CAPA

GMPQMS

CAPA is the organisation's ability to act on what its quality system learns. Inputs arrive from everywhere — deviation investigations, complaints, audit findings, monitoring trends, inspection observations — and the capability is the disciplined path from signal to removed cause: deciding which signals warrant formal action, planning corrective action that eliminates the demonstrated cause and preventive action that eliminates the potential one, implementing through the proper change routes, and verifying effectiveness afterwards. FDA's device quality system regulation and ISO 13485 treat CAPA as a named subsystem in its own right; ICH Q10 embeds it as a pharmaceutical quality system element whose rigour should be proportionate to the risk of the issue.

All 16 capabilities →

What this page does not claim

A capability is something an organization must be able to do; it is not a maturity score and not an assessment domain. The scored domains measure how consistently capabilities are performed, they do not map one-to-one, and nothing on this page rates your organization.

What this capability is

CAPA is the organisation's ability to act on what its quality system learns. Inputs arrive from everywhere — deviation investigations, complaints, audit findings, monitoring trends, inspection observations — and the capability is the disciplined path from signal to removed cause: deciding which signals warrant formal action, planning corrective action that eliminates the demonstrated cause and preventive action that eliminates the potential one, implementing through the proper change routes, and verifying effectiveness afterwards. FDA's device quality system regulation and ISO 13485 treat CAPA as a named subsystem in its own right; ICH Q10 embeds it as a pharmaceutical quality system element whose rigour should be proportionate to the risk of the issue.

The capability's hardest discipline is restraint at both ends. At intake, not everything deserves a CAPA — an organisation that opens one for every deviation drowns the significant in the trivial, and its backlog becomes the finding. At closure, the effectiveness check is what separates a CAPA system from a task tracker: evidence, gathered after enough time and real exposure, that the cause has not recurred. An action closed on implementation alone is a hypothesis, not a correction — and a system full of closed hypotheses is why the same problems keep arriving under new reference numbers.

WHY IT MATTERS

  • CAPA is where the quality system either learns or merely records. Every feedback capability — deviations, complaints, audits, monitoring — terminates here; if the terminus is weak, all of them are reduced to documentation exercises that change nothing.
  • It is a perennially top-cited subsystem in device inspections and a standing focus in GMP inspections, because the file shows everything: vague actions, missing effectiveness checks, and aged backlogs speak for themselves without the inspector needing to look further.
  • Correction, corrective action, and preventive action are practically and legally distinct, and conflating them is the classic failure: organisations fix the instance, call it corrective action, and are then surprised by recurrence.
  • An aged CAPA backlog is a risk register no one is reading — each open action is an acknowledged cause still live in the process, and its age is the time the organisation has knowingly lived with it.

[ POSITION IN THE FRAMEWORK ]

7 DIMENSIONS · 24 LINKS

CAPA is where the framework's findings converge: it turns what deviations, complaints, audits, and trends reveal into cause-removing action — routed through change control and verified effective after real exposure.

06 · QUALITY MATURITY — CAPA, REACTIVE TO ADAPTIVE

L1
Reactive

Actions are fixes to instances: the batch is corrected, the record closed, the cause untouched. CAPA exists as a form, opened under pressure and closed on implementation; recurrence is discovered by the next deviation rather than by any effectiveness check.

L2
Defined

A CAPA procedure defines sources, ownership, and timelines, and corrective is distinguished from preventive on paper. Which issues warrant a CAPA is judgement without criteria, so the backlog swings between everything and nothing, and effectiveness checks are a checkbox performed too early to mean anything.

L3
Controlled

Risk-based intake criteria decide what enters the system; actions are specific, owned, and routed through change control; and closure requires a defined effectiveness check with data gathered after real exposure. Backlog age and overdue actions are visible and actively managed.

L4
Predictive

CAPA data is analysed across sources — the same cause arriving via complaints, deviations, and audits is recognised as one problem, not three. Effectiveness-check failure rate is itself a metric, and preventive action is genuinely preventive: triggered by trends and near-misses, not re-labelled corrections.

