ISO 13485 CAPA: Clause 8.5.2 and 8.5.3 Requirements, Process and Audit Findings

Table of Contents

Introduction

The ISO 13485 CAPA procedure — covering corrective and preventive action — is consistently one of the most scrutinised elements of a medical device quality management system. In every Notified Body audit, every FDA inspection, and every MDSAP assessment, CAPA is examined in depth. And for good reason: a CAPA system that works is the clearest possible signal that an organisation understands its own quality problems, fixes them at the root, and prevents them from recurring. A CAPA system that exists only on paper is, in regulatory terms, almost worse than no system at all. From the regulatory point of view, the importance of CAPA cannot be understated. Device manufacturers are always evaluated on their CAPA processes during FDA inspections. The top reason for device manufacturers to receive FDA observations is CAPA and its related processes — and manufacturers also receive CAPA-related warning letters, mostly about quality system aspects concerned with CAPA. This guide covers everything you need to build, operate, and document a compliant ISO 13485 CAPA procedure — starting with the eleven requirements the standard actually imposes on your documented procedure, then the step-by-step process, root cause analysis methods, effectiveness verification, and the most common audit findings. If you are new to ISO 13485 and its quality management system requirements, we recommend reading our complete ISO 13485 guide first as the foundation for everything covered here.

CAPA under ISO 13485: what clauses 8.5.2 and 8.5.3 require

ISO 13485:2016 addresses CAPA in two separate clauses within Section 8.5 (Improvement). Clause 8.5.2 — Corrective action deals with nonconformities that have already occurred. The organisation must act to eliminate their causes and prevent recurrence, without undue delay, with actions proportionate to the effects of the nonconformity encountered. Clause 8.5.3 — Preventive action deals with potential nonconformities that have not yet occurred but have been identified as credible. The organisation must determine action to eliminate their causes and prevent them from occurring, proportionate to the effects of the potential problem. Both clauses require a documented procedure, and each specifies exactly what that procedure must define — six requirements for corrective action, five for preventive action. The table below sets out all eleven, what each one demands in practice, the record that satisfies it, and the finding raised when it is missing.

The eleven documented requirements, side by side

Ref. What the procedure must define What it means in practice Record that satisfies it Typical finding
Clause 8.5.2 — Corrective action (six requirements)
aReview of nonconformities, complaints includedA defined intake and screening step covering every quality data source, not only complaintsCAPA intake log; review board minutesComplaints reviewed but nonconformances, audit findings and supplier data screened informally or not at all
bDetermination of the causesA structured root cause method applied and documented, not a restatement of the problemRoot cause analysis record with method, evidence and conclusion“Operator error” or “human factor” recorded as the root cause
cEvaluation of the need for actionA documented decision on whether action is required — including when the answer is noCAPA decision record with rationaleOnly opened CAPAs are documented; rejected candidates leave no trace
dPlanning, documenting and implementing the action, updating documentation as appropriateNamed owners, target dates, and the document control chain that follows from the actionAction plan; revised SOPs; training recordsProcedure changed but training not evidenced, or vice versa
eVerification that the action does not adversely affect regulatory compliance or device safety and performanceA documented impact assessment before the action is deployedChange impact assessment; updated risk management fileThe requirement is not addressed at all — the most commonly omitted of the six
fReview of the effectiveness of the action takenCriteria defined in advance, an observation period, and objective evidenceEffectiveness verification recordCAPA closed on implementation, with effectiveness never assessed
Clause 8.5.3 — Preventive action (five requirements)
aDetermination of potential nonconformities and their causesSystematic analysis of trends and risk outputs — the intake step has no equivalent to 8.5.2(a)Trend analysis records; risk review outputsNo mechanism exists at all; preventive action is the most under-implemented element of Section 8.5
bEvaluation of the need for action to prevent occurrenceA documented decision, mirroring 8.5.2(c) but forward-lookingPreventive action decision recordPreventive actions raised only as a formality alongside corrective ones
cPlanning, documenting and implementing the action, updating documentation as appropriateIdentical in substance to 8.5.2(d)Action plan; revised documentationActions defined without owners or dates because the trigger was not an incident
dVerification that the action does not adversely affect regulatory compliance or device safety and performanceIdentical in substance to 8.5.2(e) — note the letter shifts from (e) to (d)Change impact assessmentCross-reference to the wrong sub-clause in the procedure
eReview of the effectiveness of the action taken, as appropriateSame as 8.5.2(f), but the standard qualifies it with “as appropriate” — the qualifier must be justified, not assumedEffectiveness verification record, or a documented rationale for why one is not warrantedThe qualifier used as a blanket exemption from effectiveness verification

