CAPA process flowchart (corrective and preventive action)

A CAPA process flowchart in five swimlanes: log and grade the issue, contain it, investigate the root cause, correct and prevent, then verify before closure.

Use this template

What the capa process flowchart (corrective and preventive action) process is

CAPA stands for corrective and preventive action. It is the part of a quality system that turns a single problem into a permanent fix, and it has three distinct parts that are routinely collapsed into one. A correction deals with the occurrence in front of you: quarantine the batch, reissue the document, redo the service. A corrective action removes the cause so the same failure does not return. A preventive action applies that finding to processes and products that have not failed yet.

The chart below runs across five lanes and five phases. The Originator raises the issue and writes the problem statement. Quality logs it in the register, grades the risk, decides whether a full CAPA is warranted, extends the action to similar processes and later verifies effectiveness. The Process owner contains the immediate problem, drafts the corrective action plan and implements it. The Investigator collects evidence and determines the root cause. Management approves the plan and the resources behind it, and signs the closure.

Two loops carry most of the value. 'Root cause identified?' sends the investigation back to widen its scope rather than letting a plausible-sounding cause through, and 'Actions effective?' reopens the investigation when the problem recurs after the verification period. Strip those out and the process becomes a straight line from issue to closure, which is where audit findings against ISO 9001 clause 10.2 and ISO 13485 clauses 8.5.2 and 8.5.3 tend to come from.

What this flowchart covers

In this template

  • Intake across the Originator and Quality lanes: the issue or nonconformity is raised, the originator describes the problem and the evidence, and Quality logs the CAPA in the register.
  • Initial assessment and risk grading by Quality, with immediate containment and correction handled by the Process owner before any investigation begins, so the two are recorded as separate actions.
  • A 'Full CAPA required?' decision that ends low-risk items at 'Close as correction only', keeping the register for issues that genuinely need an investigation.
  • Root cause work in the Investigator lane: collect evidence and process data, determine the root cause, then a 'Root cause identified?' decision whose No branch widens the investigation scope and re-examines rather than proceeding on a guess.
  • Corrective action drafted by the Process owner, preventive action extended to similar processes by Quality, and a Management decision on the plan and the resources it needs, with a Revise branch back to the plan.
  • Implementation, document updates and retraining, effectiveness verification after an agreed period, and an 'Actions effective?' decision that reopens the root cause step if the problem recurs, before Management approves and closes the CAPA.

When to use this template

  • You are writing or revising a CAPA procedure for ISO 9001, ISO 13485 or a customer or notified-body audit, and want the routing and handoffs agreed before anyone drafts the prose.
  • CAPAs are raised for everything or for almost nothing, because there is no written test for when a correction is sufficient and when a full investigation is required.
  • Investigations stall or close on 'operator error' and you need the root cause gate to be an explicit step with a named owner and a defined way out.
  • Corrective actions are marked complete without anyone checking, after a defined period, whether the problem actually stopped.
  • An auditor has asked you to show the CAPA process as it is genuinely run, including who investigates, who approves the plan and who authorises closure.

How it works

  1. Rename the lanes to your real roles

    Replace Originator, Quality, Process owner, Investigator and Management with the functions that exist in your organisation. Small sites usually merge Quality and Investigator into one lane; regulated manufacturers often split Quality into a CAPA coordinator and a QA approver. Keep the Originator lane even though it holds only two nodes, because it shows where the problem statement is written and how far it sits from the people who investigate it.

  2. Write the criteria behind 'Full CAPA required?'

    This decision needs objective triggers, not judgement: the risk grade from the previous step, whether the issue has recurred, whether safety or a regulatory requirement is involved, and whether it came from a complaint or an audit finding. Without written criteria this gate becomes a workload valve, and the correction-only branch quietly absorbs problems that needed an investigation.

