Quick Answer
Corrective and preventive action (CAPA) connects quality signals to investigation, action and an evaluation of effectiveness. Corrective action addresses the cause of an actual problem; preventive action addresses a potential problem before it occurs. A useful CAPA record explains the evidence, the chosen action and how its outcome will be assessed. Select the applicable drug or device requirements before adopting a procedure: former device section 820.100 is not the current universal rule for CAPA.
This guide is for quality teams designing or reviewing their investigation workflow. It explains a practical seven-step process, the handoffs between records, and ways to test whether an action addresses the supported cause. The steps are an implementation framework, not seven statutory elements shared by every FDA-regulated organization.
FDA's September 2006 Quality Systems Approach guidance, sections III.D and IV.D.4–5, distinguishes correction, corrective action and preventive action in pharmaceutical quality systems. The guidance is nonbinding; current product-specific regulations determine legal obligations.
Start with the applicable requirements
For finished drugs, 21 CFR 211.192 requires thorough investigation of covered discrepancies and failures, including potentially associated batches and products, with written conclusions and followup. Whether an organization uses a separate CAPA form does not remove that investigation duty.
ICH Q10 section 3.2.2 and Table II describe a pharmaceutical CAPA system, structured investigation and evaluation of effectiveness. Identify these as guidance recommendations, alongside the applicable CGMP requirements, when mapping a procedure.
For devices, FDA's Quality Management System Regulation took effect on February 2, 2026 and incorporates ISO 13485:2016. Determine the applicability of current 21 CFR Part 820 and the incorporated requirements. Former section 820.100 is relevant to historical records, but a procedure should not present its old subsection list as the current regulatory text.
An unclear product description is an unresolved applicability question. Identify the regulated product, activities and markets before assigning a drug-only or device-only checklist. Combination products and biologics may raise additional questions. The FDA CAPA requirements guide provides a scope-oriented starting point; it does not replace an assessment of the actual operation.
Correction, corrective action and preventive action
A correction deals with the detected condition. Corrective action addresses why an actual nonconformity occurred. Preventive action addresses a potential nonconformity and can arise from risk assessment or trends without a prior failure.
| Aspect | Corrective action | Preventive action |
|---|---|---|
| Starting signal | An actual nonconformity or quality problem | Evidence of a potential problem |
| Investigation question | What conditions caused or enabled this event? | What conditions could produce the anticipated event? |
| Action purpose | Address the supported cause and reduce recurrence | Address the potential cause before the problem occurs |
| Example | Revise an ambiguous instruction implicated in a documented error | Remove comparable ambiguity in a new process before release |
| Evaluation | Check the action against the actual failure mechanism | Check whether the anticipated failure is appropriately controlled |
Do not classify an action from its label alone. Updating a procedure can be corrective or preventive depending on the problem and evidence. Recalibrating a failed instrument may correct the immediate condition without explaining why it drifted. Reviewing similar instruments helps establish scope; it does not automatically prove that every instrument needs the same action.
The same distinction applies to deviation management. A deviation record captures and investigates a departure from an expected condition. Its investigation may lead to a linked CAPA or change-control record. Evaluate the required work and traceability before deciding how many forms are needed.
A seven-step CAPA process
Use the following sequence to structure work. Activities can overlap: containment can begin before the cause is known, and new evidence can expand an investigation after an initial plan is approved. Document such changes rather than pretending the investigation followed a straight line.
1. Identify the signal and assign the assessment
Inputs can include deviations, complaints, laboratory results, audit findings, supplier performance, equipment failures, process trends and management review. Keep the source record available so the investigator can distinguish the original observation from later interpretation.
Define escalation criteria in the approved procedure. Criteria for opening a separate CAPA record should not postpone an investigation or risk response already required for the event. An apparently isolated event can be consequential; a repeated administrative issue can reveal a wider problem.
| Input | Assessment question | Avoid this shortcut |
|---|---|---|
| Deviation | What failed, what is affected, and is the condition recurring? | Assuming a known immediate cause makes investigation unnecessary |
| Complaint | What product or process concern does the evidence indicate? | Waiting for several similar complaints before assessing a serious signal |
| Audit finding | Is the gap isolated or shared across procedures and operations? | Equating a corrected document with an effective system change |
| Laboratory result | What evidence supports the investigation and disposition? | Assuming a suspected laboratory error invalidates an OOS result |
| Regulatory observation | What does the observation establish, and what work addresses it? | Assigning an automatic form or response rule without checking the applicable situation |
For laboratory failures, use the focused OOS investigation guide alongside the applicable procedure. This CAPA overview does not establish a basis for invalidating a test result or releasing a batch.
