The Workbench · Craft
What a nonconforming-product record has to decide before it's closed
A nonconforming-product record is often built as a funnel: log the defect, open an investigation, and let it run into the CAPA system as a matter of course. ISO 13485:2016 Clause 8.3 doesn't ask for that funnel. It gives an organization three ways to close a nonconformance on its own — rework it, preclude its use, or authorize it under a documented concession — and reserves corrective action, under Clause 8.5.2, for the separate question of whether the nonconformity's cause needs to be found and removed. A record that routes every nonconformance into a CAPA number is doing more work than the standard requires. A record that never asks the second question is doing less than the standard demands.
Three ways to close it, and disposition isn't a euphemism for done
Clause 8.3.1 requires the organization to deal with nonconforming product by one or more of: taking action to eliminate the detected nonconformity, which is rework; taking action to preclude its original intended use or application, which covers scrap, downgrade, or return to a supplier; or authorizing its use, release, or acceptance under concession. Each of those is a legitimate, standard-sanctioned way to close the record without ever opening a corrective action, and a nonconformance log that treats “dispositioned” as an incomplete status until a CAPA number gets attached to it is adding a step the clause doesn't require for an isolated event.
Concession is a decision with a paper trail, not a shrug
Authorizing use under concession is the disposition most likely to get treated casually, because on the record it can look identical to simply deciding a defect doesn't matter. The standard doesn't allow that: product can be accepted by concession only if justification is provided, authorization is obtained from someone with the authority to grant it, and applicable regulatory requirements are still met, with a record naming who authorized it. A record with a concession box checked and no linked justification, no named approver, and no note on whether a regulatory requirement applied has recorded a decision without recording the reasoning the standard requires to exist behind it.
The question the record has to keep asking
Closing a single nonconformance under 8.3.1 answers a narrower question than whether the underlying cause needs fixing. That's Clause 8.5.2's territory, and the two clauses are only connected by a judgment call the record has to force explicitly: does this nonconformity, or the pattern it belongs to, indicate a cause that's likely to recur or already has. A record that never asks this question in a structured field — not a free-text comment, a field that has to be answered one way or the other before the record closes — is the same gap a CAPA tracker shows when it can't distinguish a genuine root cause from restated containment. Here the failure runs the other direction: nonconformances quietly dispositioned, over and over, without anyone ever being forced to notice the pattern across them.
After delivery, disposition isn't the end of the record either
Clause 8.3.3 covers the harder case: a nonconformity discovered after the product has already been delivered or is in use. It requires the organization to take action appropriate to the effects of the nonconformity, and, where applicable, to issue advisory notices — with records of both the action and the notice maintained. A nonconformance log built only around pre-shipment dispositions has no place to put this record at all, which means the one nonconformance category with the highest actual risk to a device already in use is the one most likely to fall outside the system built to track it.
Rework gets its own control, not a shortcut back to normal
Clause 8.3.4 doesn't treat rework as simply redoing the step that failed. The rework procedure has to account for the potential adverse effect the rework itself might have on the product, and it's subject to the same review and approval as the original work instruction it's modifying — not a lighter, faster sign-off because it's a correction rather than the primary process. Once rework is complete, the product has to be verified against its acceptance criteria again, and that verification, along with the rework itself, has to be recorded. A record that shows “reworked” with no linked verification has closed the loop on paper without closing it in fact.
Where the section moved
21 CFR 820.90, nonconforming product's old home in the CFR, is one of the sections the Quality Management System Regulation reserved when it took effect on February 2, 2026 — the same renumbering that retired the CAPA and purchasing-controls citations most quality teams still reach for from memory. Clause 8.3 is where the requirement lives now; a nonconformance SOP still citing 820.90 for its structure is citing a section that no longer states one.
A nonconforming-product record built around these distinctions — the three dispositions, a forced CAPA-trigger decision, the post-delivery advisory-notice path, and rework's own verification step — is previewed in the launch catalog. If your program handles the CAPA-trigger judgment differently, the shelf takes that correction directly.
The Regulatory Toolkit launches soon — a free shelf of source-mapped templates, checklists and browser-only tools for regulatory teams. Get one email when it opens, or contribute a template.