Nonconformance Management: When Your NCM System Becomes a Disposition Factory Nobody Learns From — and the Quality You Were Supposed to Protect Became the Rework You Authorized and the Root Causes You Never Actually Found

Blog

You know the drill. A part fails inspection. Someone fills out a
form. A disposition gets assigned — rework, use-as-is, scrap — and the
nonconformance disappears into a database that nobody opens unless an
audit is coming. The product moves. The line keeps running. The problem
comes back next Tuesday.

This is the story of Nonconformance Management in most manufacturing
organizations. Not the version described in the quality manual — the
real one. The one where your NCM (Nonconformance Management) system,
which was supposed to be your frontline defense against defective
product reaching the customer, became a rubber-stamp machine for
disposal decisions. Where the root cause analysis you were supposed to
conduct became the “unknown” field everyone skipped. Where the
corrective action you were supposed to link to became the empty column
that stayed empty because linking it meant doing actual work.

And the worst part? Nobody noticed the degradation. Because the NCM
reports still went out every month, and the numbers still looked
reasonable, and the dispositions still happened within 24 hours, and the
auditors still checked the boxes — so everyone assumed the system was
working. Right up until the customer called.

What
Nonconformance Management Was Actually Supposed to Be

Let’s reset. A nonconformance is any deviation from a requirement — a
specification, a drawing, a standard, a customer expectation. It can be
a dimensional deviation on a machined part, a cosmetic defect on an
injection-molded surface, a missing feature on an assembly, a
documentation error on a traveler. Anything that doesn’t meet the
agreed-upon requirement is a nonconformance.

Nonconformance Management is the system — the processes, the people,
the forms, the databases, the reviews — that handles these deviations
from the moment they’re detected to the moment they’re resolved and
prevented from recurring. It is one of the most fundamental processes in
any quality management system. ISO 9001 requires it. AS9100 requires it.
IATF 16949 requires it. Every industry standard that has any teeth
demands that you identify, record, evaluate, disposition, and learn from
nonconformances.

The keyword there is “learn.” The entire purpose of a nonconformance
system is not to dispose of bad product. That’s the easy part. The
purpose is to learn — to extract from each nonconformance the
information needed to prevent it from happening again. The disposition
is a tactical decision: what do we do with this specific part? The
strategic decision — what do we do with this type of failure so it never
comes back? — is where the value lives.

A functioning NCM system does five things:

1. Detects and records nonconformances promptly. Not
“when we get around to it.” Not “when the shift is over.” Promptly.
While the evidence is fresh, the conditions are documented, and the
people who observed the failure are still available.

2. Segregates and identifies nonconforming product.
Physical separation, clear labeling, controlled areas. So that bad
product doesn’t accidentally get mixed with good product and shipped.
This is basics. This is day one.

3. Dispositions each nonconformance appropriately.
Rework, repair, use-as-is (with concession), scrap, or return to
supplier. The disposition should be based on technical evaluation — not
convenience, not schedule pressure, not “the production manager said to
ship it.”

4. Investigates root causes. Not every
nonconformance requires a full 8D investigation. But every
nonconformance should have enough root cause thinking attached to it
that you can answer a simple question: “Why did this happen?” If you
can’t answer that, you’re not managing nonconformances. You’re just
counting them.

5. Feeds into corrective and preventive action. When
the same nonconformance recurs — or when the root cause suggests a
systemic issue — the NCM system should trigger a CAPA. This is where the
learning compounds. This is where the system pays for itself.

How It Actually Works in
Practice

Now let me tell you what happens in most plants I’ve walked into over
the past twenty-five years.

The Form-First Disease

The NCM form exists. It’s in the QMS software, or it’s a paper
traveler attachment, or it’s a spreadsheet. And people fill it out. They
fill it out because they’re trained to, or because the auditor checks,
or because you can’t close the job without one. So they fill it out.

But here’s what the filled-out form typically looks like:

Description of nonconformance: “Part out of spec.”
Root cause: “Operator error.”
Disposition: “Rework.” Corrective
action:
“Retrained operator.” Verified by:
[signature]

That’s not nonconformance management. That’s storytelling. “Operator
error” is not a root cause — it’s a lazy categorization that absolves
the system of responsibility. “Retrained operator” is not a corrective
action — it’s a ritual. And nobody verified anything; they signed
because the form has a line that says “verified by.”

The form-first disease is the most common failure mode in
nonconformance management. People optimize for completing the form
rather than for understanding the failure. The metric becomes “NCM
closed within 24 hours” instead of “NCM prevented from recurring.” And
because the metric rewards speed over depth, the system fills with
shallow, meaningless records that tell you nothing.

The Disposition Treadmill

In many organizations, the Material Review Board (MRB) — or whatever
they call the dispositioning authority — has become a rubber-stamp
committee. They meet daily or weekly. They review the stack of
nonconformances. They assign dispositions. They move on.

