ISO 13485 CAPA: Clauses 8.5.2 and 8.5.3 Requirements

Introduction

The ISO 13485 CAPA procedure — covering corrective and preventive action — is consistently one of the most scrutinised elements of a medical device quality management system. In every Notified Body audit, every FDA inspection, and every MDSAP assessment, CAPA is examined in depth. And for good reason: a CAPA system that works is the clearest possible signal that an organisation understands its own quality problems, fixes them at the root, and prevents them from recurring. A CAPA system that exists only on paper is, in regulatory terms, almost worse than no system at all.

What makes CAPA distinctive as an audit subject is that it cannot be prepared for in the way most clauses can. A procedure can be written the week before an audit; a CAPA system cannot, because what is examined is not the procedure but the record trail it produced over the preceding twelve months. An auditor selects three or four closed CAPAs, reads them end to end, and forms a judgement about the organisation from what those records do and do not contain. Everything else in the CAPA section of the audit follows from that reading.

This guide covers everything you need to build, operate, and document a compliant ISO 13485 CAPA procedure — starting with the eleven requirements the standard actually imposes on your documented procedure, then the mapping from the former 21 CFR 820.100 structure, the step-by-step process, root cause analysis methods, effectiveness verification, and the most common audit findings. If you are new to ISO 13485 and its quality management system requirements, we recommend reading our complete ISO 13485 guide first as the foundation for everything covered here.

Table of Contents

CAPA under ISO 13485: what clauses 8.5.2 and 8.5.3 require

ISO 13485:2016 addresses CAPA in two separate clauses within Section 8.5 (Improvement).

Clause 8.5.2 — Corrective action deals with nonconformities that have already occurred. The organisation must act to eliminate their causes and prevent recurrence, without undue delay, with actions proportionate to the effects of the nonconformity encountered.

Clause 8.5.3 — Preventive action deals with potential nonconformities that have not yet occurred but have been identified as credible. The organisation must determine action to eliminate their causes and prevent them from occurring, proportionate to the effects of the potential problem.

Both clauses require a documented procedure, and each specifies exactly what that procedure must define — six requirements for corrective action, five for preventive action. The table below sets out all eleven, what each one demands in practice, the record that satisfies it, and the way the finding is written when it is missing.

The eleven documented requirements, side by side

The right-hand column is the part most guides omit. A finding is not a topic, it is a sentence: a statement of the requirement, followed by the objective evidence that the requirement was not met. Reading the column as an auditor would write it is the fastest way to see whether your own records would survive the same sentence.

Ref.What the procedure must defineWhat it means in practiceRecord that satisfies itHow the finding is written
Clause 8.5.2 — Corrective action (six requirements)
aReview of nonconformities, complaints includedA defined intake and screening step covering every quality data source, not only complaintsCAPA intake log; review board minutesThe documented procedure identifies complaints as the only input to CAPA review; nonconformity reports, internal audit findings and supplier performance data are not defined as inputs and no evidence of their screening was available.
bDetermination of the causesA structured root cause method applied and documented, not a restatement of the problemRoot cause analysis record with method, evidence and conclusionIn the CAPA records reviewed, the root cause is recorded as “operator error”. No analysis was performed to determine why the error was possible, and no method of investigation is recorded.
cEvaluation of the need for actionA documented decision on whether action is required — including when the answer is noCAPA decision record with rationaleThe procedure does not require the evaluation of the need for action to be recorded where the outcome is that no CAPA is opened. Quality events assessed and closed without CAPA leave no record of the assessment or its rationale.
dPlanning, documenting and implementing the action, updating documentation as appropriateNamed owners, target dates, and the document control chain that follows from the actionAction plan; revised SOPs; training recordsThe corrective action required revision of a work instruction. The revised instruction was issued, but no evidence was retained that the personnel performing the activity had been trained on the revision before it took effect.
eVerification that the action does not adversely affect regulatory compliance or device safety and performanceA documented impact assessment before the action is deployedChange impact assessment; updated risk management fileThe documented procedure does not require, and the records do not contain, verification that the action taken does not adversely affect the ability to meet applicable regulatory requirements or the safety and performance of the device.
fReview of the effectiveness of the action takenCriteria defined in advance, an observation period, and objective evidenceEffectiveness verification recordThe CAPA records reviewed were closed on the date the last action was implemented. No effectiveness criteria were defined and no review of effectiveness was performed after closure.
Clause 8.5.3 — Preventive action (five requirements)
aDetermination of potential nonconformities and their causesSystematic analysis of trends and risk outputs — the intake step has no equivalent to 8.5.2(a)Trend analysis records; risk review outputsNo process is defined for the determination of potential nonconformities. Preventive action is initiated only in response to nonconformities that have already occurred, which is corrective action.
bEvaluation of the need for action to prevent occurrenceA documented decision, mirroring 8.5.2(c) but forward-lookingPreventive action decision recordPreventive actions are recorded in the same record as the corrective action, without a separate evaluation of the need for action to prevent occurrence.
cPlanning, documenting and implementing the action, updating documentation as appropriateIdentical in substance to 8.5.2(d)Action plan; revised documentationPreventive actions are recorded without an assigned owner or target date, and no evidence of implementation was available at the time of the audit.
dVerification that the action does not adversely affect regulatory compliance or device safety and performanceIdentical in substance to 8.5.2(e) — note the letter shifts from (e) to (d)Change impact assessmentThe documented procedure cross-references clause 8.5.3(e) for the verification requirement. The requirement is at 8.5.3(d); 8.5.3(e) is the review of effectiveness.
eReview of the effectiveness of the action taken, as appropriateSame as 8.5.2(f), but the standard qualifies it with “as appropriate” — the qualifier must be justified, not assumedEffectiveness verification record, or a documented rationale for why one is not warrantedThe procedure states that review of effectiveness is performed “as appropriate”. No criteria are defined for determining when it is appropriate, and no preventive action record reviewed contained a review of effectiveness or a rationale for its omission.

