Knowella

Corrective and Preventive Action

A corrective and preventive action record captures what will be done, who owns it, when it is due, and how anyone will know afterwards that it worked. It is raised from an incident, a finding, an audit, an assessment or a complaint, and it is the one action record every workspace in the library writes to rather than each maintaining its own. Its recurring failure is not the paperwork: it is a weak action, usually retraining or a reminder, closing a finding serious enough to need something eliminated or engineered out.

EllaGeneralActionFDN-01442 fields across 7 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 9001 cl.10.2, ISO 45001 cl.10.2
Workspace
General
Form type
Action
Raised from
Any incident, finding, audit, assessment or complaint
Closed by
An independent verifier, never the action owner

The short version

  • This is the generic action record used across the whole library. Action Strength, not the description of the work, is the single most predictive field in it: an eliminate-or-engineer action behaves differently to a reminder, regardless of how the action is worded.
  • Correction, corrective action and preventive action are distinct action classes on the same case, not synonyms for the same field. Conflating them produces a record that looks closed while the cause is still live.
  • Hierarchy Level should trace toward elimination, substitution or engineering before administrative controls or PPE are accepted, and a weak action against a serious finding needs its justification recorded, not just its category.
  • An effectiveness check is required for anything arising from a level 3 or 4 investigation, the verifier cannot be the action owner, and a result of not effective reopens the action and triggers a fresh investigation rather than a note in the file.
  • Downstream triggers, a document revision, a management-of-change record or a new critical control, are what make a closure durable. A CAPA closed without exercising the trigger it flagged reverts silently the next time the process runs.

What this is

What is a corrective and preventive action?

What is a corrective and preventive action?

A corrective and preventive action, or CAPA, is the record of an action taken in response to a problem: what will be done, who owns it, when it is due, and the metric that will show whether it worked. It is generic by design, so that every workspace in the library can raise one from whatever surfaced the problem, whether that is an incident, a finding, an audit or a complaint.

What is the difference between correction, corrective action and preventive action?

A correction contains the immediate problem: stop the line, isolate the batch, fix the leak. A corrective action removes the cause so the same problem does not recur in the same place. A preventive action stops the same underlying cause producing a problem somewhere else it has not yet appeared. A single event commonly needs all three, recorded as separate action rows against the same case.

Who should verify that an action was effective?

Someone other than the action owner. Effectiveness verification checks the metric named at the point the action was raised, not whether the task was completed, and a verifier who is also the owner has an incentive to see what they expect to see rather than what happened.

Scope

When is a corrective and preventive action required?

This is the general-purpose action instrument, not a diagnostic. It records what will happen and whether it worked; it does not itself establish why the underlying problem occurred or what the problem was.

Use this template when

  • An incident, finding, audit, assessment or complaint has produced a conclusion that requires something to change
  • A root cause has already been identified elsewhere and now needs an owner, a due date and a way to verify it worked
  • A correction has been made and the underlying cause still needs to be addressed so it does not recur
  • An action from one workspace needs to be visible and trackable from every other workspace that references it
  • An effectiveness check on a previously closed action needs a home, including one that is about to reopen

Do not use it for

  • Root Cause Analysis, which determines why something happened; this record only holds what will be done about it
  • Risk Assessment, which is the general hazard and risk instrument, not an action arising from one
  • Finding, which records a single deficiency picked up during an audit or inspection before any action is decided
  • Effectiveness Verification as its own event, which is a distinct record referenced from the Verification ID field rather than completed inside this one
  • Documenting the parent event itself, which belongs in the incident, complaint or audit record this action was raised from

Compliance mapping

Which ISO 9001 cl.10.2 requirements does this satisfy?

ISO 9001 and ISO 45001 both set clause 10.2 out as a sequence: react and correct, evaluate whether the cause needs eliminating, implement the action, review whether it worked, and update the management system if it should be. The form's sections follow that sequence closely enough that each one maps to a specific sub-clause.

