ISO 13485 CAPA: Clause 8.5.2 and 8.5.3 Requirements, Process and Audit Findings
Table of Contents
- Introduction
- CAPA under ISO 13485: what clauses 8.5.2 and 8.5.3 require
- Correction, corrective action, preventive action
- CAPA triggers — when to open a CAPA
- The ISO 13485 CAPA process — step by step
- Root cause analysis methods for medical device CAPA
- CAPA documentation requirements
- CAPA and QMSR — what changed in February 2026
- Common CAPA audit findings under ISO 13485
- CAPA effectiveness verification — how to do it correctly
- Frequently asked questions
- Conclusions
Introduction
The ISO 13485 CAPA procedure — covering corrective and preventive action — is consistently one of the most scrutinised elements of a medical device quality management system. In every Notified Body audit, every FDA inspection, and every MDSAP assessment, CAPA is examined in depth. And for good reason: a CAPA system that works is the clearest possible signal that an organisation understands its own quality problems, fixes them at the root, and prevents them from recurring. A CAPA system that exists only on paper is, in regulatory terms, almost worse than no system at all. From the regulatory point of view, the importance of CAPA cannot be understated. Device manufacturers are always evaluated on their CAPA processes during FDA inspections. The top reason for device manufacturers to receive FDA observations is CAPA and its related processes — and manufacturers also receive CAPA-related warning letters, mostly about quality system aspects concerned with CAPA. This guide covers everything you need to build, operate, and document a compliant ISO 13485 CAPA procedure — starting with the eleven requirements the standard actually imposes on your documented procedure, then the step-by-step process, root cause analysis methods, effectiveness verification, and the most common audit findings. If you are new to ISO 13485 and its quality management system requirements, we recommend reading our complete ISO 13485 guide first as the foundation for everything covered here.CAPA under ISO 13485: what clauses 8.5.2 and 8.5.3 require
ISO 13485:2016 addresses CAPA in two separate clauses within Section 8.5 (Improvement). Clause 8.5.2 — Corrective action deals with nonconformities that have already occurred. The organisation must act to eliminate their causes and prevent recurrence, without undue delay, with actions proportionate to the effects of the nonconformity encountered. Clause 8.5.3 — Preventive action deals with potential nonconformities that have not yet occurred but have been identified as credible. The organisation must determine action to eliminate their causes and prevent them from occurring, proportionate to the effects of the potential problem. Both clauses require a documented procedure, and each specifies exactly what that procedure must define — six requirements for corrective action, five for preventive action. The table below sets out all eleven, what each one demands in practice, the record that satisfies it, and the finding raised when it is missing.The eleven documented requirements, side by side
| Ref. | What the procedure must define | What it means in practice | Record that satisfies it | Typical finding |
|---|---|---|---|---|
| Clause 8.5.2 — Corrective action (six requirements) | ||||
| a | Review of nonconformities, complaints included | A defined intake and screening step covering every quality data source, not only complaints | CAPA intake log; review board minutes | Complaints reviewed but nonconformances, audit findings and supplier data screened informally or not at all |
| b | Determination of the causes | A structured root cause method applied and documented, not a restatement of the problem | Root cause analysis record with method, evidence and conclusion | “Operator error” or “human factor” recorded as the root cause |
| c | Evaluation of the need for action | A documented decision on whether action is required — including when the answer is no | CAPA decision record with rationale | Only opened CAPAs are documented; rejected candidates leave no trace |
| d | Planning, documenting and implementing the action, updating documentation as appropriate | Named owners, target dates, and the document control chain that follows from the action | Action plan; revised SOPs; training records | Procedure changed but training not evidenced, or vice versa |
| e | Verification that the action does not adversely affect regulatory compliance or device safety and performance | A documented impact assessment before the action is deployed | Change impact assessment; updated risk management file | The requirement is not addressed at all — the most commonly omitted of the six |
| f | Review of the effectiveness of the action taken | Criteria defined in advance, an observation period, and objective evidence | Effectiveness verification record | CAPA closed on implementation, with effectiveness never assessed |
| Clause 8.5.3 — Preventive action (five requirements) | ||||
