Investigating reports and noncompliance
An impartial investigation procedure, with documented conclusions and actions proportionate to severity.
Nonconformity and corrective action
When noncompliance occurs, identify the root cause and implement the corrective action with an effectiveness check.
Continual improvement
Updating the risk map and controls based on what each investigation teaches.
What an auditor usually asks for
- An investigation log with documented conclusions
- Disciplinary or corrective actions proportionate to each case
- Effectiveness verification of corrective actions
- An updated risk map after every significant noncompliance
How to cover improvement in Kimobox
- 1Manage every report investigation with its conclusion and linked action in Kimobox.
- 2Log the corrective action for each noncompliance with its owner and date.
- 3Update the compliance risk map after every significant noncompliance.
Every investigation stays linked to its conclusion, its action and the risk-map update it triggered.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- ISO 37301:2021 — Compliance management systems. Requirements with guidance for use ISO · April 2021
- Ley 2/2023 on the protection of persons who report regulatory breaches BOE-A-2023-4513 · 21 February 2023
- ISO 37001:2016 — Anti-bribery management systems ISO · 2016 ed.