L5
Adaptive

Cause removal is systemic: actions target process and system design, learning transfers across products and sites before the failure migrates, and the organisation can show categories of recurring problems that no longer recur — the backlog shrinking because causes are gone, not because standards dropped.

SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →

07 · REGULATORY & EVIDENCE

GOVERNING STANDARDS · 5

Derived from the 5 standards SPEQ maps to this subject, across 3 regulatory bodies: FDA, ICH, ISO.

RECORDS & OBJECTIVE EVIDENCE

  • CAPA records with documented, risk-based intake decisions
  • Action plans distinguishing correction, corrective, and preventive action
  • Implementation routed through change control with owners and dates
  • Effectiveness checks with data gathered after defined real exposure
  • Backlog age and overdue-action reviews with escalation evidence

COMMON INSPECTION FINDINGS

  • CAPA procedures not established, or not followed as written
  • Effectiveness checks missing, or written on the day of closure
  • Corrections recorded as corrective actions, with recurrence to show for it
  • An aged open backlog whose oldest items are unowned and unescalated
  • Complaint and audit findings never entering the CAPA system
EVERY CHIP IS A DOOR · WALK THE FRAMEWORK FROM ANY SUBJECTHow SPEQ maps the framework →

HOW YOU’D SEE WHERE YOU SIT

  • Take five closed CAPAs and read the effectiveness check: real data gathered after a defined interval of exposure, or a sentence written on the day of closure.
  • The proportion of "corrective actions" that are actually corrections — the instance fixed, the cause untouched — visible by asking what would stop the same event happening on another line tomorrow.
  • The age profile of the open backlog, and whether the oldest items are the highest-risk ones or simply the hardest ones no one wants to own.
  • Whether any preventive actions exist that did not originate from a failure that had already happened — the test of whether the P in CAPA is live.
  • How a CAPA that fails its effectiveness check is handled: reopened and re-investigated, or quietly re-closed.

Observable behaviours, not a self-rating — what a capability looks like from the outside, the same way SPEQ’s Quality Culture assessment reads behaviour rather than felt safety.

FREQUENTLY ASKED

What is the difference between correction, corrective action, and preventive action?

A correction fixes the nonconforming instance: rework the batch, quarantine the lot, reissue the record. A corrective action removes the cause of a nonconformity that has occurred, so it cannot happen again — anywhere the cause exists, not just where it surfaced. A preventive action removes the cause of a potential nonconformity before it has occurred at all, usually identified through trends, near-misses, or risk assessment. The distinction matters operationally: a system whose "corrective actions" are mostly corrections is treating symptoms, and its recurrence rate will say so. All three are legitimate — the failure is mislabelling one as another.

Does every deviation need a CAPA?

No — and a system that opens one for everything is failing differently, not succeeding harder. ICH Q10 expects the rigour of the CAPA process to be proportionate to the risk of the issue: a minor, isolated event with a confirmed low-impact cause can be corrected and trended without a formal CAPA, provided the decision is made against defined criteria and recorded, and provided trending would catch it becoming a pattern. What is indefensible is the opposite arrangement — intake decided by workload or mood, so that significance is determined by capacity rather than risk.

How is CAPA measured in the maturity assessment?

Through the Risk Management & CAPA domain, which scores how consistently the organisation turns findings into actions that remove causes — and verifies that they did. The capability page describes the function itself: what a working CAPA system must be able to do, and how it evolves from closing records to removing causes systemically. The assessment domain measures where your organisation actually sits on that ladder, through scored questions about observable practice. Read the capability to understand the target state; run the assessment to find your gap and its priority.

MEASURED THROUGH THE MATURITY ASSESSMENT

This capability is about what you must be able to do. How consistently you do it is what the maturity assessment scores — through the domain below.

Contributes to the FDA QMM practice area Advanced Pharmaceutical Quality System (a SPEQ mapping).

Score your quality system →