The Question You Cannot Answer
It is an accreditation assessment. The assessor is reviewing a certification file from eight months ago. She opens the Stage 2 report and sees that three nonconformities were raised: two minor and one major. She turns to the quality manager and asks a simple question:
"Show me the closure evidence for NC number seven."
The quality manager opens the client folder on the shared drive. There are twelve subfolders with inconsistent naming. She searches for "NC" and finds a file called "NC_tracking_2025.xlsx." She opens it. Row 47 shows NC #7: "Major NC - Clause 8.5.1 - No documented procedure for nonconforming output." The status column says "Closed." The date column says "2025-09-14."
The assessor asks: "Where is the corrective action evidence the client submitted? Where is the auditor's review? Where is the record of acceptance?"
The quality manager searches the email archive. She finds a thread from September 2025 where the client sent a PDF of their new procedure. She finds a reply from the auditor that says "Looks good, NC can be closed." She does not find a formal review record, a documented evaluation of the root-cause analysis, or a timestamped closure decision.
The assessor writes a finding: inadequate records of NC closure. The spreadsheet says "closed," but there is no verifiable evidence of the process that led to closure.
Why Spreadsheet NC Tracking Fails
Spreadsheets are excellent at listing things. They can track NC numbers, descriptions, due dates, and status. But they cannot manage a process. And nonconformity management is not a list -- it is a multi-step process with specific requirements.
No structured lifecycle. A spreadsheet has rows and columns. It does not enforce a sequence of steps. It cannot require that a root-cause analysis be submitted before corrective action is reviewed. It cannot prevent someone from changing the status to "closed" without supporting evidence.
No evidence linkage. When a client emails corrective action evidence, someone downloads the attachment and saves it somewhere. The spreadsheet has no link to this evidence. The connection between the NC record and the closure evidence exists only in someone's memory or email archive.
No review trail. When the auditor reviews the corrective action and decides to accept or reject it, that decision is typically communicated by email or verbally. There is no formal record of what was reviewed or when the decision was made. The spreadsheet just flips from "Open" to "Closed."
No rejection and resubmission handling. Sometimes the first corrective action attempt is inadequate. The auditor rejects it and asks the client to try again. In a spreadsheet, this might be tracked with a comment. But there is no structured second round, no record of which submission was rejected and why, and no history of how many rounds it took to close the NC.
How Certiva Manages the NC Lifecycle
In Certiva, nonconformity management is a structured workflow with defined steps, enforced sequences, and complete records at every stage.
Step 1: NC issuance. The lead auditor raises the NC within the platform, specifying the classification (minor, major, or critical), the applicable clause, and the finding description. The system automatically computes the due date based on the classification. The NC is immediately visible in the client's portal and the CB's internal dashboard.
Step 2: Client response. The client accesses the NC through their portal. They upload their root-cause analysis and corrective action evidence. The submission is timestamped and linked directly to the NC record. The client can see the status change from "Awaiting Response" to "Under Review." They do not need to email the CB to ask if the evidence was received.
Step 3: Auditor review. The assigned auditor reviews the client's submission within the platform. They have two options: accept (closing the NC) or reject (sending it back for another round). If they accept, the NC status changes to "Closed" with a timestamp and the auditor's identity recorded. If they reject, they provide a reason, and the NC returns to the client for a new submission.
Step 4: Rejection and resubmission. When an NC is rejected, a new round begins. The client sees the rejection reason and can upload a revised corrective action. The auditor reviews again. Each round is recorded with its own history: submission date, evidence uploaded, review date, decision, and reason. The NC record shows the complete journey from issuance through every round to final closure.
Step 5: Workflow gating. This is the critical enforcement mechanism. An open NC gates the certification workflow. If a major NC from Stage 2 has not been formally closed, the file cannot advance to the committee review phase. The system does not allow the certification process to proceed until all NCs are resolved. This prevents the scenario where a certificate is issued while NCs are still technically open.
What the Assessor Sees
Now replay the accreditation assessment scenario with Certiva. The assessor asks to see NC #7. The quality manager opens the client record and navigates to the NC section. The entire lifecycle is visible: the original finding with classification and clause reference, the auto-computed due date, Round 1 with the client's submission (timestamped), the auditor's rejection with a documented reason, Round 2 with the client's revised submission, and the auditor's acceptance closing the NC. Every piece of evidence is linked. Every decision has a timestamp and the identity of the person who made it. The assessor verifies the entire closure process in two minutes.
The Difference Between a Status and a Record
A spreadsheet that says "Closed" is a status. It tells you where things stand but not how they got there. A structured NC lifecycle in Certiva is a record -- every step, every submission, every decision, every timestamp.
When the accreditation body asks "show me the closure evidence for NC #7," the answer should take seconds, not a search through email. That is the difference between tracking nonconformities and managing them.