ClauseRequirementWhere it lands
ISO 9001 / 45001 cl.10.2.1(a)React to the problem and, where applicable, take action to control and correct itAction detail
ISO 9001 / 45001 cl.10.2.1(b)Evaluate the need for action to eliminate the cause, so it does not recur or occur elsewhereAction detail
ISO 9001 / 45001 cl.10.2.1(c)Implement any action needed, with an owner and a target dateOwnership
ISO 9001 / 45001 cl.10.2.1(c)Action carried out as planned, or the deviation from plan recordedImplementation
ISO 9001 / 45001 cl.10.2.1(e)-(f)Update risks and the management system where the action changes a process, document or controlDownstream triggers
ISO 9001 / 45001 cl.10.2.1(d)Review the effectiveness of any corrective action takenEffectiveness
ISO 9001 / 45001 cl.10.2.2Retain documented information as evidence of the nature of the nonconformity, the action taken, and its resultsClosure

What it does not cover

  • Root Cause Analysis, which establishes why the problem occurred; this record assumes that answer already exists.
  • Risk Assessment, which is the general hazard-and-control instrument this action might arise from, not the action itself.
  • Finding, which captures a single audit or inspection deficiency prior to any action being decided.
  • Effectiveness Verification, which is the formal check this record links to rather than performs, once one is required.
  • Management of Change, which is the approval record for the process or equipment change this action may trigger, not a substitute for raising one.

Global

Corrective and Preventive Action requirements by country

CAPA as a term comes from quality and safety management systems rather than from statute, so what varies across borders is less the duty to act on a problem and more which certifiable standard defines the expected sequence.

United States

OSH Act General Duty Clause; FDA 21 CFR 820.100 in regulated manufacturing

No general statutory CAPA requirement outside regulated sectors, but FDA-regulated manufacturers must maintain formal CAPA procedures.

Outside FDA-regulated industries, CAPA discipline is a management-system choice rather than a legal minimum, though an unaddressed recognised hazard still exposes an employer under the General Duty Clause.

United Kingdom

Management of Health and Safety at Work Regulations 1999, reg.5

Duty to have arrangements in place for the effective planning, organisation, control, monitoring and review of preventive and protective measures.

Review of measures already taken is itself a legal requirement, which is close to an effectiveness check by another name.

International

ISO 9001 cl.10.2; ISO 45001 cl.10.2

Certifiable management-system requirement to react, evaluate the need for cause-eliminating action, implement it, and review whether it worked.

Certification audits examine the CAPA log directly, and a pattern of weak actions or unverified closures is one of the most common nonconformities auditors raise.

How to complete it

How to complete a corrective and preventive action, step by step

The fields that decide whether a CAPA record is defensible later are not the description of the work; they are the ones that show the action was proportionate to the problem and actually checked.

State the action, not the intention

Action Description should be specific enough that someone who was not in the room could carry it out unchanged. "Improve training" is an intention; "add a lockout step to the changeover procedure and retrain the crew against it by the due date" is an action, and only the second can be verified as done or not done.

Match the strength to the finding, not to what is easy

A serious finding closed with retraining or a reminder because that is what can be implemented before month end is the pattern investigators and auditors look for first. Where a weak action genuinely is the right call, the justification field is where that reasoning belongs, not left implicit.

Route through the hierarchy explicitly

Hierarchy Level should show elimination and substitution were considered and rejected for a reason before an administrative control or PPE is accepted. The reasoning, not the final category, is what makes an inspector or auditor treat the action as considered rather than convenient.

Verify effectiveness independently, and let a failed check reopen the case

The verifier field exists because the owner cannot mark their own work effective. A not-effective result should reopen the action and trigger a fresh investigation, not sit as a comment; a closed action that failed its own check is worse than one left open.

What auditors find

Most common corrective and preventive action findings

CAPA findings concern the discipline around the record more often than the record itself: the action exists, but the strength, the owner, or the verification does not hold up.

FindingClauseWhat fixes it
Serious finding closed with a weak action (retraining, reminder) and no justification recorded.ISO 9001 / 45001 cl.10.2.1(b)Require Strength Justification whenever Action Strength is weak against a finding above a set severity.
Action owner and effectiveness verifier are the same person.ISO 9001 / 45001 cl.10.2.1(d)Enforce that Verifier cannot equal Action Owner at the point the check is scheduled.
Effectiveness check not performed on a level 3 or 4 investigation action.ISO 9001 / 45001 cl.10.2.1(d)Make Effectiveness Check Required a hard gate on closure for any action tied to a high-severity investigation.
Downstream trigger checked (document change, MOC, critical control) but never actually raised.ISO 9001 / 45001 cl.10.2.1(e)-(f)Require the Related Document, MOC or Control ID before the action can close, once the trigger box is checked.
Action has no due date, or is overdue with no delay reason recorded.ISO 9001 / 45001 cl.10.2.1(c)Set Due Date at the point the action is raised, and require Delay Reason before Status can move past Overdue.
Action Description too vague to verify as complete: describes a goal, not a task.ISO 9001 / 45001 cl.10.2.1(c)Route vague descriptions back to the owner before the record is accepted; require a task someone else could execute.

