Corrective Action Procedure: Write the One That Never Fails

DIRECT ANSWER

What does a corrective action procedure have to do?

A corrective action procedure has to do two jobs that look like one: remove the thing that went wrong, and remove the reason it was able to go wrong. Every management system standard requires both, and every standard describes them in slightly different words at slightly different clause numbers. A procedure that treats them as a single step will close findings quickly and change nothing, which is why the same problems reappear in systems whose closure metrics look excellent.

A corrective action procedure fails at the point it is written, not at the point it is used. By the time a finding is sitting in the log with a signature on it and the same finding is sitting three lines above it from eighteen months ago, the decision that produced that outcome was made much earlier — by whoever designed the form, chose the routing, and decided what the closure step would require. Those decisions are usually made in an afternoon, by someone adapting a document they found, and they are almost never revisited.

This article is about making those decisions deliberately. It covers what your corrective action procedure has to contain, what each of the five standards forces into it that the others do not, the two drafting failures that account for most recurring findings, and the sections a working document actually needs. It is written for the person holding the blank page — or holding a document they inherited and suspect is not doing its job.

Across 28 years, 200+ audits attended and 80+ certifications supported, MSI has watched the same handful of structural weaknesses recur in otherwise competent organizations. None of them is carelessness. All of them are drafting decisions.

Closure is an event. Cause removal is a change. A procedure that cannot tell them apart will record the first and report it as the second.

THE TWO JOBS

What a Corrective action procedure Is Actually For

Contain. Cause. Confirm.

Start with the distinction the whole document rests on, because every other decision follows from it. Something has gone wrong. There are two entirely separate responses available, and a corrective action procedure has to make room for both without letting either stand in for the other.

Correction deals with the thing in front of you. The nonconforming part is scrapped, reworked, or accepted under concession. The spill is contained. The wrong label is removed. The patient is told. Correction is immediate, it is usually obvious, and it is frequently the only thing that actually happens.

Corrective action deals with the reason the thing was able to happen. It asks what in the process allowed a part to reach final inspection uncontrolled, or a drum to be stored where a bund could not hold it, or a label to be applied from an uncontrolled print file. It changes something structural, and it is verified later against whether the condition still exists.

Those are different activities, performed by different people, on different timescales, producing different records. When one form captures both, the disposition record becomes the corrective action record by default. The finding closes. No cause is ever removed. This is the single most consequential thing a corrective action procedure either gets right or gets wrong, and it is settled entirely at the drafting stage.

DIRECT ANSWER

Is correction the same as corrective action?

No, and a corrective action procedure that blurs them is the most common reason findings recur. Correction addresses the nonconformity itself — scrap the part, contain the spill, notify the customer. Corrective action addresses the cause that allowed the nonconformity to occur, so that it does not occur again. Correction is always required. Corrective action is required when the evaluation concludes the cause needs eliminating. Writing them as one step means the second one silently never happens.

There is a second consequence people miss. Not every nonconformity needs corrective action. All five standards ask the organization to evaluate the need for action to eliminate the cause — they do not require corrective action on every event. A corrective action procedure that forces a full root cause investigation on every scratched panel will be abandoned within a quarter, and abandonment is a worse outcome than a proportionate rule. The evaluation step is where proportionality lives, and it needs writing down with criteria, not left to whoever picks up the form.

BEFORE YOU WRITE ANYTHING

Score the Procedure You Already Have — Free, About Six Minutes

Eight elements, four levels each, described as observable behaviour rather than intention — and scored on how your process runs on a busy week, not on how the document describes it. Your score and band appear immediately, with nothing to enter first. Most organizations are not uniformly weak; knowing which element is actually costing you is what changes what you do on Monday. It covers ISO 9001, ISO 13485, ISO 14001, ISO 45001 and ISO 7101, whether or not you are certified.

Score your process free →


BEFORE YOU DRAFT

Which Standard Governs Your Corrective action procedure?

