
Corrective and Preventive Action is a two-part regulatory subsystem built to eliminate the root cause of nonconformities and stop them from happening again. It's required under 21 CFR 820.100 and ISO 13485:2016, Clauses 8.5.2 and 8.5.3. This isn't optional guidance.
This article is written for quality engineers, quality managers, and regulatory affairs professionals preparing for an FDA inspection or ISO 13485 audit. CAPA is one of the most referenced processes in the industry, and also one of the most misapplied. Companies overuse it, underuse it, or mistake completed paperwork for actual root cause elimination.
Here's what CAPA actually is, why regulators treat it as the backbone of a quality system, how the process runs step by step, and when it shouldn't be triggered at all.
Key Takeaways
- CAPA is a regulatory requirement under 21 CFR 820.100 and ISO 13485:2016, not a discretionary best practice
- Corrective action fixes what already happened; preventive action stops what hasn't happened yet
- The process runs from issue identification through root cause analysis, action, and effectiveness verification
- CAPA belongs to systemic issues, not every isolated complaint or nonconformance
- Effectiveness means proven nonrecurrence, not just closed tasks
What Is CAPA for Medical Devices?
Under legacy 21 CFR 820.100(a), manufacturers must "establish and maintain procedures for implementing corrective and preventive action." Those procedures must:
- Analyze quality data sources
- Investigate root causes
- Identify and verify corrective actions
- Implement changes
- Report findings to management review
ISO 13485:2016 splits this into two clauses. Clause 8.5.2 covers corrective action: eliminating the cause of an existing nonconformity to prevent recurrence. Clause 8.5.3 covers preventive action: addressing a potential nonconformity before it ever occurs. Both require documented procedures, proportionate response, and verified effectiveness.
In plain terms, CAPA means finding what actually causes quality problems and closing that gap so it does not return.
Corrective vs. Preventive Action
- Corrective action is reactive. It responds to a nonconformity that's already happened.
- Preventive action is proactive. It responds to a potential nonconformity that hasn't happened yet.
They are distinct tools, not one process run twice. The Global Harmonization Task Force flagged this exact confusion in its 2010 guidance, noting that combining "corrective" and "preventive" into one acronym has led many companies to wrongly assume every corrective action must also include a preventive action. Some do. Many don't need to.

CAPA Is Not Every Quality Process
CAPA also gets confused with adjacent processes:
- Nonconformance handling deals with a single defective unit or batch, not a systemic pattern
- Complaint investigation determines whether a customer-reported issue is device-related
- Supplier Corrective Action Requests (SCARs) push root cause work to a supplier for a supplier-caused issue
CAPA is reserved for systemic issues. A one-off scratched housing doesn't need a CAPA. A pattern of scratched housings across three lots does.
Why CAPA Is Critical in Medical Device Quality Systems
CAPA is the most cited quality system failure in the medical device industry. In 2020, CAPA violations were cited 197 times, making it the most-cited area in FDA medical device inspections that year. That pattern has held for well over a decade.
There's a structural reason for that. Historically, CAPA sat inside FDA's QSIT inspection model as one of four major subsystems investigators always check. FDA phased out QSIT when the Quality Management System Regulation took effect on February 2, 2026, folding legacy Part 820 requirements into ISO 13485:2016. The rule changed. The scrutiny on CAPA did not.
What Investigators and Auditors Actually Look For
Both FDA inspectors and ISO 13485 auditors want traceable evidence, not narrative. Specifically:
- Root causes identified with data, not assumptions
- Actions proportionate to the actual risk, referencing ISO 14971
- Effectiveness verified with objective evidence, not just "task complete" status
Skip any of these and you face repeat nonconformities, rising complaint volumes, and delayed detection of systemic problems. The odds of a warning letter or recall climb with them.
The Real Gap Isn't Awareness
Most CAPA failures don't come from teams not knowing the procedure exists. They come from a diagnostic gap: quality engineers know 5-Why, fishbone, and FMEA exist, but freeze when deciding which one fits the problem in front of them, especially under audit pressure.
That diagnostic gap is what QMS Learning's Medical Device & Life Sciences QMS pathway is built to close. The pathway bundles ISO 13485, FDA 21 CFR Part 820, and ISO 14971 training with hands-on CAPA and root cause practice, not just clause memorization.
How the CAPA Process Works
CAPA runs through five stages: a quality event surfaces, gets evaluated for CAPA-worthiness, gets investigated for root cause, gets actioned, and finally gets verified for effectiveness before closure.
Inputs that feed this process include:
- Complaints and nonconformances
- Internal and external audit findings
- Trend data and supplier performance issues
- Management review outputs
Controls include a cross-functional review board (often an MRB), risk-based prioritization tied to ISO 14971, and a documented CAPA procedure that everyone actually follows.
A properly closed CAPA produces updated processes, procedures, training, and documentation that permanently close the gap that caused the issue.