  3. Name the root cause method and the way out of the loop

    State which methods are acceptable (5 Whys, fishbone, fault tree) and require the working to be attached to the record. Then decide what happens when 'Widen the investigation scope' has been through twice: most quality systems escalate to a cross-functional review or allow the cause to be documented as undetermined with a justification, rather than looping indefinitely.

  4. Give the preventive action a defined scope

    'Add preventive action for similar processes' is where most CAPAs go vague. Define what counts as similar: the same product family, the same equipment, the same procedure at another site, the same supplier. Record the processes that were checked and found not to be affected, because that is the evidence an auditor asks for.

  5. Fix the effectiveness period and its measure at plan approval

    Decide the check when the plan is approved, not when the check falls due. Set both a period (30, 60 or 90 days is typical) and a measure that can fail: no recurrence, three consecutive conforming batches, a re-audit of the affected step, or a complaint rate below a stated threshold. An effectiveness check with no failure condition is a formality.

  6. Decide who approves closure and what the record must contain

    The chart ends with Management approving and closing the CAPA. Confirm who holds that authority in your delegation schedule, and list what the closed record must carry: problem statement, risk grade, containment, root cause and method, actions taken, training and document updates, and the effectiveness result. If you run the map in QueryChart, the approval workflow and version history keep the current authorised version and its sign-off available as audit evidence.

Frequently asked questions

What are the steps in a CAPA process?

A complete CAPA runs: raise the issue and write a clear problem statement; log it in a register with a unique number and its source; assess scope and grade the risk; contain and correct the immediate problem; decide whether a full CAPA is warranted; assign an investigator and a due date; collect evidence and determine the root cause; plan corrective action and extend preventive action to similar processes; obtain approval for the plan and its resources; implement, update documents and retrain; verify effectiveness after an agreed period; and close with approval. The chart above adds the two branches that matter in practice, a root cause gate that widens the investigation instead of accepting a guess, and an effectiveness gate that reopens the investigation rather than closing the record.

What is the difference between a correction, a corrective action and a preventive action?

A correction fixes this occurrence: rework, replacement, quarantine, reissuing a document. A corrective action eliminates the cause so the same nonconformity does not recur. A preventive action addresses the cause of a potential nonconformity somewhere it has not happened yet. They are separate steps with separate owners, which is why this chart puts containment in the Process owner lane, the corrective plan in the same lane after root cause is established, and the preventive extension in the Quality lane. Recording a correction as if it were a corrective action is the most common CAPA finding, because the effectiveness check then measures the containment rather than the fix.

Does ISO 9001 still require preventive action?

Not as a separate clause. ISO 9001:2015 covers nonconformity and corrective action in clause 10.2 and handles prevention through clause 6.1, actions to address risks and opportunities. ISO 13485:2016 keeps both as distinct clauses, 8.5.2 for corrective action and 8.5.3 for preventive action, and the FDA's QMSR incorporates ISO 13485:2016 by reference, so device manufacturers work to the same two clauses. If your quality system serves either standard, keep the preventive branch in the flow: under ISO 9001 it is the practical expression of risk-based thinking, and under ISO 13485 it is a clause you will be audited against.

How do you verify that a CAPA was effective?

Verification needs a measure and a period, both agreed when the plan is approved. Typical measures are absence of recurrence over 30 to 90 days, a run of conforming batches or inspections, a re-audit of the affected process step, or a complaint or defect rate below a stated threshold. Sample size and period should scale with the risk grade set at assessment. If the check fails, the CAPA is reopened rather than closed with a note: in this chart the No branch on 'Actions effective?' returns to 'Determine the root cause', on the basis that an ineffective action usually means the cause was wrong rather than the implementation was.

Use this template

Guides that use this template

Part of these packages

  • ISO 9001 QMS process templates (6 linked flowcharts) — Six linked flowcharts for an ISO 9001 quality management system: CAPA, customer complaints, internal audit, root cause analysis, change control and document control, connected as the cycle they actually form.

More in Quality management process templates

More in Process flowchart templates

Browse all Quality management process templates