Resources · Quality management

CAPA explained: corrective and preventive action

CAPA is the structured method a quality system uses to fix the root cause of a problem that has happened and to head off problems that have not happened yet.

CAPA stands for corrective and preventive action. Corrective action deals with a problem that has already occurred and stops it coming back. Preventive action deals with a potential problem and stops it happening in the first place. The whole point of CAPA is to push past the quick fix and change the underlying cause, so the same non-conformance does not keep reappearing.

What does CAPA stand for?

CAPA is short for corrective and preventive action, two related but distinct responses that sit at the heart of most quality management systems. Both go further than simply patching the immediate symptom. A correction puts the current problem right; a corrective action makes sure that type of problem does not recur; a preventive action stops a problem you have foreseen from ever arising. Keeping these apart is the single most useful thing you can learn about CAPA, because confusing the quick fix with the lasting fix is why so many problems return.

Correction vs corrective action vs preventive action

These three are easy to blur, so here they are side by side.

TermWhat it doesTriggerExample
CorrectionFixes the immediate problem, but not its causeA defect or non-conformance right nowReplace the faulty part the customer received
Corrective actionRemoves the root cause so the problem does not recurA problem that has already happenedFind why the wrong part was picked and change the picking process so it cannot happen the same way
Preventive actionStops a foreseeable problem before it occursA trend, risk or near miss, no failure yetSpotting that two similar parts are easily confused and redesigning the labelling before any wrong part ships

The clearest way to remember the difference between corrective and preventive: corrective action is reactive and looks backward at something that went wrong, while preventive action is proactive and looks forward at something that could go wrong. A healthy quality system shifts its weight over time from corrective towards preventive, because preventing a problem is always cheaper than recovering from one.

Correction fixes the thing in front of you. Corrective action fixes the reason it happened. Preventive action fixes the reason it might happen. Only the last two stop the cycle repeating.

The CAPA process, step by step

A CAPA follows a consistent sequence. Working through it in order is what stops teams jumping straight to a solution before they understand the problem.

  1. Identify and describe the problem. State clearly what happened, where, when and against which requirement, with evidence. A vague problem statement produces a vague fix.
  2. Contain it and apply any immediate correction. Limit the damage now: quarantine affected stock, notify whoever needs to know, and put the current instance right. This is correction, not yet corrective action.
  3. Assess the scale and risk. Decide how serious it is, whether it is isolated or systemic, and whether it warrants a full CAPA or a lighter response. Not every non-conformance needs a formal investigation.
  4. Investigate the root cause. Find out why it really happened, not just the surface reason. Techniques such as the Five Whys or a cause-and-effect (fishbone) diagram help you get past the first plausible answer.
  5. Plan the action. Decide what to change to remove the root cause. Assign a clear owner and a due date. A corrective action with no owner is a wish.
  6. Implement the action. Make the change: update the procedure, retrain, redesign the jig, adjust the supplier agreement, whatever the cause demands.
  7. Verify effectiveness. Check that the action actually worked. This means confirming the problem has not recurred over a sensible period, not just confirming the change was made. This step is the one most often skipped, and skipping it is why “closed” CAPAs reopen.
  8. Close and record. Document the whole loop and close it. The record is what lets you spot trends across many CAPAs later.

Why root cause is the heart of CAPA

The difference between a CAPA that works and one that does not almost always comes down to root cause. The temptation, especially under time pressure, is to stop at the first explanation that sounds reasonable, usually “human error”, and attach an action like “operator reminded to take more care”. Reminders rarely change outcomes, because the conditions that made the error easy are still there.

A genuine root-cause investigation keeps asking why until it reaches something you can actually change in the system. If the operator picked the wrong part, why was that easy to do? Perhaps two parts look almost identical and sit in adjacent bins with similar labels. The root cause is the bin layout and labelling, not the operator, and the corrective action is to separate and clearly distinguish them. Now the next person physically cannot make the same mistake as easily. That is the test of a good corrective action: it changes the system, not just the instruction.

How CAPA connects to non-conformances and audits

CAPA does not start from nothing. It is triggered by things your quality system surfaces, most often a non-conformance or a finding from an internal quality audit. A non-conformance tells you something went wrong; CAPA is what you do about it so it does not recur. An audit finding tells you a process is not being followed or is not working; CAPA is the route to fixing it. Seen this way, CAPA is the thread that runs through the whole improvement loop described in the quality management guide.

Tracking CAPAs so they actually close

CAPAs fail in practice for an unglamorous reason: they get lost. An action is agreed in a meeting, written in a spreadsheet, and quietly drifts past its due date while everyone is busy. The fix is visibility. When every corrective and preventive action has an owner, a date and a status that the right people can see, overdue actions stand out and effectiveness checks actually happen. Logincident tracks corrective and preventive actions from the originating report through to verified closure, and surfaces overdue and recurring issues through data visualisation, so a quality lead can see at a glance which causes keep returning. The method is yours; the platform just stops the loop from breaking.

Frequently asked questions

What is the difference between corrective and preventive action?

Corrective action is reactive: it removes the root cause of a problem that has already happened so it does not recur. Preventive action is proactive: it addresses a potential problem, identified from a trend, risk or near miss, before it occurs. Corrective looks backward at a failure; preventive looks forward at a possible one.

What is the difference between a correction and a corrective action?

A correction fixes the immediate problem, such as replacing a faulty item, but does nothing about why it happened. A corrective action removes the root cause so the same type of problem does not return. You usually do the correction first to contain the issue, then the corrective action to fix the cause.

What are the main steps in a CAPA?

Identify and describe the problem, contain it with an immediate correction, assess its scale and risk, investigate the root cause, plan an action with an owner and date, implement it, verify it actually worked, then close and record the loop. Verification of effectiveness is the step most often missed.

How do you find the root cause for a CAPA?

Use a structured technique rather than the first explanation that comes to mind. The Five Whys keeps asking why until you reach a cause you can change in the system, and a cause-and-effect or fishbone diagram helps map the contributing factors. The aim is to reach something fixable, not to assign blame.

Why do CAPAs reopen or fail?

Usually for one of two reasons: the root cause was never really found, so the action treated a symptom, or the action was implemented but never verified, so nobody confirmed it worked. Tracking actions to a verified close, with a clear owner and date, prevents both.

Sources

  1. International Organization for Standardization, ISO 9001:2015 Quality management systems: Requirements. https://www.iso.org/standard/62085.html

Track every action to a verified close

Give each corrective and preventive action an owner, a date and a status everyone can see.

Book a demo