Step 1: Identify and Document the Issue
Every potential CAPA source needs a written problem description, the originating data source, and supporting evidence, logged at the point of discovery. This holds even if the team later decides the issue doesn't warrant a full CAPA. Skipping documentation here means you can't prove, later, that the decision process was sound.
Step 2: Evaluate and Make a Risk-Based CAPA Decision
A cross-functional team assesses risk, severity, and systemic potential before formally accepting or rejecting the request as a CAPA. This decision should reference ISO 14971 risk criteria directly, not gut feel. Low-risk, unlikely-to-recur issues may only need a correction, not a full CAPA.
Step 3: Investigate and Determine Root Cause
This is where most CAPAs fail. The investigation has to go past restating the problem statement and actually isolate the systemic cause, using structured tools like 5-Why, fishbone, or FMEA.
Picking the wrong tool for the situation is one of the most common reasons CAPAs fail effectiveness checks later:
- Fishbone diagram: best for broad, multi-factor brainstorming
- 5-Why: fits a focused causal chain on an existing failure
- FMEA: built for prospective risk, not for explaining something that already happened
QMS Learning's Method Router was built directly around this problem. It diagnoses the situation first: isolated incident, process gap, supplier issue, or design flaw. Then it recommends the right method.
In one real scenario, three defects from the same supplier in a single quarter triggered a 5-Why and Supplier CAPA recommendation. The router ruled out FMEA because the issue was closing an existing failure, not evaluating a new process. That's the exact judgment junior engineers struggle with under time pressure.
Step 4: Plan and Implement the Action Plan
The action plan needs specific actions, document or process changes, training updates, and named owners with deadlines. Every action should be proportionate to the risk identified in Step 2, not a blanket maximum response to every issue.
Step 5: Verify Effectiveness and Close with Objective Evidence
Closure requires documented proof that the recurrence has actually stopped, not just a checklist of completed tasks. That distinction, completed versus effective, is exactly where auditors dig hardest. This effectiveness record then feeds into management review.
Where CAPA Applies and Key Factors That Affect It
Where CAPA Is Triggered Across the Product Lifecycle
CAPA isn't scheduled or recurring by default. It's condition-based, and it can trigger at any lifecycle stage:
- Post-market complaints and feedback
- In-process nonconformances on the line or in test
- Supplier quality escalations and incoming defects
- Internal or external audit findings
- Adverse trends in complaints, yields, or process data
Design, production, and post-market activity can all generate a valid CAPA trigger.
Key Factors That Affect CAPA Outcomes
Four variables usually decide whether a CAPA closes the issue or only creates a file:
- Incomplete complaint or NCR records produce weak root cause conclusions
- Quality-only ownership misses engineering and operations context
- Thin investigation time and resources leave the true cause unfound
- ISO 14971 risk should scale effort—not push every CAPA to maximum response

Common CAPA Mistakes and When It's Not the Right Tool
Misconceptions and Common Mistakes
Three mistakes show up repeatedly across audits:
- Assuming every corrective action needs a matching preventive action. They're separate tools for separate situations, not a package deal.
- Treating the problem statement as the root cause. "Defect found on final inspection" is a symptom, not a cause. Teams need to keep drilling until they hit something they can actually fix.
- Confusing "completed" with "effective." Closed tasks aren't proof. Verified nonrecurrence, backed by data over a defined period, is.
When CAPA May Not Be the Right Tool
Not every quality event deserves a full CAPA. Watch for these signals:
- Isolated, non-systemic nonconformances — handle these through standard nonconformance or complaint processes.
- Growing backlog of trivial or duplicate CAPAs — a sign of overuse that strains resources without improving quality.
- Change control or routine corrective maintenance issues — don't force these into the CAPA subsystem.
Forcing every quality event through CAPA doesn't make a quality system stronger. It buries the systemic issues that deserve attention under paperwork that never needed to exist.
Conclusion
CAPA is a two-part regulatory subsystem—corrective action and preventive action—built to eliminate root causes and stop recurrence. Closing the file is not the goal; eliminating the cause is. Selective use, grounded in real diagnostic judgment, is what protects patients and holds up in an audit.
For quick reference, here are direct answers to the questions teams ask most:
What is CAPA in medical devices?
CAPA is the combined corrective and preventive action subsystem required under 21 CFR 820.100 and ISO 13485:2016. It exists to identify and eliminate the root cause of nonconforming product and quality problems.
Is CAPA part of Six Sigma?
No. CAPA is a regulatory requirement specific to FDA and ISO quality systems, while Six Sigma is a separate process-improvement methodology. They can complement each other, but CAPA isn't a Six Sigma tool.
Are CAPA and RCA the same?
No. Root Cause Analysis is one critical step inside the broader CAPA process, specifically the investigation phase. It's not a synonym for the entire CAPA workflow.
What are the steps in a medical device CAPA process?
Identify and document the issue, evaluate it for risk, investigate the root cause, plan and implement the action, then verify effectiveness before closure. Each stage requires documented evidence.
When should a CAPA be opened?
Open a CAPA when an issue is systemic, severe, or risk-significant, not for every isolated complaint or nonconformance. Low-risk, unlikely-to-recur issues usually need only a correction.
What's the difference between corrective action and preventive action?
Corrective action is reactive: it addresses a nonconformity that already occurred. Preventive action is proactive: it addresses a potential nonconformity before it happens.


