Non-conformance, anomaly, deviation: what are the differences?

Non-conformance, anomaly or deviation: how to classify a discrepancy without wasting time? Clear definitions, decision criteria and industrial examples.

    In industry, the same observation can be described in draft ways: non-conformity, anomaly, or even a request for concession. This confusion is not merely semantic.

    Concretely, it leads to:

    • inconsistent decision-making channels,

    • poorly dimensioned corrective actions,

    • risks of regulatory non-compliance,

    • continuous improvement that stalls, due to a lack of capitalisation.

    The objective of this article is simple: to provide you with clear definitions, operational criteria and a decision-making method applicable in the field to know:

    • when to raise a non-conformity report,

    • when to treat an event as an anomaly,

    • when a concession can be considered and under which conditions.

    1. Non-conformity: non-fulfillment of a requirement

    1.1 Definition

    A non-conformity is the non-fulfillment of an applicable requirement.

    This requirement can stem from:

    • a customer specification,

    • a control plan,

    • an internal procedure,

    • a standard,

    • a regulatory obligation.

    Non-conformity can relate to a product, a process, a service or a document.

    1.2 What this implies

    A non-conformity almost always calls for:

    • a correction (quarantine, sorting, rework, scrap, recall),

    • a disposition (decision on the fate of the product/batch),

    • and, depending on the criticality or recurrence, a structured corrective action (CAPA).

    The main challenge is traceability: the non-conformity must be recorded, analysed, treated and closed with proof of effectiveness.

    2. Anomaly: a warning signal, not always a non-conformity

    2.1 Definition

    An anomaly is an observed deviation or a noted malfunction, without it being immediately clear whether a requirement has been violated.

    It could be:

    • unusual behaviour of a machine,

    • doubt about a measurement,

    • a process drift,

    • a one-off deviation with no demonstrated impact.

    2.2 Why does this term exist?

    The anomaly serves as an entry level: it allows a quick investigation to be triggered, without systematically involving all the formalism of a non-conformity.

    But beware: an anomaly can become a non-conformity if:

    • an unfulfilled requirement is identified,

    • the deviation reoccurs,

    • or the risk is not managed.

    3. Concession: a temporary and formal acceptance of a deviation

    3.1 Definition

    A concession is a formal authorisation, limited in time (or volume), allowing a deviation from a requirement to be accepted, under conditions.

    It does not erase the problem. It allows a situation to be managed in a controlled manner when:

    • business continuity is at stake,

    • compensating measures exist,

    • and the residual risk is accepted by an authorised authority.

    3.2 What a concession file must contain

    A concession must be traceable and audit-ready. It generally includes:

    • the description of the deviation and its scope (batches, references, duration),

    • a technical justification,

    • a risk analysis (safety, conformity, performance),

    • compensating measures (reinforced controls, usage restrictions),

    • an end date or a maximum volume,

    • an authorised signatory.

    Without these elements, the "concession" becomes a governance non-conformity, hence an audit risk.

    4. How to decide: simple distinction criteria

    To correctly qualify an event, ask three questions.

    4.1 Is a requirement violated?

    • Yes: non-conformity.

    • No / not certain: anomaly (quick investigation).

    4.2 Can the deviation be accepted temporarily?

    • Yes, under conditions and formal validation: concession.

    • No: classic disposition (sorting, rework, scrap, hold).

    4.3 What is the level of risk?

    Criticality must be assessed using objective criteria:

    • safety / regulatory compliance impact,

    • product functional impact,

    • frequency / recurrence,

    • scope (one station, one line, one site, one supplier),

    • detectability.

    The higher the risk, the more structured the response must be (escalation, CAPA, management review).

    5. Operational comparison

    5.1 Quick summary

    • Anomaly: signal, observation, short investigation, can evolve.

    • Non-conformity: unfulfilled requirement, disposition + traceability, often CAPA depending on criticality/recurrence.

    • Concession: temporary acceptance, formal file, risk analysis, compensating measures, authorised signature.

