What CAPA actually means
CAPA — corrective and preventive action — is the discipline of responding to a non-conformity so thoroughly that it does not come back. The two words carry precise meanings from ISO 9000. Corrective action eliminates the cause of a non-conformity that has already occurred, so it cannot recur. Preventive action eliminates the cause of a potential non-conformity, before it ever happens. Sitting in front of both is a third term people constantly confuse with corrective action: correction, which is the immediate fix of the symptom itself.
For an audit programme, CAPA is the machinery that turns a finding into improvement. A non-conformance is raised, contained, analysed for root cause, corrected at the cause, and then verified and closed. Without it, an audit is a diagnosis with no treatment — a list of problems that recur audit after audit. With it, the audit becomes the front end of a genuine improvement loop, which is the whole point of running one. The CAPA process is the closure stage of the lifecycle set out in the audit management pillar.
Why "we fixed it" is not closure
The most common way an audit programme fails is that findings are closed on the strength of a correction alone. Someone reworks the batch, files the missing record, re-trains the operator — and the finding is marked done. It feels like closure, but nothing has been done about why the record was missing or the operator untrained, so the same non-conformity surfaces at the next audit as a repeat. A rising count of repeat NCs is the surest sign a programme is closing findings on corrections, not corrective action.
Real closure has three properties a quick fix lacks. It reaches the root cause, so the mechanism that produced the problem is removed. It is verified for effectiveness, so closure rests on evidence the problem stopped, not a promise it was addressed. And it is signed off by someone other than the person who did the work, so closure is a judgement, not a self-assessment. A CAPA process is the set of controls that guarantees all three.
The CAPA lifecycle, step by step
ISO 9001 clause 10.2 lays out what a corrective-action process must do when a non-conformity occurs — react and correct, evaluate and eliminate the cause, implement, review effectiveness, and update the system and its risks. Compressed into a working loop, that is five steps:
Two of these are routinely skipped under time pressure — finding the true cause, and verifying effectiveness — and they are precisely the two that determine whether the finding stays closed. A CAPA workflow that forces the loop to pass through both, with a distinct owner for each, is what stops the programme from quietly regressing to mop-and-move-on.
Root cause: getting past the symptom
The heart of corrective action is honest root-cause analysis. The goal is to reach the systemic reason a non-conformity occurred, not to stop at the first plausible explanation. Several established methods help, and a mature programme picks the depth to match the severity of the finding:
| Method | How it works | Best for |
|---|---|---|
| 5 Whys | Ask "why" repeatedly until a systemic cause is reached, not a symptom | Minor NCs and quick, single-cause issues |
| Fishbone (Ishikawa) | Group candidate causes by method, machine, material, manpower, measurement, environment | Findings with several possible contributing causes |
| 8D | An eight-discipline team method with containment, root cause and verification steps | Major NCs and customer-facing automotive issues |
| Occurrence vs escape | Analyse both why the problem happened and why it was not detected | Any finding — both usually need action |
The last row is the one auditors most want to see. A robust analysis separates the occurrence root cause — why the defect was created — from the escape root cause — why the control system let it through undetected. Fixing only the first leaves the detection gap open; addressing both is what genuinely hardens the process. For major or recurring findings, a serious method like 8D in Fast Quality is the right escalation.
How many of last year's NCs are still genuinely open?
See Fast Audit drive a finding from action plan through coordinator review to auditor-verified closure — with due dates and reminders — in a 30-minute demo.
The multi-role closure trail
Closure that means something requires more than one pair of hands. The person who caused a non-conformity, or who owns the process, should not be the sole judge of whether their own fix worked — that is marking your own homework. A sound CAPA process therefore runs each finding through a multi-role sign-off, with the responsibility separated at each stage:
Each step appends to the finding's own history rather than overwriting it, so the closure trail is complete and auditable — you can see who did what and when, months later, without reconstructing anything. That separation of roles and the retained trail are what a certification body inspects, and what the Findings, NC & CAPA Closure feature is built around.
