What Is CAPA (Corrective and Preventive Action)

Introduction

The same nonconformity keeps showing up on the line. Every time, someone patches it, closes the paperwork, and moves on, until it resurfaces three months later during the next audit.

That's not bad luck. It's usually a sign that the "fix" only touched the symptom, never the cause.

CAPA, or Corrective and Preventive Action, exists to stop that cycle. It's the two-part problem-solving process at the center of every serious quality management system: correct what happened, and prevent what hasn't happened yet.

You'll find it running through aerospace, medical device manufacturing, general manufacturing, and everywhere else a regulator or a registrar shows up with a checklist.

This guide covers what CAPA actually means, how it connects to root cause analysis, the five-step process auditors expect to see, a real workplace example, and the mistakes that quietly sink most CAPA programs.

Key Takeaways

  • CAPA pairs corrective action (fix what failed) with preventive action (stop what could fail next).
  • Corrective action responds to an existing nonconformity; preventive action targets a risk that has not occurred.
  • Root cause analysis makes CAPA real — without it, you only treat symptoms.
  • ISO 9001, AS9100D, ISO 13485, and FDA 21 CFR 820 require documented CAPA; it ranks among top audit findings.
  • Passing CAPA training is not the same as choosing the right method when a live nonconformity hits.

What Is CAPA? Definition, Meaning & Regulatory Context

CAPA is a systematic approach used across manufacturing, aerospace, healthcare, and life sciences to identify, investigate, and resolve nonconformities in products, processes, and systems.

The point is permanence: solve the root problem once instead of patching the same issue repeatedly.

Corrective Action vs. Preventive Action Explained

The two halves of CAPA solve different problems:

  • Corrective action is reactive. It eliminates the root cause of a nonconformity that has already happened, so it doesn't recur.
  • Preventive action is proactive. It eliminates the root cause of a nonconformity that hasn't happened yet but could, based on trends, risk data, or a near miss.

Mixing these up is common. Fixing a defective batch is a correction. Figuring out why the batch went bad and stopping it from happening again is the corrective action.

Where CAPA Fits in the PDCA Cycle

CAPA maps directly onto the Plan-Do-Check-Act cycle. Problems surface in the Check phase, when you're reviewing data, audits, or complaints. They get resolved and prevented in the Act phase, when you implement and standardize the fix. In practice, CAPA is the Act phase done formally and documented.

Which Standards Require CAPA

There's no single universal CAPA template, but the underlying requirement shows up almost everywhere:

Standard Where CAPA lives
ISO 9001:2015 Clause 10.2, Nonconformity and Corrective Action
AS9100D Clause 10.2.1, with specific causal-analysis requirements
ISO 13485:2016 Clause 8.5.2 (Corrective) and 8.5.3 (Preventive)
FDA 21 CFR 820.100(a) Historical QSR requirement; folded into the QMSR from Feb 2026
ISO 14001 / ISO 45001 Clause 10.2, Nonconformity and Corrective Action

The stakes aren't theoretical. In FY2017, CAPA-related issues accounted for 1,168 of 3,519 total Form 483 observations, or 33%, making it the single most-cited subsystem in FDA device inspections that year. If your CAPA process is weak, it's likely to be the first thing an auditor finds.

CAPA and Root Cause Analysis: How They Work Together

Root cause analysis (RCA) is the investigative engine inside CAPA. You cannot select the right corrective or preventive action without first understanding what actually caused the problem. Skip this step, and you're guessing.

Three RCA methods show up most often inside a CAPA process:

  • 5 Whys — good for pushing a team past the obvious answer into deeper causes, especially on straightforward problems.
  • Fishbone (Ishikawa) diagrams — useful when there are many possible contributing factors to sort and categorize before you can isolate the real one.
  • Fault Tree Analysis — better suited to complex engineered systems, working backward from a defined failure to the combinations of events that could produce it.

Three root cause analysis methods 5 Whys Fishbone Fault Tree comparison

The "Human Error" Trap

Here's where a lot of CAPAs fail. A problem gets blamed on "operator error," the operator gets retrained, and the file gets closed. Then it happens again six months later with a different operator.

Most repeat problems blamed on human error actually trace back to an unchanged process or system gap: unclear work instructions, missing controls, poor tooling, or a training program that never addressed the real skill gap. A genuine one-time human error should only be the final conclusion after every other cause has been ruled out, not the first convenient answer.

Finding those system gaps takes a cross-functional team. The point where a problem is detected—an inspection station, a customer complaint, a field return—is rarely where the root cause lives. That usually sits upstream: design, purchasing, or a process step nobody thought to question.

Rushing past RCA to jump straight to a "fix" is one of the most common reasons CAPAs fail verification and the same nonconformity comes back.

The CAPA Process: 5 Steps From Detection to Verification

No single regulatory body mandates one exact CAPA template, but effective programs consistently follow the same five-stage arc.

1. Detection & Problem Identification

Document the who, what, when, where, and how of the issue. Then run a risk-based assessment to set urgency:

  • Safety-critical defect → same-day response
  • Minor documentation gap → lower priority, still tracked

2. Investigation & Root Cause Determination

Apply the appropriate RCA method for the complexity of the problem. Keep end-to-end traceability from the identified root cause through to every action step that follows, so an auditor can follow the logic later.