Records are mandatory for both clauses. ISO 13485 requires that the results of any investigation and of the action taken be retained as records, controlled under Clause 4.2.5. An investigation that reached the right conclusion but left no record is, for audit purposes, an investigation that did not happen.

The four differences between the two clauses

Manufacturers routinely copy the corrective action procedure, change the title, and call it the preventive action procedure. Four differences make that a finding: 1. There is no preventive equivalent of 8.5.2(a). Corrective action starts from a review of nonconformities that already exist. Preventive action has no such input — it must be fed by trend analysis, risk management output, and process review, which means the procedure has to define where that data comes from and who looks at it. 2. The sub-lettering shifts. The impact verification requirement is (e) under corrective action and (d) under preventive action. Procedures that cross-reference the wrong letter are common and easy for a reviewer to spot. 3. Effectiveness review is qualified only in 8.5.3. Under 8.5.2(f) the review of effectiveness is unconditional. Under 8.5.3(e) it is required “as appropriate” — which is a decision the manufacturer must document, not an exemption. 4. The proportionality anchor differs. Corrective actions are proportionate to the effects of the nonconformities encountered; preventive actions to the effects of the potential problems. The second is an estimate, and the basis for that estimate has to be recorded.

✦ PREMIUM BUNDLE · ISO 13485 + MDSAP

The ultimate global QMS documentation bundle.

Combine ISO 13485 and all 5 MDSAP markets in one premium package. A deduplicated structure means you customise each document once, not twice.

  • 41 SOPs covering both ISO 13485 and MDSAP
  • 70+ templates with deduplicated structure
  • Save €199 vs buying separately

FROM

€699

Get the Combined Kit →

Correction, corrective action, preventive action

One of the most persistent sources of confusion in CAPA management is the distinction between three related but distinct concepts. Conflating them is the origin of a large share of CAPA findings.
Concept What it addresses When it applies Example
CorrectionThe specific instance — the symptom, not the causeImmediately, on discoveryQuarantining the affected batch; correcting the erroneous record
Corrective actionThe root cause of a nonconformity that has occurredAfter root cause analysisRewriting the ambiguous work instruction and adding independent verification
Preventive actionThe cause of a nonconformity that has not occurred yetOn trend, risk or process analysisAdding a poka-yoke to a process where a comparable line has failed
It is misleading to speak of a single “CAPA process”. Statements such as “the CAPA process begins with identifying the problem” reveal an inadequate understanding: manufacturers generally need several processes to meet regulatory requirements, and combining corrective and preventive action into one undifferentiated workflow is just as imprecise as failing to distinguish corrections from corrective actions. In practice, most organisations implement a unified CAPA management system that handles both through a common workflow — but with clearly differentiated triggers, investigation approaches, and documentation requirements for each type. That is acceptable, provided the procedure makes the differentiation explicit.

