ISO 9001 · Clause 8 · 8.7
Control of nonconforming outputs
In plain words
At some point a part is bad, a service has failed. The standard does not demand that this never happens — it demands that it then does not run on uncontrolled. Three steps: detect and identify, segregate or otherwise secure, then decide deliberately what happens to it.
For the decision there are four clean paths: correction (rework and re-check), sorting out (scrap or hold back), informing the customer — and, where defensible, the concession with approval, where applicable by the customer. What there is not: the fifth, silent procedure — just letting it slip through.
Two records belong to it: what was nonconforming and what was decided, including the approving body for a concession. And important for small companies: 8.7 is the immediate handling of the bad part. The question “why did it happen, and how do we prevent it in future?” is the corrective action (10.2) — a separate, second step.
Why this requirement exists
The most expensive part of production is the bad part that runs on. In your own hall it costs rework; at the customer it costs a complaint, trust, and in the worst case the recall — in medical technology with reporting duties. The clause exists so that between “detected” and “reused” there is always a block and a decision, never just a shrug.
The identification and segregation duty has a simple reason: people reach into the shelf, not into the record. A red label and a separate place prevent more misdeliveries than any procedure instruction. And the documented decision protects in both directions — in a liability case it proves that a block happened, and it makes the concession what it should be: a responsible exception rather than a habit.
What good looks like
Everyone in production knows what to do on a not-OK find: identify (red label, not-OK note on the job card), to the segregation area, report to the deciding body. The segregation area is a real place — a marked shelf, a red bin —, not a corner where other things also lie. The decision is made promptly and recorded: rework (with a re-check per 8.6), scrap, or — justified and approved — concession, on a customer-specific characteristic with the customer’s consent.
You recognise the system by the fact that it also works after delivery: if an error is discovered only at the customer, the same logic applies — pin down affected deliveries (the traceability from 8.5.2 pays off here), inform the customer, agree the action. And: the not-OK cases are looked at together — they are the raw material for improvement (9.1, 10.2), not just single events.
What changes as you grow: From around 50 people the handling gets structure — defined segregation areas per area, a simple not-OK record with defect types, a rule on who may approve concessions. From 100–250 people, quarantine stores with a booking block in the ERP, formal concession procedures with the customer and systematic defect analysis (Pareto per defect type) arrive. The core stays: block, decide, record — at every size.
The minimum to pass
- Not-OK is detected and immediately identified — on the part and in the papers.
- Mix-up is excluded: a separate, marked segregation area or equivalent securing.
- Every decision is recorded: correction, sorting out, customer info or concession — with the approving person.
- Rework is re-checked — against the same criteria as the first time (8.6).
- Errors discovered after delivery also trigger the procedure: pin down, inform, act.
What an auditor asks for
- The tour to the segregation area: does it exist, is it marked, does only blocked material really lie there — and does it carry labels?
- Two or three not-OK cases lengthwise: find, identification, decision, on rework the re-check — does the file close?
- A concession, if there was one: justification, approver, customer involvement on the customer-specific characteristic.
- The question to the worker at the machine: “what do you do when you notice a bad part?” — the answer shows whether the procedure is lived or lives in the binder.
- The case after delivery: how was it pinned down, when was the customer informed — and did the case lead into a corrective action (10.2)?
Common traps
- The bin without a name. Sorted-out parts lie next to good ones, nothing is marked — at the next shortage they wander back into the flow. The most common not-OK finding of all.
- Rework without re-inspection. Reworked and packed straight away — but reworked goods are new goods: they must pass the same release as the first time.
- The permanent concession. The same deviation is released “as an exception” for the third time. By now it is no longer an exception but an unaddressed cause — and belongs in the corrective action (10.2).
- Concession past the customer. The dimension is outside the customer drawing, released internally. On customer-specific requirements the customer decides too — otherwise the concession is a concealed breach of contract.
- Confusing 8.7 with 10.2. Part blocked, case closed — the cause question is never asked, the same error comes back. 8.7 handles the part, 10.2 the cause; one does not replace the other.
- Fear as a system fault. Where the not-OK find means trouble, parts vanish into the scrap container instead of the segregation shelf. The numbers look better — until the error surfaces at the customer. How leadership handles bad news (5.1) decides whether 8.7 works.
Worked example
At Berger Präzisionsteile GmbH a red sign hangs on the segregation shelf, and the way there is short. The teaching case came months after the new worker’s first stop (5.3) — back then his doubt about a dimension had been unfounded, and he had been praised before the team all the same. This time the doubt was founded: on the sample of a milled lot a diameter lay at the tolerance limit, two parts just above. The same move as back then — machine stopped, lot blocked, Lea fetched; the “better one stop too many” paid off on the first real hit. The 100% re-measurement of the lot showed: eleven parts out of tolerance. Decision, documented on the not-OK record: eleven parts scrap (rework on the groove impossible), rest of the lot released — and because two lots before had run with the same tool, they too were re-measured: in order. The traceability via the job cards (8.5.2) made the pinning-down a matter of minutes, not days.
The cause question — tool wear faster than the inspection rhythm — moved into 10.2 as a corrective action; on the 8.7 page remained the clean immediate handling. And a concession happened exactly once that year: a dimension outside the drawing, functionally uncritical — a query to the customer with measured values, their written consent, delivery with a mark in the accompanying paper. Once, justified, approved: that is how the concession is meant.
<!-- easo:worked_example profile=service -->
At Klarwerk GmbH the nonconforming output is not a part but, say, a failed deployment or an error that made it into the production environment. The 8.7 logic is the same: contain rather than let run on (rollback, deactivate a feature), decide (fix immediately or withdraw), inform the customer if they are affected — and the incident gets a ticket, never just corridor talk. The temptation is the same as on the shop floor: “nobody will notice, it’s running” — and so is the answer.
How easo covers it
Clause 8.7 is a row in the readiness denominator — the evidence is your described handling of nonconforming outputs.
- Create from the gap links the clause; the starter template brings the structure: detect and identify, block, the four decision paths, the re-check after rework, the case after delivery.
- The bridge to the cause is built into easo: from the not-OK case one step makes the corrective action (10.2) — as a case of its own with a lifecycle, whose closure the engine allows only after evidenced effectiveness. 8.7 and 10.2 stay two steps, but one thread.
- What stays honest: the segregation area, red labels and not-OK records live in your hall. easo controls the procedure and carries the cases — the discipline at the shelf replaces no tool.
Stay in the loop
easo is available for macOS — the Windows version is coming soon. Leave us a note and we'll reach out the moment it lands.