Case in point

Case in point: the CAPA log that always closed on time

A packaging line raised four CAPAs over a year for the same fault: intermittent seal failures on one lane. Each named a correction (rerun the affected pack), each rated Action Strength as retraining, and each closed on time with the owner's own signature standing in for a check. On-time-percent for the site looked excellent throughout.

The fifth occurrence reached a customer. The investigation found the seal head on that lane had been drifting out of tolerance for over a year, and every prior CAPA had retrained operators against a machine fault training could not fix. No action had ever been verified by someone other than the owner who raised it, so nobody had asked whether earlier actions worked, only whether they had been closed.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

42fields
7 sections
Reference
FDN-014
Archetype
Action
Record ID
CAPA-2026-000
Scoring
Strength 1 to 3, on time percent
Direction
Mixed
Singleton
Yes
Basis
ISO 9001 cl.10.2, ISO 45001 cl.10.2
Links
Linked from every workspace
Tags
Action
Sections
7
Fields
42
Follow up fields
0
Repeating sections
0
Links out
7
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

6 fields
Text

CAPA ID*

Generated on save

Format CAPA-2026-00000.

The record's own ID. Other templates point at this value.

Text

Case ID

OptionalThread key

Carried from the parent event so the whole chain retrieves together.

Thread key

Single Choice

Parent Type*

Incident, finding, audit, assessment, complaint or review.

IncidentNear missFindingAuditInspectionRisk assessmentComplaintEquipment failureNonconformanceManagement of change
Text

Parent ID*

Thread key

Immediate predecessor record

Date & Time

Raised Date*

Users

Raised By*

Action detail

7 fields
Single Choice

Action Class*

Correction contains the immediate problem. Corrective action removes the cause. Preventive action stops it elsewhere.

Correction, immediate containmentCorrective action, removes the causePreventive action, stops it elsewhere
Text

Action Description*

What will actually be done. Be specific enough that someone else could do it.

Info

Strength Guidance

Strong actions eliminate or engineer out the hazard. Weak actions rely on people remembering. A serious investigation cannot close on weak actions alone.

Single Choice

Action Strength*

Scored

Strong, medium or weak. This is the single most predictive field in the whole system.

  • Eliminate or engineer4 pts
  • Process change3 pts
  • Supervision or verification2 pts
  • Retraining1 pt
  • Reminder or reissue0 pts
Text

Strength Justification

Optional

Required where a weak action is proposed for a serious finding.

Single Choice

Hierarchy Level*

Scored

Which level of the hierarchy of controls this action sits at.

  • Elimination5 pts
  • Substitution4 pts
  • Engineering3 pts
  • Administrative2 pts
  • PPE1 pt
Single Choice

Priority*

Scored
  • High0 pts
  • Medium1 pt
  • Low3 pts

Ownership

8 fields
Users

Action Owner*

One named person, never a department.

Text

Owner Person ID*

Linked

Links to FDN-003 Person ID

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Links to FDN-001 Site ID

Pick List

Related Asset

OptionalFrom FDN-002 Asset NameFilter: Site matches
Text

Asset ID

OptionalLinked

Links to FDN-002 Asset ID

Date & Time

Due Date*

Single Choice

Status*

Scored
  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts

Implementation

6 fields
Text

Work Completed

Optional

What was actually done, which is sometimes different from what was planned.

File Upload

Completion Evidence

Optional

Photo or document showing the action in place.

Date & Time

Actual Completion Date

Optional
Single Choice

Completed On Time

OptionalScored
  • Yes3 pts
  • Late1 pt
  • Not completed0 pts
Text

Delay Reason

Optional
Signature

Owner Signature

Optional

Downstream triggers

6 fields
Checkbox

Triggers Document Change

Optional

Opens a document revision and a retraining requirement.

Checkbox

Triggers MOC

Optional

Required where this action changes a process or asset.

Checkbox

Adds Critical Control

Optional

Adds the control to the register with a verification frequency.

