ISO27K

Disputing an ISO 27001 nonconformity with your certification body

Contest a finding at the closing meeting with evidence of conformity, then in writing if it stands. Every accredited certification body must run an appeals and complaints process under ISO/IEC 17021-1. Dispute the grading or the facts; a finding that is accurate is closed faster than it is argued.

Last reviewed 2026-10-01Written by Jacob Masse, TrazTech Inc.

Most ISO 27001 nonconformities are accurate, and the quickest way through one is the corrective action route on the nonconformity page. Some are not. An auditor misreads a scope statement, grades a documentation slip as a major, or raises a finding against a control you justified excluding in the Statement of Applicability. Those are worth contesting, because a major delays the certificate and stays on the record the next auditor reads.

This page covers how to do it without damaging a relationship that runs for a three-year cycle.

Which nonconformities are worth disputing?

Grounds for challenging an ISO 27001 finding
GroundExampleWorth contesting?
The facts are wrongThe auditor says no risk assessment was done this year; you have a dated one they did not seeYes. Produce it before the closing meeting ends
Wrong requirementA finding against an Annex A control your SoA excludes with a documented justificationYes, if the justification is sound
Outside the certified scopeA finding about a subsidiary or site the scope statement excludesYes. Point to the scope statement
Graded too highA single missed record raised as a major rather than a minorOften, if you can show the process works and this was isolated
You disagree with the auditor's preferenceThe auditor would have designed the control differentlyNo, unless the requirement itself is not met
The finding is accurate but inconvenientInternal audit was not completed before stage 2No. Close it

The grading line matters most. A major nonconformity is the absence or total breakdown of a requirement, or a situation that raises significant doubt the management system can achieve its intended results. A minor is a lapse that does not. If the auditor has evidence of one missed instance in a process that otherwise runs, the argument for a minor is usually a good one.

How do you contest a finding at the closing meeting?

The closing meeting is the best moment, because the audit team is still together and can change a finding before it is written into the report. Three things help.

  1. Ask to see the finding as written: the requirement cited, the evidence the auditor relied on, the grading.
  2. If you have evidence of conformity the auditor did not see, produce it then, not afterwards. A dated record shown at the meeting can remove the finding entirely.
  3. If the dispute is about grading, ask the auditor to walk through why it meets the major definition, and set out why the process works apart from the instance found.

Stay on the requirement. An argument about the auditor's experience or tone gets nowhere and is remembered at the next surveillance visit.

What if the finding stands after the closing meeting?

Put your position in writing to the lead auditor, promptly and within whatever window the body's process allows. Keep it short: the finding reference, the clause or control cited, why you believe it is wrong or mis-graded, and the evidence attached. Ask for the finding to be reviewed. Certification decisions are made by someone in the body other than the audit team, so a reasoned written objection reaches a reviewer who was not in the room.

Keep the clock running

While you contest a major, the closure deadlines in your contract do not necessarily stop. Agree with the body in writing whether they pause, or submit a correction plan in parallel, so a dispute you win does not leave you outside the outer limit for stage 2.

How does a certification body's appeals process work?

Every accredited certification body has to run a documented process for appeals against its decisions and for complaints about its auditors. That is a requirement of ISO/IEC 17021-1, the standard bodies are accredited against, and the process should be published or provided on request.

An appeal
A request to reconsider a decision the body made: refusing certification, suspending a certificate, or grading a finding in a way that changes the certification outcome.
A complaint
An expression of dissatisfaction with how the audit was conducted, such as an auditor who exceeded the scope or behaved unprofessionally.

The standard requires the body to acknowledge an appeal, investigate it through people who were not involved in the decision, and give you a formal outcome. Ask for the process in writing before you file, and file within its time limit.

Can you escalate to the accreditation body?

Yes, but only after the certification body's own process is exhausted. In Canada that is the Standards Council of Canada for SCC-accredited bodies; a body accredited by UKAS or ANAB answers to them instead. The accreditation body does not re-audit your company or overturn a finding directly. It examines whether the certification body followed its accredited process. That is a slow and serious step, worth taking only when you believe the body itself failed, not when you disagree with one auditor. ISO 27001 accreditation explains who accredits whom.

How do you manage a surveillance audit so findings do not escalate?

Surveillance audits are shorter than stage 2 and sample less, which is why small problems found there escalate quickly: an open minor from last year that is still open becomes a major. Manage the visit the same way you manage the relationship.

  • Close every open finding, with evidence, before the auditor arrives, and lead with the closure evidence at the opening meeting.
  • Agree the audit plan in advance: which clauses, which Annex A controls, which sites. Ask for it if it has not been sent two weeks out.
  • Have management review minutes and the internal audit report ready; they are sampled at almost every surveillance visit.
  • Tell the auditor about significant changes to scope, people or systems before they find them.

ISO 27001 surveillance audits covers the three-year cycle and what each visit looks at.

Can you switch certification bodies over a dispute?

Yes. Accredited certificates can be transferred between bodies under the International Accreditation Forum's transfer rules, usually at a surveillance or recertification point. The new body reviews the old one's findings, so an open major does not disappear with a transfer; it has to be closed or reviewed by the new body first. Switching is the right move when the relationship has broken down, not as a way around a finding. Certification bodies in Canada lists the alternatives.

Common questions

Can I challenge an ISO 27001 major nonconformity?

Yes. Challenge it at the closing meeting with evidence of conformity, then in writing to the certification body, and then through its appeals process. Grading disputes, major against minor, are the most common and the most often successful when the process demonstrably works apart from one instance.

Does disputing a finding delay our certificate?

It can, because the certification decision waits on the finding. Agree in writing whether closure deadlines pause during the dispute, or submit a correction plan in parallel so you stay inside the outer time limit either way.

Who decides an appeal?

People in the certification body who were not involved in the audit or the original decision. ISO/IEC 17021-1 requires that separation, and the body has to give you a formal outcome.

Can the Standards Council of Canada overturn a finding?

Not directly. SCC examines whether an accredited body followed its process. If it did not, the body has to correct its process, which may lead it to revisit the decision, but SCC does not re-audit your company.

Will contesting a finding sour the relationship with our auditor?

Not if it is about the requirement and the evidence. Certification bodies handle contested findings routinely. What damages the relationship is arguing about accurate findings or about the auditor personally.

Get help with a finding or a surveillance audit

ISO 27001 consultants who manage certification body relationships for clients.

Get matched