The problem is not that the dispositions are wrong (though they often
are). The problem is that the MRB has become a disposal system rather
than an investigation system. They’re asking “what do we do with this
part?” when they should also be asking “what does this failure tell us
about our process?”

I’ve seen MRB meetings where 40 nonconformances are dispositioned in
30 minutes. That’s 45 seconds per nonconformance. You cannot conduct
root cause analysis in 45 seconds. You can barely read the description
in 45 seconds. What you can do in 45 seconds is look at the part type,
look at the defect, say “rework,” and move to the next one. And that’s
exactly what happens.

The Use-As-Is Trap

“Use-as-is” is a legitimate disposition. Sometimes a part that
doesn’t meet drawing requirements is perfectly functional for its
intended application, and the cost and schedule impact of scrapping or
reworking it outweighs the technical risk of using it as-is. The
concession process exists for exactly this reason.

But “use-as-is” has a dark side. When it becomes the default
disposition — when the MRB stamps “use-as-is” on everything because it’s
faster than arranging rework or cheaper than scrapping — the
nonconformance system has failed. You’re not making quality decisions.
You’re making accounting decisions dressed up as engineering
decisions.

I’ve walked into plants where the use-as-is rate was over 60% of all
nonconformances. Six out of ten parts that failed inspection were
shipped anyway. When I asked how they justified it, the answer was
always some variation of “engineering reviewed and approved.” When I
asked to see the engineering review, it was a signature on a form. No
analysis. No risk assessment. No data. Just a signature from an engineer
who was under pressure to keep the line running and knew that saying
“use-as-is” was faster than saying “no.”

The use-as-is disposition should be rare. It should require genuine
technical justification. It should involve a documented risk assessment.
It should involve the customer when the contract requires it. When it
becomes routine, it means your engineering tolerances are wrong, your
process capability is inadequate, or your quality culture is broken.
Possibly all three.

The Recurrence Problem

Here’s the test that tells you whether your NCM system is working:
pick any nonconformance from six months ago. Look at the part number,
the defect type, and the root cause. Now search for the same combination
in the last month. If you find it — the same part, the same defect, the
same (or absent) root cause — your system has failed. You detected the
nonconformance. You dispositioned it. You closed it. And you learned
nothing.

Recurrence is the ultimate metric of nonconformance management. Not
closure rate. Not cycle time. Not the number of NCMs opened. Recurrence
rate. If the same failures keep coming back, your system is a disposal
pipeline, not a learning system.

I’ve never been to a plant that tracked recurrence rate as a metric.
Not once. They track everything else — NCM count, closure time,
disposition breakdown, cost of scrap, cost of rework. But they never
track the one metric that would tell them whether any of it is working.
Because tracking recurrence would mean confronting the truth: that most
of their nonconformance management is theater.

The Database Nobody Opens

Most NCM data lives in a QMS database — quality management software
that stores every record, every disposition, every signature, every
date. The data is there. It’s accessible. And nobody looks at it.

Not the operators. Not the engineers. Not the quality manager — at
least not beyond pulling the monthly report for the management review.
The data sits in the system like books in a library that nobody visits.
And the patterns — the recurring failures, the problematic part numbers,
the problematic suppliers, the problematic processes — remain invisible
because nobody is looking for them.

This is perhaps the greatest waste in nonconformance management.
You’re collecting data — enormous amounts of data — and you’re doing
nothing with it. You’re not running trend analysis. You’re not looking
for systemic issues. You’re not feeding the data back to engineering for
design improvements. You’re not feeding it to supplier quality for
supplier development. You’re not feeding it to production for process
changes. You’re just storing it, month after month, year after year,
until the database gets so large that searching it becomes an exercise
in frustration.

The data from your nonconformance system should be one of the most
valuable assets in your organization. It tells you exactly where your
processes are failing, which designs are problematic, which suppliers
are struggling, and which trends are developing. It’s a roadmap for
improvement — if anyone bothered to read it.

The Cost of a Broken System

Let me quantify this for you, because the cost is not abstract.

A typical mid-sized manufacturer generates somewhere between 200 and
2,000 nonconformances per year, depending on complexity and volume. Each
nonconformance carries direct costs — scrap material, rework labor, MRB
time, documentation overhead — that typically range from $200 to $5,000
per incident. But those are just the visible costs.

The invisible costs are where the real damage happens:

Recurrence cost. If your root cause analysis is
inadequate (or nonexistent), the same failure recurs. If a
nonconformance that cost $2,000 to resolve recurs five times in a year,
that’s $10,000 — plus the cost of the defective product that may have
reached the customer. Over a portfolio of recurring nonconformances, the
annual cost easily reaches six or seven figures.

Customer trust cost. Every time a defective product
reaches a customer — whether through a failed use-as-is disposition or
an inspection miss — trust erodes. The customer may not return the part.
They may not file an SCAR (Supplier Corrective Action Request). They may
simply start looking for an alternative supplier. You’ll never see this
cost on a P&L statement, but it shows up in the quote-win rate
eighteen months later.

