CAPA
CAPA software that closes the loop with complaints, audits and risk
CAPA software manages corrective and preventive actions, the process ISO 13485:2016 clauses 8.5.2 and 8.5.3 require for eliminating the causes of nonconformities and preventing them from occurring. A CAPA record covers the source, the investigation and root cause, the actions, verification that actions do not adversely affect device conformity, and a check of effectiveness. MDR Article 10(9) also lists CAPA as a QMS element. In MDRpilot CAPA records sit alongside complaints, internal audits and the risk file, with due dates and status that feed the audit readiness view.
Who it is for
- Quality managers running CAPA on spreadsheets
- Teams that need CAPA linked to complaints and audit findings
- Manufacturers preparing for a notified body QMS audit
Key capabilities
CAPA records
Open, in progress, overdue and closed status with due dates and owners.
CAPA procedure
SOP drafted from your answers on sources, root-cause method, target times, effectiveness period and closure approver.
Linked sources
Complaints, internal audits and nonconforming product records in the same workspace.
Readiness impact
Overdue CAPAs appear as open actions in the audit readiness view.
Anatomy of a CAPA record
| Step | What to record |
|---|---|
| Source | Complaint, internal or external audit finding, nonconforming product, trend, PMS signal |
| Problem statement | What happened, where, how often, which products and lots |
| Containment | Immediate actions to limit impact |
| Root cause | Method used, for example 5 Whys or fishbone, and the cause found |
| Actions | Corrective or preventive actions with owner and due date |
| Verification | Evidence the actions were implemented and do not harm conformity |
| Effectiveness | Check after a defined period that the problem has not recurred |
| Closure | Approval by the responsible person |
Why auditors look at CAPA first
CAPA shows whether a QMS learns. Auditors sample open and overdue CAPAs, check whether root causes are real causes rather than restated symptoms, and look for effectiveness checks with evidence. They also check whether CAPAs that affect safety have been reflected in the risk file.
How the workflow runs
- 1
Open
Create a CAPA from its source.
- 2
Investigate
Record root cause analysis.
- 3
Act
Assign actions with owners and dates.
- 4
Verify
Attach evidence of implementation.
- 5
Check effectiveness
Confirm the problem did not recur, then close.
Connected to the rest of the file
MDRpilot is not a stand-alone document generator. Requirements, evidence and documents share one product record.
Each step reads from the same product record. A test report linked to a GSPR row can verify a risk control, a change to the device class flags the documents that depend on it, and the audit readiness view counts what is still open across all of them.
Limitations
- MDRpilot does not determine root causes; it records the analysis your team performs.
- Effectiveness criteria must be defined by your team in the CAPA procedure.
MDRpilot is documentation and workflow software. It is not a medical device, not a notified body and not a regulatory authority. It does not certify devices or guarantee compliance; AI-generated drafts must be reviewed and approved by qualified people in the manufacturer's organisation.
Frequently asked questions
What is CAPA in medical devices?
Corrective and preventive action: the QMS process for finding and removing the causes of nonconformities (corrective) or potential nonconformities (preventive), required by ISO 13485 clause 8.5.
Can MDRpilot write our CAPA procedure?
It drafts a CAPA SOP from your company profile and the CAPA-specific decisions you enter. Undecided points are marked [TO BE CONFIRMED].
Does every complaint need a CAPA?
No. Complaints are evaluated and investigated; a CAPA is opened when the investigation shows a nonconformity or a risk that needs corrective or preventive action, according to your procedure.
How does CAPA connect to risk management?
CAPAs that reveal new hazards or changed probabilities should trigger a review of the risk file. In MDRpilot both live in the same workspace.
Can I see overdue CAPAs before an audit?
Yes. Overdue CAPAs are listed in the CAPA module and counted in the audit readiness view.
Related workflows
- ISO 13485 software for quality manuals, procedures and controlled recordsBuild and run ISO 13485:2016 documentation: quality manual wizard, SOPs, forms, document control with review and approval, and a controlled document register.Read more
- PMS and PMCF software that feeds back into risk and clinical evaluationPost-market surveillance under MDR Articles 83–86: PMS plan, PMCF plan and survey, PSUR or PMS report by device class, linked to complaints, CAPA and risk.Read more
- ISO 14971 risk management software connected to your evidenceMaintain an ISO 14971:2019 risk management file per device: plan, hazard analysis, risk controls, verification of controls and benefit-risk, linked to GSPR and PMS.Read more
- Audit readiness for MDR and ISO 13485 auditsPrepare for notified body and internal audits with a readiness score, a list of missing actions across technical file, QMS and CAPA, and an audit simulator.Read more
- A medical device QMS that is connected to your devicesWhat a medical device quality management system must cover under MDR Article 10(9) and ISO 13485, and how it connects to technical documentation and PMS.Read more
Guides and resources
- Medical Device CAPA GuideHow to run CAPA under ISO 13485 clause 8.5 and MDR: when to open a CAPA, root cause analysis, actions, verification, effectiveness checks and links to risk and PMS.Read more
- ISO 13485 for Medical Device ManufacturersWhat ISO 13485:2016 requires, how it differs from ISO 9001, how it relates to MDR Article 10(9), which documents you need and how certification works.Read more
- MDR Audit Preparation ChecklistA practical checklist for notified body QMS audits and technical documentation reviews under the EU MDR, including unannounced audits, records to have ready and how to rehearse.Read more
References
- ISO 13485:2016 Medical devices — Quality management systems — Requirements for regulatory purposes — International Organization for Standardization.
- Regulation (EU) 2017/745 on medical devices (MDR) — EUR-Lex, Publications Office of the European Union.
Always check the consolidated text of the regulation and the current version of each guidance document before relying on it.
See it with your own device
Create an account, add your company and one real device. The Suite demo runs for 3 days and the first procedure opens straight away, not an empty dashboard.