Same. Clause. Different.

Four of the five standards put corrective action at Clause 10.2. That coincidence is responsible for a great deal of wasted effort, because it suggests the requirement is portable and it is not. An organization running more than one management system cannot copy a corrective action procedure across, and a document written to one standard will silently miss obligations in another. The clause number matches. The obligations do not.

DIRECT ANSWER

Do all ISO standards require the same corrective action procedure?

No. ISO 9001, ISO 14001, ISO 45001 and ISO 7101 all place corrective action at Clause 10.2, and ISO 13485 places it at Clause 8.5.2 — but each imposes at least one obligation the others do not. ISO 9001 requires the risk register to be updated. ISO 13485 requires action without undue delay and verification that the fix has not compromised regulatory compliance or device safety. ISO 14001 scales action to environmental significance. ISO 45001 requires worker participation in evaluating the cause. ISO 7101 requires the service user to be told. A single corrective action procedure covering several standards has to carry all of them.

Standard Clause What it requires that the others do not
ISO 9001:2015 10.2 Update the risks and opportunities determined during planning, if necessary — 10.2.1 e). The only place in any of the five where the improvement loop is required to touch the risk register.
ISO 13485:2016 8.5.2 Action without undue delay, and verification that the corrective action has not adversely affected regulatory compliance or the safety and performance of the device — 8.5.2 e). A documented procedure is mandated by name. Preventive action still exists as a separate clause.
ISO 14001:2026 10.2 Action appropriate to the significance of the effects, including the environmental impacts. Correction must include mitigating adverse environmental impacts — a third activity distinct from both correction and corrective action.
ISO 45001:2018 10.2 Evaluate the need for action with the participation of workers. Select action in accordance with the hierarchy of controls. Assess risks from new or changed hazards before taking the action. Communicate the outcome to workers.
ISO 7101:2023 10.2 Nine named sources feed the process. Eight elements are mandatory in the action itself. The service user affected is told what happened and what is being done.

Read down the right-hand column and the drafting problem becomes concrete. If you write a corrective action procedure to ISO 9001 and later add ISO 45001, the document you already hold has no place to record worker participation, no hierarchy-of-controls step at action selection, and no pre-implementation hazard assessment. Those are not refinements. They are lettered obligations, and an auditor will find their absence in the procedure before looking at a single record.

This is also why MSI writes a separate corrective action procedure for each standard rather than one master document with the standard's name swapped at the top. Where organizations genuinely run two systems, the honest answer is an integrated procedure with every divergence named and decided in writing — not a quality document with an environmental label on it. The full ISO procedure templates and guides library is built that way across all five standards plus the integrated combinations.

Quality and environment is the pairing where this bites hardest, because the two standards share the harmonized structure closely enough that a single process looks obviously correct. It is not. ISO 9001’s risk-register write-back has no environmental counterpart, and ISO 14001’s mitigation step and significance routing have no quality counterpart — so an organization running one improvement process across both will typically implement whichever standard it documented first and quietly drop the other standard’s additions. Anyone managing both revisions together will find the wider programme mapped in MSI’s work on the ISO 9001 and 14001 transition, which makes the case for running them as one plan rather than two.


ISO 9001

What ISO 9001 Forces Into Your Corrective action procedure

React. Evaluate. Update.

ISO 9001 Clause 10.2.1 is six lettered requirements, and most procedures written to it carry four. The two that go missing are e) and f), and e) is the more interesting failure because it is the only point in any of these standards where the reactive loop is required to reach back into the planning system.

The clause requires the organization to react to the nonconformity and, as applicable, control and correct it and deal with the consequences; evaluate the need for action to eliminate the causes so that it does not recur or occur elsewhere; implement any action needed; review the effectiveness of the action taken; update the risks and opportunities determined during planning, if necessary; and make changes to the quality management system if necessary.