Opportunity cost. Every hour your engineering team
spends fighting fires — investigating escapes, supporting customer
complaints, managing recalls — is an hour they’re not spending on
process improvement, new product introduction, or cost reduction. The
nonconformance system that was supposed to free up resources by
preventing problems has instead consumed resources by failing to prevent
them.

Culture cost. This is the most insidious. When
people see that nonconformances are handled superficially — that root
causes are fabricated, that corrective actions are toothless, that the
same problems keep coming back — they stop believing in the quality
system. They go through the motions. They fill out the forms. And when a
real problem surfaces, one that requires genuine investigation and real
corrective action, nobody has the appetite for it. The culture of
shallowness, once established, is extraordinarily difficult to
reverse.

How to Fix It

The fix is not complicated. It’s not easy, but it’s not
complicated.

1. Separate
Disposition from Investigation

Stop trying to do root cause analysis in the MRB meeting. The MRB’s
job is to decide what to do with the nonconforming product — right now,
today, within the constraint of keeping the line running. That’s a
legitimate and time-sensitive decision, and it should be made quickly by
people with the authority to make it.

But root cause investigation is a different activity that requires
different people, different timeframes, and different methods. It should
happen after the disposition, not during it. Assign the investigation to
someone who has the skills and the time to do it properly. Use 5 Whys,
Ishikawa, or whatever method fits. And track the investigation as a
separate activity with its own deadline and its own owner.

2. Track Recurrence

This is the single most important change you can make. Track whether
the same nonconformance — same part, same defect, same cause — appears
again after it was “resolved.” If your QMS software doesn’t support this
natively, do it manually with a monthly cross-reference check. Report
recurrence rate to management. Make it visible. Make it painful. Because
a high recurrence rate is the clearest possible signal that your
corrective actions aren’t working.

3. Raise the Bar on Root
Cause

“Operator error” should be banned as a root cause entry. Not because
operators don’t make errors — they do — but because “operator error” is
never the end of the investigation. It’s the beginning. The question is
always: “Why did the operator make that error?” Was the work instruction
unclear? Was the fixture inadequate? Was the gauge unreliable? Was the
training insufficient? Was the process inherently error-prone?

If your root cause field accepts “operator error” without further
investigation, your system is broken. Fix the field. Require deeper
analysis. And if the person entering the NCM doesn’t have the skills to
do root cause analysis, that’s fine — but route it to someone who
does.

4. Use the Data

Your NCM database is a goldmine. Start mining it. Run Pareto analysis
on defect types. Track nonconformance rates by part number, by supplier,
by process, by shift. Look for trends over time. Feed the findings back
to engineering, to supplier quality, to production. The data you already
have is more valuable than any new initiative you’re about to
launch.

5.
Make Nonconformance Management a Leadership Conversation

Nonconformance management is not a quality department activity. It’s
a business activity. The trends, the costs, the recurrence patterns —
these should be on the operations review agenda every month. Not as a
report-out from quality (“we had 47 NCMs this month, down from 52 last
month”) but as a discussion: “What are our top three recurring
nonconformances, what’s being done about them, and when will we see the
results?”

Leadership attention is the single most powerful driver of NCM system
performance. When the plant manager asks about recurrence rates, people
start investigating root causes. When the VP of operations wants to know
why the same defect keeps appearing on the same part, corrective actions
get assigned and completed. When nobody above the quality manager cares,
the system atrophies.

The Choice

Every manufacturer has a nonconformance system. The question is
whether it’s a learning system or a disposal system. A learning system
gets smarter over time — nonconformances decrease, root causes are
identified and eliminated, and the data drives improvement. A disposal
system stays the same — nonconformances continue at the same rate, the
same problems recur, and the database grows larger and more useless.

The difference between the two is not technology. It’s not the QMS
software. It’s not the form. It’s not even the people. It’s the
commitment — the commitment to actually investigate failures, to
actually identify root causes, to actually implement corrective actions,
and to actually verify that they worked.

That commitment costs time and effort up front. It means slower
dispositions on complex nonconformances. It means more investigation
hours. It means holding product while the root cause is being determined
instead of shipping it and hoping for the best. It means having
difficult conversations about process capability, design margins, and
supplier performance.

But the return on that commitment is enormous: fewer defects, lower
costs, higher customer satisfaction, and a quality culture that people
actually believe in. The choice is yours. You can keep filling out forms
and filing them away. Or you can start using the system the way it was
designed to be used — as a tool for learning, for improvement, and for
the relentless elimination of the conditions that cause defects in the
first place.

Your nonconformance system is talking to you. The question is whether
anyone is listening.


About the Author: Peter Stasko is a Quality
Architect with over 25 years of experience transforming quality systems
across manufacturing organizations. He specializes in turning
dysfunctional compliance processes into engines of continuous
improvement, and he writes about the gap between what quality systems
are supposed to do and what they actually do.

Scroll top