3. Containment & Correction

Stabilize the situation immediately before you design the long-term fix. Typical containment moves include:

  • Quarantining nonconforming product
  • Halting an affected process
  • Isolating impacted units

This buys time without letting the problem spread.

4. Implementing Corrective & Preventive Actions

Roll out the corrective action to eliminate the root cause of the existing nonconformity. Add preventive action where the same cause could create a future nonconformity elsewhere in the system. Common actions include:

  • Process or procedure changes
  • Targeted retraining
  • Supplier corrective action requests
  • Design or tooling updates

5. Verification of Effectiveness

Confirm the nonconformity is actually resolved. Monitor for a defined period to make sure the change didn't introduce a new problem. Document the outcome as objective evidence — a written action plan is not a completed, effective CAPA.

5-step CAPA process flow from detection to verification of effectiveness

CAPA Example: What It Looks Like in the Workplace

Here's a simple, complete example. During final inspection, an operator catches a defective part with an out-of-tolerance dimension.

  1. Detection: The part fails inspection. The lot is flagged and the quality team is notified.
  2. Investigation: RCA traces the defect to a worn tooling fixture that had drifted out of spec between calibration cycles.
  3. Containment: The affected lot is quarantined and held from shipment while the fixture is pulled from service.
  4. Corrective action: The fixture is repaired or replaced, and the affected parts are reworked or scrapped.
  5. Preventive action: A tooling replacement and inspection schedule is added so drift is caught before it produces defects again.
  6. Verification: Follow-up dimensional checks on later runs confirm the defect has not returned, and the CAPA is closed.

The same logic holds across industries with small adjustments. In aerospace, a supplier delivering nonconforming parts triggers a Supplier CAPA rather than an internal tooling fix.

In an EHS context, a near-miss slip-and-fall might look like a simple cleanup. The real fix often needs a mechanical-integrity program that catches leaks before someone gets hurt, not just a mop and a warning sign.

What separates a real CAPA from an informal fix is the paper trail. A dated record connecting the problem, the root cause, the actions taken, and the verification of effectiveness is what an auditor actually reviews. No trail, no CAPA, regardless of whether the problem got fixed.

Common CAPA Mistakes & How to Build Real CAPA Competence

Most CAPA programs don't fail because nobody understands the theory. They fail in execution. The recurring mistakes look like this:

  • Restating the problem as the root cause — "the part was out of spec" is a symptom, not a cause.
  • Setting unreasonable deadlines that push teams to close CAPAs before effectiveness can actually be verified.
  • Flipping the verification order, borrowing habits from other problem-solving models where containment gets treated as if it were the final fix.
  • Letting political influence bloat the approval chain, so a straightforward CAPA sits for weeks waiting on sign-offs that add no diagnostic value.

According to ISO/IAF guidance on nonconformity closure, corrective action requires objective evidence of full implementation and effectiveness, not just a documented plan. That distinction is exactly where most CAPA files fall apart under audit scrutiny.

Why Training Alone Doesn't Fix This

Teams pass CAPA training regularly. They still freeze when a live nonconformity lands and they have to pick the right method under audit pressure, in the moment, with a clock running.

This is the specific gap QMS Learning's AI Workbench was built to close. Its Method Router takes a plain-language description of a live problem and diagnoses whether it is a process gap, isolated incident, supplier issue, or design flaw. It then recommends 5-Why, FMEA, CAPA, or Gap Analysis.

Take a problem like "the same defect appeared on three different jobs from the same supplier this quarter." In that case, the Router flagged a systemic pattern and generated a Supplier CAPA with a 5-Why attached, mapped to AS9100D §8.4.3 and ready to send. That workflow reflects founder Will Trikha's two decades writing and closing findings on aerospace audit floors, where the difference between "trained on CAPA" and "can run one under pressure" shows up every day.

QMS Learning AI Workbench Method Router diagnosing a live nonconformity

CAPA competence shouldn't sit with one senior quality engineer while everyone else escalates. When the diagnostic judgment is built into the tool, a junior engineer can work through a Clause 8.4.3 finding, generate an audit-ready report, and move on, without the whole quality function waiting on one person's calendar.

Frequently Asked Questions

What is CAPA in the workplace?

CAPA is the formal process employees and quality teams use to document a problem, fix it, and put a change in place so it doesn't happen again. It's often triggered by audits, customer complaints, or internal inspections.

What is the difference between RCA and CAPA?

RCA (root cause analysis) is the investigative method used to find the true source of a problem. CAPA is the broader process that uses those RCA findings to correct the issue and prevent it from recurring.

What is an example of CAPA?

A defective part caught during inspection gets traced to a worn tooling fixture. The lot is quarantined (correction), the fixture is fixed (corrective action), and a tooling replacement schedule is added (preventive action).

What does CAPA stand for?

CAPA stands for Corrective and Preventive Action, a two-part approach to fixing existing quality issues and preventing new ones from occurring.

What is the difference between corrective and preventive action?

Corrective action is reactive; it fixes the cause of a problem that already happened. Preventive action is proactive; it stops a potential problem from happening in the first place.

Is CAPA required by ISO 9001?

ISO 9001 requires documented corrective action under Clause 10.2; prevention is addressed through risk-based thinking. Related standards like ISO 13485 and AS9100D carry broader CAPA-style expectations as evidence of continual improvement.