corrective-action-preventive-action

By July 25th, 2026ISO Audit And Certificate9 min read

Corrective Action vs Preventive Action: CAPA Explained

Corrective Action and Preventive Action – collectively known as CAPA – are two of the most misunderstood concepts in management system standards. Yet they are fundamental to ISO 9001, ISO 27001, ISO 14001, and virtually every ISO management system. Without an effective CAPA process, your management system cannot improve. This article explains the difference between corrective and preventive action, walks through the CAPA lifecycle, and shows you how to build a CAPA system that drives real, sustained improvement.

Definitions: Corrective Action vs Preventive Action

A corrective action is taken to eliminate the cause of a detected non-conformity and prevent recurrence. It is reactive – something has already gone wrong, and you are fixing the root cause so it does not happen again. A preventive action is taken to eliminate the cause of a potential non-conformity and prevent occurrence. It is proactive – you have identified a risk that has not yet materialised, and you are acting to prevent it from ever happening.

The distinction matters because the two types of action demand different thinking, different triggers, and different verification methods. Many organisations blur the two, which leads to weak corrective actions (treating symptoms instead of root causes) and poor preventive actions (ignoring risks until they become problems).

AspectCorrective ActionPreventive Action
TriggerNon-conformity has occurredPotential non-conformity identified
TimingReactive (after the event)Proactive (before the event)
PurposeEliminate root cause of existing problemEliminate root cause of potential problem
ExamplesCustomer complaint, audit finding, product defectRisk assessment finding, trend analysis, early warning
VerificationConfirm problem does not recurConfirm risk has been reduced or eliminated
OutputClosure of non-conformityRisk mitigation, improved controls

The CAPA Process: Step by Step

An effective CAPA process follows a defined lifecycle. Each step must be documented, assigned to a responsible person, and tracked to completion. The six-step model below is widely used across ISO standards and regulatory frameworks including FDA, GMP, and IATF 16949.

Step 1: Identify

The CAPA process begins with identification. For corrective actions, the trigger is a detected non-conformity from internal audits, customer complaints, product returns, process deviations, or supplier issues. For preventive actions, the trigger is a risk identified through risk assessments, trend analysis, management review, or external intelligence such as industry incidents or regulatory changes. All CAPA triggers must be captured in a central register with sufficient detail to allow prioritisation.

Step 2: Evaluate

Not every non-conformity or risk warrants a full CAPA. Minor, isolated issues can be corrected on the spot without a formal investigation. The evaluation step determines the severity, frequency, and impact of the issue. If the issue is significant or recurring, a CAPA is initiated. Each CAPA is assigned a priority level (critical, high, medium, low) based on the risk to product quality, customer satisfaction, or regulatory compliance.

Step 3: Investigate

Investigation is the most important step. You must identify the root cause of the problem, not just the symptoms. This requires structured root cause analysis techniques rather than guesswork. The investigation should include interviews, data analysis, process observation, and document review. The outcome of the investigation is a clear root cause statement and evidence to support it.

Step 4: Action Plan

Once the root cause is identified, develop an action plan to eliminate it. The plan should specify what actions will be taken, who is responsible, the timeline for completion, and the resources required. For complex CAPAs, there may be multiple actions addressing different aspects of the root cause. Each action should have a clear completion criterion so there is no ambiguity about whether it has been done.

Step 5: Verify Effectiveness

After the actions are implemented, you must verify that they have been effective. For corrective actions, verification means checking that the non-conformity does not recur over an agreed period. For preventive actions, verification means confirming that the risk has been reduced to an acceptable level. Verification may involve follow-up audits, data analysis, additional testing, or process monitoring. If the actions are not effective, the CAPA must be reopened.

Step 6: Close

Once effectiveness is verified, the CAPA is formally closed. All documentation is reviewed for completeness, the CAPA register is updated, and lessons learned are communicated to relevant stakeholders. The final step is to consider whether the CAPA reveals broader trends that require systemic changes to the management system.

StepActivityKey OutputTypical Duration
1. IdentifyDetect non-conformity or riskCAPA initiation recordOngoing
2. EvaluateAssess severity, frequency, impactPrioritised CAPA log1–2 days
3. InvestigateRoot cause analysis (5 Whys, fishbone, FMEA)Root cause statement with evidence1–4 weeks
4. Action planDefine actions, owners, deadlinesCAPA action plan1–2 weeks
5. VerifyMonitor effectiveness over timeEffectiveness verification report4–12 weeks
6. CloseReview documentation, update registerClosed CAPA record1 day

Root Cause Analysis Tools for CAPA

Effective root cause analysis is the difference between a CAPA that fixes the problem permanently and one that lets it recur. Several structured tools are available, and the best organisations use them systematically rather than relying on intuition.

