opwise.ai
May 15, 2026 · Opwise

How to Write a Nonconformance Report That Actually Holds Up

A step-by-step guide to writing nonconformance reports (NCRs) that satisfy ISO 13485, 21 CFR Part 820, and ISO 9001 auditors — and actually help you fix the problem.

A nonconformance report is not a punishment form. It is not a blame document. And it is definitely not something you fill out just to satisfy an auditor.

A well-written NCR is a factual record of what happened, what you did about it, and what you decided. When it’s done right, it protects you in an audit, gives your quality team the data they need to spot patterns, and creates a clean handoff if the problem turns out to need a CAPA.

When it’s done wrong — vague descriptions, missing disposition rationale, no containment record — it becomes the exhibit an auditor reads aloud in an observation. And it becomes the reason your CAPA team spends two hours reconstructing what actually happened six months ago.

This guide walks through how to write an NCR that does its job.


What an NCR is required to capture

Before you open a blank form, it helps to know what the regulations actually require.

ISO 13485:2016 §8.3 requires that your organization identify, document, and control nonconforming product. It requires procedures for review and disposition, and records of the nature of the nonconformity and any subsequent actions taken — including concessions obtained. Clause 8.3.3 extends this to post-delivery nonconformities: if a device ships and a nonconformance is discovered later, the same documentation obligations apply.

21 CFR Part 820 (now the QMSR, effective February 2, 2026, which incorporates ISO 13485:2016 by reference) requires procedures for identifying, documenting, evaluating, segregating, and disposing of nonconforming product. Rework must be documented in the Device History Record.

ISO 9001:2015 §8.7 requires that nonconforming outputs be identified and controlled to prevent unintended use or delivery, with documented information describing the nonconformity, the actions taken, and any concessions obtained.

The common thread: identification, documentation, disposition, and records. Your NCR needs to satisfy all four.


The six fields that matter most

Every NCR form looks a little different, but the fields below are the ones that determine whether your record holds up. If your current form doesn’t have all six, that’s worth fixing before your next audit.

1. A clear, specific description of the nonconformance

This is where most NCRs fall apart.

“Part out of spec” is not a description. “Dimensional nonconformance on Part #A4421-Rev3, OD measured 12.47mm against a specification of 12.50mm ± 0.02mm, on Work Order 2024-0813, Lot 44B” is a description.

The description should answer: What failed, where (part number, lot, work order, operation), how much (quantity affected), and against what requirement (specification, drawing revision, procedure). If the nonconformance was detected during an inspection step, note which step.

Specificity matters for two reasons. First, it makes the disposition decision defensible. Second, it makes trend analysis possible. If you’re logging “dimensional issue” across 40 NCRs, you can’t tell whether you have one recurring problem or 40 different ones.

2. The defect code or nonconformance category

Most quality systems include a defect code library — a controlled list of nonconformance categories (dimensional, visual, functional, documentation, process deviation, and so on). Assign one.

Defect codes are what turn your NCR log into a Pareto chart. Without them, you have a list of incidents. With them, you have data.

If your organization doesn’t have a defect code library, building one is a half-day project worth doing.

3. Containment actions and results

Before you decide what to do with the nonconforming product, you need to know how much of it exists and where it is.

Containment means checking every location where affected product could be: the production floor, the inspection queue, finished goods, in-transit inventory, and — if the nonconformance is post-delivery — at customer sites.

Document each location checked, who checked it, when, and how many units were found. If you found nonconforming units at an external location (a customer, a distributor, a downstream manufacturer), that triggers a notification obligation. Record that notification — who was contacted, when, and what was communicated.

Containment is not optional. ISO 13485:2016 §8.3 and 21 CFR Part 820 both require that nonconforming product be segregated where practicable to prevent unintended use. “We checked and found nothing” is a valid containment record. “We didn’t check” is not.

4. Disposition decision and rationale

Disposition is the formal decision about what happens to the nonconforming product. The standard options are:

  • Rework: bring the product into conformance through additional processing. Rework instructions must be documented and the reworked product re-inspected.
  • Scrap: destroy or render the product unusable. Record the quantity scrapped.
  • Sort: inspect the lot unit by unit to separate conforming from nonconforming. Record the sort criteria and what happens to the rejects.
  • Return to vendor: for purchased material. Record the quantity returned and the supplier notification.
  • Use-as-is (concession): accept the nonconforming product as-is, with documented justification that it still meets safety and functional requirements. Under ISO 13485:2016 §8.3.2, use-as-is is only permitted with authorization from a relevant authority — and, where applicable, the customer. This decision requires a written justification, not just a signature.

