Most small quality teams collect nonconformance data diligently and analyse almost none of it. Findings are raised, recorded, actioned and closed, one at a time. The register grows. At management review, someone reports how many were raised and how many were closed.
That is counting, not analysis. And the data already sitting in that register usually contains the answer to a question the site has been asking for two years: why does the same problem keep coming back?
The obstacle is rarely capability. It is that the data was never structured in a way that permits analysis.
Structure the data before you try to analyse it
Free-text descriptions cannot be trended. If every nonconformance is recorded as a paragraph, the only analysis possible is reading all of them, which nobody has time for.
The enabling decision is a fixed category taxonomy — somewhere between ten and fifteen categories, applied consistently. Something like: cleaning and sanitation, maintenance and equipment, personal hygiene, pest control, allergen control, documentation and records, traceability, calibration, temperature control, training and competence, chemical control, foreign body control, supplier and incoming.
Alongside the category, capture for each nonconformance:
- Date raised and date closed
- Area or process where it occurred
- Source — internal audit, external audit, customer complaint, routine inspection, staff report
- Severity classification
- Root cause category, using a second short fixed list — system design, procedure inadequate, training and competence, equipment condition, resourcing, supplier, communication
- Whether it is a repeat of a previously closed finding
Adding these fields to your existing form costs very little. Without them, nothing below is possible.
Four analyses that need nothing more than a spreadsheet
1. Pareto by category. Count nonconformances by category and sort descending. The distribution is almost always concentrated: a small number of categories generate most of the findings. This tells you where improvement effort will actually pay, as opposed to where it feels most urgent.
2. Recurrence analysis. For each category, count how many findings were raised after a previous finding in that same category was closed. This is the single most valuable analysis available, because recurrence means the corrective action process is not working. A closed action followed by the same finding six months later was not an effective action — it was an administrative closure.
3. Time-to-closure and overdue ageing. Calculate days from raised to closed by category and severity, and age the currently open ones. Two patterns are worth watching: categories that consistently take longest (usually those needing capital or cross-departmental cooperation), and findings that sit open past their due date without escalation, which indicates the tracking system has no teeth.
4. Source analysis. Count findings by who found them. Then compare internal detection against external detection — internal audit and staff reports versus customer complaints and external audits.
That ratio is a direct measure of how well your own detection is working. If customers and external auditors find more of your significant problems than you do, the internal program is not performing, regardless of how many audits it completed.
The two metrics worth reporting every month
Of everything above, two carry the most information:
- Recurrence rate — the proportion of findings that repeat a previously closed finding. A rising recurrence rate means corrective actions are being closed prematurely, and it will predict an external audit problem before that problem arrives.
- Internal-to-external detection ratio — what proportion of significant findings you found yourselves.
Both are calculable from the fields above, both fit on one line of a management review pack, and both describe system health rather than activity volume.
Cautions when the numbers are small
Small teams generate small datasets, and small datasets mislead easily.
- Do not over-interpret month-to-month movement. Three findings becoming five is noise. Look at rolling quarters.
- Normalise where you can. Findings per audit conducted, or per production shift, rather than absolute counts — otherwise a busier audit month looks like a deteriorating system.
- A rise in reported nonconformances is often good news. It usually means detection improved or reporting became safer, not that performance declined. Read it alongside the source analysis before concluding anything.
- Watch for category drift. If two people classify differently, trends become meaningless. Write one-line definitions for each category and review consistency occasionally.
Make it a management review input
Nonconformance analysis has a natural home in management review, where food safety management system requirements already expect nonconformities, corrective actions and audit results to be considered as inputs.
Presenting a Pareto chart, a recurrence rate and a detection ratio turns that agenda item from a status update into a decision-making input. It is also considerably more persuasive when asking for resources: "cleaning and sanitation accounts for 40% of our findings and has a 30% recurrence rate" makes a case that "we keep having cleaning issues" does not.
Practical takeaways
- Add a fixed category field and a root cause category field to your nonconformance form. Everything else depends on this.
- Run a Pareto by category quarterly and direct improvement effort at the top two.
- Track recurrence rate as a headline metric. It measures whether your corrective action process works.
- Compare internal versus external detection and report it at management review.
- Use rolling quarters, not months, and normalise counts against activity.
- Do not panic at a rising count until you have checked whether detection improved.
The register you already keep contains a description of how your system actually behaves over time. Counting it tells you how busy you were. Analysing it tells you what to fix.