CAPA SOP: Root Cause, Effectiveness Checks, and Part 11

A Corrective and Preventive Action standard operating procedure gives your organization a written, repeatable method for finding the root cause of quality problems and confirming those problems stay fixed. For medical device manufacturers, a documented CAPA SOP is required by 21 CFR 820.100, and as of February 2, 2026, the FDA’s renamed Quality Management System Regulation also incorporates ISO 13485:2016 by reference, so the SOP has to satisfy both frameworks at once.1eCFR. 21 CFR 820.100 – Corrective and Preventive Action2U.S. Food and Drug Administration. Quality Management System Regulation (QMSR)

What the SOP Must Contain

21 CFR 820.100 lists seven elements your procedures have to cover. The SOP must describe how you analyze quality data from processes, audits, complaints, and returned products to identify existing and potential causes of nonconforming product. It must describe how you investigate those causes, decide on action, verify that the action works without introducing new problems, and disseminate quality-problem information to the people responsible for fixing or preventing recurrence. CAPA activities and results must be documented, and information must be submitted for management review. Statistical methods are required where necessary to detect recurring quality problems.1eCFR. 21 CFR 820.100 – Corrective and Preventive Action

Under the QMSR, ISO 13485:2016 sits alongside 820.100. Section 8.5.2 of that standard adds two obligations worth writing directly into the SOP: corrective actions must be proportionate to the severity of the nonconformity, and verification must confirm the action does not adversely affect device safety, performance, or regulatory compliance. Section 8.5.3 mirrors that structure for preventive action targeting potential nonconformities. Both sections require records of investigations and actions.

If your existing SOP was drafted around the old 820.100 checklist alone, this is the moment to reconcile it with ISO 13485. The obligations haven’t shrunk.

Two Workflows: Corrective and Preventive

The SOP should treat corrective action and preventive action as separate workflows with separate triggers. Corrective action responds to a problem that has already occurred: a nonconforming product, a failed test, a complaint. Preventive action responds to a problem that has not yet occurred but that data analysis, trending, or near-miss review suggests could occur.

Inspectors look for this separation. A CAPA system that only produces records after something has gone wrong, and never opens a preventive action from trend data, draws scrutiny because the regulation explicitly requires both.1eCFR. 21 CFR 820.100 – Corrective and Preventive Action Build the preventive path into the SOP with its own initiation criteria, not as an afterthought under the corrective workflow.

Writing the Intake Step

The SOP should name the specific data sources your team is required to pull from: complaint files, nonconformance reports, audit findings, production records, equipment logs, and field performance data. Those sources have to be analyzed for both existing problems and emerging trends.1eCFR. 21 CFR 820.100 – Corrective and Preventive Action

When someone opens a CAPA record, the SOP should require enough specificity that a person unfamiliar with the situation can understand what happened. That means the affected product, batch or lot numbers, the date the issue was discovered, and the source that flagged it. “Quality issue on production line” is not a problem description; it is a placeholder that guarantees a vague investigation.

Severity classification belongs at intake, not later. The category assigned to an issue drives the resolution timeline, the level of oversight, and whether regulatory reporting is triggered. Define the tiers in the SOP in advance. A cosmetic labeling error and a device malfunction that could injure a patient both require a CAPA, but they should not follow the same clock.

Root Cause and Action Planning

Name the approved root cause methods in the SOP and require that the chosen method be recorded in the CAPA file. The 5 Whys technique and fishbone diagrams that map causes across equipment, materials, methods, personnel, and environment are commonly used. Whatever you approve, the SOP should require that the investigation goes past the proximate cause. If a sensor failed and the record stops at “the sensor was defective,” the underlying reason, whether supplier quality, storage, or an inspection gap, is still open. That underlying reason is what your action has to address.

Once the cause is identified, the action plan needs to name the person responsible, set a realistic deadline, and describe the specific change: a revised work instruction, a supplier requalification, a calibration schedule change, a targeted retraining. The regulation requires verification or validation that the action is effective and does not adversely affect the finished device.1eCFR. 21 CFR 820.100 – Corrective and Preventive Action Write the verification step into the plan before implementation begins.

