Corrective and preventive action, commonly abbreviated CAPA, is a structured quality process for eliminating the cause of a nonconformity so it does not happen again, and for addressing potential problems before they occur. It turns audit findings, complaints, and defects into lasting improvement rather than repeated firefighting.
CAPA sits at the heart of every mature management system, from ISO 9001 quality to ISO 27001 security. Done well, it converts a single failure into a permanent fix. Done badly, it treats symptoms while the real cause quietly waits to strike again. The difference lies almost entirely in how rigorously you find and remove the root cause. A well-run CAPA process also builds organizational memory: each closed record becomes evidence that a known weakness has been engineered out, which is exactly what auditors, customers, and regulators want to see. Over time, a healthy CAPA log tells the story of a system that learns from its own mistakes instead of repeating them.
Correction vs corrective action vs preventive action
These three terms are constantly confused, yet they describe very different things. Getting them straight is the single most valuable step in understanding CAPA.
- Correction: an immediate fix that removes the detected nonconformity, such as scrapping or reworking a defective batch, without addressing why it happened
- Corrective action: action taken to eliminate the root cause of an existing problem so it does not recur, driven by root cause analysis
- Preventive action: action taken to eliminate the cause of a potential problem before it ever occurs, driven by data and trend analysis
A quick example makes it concrete. If a machine produces out-of-spec parts, the correction is reworking those parts. The corrective action is repairing the worn tooling that caused the drift and updating the maintenance schedule. A preventive action might be adding vibration monitoring to catch the same wear pattern on similar machines before they fail.
The ISO 9001:2015 shift to risk-based thinking
One point trips up many practitioners: ISO 9001:2015 removed the explicit clause for preventive action. It was not abandoned. Instead, the standard embedded prevention into an overarching concept called risk-based thinking, where the entire quality management system is designed to identify and treat risks and opportunities before they turn into problems.
In effect, the whole QMS became a preventive action engine. Corrective action remains an explicit requirement in clause 10.2, triggered by nonconformity, while prevention is now handled through the risk clauses rather than a standalone procedure. Most organizations still run a combined CAPA process, because the discipline of documenting and verifying both types of action remains invaluable. The practical takeaway is not to abandon preventive action but to relocate it: the trends, near-misses, and risk assessments that once fed a preventive action procedure now feed the risk-based thinking that shapes the whole system. A team that treats every audit finding and complaint as a signal about wider risk is doing exactly what the 2015 revision intended.
Per Advisera and multiple ISO 9001 practitioners, the 2015 revision removed the standalone preventive action clause and replaced it with risk-based thinking, so the entire quality management system is geared toward preventing problems rather than a separate procedure. Source: advisera.com 9001Academy.
The CAPA process step by step
A robust CAPA follows a repeatable sequence. Each step feeds the next, and skipping any of them is usually where CAPA programmes fail. Our root cause analysis guide expands on the middle stages, and our post on handling audit findings shows how nonconformities enter this pipeline.
- Identify and document the nonconformity, drawing on audit findings, complaints, defects, or trends
- Containment: take immediate correction to limit the impact, such as quarantining affected product
- Investigate the root cause using tools such as 5 Whys or a fishbone (Ishikawa) diagram
- Plan and implement corrective action that eliminates the identified root cause
- Consider preventive action for similar processes, products, or sites exposed to the same risk
- Verify effectiveness: confirm the action worked and the problem has not recurred over time
- Close out and record the CAPA, updating procedures, training, and risk assessments as needed
Two of these steps deserve emphasis. Root cause analysis is where 5 Whys and fishbone diagrams earn their keep, pushing the team past the obvious symptom to the underlying failure. Verification of effectiveness is where discipline separates real CAPA from paperwork: an action that is applied but never checked may be quietly ineffective, and if so a new action must be raised.
Links to nonconformity, audit findings, and common failures
CAPA is the natural home for anything flagged as a nonconformity. Internal and external audit findings, customer complaints, process deviations, and negative trends all feed the same funnel. In ISO 9001:2015 internal audits, an auditor who raises a nonconformity expects the organization to respond with correction plus corrective action, then to demonstrate that the fix held.
The most common failure mode is simple: fixing the symptom instead of the cause. Reworking bad parts, retraining one operator, or reissuing a document may close the immediate gap while the systemic driver remains untouched, and the same nonconformity resurfaces at the next audit. Weak or absent verification of effectiveness is the close runner-up, followed by root cause analysis that stops at the first plausible answer. A further trap is closing CAPA records under schedule pressure, marking an action complete before there is any evidence the problem has actually stopped recurring. Guarding against these failures usually comes down to two habits: forcing the investigation past the first answer, and refusing to close a record until real-world data confirms the fix held.
Corrective and preventive action must be verified to confirm it is effective; if the action is found ineffective, a new corrective or preventive action must be applied. Skipping this verification is a leading cause of recurring nonconformities.
Treat CAPA as a learning loop rather than a compliance chore and it becomes one of the most powerful tools in any management system. Distinguish correction from corrective and preventive action, dig for the true root cause with 5 Whys or a fishbone, and always verify that the fix actually worked. That habit is what stops the same problem from returning audit after audit.