The CAPA Process: Why ISO 9001 Never Uses the Term — and What 10.2 Asks For Instead
A finding is cheap. What gets expensive is the same finding two audits later — same process, same one-line cause, and an action that was closed out months ago.
Part of that pattern is a vocabulary problem. Most CAPA forms ask for a “preventive action” — something ISO 9001 has not required for eleven years and never called by that name. Fill the form in good faith and you complete a field with no normative counterpart while leaving open the subclause an auditor will actually test.
Where the Term CAPA Comes From — and Why ISO 9001 Doesn’t Use It
CAPA is not ISO vocabulary. It comes from US medical device regulation: until early 2026, 21 CFR § 820.100 “Corrective and preventive action” was a section of the FDA’s Quality System Regulation, and it filled the whole of Subpart J — the subpart carried the same name and contained that single section [1].
Its content was far more prescriptive than anything in ISO 9001: seven numbered items plus a blanket documentation duty. Manufacturers had to maintain procedures covering, among other things, the analysis of process, audit and complaint data to identify existing and potential causes of nonconforming product, the investigation of those causes, the verification or validation of the action to confirm it is effective, and the submission of results into management review [1].
Here is the part almost nobody has caught up with: that section no longer exists. In the final rule “Medical Devices; Quality System Regulation Amendments” (89 FR 7496, published 2 February 2024) the FDA rebuilt Part 820 from the ground up; the rule took effect on 2 February 2026 [2]. Part 820 is now titled “Quality Management System Regulation” (QMSR), Subparts C through O are reserved — empty — and § 820.100 is gone [3]. In its place sits an incorporation-by-reference construction: § 820.7 incorporates ISO 13485:2016(E), third edition of 1 March 2016, and § 820.10 requires the manufacturer to document a quality management system that meets the applicable requirements of ISO 13485 [3].
The FDA says in the preamble to the final rule where the requirement went: ISO 13485 addresses corrective action in clause 8.5.2 and preventive action in clause 8.5.3, and both became part of the QMSR through the reference [2]. A telling detail: the abbreviation CAPA does not appear once in the text of the final rule.
ISO 9001 never carried the term in the first place. Its vocabulary is correction and corrective action, set out in clause 10.2, “Nonconformity and corrective action” [4]. An organization running a single-standard QMS to ISO 9001 therefore imports, along with the word CAPA, a structure from a legal system it is not subject to — and one that no longer exists in that form even there. For the other things ISO 9001 is widely believed to require and doesn’t, see ISO 9001 explained.
Correction, Corrective Action, Preventive Action: Drawing the Line
The three terms are not synonyms, and in ISO 9001:2015 they sit in three different places — or rather two, because one of them is missing.
Correction targets the defective output. Clause 8.7 is about identifying and controlling nonconforming outputs so they are not used or delivered unintentionally, and it lists correction, segregation or containment, informing the customer, and acceptance under concession as the available dispositions [4]. It requires no cause analysis at all. Correction appears again in 10.2.1 a): react, control and correct, deal with the consequences.
Corrective action targets the cause. It lives in 10.2.1 b) to d), aimed at the nonconformity not recurring or occurring elsewhere [4].
Preventive action is gone. ISO 9001:2008 had a dedicated clause 8.5.3 requiring action against the causes of potential nonconformities, backed by a documented procedure [5]. The 2015 edition deleted it outright, and Annex A.4 explains why: because a quality management system is itself meant to act as a preventive tool, the standard has no separate clause or subclause on preventive action; the concept is expressed through risk-based thinking, which anchors the determination of risks as a basis for planning in 6.1. Annex A.4 also rules out any obligation to adopt formal risk management methods or a documented risk management process [4].
| Term | ISO 9001:2015 | ISO 9001:2008 | 21 CFR Part 820 |
|---|---|---|---|
| Correction (on the output) | 8.7 and 10.2.1 a) [4] | 8.3 [5] | via ISO 13485, § 820.10 [3] |
| Corrective action (on the cause) | 10.2.1 b)–d) [4] | 8.5.2 [5] | ISO 13485, 8.5.2 [2] |
| Preventive action | no clause of its own, absorbed into 6.1 [4] | 8.5.3 [5] | ISO 13485, 8.5.3 [2] |
| Documented procedure required? | no [4] | yes, for 8.5.2 and 8.5.3 [5] | § 820.10 requires a documented QMS [3] |
In practice: a “preventive action” field on your form is not wrong, it is optional. It becomes audit-relevant only if your own procedure declares it mandatory — at which point an auditor will test it against 9.2.1, because the internal audit has to demonstrate conformity to the organization’s own requirements as well as to the standard [4].
The Most Common Mistake: Recording the Symptom as the Cause
Worked example. Internal audit finding: in three of twelve sampled batch releases for a purchased part, the inspection record carries no documented release decision. The batches were produced and shipped.
