Best Practices

The CAPA Process: From Finding to Lasting Corrective Action

An audit finding is uncomfortable - but it isn’t the real problem. The real problem is when the same nonconformity resurfaces a year later because the corrective action only treated the symptom. The CAPA process (Corrective and Preventive Action) exists to prevent exactly that - yet in practice it’s often cut short.

What CAPA Actually Means

CAPA stands for Corrective and Preventive Action, and the term deliberately separates two levels:

  • Correction: the immediate fix for the specific problem (e.g., quarantining a defective batch).
  • Corrective action: eliminating the root cause so the problem doesn’t recur.
  • Preventive action: addressing potential problems with a similar cause that haven’t occurred yet.

ISO 9001:2015 clause 10.2 explicitly requires organizations to react to nonconformities, evaluate their cause, and take appropriate action - including verifying that the action was effective.

The Most Common Mistake: Treating Symptoms Instead of Root Causes

By far the most common weakness in practice: the “root cause” recorded is actually just the symptom. Example: finding “inspection record not signed” → cause “employee forgot to sign” → action “employee retrained.” Three months later, the same deviation shows up with a different employee - because the real root cause (e.g., an unclear process step or a missing reminder in the workflow) was never identified.

Methods for a Robust Root Cause Analysis

5 Whys. Ask “why?” five times until you reach a systemic cause rather than a person-blaming one. “Why wasn’t it signed?” → “Because the step is easy to miss on the form” → “Because the form has no required field for it” - that’s a cause you can actually fix. For a deeper walkthrough with more examples and the method’s documented limits, see our article on the 5-Why method.

Ishikawa (fishbone) diagram. For more complex deviations, structuring the analysis around categories like people, machine, method, material, environment, and measurement helps surface contributing factors.

Failure Mode and Effects Analysis (FMEA). For recurring or particularly critical deviations, a more systematic assessment of occurrence probability, severity, and detectability is worthwhile.

The Four Building Blocks of a Working CAPA Process

  1. Clear capture of the finding, directly linked to the affected standard clause or process step - not just as free text.
  2. Structured root cause analysis using a repeatable method rather than gut feeling.
  3. An action with a clear owner and deadline that actually targets the root cause.
  4. Effectiveness verification after an appropriate period - not just “action completed,” but documented confirmation that the nonconformity hasn’t recurred.

That fourth point is the one most often skipped. An action marked “done” without a later check on whether it actually worked isn’t closed in the sense the standard intends.

Once several findings accumulate per month, manually tracking root cause, action, and effectiveness deadline quickly becomes unmanageable - especially when findings aren’t consistently linked to the same standard clauses, making it impossible to spot patterns like recurring deviations against the same clause across multiple sites.

For how to keep a finding and its corrective action as one continuous record instead of separate lists - with effectiveness verification as a fixed lifecycle step - see our article on findings management. Teams running CAPA inside SAP QM often hit gaps between the module’s core processes and the actual audit lifecycle; we cover that in our look at SAP QM and audit management.

Conclusion

A CAPA process is only as good as its root cause analysis. Fix symptoms instead of causes, and you’ll keep generating recurring findings that erode credibility at the next audit. Push consistently to the systemic cause and actually verify effectiveness, and the number of findings will visibly drop from one audit to the next.