OFI vs Nonconformity: How ISO 42001 Auditors Actually Draw the Line

OFI vs nonconformity in ISO/IEC 42001 audits — three finding types (conformity, nonconformity, opportunity for improvement), the four judgment criteria auditors apply (explicit requirement, evidence sufficiency, systemic vs isolated failure, repetition), and the response each demands: mandatory four-step corrective action for nonconformities, review-decide-record for OFIs

The judgment criteria auditors actually apply — and the right way to respond to each type of finding

Almost every organization that has been through an ISO certification audit asks some version of the same question afterwards: "The auditor kept distinguishing between 'nonconformities' and 'OFIs' — what exactly is the difference? And can we just ignore the OFIs?" This article explains how auditors actually draw that line in an ISO/IEC 42001 audit, and how to respond to each type of finding — from the perspective of audit practice, not the textbook.

The three possible outcomes of an audit finding

Everything an auditor examines resolves into one of three conclusions:

  • Conformity — the requirement is met; nothing further is demanded.
  • Nonconformity (NC) — a requirement of ISO/IEC 42001, or of the organization's own AI management system, is not met; corrective action is mandatory.
  • Opportunity for improvement (OFI) — the requirement is met, but there is room to operate more effectively or efficiently; acting on it is optional.

The obligation attached to each is what matters. A nonconformity must be corrected; an OFI must merely be considered — and confusing the two leads organizations to panic over OFIs, or to shelve them as if they carried no information at all.

What a nonconformity is

A nonconformity is a failure to meet a requirement — either one that ISO/IEC 42001 states explicitly, or one the organization has set for itself. That second half matters: if your procedure promises quarterly model monitoring and the records show it happening twice a year, that is a nonconformity even though the standard prescribes no frequency.

Major vs minor

Nonconformities are graded by severity, and the grade drives the consequences.

A major nonconformity is the complete absence of a required element, or a systematic failure that undermines the management system as a whole. Typical examples from ISO/IEC 42001 audits:

  • No AI risk assessment exists at all
  • No AI policy, or a policy top management never approved
  • No internal audit has ever been performed
  • Multiple minor nonconformities recurring in the same area — a pattern that adds up to systemic failure

A major nonconformity can hold up or, in a surveillance audit, suspend certification until it is resolved.

A minor nonconformity is a partial or isolated failure to meet a requirement. It does not directly threaten certification, but a corrective action plan and evidence of implementation are still mandatory. Typical examples:

  • An AI risk assessment exists, but some AI-specific risks are missing from it
  • Training records exist for most staff, with a few gaps
  • AI objectives are defined, but some lack measurable indicators
  • A supplier management procedure operates, but evaluation records are missing for some suppliers

If these look familiar, it is because they overlap heavily with the nonconformities most likely to appear in an ISO 42001 certification audit.

What an OFI is

An opportunity for improvement means the requirement is met — but the auditor sees a way the organization could meet it better. Three characteristics define it. It is not binding: declining to act on an OFI has no effect on certification, and no corrective action plan is owed. It is advice, not criticism: an OFI is the auditor applying experience gathered across many organizations to point out something yours could do better. And yet ignoring it still has a cost: an OFI that is simply filed and forgotten can resurface at the next audit — and what was advice last year can become a finding this year.

Typical OFIs in an ISO/IEC 42001 audit:

  • The AI risk assessment process is adequate, but tooling could make it more efficient
  • Internal audits run annually, but high-risk AI areas might warrant a semi-annual cycle
  • AI objectives are measured, but a dashboard would allow closer monitoring than periodic reports
  • Supplier evaluations happen, but more specific criteria would make them more consistent

How auditors draw the line

Four questions, applied roughly in order, decide most classifications.

1. Does the standard actually require it?

The first check is always whether ISO/IEC 42001 — or the organization's own documented system — explicitly requires the thing at issue. An explicit requirement not met is a nonconformity; a requirement that is met, with a better way visible, is an OFI. Auditors are trained to cite the specific clause a nonconformity is raised against — a finding that cannot be anchored to a requirement should not be written as one.

2. Does the evidence exist, and is it sufficient?

The next question is what the records show, and the pattern is consistent: a required activity that never happened is a nonconformity, likely major. An activity that happened but produced no record is still a nonconformity — in an audit, undocumented work effectively did not happen — though usually a minor one. Incomplete records fall to judgment: minor nonconformity or OFI depending on how material the gap is. Complete records with visible room to improve are OFI territory. (This is why the documentation an ISO 42001 audit expects to see is worth settling long before audit day.)

3. Systemic failure or isolated lapse?

A missing supplier management procedure is a failure of the system itself — plausibly a major nonconformity. One missing evaluation record out of ten suppliers is an isolated lapse — a minor nonconformity, or in some circumstances an OFI. The real question is whether the process is broken or merely imperfect.