    5.2 Decision-making table to integrate into your procedures

    For field use, a simple table is sufficient, containing:

    • type of deviation,

    • trigger,

    • immediate action,

    • evidence requirements,

    • responsible owner,

    • target deadline,

    • closure conditions.

    This is an excellent candidate to integrate into a digital QMS to standardise qualification.

    6. Detection, recording and monitoring

    6.1 Record quickly, record well

    Regardless of the term used initially, the quality of the treatment depends on factual recording:

    • date/time, station, line, batch,

    • observable description,

    • evidence (photos, measurements, reports),

    • initial criticality,

    • status (isolated / in progress / closed).

    A unique identifier and a timestamp are essential for traceability.

    6.2 Useful indicators

    To monitor, focus on a few KPIs:

    • average processing time,

    • recurrence rate,

    • reopening rate,

    • cost of non-quality (scrap, rework, downtime),

    • distribution of deviations by type and criticality.

    7. Root cause analysis and CAPA: when and how?

    7.1 The goal is not just to "fill out a form"

    For recurring or major non-conformities, the critical point is root cause analysis and the effectiveness of the action plan.

    Suitable methods:

    • 5 Whys (quick validation in the field),

    • Ishikawa (structured group exploration),

    • Pareto (prioritisation),

    • FMEA (if the risk is high).

    7.2 What makes an effective CAPA

    A robust CAPA must link:

    • proven root cause,

    • sustainable corrective action,

    • preventive action,

    • owners and deadlines,

    • measurable effectiveness criteria,

    • planned verification before closure.

    8. Governance best practices

    8.1 Clarify roles

    A simple RACI avoids ambiguity:

    • production: quarantine, collection of evidence,

    • quality: qualification, disposition decision, CAPA management,

    • methods / industrialisation: process corrections,

    • management: arbitration of concessions and resources on major issues,

    • suppliers: external corrective actions.

    8.2 Digitise to avoid drift

    Digitisation is not about "using software". It is used to:

    • impose a unique workflow,

    • avoid Excel/email duplication,

    • trace decisions and evidence,

    • manage deadlines and reminders,

    • quickly find history and similar cases.

    9. Sector-specific examples

    9.1 Aerospace

    The boundary between non-conformity and concession is strict. A concession requires solid technical justification, an authorized authority, and impeccable traceability.

    9.2 Automotive

    Volumes make recurrence critical. A deviation starting as an anomaly can quickly escalate to a major non-conformity if indicator trends deteriorate (scrap, returns, PPM).

    9.3 Energy

    Business continuity may push for temporary concessions, but they must be strictly regulated (risk, duration, compensating measures, control).

    FAQ

    Must an anomaly always become a non-conformity?
    No. An anomaly is a signal. It becomes a non-conformity if an unfulfilled requirement is confirmed or if the risk is not managed.

    When is a concession acceptable?
    When the residual risk is assessed, controlled, documented, and formally accepted by an authorised authority, with a limited duration or volume.

    Why do audits often penalise concessions?
    Because many organisations accept "informal" deviations without a file, risk analysis, or proof of control.

    Conclusion

    Non-conformity, anomaly and concession do not trigger the same responsibilities, nor the same requirements for proof.

    The operational distinction is simple:

    • if a requirement is violated → non-conformity,

    • if it is a signal without a confirmed requirement → anomaly (quick investigation),

    • if the deviation must be accepted temporarily → concession (formal file, managed risk, limited duration).

    The key is not the vocabulary. It is the ability to qualify quickly, decide consistently, and capitalise on history to prevent recurrence.

    Continue reading

    The latest innovations in Industry 4.0

    Yxir application screen with notification of similar non-conformities detection, illustrating the platform's added value

    Discover Yxir in action on your challenges

    Book a personalised demo and discover how our platform built for industry reduces your non-conformances, accelerates your resolutions, and improves your performance indicators.

    Discover Yxir in action on your challenges

    Book a personalised demo and discover how our platform built for industry reduces your non-conformances, accelerates your resolutions, and improves your performance indicators.

    Discover Yxir in action on your challenges

    Book a personalised demo and discover how our platform built for industry reduces your non-conformances, accelerates your resolutions, and improves your performance indicators.