Records are mandatory for both clauses. ISO 13485 requires that the results of any investigation and of the action taken be retained as records, controlled under Clause 4.2.5. An investigation that reached the right conclusion but left no record is, for audit purposes, an investigation that did not happen.

The four differences between the two clauses

Manufacturers routinely copy the corrective action procedure, change the title, and call it the preventive action procedure. Four differences make that a finding:

1. There is no preventive equivalent of 8.5.2(a). Corrective action starts from a review of nonconformities that already exist. Preventive action has no such input — it must be fed by trend analysis, risk management output, and process review, which means the procedure has to define where that data comes from and who looks at it.

2. The sub-lettering shifts. The impact verification requirement is (e) under corrective action and (d) under preventive action. Procedures that cross-reference the wrong letter are common and easy for a reviewer to spot.

3. Effectiveness review is qualified only in 8.5.3. Under 8.5.2(f) the review of effectiveness is unconditional. Under 8.5.3(e) it is required “as appropriate” — which is a decision the manufacturer must document, not an exemption.

4. The proportionality anchor differs. Corrective actions are proportionate to the effects of the nonconformities encountered; preventive actions to the effects of the potential problems. The second is an estimate, and the basis for that estimate has to be recorded.

✦ Premium bundle · ISO 13485 + MDSAP

The ultimate global QMS documentation bundle.

Combine ISO 13485 and all 5 MDSAP markets in one premium package. A deduplicated structure means you customise each document once, not twice.

✓ 41 SOPs covering both ISO 13485 and MDSAP

✓ 70+ templates with deduplicated structure

✓ Save €199 vs buying separately

Get the Combined Kit → €699

21 CFR 820.100 mapped onto ISO 13485

Until February 2026 the FDA expressed its CAPA expectations through the seven requirements of 21 CFR 820.100(a). Under the QMSR those seven no longer stand alone: the reference framework is now the eleven requirements above. The two structures overlap substantially but not completely, and the gaps run in both directions.

The table below is the mapping. It matters for two reasons. If your procedure was written against the old seven-point structure, the empty cells in the right-hand column are the clauses your procedure never had to address and now does. And the two ISO requirements with no FDA equivalent are the ones US-only manufacturers are most likely to be missing entirely.

