← Back to blog

6 Step QMS Triage for QA Teams: Classify Nonconformance vs Deviation

September 6, 2026
6 Step QMS Triage for QA Teams: Classify Nonconformance vs Deviation

A deviation is a departure from an approved process, procedure, or specification during production. A nonconformance is a product, material, or result that fails to meet a defined requirement. The triage rule is simple: if something went off the approved path, call it a deviation; if the output itself failed a spec or test, call it a nonconformance. Usage varies by industry, so your QMS needs to define both terms in writing.


TL;DR:

  • Proper classification relies on whether process departure or output failure occurred, guiding proper investigation and containment actions.
  • Automated inspection systems linking measurement data to drawings reduce classification errors and ensure compliance with audit standards.
  • Documentation and thresholds in your quality management system should clearly define when deviations, nonconformances, or concessions are triggered and routed.
  • Immediate containment and thorough root cause analysis are crucial following any deviation or nonconformance to maintain regulatory compliance.
  • Consistent, scenario-based training and real-time metrics help prevent misclassification and improve overall quality process control.

Table of Contents

Deviation vs Nonconformance: The Terms You Need to Know

Getting the vocabulary right matters more than it sounds, because your entire investigation and CAPA routing depends on which door an event walks through first.

A deviation is any departure from an approved procedure, batch record, or process parameter. Deviations split into two categories. A planned deviation is requested and approved before execution, like temporarily raising a mixing speed for a validation run. An unplanned deviation happens without prior approval, like an operator skipping a hold step because a line was running behind schedule.

A nonconformance describes an output, whether a part, batch, or test result, that fails to meet a specified requirement. A machined bracket outside its tolerance band is a nonconformance. So is a lab assay that returns a result outside its acceptance range, which the industry calls an out-of-specification (OOS) result. OOS is really just a nonconformance with a specific laboratory pedigree.

A concession, sometimes called a waiver, sits in its own category. It's a documented decision to accept product that doesn't meet spec, and timing is what separates it from a deviation. A deviation permit is requested before the nonconforming condition occurs. A concession is granted after the fact, once the gap already exists, as explained in this breakdown of deviation permits versus concessions.

Deviation, nonconformance, and concession timing

Two quick contrasts make this concrete. A lab technician runs an assay and the result falls outside the range: that's an OOS nonconformance. A technician skips a required in-process check because the batch record wasn't followed: that's an unplanned deviation, with no failed measurement involved yet.

How Pharma and Device Teams Use These Terms Differently

Vocabulary drifts by industry, and knowing the local dialect saves you from misreading an audit finding.

Pharmaceutical and biotech quality teams lean heavily on "deviation" as the umbrella term. Their lab workflows are built around the FDA's two-phase OOS model: a Phase I investigation checks for lab error, and if none is found, a Phase II investigation expands into manufacturing and process causes, according to FDA's OOS guidance. In that world, a deviation can exist for days before it graduates into a confirmed nonconformance.

Medical device manufacturers tend to reach for "nonconformance" first, because their language traces directly to ISO 13485 §8.3 and 21 CFR §820.90, both of which use "nonconforming product" as the operative phrase. Aerospace and automotive shops mirror that pattern, since AS9100 and IATF 16949 both build on the same nonconformance framework.

Neither convention is wrong. Quality Digest's analysis of the two terms notes that the words overlap enough that organizations get more value from a firm internal definition than from chasing a universal one. Misclassify during an inspection, though, and the cost is real: an auditor who sees a deviation log with no linked nonconformance records, when test data clearly failed, will flag it as a documentation gap, not a paperwork quirk.

When Is It a Deviation and When Does It Become a Nonconformance?

Classification gets easier once you stop asking "which word sounds right" and start asking "did the process depart, or did the output fail?"

Use this checklist before logging an event:

  • Did someone deviate from an approved procedure, drawing, or batch record before any measurement was taken? Log it as a deviation.
  • Did a measured result, test, or inspection fail a documented requirement? Log it as a nonconformance.
  • Was the change requested and approved before execution? That's a planned deviation, often documented on a deviation permit.
  • Was the condition discovered after the fact, with product already made or shipped? That calls for a concession or waiver review, not a fresh deviation.
  • Is there any patient, safety, or regulatory exposure? If yes, quarantine the affected lot immediately regardless of which term applies.

A few real scenarios show the line clearly. Raising mixing speed for an approved experimental run is a planned deviation, closed out with documentation before parts move downstream. Discovering that a CMM was out of calibration when it measured a batch of parts turns those parts into nonconformances the moment the measurement is questioned. A mislabeled batch caught during incoming inspection is a nonconformance on the label control requirement, even though the root cause traces back to a process deviation upstream. When in doubt, quarantine the material and let testing decide. Testing that returns a failing result converts an open deviation into a confirmed nonconformance.

What Happens After You Detect a Deviation or Nonconformance?

Detection is only the starting line. What you do in the next few hours determines whether an auditor sees a controlled event or a compliance gap.