| a | Determination of potential nonconformities and their causes | Systematic analysis of trends and risk outputs — the intake step has no equivalent to 8.5.2(a) | Trend analysis records; risk review outputs | No mechanism exists at all; preventive action is the most under-implemented element of Section 8.5 |
| b | Evaluation of the need for action to prevent occurrence | A documented decision, mirroring 8.5.2(c) but forward-looking | Preventive action decision record | Preventive actions raised only as a formality alongside corrective ones |
| c | Planning, documenting and implementing the action, updating documentation as appropriate | Identical in substance to 8.5.2(d) | Action plan; revised documentation | Actions defined without owners or dates because the trigger was not an incident |
| d | Verification that the action does not adversely affect regulatory compliance or device safety and performance | Identical in substance to 8.5.2(e) — note the letter shifts from (e) to (d) | Change impact assessment | Cross-reference to the wrong sub-clause in the procedure |
| e | Review of the effectiveness of the action taken, as appropriate | Same as 8.5.2(f), but the standard qualifies it with “as appropriate” — the qualifier must be justified, not assumed | Effectiveness verification record, or a documented rationale for why one is not warranted | The qualifier used as a blanket exemption from effectiveness verification |
Records are mandatory for both clauses. ISO 13485 requires that the results of any investigation and of the action taken be retained as records, controlled under Clause 4.2.5. An investigation that reached the right conclusion but left no record is, for audit purposes, an investigation that did not happen.
The four differences between the two clauses
Manufacturers routinely copy the corrective action procedure, change the title, and call it the preventive action procedure. Four differences make that a finding: 1. There is no preventive equivalent of 8.5.2(a). Corrective action starts from a review of nonconformities that already exist. Preventive action has no such input — it must be fed by trend analysis, risk management output, and process review, which means the procedure has to define where that data comes from and who looks at it. 2. The sub-lettering shifts. The impact verification requirement is (e) under corrective action and (d) under preventive action. Procedures that cross-reference the wrong letter are common and easy for a reviewer to spot. 3. Effectiveness review is qualified only in 8.5.3. Under 8.5.2(f) the review of effectiveness is unconditional. Under 8.5.3(e) it is required “as appropriate” — which is a decision the manufacturer must document, not an exemption. 4. The proportionality anchor differs. Corrective actions are proportionate to the effects of the nonconformities encountered; preventive actions to the effects of the potential problems. The second is an estimate, and the basis for that estimate has to be recorded.✦ PREMIUM BUNDLE · ISO 13485 + MDSAP
The ultimate global QMS documentation bundle.
Combine ISO 13485 and all 5 MDSAP markets in one premium package. A deduplicated structure means you customise each document once, not twice.
- ✓ 41 SOPs covering both ISO 13485 and MDSAP
- ✓ 70+ templates with deduplicated structure
- ✓ Save €199 vs buying separately
FROM
€699
Get the Combined Kit →Correction, corrective action, preventive action
One of the most persistent sources of confusion in CAPA management is the distinction between three related but distinct concepts. Conflating them is the origin of a large share of CAPA findings.| Concept | What it addresses | When it applies | Example |
|---|---|---|---|
| Correction | The specific instance — the symptom, not the cause | Immediately, on discovery | Quarantining the affected batch; correcting the erroneous record |
| Corrective action | The root cause of a nonconformity that has occurred | After root cause analysis | Rewriting the ambiguous work instruction and adding independent verification |
| Preventive action | The cause of a nonconformity that has not occurred yet | On trend, risk or process analysis | Adding a poka-yoke to a process where a comparable line has failed |
CAPA triggers — when to open a CAPA
Not every quality event requires a CAPA. A proportionate, risk-based approach means applying CAPA to events of significance — where the underlying cause is systemic, where recurrence would pose a risk to product safety or regulatory compliance, or where the potential impact is significant. Events that typically trigger corrective action:- Internal audit nonconformities — for how audit findings feed into CAPA, see our ISO 13485 internal audit checklist guide
- Customer complaints indicating potential product safety or performance issues
- Nonconforming product findings during inspection or testing
- Process deviations with potential patient safety implications
- Adverse events or vigilance reports
- Supplier nonconformities with patient safety implications
- Regulatory inspection findings — including MDSAP audit findings
- Adverse trends identified in quality data — complaint rates, rejection rates, audit finding patterns