CAPA triggers — when to open a CAPA

Not every quality event requires a CAPA. A proportionate, risk-based approach means applying CAPA to events of significance — where the underlying cause is systemic, where recurrence would pose a risk to product safety or regulatory compliance, or where the potential impact is significant. Events that typically trigger corrective action:
  • Internal audit nonconformities — for how audit findings feed into CAPA, see our ISO 13485 internal audit checklist guide
  • Customer complaints indicating potential product safety or performance issues
  • Nonconforming product findings during inspection or testing
  • Process deviations with potential patient safety implications
  • Adverse events or vigilance reports
  • Supplier nonconformities with patient safety implications
  • Regulatory inspection findings — including MDSAP audit findings
Events that typically trigger preventive action:
  • Adverse trends identified in quality data — complaint rates, rejection rates, audit finding patterns
  • Risk assessment outputs identifying high-probability failure modes, connected to the ISO 14971 risk management process
  • Industry-wide safety signals or regulatory guidance updates
  • Management review outputs identifying systemic vulnerabilities
  • Process hazard analyses identifying potential failure points
The decision must be documented either way, with its rationale — both when a CAPA is opened and when a quality event is assessed and determined not to require one. Clause 8.5.2(c) requires the evaluation of the need for action, not merely the record of the actions taken.
ISO 13485 CAPA process flowchart from trigger event through containment, root cause analysis, action planning and effectiveness verification to closure
Figure 1 — The ISO 13485 CAPA process from trigger to closure

The ISO 13485 CAPA process — step by step

Step 1 — Problem identification and CAPA initiation

The process begins with the identification of a trigger event and the formal opening of a CAPA record. The record must capture at minimum: the source of the trigger, the date of identification, the initial description of the problem, the person responsible for the investigation, and the assigned priority based on initial risk assessment. Priority assignment matters — it determines how quickly the investigation must be completed and how quickly actions must be implemented. A CAPA triggered by a potential patient safety issue requires faster response than one triggered by an administrative nonconformity.

Step 2 — Immediate containment

Before investigating the root cause, the immediate impact of the nonconformity must be contained. This may involve segregating and quarantining nonconforming product, suspending a process, notifying customers or regulatory authorities, or issuing a field safety corrective action. Containment is a correction — it addresses the specific instance of the problem. It must be documented and linked to the CAPA record, but it does not replace the corrective action that addresses the root cause.

Step 3 — Problem description

A precise problem description is the foundation of an effective root cause investigation. It must answer five questions: what is the problem, where was it observed, when was it first identified, how often does it occur, and what is its potential impact on product safety, patient safety, or regulatory compliance. A vague problem description — “supplier performance issue” — produces a vague investigation. A precise description — “28% of incoming inspection records for Component X from Supplier Y were missing the required signature in Field 4 during Q3 2025” — enables targeted root cause analysis.

Step 4 — Root cause analysis

Root cause analysis is the most critical and most frequently deficient step in CAPA management. If a CAPA skips root cause analysis or effectiveness checks, it becomes little more than a to-do list of corrections rather than a true improvement engine. The root cause is the fundamental systemic reason why the problem occurred. “Operator error” is a symptom. “The work instruction was ambiguous and there was no independent verification required” is a root cause. Root cause analysis should always involve a cross-functional team — a single investigator will be limited by their own experience and perspective.

Step 5 — Action planning

The action plan defines the specific actions to be implemented, the owner responsible for each, the target completion date, the expected outcome, and — critically — the effectiveness verification criteria. These criteria must be defined before implementation, not retrospectively. Actions must target the root cause. A corrective action that retrains the operator without fixing the procedure that created the conditions for error will fail the effectiveness check — and generate the same finding in the next audit.

Step 6 — Implementation

All actions must be implemented within the defined timelines. All changes must go through document control: updated procedures require formal revision, and training on changes must be documented with evidence of completion and evaluation. Before deployment, the action must be assessed for its impact on regulatory compliance and on the safety and performance of the device — this is the requirement in Clause 8.5.2(e), and its counterpart 8.5.3(d). This step connects directly to the wider change control obligations of ISO 13485: changes to manufacturing processes or device design triggered by a CAPA must be evaluated against their full impact on the quality management system, and where the change affects risk, the risk management file must be updated.

Step 7 — Effectiveness verification

Effectiveness verification is the evidence-based confirmation that the action eliminated the root cause and the problem has not recurred. It requires a review after a defined time or number of cycles, against criteria set in advance, using objective evidence. If verification reveals the problem has recurred or the action was insufficient, the CAPA is reopened and the root cause analysis revisited. This is not a failure — it is the system working as designed.

