Non-conformance

Nonconformance is the failure of a product, process, or service to meet a specified requirement within a medical device quality system. Under ISO 13485 Clause 8.3, a manufacturer must identify, document, evaluate, and control nonconforming product to prevent its unintended use or delivery, then decide an appropriate disposition.


What is nonconformance?

Nonconformance is a core concept in a medical device quality management system. It describes any point where a component, an in-process assembly, a finished device, or a procedure fails to meet a defined requirement. That requirement can come from a customer specification, an internal standard, a design output, or a regulation.

The industry draws a useful line between two ideas. A nonconformity is the broad state of not meeting a requirement, and it can be a process, document, or product issue. A nonconforming product is the narrower case: a physical item that fails its acceptance criteria. ISO 13485 Clause 8.3, titled ” Control of Nonconforming Product, sets the rules for handling that physical case across the device lifecycle, from incoming material to product already in the field.


Why nonconformance matters in medical device development

A missed or mishandled nonconformance can put a defective device in a clinician’s hands. That is why regulators treat control of nonconforming product as a foundational quality-system requirement rather than a paperwork exercise.

Inadequate nonconforming-product procedures are a recurring source of FDA Form 483 observations, and weak controls surface quickly during ISO 13485 and MDSAP audits. Unresolved nonconformances also feed downstream failures: escaped defects become complaints, complaints become vigilance reports, and clusters of the same defect can end in a recall or a field safety corrective action. Catching a nonconforming component at incoming inspection is cheap; catching it after the device ships means investigation, retrieval, rework or scrap, and lost time.


How nonconformance control works

Control of nonconforming product under ISO 13485 Clause 8.3 follows a defined sequence. The clause splits into general requirements (8.3.1), actions before delivery (8.3.2), actions after delivery or use (8.3.3), and rework (8.3.4). A typical workflow runs:

  • Identify and record. Flag the item and open a nonconformance report (NCR) that captures what failed, where, and against which requirement.
  • Segregate. Quarantine the product, physically or in the system of record, so it cannot be used or shipped by mistake.
  • Evaluate. Assess the nature and extent of the nonconformity and its risk under ISO 14971.
  • Decide disposition. Choose one route: eliminate the nonconformity, authorize use or release under concession where regulatory requirements are met, or preclude the original intended use through scrap or return.
  • Document and escalate. Record the action taken, and feed systemic or recurring issues into corrective action under Clause 8.5.

Rework, when chosen, must follow the same authorization and acceptance criteria as the original operation, and the results go into the device history record. Under the FDA Quality Management System Regulation, effective February 2, 2026, 21 CFR Part 820 incorporates ISO 13485 by reference, so Clause 8.3 now carries the force of US law.


Common challenges and best practices

The most common mistake is routing every nonconformance straight into the CAPA system. That floods the process, buries the serious issues, and slows genuine corrective action. A better model triages: contain and disposition first, then escalates only what the data justifies.

Segregation is another weak point. If quarantined product is not clearly controlled, a nonconforming part can find its way back into a build. Clear status labeling and system holds prevent that. Concession is a third pressure point: repeatedly accepting the same deviation is a signal that the specification, process, or supplier needs attention, not a standing waiver. Strong teams trend nonconformances by type, part, and supplier so patterns surface early and feed supplier qualification and process improvement, while reserving CAPA for systemic causes.


How SJML helps with nonconformance

SJML manages nonconformance as part of its quality and regulatory services for medical device manufacturers. Its teams handle nonconformance intake, root-cause analysis, and CAPA within an ISO 13485 and MDSAP quality management system, so disposition decisions stay documented and defensible. On the manufacturing side, in-process controls such as solder-paste inspection, automated optical inspection, and X-ray, together with validated processes (IQ, OQ, PQ) and supplier qualification, reduce the nonconformances that reach a device in the first place. SJML also supports the regulatory follow-through when a field issue arises, from advisory notices to vigilance and field safety corrective actions.

Talk to SJML’s QARA team →


Frequently asked questions

What is the difference between a nonconformance and a nonconformity?

In practice, the terms overlap. A nonconformity, in ISO 13485 language, is any failure to meet a requirement, which can be a process, document, or product issue. A nonconforming product is the narrower case: a physical component or finished device that fails its acceptance criteria. Many manufacturers use nonconformance as the umbrella label for both, then classify severity during evaluation.

Does every nonconformance require a CAPA?

No. Most nonconformances are handled through disposition alone: correcting the item, scrapping it, reworking it, or accepting it under concession. A corrective action is warranted when an investigation shows a systemic or recurring cause, when risk to the patient is significant, or when trending signals a pattern. ISO 13485 Clause 8.5.2 expects corrective action proportionate to the effects of the nonconformity.

How does ISO 13485 handle a nonconforming product found after delivery?

Clause 8.3.3 covers products detected after delivery or after use has started. The manufacturer must act in proportion to the actual or potential effects of the nonconformity, which can include issuing advisory notices, field actions, or recalls. These steps often trigger vigilance reporting and a field safety corrective action under EU MDR and medical device reporting under FDA rules.

What is a concession in nonconformance control?

A concession is a documented authorization to use, release, or accept a nonconforming product as is, without meeting the original specification. ISO 13485 permits it only when regulatory requirements are still met, and the person granting it has the authority to do so. A concession records the accepted deviation; it does not remove the need to address the underlying cause.


Related terms

  • Corrective and Preventive Action (CAPA)
  • Nonconformance Report (NCR)
  • Material Review Board (MRB)
  • Rework
  • Vigilance Reporting

Table of Contents

Free EU MDR Technical Documentation Compliance Checklist

Understand documentation gaps and use our single-window worksheet to prepare for Notified Body review.

Related Glossaries

Ask Sygma AI

AI-Powered Assistant

SJ Assistant