The step almost nobody performs

Clause 10.2.1 e) is a single line and it is routinely read as boilerplate. It is not. A nonconformity is empirical evidence about a risk assessment. Either the risk was in the register and its likelihood rating was wrong, or the risk was never in the register at all. Both are findings about the planning process, and both are supposed to travel back there.

What happens instead is that the risk register and the corrective action log live in different files, owned by different people, reviewed on different cycles. The register is revisited annually before management review. The log is worked weekly. Nothing connects them, so a risk rated unlikely stays rated unlikely through four occurrences of the thing it describes.

The fix in the corrective action procedure is a field and a rule, not a paragraph of intent. The closure step asks one question — does this event change a risk rating, or reveal a risk not registered? — and the answer is Yes, No, or a register reference. No is a legitimate answer. An unanswered field is not, and an auditor reading a run of blanks in that column is reading evidence that 10.2.1 e) is not implemented. MSI's risk management procedure template carries the same interface from the other side, which is the only way the link holds: both documents have to name it.

A nonconformity is empirical evidence about a risk assessment. Clause 10.2.1 e) is the one line in ISO 9001 that requires the evidence to travel back to the register that got it wrong.

Preventive action is gone from ISO 9001, and procedures still cite it

ISO 9001:2015 removed the preventive action clause and distributed its intent into risk-based thinking at Clause 6.1. A corrective action procedure that still routes work through a preventive action workflow is describing a structure the standard no longer contains. This shows up most often in documents converted from a 2008-era system, and in documents produced by generative tools trained on older material. It is worth a search-and-check before you adopt anything.

Note the asymmetry, because it matters for anyone running both quality standards: preventive action is gone from ISO 9001 and very much alive in ISO 13485 at Clause 8.5.3. A shared document has to carry it for one scope and not the other, which is exactly the kind of divergence that has to be decided once, in writing, rather than improvised.

What is coming next is worth writing for now rather than later. The ISO 9001:2026 FDIS ballot closed on 9 July 2026 and publication is expected around September 2026. Corrective action is expected to remain at 10.2. Build the corrective action procedure to the edition your certificate is issued against, and build it so the clause cross-reference table is the only thing that has to change when the new edition lands. That is a drafting decision too: a procedure that quotes clause numbers throughout its body is a procedure you will rewrite.

THE ISO 9001 DOCUMENT

The ISO 9001 Corrective Action Procedure Template and Guide

A complete, editable Clause 10.2 procedure in Microsoft Word — written as a filled-in worked example rather than an outline, with the judgment calls already made and explained. It carries the risk-register interface as a closure field rather than an intention, the correction and corrective action routes separated at the form, the effectiveness review with a defined interval, and the eight-element maturity ladder the free check scores you against. Bracketed placeholders only where a value is genuinely yours to set.

See the ISO 9001 template →


ISO 13485

What ISO 13485 Forces Into Your Corrective action procedure

Prompt. Proportionate. Proven.

ISO 13485 puts corrective action at Clause 8.5.2, and it does something none of the harmonized standards do: it mandates a documented procedure by name. The document is itself an inspectable artifact. That distinction became sharper on 2 February 2026, when the FDA's Quality Management System Regulation took effect and incorporated ISO 13485:2016 into 21 CFR Part 820 by reference. Your corrective action procedure is now a regulatory document as well as a quality one.

Note first what ISO 13485 does not share. It predates the harmonized ten-clause structure, so its numbering does not map across to ISO 9001, ISO 14001, ISO 45001 or ISO 7101. A device organization that renumbers a quality document into 8.5.2 has produced a cross-reference table that will not survive its first serious read.

Without undue delay

The clause requires that any necessary corrective actions be taken without undue delay, and that they be proportionate to the effects of the nonconformities encountered. Those two phrases pull in opposite directions and a working corrective action procedure has to reconcile them rather than quote them.

