Expert Advice Community

Guest

Corrective action logs

  Quote
Guest
Guest user Created:   Mar 04, 2023 Last commented:   Mar 04, 2023

Corrective action logs

We are working on the ISO 27001 implementation and one of the questions that popped out to us is about the corrective action logs.

May I know what are the requirements of the corrective action logs? What elements should them be included?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Mar 04, 2023

The corrective action log in general contains a unique identification (e.g., number or code), the description of the non-conformity, identification of similarly identified nonconformities, actions to be implemented, and identification of approver and implementer.

If you need evidence of the actions that follow, at least the following information needs to be recorded:

  • the nature of the nonconformities and actions taken
  • the results of corrective actions performed

For example, if the nature of the nonconformity is about lack of competence, the proposed action could be training, and the results to be recorded would be certifications, attendance lists, or interviews with employees about the training topic.

This article will provide you with a further explanation about corrective actions:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 04, 2023

Mar 04, 2023