Implementation and Effectiveness Verification

After the plan is approved, whoever holds the authority defined in your SOP (typically a quality manager), each task should be executed with evidence attached to the CAPA record as it completes. Revised procedures with tracked changes, training logs, calibration certificates, supplier audit reports: the file should be self-contained enough that an auditor can walk from problem identification to closure without asking for anything on the side.

Effectiveness verification is where CAPA systems most often break down. Define what “effective” means before the action is taken, not after. If a supplier was replaced, effectiveness might be zero incoming inspection failures for the replacement material over the next three production lots. If staff were retrained, it might be no recurrence of the nonconformity within 90 days. The criteria have to be measurable, and the monitoring window has to be long enough to catch a relapse.

Tier the monitoring by risk in the SOP itself. A minor documentation error can warrant a short window and a single follow-up check. A failure that could affect patient safety warrants a longer window, larger samples, and verification across all affected lines, shifts, and sites. Making those tiers a written policy stops the decision from being made ad hoc under each CAPA.

Closure requires a quality department signature certifying that the problem is addressed and the risk mitigated. If monitoring shows the action didn’t work, the CAPA stays open, the root cause analysis is revisited, and a new plan is developed. That reopening is the system working, not failing.

Records, Retention, and Management Review

Every CAPA record, from the initial report through investigation, action plan, implementation evidence, and effectiveness results, must be retained for the design and expected life of the device, with a minimum of two years from commercial release.3eCFR. 21 CFR 820.180 – General Requirements For implants and long-service-life devices, that stretches to a decade or more. The SOP should say where records are stored, who has access, and how they’re protected from alteration or loss.

During inspections, investigators check the SOP first, then pull actual records to test whether the procedures are followed in practice.4U.S. Food and Drug Administration. Guide to Inspections of Quality Systems A well-written SOP paired with incomplete records reads worse than a mediocre SOP that’s consistently followed.

The regulation requires that CAPA information be submitted for management review.1eCFR. 21 CFR 820.100 – Corrective and Preventive Action The SOP should set the frequency and define what management sees: open CAPAs, overdue actions, effectiveness check results, and recurring failure modes. Document the review itself.

Electronic CAPA Systems and 21 CFR Part 11

If CAPA records live in an electronic quality management system, 21 CFR Part 11 applies. Part 11 sets the standards for treating electronic records and signatures as equivalent to paper: audit trails that capture who changed what and when, access controls that prevent unauthorized alteration, and signature systems that reliably link each signature to a specific individual.5eCFR. Electronic Records; Electronic Signatures

The FDA’s February 2026 guidance on computer software assurance outlines a risk-based approach for establishing confidence that production and quality management system software works as intended.6U.S. Food and Drug Administration. Computer Software Assurance for Production and Quality Management System Software For a CAPA module, focus assurance activities on the features that matter most: workflow routing, approval controls, record integrity, and reporting accuracy.

The SOP should address how electronic approvals satisfy signature requirements at each stage (initiation, investigation approval, action plan approval, closure) and should define backup and recovery procedures so records are not lost if the system goes down. Auditors will ask to see Part 11 compliance documentation alongside CAPA records.

Failure Modes to Design Out of the SOP

The CAPA observations that appear most often on FDA Form 483s are a short list, and each one can be blocked at the SOP level.7U.S. Food and Drug Administration. Inspection Observations

  • No CAPA opened at all. A nonconformity gets fixed on the spot and nobody initiates a formal record. Require CAPA initiation for defined trigger conditions rather than leaving it to judgment.
  • Investigations that stall. A CAPA opens, ownership is unclear, the deadline slips. Require named ownership and enforced deadlines at initiation.
  • Shallow root cause analysis. The investigation stops at the first plausible explanation. Require a named methodology and evidence that the analysis went beyond the proximate cause.
  • No effectiveness verification. The action is implemented and the CAPA is closed without monitoring. This is the most common CAPA observation across years of inspection data. Require defined effectiveness criteria and completed monitoring before closure is permitted.
  • Missing documentation. Actions were taken but evidence was never attached. Require attached evidence as a mandatory field before closure.

The companies that struggle in inspections usually aren’t the ones with the hardest quality problems. They’re the ones whose SOPs allow shortcuts that look harmless until an investigator starts pulling records.