What this is
What is a corrective and preventive action?
What is a corrective and preventive action?
A corrective and preventive action, or CAPA, is the record of an action taken in response to a problem: what will be done, who owns it, when it is due, and the metric that will show whether it worked. It is generic by design, so that every workspace in the library can raise one from whatever surfaced the problem, whether that is an incident, a finding, an audit or a complaint.
What is the difference between correction, corrective action and preventive action?
A correction contains the immediate problem: stop the line, isolate the batch, fix the leak. A corrective action removes the cause so the same problem does not recur in the same place. A preventive action stops the same underlying cause producing a problem somewhere else it has not yet appeared. A single event commonly needs all three, recorded as separate action rows against the same case.
Who should verify that an action was effective?
Someone other than the action owner. Effectiveness verification checks the metric named at the point the action was raised, not whether the task was completed, and a verifier who is also the owner has an incentive to see what they expect to see rather than what happened.
Scope
When is a corrective and preventive action required?
This is the general-purpose action instrument, not a diagnostic. It records what will happen and whether it worked; it does not itself establish why the underlying problem occurred or what the problem was.
Use this template when
- An incident, finding, audit, assessment or complaint has produced a conclusion that requires something to change
- A root cause has already been identified elsewhere and now needs an owner, a due date and a way to verify it worked
- A correction has been made and the underlying cause still needs to be addressed so it does not recur
- An action from one workspace needs to be visible and trackable from every other workspace that references it
- An effectiveness check on a previously closed action needs a home, including one that is about to reopen
Do not use it for
- Root Cause Analysis, which determines why something happened; this record only holds what will be done about it
- Risk Assessment, which is the general hazard and risk instrument, not an action arising from one
- Finding, which records a single deficiency picked up during an audit or inspection before any action is decided
- Effectiveness Verification as its own event, which is a distinct record referenced from the Verification ID field rather than completed inside this one
- Documenting the parent event itself, which belongs in the incident, complaint or audit record this action was raised from
Compliance mapping
Which ISO 9001 cl.10.2 requirements does this satisfy?
ISO 9001 and ISO 45001 both set clause 10.2 out as a sequence: react and correct, evaluate whether the cause needs eliminating, implement the action, review whether it worked, and update the management system if it should be. The form's sections follow that sequence closely enough that each one maps to a specific sub-clause.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 9001 / 45001 cl.10.2.1(a) | React to the problem and, where applicable, take action to control and correct it | Action detail |
| ISO 9001 / 45001 cl.10.2.1(b) | Evaluate the need for action to eliminate the cause, so it does not recur or occur elsewhere | Action detail |
| ISO 9001 / 45001 cl.10.2.1(c) | Implement any action needed, with an owner and a target date | Ownership |
| ISO 9001 / 45001 cl.10.2.1(c) | Action carried out as planned, or the deviation from plan recorded | Implementation |
| ISO 9001 / 45001 cl.10.2.1(e)-(f) | Update risks and the management system where the action changes a process, document or control | Downstream triggers |
| ISO 9001 / 45001 cl.10.2.1(d) | Review the effectiveness of any corrective action taken | Effectiveness |
| ISO 9001 / 45001 cl.10.2.2 | Retain documented information as evidence of the nature of the nonconformity, the action taken, and its results | Closure |
What it does not cover
- Root Cause Analysis, which establishes why the problem occurred; this record assumes that answer already exists.
- Risk Assessment, which is the general hazard-and-control instrument this action might arise from, not the action itself.
- Finding, which captures a single audit or inspection deficiency prior to any action being decided.
- Effectiveness Verification, which is the formal check this record links to rather than performs, once one is required.
- Management of Change, which is the approval record for the process or equipment change this action may trigger, not a substitute for raising one.
Global
Corrective and Preventive Action requirements by country
CAPA as a term comes from quality and safety management systems rather than from statute, so what varies across borders is less the duty to act on a problem and more which certifiable standard defines the expected sequence.
