CAPA vs Change Control
Fixing what went wrong vs controlling what you deliberately change.
What a comparison is not
A comparison is SPEQ’s reading of how two published documents differ. Neither is the right answer, it is not a determination of which applies to you, and neither is summarised in a way that replaces reading it.
CAPA is the quality-system process for investigating problems, correcting them, and preventing recurrence. Change control is the process for proposing, assessing, approving, and implementing a deliberate change without introducing new risk. They interlock — a CAPA often drives a change, and a change is implemented under change control — but they answer different questions and are distinct records.
| ASPECT | CAPA | CHANGE CONTROL |
|---|---|---|
| Trigger | A problem: nonconformance, deviation, complaint, audit finding | A proposed change: process, equipment, supplier, document, system |
| Goal | Correct the issue and prevent recurrence (root-cause driven) | Implement change with risk assessed and no new problems introduced |
| Direction | Reactive (something already went wrong) | Proactive (something is about to change) |
| Core steps | Investigate → root cause → correct → preventive action → effectiveness check | Propose → impact/risk assess → approve → implement → verify/close |
| Effectiveness | Effectiveness check is mandatory and often a weak point | Post-implementation review confirms the change worked and was safe |
| Relationship | A CAPA may require a change → routed through change control | A change gone wrong may spawn a CAPA |
Open a CAPA when something has gone wrong and you need to correct it and stop it recurring — the emphasis is root cause and an effectiveness check that proves the fix held.
Open a change control when you intend to change something — the emphasis is impact assessment, approval before implementation, and verification that the change introduced no new risk.
CAPA is reactive, change control is proactive — and they hand off to each other. The classic inspection finding is confusing the two: implementing a “fix” as a quiet change with no root-cause CAPA, or running a CAPA that never routes its corrective change through change control. Keep them distinct records that reference each other, and make sure the CAPA effectiveness check actually closes the loop.
CAPA vs Change Control: frequently asked questions
Common questions on how CAPA and Change Control differ and when each applies.
Is change control part of CAPA?
No — they are separate processes that interact. A corrective action from a CAPA may require a change, which is then executed under change control. But change control also handles planned changes that have nothing to do with any problem.
Does every deviation need a CAPA?
Not necessarily. A deviation is investigated; whether it escalates to a formal CAPA depends on risk, recurrence, and root cause. Minor, one-off deviations with clear causes may be corrected and closed without a full CAPA, if your procedure allows and the rationale is documented.
What is the most common CAPA failure?
A weak or missing effectiveness check. Firms correct the immediate issue but never verify that the preventive action actually stopped recurrence — so the same problem returns and draws a repeat observation.
Where are these required?
CAPA is an explicit requirement in device regulation (21 CFR 820 / QMSR) and a core element of the pharmaceutical quality system (ICH Q10). Change management is likewise an ICH Q10 element and embedded in GMP across regions.