21 CFR 820.100(a)What it requiredISO 13485:2016 equivalentWhat changes in practice
(1)Analysing processes, work operations, concessions, quality audit reports, quality records, service records, complaints, returned product and other quality data sources to identify existing and potential causes of nonconforming product8.5.2(a) and 8.5.3(a) — split across both clausesThe single FDA requirement becomes two separate obligations with different inputs. What was one analysis is now an intake step for corrective action and a distinct trend analysis for preventive action.
(2)Investigating the cause of nonconformities relating to product, processes and the quality system8.5.2(b)Substantively unchanged.
(3)Identifying the action needed to correct and prevent recurrence of nonconforming product and other quality problems8.5.2(c) and 8.5.2(d)ISO separates the decision on whether action is needed from the planning of the action. The evaluation itself now has to be recorded, including where the outcome is that no action is taken.
(4)Verifying or validating the corrective and preventive action to ensure it is effective and does not adversely affect the finished device8.5.2(e) and 8.5.2(f)One FDA requirement becomes two ISO requirements that are frequently confused: the impact assessment before deployment, and the effectiveness review after it. Procedures that address only one of the two are the most common consequence of the transition.
(5)Implementing and recording changes in methods and procedures needed to correct and prevent identified quality problems8.5.2(d)Substantively unchanged.
(6)Ensuring that information related to quality problems or nonconforming product is disseminated to those directly responsible for assuring quality or preventing such problemsNo direct equivalentISO 13485 has no standalone dissemination requirement. The obligation survives through clause 5.5.3 (internal communication) and the training requirements of 6.2, but a procedure that simply deletes it loses a control the FDA still expects to see operating.
(7)Submitting relevant information on identified quality problems, and on corrective and preventive actions, for management reviewNo direct CAPA equivalentThe obligation moves to clause 5.6.2, which lists corrective and preventive action among the mandatory management review inputs. The requirement is unchanged in substance but now lives outside Section 8.5, and CAPA procedures that do not cross-reference it tend to lose the linkage.
Requirements in ISO 13485 with no counterpart in 21 CFR 820.100
—8.5.3 as a whole — preventive action as a separately documented process with its own inputs, decisions and recordsThe old QSR treated corrective and preventive action as a single combined system. A US-only manufacturer transitioning to QMSR must now be able to show a preventive action process that operates independently of any nonconformity having occurred.
—The proportionality qualifiers in 8.5.2 and 8.5.3 — action proportionate to the effects encountered or potentialThe FDA text carries no proportionality language. Under ISO the extent of investigation and action must be justified against the effects, which means the justification itself becomes a record.

Procedures written against the old seven-point structure map onto the new framework imperfectly and should be reviewed clause by clause rather than relabelled. The two most frequent gaps are the missing impact assessment — requirement (4) split into 8.5.2(e) and (f), with only (f) implemented — and a preventive action process that has no input of its own.

Correction, corrective action, preventive action

One of the most persistent sources of confusion in CAPA management is the distinction between three related but distinct concepts. Conflating them is the origin of a large share of CAPA findings.

ConceptWhat it addressesWhen it appliesExample
CorrectionThe specific instance — the symptom, not the causeImmediately, on discoveryQuarantining the affected batch; correcting the erroneous record
Corrective actionThe root cause of a nonconformity that has occurredAfter root cause analysisRewriting the ambiguous work instruction and adding independent verification
Preventive actionThe cause of a nonconformity that has not occurred yetOn trend, risk or process analysisAdding a poka-yoke to a process where a comparable line has failed

The practical test is what happens if the action succeeds completely. A successful correction leaves the process exactly as it was, with one defective output removed. A successful corrective action means the same output cannot be produced again by the same mechanism. If the action taken would not survive that test — if the process is unchanged once the action is complete — it has been recorded in the wrong category, and the nonconformity will recur.

Most organisations run corrective and preventive action through a single workflow with a common record format. That is acceptable, and often sensible, provided the procedure makes the differentiation explicit: different triggers, different investigation inputs, and a decision point that assigns each event to the correct category before the investigation begins rather than after it.

CAPA triggers — when to open a CAPA

Not every quality event requires a CAPA. A proportionate, risk-based approach means applying CAPA to events of significance — where the underlying cause is systemic, where recurrence would pose a risk to product safety or regulatory compliance, or where the potential impact is significant.

Events that typically trigger corrective action

  • Internal audit nonconformities — for how audit findings feed into CAPA, see our ISO 13485 internal audit checklist guide
  • Customer complaints indicating potential product safety or performance issues
  • Nonconforming product findings during inspection or testing
  • Process deviations with potential patient safety implications
  • Adverse events or vigilance reports
  • Supplier nonconformities with patient safety implications
  • Regulatory inspection findings — including MDSAP audit findings

Events that typically trigger preventive action

  • Adverse trends identified in quality data — complaint rates, rejection rates, audit finding patterns
  • Risk assessment outputs identifying high-probability failure modes, connected to the ISO 14971 risk management process
  • Industry-wide safety signals or regulatory guidance updates
  • Management review outputs identifying systemic vulnerabilities
  • Process hazard analyses identifying potential failure points

The decision must be documented either way, with its rationale — both when a CAPA is opened and when a quality event is assessed and determined not to require one. Clause 8.5.2(c) requires the evaluation of the need for action, not merely the record of the actions taken.

