CAPA and nonconformance under ISO 13485
ISO 13485:2016 · Clauses 8.3, 8.5.2, 8.5.3 — the most common NB audit focus areas
Quick answer
Clauses 8.3, 8.5.2 and 8.5.3 are the most common notified body audit focus areas. Strong documentation, timely root cause analysis, and documented effectiveness verification are essential. Weak CAPA — particularly lack of systemic root cause analysis or failure to verify effectiveness — is the single most common major nonconformity raised during ISO 13485 audits.
8.3 — Control of nonconforming product
Any product that does not conform to requirements must be identified and controlled to prevent unintended use or delivery. The nonconforming product (NCP) procedure must address: identification (marking, tagging, or labelling), documentation (raising an NCR — nonconformance report), segregation (physical quarantine away from conforming product), evaluation (who determines disposition), and disposition.
Permissible dispositions under ISO 13485 include:
- Rework: The product is brought into conformance through additional processing. Reworked product must be re-inspected against original acceptance criteria.
- Scrap / reject: Product is permanently removed from the supply chain and destroyed or segregated.
- Concession (use-as-is): The product is used or released despite not fully meeting specifications, but after documented risk assessment confirming safety is not compromised.
- Return to supplier: Non-conforming incoming goods returned for replacement or credit.
Concession (use-as-is)
Using a nonconforming product under concession is permitted in limited circumstances — typically where the nonconformance is minor, does not affect safety or essential performance, and a documented justification is approved by an authorised person. In some jurisdictions, regulatory notification is required before granting a concession on a finished device. All concession records must be retained in the device history record (DHR).
8.5.2 — Corrective action
Corrective action is taken to eliminate the cause of an existing nonconformity to prevent recurrence. The CAPA process must follow a structured approach:
- Detect and document: Identify the nonconformity from audit findings, complaints, NCRs, field data, or management review
- Contain: Immediate containment actions to limit the impact — quarantine, field safety notice, customer notification
- Root cause analysis: Determine the underlying cause using systematic methods
- Action planning: Define corrective actions addressing the root cause(s)
- Implement: Carry out the defined actions within agreed timelines
- Verify effectiveness: Confirm the corrective action has resolved the problem and the nonconformity has not recurred
- Close: Formally close the CAPA with documented evidence of effectiveness
Root cause analysis methods
ISO 13485 does not mandate a specific root cause analysis method, but the chosen method must be systematic and documented. Common approaches used in the medical device industry include:
- 5-Why analysis: Iterative questioning — ask "why?" five times to move from symptom to root cause. Fast and effective for straightforward problems.
- Fishbone (Ishikawa) diagram: Categorises potential causes into branches (People, Process, Equipment, Materials, Measurement, Environment). Good for complex, multi-factor problems.
- Fault tree analysis (FTA): Top-down logic diagram tracing failure modes back to root causes. More resource-intensive but thorough for safety-critical failures.
8.5.3 — Preventive action
Preventive action addresses potential nonconformities before they occur. Inputs for preventive action include: quality data trends showing adverse drift, risk management outputs identifying high-likelihood scenarios, internal audit observations (not nonconformities but opportunities for improvement), and external intelligence (competitor field issues, regulatory guidance updates). Preventive actions must be documented, implemented, and their effectiveness verified — just like corrective actions.
Trending requirements (clause 8.4)
Individual events may not trigger CAPA, but trends across multiple events often do. ISO 13485 clause 8.4 requires analysis of data including feedback, complaint rates, product conformity statistics, and supplier performance. When trend analysis reveals a statistically significant adverse trend, corrective action must be initiated even if no individual event crossed a reporting threshold. Trend analysis should be part of management review inputs.
Common CAPA failures
| Failure | Why it is a problem | How to prevent it |
|---|---|---|
| Treating symptoms, not root causes | Problem recurs; NB raises repeat major NC | Require documented RCA with specific method before action planning |
| No effectiveness verification | Cannot demonstrate CAPA actually worked | Define measurable effectiveness criteria before closing CAPA |
| Overdue CAPAs | Demonstrates lack of QMS control | Set realistic timelines; escalate at 75% of deadline |
| Weak documentation | Auditor cannot verify what was done or why | Use a structured CAPA form covering all 7 steps |
| CAPA not linked to complaint or NCR | Cannot demonstrate systemic response to field issues | Cross-reference all CAPAs to source documents |
Typical NB audit findings on CAPA
Notified body auditors review CAPA records in detail during stage 2 and surveillance audits. The most common findings include: root cause analysis that does not address systemic causes (only describes the event); effectiveness verification performed too soon after implementation (before sufficient data is available); CAPAs closed without documented evidence; and a high proportion of corrective actions that are merely retraining without process changes.
CAPA record fields
| Field | Content |
|---|---|
| CAPA number | Unique identifier (e.g., CAPA-2025-042) |
| Source / trigger | Reference to NCR, complaint, audit finding, trend |
| Problem description | Clear statement of the nonconformity or risk |
| Immediate containment | Actions taken to limit impact |
| Root cause analysis | Method used, findings, evidence |
| Action plan | Specific actions, responsible persons, target dates |
| Implementation evidence | Updated documents, training records, process changes |
| Effectiveness criteria | Measurable criteria defined before close |
| Effectiveness verification | Data collected post-implementation, comparison to criteria |
| Closure approval | Signature of quality manager or authorised person |