Ask a quality manager where most of their QMS effort goes and the answer is usually CAPA — Corrective and Preventive Action. Yet many CAPAs close without changing anything: the root cause reads 'operator error', the action is 'retrained the operator', and six months later the same non-conformity reappears with a new CAPA number attached.
This guide explains how correction, corrective action and preventive action actually differ, what ISO 13485:2016 and the FDA's QMSR expect from your CAPA system, and how to run a seven-step process that produces CAPAs you can defend in an audit — with a worked example you can adapt to your own records.
A CAPA system is a feedback loop, not a form
CAPA exists to make the QMS learn. If the same finding keeps returning, the loop is broken somewhere — usually at root cause or effectiveness verification — not at the paperwork.
1. Correction, corrective action, preventive action
The three terms are not interchangeable, and auditors notice when they are mixed up. Getting the language right is the first step, because each term implies a different response and a different record.
| Term | What it does | Where it lives in ISO 13485 | Example |
|---|---|---|---|
| Correction | Fixes the immediate problem; does not address the cause | Clause 8.3 (nonconforming product control) | Quarantining and sorting defective units out of a batch |
| Corrective action | Eliminates the cause of an existing nonconformity so it does not recur | Clause 8.5.2 | Requalifying the bonding station that produced the defect |
| Preventive action | Eliminates the cause of a potential nonconformity before it occurs | Clause 8.5.3 | Adding a process control after a near-miss trend, before any defect ships |
Under the FDA's Quality Management System Regulation (QMSR), which incorporates ISO 13485:2016 by reference, the terminology converges: correction, corrective action and preventive action must be distinct, documented and trended. One well-designed CAPA process can serve both frameworks, provided the data sources, records and trending that FDA expects are built in from the start.
| Clause | The requirement in one line | What an auditor actually tests |
|---|---|---|
| 8.2.1 | Feedback is collected and monitored as one of the measurements of QMS performance | Is there a visible thread from feedback data to CAPA initiation? |
| 8.3 | Nonconforming product is identified, controlled and dispositioned | Are corrections recorded as corrections, not dressed up as corrective actions? |
| 8.4 | Data analysis covers feedback, conformity, suppliers and processes | Do trends from production, audits and suppliers feed the CAPA system, or only complaints? |
| 8.5.2 | Action is taken to eliminate the cause of actual nonconformities | Did the action remove the cause — or only the symptom? Did it recur? |
| 8.5.3 | Action is taken to eliminate the cause of potential nonconformities | Where do preventive actions come from, and is the absence of them justified? |
2. The seven-step CAPA process
A defensible CAPA follows the same sequence every time. Skipping a step is what turns a CAPA into paperwork. For each step, keep the evidence — the record is what the auditor samples.
- 1Identify and document the problem. Sources include complaints, internal audits, production data, supplier performance and trends. State what happened, where, when, how many, and which product or batch.
- 2Triage by risk. Not every deviation deserves a CAPA — but every decision either way needs a documented justification. Risk decides the depth of the investigation, not convenience.
- 3Contain. Quarantine, sort, hold shipments, notify affected customers if needed. A correction protects the customer; it is not the corrective action and should be recorded separately.
- 4Investigate. Gather the evidence: batch records, logs, calibration data, interviews. Define the problem precisely before explaining it — most weak investigations start with an assumed cause.
- 5Determine root cause. Use a structured method (5 Whys, fishbone, fault tree), verify the cause against objective evidence, and document why alternative causes were rejected.
- 6Act. Implement corrective actions for the actual cause and preventive actions where a potential problem was identified. Assign owners and due dates, and update risk management files, procedures and training where the actions require it.
- 7Verify effectiveness, then close. Define success criteria and a timeframe before closure, verify against data, and feed the result to management review.
| Step | Output | Evidence to keep |
|---|---|---|
| Identify | Documented problem statement | Source record: complaint, audit finding, trend report |
| Triage | Risk-based open/no-CAPA decision | Risk rationale, even when no CAPA is opened |
| Contain | Immediate exposure controlled | Correction record, disposition, customer notifications |
| Investigate | Precise problem definition and data | Batch records, logs, analysis worksheets |
| Root cause | Verified cause with rejected alternatives | Method used, evidence, rejection rationale |
| Act | Implemented actions with owners and dates | Updated procedures, risk file entries, training records |
| Verify & close | Effectiveness conclusion | Predefined criteria, sampled data, closure approval |
3. A worked example: one complaint, end to end
Scenario: three complaints arrive over eight weeks reporting that an infusion set's tubing cracks at the luer connector within two hours of infusion start. Here is the same CAPA done weakly and done well.
