For your business to comply with the ISO 9001 standard, it needs a quality management system (QMS) that includes adequate CAPA processes.
These processes must be properly defined, in accordance with the CAPA requirements in ISO 9001:2015.
What is CAPA?
CAPA stands for corrective and preventive action. CAPA processes provide a structure for addressing quality issues or nonconformities.
Corrective action tackles existing problems. To prevent those problems from recurring, it has to identify and eliminate their root causes.
Preventive action is designed to avoid problems before they happen. In other words, it involves identifying potential nonconformities and taking steps to prevent them.
Corrective action is reactive, whereas preventive action is proactive.

The two are connected but, for the sake of a thorough and effective CAPA structure, they should be defined as individual processes. This ensures they can be implemented separately when needed.
CAPA requirements in ISO 9001:2015
ISO 9001:2015 encourages a proactive, risk-based approach to quality management. CAPA is a central component of this approach.
Clause 10.2: preventing nonconformity recurrence
In the standard, clause 10.2 focuses specifically on preventing nonconformity recurrence.
It sets a requirement for documenting the results of corrective actions.
The clause specifies that management and team leaders must be actively involved in identifying, recording, removing, and mitigating risk.
Employees down the chain of command must be able to give their feedback on risk to management for consideration.
Other CAPA documentation requirements in ISO 9001:2015
Under ISO 9001:2015, it’s mandatory to maintain the following records (among others):
- record of nonconforming outputs (clause 8.7.2)
- monitoring and measurement results (clause 9.1.1)
- internal audit program (clause 9.2)
- results of internal audits (clause 9.2)
- results of the management review (clause 9.3)
These requirements all relate to CAPA in some way.
Where actual or potential problems or nonconformances are identified, they should trigger CAPA processes. The steps taken should be properly documented and the outcome should be recorded and evaluated.
CAPA reports are an integral part of internal audits. Typically, a business will compile separate reports for corrective action and preventive action in response to nonconformities and quality issues.
The current standard doesn’t, however, require separately documented, predefined procedures for preventive actions. (These were required by earlier editions of ISO 9001).
This doesn’t mean preventive action is any less important. It’s a vital component of the required risk-based approach – but documentation requirements have been streamlined.
Future changes to ISO 9001
In December 2023, revision of ISO 9001:2015 was started by a working group of more than 150 country representatives from almost all standards organizations.
The broad strokes of the standard are expected to stay largely the same, with a few exceptions. The standard will be tweaked to better align with ISO 9000.
The risks and opportunities topics in chapter 6.1 are also likely to be split into two separate sections. This is so companies won’t get bogged down focusing on risks and end up overlooking potential opportunities.
If all goes according to plan, the expected revision of ISO 9001 will be released in September 2026.
Key steps in a compliant CAPA process
There’s no single template for a CAPA process that can be applied to every business or industry.
However, an effective and compliant CAPA process will include the following key steps:
1. Identification
When a nonconformance, quality issue or defect is noticed by a staff member or customer, the nature of the issue must be recorded.
Include as much context and information as possible.
2. Evaluation
Evaluate the severity of the issue to decide if it warrants a CAPA plan.
Not all issues need a CAPA response.
This will depend on the complexity and potential harm of the issue.
3. Investigation
Investigate the root cause of the issue.
This can be a time-consuming step because there might be more than one cause.
Don’t point fingers until the causes are clearly identified.
4. Implementation
Implement either corrective or preventive action (or both).
Corrective action needs to be immediate to resolve the issue.
Preventive actions must ensure the issue doesn’t reoccur.
5. Monitoring
Monitor the CAPA that was implemented to document its effectiveness.
The actions taken must have resolved the issue and stopped it from reoccurring.
An internal audit can also be useful.
6. Modification
If any weaknesses are identified in the CAPA process, modifications must be made so that the initial corrective response is effective, and the preventive action is more proactive in the future.
What to include in a CAPA report
When a quality management nonconformity is identified, it’s important to report on the responding CAPA process.
Multiple people might contribute to the report, including whoever initiated the CAPA process, the person responsible for implementing it and whoever needs to sign it off.
The report should typically include:
- the nature of the nonconformity
- its severity
- immediate actions that were taken
- suspected causes
- the plan for corrective and/or preventive actions
- verification that action was taken and was effective
- sign-off from a quality manager once the process is complete.
How isoTracker’s CAPA software can help
isoTracker offers modular, cloud-based quality management software that includes CAPA capabilities to facilitate ISO 9001:2015 compliance.
The benefits of using QMS software for CAPA compliance include:
The QMS modules that include CAPA software are Complaints Management, Audit Management, Training and Non-Conformance Management software.
Contact us to find out more or sign up for a free 60-day trial of isoTracker’s quality management software to see how it can help your organization be compliant with the latest CAPA requirements in ISO 9001:2015.