  1. Contain it immediately. Physically segregate affected material and apply a system-level hold in your QMS or MES so nobody can ship or consume it by accident.
  2. Investigate before assuming a root cause. Check data integrity first, then run the actual root cause analysis, using structured RCA methods rather than guesswork. Lab events follow the Phase I and Phase II OOS model when applicable.
  3. Route to MRB for disposition. A Material Review Board, typically quality, engineering, and manufacturing representatives, decides whether to scrap, rework, use-as-is under concession, or return to supplier. Every disposition needs documented evidence, not a verbal sign-off.
  4. Trigger CAPA when the root cause points to a systemic gap. Not every nonconformance needs a CAPA, but a repeat root cause, or one with regulatory exposure, does.
  5. Verify CAPA effectiveness after implementation, on a set schedule, and document that the fix actually held.
  6. Record everything. Auditors expect a traceable chain: detection, containment, investigation, disposition, and closure, all timestamped and linked, ideally through a structured NCR record.

Pro Tip: Build your investigation template with a checkbox for "data integrity reviewed" before root cause analysis begins. Skipping straight to root cause is one of the most common findings auditors cite when a lab result later gets thrown out.

What Do FDA and ISO Rules Actually Require Here?

Three references anchor almost every classification argument you'll have with an auditor.

21 CFR §820.90 requires device manufacturers to identify, document, evaluate, and segregate nonconforming product, and to justify any disposition in writing, per the Electronic Code of Federal Regulations. ISO 13485 §8.3 mirrors this, requiring documented disposition decisions and a defined escalation path when nonconforming product reaches a customer. FDA's OOS guidance governs the pharmaceutical lab side, defining the two-phase investigation that decides whether a suspect result becomes a confirmed nonconformance.

None of these documents hands you a triage matrix. Inspectors repeatedly cite inadequate segregation and weak disposition justification as findings, which tells you where the actual risk sits: not in which word you chose, but in whether the paper trail proves you controlled the material and justified the decision.

Building Deviation and Nonconformance Rules Into Your QMS

A policy that only defines terms on paper doesn't help the person on the floor deciding what to log at 2 a.m. Build the definitions into a working document with teeth.

Your written policy should cover:

  • Clear definitions of deviation, nonconformance, concession, and OOS, matched to your industry's dominant convention.
  • Scope statements specifying which processes, products, or facilities the policy governs.
  • Named authorities for each disposition path, so nobody guesses who sign off.
  • A triage matrix scoring impact, affected quantity, regulatory exposure, and patient or end-user risk.
  • Defined thresholds for when an event automatically routes to MRB versus a standard NCR closure.

An EQMS earns its keep by enforcing that matrix automatically rather than leaving it to memory. Automatic holds on flagged parts, routing rules that push high-risk events straight to MRB, and dashboards that trend recurring root causes all reduce the lag between detection and containment. Track a few metrics monthly: time-to-containment, the percentage of deviations later reclassified as nonconformances, and trend rate by root cause category. A rising reclassification rate usually means your triage checklist needs sharper language, not more training.

How Inspection Automation Reduces Misclassification

Misclassification often traces back to a gap in the measurement data itself, not a definitional argument. If a dimension was never properly ballooned, mapped, or compared against tolerance, an inspector might log a "deviation" for a missed check when the real issue is an unrecorded nonconformance sitting in a part nobody flagged.

Audit-ready First Article Inspection reports that link every ballooned drawing dimension to a measured result close that gap directly. When CMM data imports automatically and tolerance validation flags out-of-spec values the moment they land, the classification question mostly answers itself: the system already shows whether the part failed a requirement.

Inspection dimensions mapped to tolerance outcomes

Look for automatic drawing ballooning, CMM import with auto-mapping, tolerance validation, and hold or segregation flags tied to the inspection record itself. For a closer look at how automated CMM data import reshapes documentation, QA-Report's guide to automating inspection reports walks through the mechanics. QA-Report's editorial team, including contributor Michael Chen, publishes deeper procedural templates on the QA-Report blog for teams building out their own triage policy.

Getting the Culture Right, Not Just the Definitions

Over-classifying every hiccup as a nonconformance buries your MRB in low-value paperwork. Under-classifying real failures as harmless deviations buries your risk. Neither extreme holds up under audit.

Three things move the needle fastest: a one-page policy your floor staff will actually read, scenario-based training using real examples instead of abstract definitions, and a monthly trending review with quality leadership to catch drift before it becomes a pattern.

— Michael Chen

See How QA-Report Supports Consistent Classification

There are tools available that help quality teams catch nonconformances more quickly than manual inspection, without adding disconnected systems to your stack. Some software measurement wizards link ballooned drawing dimensions to measured results and flag out-of-tolerance values automatically, helping ensure failed specs are accurately logged.

QA-Report

CMM data import, tolerance validation, and flags for hold and segregation can feed into audit-ready FAI, dimensional, and GD&T reports meeting relevant standards. When inspection and MES layers are integrated on the same platform, flagged parts can move into containment workflows more seamlessly. If your team is still deciding classification by memory and a spreadsheet, start a QA-Report trial and see how ballooned inspection data can settle the deviation versus nonconformance question before an auditor ever asks it.

Sources