DEV Community

Rajiv Iyer
Rajiv Iyer

Posted on

Why our CAPA effectiveness check keeps coming back as an audit finding

For three NB cycles running, our CAPA effectiveness check has been the same minor observation. And honestly, it deserves to be.

I work at a contract manufacturer with three OEM customers and around forty direct suppliers of our own. Every CAPA we run has two questions the auditor is paid to ask: did you fix it, and did the fix stick? The second one is where we kept stumbling, and it took me longer than I would like to admit to see why.

What the standard actually asks for

ISO 13485:2016 clause 8.5.2 is fairly explicit. Corrective action has to include:

  • a review of the nonconformity
  • determination of causes
  • evaluation of the need for action to prevent recurrence
  • planning and documenting actions to ensure recurrence is prevented
  • verification that the corrective action does not adversely affect the ability to meet applicable regulatory requirements
  • a review of the effectiveness of any corrective action taken

The last bullet is the one that gets abbreviated in practice. The first five are paperwork; the sixth is a question that takes months to answer honestly.

FDA 21 CFR 820.100 does the same dance, and under MDR the expectation is documented through the quality system. Most of us know the requirement. Fewer of us build a process that survives contact with a plant floor.

What we were actually doing

Our pattern, looking back at twelve months of closed CAPAs, was roughly this:

  • A CAPA opened in February for a recurring dimension drift on a turned part.
  • Immediate action: 100% inspection at incoming for eight weeks.
  • Corrective action: process change at the supplier, a new control plan, a pFMEA revision.
  • Effectiveness check: a single follow-up inspection at week 12 showing zero NCRs.
  • Close CAPA.

That single follow-up was the auditor's problem. It looked like confirmation bias wearing a clipboard. The original nonconformity had been intermittent in the records, and we "verified effectiveness" with one snapshot. The next cycle, the same drift came back through a different part number.

The auditor's written observation was polite: The verification of effectiveness for CAPA-XXXX does not include objective evidence over a sufficient time period or product mix to demonstrate that recurrence has been prevented.

Translated: you checked once, you got lucky, you closed it.

What "effective" actually means on a plant floor

I had to sit with this for a while before the picture got clearer. Effectiveness, for a CAPA that touches process or supplier behaviour, is not a single inspection. It is a small evidence pack:

  • a defined lookback window, not "whenever I happen to remember"
  • a sampling plan across the product family, not just the part that originally failed
  • a metric that actually moves (SPC Cp/Cpk if the data exists, NCR rate per shift, supplier COA trend)
  • a documented conclusion that ties the numbers back to the original problem statement

None of this is exotic. All of it is tedious. Tedious is exactly the thing that gets dropped when the queue is long and the next CAPA is already open.

What we changed

I am not going to dress this up as a programme. It is four small habits we built into the CAPA closure step:

  • A minimum lookback of 90 days for process or supplier CAPAs, longer if the original failure was sporadic. The number is documented in the CAPA record itself, not in someone's head.
  • Effectiveness evidence tied to the metric that defined the original problem. If the original was a Cpk issue, the verification is a Cpk trend, not an NCR count. If the original was a documentation lapse, the verification is a sample of records, not a single audit.
  • A second pair of eyes. The CAPA owner drafts the effectiveness review; the QA lead challenges the evidence before closure. Most of my team's improvement here came from being forced to defend the closure to someone who had not lived through the original incident.
  • A simple log of "where we got it wrong." Every CAPA that comes back as a recurrence goes into a one-page note — what did the effectiveness review miss, and why. We review this at our quarterly QRM meeting. It is not a punishment document; it is a calibration document.

These are not innovations. They are the difference between treating CAPA closure as the end of a project and treating it as the start of a measurement.

The honest part

I still do not think we have fully solved this. The pattern that keeps tripping us is the rare-event CAPA — the ones where the original failure happened once in a blue moon. You cannot run a meaningful 90-day trend on something that may not recur in 90 days. For those, we are still experimenting with adjacent-process evidence and periodic re-checks beyond the formal closure.

The thing I would tell my past self is that the auditor is not the enemy in this. The minor observation on CAPA effectiveness is, in our experience, almost always pointing at a real fragility in the closure step. The fix is rarely heroic. It is mostly the discipline of writing down, in advance, what evidence will count as "this worked," before you start measuring.


What is the audit finding your team sees come back every cycle? I would rather hear about it now than in an observation response.

Top comments (0)