Form

Nonconformance report template

A per-event form for nonconforming product: what was found, the requirement it fails, what was done immediately, and what happens to the item — with the decision trail attached.

A nonconformance report has one job: make the disposition defensible later. This form structures that — an identification block for what, where, when, and who found it; a description tied to the requirement it fails and the evidence; containment with a scope check; a classification row that points at your own procedure's criteria instead of inventing new ones; a disposition block with justification and approval; and a closure row that counts repeats, because the report's quieter second job is noticing when disposition-and-move-on has stopped being enough.

Free · Excel workbook · unlocks in seconds
Explore CAPA & Deviations
Nonconformance report template — the Excel workbook you download, showing the worked incoming-inspection example

What the form covers

Containment before classification. That order is the form. The How to use tab explains what the form is and is not, why classification criteria stay in your own procedure, and the failure modes: conclusions instead of observations, containment with no scope check, use-as-is with no recorded justification, closure with the CAPA cross-reference left blank. The NC Report tab walks one event through six blocks. The Worked Example tab shows a completed incoming-inspection find on a generic machining line — a concrete answer to what counts as sufficient evidence in each block.

  • Identification — NC ID and source, what, where, when, found by, quantity affected
  • Description with an evidence column, tied to the specific requirement the item fails
  • Containment with a scope check on neighbouring lots, orders, and delivered product
  • Disposition — use as is, rework, scrap, or return to supplier — with justification and approval rows
  • Closure with the CAPA cross-reference, and a trend row that counts repeats

The form is not the investigation

The NC report documents the event and the disposition. It is deliberately not the investigation: root cause analysis and corrective action continue in your CAPA system, and the form's closure block cross-references that record rather than duplicating it. For the root-cause step itself, use our 5-Whys root cause analysis worksheet. For structuring a full investigation from intake to closure, use the deviation investigation checklist. This form sits upstream of both — it is the record that captures the event, holds the product, and carries the disposition decision and its approvals.

One row earns special mention: the trend count. A site that dispositions the same nonconformance every month, one defensible report at a time, has a system that works on paper and fails in aggregate — the trend row exists so the repeat pattern is visible on the form itself, not only in an annual review.

Classification, disposition, and the regulatory frame

The classification row deliberately carries no severity definitions. What counts as minor, major, or critical — and what each classification triggers — belongs to your site's own procedure, and inventing a second scale inside a form is how sites end up arguing with their own paperwork. The form records the classification result and the procedure it came from, nothing more.

Control of nonconforming product is a core quality system requirement — ISO 13485:2016 clause 8.3 (control of nonconforming product) requires nonconforming product to be identified and controlled to prevent its unintended use or delivery, and the FDA requirement historically stated in 21 CFR 820.90 (nonconforming product), carried forward under the QMSR through its incorporation of ISO 13485, does the same. Neither mandates a form layout; what they require is that nonconformities are documented, evaluated, and dispositioned under a defined procedure. Adapt this form to yours and have QA approve the adapted version. The questions that come first under audit: was affected product contained, was anything already delivered, and if you used it as-is, who authorised that.

Frequently asked questions

Is a nonconformance the same as a deviation?

The vocabularies differ by tradition more than the concepts do. Manufacturing and medical device quality systems usually say 'nonconformance' for product or output that fails a requirement; pharmaceutical quality systems usually say 'deviation' for a departure from an approved procedure or instruction. Many sites use both terms with a defined boundary between them. What matters is that your own procedure defines the boundary and the handling for each — not which label a template uses.

Why doesn't the template define minor, major, and critical?

Because classification criteria — and what each classification triggers — belong to your site's own procedure, and a form that carries its own severity scale will eventually contradict it. Inventing a second scale is how sites end up arguing with their own paperwork during an audit. The form records the classification result and a reference to the procedure it came from; the criteria live in one place, yours.

Does every nonconformance need a CAPA?

No. Escalation to CAPA is a risk-based decision made under your own procedure — severity, recurrence, and trend all feed it. The form supports the decision either way: the closure block cross-references the CAPA record when one is raised, and the trend row counts repeats — because a nonconformance that keeps coming back, dispositioned defensibly every time, is the strongest signal that disposition alone has stopped being enough.

Bring a closed NC

Take one report into a demo and walk the three questions inspectors ask first: was product held, was anything delivered, and if you used it as-is, who authorised that.