The disposition field is where many NCRs are weakest. “Scrapped” with no quantity. “Use-as-is” with no justification. These are the records that generate observations.

Write the rationale. If you’re accepting product under concession, explain why it still meets the intended requirement. If you’re scrapping, note the quantity. If you’re reworking, reference the rework procedure or instructions.

5. Disposition execution record

Deciding to rework is not the same as reworking. Your NCR record needs to show that the disposition was carried out — who did it, when, and (for rework) that the product passed re-inspection.

For rework specifically, 21 CFR Part 820 requires that rework and re-evaluation activities be documented in the Device History Record. If your NCR system links to your DHR, make sure that link is explicit.

6. CAPA escalation decision

Not every nonconformance needs a CAPA. A one-time operator error on a low-risk characteristic, caught in-process and scrapped, probably doesn’t warrant a full corrective action investigation.

But your NCR record should document the escalation decision either way. “No CAPA required — isolated incident, no recurrence in prior 12 months, low risk characteristic” is a defensible record. Silence is not.

When a CAPA is warranted — recurring nonconformance, systemic process failure, customer complaint, audit finding — the NCR becomes the origin record for the CAPA. Make sure the link is explicit and traceable.


The containment step most teams skip

Here’s the one that gets manufacturers in trouble most often: external containment notification.

If nonconforming product has left your facility — shipped to a customer, sent to a contract manufacturer, distributed to a warehouse — you have an obligation to notify the affected parties. ISO 13485:2016 §8.3.3 is explicit: when nonconformity is detected after delivery, the organization must take action appropriate to the effects of the nonconformity.

That action needs to be documented. Who was notified, when, what they were told, and what response was received. If the product is a medical device and the nonconformance could affect safety or performance, you may also have MDR (Medical Device Reporting) obligations under 21 CFR Part 803 or EU MDR (Regulation 2017/745) Article 87.

The NCR is not the place to make that regulatory determination — that belongs in your complaint handling and vigilance procedures. But the NCR should flag that external notification was required and record that it happened.


What makes an NCR audit-ready

An auditor reviewing your NCR log is looking for a few things:

Completeness: Every open NCR has a disposition. Every disposition has a rationale. Every rework has an execution record and re-inspection result.

Timeliness: NCRs are opened promptly when nonconformances are detected, not days later. Disposition decisions are made within a reasonable timeframe — not sitting in “pending” for weeks.

Traceability: You can trace from the NCR back to the lot, work order, and inspection record. You can trace forward to the CAPA if one was opened.

Trend visibility: Your NCR log, when filtered by defect code, part family, or work center, tells a story. If it doesn’t — if every NCR is a one-off with no pattern — that’s either a sign your defect codes are too granular or your process is genuinely stable. Either way, you should be able to show the analysis.

Segregation evidence: Nonconforming product was physically identified and separated from conforming product. A tag, a quarantine location, a system status — something that shows the product couldn’t accidentally ship.


A practical template for the description field

If you’re staring at a blank NCR and not sure how to start the description, this structure works:

[Part/Document/Process] [identifier and revision] failed to meet [specific requirement] by [magnitude or nature of deviation]. Detected at [operation/inspection step] on [date]. Quantity affected: [n] units from [lot/work order].

For example:

Gasket assembly P/N 8821-B Rev 4 failed leak test at final inspection (Step 7, Procedure QP-044 Rev 2): measured leak rate 0.08 mL/min against a maximum allowable of 0.05 mL/min. Detected 2026-04-14. Quantity affected: 12 units from Lot 2026-0412-C.

That description gives the disposition team everything they need. It gives the CAPA team a starting point if escalation is needed. And it gives an auditor a record they can read without asking follow-up questions.


Where to go from here

If your NCR process is paper-based or running on a spreadsheet, the single highest-leverage change you can make is moving to a system that enforces required fields at the point of entry — before the form is saved, not after the auditor finds the gap.

Required fields prevent the “disposition: TBD” problem. Defect code libraries make trend analysis automatic. Containment checklists ensure external zones get checked, not just the production floor. And a clear escalation path from NCR to CAPA means the decision gets made and documented, not deferred.

If you’re evaluating how your current NCR process stacks up against ISO 13485:2016 §8.3 or 21 CFR Part 820 requirements, start with your last 20 closed NCRs. Check each one for the six fields above. The gaps you find are your improvement roadmap.

Opwise’s quality management system includes a structured NCR workflow — containment zone checks, disposition with e-signature for use-as-is concessions, and a direct link to CAPA when escalation is needed. If you’d like to see how it works, request a demo.