OSH Act General Duty Clause; FDA 21 CFR 820.100 in regulated manufacturing
No general statutory CAPA requirement outside regulated sectors, but FDA-regulated manufacturers must maintain formal CAPA procedures.
Outside FDA-regulated industries, CAPA discipline is a management-system choice rather than a legal minimum, though an unaddressed recognised hazard still exposes an employer under the General Duty Clause.
Management of Health and Safety at Work Regulations 1999, reg.5
Duty to have arrangements in place for the effective planning, organisation, control, monitoring and review of preventive and protective measures.
Review of measures already taken is itself a legal requirement, which is close to an effectiveness check by another name.
ISO 9001 cl.10.2; ISO 45001 cl.10.2
Certifiable management-system requirement to react, evaluate the need for cause-eliminating action, implement it, and review whether it worked.
Certification audits examine the CAPA log directly, and a pattern of weak actions or unverified closures is one of the most common nonconformities auditors raise.
How to complete it
How to complete a corrective and preventive action, step by step
The fields that decide whether a CAPA record is defensible later are not the description of the work; they are the ones that show the action was proportionate to the problem and actually checked.
Action Description should be specific enough that someone who was not in the room could carry it out unchanged. "Improve training" is an intention; "add a lockout step to the changeover procedure and retrain the crew against it by the due date" is an action, and only the second can be verified as done or not done.
A serious finding closed with retraining or a reminder because that is what can be implemented before month end is the pattern investigators and auditors look for first. Where a weak action genuinely is the right call, the justification field is where that reasoning belongs, not left implicit.
Hierarchy Level should show elimination and substitution were considered and rejected for a reason before an administrative control or PPE is accepted. The reasoning, not the final category, is what makes an inspector or auditor treat the action as considered rather than convenient.
The verifier field exists because the owner cannot mark their own work effective. A not-effective result should reopen the action and trigger a fresh investigation, not sit as a comment; a closed action that failed its own check is worse than one left open.
What auditors find
Most common corrective and preventive action findings
CAPA findings concern the discipline around the record more often than the record itself: the action exists, but the strength, the owner, or the verification does not hold up.
| Finding | Clause | What fixes it |
|---|---|---|
| Serious finding closed with a weak action (retraining, reminder) and no justification recorded. | ISO 9001 / 45001 cl.10.2.1(b) | Require Strength Justification whenever Action Strength is weak against a finding above a set severity. |
| Action owner and effectiveness verifier are the same person. | ISO 9001 / 45001 cl.10.2.1(d) | Enforce that Verifier cannot equal Action Owner at the point the check is scheduled. |
| Effectiveness check not performed on a level 3 or 4 investigation action. | ISO 9001 / 45001 cl.10.2.1(d) | Make Effectiveness Check Required a hard gate on closure for any action tied to a high-severity investigation. |
| Downstream trigger checked (document change, MOC, critical control) but never actually raised. | ISO 9001 / 45001 cl.10.2.1(e)-(f) | Require the Related Document, MOC or Control ID before the action can close, once the trigger box is checked. |
| Action has no due date, or is overdue with no delay reason recorded. | ISO 9001 / 45001 cl.10.2.1(c) | Set Due Date at the point the action is raised, and require Delay Reason before Status can move past Overdue. |
| Action Description too vague to verify as complete: describes a goal, not a task. | ISO 9001 / 45001 cl.10.2.1(c) | Route vague descriptions back to the owner before the record is accepted; require a task someone else could execute. |
Case in point
Case in point: the CAPA log that always closed on time
A packaging line raised four CAPAs over a year for the same fault: intermittent seal failures on one lane. Each named a correction (rerun the affected pack), each rated Action Strength as retraining, and each closed on time with the owner's own signature standing in for a check. On-time-percent for the site looked excellent throughout.
