What the form covers
Containment before classification. That order is the form. The How to use tab explains what the form is and is not, why classification criteria stay in your own procedure, and the failure modes: conclusions instead of observations, containment with no scope check, use-as-is with no recorded justification, closure with the CAPA cross-reference left blank. The NC Report tab walks one event through six blocks. The Worked Example tab shows a completed incoming-inspection find on a generic machining line — a concrete answer to what counts as sufficient evidence in each block.
- Identification — NC ID and source, what, where, when, found by, quantity affected
- Description with an evidence column, tied to the specific requirement the item fails
- Containment with a scope check on neighbouring lots, orders, and delivered product
- Disposition — use as is, rework, scrap, or return to supplier — with justification and approval rows
- Closure with the CAPA cross-reference, and a trend row that counts repeats
The form is not the investigation
The NC report documents the event and the disposition. It is deliberately not the investigation: root cause analysis and corrective action continue in your CAPA system, and the form's closure block cross-references that record rather than duplicating it. For the root-cause step itself, use our 5-Whys root cause analysis worksheet. For structuring a full investigation from intake to closure, use the deviation investigation checklist. This form sits upstream of both — it is the record that captures the event, holds the product, and carries the disposition decision and its approvals.
One row earns special mention: the trend count. A site that dispositions the same nonconformance every month, one defensible report at a time, has a system that works on paper and fails in aggregate — the trend row exists so the repeat pattern is visible on the form itself, not only in an annual review.
Classification, disposition, and the regulatory frame
The classification row deliberately carries no severity definitions. What counts as minor, major, or critical — and what each classification triggers — belongs to your site's own procedure, and inventing a second scale inside a form is how sites end up arguing with their own paperwork. The form records the classification result and the procedure it came from, nothing more.
Control of nonconforming product is a core quality system requirement — ISO 13485:2016 clause 8.3 (control of nonconforming product) requires nonconforming product to be identified and controlled to prevent its unintended use or delivery, and the FDA requirement historically stated in 21 CFR 820.90 (nonconforming product), carried forward under the QMSR through its incorporation of ISO 13485, does the same. Neither mandates a form layout; what they require is that nonconformities are documented, evaluated, and dispositioned under a defined procedure. Adapt this form to yours and have QA approve the adapted version. The questions that come first under audit: was affected product contained, was anything already delivered, and if you used it as-is, who authorised that.