A useful initiation record identifies the signal, product or process, discovery date, original evidence, initial risk assessment, accountable owner and next review date. Record any immediate controls and the reason for escalation or non-escalation. A reviewer should be able to follow that decision without interviewing the original author.
2. Describe the problem and contain the immediate risk
State the observed discrepancy in terms another investigator can test. Include the expected condition, actual result, timing, location and known extent. Avoid writing the suspected root cause into the problem statement before gathering evidence.
For example, “the temperature was entered in the pressure field on the revised form” is a more useful observation than “the operator needs retraining.” The second statement selects an action before the mechanism has been established.
Possible containment actions include segregating potentially affected material, controlling equipment availability, securing records or introducing a justified interim check. Select actions based on the actual risk and authorized procedures. Stopping an operation, releasing a product or changing a manufacturing control requires the appropriate technical and quality decision.
Retain the scope of the containment, who authorized it, affected identifiers, evidence of execution and the conditions for review. Keep containment separate from the permanent action. An extra check can reduce exposure while the investigation continues, but it may leave the underlying cause unchanged.
Expand the assessment when new evidence identifies another batch, shared material, instruction, equipment configuration or operating condition. Explain relevant scope exclusions. “Not applicable” without a rationale gives a later reviewer little basis to assess the decision.
3. Investigate the causal mechanism
Root cause analysis should connect the observed event to evidence about how it occurred and why available controls did not prevent or detect it. “Human error,” “equipment failure” and “procedure not followed” may describe a result without explaining the cause.
| Tool | Useful question | Limitation |
|---|---|---|
| Five Whys | What causal conditions connect the event to the process? | A plausible sequence of answers is not evidence; do not force exactly five levels. |
| Fishbone diagram | Which categories of causes deserve investigation? | A list of possibilities does not establish which one caused the event. |
| Fault-tree analysis | Which combinations of conditions could produce the failure? | The logic depends on correct assumptions about the system. |
| FMEA | What potential failure modes need assessment or control? | A risk score is not proof of the cause of an actual event. |
| Is/Is Not comparison | What differs between affected and unaffected cases? | An apparent association may have another explanation. |
Consider personnel, methods, equipment, materials, environment and management conditions where relevant. Examples include instruction clarity, workload, calibration, supplier variation, access to the correct document version and availability of resources. Do not treat the categories as a mandatory list that replaces thinking about the actual event.
For each serious candidate cause, identify supporting evidence, contradictory evidence and the next discriminating check. Useful records may include the event timeline, equipment history, controlled documents, observations of the task and comparisons with unaffected batches or runs.
Before accepting a conclusion, ask:
- Does the explanation account for the observed pattern?
- What evidence would contradict it?
- Were reasonable alternatives considered?
- Does the proposed action interrupt the demonstrated mechanism?
- What uncertainty remains, and how does it affect the risk response?
If the cause remains uncertain, record the limits and further work. Do not convert the most convenient hypothesis into a confirmed root cause merely to close the record. The scope and formality of a pharmaceutical investigation should reflect risk, as described in ICH Q10 section 3.2.2, linked above.
4. Plan corrective actions and define ownership
Translate the supported cause into specific work. An action plan should identify the change, owner, justified due date, dependencies, implementation evidence and effectiveness criterion. Each field serves a different purpose; an attendance sheet cannot answer all of them.
The examples below are planning exercises, not approved remedies or FDA-prescribed intervals.
| Supported condition | Incomplete action | More testable action plan |
|---|---|---|
| An instruction has two plausible interpretations | Retrain everyone on the same instruction | Revise the ambiguous step, check it against the actual task, and assess affected users on the revised version. |
| Instrument drift is associated with the maintenance approach | Recalibrate and close | Investigate the drift mechanism, revise the appropriate control, and define evidence that the revised approach detects or prevents it. |
| Required information is unavailable at the point of use | Tell personnel to be more careful | Correct the information access or handoff, then check whether the intended user receives the needed version under routine conditions. |
Make the plan specific enough to verify without prescribing unsupported solutions. A second-person check, additional software or more training may be appropriate, but each should address the demonstrated mechanism and be assessed for new risks or unintended consequences.