- Risk assessment outputs identifying high-probability failure modes, connected to the ISO 14971 risk management process
- Industry-wide safety signals or regulatory guidance updates
- Management review outputs identifying systemic vulnerabilities
- Process hazard analyses identifying potential failure points

The ISO 13485 CAPA process — step by step
Step 1 — Problem identification and CAPA initiation
The process begins with the identification of a trigger event and the formal opening of a CAPA record. The record must capture at minimum: the source of the trigger, the date of identification, the initial description of the problem, the person responsible for the investigation, and the assigned priority based on initial risk assessment. Priority assignment matters — it determines how quickly the investigation must be completed and how quickly actions must be implemented. A CAPA triggered by a potential patient safety issue requires faster response than one triggered by an administrative nonconformity.Step 2 — Immediate containment
Before investigating the root cause, the immediate impact of the nonconformity must be contained. This may involve segregating and quarantining nonconforming product, suspending a process, notifying customers or regulatory authorities, or issuing a field safety corrective action. Containment is a correction — it addresses the specific instance of the problem. It must be documented and linked to the CAPA record, but it does not replace the corrective action that addresses the root cause.Step 3 — Problem description
A precise problem description is the foundation of an effective root cause investigation. It must answer five questions: what is the problem, where was it observed, when was it first identified, how often does it occur, and what is its potential impact on product safety, patient safety, or regulatory compliance. A vague problem description — “supplier performance issue” — produces a vague investigation. A precise description — “28% of incoming inspection records for Component X from Supplier Y were missing the required signature in Field 4 during Q3 2025” — enables targeted root cause analysis.Step 4 — Root cause analysis
Root cause analysis is the most critical and most frequently deficient step in CAPA management. If a CAPA skips root cause analysis or effectiveness checks, it becomes little more than a to-do list of corrections rather than a true improvement engine. The root cause is the fundamental systemic reason why the problem occurred. “Operator error” is a symptom. “The work instruction was ambiguous and there was no independent verification required” is a root cause. Root cause analysis should always involve a cross-functional team — a single investigator will be limited by their own experience and perspective.Step 5 — Action planning
The action plan defines the specific actions to be implemented, the owner responsible for each, the target completion date, the expected outcome, and — critically — the effectiveness verification criteria. These criteria must be defined before implementation, not retrospectively. Actions must target the root cause. A corrective action that retrains the operator without fixing the procedure that created the conditions for error will fail the effectiveness check — and generate the same finding in the next audit.Step 6 — Implementation
All actions must be implemented within the defined timelines. All changes must go through document control: updated procedures require formal revision, and training on changes must be documented with evidence of completion and evaluation. Before deployment, the action must be assessed for its impact on regulatory compliance and on the safety and performance of the device — this is the requirement in Clause 8.5.2(e), and its counterpart 8.5.3(d). This step connects directly to the wider change control obligations of ISO 13485: changes to manufacturing processes or device design triggered by a CAPA must be evaluated against their full impact on the quality management system, and where the change affects risk, the risk management file must be updated.Step 7 — Effectiveness verification
Effectiveness verification is the evidence-based confirmation that the action eliminated the root cause and the problem has not recurred. It requires a review after a defined time or number of cycles, against criteria set in advance, using objective evidence. If verification reveals the problem has recurred or the action was insufficient, the CAPA is reopened and the root cause analysis revisited. This is not a failure — it is the system working as designed.Step 8 — CAPA closure and management review
A CAPA can be closed only when all actions have been completed, all documentation is updated, training has been conducted and documented, and effectiveness verification confirms resolution. CAPA trends must be reported at management review, giving top management visibility into systemic quality challenges.✦ AUDIT-READY KIT · ISO 13485
Build your ISO 13485 QMS with confidence.
Built on 15+ years of audit experience — every SOP and template references the regulations auditors expect. Get to certification faster, with industry best practices baked in.
