Evidence
Corrective action is not the same as fixing it
Auditors ask for both, and the second is the one organisations skip — which is why the same finding reappears at the next audit.
Facts checked — 2026-09-11
What is the difference between a correction and a corrective action?
When a nonconformity occurs you are expected to react to it and deal with the consequences, then evaluate whether action is needed to eliminate the cause so it does not recur — and to review the effectiveness of whatever you did.
In practice: the missed access review gets done (the fix), and then somebody asks why it was missed. If the answer is that it lived in one person’s calendar and they were on leave, the corrective action is a shared owner and a reminder that does not depend on them. Closing the instance without that is how you meet the same finding next year.
The bottom line
Record the cause and the change you made because of it. "Done" is a fix; "and here is why it will not recur" is corrective action.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
Related insights
Evidence
Running an internal audit that is worth the day it costs
Its job is to find things before the external auditor does, not to pass.
Evidence
Evidence that collects itself
If producing evidence is a separate task, it will be skipped in a busy quarter.
Evidence
Access reviews that survive an auditor’s sample
The most sampled control in both frameworks, and the most commonly half-done.