| Step | Weak version (will not survive an audit) | Strong version (defensible) |
|---|---|---|
| Problem statement | 'Tubing issue reported' | '3 complaints in 8 weeks: tubing cracks at the luer connector within 2 hours of infusion start; complaints cluster on one production batch' |
| Root cause | 'Operator error at the bonding station' | 'Bonding temperature drifted out of the validated range after a heater replacement; confirmed against temperature logs and verified with a 5 Whys trace' |
| Action | 'Retrained the operator' | 'Revalidated bonding parameters; heater replacement now triggers partial requalification; interim 100% inspection on affected batches' |
| Effectiveness | 'No complaints since' | 'Zero recurrences across 6 months and 3 production lots; temperature SPC shows the process back in control' |
| Closure | 'Closed 5 days after the action' | 'Closed after the pre-agreed 6-month effectiveness window; residual risk in the risk file reviewed and updated' |
The weak column has a pattern
Every weak entry replaces evidence with a statement. 'No complaints since' is a claim; 'zero recurrences across 6 months and 3 lots' is a record. Auditors sample records, not claims.
4. Root cause quality: the make-or-break step
'Operator error' fails not because operators never err, but because it names a person instead of a system. If a person made a mistake, the auditor's question is: what in the system allowed that mistake to reach product — or to go undetected until it did?
- A real root cause explains why, not just what — trace from the symptom down to a controllable process cause.
- It is verified against evidence: logs, records, measurements — not agreed in a meeting.
- It passes the recurrence test: remove this cause and the event cannot repeat the same way.
- 5 Whys must stop at a process cause. If the fifth 'why' is a person, keep asking.
- A fishbone helps rule out categories — method, machine, material, measurement, environment, people — and the record should say why rejected causes were rejected.
Two phrases that invite findings
'Human error' combined with 'retrained the operator' is the most commonly cited CAPA weakness in audits and inspections. If retraining is the action, show what changed in the system that made the error possible in the first place.
5. Effectiveness verification: prove it worked
ISO 13485 requires review of the effectiveness of corrective action (8.5.2) and preventive action (8.5.3) — but a closure box that says 'verified' is not a review. Verification is a planned activity with its own evidence.
- Define the success criteria before the action is implemented — not on the day of closure.
- Set the timeframe from the process cycle time and production volume, not from convenience.
- Sample enough data: repeat events, complaint rates, SPC trends, internal audit results.
- Include the negative test: what evidence would have shown the action failed? If nobody can answer, the verification was a formality.
- Record the verification itself — data, dates, sampler — as a record attached to the CAPA.
- If effectiveness is not demonstrated, the CAPA reopens. That is the system working, not failing.
Auditor tip: test the verification, not the closure date
Ask the CAPA owner to show the effectiveness data and then ask: 'What would this data have looked like if the action had failed?' If they cannot answer, the check was a formality — and it will read that way in the report.
6. Where weak CAPAs get found
Auditors and FDA investigators look for the same weak-evidence signals. Use this table as a self-check before they do.
| Clause / area | Weak-evidence signal | What good looks like |
|---|---|---|
| 8.5.2 | Root cause = operator error; action = retraining | System-level cause verified against records, with rejected alternatives documented |
| 8.5.2 / 8.5.3 | Effectiveness = 'no recurrence', with no data | Predefined criteria, a defined timeframe and sampled records |
| 8.4 | CAPA sources limited to complaints | Production, audit, supplier and feedback trends all feed the CAPA system |
| 8.3 | Corrections recorded as corrective actions | Corrections and corrective actions are distinct records with distinct dispositions |
| 8.5.3 | No preventive actions on record, ever | Either an active preventive pipeline or a documented risk-based justification |
| 4.2.5 | Records closed unsigned, undated or incomplete | Complete, attributable, contemporaneous records a third party can follow |
7. Quick CAPA checklist
Use this on every CAPA before you close it
- Problem statement is specific: what, where, when, how many, which product or batch
- Risk-based decision recorded to open — or deliberately not open — a CAPA
- Correction (containment) is recorded separately from the corrective action
- Investigation method is documented (5 Whys, fishbone, fault tree) and actually followed
- Root cause is verified against objective evidence, not opinion
- Rejected alternative causes are documented with a reason
- Actions address the cause, with owners and due dates
- Risk file, procedures and training updated where the actions require it
- Effectiveness criteria and timeframe defined before closure
- Effectiveness verified against data — dates, samples, trends — not statements
- A failed effectiveness check reopens the CAPA instead of closing it
- Result fed to management review and back to the trend data that triggered it
8. Where to go next
If you want to build CAPA handling into a repeatable skill — precise terminology, investigation technique, root cause quality and audit-ready records — the free CAPA Fundamentals course covers all of it with realistic examples, decision tables and a certification exam at the end.
Related training
CAPA Fundamentals: A Practical Guide for Medical Devices
A free self-paced course with realistic examples, decision tables, workflow diagrams, quick-reference notes and a certification exam.
View the course Browse free courses