Step 8 — CAPA closure and management review

A CAPA can be closed only when all actions have been completed, all documentation is updated, training has been conducted and documented, and effectiveness verification confirms resolution. CAPA trends must be reported at management review, giving top management visibility into systemic quality challenges.

✦ AUDIT-READY KIT · ISO 13485

Build your ISO 13485 QMS with confidence.

Built on 15+ years of audit experience — every SOP and template references the regulations auditors expect. Get to certification faster, with industry best practices baked in.

  • ✓ 30 SOPs covering the full QMS scope
  • ✓ 56 templates ready to customise
  • ✓ Aligned with EU MDR + FDA QMSR

From €499

Get the ISO 13485 Kit →

Root cause analysis methods for medical device CAPA

No method is mandated. The choice should follow the shape of the problem, and the rationale for the choice belongs in the CAPA record.
Method How it works Best suited to Limitation
5 WhysRepeated questioning until a systemic cause is reachedLinear, single-cause problems; the right starting point for most CAPAsFollows one chain; misses interacting causes
Fishbone (Ishikawa)Contributing factors sorted into Man, Machine, Method, Material, Measurement, EnvironmentProblems with several contributing factors; cross-functional workshopsGenerates candidates, does not rank them
FMEAFailure modes scored on severity, occurrence and detectability, then prioritisedPreventive action and process planningProactive by design; awkward as a retrospective tool
Fault Tree AnalysisTop-down Boolean modelling from the failure event to its causesCritical CAPAs where several causes must combineTime-consuming; needs system knowledge
A combined approach is often best: 5 Whys to reach the immediate causes, a fishbone diagram to categorise contributing factors, and fault tree analysis to map complex interactions. FMEA is also central to risk management under ISO 14971 — our ISO 14971 guide covers how failure modes feed into the wider risk management process.
Root cause analysis methods for medical device CAPA compared: 5 Whys, fishbone diagram, FMEA and fault tree analysis
Figure 2 — Root cause analysis methods compared

CAPA documentation requirements

ISO 13485 requires records to be maintained for all CAPA activities. A complete CAPA record must contain: Problem description — the precise description of the nonconformity including source, date, frequency, scope, and initial risk assessment. Immediate correction — what was done to address the specific instance of the problem. Root cause analysis — the method used, the investigation process, the evidence reviewed, and the identified root cause. Action plan — every action defined, with owner, target date, expected outcome, and effectiveness criteria. Impact assessment — the evaluation showing the action does not compromise regulatory compliance or device safety and performance. Implementation evidence — documents, training records, validation data, or other objective evidence that actions were completed as planned. Effectiveness verification — the criteria defined, the observation period, the data collected, and the conclusion. Closure decision — who closed the CAPA, on what date, and based on what evidence. Management review linkage — reference to the management review where CAPA status was reported. For medical device software manufacturers, CAPA records related to software anomalies must also align with the anomaly resolution requirements of IEC 62304, which defines how software problems discovered in post-production must be evaluated, tracked, and resolved within the QMS framework.

CAPA and QMSR — what changed in February 2026

The FDA Quality Management System Regulation (QMSR), effective 2 February 2026, incorporates ISO 13485:2016 by reference into 21 CFR Part 820. Under the previous QSR, CAPA was a single combined system that did not separate corrective from preventive action in law. Under QMSR and ISO 13485, manufacturers maintain documented processes for corrective action under Clause 8.5.2 and preventive action under Clause 8.5.3, each with its own triggers and documentation requirements. The practical consequence for US-facing manufacturers is that the eleven requirements in the table above are now the reference framework for an FDA inspection, not only for a Notified Body audit. Procedures written against the old 21 CFR 820.100 seven-point structure map onto the new framework imperfectly and should be reviewed rather than relabelled. For organisations pursuing MDSAP certification, CAPA requirements are assessed across all five participating regulatory authorities — Australia, Brazil, Canada, Japan and the United States — making a fully documented, evidence-based CAPA system even more critical.