STEP 1 Identification and initiation STEP 2 Immediate containment STEP 3 Problem description STEP 4 Root cause analysis STEP 5 Action planning STEP 6 Implementation STEP 7 Effectiveness verification STEP 8 Closure and management review If effectiveness is not demonstrated, the CAPA is reopened at Step 4 The two steps most often missing from the record Step 6 impact assessment — clause 8.5.2(e) · Step 7 effectiveness verification — clause 8.5.2(f)
Figure 1 — The ISO 13485 CAPA process from trigger to closure

The ISO 13485 CAPA process — step by step

Step 1 — Problem identification and CAPA initiation

The process begins with the identification of a trigger event and the formal opening of a CAPA record. The record must capture at minimum: the source of the trigger, the date of identification, the initial description of the problem, the person responsible for the investigation, and the assigned priority based on initial risk assessment.

Priority assignment matters — it determines how quickly the investigation must be completed and how quickly actions must be implemented. A CAPA triggered by a potential patient safety issue requires faster response than one triggered by an administrative nonconformity.

Step 2 — Immediate containment

Before investigating the root cause, the immediate impact of the nonconformity must be contained. This may involve segregating and quarantining nonconforming product, suspending a process, notifying customers or regulatory authorities, or issuing a field safety corrective action.

Containment is a correction — it addresses the specific instance of the problem. It must be documented and linked to the CAPA record, but it does not replace the corrective action that addresses the root cause.

Step 3 — Problem description

A precise problem description is the foundation of an effective root cause investigation. It must answer five questions: what is the problem, where was it observed, when was it first identified, how often does it occur, and what is its potential impact on product safety, patient safety, or regulatory compliance.

A vague problem description — “supplier performance issue” — produces a vague investigation. A precise description — “28% of incoming inspection records for Component X from Supplier Y were missing the required signature in Field 4 during Q3 2025” — enables targeted root cause analysis.

Step 4 — Root cause analysis

Root cause analysis is the most critical and most frequently deficient step in CAPA management. If a CAPA skips root cause analysis or effectiveness checks, it becomes little more than a to-do list of corrections rather than a true improvement engine.

The root cause is the fundamental systemic reason why the problem occurred. “Operator error” is a symptom. “The work instruction was ambiguous and there was no independent verification required” is a root cause. Root cause analysis should always involve a cross-functional team — a single investigator will be limited by their own experience and perspective.

Step 5 — Action planning

The action plan defines the specific actions to be implemented, the owner responsible for each, the target completion date, the expected outcome, and — critically — the effectiveness verification criteria. These criteria must be defined before implementation, not retrospectively.

Actions must target the root cause. A corrective action that retrains the operator without fixing the procedure that created the conditions for error will fail the effectiveness check — and generate the same finding in the next audit.

Step 6 — Implementation

All actions must be implemented within the defined timelines. All changes must go through document control: updated procedures require formal revision, and training on changes must be documented with evidence of completion and evaluation. Before deployment, the action must be assessed for its impact on regulatory compliance and on the safety and performance of the device — this is the requirement in Clause 8.5.2(e), and its counterpart 8.5.3(d).

This step connects directly to the wider change control obligations of ISO 13485: changes to manufacturing processes or device design triggered by a CAPA must be evaluated against their full impact on the quality management system, and where the change affects risk, the risk management file must be updated.

Step 7 — Effectiveness verification

Effectiveness verification is the evidence-based confirmation that the action eliminated the root cause and the problem has not recurred. It requires a review after a defined time or number of cycles, against criteria set in advance, using objective evidence.

If verification reveals the problem has recurred or the action was insufficient, the CAPA is reopened and the root cause analysis revisited. This is not a failure — it is the system working as designed.

Step 8 — CAPA closure and management review

A CAPA can be closed only when all actions have been completed, all documentation is updated, training has been conducted and documented, and effectiveness verification confirms resolution. CAPA trends must be reported at management review, giving top management visibility into systemic quality challenges.

