The control of nonconforming product is covered by clause 8.3 of ISO 13485. It is one of the most scrutinised processes in audits, because it directly reveals the maturity of the QMS. An organisation that handles its nonconformities well learns from its mistakes. An organisation that handles them poorly repeats them.
What clause 8.3 requires (8.3.1)
The organisation identifies and controls product that does not conform to requirements in order to prevent its unintended use or delivery. The documented procedure defines the controls, responsibilities and authorities. It covers the identification of the products concerned, the recording of the nonconformity, the evaluation of its severity, impact, scope and the batches concerned, the disposition decision, and traceability through to the effective treatment.
Clause 8.3 does not present a menu of equivalent options. It distinguishes two situations according to when the nonconformity is detected.
Nonconforming product detected before delivery (8.3.2)
At this stage, the organisation takes one or more of the following three actions.
Eliminate the nonconformity. Rework according to a documented procedure, repair, or reclassification of the product into a category for which it is conforming.
Prevent the originally intended use or application. Quarantine or destruction, where rework is not possible or where the risk does not justify use in its current state.
Authorise use, release or acceptance under concession. This is not a blank cheque. A concession requires a justification, a formal authorisation from an authorised person, and compliance with the applicable regulatory requirements. The record retains the identity of the person who granted the concession. An enforceable customer or regulatory requirement prohibits any concession granted unilaterally.
Rework: a controlled action (8.3.4)
Rework is not a simple “let’s start over”. Clause 8.3.4 requires a documented procedure that takes account of the potential adverse effects of the rework on the product. After rework, the product is re-verified to demonstrate that it meets the requirements. Rework carried out without this re-verification, or without an analysis of its effect on the product, is the classic finding raised in audits on this clause.
Nonconforming product detected after delivery (8.3.3)
When the nonconformity is identified after the product has been placed on the market, the organisation takes action proportionate to the effects, actual or potential, of the defect. It assesses the need to inform the customer, the distributors or the users. Where the nonconformity presents a risk to safety, the assessment of the need for a safety notice — a field safety corrective action (FSCA) within the meaning of the MDR — is mandatory and documented in accordance with regulatory requirements.
The expected traceability
For each nonconformity handled, the QMS retains the precise description of the nonconformity, the products or batches concerned with quantities, the action selected and its justification, the identity of the persons who made the decisions, and the evidence of the effective treatment, including the re-verification after rework.
This traceability is not optional. An auditor who asks to see the handling of a specific nonconformity must be able to trace from the initial finding through to the evidence of closure, without any gaps.
Product nonconformity vs. system nonconformity
Clause 8.3 covers product nonconformities. System nonconformities — failure to follow a procedure, or a deviation from a requirement of the standard raised in an audit — fall under the corrective action process (clause 8.5.2).
Confusing the two within the same procedure creates gaps. A deviation raised during an internal audit does not generate a product nonconformity record. It generates a corrective action.