Most audits don’t fail because a business is “bad”. They fail because the basics aren’t controlled.

And the frustrating bit? It’s usually the same handful of issues, again and again.

Here are the **top 10 nonconformities we see in SMEs** (across security, construction, cleaning, manufacturing — the lot) — plus the straight-talking fixes that get you back in control fast.

## 1) Document control is a mess (wrong versions in use)

**What auditors see:** procedures with no version/date, staff using old templates, multiple copies in different folders.

**Fix (fast):**
– one source of truth (one controlled folder)
– version + date on every controlled document
– archive old versions so they can’t be used by mistake

## 2) No evidence of competence/training

**What auditors see:** “We trained them” but no sign-offs, no matrix, no refresh dates.

**Fix (fast):**
– simple training matrix (role vs required training)
– keep sign-off sheets or digital records
– set refresh dates for critical roles

## 3) Corrective actions don’t fix root cause

**What auditors see:** “fixed” actions that don’t stop the issue repeating.

**Fix (fast):**
– write the root cause in one sentence
– add a prevention step (not just a patch)
– verify effectiveness after 30–60 days

## 4) Internal audits are missing or poor quality

**What auditors see:** audits not done, or tick-box audits with no findings.

**Fix (fast):**
– schedule audits quarterly (minimum)
– audit processes, not paperwork
– record findings + actions + follow-up

## 5) Management review isn’t happening (or has no outputs)

**What auditors see:** no meeting, or a meeting with no decisions, no actions, no evidence.

**Fix (fast):**
– one agenda template
– record decisions + actions + owners
– review KPIs, complaints, audits, risks, objectives

**Infographic placement:** Insert “Top 10 Audit Nonconformities in SMEs (Part 1)” after the intro, and “Part 2” after point 5.

## 6) Risks and opportunities aren’t controlled

**What auditors see:** risk assessment exists, but it’s generic and never updated.

**Fix (fast):**
– keep one live risk register
– update it when changes happen (new contract, new site, new supplier)
– assign owners and review dates

## 7) Calibration/maintenance records are missing

**What auditors see:** equipment used for measuring/testing with no calibration or maintenance evidence.

**Fix (fast):**
– list critical equipment
– set calibration/maintenance dates
– store certificates/records in one folder

## 8) Supplier/subcontractor control is weak

**What auditors see:** subcontractors used with no checks, no approvals, no monitoring.

**Fix (fast):**
– approved supplier list
– minimum checks (insurance, competence, accreditations)
– review performance annually

## 9) Objectives exist but aren’t measured

**What auditors see:** objectives like “Improve quality” with no metric, no target, no review.

**Fix (fast):**
– set 3–5 measurable objectives
– track monthly (simple dashboard)
– link actions to results

## 10) Records are incomplete or impossible to retrieve

**What auditors see:** evidence exists “somewhere” but can’t be found quickly.

**Fix (fast):**
– standard naming convention
– one folder per process
– monthly/quarterly subfolders

## The quickest way to stop nonconformities coming back

If you want a simple rule:

**Control the system, and the audit takes care of itself.**

That means:
– controlled documents
– controlled records
– controlled actions
– controlled reviews

## How CAW helps

We don’t do corporate fluff. We build audit-ready systems that staff actually use — and we keep them simple.

## CTA

If you want us to sanity-check your system before your next audit, message us. We’ll tell you what’s missing, what’s overkill, and what to fix first.

Leave a comment

I’m Craig

Meet Craig Willetts

Welcome to the ISO and Compliance Blog, I have spent over 20 years in compliance specialising in accreditation and business growth, I own a number of compliance related businesses including CAW Consultancy, Global ISO Services, CAW Digital, Screen my staff and fusion consultancy worldwide and this blog is designed to help SME’s on their journey to top notch compliance, any questions feel free to drop me an email at Craig@CAWConsultancy.co.uk

Let’s connect