The fifth occurrence reached a customer. The investigation found the seal head on that lane had been drifting out of tolerance for over a year, and every prior CAPA had retrained operators against a machine fault training could not fix. No action had ever been verified by someone other than the owner who raised it, so nobody had asked whether earlier actions worked, only whether they had been closed.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
7 sections
- Reference
- FDN-014
- Archetype
- Action
- Record ID
- CAPA-2026-000
- Scoring
- Strength 1 to 3, on time percent
- Direction
- Mixed
- Singleton
- Yes
- Basis
- ISO 9001 cl.10.2, ISO 45001 cl.10.2
- Links
- Linked from every workspace
- Tags
- Action
- Sections
- 7
- Fields
- 42
- Follow up fields
- 0
- Repeating sections
- 0
- Links out
- 7
Header
6 fieldsCAPA ID*
Format CAPA-2026-00000.
The record's own ID. Other templates point at this value.
Case ID
Carried from the parent event so the whole chain retrieves together.
Thread key
Parent Type*
Incident, finding, audit, assessment, complaint or review.
Parent ID*
Immediate predecessor record
Raised Date*
Raised By*
Action detail
7 fieldsAction Class*
Correction contains the immediate problem. Corrective action removes the cause. Preventive action stops it elsewhere.
Action Description*
What will actually be done. Be specific enough that someone else could do it.
Strength Guidance
Strong actions eliminate or engineer out the hazard. Weak actions rely on people remembering. A serious investigation cannot close on weak actions alone.
Action Strength*
Strong, medium or weak. This is the single most predictive field in the whole system.
- Eliminate or engineer4 pts
- Process change3 pts
- Supervision or verification2 pts
- Retraining1 pt
- Reminder or reissue0 pts
Strength Justification
Required where a weak action is proposed for a serious finding.
Hierarchy Level*
Which level of the hierarchy of controls this action sits at.
- Elimination5 pts
- Substitution4 pts
- Engineering3 pts
- Administrative2 pts
- PPE1 pt
Priority*
- High0 pts
- Medium1 pt
- Low3 pts
Ownership
8 fieldsAction Owner*
One named person, never a department.
Owner Person ID*
Links to FDN-003 Person ID
Site*
Site ID*
Links to FDN-001 Site ID
Related Asset
Asset ID
Links to FDN-002 Asset ID
Due Date*
Status*
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Implementation
6 fieldsWork Completed
What was actually done, which is sometimes different from what was planned.
Completion Evidence
Photo or document showing the action in place.
Actual Completion Date
Completed On Time
- Yes3 pts
- Late1 pt
- Not completed0 pts
Delay Reason
Owner Signature
Downstream triggers
6 fieldsTriggers Document Change
Opens a document revision and a retraining requirement.
Triggers MOC
Required where this action changes a process or asset.
Adds Critical Control
Adds the control to the register with a verification frequency.
Related Document ID
Links to FDN-008 Document ID
Related MOC ID
Links to FDN-020 MOC ID
Related Control ID
Links to FDN-011 Control ID
Effectiveness
6 fieldsEffectiveness Check Required*
Required for any action arising from a level 3 or 4 investigation.
Effectiveness Metric
How you will know it worked. A number, not an opinion.
Verification Due Date
Between 30 and 180 days after implementation.
Verifier
Cannot be the action owner.
Verification ID
Links to FDN-016 Verification ID
Effectiveness Result
If this fails, the action reopens and a fresh investigation is triggered.
- Effective2 pts
- Partially effective1 pt
- Not effective0 pts
Closure
3 fieldsClosure Approved By
Closure Date
Closure Signature
FDN-014 · record IDs look like CAPA-2026-000 · Linked from every workspace
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The record itself is simple. What slips is the routing across workspaces, the verifier who is quietly also the owner, and the downstream trigger that was checked but never actually raised.
Watches CAPAs raised from incidents and assessments, checks that action strength matches severity, and flags weak actions closing serious findings.
Tracks CAPAs raised from nonconformance and complaint records back to the batches and products they touched, and holds the case thread together.
Turns an administrative-control action into an actual competency requirement and training record, rather than a note that training happened.

Holds the CAPA log against due dates and verifiers, blocks a verifier who is also the owner, and surfaces downstream triggers checked but never raised.
