A minor nonconformity is an isolated lapse in a system that otherwise works — one quarterly access review missed, one vendor assessed late. A major is systemic: a required process that doesn’t exist, a control that never operated, or a cluster of minors pointing at the same broken loop. The grade matters because the consequences differ sharply — a major found at stage 2 stops the certification recommendation, and one found at a surveillance audit can put an existing certificate at risk.
Closure is more than fixing the instance. The auditor expects root-cause analysis — why did the review get missed? — plus correction of the specific gap, corrective action addressing the cause, and evidence of both. Minor findings are usually reviewed at the next audit; for majors, the certification body verifies remediation before anything moves forward. Findings that reappear across audit cycles get read as a management-system failure, not bad luck.
Clean audits happen when someone pre-finds the problems: internal audits that behave like the real thing, evidence checked continuously rather than the week before fieldwork, and corrective actions tracked to closure. CloudCover, an IT services firm, passed ISO 27001 with zero audit findings running exactly that model with Agency — the full story is in the CloudCover case study.