Somewhere in a conference room right now, an auditor is sliding a piece of paper across a table and a quality manager is saying the six most predictable words in our industry: “So do we need a CAPA?”
Sometimes yes. Often no. And the reason that question causes so much anguish is that most companies have collapsed three genuinely different activities into one word and one form. Let’s pull them apart, because the difference between them is the difference between a quality system that learns and a quality system that just files things.
First, the finding is not the problem. It’s the evidence of the problem.
A finding is a fact: this requirement, this evidence, this gap. That’s exactly what a well-written finding gives you — a requirement, an observation, and no editorializing. What it does not give you is a diagnosis. That part is your job, and it starts the moment the audit closes.
ISO 13485 §8.2.4 is unusually blunt about this. The audited area’s management shall ensure “any necessary correction and corrective action” is taken “without undue delay.” Two different things, named separately, in the same sentence. That’s not sloppy drafting. That’s the standard telling you the order of operations.
Step one: containment. Stop the bleeding.
Before you philosophize about root cause, ask a colder question: is anything bad in motion right now?
If the audit found that three lots shipped without a completed final inspection record, the intellectual question of why can wait forty-five minutes. The immediate question is: where is that product, is more of it about to ship, and do we have a potential nonconforming product situation under §8.3? Quarantine first. Think second.
Containment is the step people skip when a finding feels administrative. A missing training record doesn’t feel urgent — until you ask whether the untrained person is on shift tomorrow doing the same thing. Ask anyway. It takes a minute and occasionally saves you a very bad month.
Step two: correction. Fix the thing.
A correction eliminates the detected nonconformity. That’s all. Complete the missing record. Recalibrate the gage. Revise the procedure that says “Quality Assurance Manager” for a role you renamed in 2023.
Correction is necessary, it’s usually fast, and it is not corrective action. This is the single most common confusion I see, and it’s genuinely understandable, because the words are nearly identical and someone in the 1990s decided that was fine.
Here’s the tell: if the only thing you did was fix the specific instance in front of you, and nothing about the system changed, you performed a correction. Write it down, close it out, and move to the real question.
Step three: the decision. Does this need corrective action?
Now — and only now — you evaluate. ISO 13485 §8.5.2 asks you to review the nonconformity, determine its cause, and evaluate the need for action to ensure it doesn’t recur. That middle phrase is doing a lot of work. The standard does not say every nonconformity gets a corrective action. It says you must decide, on the record, whether it needs one.
So decide like an adult, using risk:
- How bad could this get? Product safety and regulatory impact outrank paperwork tidiness.
- Is it a one-off or a pattern? One missing signature is a correction. The fourth missing signature this year on the same form is a system telling you something.
- Did the system allow it, or did the system catch it? If your own controls detected it, that’s evidence the system is working — a different conclusion entirely.
- Is the cause knowable and fixable? If you genuinely can’t tell yet, that’s an investigation, not a foregone CAPA.
Then, and this is very important, record your rationale. “Correction only; isolated clerical error, no trend across 12 months of the same record type, and an explanation for why there is no product impact” is a perfectly defensible decision. “We didn’t open a CAPA” with no reasoning attached is not a decision — it’s a gap with a shrug in it.
A side note on CAPA logs. They are generally not structured correctly. Someone creates a list and the first column is CAPA number so everything added to the log is by default a CAPA. (This is a fundamental problem with some eQMS systems or paper based systems driven by spreadsheets.) By shifting that to Issue number, describing the nonconformity, and answering the questions above, and determining in a yes or no column whether or not it is indeed a CAPA, the last columns should be the assigned CAPA number if the answer is yes and if it is no, then the rationale is recorded. With Candor the rationale for not opening a CAPA is documented with the finding.
Where it goes wrong in real life
Two failure modes, and they’re mirror images.
The first is CAPA everything. I once worked with a company whose rule was that every audit finding automatically opened a CAPA. Noble! Also fatal. They had ninety-one open CAPAs, an average age of eleven months, and a quality engineer who had stopped making eye contact. The genuinely dangerous ones were buried in a queue with typo corrections. Their CAPA system wasn’t overworked — it was meaningless, because nothing in it was prioritized. An inspector doesn’t have to be clever to find that problem. They just have to ask for the aging report.
The second is correction dressed up as corrective action. You know this one. Finding: an assembly step was performed out of sequence. Root cause: “operator did not follow the work instruction.” Corrective action: “operator retrained.” Closed.
Reader, they did it again in March and twice in April. Nothing about the work instruction, the fixture, the line layout, or the shift handoff had changed — only one human’s memory had been briefly refreshed. That’s not corrective action. That’s a correction wearing a mask.
Do this today
Open your last internal audit report. For each finding, check that three things are visible and dated: what you contained, what you corrected, and the documented decision about whether corrective action was warranted — with a reason. If that third item is missing on most of them, that’s your gap, and it’s a very fixable one.
Then look across the last twelve months and ask whether the same area keeps generating “isolated” findings. Individually defensible, collectively a trend. This is exactly the kind of thing that’s invisible in a folder of PDFs and obvious in a system that tracks findings over time — which is, not coincidentally, how we built Candor to work for the clients whose audit programs we run.
And remember that under the QMSR, your internal audit records are no longer off-limits to FDA. Which sounds alarming until you realize what it actually rewards: a company that found its own problem, sized it honestly, fixed the right layer, and wrote down why. That’s not a liability. On a good day, it’s the best evidence you own.