Use due dates to manage accountable work. If an extension is needed, record the reason, remaining risk, interim controls and approval through the applicable procedure. Repeatedly changing the date without addressing the constraint can conceal a resource or technical problem.
5. Assess related and potential problems
Consider whether the condition could exist in another product, process, supplier, facility or operating mode. Identify the basis for similarity and collect evidence before applying the same remedy everywhere.
Preventive action is broader than copying a correction to another area. Trend analysis or risk assessment may identify a potential failure before any actual event. FDA's Quality Systems Approach guidance, section IV.D.5, linked above, discusses that proactive use of data and risk analysis.
Practical approaches include examining comparable instructions, reviewing process interfaces, testing an error-proofing control or monitoring a leading indicator. For example, a review of new forms could identify confusing field labels before the forms enter use. An interlock could prevent a known setup error, but its design and failure behavior still need appropriate assessment.
Document why an area needs action or why the evidence supports no additional action. Record any new potential problem introduced by the proposed change. Do not add unrelated tasks solely to make the action plan appear more comprehensive.
6. Implement the plan and preserve the evidence
Implementation converts a proposed change into a controlled operating condition. Apply relevant change-control, training, qualification and validation procedures according to the effect of the change. A CAPA label does not determine every documentation requirement.
| Action | Possible evidence | Question for review |
|---|---|---|
| Procedure change | Approved revision, change assessment and distribution records | Is the intended version available, and are obsolete copies controlled? |
| Training or task assessment | Training record and relevant demonstration of competence | Does the evidence address the identified knowledge or execution gap? |
| Equipment change | Change assessment and qualification or other technical evidence, as applicable | Does the evidence cover the changed use and operating conditions? |
| Electronic-system change | Configuration/change record and applicable verification or validation evidence | Does the configured workflow perform its intended task and preserve the needed records? |
These are examples rather than a universal IQ/OQ/PQ package. For electronic records, first determine the scope of 21 CFR 11.1. The fact that a tool stores information electronically does not settle all applicability questions.
Maintain a status record that distinguishes planned, implemented and evaluated work. Keep owners and dependencies visible. If the investigation changes the action plan, retain the rationale and the relationship between the earlier and approved versions.
7. Evaluate effectiveness and document the conclusion
Implementation verification asks whether the change was made. Effectiveness evaluation asks whether the evidence supports the intended result. An approved SOP, purchase order or training log can demonstrate activity without showing that the original problem is controlled.
Define the criterion, observation or sampling approach, reviewer and response to an unsuccessful result before evaluating the action. Relate the observation opportunities to the mechanism and event frequency. A quiet period with little relevant activity may provide weak evidence.
| Evidence approach | What it can show | What to check before concluding |
|---|---|---|
| Review subsequent production records | Whether the targeted discrepancy recurred | Relevant activity occurred, reporting remained consistent and the right records were assessed. |
| Observe the revised task | Whether users can perform the intended process | The conditions reasonably represent routine use, rather than unusually close supervision. |
| Analyze a trend | Whether the pattern changed | The denominator and operating conditions make the comparison meaningful. |
| Conduct a focused audit | Whether the revised controls are being used | Procedure adherence also addresses the causal mechanism or is paired with suitable outcome evidence. |
The cited guidance does not establish a universal 30-, 60- or 90-day effectiveness interval. Choose and justify evidence suited to the problem. A longer interval alone does not repair a weak criterion or an incorrect causal hypothesis.
If the check fails, retain the unsuccessful result, reassess the cause and implementation, and decide what further action and risk controls are needed. Do not record the action as effective merely because its tasks were completed. Where the procedure permits separate followup records, keep the unresolved work and accountable owner explicit.
Worked scenario: the action is complete, but effectiveness is uncertain
Consider an illustrative packaging-line investigation. An approved form places two similar fields beside each other. Records show repeated entries in the wrong field. Observation of the task and review of the instruction identify inconsistent field names as a credible contributor.
