CAPA

CAPA software that closes the loop with complaints, audits and risk

CAPA software manages corrective and preventive actions, the process ISO 13485:2016 clauses 8.5.2 and 8.5.3 require for eliminating the causes of nonconformities and preventing them from occurring. A CAPA record covers the source, the investigation and root cause, the actions, verification that actions do not adversely affect device conformity, and a check of effectiveness. MDR Article 10(9) also lists CAPA as a QMS element. In MDRpilot CAPA records sit alongside complaints, internal audits and the risk file, with due dates and status that feed the audit readiness view.

Who it is for

  • Quality managers running CAPA on spreadsheets
  • Teams that need CAPA linked to complaints and audit findings
  • Manufacturers preparing for a notified body QMS audit

Key capabilities

  • CAPA records

    Open, in progress, overdue and closed status with due dates and owners.

  • CAPA procedure

    SOP drafted from your answers on sources, root-cause method, target times, effectiveness period and closure approver.

  • Linked sources

    Complaints, internal audits and nonconforming product records in the same workspace.

  • Readiness impact

    Overdue CAPAs appear as open actions in the audit readiness view.

Anatomy of a CAPA record

StepWhat to record
SourceComplaint, internal or external audit finding, nonconforming product, trend, PMS signal
Problem statementWhat happened, where, how often, which products and lots
ContainmentImmediate actions to limit impact
Root causeMethod used, for example 5 Whys or fishbone, and the cause found
ActionsCorrective or preventive actions with owner and due date
VerificationEvidence the actions were implemented and do not harm conformity
EffectivenessCheck after a defined period that the problem has not recurred
ClosureApproval by the responsible person

Why auditors look at CAPA first

CAPA shows whether a QMS learns. Auditors sample open and overdue CAPAs, check whether root causes are real causes rather than restated symptoms, and look for effectiveness checks with evidence. They also check whether CAPAs that affect safety have been reflected in the risk file.

How the workflow runs

  1. 1

    Open

    Create a CAPA from its source.

  2. 2

    Investigate

    Record root cause analysis.

  3. 3

    Act

    Assign actions with owners and dates.

  4. 4

    Verify

    Attach evidence of implementation.

  5. 5

    Check effectiveness

    Confirm the problem did not recur, then close.

Connected to the rest of the file

MDRpilot is not a stand-alone document generator. Requirements, evidence and documents share one product record.

  1. Requirements
  2. Evidence
  3. Documents
  4. Risk
  5. Clinical
  6. PMS
  7. QMS
  8. Audit

Each step reads from the same product record. A test report linked to a GSPR row can verify a risk control, a change to the device class flags the documents that depend on it, and the audit readiness view counts what is still open across all of them.

Limitations

  • MDRpilot does not determine root causes; it records the analysis your team performs.
  • Effectiveness criteria must be defined by your team in the CAPA procedure.

MDRpilot is documentation and workflow software. It is not a medical device, not a notified body and not a regulatory authority. It does not certify devices or guarantee compliance; AI-generated drafts must be reviewed and approved by qualified people in the manufacturer's organisation.

Frequently asked questions

What is CAPA in medical devices?

Corrective and preventive action: the QMS process for finding and removing the causes of nonconformities (corrective) or potential nonconformities (preventive), required by ISO 13485 clause 8.5.

Can MDRpilot write our CAPA procedure?

It drafts a CAPA SOP from your company profile and the CAPA-specific decisions you enter. Undecided points are marked [TO BE CONFIRMED].

Does every complaint need a CAPA?

No. Complaints are evaluated and investigated; a CAPA is opened when the investigation shows a nonconformity or a risk that needs corrective or preventive action, according to your procedure.

How does CAPA connect to risk management?

CAPAs that reveal new hazards or changed probabilities should trigger a review of the risk file. In MDRpilot both live in the same workspace.

Can I see overdue CAPAs before an audit?

Yes. Overdue CAPAs are listed in the CAPA module and counted in the audit readiness view.

References

  1. ISO 13485:2016 Medical devices — Quality management systems — Requirements for regulatory purposes — International Organization for Standardization.
  2. Regulation (EU) 2017/745 on medical devices (MDR) — EUR-Lex, Publications Office of the European Union.

Always check the consolidated text of the regulation and the current version of each guidance document before relying on it.

See it with your own device

Create an account, add your company and one real device. The Suite demo runs for 3 days and the first procedure opens straight away, not an empty dashboard.