This template lives in General — control tower. The orchestration layer. Registries and engines every other workspace reads from.
Meet General→Glossary
Corrective and Preventive Action definitions and key terms
- Correction
- The immediate action that contains a problem: stopping a line, isolating a batch, fixing a fault, without addressing why it happened.
- Corrective action
- An action that removes the cause of a problem so the same failure does not recur in the same place.
- Preventive action
- An action that addresses a cause before it produces a problem elsewhere, taken from a trend or a near miss rather than an event.
- Action strength
- A rating of how durable an action is, from eliminate-or-engineer at the top to reminder-or-reissue at the bottom, independent of how it is worded.
- Effectiveness verification
- An independent check, after enough time has passed, that the action actually produced the result it was meant to, rather than that the task was completed.
FAQ
Frequently asked questions about corrective and preventive action
Is CAPA one record type used everywhere, or a different form per workspace?+
One record type. Every workspace in the library, safety, quality, maintenance and the rest, raises the same CAPA record and links it back to whatever surfaced the problem. This is what lets a single view roll up completion and on-time percent across the whole business rather than per workspace.
Does every finding need a corrective action?+
No. A correction alone is enough where the cause is not expected to recur and is not systemic; ISO 9001 and ISO 45001 both frame corrective action as needed only where the cause warrants eliminating. Raising one for every trivial correction dilutes the log and slows review of the ones that matter.
Who decides whether an action counts as corrective or preventive?+
Whoever raises the case, based on whether a problem has already occurred at this location (corrective) or has not yet appeared but the same cause exists elsewhere (preventive). The distinction matters for reporting trend, not for the mechanics of the record itself.
What happens if the effectiveness check fails?+
The action should reopen, not simply record the failure. A failed effectiveness result is itself evidence that the original cause analysis or the action chosen was wrong, and the correct response is a fresh look at the cause rather than a second attempt at the same action.
Can a CAPA close without triggering the document or MOC change it flagged?+
It should not. A checked downstream trigger with no linked record behind it means the change the action depended on was never actually made, which leaves the process exactly as it was before the action was raised.
How long after implementation should effectiveness be checked?+
The field allows thirty to a hundred and eighty days; the right point depends on how long the failure mode takes to reappear. Checking too soon confirms implementation, not that it worked; checking too late lets a failed action run for months unnoticed.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Incident and Investigation
A single case thread from the event to a verified corrective action, with regulatory reporting handled.
Master Data and Foundations
One place for each thing, so a change updates everywhere rather than in eight lists.
Nonconformance and Complaints
Product decisions made by quality, and complaints traced to a cause rather than answered politely.
Used together in Incident and Investigation
Root Cause Analysis
Finds out why something happened rather than who was involved
Finding
Records a single deficiency picked up during an audit, inspection or check
Effectiveness Verification
Checks whether an action actually worked, some time after it was put in place
Just Culture Determination
Separates a system problem from a genuine choice to take a risk, using a consistent set of questions
Extent of Condition Review
Asks two questions after an investigation: where else does this same condition exist, and where else could this same cause bite us
Witness Statement
Captures what one person saw, heard or did, in their own words
More in Engines
Risk Assessment
The single risk assessment used across the whole business
Root Cause Analysis
Finds out why something happened rather than who was involved
Finding
Records a single deficiency picked up during an audit, inspection or check
Effectiveness Verification
Checks whether an action actually worked, some time after it was put in place
Just Culture Determination
Separates a system problem from a genuine choice to take a risk, using a consistent set of questions
Extent of Condition Review
Asks two questions after an investigation: where else does this same condition exist, and where else could this same cause bite us

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 9001:2015 clause 10.2, Nonconformity and corrective action
- ISO 45001:2018 clause 10.2, Incident, nonconformity and corrective action
- Management of Health and Safety at Work Regulations 1999, regulation 5 (GB)
- FDA 21 CFR 820.100, Corrective and preventive action (US, regulated manufacturing)
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.