✦ Audit-ready kit · ISO 13485

Build your ISO 13485 QMS with confidence.

Built on 15+ years of audit experience — every SOP and template references the regulations auditors expect. Get to certification faster, with industry best practices baked in.

✓ 30 SOPs covering the full QMS scope

✓ 56 templates ready to customise

✓ Aligned with EU MDR + FDA QMSR

Get the ISO 13485 Kit → from €499

Root cause analysis methods for medical device CAPA

No method is mandated. The choice should follow the shape of the problem, and the rationale for the choice belongs in the CAPA record.

MethodHow it worksBest suited toLimitation
5 WhysRepeated questioning until a systemic cause is reachedLinear, single-cause problems; the right starting point for most CAPAsFollows one chain; misses interacting causes
Fishbone (Ishikawa)Contributing factors sorted into Man, Machine, Method, Material, Measurement, EnvironmentProblems with several contributing factors; cross-functional workshopsGenerates candidates, does not rank them
FMEAFailure modes scored on severity, occurrence and detectability, then prioritisedPreventive action and process planningProactive by design; awkward as a retrospective tool
Fault Tree AnalysisTop-down Boolean modelling from the failure event to its causesCritical CAPAs where several causes must combineTime-consuming; needs system knowledge

A combined approach is often best: 5 Whys to reach the immediate causes, a fishbone diagram to categorise contributing factors, and fault tree analysis to map complex interactions. FMEA is also central to risk management under ISO 14971 — our ISO 14971 guide covers how failure modes feed into the wider risk management process.

Choosing the method by the shape of the problem 5 Whys One cause, one chain Start here for most CAPAs Limitation Misses interacting causes Fishbone Several contributing factors Cross-functional workshop Limitation Lists candidates, does not rank them FMEA Failure modes ranked by risk The preventive-action tool Limitation Awkward used retrospectively Fault Tree Causes that must combine Critical CAPAs only Limitation Slow; needs deep system knowledge The method chosen and the reason for choosing it both belong in the CAPA record
Figure 2 — Root cause analysis methods compared

CAPA documentation requirements

ISO 13485 requires records to be maintained for all CAPA activities. A complete CAPA record must contain:

  • Problem description — the precise description of the nonconformity including source, date, frequency, scope, and initial risk assessment.
  • Immediate correction — what was done to address the specific instance of the problem.
  • Root cause analysis — the method used, the investigation process, the evidence reviewed, and the identified root cause.
  • Action plan — every action defined, with owner, target date, expected outcome, and effectiveness criteria.
  • Impact assessment — the evaluation showing the action does not compromise regulatory compliance or device safety and performance.
  • Implementation evidence — documents, training records, validation data, or other objective evidence that actions were completed as planned.
  • Effectiveness verification — the criteria defined, the observation period, the data collected, and the conclusion.
  • Closure decision — who closed the CAPA, on what date, and based on what evidence.
  • Management review linkage — reference to the management review where CAPA status was reported.

For medical device software manufacturers, CAPA records related to software anomalies must also align with the anomaly resolution requirements of IEC 62304, which defines how software problems discovered in post-production must be evaluated, tracked, and resolved within the QMS framework.

The nine elements a complete CAPA record contains 1 · Problem description Source, date, frequency, scope, risk 2 · Immediate correction What was done about this instance 3 · Root cause analysis Method, evidence, conclusion 4 · Action plan Owner, date, outcome, criteria 5 · Impact assessment Clause 8.5.2(e) — most often absent 6 · Implementation evidence Documents, training, validation data 7 · Effectiveness verification Clause 8.5.2(f) — most often absent 8 · Closure decision Who, when, on what evidence 9 · Management review link Clause 5.6.2 reference
Figure 3 — Mandatory elements of a CAPA record

CAPA and QMSR — what changed in February 2026

The FDA Quality Management System Regulation (QMSR), effective 2 February 2026, incorporates ISO 13485:2016 by reference into 21 CFR Part 820. Under the previous QSR, CAPA was a single combined system that did not separate corrective from preventive action in law. Under QMSR and ISO 13485, manufacturers maintain documented processes for corrective action under Clause 8.5.2 and preventive action under Clause 8.5.3, each with its own triggers and documentation requirements.