Text

Related Document ID

OptionalLinked

Links to FDN-008 Document ID

Text

Related MOC ID

OptionalLinked

Links to FDN-020 MOC ID

Text

Related Control ID

OptionalLinked

Links to FDN-011 Control ID

Effectiveness

6 fields
Checkbox

Effectiveness Check Required*

Required for any action arising from a level 3 or 4 investigation.

Text

Effectiveness Metric

Optional

How you will know it worked. A number, not an opinion.

Date & Time

Verification Due Date

Optional

Between 30 and 180 days after implementation.

Users

Verifier

Optional

Cannot be the action owner.

Text

Verification ID

OptionalLinked

Links to FDN-016 Verification ID

Single Choice

Effectiveness Result

OptionalScored

If this fails, the action reopens and a fresh investigation is triggered.

  • Effective2 pts
  • Partially effective1 pt
  • Not effective0 pts

Closure

3 fields
Users

Closure Approved By

Optional
Date & Time

Closure Date

Optional
Signature

Closure Signature

Optional

FDN-014 · record IDs look like CAPA-2026-000 · Linked from every workspace

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The record itself is simple. What slips is the routing across workspaces, the verifier who is quietly also the owner, and the downstream trigger that was checked but never actually raised.

KnowSafe

Watches CAPAs raised from incidents and assessments, checks that action strength matches severity, and flags weak actions closing serious findings.

KnowQuality

Tracks CAPAs raised from nonconformance and complaint records back to the batches and products they touched, and holds the case thread together.

KnowTrain

Turns an administrative-control action into an actual competency requirement and training record, rather than a note that training happened.

Ella
Ella

Holds the CAPA log against due dates and verifiers, blocks a verifier who is also the owner, and surfaces downstream triggers checked but never raised.

This template lives in General — control tower. The orchestration layer. Registries and engines every other workspace reads from.

Meet General→

Glossary

Corrective and Preventive Action definitions and key terms

Correction
The immediate action that contains a problem: stopping a line, isolating a batch, fixing a fault, without addressing why it happened.
Corrective action
An action that removes the cause of a problem so the same failure does not recur in the same place.
Preventive action
An action that addresses a cause before it produces a problem elsewhere, taken from a trend or a near miss rather than an event.
Action strength
A rating of how durable an action is, from eliminate-or-engineer at the top to reminder-or-reissue at the bottom, independent of how it is worded.
Effectiveness verification
An independent check, after enough time has passed, that the action actually produced the result it was meant to, rather than that the task was completed.

FAQ

Frequently asked questions about corrective and preventive action

Is CAPA one record type used everywhere, or a different form per workspace?+

One record type. Every workspace in the library, safety, quality, maintenance and the rest, raises the same CAPA record and links it back to whatever surfaced the problem. This is what lets a single view roll up completion and on-time percent across the whole business rather than per workspace.

Does every finding need a corrective action?+

No. A correction alone is enough where the cause is not expected to recur and is not systemic; ISO 9001 and ISO 45001 both frame corrective action as needed only where the cause warrants eliminating. Raising one for every trivial correction dilutes the log and slows review of the ones that matter.

Who decides whether an action counts as corrective or preventive?+

Whoever raises the case, based on whether a problem has already occurred at this location (corrective) or has not yet appeared but the same cause exists elsewhere (preventive). The distinction matters for reporting trend, not for the mechanics of the record itself.

What happens if the effectiveness check fails?+

The action should reopen, not simply record the failure. A failed effectiveness result is itself evidence that the original cause analysis or the action chosen was wrong, and the correct response is a fresh look at the cause rather than a second attempt at the same action.

Can a CAPA close without triggering the document or MOC change it flagged?+

It should not. A checked downstream trigger with no linked record behind it means the change the action depended on was never actually made, which leaves the process exactly as it was before the action was raised.

How long after implementation should effectiveness be checked?+

The field allows thirty to a hundred and eighty days; the right point depends on how long the failure mode takes to reappear. Checking too soon confirms implementation, not that it worked; checking too late lets a failed action run for months unnoticed.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 9001:2015 clause 10.2, Nonconformity and corrective action
  • ISO 45001:2018 clause 10.2, Incident, nonconformity and corrective action
  • Management of Health and Safety at Work Regulations 1999, regulation 5 (GB)
  • FDA 21 CFR 820.100, Corrective and preventive action (US, regulated manufacturing)

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.