Verification of effectiveness
Verification of effectiveness is the step that most distinguishes a real CAPA process from a to-do list. ISO 9001 explicitly requires organisations to review the effectiveness of corrective action taken — not just that it was done. That means a deliberate check, some time after implementation, that the non-conformity has actually stopped happening: a follow-up sample, a re-audit of the same clause, a run of clean records where there were gaps before. The gap between "action complete" and "effectiveness verified" is real, and closing a finding on the former is one of the most common audit weaknesses. Because verification sits with the auditor — a different role from the auditee who implemented the fix — the process bakes in the independence that makes the verdict trustworthy.
Due dates, reminders and ageing
Corrective action rots when it has no clock. Findings that sit open until the week before the next surveillance audit are the operational reality most programmes fight, and the cure is disciplined due-date management. Every action carries a target date; overdue actions generate reminders automatically so chasing does not depend on someone remembering; and an ageing view shows how long each NC has been open and which are overdue, so management attention goes where it is needed. Automated reminders on due and overdue actions are the single highest-leverage control for actually getting findings fixed, and they are the theme of the operations guides linked below.
How Fast Audit closes findings
Fast Audit Software implements the whole closure loop on the shared Fast Suite platform, so corrective action is tracked, verified and evidenced rather than trusted:
Because it runs on the shared platform, the closure trail, the reminder emails and the retained evidence all use the same document, party and user masters as the rest of the suite — and the findings feeding this loop come straight from checklist entry and grading. The result is corrective action that closes because it was verified, not because someone said so. Confirm effectiveness and retention expectations with your certification body.
Frequently asked questions
What is CAPA?
CAPA stands for corrective and preventive action — the disciplined process of dealing with a non-conformity so it does not happen again. Corrective action eliminates the cause of a non-conformity that has occurred; preventive action eliminates the cause of a potential non-conformity before it occurs. For audit findings, CAPA is the loop that runs from a raised non-conformance through containment, root-cause analysis and corrective action to verified, signed-off closure. It is what separates an audit that improves the organisation from one that merely produces a list.
What is the difference between correction and corrective action?
A correction is immediate action to eliminate a detected non-conformity — rework the part, retrieve the wrong document, re-train the operator today. Corrective action goes deeper: it eliminates the root cause so the non-conformity cannot recur. Fixing the symptom is a correction; fixing the reason the symptom appeared is corrective action. A finding closed with only a correction will almost always come back, which is why it re-appears as a repeat non-conformance at the next audit. Effective closure needs both — contain now, and remove the cause.
What is root cause analysis in CAPA?
Root cause analysis is the structured search for why a non-conformity really happened, rather than what it looked like. Common methods include the 5 Whys, which repeatedly asks why until a systemic cause is reached, and the fishbone or Ishikawa diagram, which groups possible causes by category such as method, machine, material, manpower, measurement and environment. Automotive suppliers use the 8D method for major issues. Good analysis distinguishes the cause of the problem occurring from the cause of it escaping detection, because both usually need action.
What is verification of effectiveness?
Verification of effectiveness is confirming, with objective evidence, that a corrective action actually worked — not merely that it was carried out. It is the step where an auditor checks, some time after the action was implemented, that the non-conformity has genuinely stopped recurring. ISO 9001 requires organisations to review the effectiveness of corrective action, and it is the reason a finding should not close the moment an action is marked done. Only verified effectiveness justifies closing a finding, which is why closure is a separate role from doing the work.
What does ISO 9001 clause 10.2 require for corrective action?
ISO 9001 clause 10.2 requires that when a non-conformity occurs, the organisation reacts to control and correct it and deals with the consequences; evaluates the need to eliminate the cause so it does not recur, including reviewing the non-conformity and determining its causes and whether similar ones exist; implements the action needed; reviews the effectiveness of that action; updates risks and opportunities if necessary; and makes changes to the management system if needed. It also requires retained documented information on the nature of the non-conformities, the actions taken and the results.
How does Fast Audit manage CAPA closure?
Fast Audit tracks each finding's corrective action in an append-only history that records the status, who updated it, the date, a due date and remarks at every step. Closure is a multi-role sign-off: the same finding carries an auditee status, a system-coordinator status and an auditor status, so the person who did the work is not the person who confirms it worked. Overdue actions trigger reminder emails, and the audit only moves to its closure status once the non-conformances are actioned and verified — with the whole trail retained for the record.