The practical consequence for US-facing manufacturers is that the eleven requirements set out above are now the reference framework for an FDA inspection, not only for a Notified Body audit. The mapping table earlier in this guide shows exactly where the old seven-point structure lands and where it leaves gaps.

For organisations pursuing MDSAP certification, CAPA requirements are assessed across all five participating regulatory authorities — Australia, Brazil, Canada, Japan and the United States — making a fully documented, evidence-based CAPA system even more critical.

Common CAPA audit findings under ISO 13485

The six findings that recur, in the order they are most often raised 1 · Root cause recorded at symptom level — clause 8.5.2(b) 2 · No effectiveness verification before closure — clause 8.5.2(f) 3 · No impact assessment before deployment — clause 8.5.2(e) 4 · No preventive action process with its own input — clause 8.5.3(a) 5 · CAPAs open beyond the defined timeline without justification 6 · Incomplete records — missing analysis, evidence or closure entry
Figure 4 — The recurring CAPA audit findings under ISO 13485

Symptom-level root cause is the single most common CAPA finding. Auditors routinely ask how the organisation ensures that a CAPA addresses the root cause rather than the symptom — and the answer lies in the consistent application of structured root cause analysis tools, evidenced in the record. Where the same retraining action appears as the corrective action across several CAPAs for the same type of error, that pattern is itself the evidence that root causes were never identified.

No effectiveness verification — CAPAs are closed once actions are implemented, without subsequent monitoring to confirm the problem did not recur. This is one of the clearest indicators of a CAPA system managed for compliance rather than improvement, and it is a direct failure of Clause 8.5.2(f).

No impact assessment — the requirement in Clause 8.5.2(e) is the most frequently omitted of the six, because it is the least intuitive. The corrective action is deployed without any documented evaluation of whether it compromises regulatory compliance or device safety and performance. Procedures carried over from the old 21 CFR 820.100 structure are particularly exposed here, because requirement (4) bundled the impact check together with effectiveness and most procedures implemented only the second half.

No preventive action system — quality data is collected but never systematically analysed to identify potential nonconformities and trigger preventive action. Clause 8.5.3(a) has no equivalent intake step to fall back on, so where the analysis does not exist, the clause is simply unimplemented. Preventive action is consistently the most underused element of Section 8.5.

Inadequate timelines — CAPAs remain open for excessive periods with no documented progress or justification for delays. ISO 13485 requires corrective actions to be taken without undue delay, and Notified Bodies apply significant scrutiny to CAPA ageing reports during surveillance audits. This is also one of the most visible findings during the ISO 13485 internal audit process.

Incomplete CAPA records — missing root cause analysis documentation, absent implementation evidence, or no formal closure record. Under FDA QMSR, CAPA records are subject to FDA inspection.

CAPA effectiveness verification — how to do it correctly

Effectiveness verification is the most frequently deficient element of CAPA management. Four principles define a robust approach.

Define criteria before implementation. Effectiveness criteria belong in the action plan, not in a retrospective judgement. They should be measurable and specific: “zero recurrence of this nonconformity in the next 50 incoming inspection records” is measurable; “no further issues” is not.

Allow sufficient observation time. For a nonconformity that occurred twice in a quarter, a two-week observation period is insufficient. The observation period should cover at least the same timeframe over which the original nonconformity was observed.

Use objective evidence. Effectiveness cannot rest on subjective assessment. It must be based on data, records, inspection results, or complaint rates.

Report results formally. The verification must be documented in the CAPA record with the evidence reviewed, the conclusion, and the name and date of the person who verified it.

All CAPA records must be retained for a minimum period defined in your document control procedure — typically the lifetime of the product plus the applicable regulatory retention period, with a general minimum of five years for most ISO 13485-certified organisations.

For manufacturers of medical device software, CAPA records triggered by software anomalies must be cross-referenced with the anomaly resolution process defined under IEC 62304. The software anomaly list — also a key component of SOUP management for third-party components — feeds directly into the CAPA system when anomalies cross the threshold of regulatory significance.

✦ Complete catalogue

Find the documentation you need — instantly.

Whether you need a complete kit or just one specific SOP, the catalogue has it. Individual process packages and complete bundles, all instantly downloadable and fully editable.

✓ Complete bundles or individual packages

✓ Individual process packages from €69 each

✓ ISO 13485 · MDSAP · Combined Kit

Browse All Kits →

Frequently asked questions

What does ISO 13485 require for CAPA?