The usual write-up takes four lines. Cause: “inspector forgot to enter it.” Action: “inspectors briefed on 14 March.” Owner: incoming inspection team lead. Status: closed. Twenty minutes, start to finish.
Follow the causal chain further and it looks different:
- The inspector forgot. Not a finding — the original observation restated in personal form. Action: training. Typical shelf life: one quarter.
- The release decision is not a mandatory field. The inspection step closes with the field empty. Action: configure it as mandatory. Cost: an hour.
- The inspection plan places the decision after the goods have been posted onward. The inspector back-fills when there is time, and sometimes there isn’t. Action: reorder the plan.
- Inspection severity for this part was reduced after a supplier evaluation, without the inspection plan being updated. Action: couple supplier evaluation to inspection plan maintenance.
Only from level 2 onward does the action change the system rather than the person. And only level 4 answers the question 10.2.1 b) 3) asks — whether similar nonconformities exist or could potentially occur [4] — because if that coupling is missing in general, the finding touches every part on reduced inspection, not three batches.
None of which makes training wrong in itself. It is a corrective action only where the cause really was a competence gap. Everywhere else it is a correction with an educational flavor.
How Far the Causal Chain Has to Go
The standard names no depth. It names two criteria that produce one.
The first is 10.2.1 b) 3): you have to determine whether similar nonconformities exist or could potentially occur [4]. That is the practical stopping rule — you are deep enough when you can answer it without guessing. With “the inspector forgot” you cannot; the statement says nothing about other inspectors, sites or parts. With “supplier evaluation and inspection plan maintenance are not coupled” you can, and the answer is countable.
The second sits at the end of 10.2.1: corrective actions shall be appropriate to the effects of the nonconformities encountered [4]. Depth is not free to maximize. A missing initial on an internal routing slip does not justify redrawing the process landscape.
On method the standard says nothing. Two formats have earned their place, with clearly different scopes: the 5 Whys method with worked examples for single findings with a short chain, and the 8D report to VDA Volume 8D for customer complaints, where containment and permanent corrective action sit in separate disciplines. Which one carries which case is set out in the overview of root cause analysis in quality management.
Assessment: the five in “5 Whys” is a mnemonic, not a requirement. For systemic findings the usable chain tends to run three or four levels; below that you stop at people, above it you lose the connection to the finding.
What ISO 9001 Clause 10.2 Actually Requires
First a correction that many question catalogues get wrong: subclauses 10.2.1 and 10.2.2 carry no printed headings in the standard. Anyone citing “10.2.1 General” is citing something that does not exist. Nor does the standard require a procedure for handling corrective action.
What it does require can be listed in full. Clause 10.2.1 applies to nonconformities, including any arising from complaints [4]:
| Subclause | Requirement (paraphrased) | What an auditor looks at |
|---|---|---|
| 10.2.1 a) | react: control and correct, deal with the consequences | quarantine note, recall, customer notification, rework record |
| 10.2.1 b) 1) | review and analyse the nonconformity | a description that goes beyond restating the finding |
| 10.2.1 b) 2) | determine the causes | a named method and its output, not a single line |
| 10.2.1 b) 3) | determine whether similar ones exist or could occur | a documented sweep across sites, parts, processes |
| 10.2.1 c) | implement any action needed | action with an owner and a due date |
| 10.2.1 d) | review the effectiveness of corrective action taken | a post-implementation result, with a date on it |
| 10.2.1 e) | update risks and opportunities, if necessary | a change trail in the 6.1 risk assessment |
| 10.2.1 f) | change the QMS, if necessary | revised process description, release status |
| 10.2.2 a) | evidence of the nature of the nonconformity and actions taken | the record itself |
| 10.2.2 b) | evidence of the results of any corrective action | the outcome of the effectiveness review |
Two connections regularly get missed. Clause 9.2.2 e) requires correction and corrective action without undue delay for audit findings, wiring internal audit straight into 10.2; and nonconformities and corrective actions are inputs to the management review under 9.3.2 [4]. An action list that has to be reassembled by hand before every management review is a symptom in its own right; how to run the lifecycle as one continuous record is covered in the article on managing audit findings and actions.
The Effectiveness Review — the Step That Goes Missing
Clauses 10.2.1 d) and 10.2.2 b) are two requirements, not one. The first demands the act: review whether the corrective action worked. The second demands evidence of the result of that review [4]. Most action registers I see in audits satisfy the first half and none of the second. A tick next to “implemented” proves somebody did something. It does not prove it worked.
The difference is operational, not semantic. Implemented means: the mandatory field is configured. Effective means: across the next thirty batch releases no empty field occurred, verified by a system query three months after the change, result on file.
For that to work, the effectiveness criterion has to be set when the action is decided, not when it is closed. Three things are enough: an observable measure, an observation window, and a sample. Define the criterion at the end and you will inevitably define one the action has already passed.
