RJC Audit Nonconformities: What Trips Up Exporters

Most RJC audit nonconformities don't come from a missing policy or an unfamiliar requirement. They come from documentation, staff interviews, and floor observations that don't quite match each other, plus a set of gaps that show up in predictable places once you look at enough audits. Knowing where these issues cluster, both during the audit itself and in the years after certification, makes them far easier to catch before an auditor does. That matters because the cost of a finding is rarely the finding itself. It is the corrective action window, the follow-up evidence, and in some cases a second visit before certification can move forward.
What counts as a nonconformity in an RJC audit
The Responsible Jewellery Council (RJC) certifies jewellery and gemstone companies against its Code of Practices (COP), which covers ethics, human rights, environmental management, and product integrity. A nonconformity (NC) is any point where an auditor finds that a requirement isn't fully met. A major NC usually involves a systemic failure or a legal breach and can hold up certification on its own. A minor NC is a narrower gap: an isolated instance, an incomplete record, a step that isn't applied the same way every time. Minor NCs need to be closed within an agreed timeframe, but they don't block certification by themselves. In practice, a company can close several minor NCs with corrective evidence and still be certified on schedule, which is one reason it helps to know in advance which categories they usually fall into.
Where exporters run into trouble during the audit
By the time most companies reach the audit stage, they have already read the requirements and built out documentation, and on paper the policies usually look reasonable. The trouble starts when an external auditor tests that documentation against staff interviews and what they observe on site. RJC certification is assessed at company level, so auditors are checking whether a business actually runs the way its paperwork says it does.
Policies that exist but aren't applied the same way twice
Many companies introduce procedures well before the audit, then run into trouble with how consistently those procedures are followed across teams and shifts. Supplier checks might happen in practice but get recorded differently each time. HR policies might be written down but not fully understood by the staff who are supposed to follow them. These inconsistencies tend to surface quickly once an auditor starts asking employees to describe their own process in their own words.
Records that can't be produced quickly
RJC places real weight on traceability and due diligence across the supply chain. In practice, the underlying information often exists. It is just spread across departments, inboxes, and individual spreadsheets rather than a single system. During an audit, pulling that information together on short notice takes time, and any gaps become more visible under pressure than they ever were during normal operations.
No clear owner for a given requirement
RJC expects clear ownership across compliance, sourcing, HR, and environmental management. When a responsibility is shared informally, or several people assume someone else is handling it, coordination slows down. That usually shows up as delay in producing evidence during the audit, which auditors tend to read as a control gap even when the underlying work is actually being done.
Knowledge that lives in one person's head
In smaller or family-run operations, a lot of practical knowledge sits with one or two long-serving staff members rather than in a written procedure. That works fine day to day, but it becomes a problem in an audit, because an auditor cannot verify a control that exists only as a habit someone carries around. If that person is unavailable on audit day, or simply describes the process differently than the file does, the gap between memory and documentation becomes a finding.
→ See: RJC Certification: What Jewellery and Gemstone Exporters Should Prepare Before They Start
What IA's audit data shows about where nonconformities concentrate
It helps to look at where these gaps actually land once you get past the individual anecdotes. An audit dataset compiled by International Associates Limited (IA), Agence de Tounens' certification audit partner, tracked 664 active findings across 75 companies certified in Thailand. Eighty-eight percent of the minor nonconformities in that dataset were concentrated in health and safety documentation, not in the supply chain or business ethics requirements that most companies spend the most time preparing for.
That's a useful reality check for where preparation time actually goes. Companies tend to put the most effort into supply chain traceability and business ethics, because those areas feel higher-stakes and get the most attention in RJC guidance. Health and safety documentation (training records, incident logs, PPE issuance, risk assessments reviewed on schedule) gets treated as routine paperwork and slips. IA's figures suggest that is exactly where the checkable, day-to-day items pile up as findings.
None of this means supply chain and ethics requirements don't matter. It means the health and safety file is worth a second pass before the audit, specifically checking that dates are current, that records are complete for every site and shift, and that what is in the file matches what staff describe when asked.
What gets overlooked after certification
The audit itself is one stage in an ongoing cycle. Once certification is granted, the same systems are expected to keep operating and to hold up under surveillance audits, not just perform well once. Records need to keep being maintained, supplier information needs to stay current, and internal practices need to keep being tracked the same way they were in the run-up to the first audit. RJC certification usually runs on a multi-year cycle with surveillance checks in between full recertification, so the gap between audits is exactly when maintained systems either stay in shape or quietly drift.
Systems built only to pass the initial audit tend to weaken once the pressure is off. A supplier list that was current the week of the audit can go stale within a year if nobody owns keeping it updated. Training logs stop being filled in once the person who built the habit moves on or changes roles. None of this causes a problem right away. It tends to surface at the next surveillance audit, often as a new finding in an area that was clean the first time around.
Maintaining certification takes the same level of structure as preparing for it the first time. The difference is that the work is spread out over the certification cycle rather than compressed into a few weeks before an audit date.
Where the RJC Pre-Audit Readiness Checklist fits
Before an audit, or even partway through preparation, it helps to step back and check how your systems would hold up under this kind of review. The RJC Pre-Audit Readiness Checklist is built around how RJC audits actually run: document review, staff interviews, and observation of operations, scored across three dimensions rather than a single pass or fail.
It is designed to surface the kind of gaps described above: where documentation is incomplete, where practices are not applied consistently, and where a requirement has no clear owner, before an external auditor finds them first.
Frequently asked questions
What is the most common RJC audit nonconformity?
Based on audit data compiled by International Associates Limited (IA) across 75 RJC-certified companies in Thailand, 88 percent of minor nonconformities in that dataset were found in health and safety documentation rather than supply chain traceability or business ethics. Training records, incident logs, and risk assessments are the items most likely to have gaps.
What is the difference between a major and a minor nonconformity?
A major nonconformity is a systemic failure or a legal breach and can hold up certification until it is resolved. A minor nonconformity is a narrower gap, such as an inconsistent record or an isolated lapse, that needs to be corrected within an agreed timeframe but does not block certification on its own.
Do RJC audit issues stop once a company is certified?
No. Certification requires ongoing surveillance audits, and systems built only to pass the initial audit tend to weaken once daily pressure eases off. Supplier records go stale, training logs stop being updated, and gaps that did not exist at first certification often appear at the next review.
How can a company find its own gaps before an auditor does?
The most reliable way is to test documentation, staff knowledge, and actual practice against each other, the same way an auditor would, rather than reviewing policies on their own. The RJC Pre-Audit Readiness Checklist is built around that same three-part structure so gaps surface internally first.