Common CAPA audit findings under ISO 13485

Most common ISO 13485 CAPA audit findings including symptom-level root cause, missing effectiveness verification, excessive CAPA ageing and no preventive action system
Figure 3 — Most common CAPA audit findings under ISO 13485
Symptom-level root cause is the single most common CAPA finding in FDA inspections. Inspectors routinely ask how the organisation ensures that a CAPA addresses the root cause rather than the symptom — and the answer lies in the consistent application of structured root cause analysis tools, evidenced in the record. No effectiveness verification — CAPAs are closed once actions are implemented, without subsequent monitoring to confirm the problem did not recur. This is one of the clearest indicators of a CAPA system managed for compliance rather than improvement, and it is a direct failure of Clause 8.5.2(f). Inadequate timelines — CAPAs remain open for excessive periods with no documented progress or justification for delays. ISO 13485 requires corrective actions to be taken without undue delay, and Notified Bodies apply significant scrutiny to CAPA ageing reports during surveillance audits. This is also one of the most visible findings during the ISO 13485 internal audit process. Actions addressing symptoms rather than root causes — retraining the operator without fixing the underlying procedure. If the same training has been applied as a corrective action for the same type of error across multiple CAPAs, that pattern itself signals that root causes have never been properly identified. No impact assessment — the requirement in Clause 8.5.2(e) is the most frequently omitted of the six, because it is the least intuitive. The corrective action is deployed without any documented evaluation of whether it compromises regulatory compliance or device safety and performance. Incomplete CAPA records — missing root cause analysis documentation, absent implementation evidence, or no formal closure record. Under FDA QMSR, CAPA records are subject to FDA inspection. No preventive action system — quality data is collected but never systematically analysed to identify potential nonconformities and trigger preventive action. Clause 8.5.3(a) has no equivalent intake step to fall back on, so where the analysis does not exist, the clause is simply unimplemented. Preventive action is consistently the most underused element of Section 8.5.

CAPA effectiveness verification — how to do it correctly

Effectiveness verification is the most frequently deficient element of CAPA management. Four principles define a robust approach. Define criteria before implementation. Effectiveness criteria belong in the action plan, not in a retrospective judgement. They should be measurable and specific: “zero recurrence of this nonconformity in the next 50 incoming inspection records” is measurable; “no further issues” is not. Allow sufficient observation time. For a nonconformity that occurred twice in a quarter, a two-week observation period is insufficient. The observation period should cover at least the same timeframe over which the original nonconformity was observed. Use objective evidence. Effectiveness cannot rest on subjective assessment. It must be based on data, records, inspection results, or complaint rates. Report results formally. The verification must be documented in the CAPA record with the evidence reviewed, the conclusion, and the name and date of the person who verified it.
Mandatory elements of an ISO 13485 CAPA record from problem description and root cause analysis through effectiveness verification to closure
Figure 4 — Mandatory elements of a CAPA record
All CAPA records must be retained for a minimum period defined in your document control procedure — typically the lifetime of the product plus the applicable regulatory retention period, with a general minimum of five years for most ISO 13485-certified organisations. For manufacturers of medical device software, CAPA records triggered by software anomalies must be cross-referenced with the anomaly resolution process defined under IEC 62304. The software anomaly list — also a key component of SOUP management for third-party components — feeds directly into the CAPA system when anomalies cross the threshold of regulatory significance.

✦ COMPLETE CATALOGUE

Find the documentation you need — instantly.

Whether you need a complete kit or just one specific SOP, the catalogue has it. 45 process packages and 3 complete bundles, all instantly downloadable and fully editable.

