CAPA process flowchart (corrective and preventive action)
A CAPA process flowchart in five swimlanes: log and grade the issue, contain it, investigate the root cause, correct and prevent, then verify before closure.
How it works
Rename the lanes to your real roles
Replace Originator, Quality, Process owner, Investigator and Management with the functions that exist in your organisation. Small sites usually merge Quality and Investigator into one lane; regulated manufacturers often split Quality into a CAPA coordinator and a QA approver. Keep the Originator lane even though it holds only two nodes, because it shows where the problem statement is written and how far it sits from the people who investigate it.
Write the criteria behind 'Full CAPA required?'
This decision needs objective triggers, not judgement: the risk grade from the previous step, whether the issue has recurred, whether safety or a regulatory requirement is involved, and whether it came from a complaint or an audit finding. Without written criteria this gate becomes a workload valve, and the correction-only branch quietly absorbs problems that needed an investigation.
Name the root cause method and the way out of the loop
State which methods are acceptable (5 Whys, fishbone, fault tree) and require the working to be attached to the record. Then decide what happens when 'Widen the investigation scope' has been through twice: most quality systems escalate to a cross-functional review or allow the cause to be documented as undetermined with a justification, rather than looping indefinitely.
Give the preventive action a defined scope
'Add preventive action for similar processes' is where most CAPAs go vague. Define what counts as similar: the same product family, the same equipment, the same procedure at another site, the same supplier. Record the processes that were checked and found not to be affected, because that is the evidence an auditor asks for.
Fix the effectiveness period and its measure at plan approval
Decide the check when the plan is approved, not when the check falls due. Set both a period (30, 60 or 90 days is typical) and a measure that can fail: no recurrence, three consecutive conforming batches, a re-audit of the affected step, or a complaint rate below a stated threshold. An effectiveness check with no failure condition is a formality.
Decide who approves closure and what the record must contain
The chart ends with Management approving and closing the CAPA. Confirm who holds that authority in your delegation schedule, and list what the closed record must carry: problem statement, risk grade, containment, root cause and method, actions taken, training and document updates, and the effectiveness result. If you run the map in QueryChart, the approval workflow and version history keep the current authorised version and its sign-off available as audit evidence.
Frequently asked questions
What are the steps in a CAPA process?
A complete CAPA runs: raise the issue and write a clear problem statement; log it in a register with a unique number and its source; assess scope and grade the risk; contain and correct the immediate problem; decide whether a full CAPA is warranted; assign an investigator and a due date; collect evidence and determine the root cause; plan corrective action and extend preventive action to similar processes; obtain approval for the plan and its resources; implement, update documents and retrain; verify effectiveness after an agreed period; and close with approval. The chart above adds the two branches that matter in practice, a root cause gate that widens the investigation instead of accepting a guess, and an effectiveness gate that reopens the investigation rather than closing the record.
What is the difference between a correction, a corrective action and a preventive action?
A correction fixes this occurrence: rework, replacement, quarantine, reissuing a document. A corrective action eliminates the cause so the same nonconformity does not recur. A preventive action addresses the cause of a potential nonconformity somewhere it has not happened yet. They are separate steps with separate owners, which is why this chart puts containment in the Process owner lane, the corrective plan in the same lane after root cause is established, and the preventive extension in the Quality lane. Recording a correction as if it were a corrective action is the most common CAPA finding, because the effectiveness check then measures the containment rather than the fix.
Does ISO 9001 still require preventive action?
Not as a separate clause. ISO 9001:2015 covers nonconformity and corrective action in clause 10.2 and handles prevention through clause 6.1, actions to address risks and opportunities. ISO 13485:2016 keeps both as distinct clauses, 8.5.2 for corrective action and 8.5.3 for preventive action, and the FDA's QMSR incorporates ISO 13485:2016 by reference, so device manufacturers work to the same two clauses. If your quality system serves either standard, keep the preventive branch in the flow: under ISO 9001 it is the practical expression of risk-based thinking, and under ISO 13485 it is a clause you will be audited against.
How do you verify that a CAPA was effective?
Verification needs a measure and a period, both agreed when the plan is approved. Typical measures are absence of recurrence over 30 to 90 days, a run of conforming batches or inspections, a re-audit of the affected process step, or a complaint or defect rate below a stated threshold. Sample size and period should scale with the risk grade set at assessment. If the check fails, the CAPA is reopened rather than closed with a note: in this chart the No branch on 'Actions effective?' returns to 'Determine the root cause', on the basis that an ineffective action usually means the cause was wrong rather than the implementation was.