ISO 13485:2016 requires a documented procedure covering six defined requirements for corrective action under Clause 8.5.2 and five for preventive action under Clause 8.5.3 — from the review of nonconformities and determination of causes through to the review of effectiveness. Records of every investigation and of the action taken must be retained under Clause 4.2.5. The full breakdown of all eleven requirements is in the table above.

What is the difference between clause 8.5.2 and 8.5.3?

Clause 8.5.2 covers corrective action — nonconformities that have already occurred — and lists six requirements. Clause 8.5.3 covers preventive action — potential nonconformities — and lists five. There is no preventive equivalent of the intake step at 8.5.2(a); the impact verification requirement moves from (e) to (d); and the review of effectiveness is unconditional under 8.5.2(f) but qualified as “as appropriate” under 8.5.3(e).

How do the seven requirements of 21 CFR 820.100 map onto ISO 13485?

Five of the seven map directly onto clauses 8.5.2 and 8.5.3, though two of them split into more than one ISO requirement. Requirement (6) on dissemination of information and requirement (7) on submission to management review have no direct equivalent inside Section 8.5 — they survive through clauses 5.5.3 and 5.6.2 respectively. In the other direction, preventive action as a separately documented process and the proportionality qualifiers have no counterpart in the FDA text at all.

What is the difference between a correction and a corrective action?

A correction addresses the specific instance of a nonconformity — fixing the defective product, correcting the erroneous record. A corrective action addresses the root cause to prevent recurrence. Both may be required for the same event but are distinct activities with different objectives, and must be separately documented in the CAPA record.

How long should a CAPA remain open?

ISO 13485 requires corrective actions to be taken without undue delay. There is no prescribed maximum duration, but most organisations define target timelines in their CAPA procedure — typically 30 to 90 days, with shorter timelines for patient safety-related findings. Extended timelines must be formally justified and approved.

Is a CAPA required for every nonconformity?

No. A proportionate, risk-based approach is appropriate. Minor, isolated nonconformities with no safety implications may be addressed through immediate correction without a formal CAPA. However, the decision not to open a CAPA must be documented and justified — that is what Clause 8.5.2(c) requires. If the same nonconformity recurs, a CAPA is required regardless of severity, and recurring findings that were never escalated will themselves become a finding in the next internal audit.

How does CAPA connect to EU MDR post-market surveillance?

EU MDR requires that post-market surveillance data feeds back into the risk management file and — where significant signals are identified — into the CAPA system. A PSUR identifying an adverse trend in complaint data or post-market performance should trigger a CAPA investigation. This integration between post-market surveillance and CAPA is one of the most closely examined connections in Notified Body surveillance audits, and connects directly to the benefit-risk analysis that must be maintained continuously throughout the device lifecycle.

Can preventive actions be triggered by data that is not negative?

Yes — and this is a sign of a mature QMS. Preventive actions can be triggered by risk assessments, regulatory guidance updates, process changes that introduce new failure modes, or management review decisions. Preventive action is not only a response to adverse trends; it is also a proactive management tool, and one of the most underused elements of most QMS implementations.

Conclusions

The ISO 13485 CAPA procedure is not a compliance checkbox — it is the engine of quality improvement in a medical device organisation. When it functions correctly, it identifies systemic problems early, addresses their root causes permanently, and prevents the recurrence of quality events that could harm patients or damage the organisation’s regulatory standing. When it functions poorly — closing CAPAs on time without verifying effectiveness, identifying symptoms rather than causes, treating preventive action as an afterthought — it creates the illusion of quality management without the substance.

The eleven requirements of Clauses 8.5.2 and 8.5.3 are the measure a reviewer will apply, and since February 2026 they are the measure an FDA investigator will apply too. A procedure that addresses ten of them is a procedure with a finding waiting in it.

The organisations that consistently achieve clean audit outcomes on CAPA are not those with the most elaborate software or procedures. They are the ones that invest real time and cross-functional expertise in root cause analysis, that define meaningful effectiveness criteria before implementing actions, and that use CAPA data actively to inform management review and quality strategy.

If you are building or upgrading your CAPA system, the right starting point is a well-structured, role-specific documented procedure that your quality team can actually follow. The ISO 13485 Documentation Kit covers the full QMS scope including corrective and preventive action, and the individual CAPA process package is available separately for organisations that only need this element.

Related articles