  • Complete bundles or individual packages
  • 45 process packages from €69 each
  • ISO 13485 · MDSAP · Combined Kit
Browse All Kits →

Frequently asked questions

What does ISO 13485 require for CAPA? ISO 13485:2016 requires a documented procedure covering six defined requirements for corrective action under Clause 8.5.2 and five for preventive action under Clause 8.5.3 — from the review of nonconformities and determination of causes through to the review of effectiveness. Records of every investigation and of the action taken must be retained under Clause 4.2.5. The full breakdown of all eleven requirements is in the table above. What is the difference between clause 8.5.2 and 8.5.3? Clause 8.5.2 covers corrective action — nonconformities that have already occurred — and lists six requirements. Clause 8.5.3 covers preventive action — potential nonconformities — and lists five. There is no preventive equivalent of the intake step at 8.5.2(a); the impact verification requirement moves from (e) to (d); and the review of effectiveness is unconditional under 8.5.2(f) but qualified as “as appropriate” under 8.5.3(e). What is the difference between a correction and a corrective action? A correction addresses the specific instance of a nonconformity — fixing the defective product, correcting the erroneous record. A corrective action addresses the root cause to prevent recurrence. Both may be required for the same event but are distinct activities with different objectives, and must be separately documented in the CAPA record. How long should a CAPA remain open? ISO 13485 requires corrective actions to be taken without undue delay. There is no prescribed maximum duration, but most organisations define target timelines in their CAPA procedure — typically 30 to 90 days, with shorter timelines for patient safety-related findings. Extended timelines must be formally justified and approved. Is a CAPA required for every nonconformity? No. A proportionate, risk-based approach is appropriate. Minor, isolated nonconformities with no safety implications may be addressed through immediate correction without a formal CAPA. However, the decision not to open a CAPA must be documented and justified — that is what Clause 8.5.2(c) requires. If the same nonconformity recurs, a CAPA is required regardless of severity, and recurring findings that were never escalated will themselves become a finding in the next internal audit. How does CAPA connect to EU MDR post-market surveillance? EU MDR requires that post-market surveillance data feeds back into the risk management file and — where significant signals are identified — into the CAPA system. A PSUR identifying an adverse trend in complaint data or post-market performance should trigger a CAPA investigation. This integration between post-market surveillance and CAPA is one of the most closely examined connections in Notified Body surveillance audits, and connects directly to the benefit-risk analysis that must be maintained continuously throughout the device lifecycle. Can preventive actions be triggered by data that is not negative? Yes — and this is a sign of a mature QMS. Preventive actions can be triggered by risk assessments, regulatory guidance updates, process changes that introduce new failure modes, or management review decisions. Preventive action is not only a response to adverse trends; it is also a proactive management tool, and one of the most underused elements of most QMS implementations.

Conclusions

The ISO 13485 CAPA procedure is not a compliance checkbox — it is the engine of quality improvement in a medical device organisation. When it functions correctly, it identifies systemic problems early, addresses their root causes permanently, and prevents the recurrence of quality events that could harm patients or damage the organisation’s regulatory standing. When it functions poorly — closing CAPAs on time without verifying effectiveness, identifying symptoms rather than causes, treating preventive action as an afterthought — it creates the illusion of quality management without the substance. The eleven requirements of Clauses 8.5.2 and 8.5.3 are the measure a reviewer will apply, and since February 2026 they are the measure an FDA investigator will apply too. A procedure that addresses ten of them is a procedure with a finding waiting in it. The organisations that consistently achieve clean audit outcomes on CAPA are not those with the most elaborate software or procedures. They are the ones that invest real time and cross-functional expertise in root cause analysis, that define meaningful effectiveness criteria before implementing actions, and that use CAPA data actively to inform management review and quality strategy. If you are building or upgrading your CAPA system, the right starting point is a well-structured, role-specific documented procedure that your quality team can actually follow. The ISO 13485 CAPA SOP package available on MD Regulatory includes a complete corrective action procedure (Clause 8.5.2), a preventive action procedure (Clause 8.5.3), a CAPA initiation and investigation form, an effectiveness verification record, and a CAPA trend analysis template — all written to current Notified Body expectations and immediately deployable in your QMS. Related articles