The team assesses affected records and product, corrects the form and instruction through change control, withdraws obsolete copies and assesses affected users. These records establish implementation. The effectiveness plan separately defines which routine uses will be examined and how entry errors will be identified.
At the planned review, no new errors have been reported. That fact supports different decisions depending on the available evidence:
- The line has not operated: routine-use evidence is unavailable. Assess the remaining uncertainty and the next justified review opportunity.
- The line operated, but the revised form was not consistently used: resolve implementation and document-control gaps before crediting the proposed control.
- The intended form was used under relevant conditions and the planned criteria were met: assess the evidence and document the conclusion, including its limits.
- The error recurred despite the change: reassess the causal explanation and the control. Do not assume that more training or a longer waiting period is the answer.
This scenario also exercises the preventive branch: assess whether other forms have the same confusing design. A similar appearance is a reason to investigate, not proof that the same remedy is needed everywhere.
Review records before an inspection
Use the following questions for internal preparation. They are not quotations from inspectors or a ranking of FDA observations. For current device inspection procedures, consult FDA's QMSR information; do not treat the former QSIT approach as the current process.
At system level, check how incoming signals are assessed, how responsibilities are assigned, how overdue work is escalated and how management decisions are recorded. Inspect whether thresholds inadvertently delay work required by the applicable regulation.
For an individual record, trace the original signal through scope, evidence, causal reasoning, action, implementation and effectiveness. Ask why the selected investigation method fits the problem, what alternatives were considered and what would have changed the conclusion.
Common review weaknesses include an unsupported “human error” conclusion, training that leaves the defective instruction unchanged, an effectiveness test that measures only task completion, unexplained scope exclusions and broken links to evidence. These are practical review categories, not measured frequencies of enforcement findings.
Map the procedure to the current applicable requirements and identify the exact procedure or record that addresses each obligation. Record any unresolved applicability question. Do not use a historical 820.100 cross-reference as proof of current QMSR or drug CGMP compliance.
Documentation, retention and management review
A useful record set includes the initiation decision, investigation, action plan, implementation evidence, effectiveness evaluation and closure or followup decision. Linked records should retain the intended versions and support an independent review.
Determine retention from the applicable product and record requirements and the approved retention schedule. There is no single retention period supplied by this guide for every CAPA document. In particular, do not assume “life of product plus one year” applies to all drug and device CAPA records.
Use management review to make decisions about unresolved risk, resources and recurring conditions. A status dashboard is useful when it leads to an assigned action or documented decision; administrative closure counts alone can hide weak investigations.
| Metric | Possible calculation | Interpretation limit |
|---|---|---|
| On-time closure | Records due in the period and closed by their due date divided by all records due in that period | Define treatment of extensions; exclude misleading changes to the denominator. |
| Age of open records | Days since opening, grouped by risk and stage | An average can hide one important aging investigation. |
| Effectiveness results | Effective, ineffective and inconclusive checks by period | Report unresolved checks separately instead of treating them as successes. |
| Repeat failure modes | Recurrence assessed using a defined failure classification | Different record names may conceal the same mechanism. |
| Overdue work | Actions past their approved due dates, with reasons and controls | A count does not establish the risk of each item. |
Document the period and population for each metric. If a denominator is zero, report that the rate is not applicable rather than implying perfect performance. Set internal targets from the operation's risks and evidence; this article does not establish FDA benchmark percentages.
Frequently Asked Questions
No. Correcting an error addresses the detected condition. Corrective action addresses its cause; preventive action addresses a potential problem. A record should explain which task was performed and what evidence supports it.
Next steps
Select one open or recently closed record and apply the worked scenario's decision points. Identify the relevant obligation, test the link between cause and action, and separate implementation evidence from effectiveness evidence. Assign any missing work through the approved quality process.
For a closer look at regulatory applicability, use the FDA CAPA requirements guide. For the investigation itself, use the root cause analysis guide. A completed checklist is useful only when the underlying evidence supports the conclusion.
About the author
Assyro Team
Expert regulatory operations consultants helping pharmaceutical companies navigate complex compliance challenges.