4. Has this appeared before?

Repetition escalates. An OFI from the previous audit that was never even reviewed can return as a minor nonconformity; a minor nonconformity whose corrective action proved ineffective can return as a major one. Experienced auditors read the previous audit report before anything else — the prior findings are the first sampling plan.

Three situations from audit practice

Same gap, different verdicts

Consider the same observation in two organizations: the AI risk assessment contains no bias-related risks. For an organization running an AI-assisted recruitment system, that omission concerns its most significant high-risk exposure — a systematic failure to assess what most needed assessing, and a strong candidate for a major nonconformity. For an organization using AI only to classify internal documents, the same omission is still a gap, but its impact is limited — a minor nonconformity is the more likely outcome. Identical evidence, different classification, because the judgment runs through the organization's AI use context. It is also why a risk assessment that engages seriously with context — rather than recycling a generic register — holds up better under audit.

The OFI that became a nonconformity

First audit, recorded as an OFI: "AI objectives have indicators, but an annual monitoring cycle is too long for meaningful management — quarterly monitoring is recommended." Second audit, a year later, recorded as a minor nonconformity: "The monitoring cycle raised as an OFI at the previous audit remains annual, and there is no evidence the OFI was ever reviewed." The escalation was driven not by the monitoring cycle itself but by the absence of any review. An organization that had examined the OFI and documented a reasoned decision to keep annual monitoring would likely have faced no finding at all.

The borderline call

AI awareness training was delivered to all fifty in-scope staff; the attendance records are missing two signatures. One auditor writes it as a minor nonconformity — the requirement to train all staff is not fully evidenced. Another treats it as an OFI — the training demonstrably took place, and the lapse is administrative. Both positions are defensible, and borderline cases like this genuinely do land differently with different auditors. That variability is not a flaw to exploit; it is a reason to prepare so thoroughly that your evidence never sits on the borderline.

Responding to a nonconformity: four steps

Every nonconformity, major or minor, calls for the same sequence — the discipline ISO/IEC 42001 Clause 10 expects:

  • Correction — fix the immediate state: complete the missing record, finish the unfinished document.
  • Root cause analysis — establish why it happened. "We were busy" and "we didn't know" are not root causes; locate the point in the process where the failure originated.
  • Corrective action — change the process so the failure cannot simply recur; the action must address the root cause, not the symptom.
  • Effectiveness verification — confirm, with evidence, that the action worked. The same nonconformity resurfacing at the next audit is itself evidence that it did not — and auditors treat it exactly that way.

Where a major nonconformity is raised at an initial certification audit, the certification decision is typically held until a corrective action plan — and, depending on the certification body, evidence of implementation — has been submitted and reviewed; timeframes on the order of 30 days for the plan are common, though practice varies by certification body. At a surveillance audit, an unresolved major nonconformity can lead to suspension of the certificate. Minor nonconformities are generally closed by presenting completed corrective action evidence by the next audit.

Responding to an OFI: review, decide, record

The right response to an OFI is not automatic implementation — it is a conscious decision.

  • Review it. The AI governance owner, or management where warranted, examines what the OFI is actually pointing at.
  • Accept or decline it. Weigh circumstances, cost, and priorities. Declining is a legitimate outcome.
  • Record the decision. "Reviewed; not adopted at this time given current organizational scale and risk level" — with the reasoning — is a perfectly good record.

That record is what separates "the organization ignored the OFI" from "the organization considered it and decided" at the next audit. The first invites escalation; the second closes the topic.

A short checklist

  • ☐ Do documents and records exist for every ISO/IEC 42001 requirement — and does practice match them?
  • ☐ Have corrective actions from the previous audit's nonconformities been completed and verified?
  • ☐ Has every OFI from the previous audit been logged and reviewed?
  • ☐ Is there a recorded accept/decline decision, with reasons, for each OFI?
  • ☐ For accepted OFIs, is there an improvement plan with an owner?

Working through findings systematically is exactly what a well-run internal audit rehearses — our internal audit checklist covers how to classify and close out findings before an external auditor ever sees them.

The bottom line

A nonconformity is a mandatory fix; an OFI is an optional improvement that demands a conscious decision. Organizations that manage both systematically — correcting nonconformities at the root cause, reviewing OFIs on the record even when declining them — sustain a working AI management system between audits, not just during them. And it helps to remember what an audit is for: not a pass/fail examination, but a verification that the organization's AI governance actually works in practice. Seen that way, an OFI is not a blemish on the report — it is free, specific advice on where the system could go next.

Wondering how your AI governance would hold up under that lens? Our free AI governance readiness assessment takes about 10 minutes, requires no document uploads, and shows where you stand against ISO/IEC 42001 before an auditor does.

 


Related

🔍 What auditors find: the 5 nonconformities most likely to appear in your ISO 42001 audit.

Rehearse before the real thing: the ISO 42001 internal audit checklist, phase by phase.

📄 The paper trail: the 10 documents your certification audit will check.

🗺 The whole portfolio: part of our SC 42 AI Standards Map — the international AI standards portfolio, explained.