  • 5 Whys: Ask ‘why’ repeatedly until the fundamental cause is revealed. Simple, fast, and effective for straightforward problems. Risk: stopping too early at a symptom rather than the root cause.
  • Fishbone (Ishikawa) Diagram: Categories potential causes (e.g. man, machine, method, material, measurement, environment) and identifies where the root cause lies. Best for complex problems with multiple contributing factors.
  • FMEA (Failure Mode and Effects Analysis): Systematically evaluates potential failure modes, their causes, and their effects. Used proactively for preventive action and reactively for corrective action on high-risk processes.
  • Fault Tree Analysis: Top-down deductive analysis that maps the logical relationships between failures and their causes. Common in safety-critical industries.
  • Cause-and-Effect Matrix: Relates process inputs to outputs to identify which inputs have the strongest influence on the problem. Useful for processes with many variables.

Effectiveness Verification in CAPA

Verification is the step most organisations get wrong. Too many CAPAs are closed as soon as the action is completed, without any check that the action actually solved the problem. Effectiveness verification must be objective and time-bound. For a corrective action related to a customer complaint, verification might mean monitoring complaint data for three months to confirm no recurrence. For a preventive action addressing a risk in supplier quality, verification might mean auditing the supplier again after six months.

If verification finds the problem has recurred or the risk persists, the CAPA is reopened and the investigation cycle repeats. This iterative approach is what drives continual improvement rather than quick fixes.

CAPA TypeVerification MethodTypical Verification Period
Customer complaintMonitor complaint data, confirm root cause eliminated3 months
Internal audit findingFollow-up audit of process and recordsNext audit cycle
Product defectIncreased sampling or 100% inspection for defined period1–3 production batches
Risk-based preventive actionRe-assessment of risk score, control testing6–12 months

CAPA in ISO Standards

CAPA appears in different forms across ISO management system standards. In ISO 9001:2015, corrective action is addressed in Clause 10.2 (non-conformity and corrective action). Preventive action is no longer a separate clause in ISO 9001:2015 – it has been subsumed into the risk-based thinking approach required by Clause 6.1 (actions to address risks and opportunities). In ISO 27001:2022, corrective action is covered in Clause 10.1, and preventive action is embedded in the risk assessment and treatment process (Clauses 6.1 and 8.3).

Despite these differences in structure, the underlying principle is the same: when something goes wrong, fix the cause, not the symptom. When a risk is identified, act before the risk materialises. A well-designed CAPA process satisfies the requirements of multiple standards simultaneously.

Frequently Asked Questions

What is the difference between correction and corrective action?

A correction fixes the immediate problem (e.g. reprocessing a defective product). A corrective action addresses the root cause to prevent recurrence (e.g. updating the training programme that caused the defect). Both are needed – correction deals with the non-conformity itself; corrective action prevents it happening again.

Do I need a separate preventive action process?

Not necessarily. In ISO 9001:2015, preventive action is addressed through risk-based thinking rather than a separate procedure. However, many organisations maintain a separate preventive action process for clarity, particularly in regulated industries such as medical devices or pharmaceuticals where CAPA is a regulatory requirement.

How long should a CAPA take to close?

There is no fixed timeline, but best practice is to set target closure times based on severity. Critical CAPAs should close within 30 days, high within 60 days, medium within 90 days, and low within 120 days. The verification period should be additional to these targets.

Can a single CAPA cover multiple non-conformities?

Yes, if the non-conformities share the same root cause. This is common when an audit identifies several related findings that all trace back to a single systemic issue, such as inadequate training or poor documentation control. One CAPA with multiple actions is more efficient than several separate ones.

What if the root cause cannot be identified?

If a thorough investigation fails to identify the root cause, document what was investigated, what was ruled out, and why. Implement containment actions to minimise the impact of the problem while continuing to monitor. Escalate to management review if the problem recurs without a root cause being found.

Is CAPA required for ISO 27001?

Yes. ISO 27001:2022 Clause 10.1 requires the organisation to take corrective action when a non-conformity occurs. The information security risk treatment process (Clause 6.1 and 8.3) fulfils the preventive action role by identifying and treating risks before they become security incidents.

Implement a CAPA System That Works

An effective CAPA system is the engine of continual improvement in your management system. If your CAPA process is struggling, or if you are preparing for certification and need to design one from scratch, Bitrixme can help. Contact our team or send us a message on WhatsApp to discuss your CAPA requirements.