Responding to noncompliance
Investigating the root cause and applying a proportionate action, tracked through to closure.
Organizational learning
Updating the risk map and controls based on what each case teaches.
Continual system improvement
A periodic review of the compliance system's overall effectiveness, beyond isolated cases.
What an auditor usually asks for
- A noncompliance log with root cause and action
- An updated risk map after every significant case
- Evidence of continual system improvement
- Actions tracked through to closure
How to cover continual improvement in Kimobox
- 1Log every instance of noncompliance with its root cause and linked action in Kimobox.
- 2Update the compliance risk map after every significant case.
- 3Track every action through to closure and its effectiveness check.
Every instance of noncompliance stays linked to its cause, its action and the risk-map update it triggered.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- ISO 19600:2014 — Compliance management systems. Guidelines (withdrawn) ISO · Withdrawn
- ISO 37301:2021 — Compliance management systems. Requirements ISO · April 2021