CAPA

Medical Device CAPA Guide

CAPA, corrective and preventive action, is the QMS process for eliminating the causes of existing nonconformities (corrective action, ISO 13485 clause 8.5.2) and of potential nonconformities (preventive action, clause 8.5.3). A good CAPA records the problem, investigates the root cause, takes proportionate actions, verifies that they do not adversely affect device conformity and checks that they were effective. MDR Article 10(9) requires CAPA as part of the QMS.

Topic: CAPA

Author
MDRpilot Editorial Team
Reviewer
Independent regulatory review not yet assigned
Last updated
Applies to
ISO 13485:2016 clause 8.5 · EU MDR 2017/745 Article 10(9)

Terminology

TermMeaning
CorrectionAction to eliminate a detected nonconformity, such as reworking a batch
ContainmentImmediate action to limit the impact while the cause is investigated
Corrective actionAction to eliminate the cause of a nonconformity and prevent recurrence
Preventive actionAction to eliminate the cause of a potential nonconformity and prevent occurrence
Effectiveness checkEvidence after a defined period that the action achieved its purpose

Sources that should feed CAPA

  • Complaints and vigilance events
  • Internal and external audit findings
  • Nonconforming product and process deviations
  • Trends in PMS and production data
  • Supplier issues
  • Management review outputs

Root cause analysis

Choose a method proportionate to the problem: 5 Whys for simple causal chains, a fishbone (Ishikawa) diagram to explore categories such as method, material, machine, people, measurement and environment, or fault tree analysis for complex failures. Document the evidence for the cause you choose. 'Human error' is rarely a root cause; ask why the process allowed the error.

Actions, verification and effectiveness

Each action needs an owner and a due date. ISO 13485 requires verification that the action does not adversely affect the ability to meet regulatory requirements or the safety and performance of the device. The effectiveness check is separate: define in advance what will show success, for example no recurrence in the next three production lots or a complaint rate below a threshold for six months, and record the result.

Links to risk management and PMS

A CAPA that reveals a new hazard, a higher probability of harm or an ineffective risk control should trigger a review of the risk management file and, where relevant, the clinical evaluation and IFU. CAPA trends are also an input to the PSUR or PMS report.

How MDRpilot supports CAPA

MDRpilot keeps CAPA records with status, owners and due dates next to complaints, internal audits, nonconforming product records and the risk file. The CAPA procedure is drafted from the company profile and the CAPA-specific decisions you enter: sources, root cause method, target times, effectiveness period and closure approver. Overdue CAPAs appear in the audit readiness view.

References

  1. ISO 13485:2016 Medical devices — Quality management systems — Requirements for regulatory purposes — International Organization for Standardization.
  2. Regulation (EU) 2017/745 on medical devices (MDR) — EUR-Lex, Publications Office of the European Union.
  3. ISO 14971:2019 Medical devices — Application of risk management to medical devices — International Organization for Standardization.

Always check the consolidated text of the regulation and the current version of each guidance document before relying on it.

This guide is general information about the regulation and standards named above. It is not legal or regulatory advice for a specific device.

MDRpilot is documentation and workflow software. It is not a medical device, not a notified body and not a regulatory authority. It does not certify devices or guarantee compliance; AI-generated drafts must be reviewed and approved by qualified people in the manufacturer's organisation.

See it with your own device

Create an account, add your company and one real device. The Suite demo runs for 3 days and the first procedure opens straight away, not an empty dashboard.