Nonconformity and continual improvement
Clause 10 requires the organization to react to failures in the AI Management System (AIMS) by taking corrective actions to prevent recurrence. It also mandates a proactive process for continually improving the suitability, adequacy, and effectiveness of the AIMS over time.
What it means
In practice, this clause establishes the "Act" phase of the Plan-Do-Check-Act (PDCA) cycle. When a nonconformity occurs—such as a breach of an AI policy, a failure in a risk control, or a missed objective—the organization must not only fix the immediate problem but also determine why it happened to ensure it does not happen again.
Continual improvement differs from corrective action; while corrective action is reactive (fixing a known error), continual improvement is proactive. It involves using data from performance evaluations, audits, and management reviews to evolve the AIMS, ensuring it remains aligned with the organization's AI goals and changing regulatory landscapes.
How to meet it
- Establish a formal process for reporting and documenting nonconformities within the AIMS.
- Implement a Root Cause Analysis (RCA) procedure to investigate why a nonconformity occurred rather than just treating the symptoms.
- Define a workflow for "Corrective Actions," including who is responsible for implementing the fix and how its effectiveness will be verified.
- Create a mechanism to track the status of open nonconformities through to closure.
- Use outputs from Management Reviews (Clause 9.3) and internal audits to identify specific areas for systemic improvement.
- Document AI-specific improvements, such as updating model monitoring thresholds or refining data governance policies based on observed performance.
Evidence an auditor asks for
- A Nonconformity and Corrective Action Log (or ticket system) showing the date of discovery, description of the issue, and resolution status.
- Records of Root Cause Analysis performed for significant failures or recurring issues.
- Verification records proving that a corrective action actually worked (e.g., a follow-up check conducted after 30 days).
- Management Review minutes specifically highlighting decisions made to improve the AIMS.
- Updated policy documents or risk registers showing versions evolved as a result of continual improvement efforts.
Common pitfalls
- Confusing "correction" with "corrective action." (e.g., fixing a single AI model error is a correction; updating the validation pipeline to prevent that class of error across all models is a corrective action).
- Failing to document the "effectiveness review," leaving an auditor to wonder if the fix actually solved the problem.
- Treating the AIMS as a static project that is "finished" after certification rather than a living system requiring ongoing refinement.