- ✓ 30 SOPs covering the full QMS scope
- ✓ 56 templates ready to customise
- ✓ Aligned with EU MDR + FDA QMSR
From €499
Get the ISO 13485 Kit →Root cause analysis methods for medical device CAPA
No method is mandated. The choice should follow the shape of the problem, and the rationale for the choice belongs in the CAPA record.| Method | How it works | Best suited to | Limitation |
|---|---|---|---|
| 5 Whys | Repeated questioning until a systemic cause is reached | Linear, single-cause problems; the right starting point for most CAPAs | Follows one chain; misses interacting causes |
| Fishbone (Ishikawa) | Contributing factors sorted into Man, Machine, Method, Material, Measurement, Environment | Problems with several contributing factors; cross-functional workshops | Generates candidates, does not rank them |
| FMEA | Failure modes scored on severity, occurrence and detectability, then prioritised | Preventive action and process planning | Proactive by design; awkward as a retrospective tool |
| Fault Tree Analysis | Top-down Boolean modelling from the failure event to its causes | Critical CAPAs where several causes must combine | Time-consuming; needs system knowledge |

CAPA documentation requirements
ISO 13485 requires records to be maintained for all CAPA activities. A complete CAPA record must contain: Problem description — the precise description of the nonconformity including source, date, frequency, scope, and initial risk assessment. Immediate correction — what was done to address the specific instance of the problem. Root cause analysis — the method used, the investigation process, the evidence reviewed, and the identified root cause. Action plan — every action defined, with owner, target date, expected outcome, and effectiveness criteria. Impact assessment — the evaluation showing the action does not compromise regulatory compliance or device safety and performance. Implementation evidence — documents, training records, validation data, or other objective evidence that actions were completed as planned. Effectiveness verification — the criteria defined, the observation period, the data collected, and the conclusion. Closure decision — who closed the CAPA, on what date, and based on what evidence. Management review linkage — reference to the management review where CAPA status was reported. For medical device software manufacturers, CAPA records related to software anomalies must also align with the anomaly resolution requirements of IEC 62304, which defines how software problems discovered in post-production must be evaluated, tracked, and resolved within the QMS framework.CAPA and QMSR — what changed in February 2026
The FDA Quality Management System Regulation (QMSR), effective 2 February 2026, incorporates ISO 13485:2016 by reference into 21 CFR Part 820. Under the previous QSR, CAPA was a single combined system that did not separate corrective from preventive action in law. Under QMSR and ISO 13485, manufacturers maintain documented processes for corrective action under Clause 8.5.2 and preventive action under Clause 8.5.3, each with its own triggers and documentation requirements. The practical consequence for US-facing manufacturers is that the eleven requirements in the table above are now the reference framework for an FDA inspection, not only for a Notified Body audit. Procedures written against the old 21 CFR 820.100 seven-point structure map onto the new framework imperfectly and should be reviewed rather than relabelled. For organisations pursuing MDSAP certification, CAPA requirements are assessed across all five participating regulatory authorities — Australia, Brazil, Canada, Japan and the United States — making a fully documented, evidence-based CAPA system even more critical.Common CAPA audit findings under ISO 13485

CAPA effectiveness verification — how to do it correctly
Effectiveness verification is the most frequently deficient element of CAPA management. Four principles define a robust approach. Define criteria before implementation. Effectiveness criteria belong in the action plan, not in a retrospective judgement. They should be measurable and specific: “zero recurrence of this nonconformity in the next 50 incoming inspection records” is measurable; “no further issues” is not. Allow sufficient observation time. For a nonconformity that occurred twice in a quarter, a two-week observation period is insufficient. The observation period should cover at least the same timeframe over which the original nonconformity was observed. Use objective evidence. Effectiveness cannot rest on subjective assessment. It must be based on data, records, inspection results, or complaint rates. Report results formally. The verification must be documented in the CAPA record with the evidence reviewed, the conclusion, and the name and date of the person who verified it.
✦ COMPLETE CATALOGUE
Find the documentation you need — instantly.
Whether you need a complete kit or just one specific SOP, the catalogue has it. 45 process packages and 3 complete bundles, all instantly downloadable and fully editable.
- ✓ Complete bundles or individual packages
- ✓ 45 process packages from €69 each
- ✓ ISO 13485 · MDSAP · Combined Kit