Back to all articles
Compliance9 min read

The CAPA Process Explained: A Step-by-Step Guide for Life Sciences Teams

Corrective and Preventive Action (CAPA) is one of the most cited subsystems in FDA Form 483s. This guide walks through the eight stages of a defensible CAPA process under 21 CFR 820.100 and ISO 13485.

By IntelaSolve™ Editorial

IntelaSolve editorial cover: The CAPA Process Explained

Corrective and Preventive Action — CAPA — is the backbone of every life sciences quality system. It's also the single most cited subsystem in FDA Form 483 observations year after year. The reason is simple: regulators don't expect you to have zero problems. They expect you to find them, understand them, fix them, and prevent them from coming back, with documented evidence at every step.

This guide walks through the eight stages of a defensible CAPA process under 21 CFR 820.100 and ISO 13485 §8.5.2 / 8.5.3, and flags the places teams most often go wrong.

What CAPA actually is

CAPA is a structured, evidence-based process for addressing two related but distinct things:

  • Corrective action: action taken to eliminate the cause of a detected nonconformity so it doesn't happen again.
  • Preventive action: action taken to eliminate the cause of a potential nonconformity that has not yet occurred.

Note what CAPA is not: it is not a place to log every deviation, complaint, or out-of-spec result. Those have their own processes. CAPA is reserved for issues significant enough — either by severity, frequency, or trend — to warrant root cause analysis and systemic change.

The eight stages of a defensible CAPA

1. Identification

Every CAPA starts with a triggering signal. Common sources include complaints, internal audits, supplier nonconformities, deviations, out-of-spec results, management review findings, and trends from ongoing data analysis. The identification step captures what was observed, when, where, by whom, and the source record (e.g., complaint ID, audit finding ID).

2. Evaluation

Not every signal warrants a CAPA. The evaluation step assesses risk, impact on product or patient safety, regulatory implications, and whether the issue is isolated or systemic. The output is a documented decision: open a CAPA, route to another process (e.g., a single deviation), or close with justification. Skipping this step — opening a CAPA for every minor issue — is one of the fastest ways to drown a quality team.

3. Investigation and root cause analysis

This is where most CAPAs fail. The investigation must establish the actual root cause, not a symptom or a convenient explanation. Common tools include:

  • 5 Whys
  • Fishbone (Ishikawa) diagrams
  • Fault tree analysis
  • Failure mode and effects analysis (FMEA)

"Operator error" is almost never an acceptable root cause on its own. If an operator made a mistake, ask why the system allowed the mistake — inadequate training, ambiguous procedure, poor ergonomics, missing poka-yoke. Auditors will push on this exact point.

4. Action plan

Once the root cause is established, document the specific corrective and (where applicable) preventive actions, the owner of each, the due dates, and the resources required. The plan should also explicitly identify any related products, processes, or sites that may be affected — scoping a CAPA too narrowly is a common finding.

5. Implementation

Execute the plan and capture objective evidence: revised procedures with change control records, updated training records with competency assessments, validated equipment changes, supplier notifications, and so on. Every action item should link back to a controlled artifact.

6. Verification of effectiveness

This is the single most overlooked stage. Closing a CAPA without verifying that the action actually solved the problem is a guaranteed audit finding. Effectiveness checks should:

  • Define a measurable success criterion up front (e.g., "no recurrence over 90 days and 10 production lots")
  • Use objective data, not opinion
  • Be performed after enough time has passed for recurrence to be possible
  • Be documented with the evidence reviewed and the conclusion reached

7. Closure

Once effectiveness is verified, the CAPA can be formally closed by an authorized approver — typically QA, independent of the action owner. The closure record should reference all linked artifacts: investigation report, action evidence, effectiveness data, and any related change controls.

8. Management review and trending

Individual CAPAs solve individual problems. Management review and trending across all CAPAs is where systemic issues surface. ISO 13485 and 21 CFR 820 both require periodic analysis of CAPA data as a quality system input. If three CAPAs in a year all trace back to a single supplier or a single product family, that's a signal the system itself needs to change.

The most common FDA observations against CAPA

Year after year, the same patterns show up in 483s and Warning Letters:

  1. No documented CAPA procedure, or a procedure that doesn't match what the company actually does.
  2. Root cause not established — investigations stop at the symptom.
  3. Actions not implemented in a timely manner, with CAPAs open for months or years past their due date.
  4. No verification of effectiveness, or effectiveness checks that are checkbox-only.
  5. Failure to extend corrective action to other affected products, lots, or processes.
  6. No trend analysis across CAPAs, complaints, and nonconformities.

What good CAPA looks like in practice

A high-functioning CAPA system has a few defining characteristics:

  • A clear, documented decision rule for what becomes a CAPA versus a single deviation
  • Standard timelines for each stage with escalation when they slip
  • Independent QA ownership of investigation review and closure approval
  • Direct links between CAPAs and the records they originated from — complaints, audits, deviations
  • Direct links between CAPAs and the change controls, training records, and procedure revisions they produce
  • A dashboard of open CAPAs, aging, and trending available to management at any time

How a modern eQMS changes the equation

In paper or spreadsheet-based systems, the connections between a complaint, the CAPA it triggered, the procedure that got revised, and the training that followed live in three different binders and a shared drive. Reconstructing the chain for an auditor takes days, and the risk of a broken link is real.

A connected eQMS treats every CAPA as a node with explicit relationships to its source records, action artifacts, effectiveness data, and downstream changes. Aging, trending, and management review outputs are computed automatically. The result is less time preparing for audits and far less risk of a 483 observation built on broken traceability. See how IntelaSolve reimagines the eQMS as continuously monitored compliance.

Key takeaways

  • CAPA covers both corrective action (cause already happened) and preventive action (cause hasn't happened yet).
  • Not every issue is a CAPA — evaluate first.
  • Root cause analysis is the stage where most CAPAs fail; "operator error" is rarely the real cause.
  • Verification of effectiveness is non-negotiable and must be objective and time-bounded.
  • Trending across CAPAs is what turns isolated fixes into systemic improvement.
  • Connected systems make defensible CAPA dramatically easier than disconnected ones.

From the platform

Build audit-ready compliance without the spreadsheets.

IntelaSolve is the compliance infrastructure platform unifying regulatory, clinical, quality, and post-market operations for medical device and pharmaceutical teams.