Assessment: the standard gives no interval. One rule from audit practice holds up well: the observation window has to contain at least one full cycle of the affected process — days for a batch release, potentially a year for a calibration interval. A blanket three months for everything is convenient and wrong in both directions.
On the tooling side this is a linkage problem, not a form problem: finding, cause, action and effectiveness review have to be one record before an overdue effectiveness date can become visible at all. How qportal models that is on the page for actions and CAPA, with the audit side under audit management. The normative emphasis shifts further toward evidence of effectiveness in the coming revision, which the article on the changes in ISO 9001:2026 covers.
Conclusion
Keep calling the process CAPA. The term is established, and in a plant with medical device or automotive customers everyone knows what you mean. Just don’t build the process out of the term — build it out of 10.2. Otherwise you maintain a preventive-action field that has matched no requirement since 2015 while leaving open the subclause that actually gets tested.
That § 820.100 has not existed since February 2026 is more than a footnote. It shows how quickly a borrowed structure dates while your own normative reference stays put: 10.2.1 a) through f) and 10.2.2 a) and b) have stood unchanged for eleven years.
If you change one thing about your process, change this: fix the effectiveness criterion before you approve the action. A well-kept record takes care of most of 10.2 on its own. It never takes care of that.
Sources
Primary sources — regulation
- Electronic Code of Federal Regulations: 21 CFR § 820.100 — Corrective and preventive action, Subpart J of Part 820 (Quality System Regulation), as in force on 2 June 2025, i.e. before the QMSR amendments took effect. https://www.ecfr.gov/on/2025-06-02/title-21/part-820/section-820.100 (accessed 2026-08-27)
- U.S. Food and Drug Administration: Medical Devices; Quality System Regulation Amendments. Final rule, 89 FR 7496, published 2 February 2024, effective 2 February 2026. The mapping of corrective and preventive action onto clauses 8.5.2 and 8.5.3 of ISO 13485 is made by the FDA itself in the preamble to the final rule. https://www.federalregister.gov/documents/2024/02/02/2024-01709/medical-devices-quality-system-regulation-amendments (accessed 2026-08-27)
- Electronic Code of Federal Regulations: 21 CFR Part 820 — Quality Management System Regulation, current edition. §§ 820.1, 820.3, 820.7, 820.10, 820.35, 820.45; Subparts C through O reserved. https://www.ecfr.gov/current/title-21/chapter-I/subchapter-H/part-820 (accessed 2026-08-27)
Primary sources — standards
- ISO 9001:2015, Quality management systems — Requirements, consulted in the bilingual edition DIN EN ISO 9001:2015-11, Beuth Verlag, Berlin. Clauses used: 3, 6.1, 8.7, 9.2, 9.3.2, 10.2 and informative Annex A.4.
- ISO 9001:2008, Quality management systems — Requirements, consulted in the trilingual edition DIN EN ISO 9001:2008-12, Beuth Verlag, Berlin. Clauses used: 8.5.2 and 8.5.3.
Normative text is copyrighted; requirements are paraphrased throughout rather than quoted. Consultancy, certification body and content marketing pages are not used as sources. Where this article goes beyond the documented evidence, it is labelled as an assessment.
Frequently asked questions
- Does ISO 9001 require a CAPA process?
- No. The word CAPA does not appear anywhere in ISO 9001. The standard covers nonconformity and corrective action in clause 10.2 and the control of nonconforming outputs in clause 8.7. Calling your process CAPA breaks nothing, but the requirements behind it have to come from 10.2, not from a US regulation that most ISO 9001 users are not subject to.
- What is the difference between a correction and a corrective action?
- A correction deals with the defective output itself: quarantine the batch, complete the record, notify the customer. A corrective action removes the cause so the nonconformity does not recur or occur elsewhere. ISO 9001:2015 places them separately — correction in 8.7 and 10.2.1 a), cause removal in 10.2.1 b) through d) — and one event usually triggers both.
- Does ISO 9001:2015 still have preventive action?
- Not as a clause of its own. Annex A.4 states explicitly that the standard contains no separate clause or subclause on preventive action, because the quality management system is itself meant to act as a preventive tool. The concept is carried by risk-based thinking, which anchors the determination of risks as a basis for planning in clause 6.1. ISO 9001:2008 still had a dedicated clause 8.5.3.
- Does the standard require a documented procedure for corrective action?
- ISO 9001:2015 does not. The obligation to establish documented procedures for corrective and preventive action sat in ISO 9001:2008, clauses 8.5.2 and 8.5.3, and was dropped in the 2015 revision. What remains is the retention duty in 10.2.2: evidence of the nature of the nonconformity, the actions taken, and the results of any corrective action.
- How do you evidence that a corrective action was effective?
- By defining the effectiveness criterion when the action is decided, not when it is closed. You need three things: an observable measure, an observation window, and a sample — for example, the next thirty batch releases with no empty release field, checked three months after the change. Clause 10.2.1 d) requires the review; it names neither a deadline nor a method.