what governs the choice?

Five options under ISO 13485 §8.3 and 21 CFR §820.90: reject (destroyed or returned to supplier), rework (under a documented procedure with re-verification), accept-by-concession (documented justification, customer notification where required, risk acceptance signoff), regrade (reclassified for different intended use), or release (assessment concludes the originally-suspected failure does not actually breach specification). Rework requires the rework procedure to provide equivalent quality assurance to the original process; accept-by-concession requires patient/user risk evaluation.

Who has the authority to disposition a nonconformance, and what evidence supports the signoff?

Disposition authority is defined in the nonconformance SOP and follows a risk-tiered model: low-risk dispositioned by QA at analyst or supervisor level; moderate-risk requires QA management signoff; high-risk requires QA + functional management (Manufacturing, Regulatory) + senior management signoff. Supporting evidence includes the assessment record, the risk analysis, the rationale for the chosen disposition versus alternatives, and any external inputs (supplier acknowledgement, customer concurrence). Electronic signature with role-based routing enforces the authority model.

How is a nonconformance different from a deviation?

A deviation is a departure from an approved procedure or batch record during a controlled process execution — typically planned (approved before execution) or unplanned (captured during or after). A nonconformance is broader: product failing inspection, process failing validation, supplier material failing incoming inspection, system failing validation — including cases where no procedure was being followed. Pharma manufacturing tends to use 'deviation' prominently; medical-device manufacturing uses 'nonconformance' prominently. Strong systems document the classification framework and apply it consistently.

How does OOS investigation differ from nonconformance investigation?

OOS investigation has its own two-phase framework under FDA's 2006 OOS Guidance: Phase I laboratory investigation (was the result caused by laboratory error?); Phase II full investigation if Phase I is inconclusive (extends to manufacturing, raw materials, in-process controls). The OOS finding is narrow (one test, one lot); a nonconformance investigation under §820.90(b) is broader. A confirmed Phase II OOS typically generates a nonconformance for the affected lot that follows the standard pathway.

What's a defensible handling pattern for recurring nonconformances of the same type?

Recurring nonconformances are the strongest single CAPA-escalation trigger. Defensible pattern: (1) first occurrence — full assessment and disposition; (2) second occurrence within a defined window — assessment evaluates whether the original disposition was effective and explicitly considers CAPA escalation, documenting the decision; (3) third occurrence — CAPA escalation is essentially mandatory; (4) the CAPA investigation extends beyond the original detection to address the systemic cause. Inspectors routinely flag logs where the same failure mode appears 3+ times with no CAPA linkage.

How are customer complaints handled in relation to the nonconformance framework?

Customer complaints flow through complaint handling (ISO 13485 §8.2.2; under the QMSR, §820.35 Control of Records) first. Where a product nonconformance is confirmed, a nonconformance record is opened with linkage back to the complaint. The two workflows share assessment evidence and CAPA outcomes. For reportable adverse events under medical-device scope, ISO 13485 §8.3.3 and 21 CFR §803 (Medical Device Reporting) impose regulatory-notification timelines — typically 30 days for a death, serious injury, or malfunction, and 5 days for an event requiring remedial action to prevent an unreasonable risk of substantial harm — which the workflow must enforce.

About the author

Complere Reference Team

Compliance and quality-systems specialists maintaining the Complere glossary for regulated quality, validation, and inspection-readiness teams. Entries are reviewed against current FDA, MHRA, EMA, ICH, and PIC/S guidance.

Continue Exploring

Explore related topics, modules, and compliance resources for a deeper understanding of your quality system.

CAPA and deviations
Related

CAPA & Deviations

Explore this topic in more depth to build a complete picture of your quality and compliance operations.

Explore
Deviation
Related

Deviation

Explore this topic in more depth to build a complete picture of your quality and compliance operations.

Explore
Slow CAPAs are a QMS architecture problem
Related

Why Your CAPAs Are Slow — It's the Architecture

Explore this topic in more depth to build a complete picture of your quality and compliance operations.

Explore

See nonconformance handled in a governed workflow

Walk through how nonconformities flow from detection to disposition to CAPA escalation with full audit trail across Complere's quality-event workflows.