Without undue delay is not a number, which means someone has to supply one. The defensible route is to tier it: severity determines the clock, the clock is written into the procedure, and any breach of it is itself recorded with a reason. An organization that leaves the phrase unquantified has, in practice, no delay standard at all — and discovers this when an inspector asks what undue means here and the answer is reconstructed in the room. Proportionality then works in the other direction, keeping the full investigative machinery off events that do not warrant it.

DIRECT ANSWER

What does ‘without undue delay’ mean in an ISO 13485 corrective action procedure?

The standard does not define an interval, so the corrective action procedure has to. The defensible approach is a severity-tiered clock written into the document — each tier carrying its own target for initiating the investigation, completing it, and verifying effectiveness — with any breach recorded and reasoned rather than absorbed. An organization that leaves the phrase unquantified has no delay standard, and nothing to demonstrate conformity against.

The verification step that has no counterpart anywhere else

Clause 8.5.2 e) requires verification that the corrective action does not adversely affect the ability to meet applicable regulatory requirements, or the safety and performance of the medical device. Read that as what it is: a requirement to check that the fix did not break something else.

No other standard in this family asks for it, and it is the step most commonly missing from a device corrective action procedure. The reason it matters is that corrective actions are changes, and changes to a device or its process can affect a validated state, a registered specification, a labelling claim, or a risk file estimate. A material substitution that resolves a supply nonconformity may alter biocompatibility. A software change that closes a complaint may fall inside a submission. A process parameter change may invalidate the validation that permitted the process to run unverified.

A corrective action is a change. In a regulated product, an unassessed change is a new nonconformity with a longer fuse. Clause 8.5.2 e) exists because the fix is a risk event in its own right.

In the document this becomes a mandatory gate before closure, with two named signatures — regulatory and technical — and an explicit route back into the risk management file and the change control process. It cannot be a checkbox on the same form the originator fills in, because the originator is rarely the person who knows what the registration says.

Preventive action still exists

Clause 8.5.3 remains a separate requirement in ISO 13485, and it is a genuine one: determine action to eliminate the causes of potential nonconformities in order to prevent their occurrence. A device corrective action procedure written by adapting an ISO 9001 document will not have it, because ISO 9001 does not.

MSI's fuller treatment of the device side — the eight-source intake, the reportability clock, and the link into risk management — is in the guide to CAPA under ISO 13485, which goes deeper on complaint handling than this article does.

THE ISO 13485 DOCUMENT

The ISO 13485 Corrective Action Procedure Template and Guide

The Clause 8.5.2 documented procedure the standard mandates by name — editable Word, written to the device standard's own numbering rather than renumbered from a quality base. Carries the severity-tiered delay standard with the reasoning attached so you can defend the interval, the 8.5.2 e) regulatory and safety verification as a gate with two named signatures, the preventive action route at 8.5.3 that quality documents do not have, and the mapping to 21 CFR Part 820 as amended 2 February 2026.

See the ISO 13485 template →


ISO 14001:2026

What ISO 14001 Forces Into Your Corrective action procedure

Mitigate. Weigh. Prove.

ISO 14001:2026 was published on 15 April 2026, cancelling and replacing the 2015 edition, with a transition deadline of 30 April 2029. Corrective action remains at Clause 10.2, and it carries two things a quality corrective action procedure has no place to put.

Mitigation is a third activity, not a synonym for correction

The clause requires the organization to react to the nonconformity and, as applicable, take action to control and correct it, and deal with the consequences including mitigating adverse environmental impacts. That final phrase introduces a step with no counterpart in ISO 9001, and treating it as a restatement of correction is a drafting error with real consequences.

The difference is receptor-facing. Correction stops the nonconforming condition: the valve is closed, the discharge ends. Mitigation addresses the harm already released into the environment: the watercourse is remediated, the contaminated soil is lifted, the affected habitat is restored. Corrective action then removes the cause so it cannot recur. Three activities, three owners, three records — and an environmental corrective action procedure that offers one free-text box called action taken will reliably capture only the first.

DIRECT ANSWER

How is an environmental corrective action procedure different from a quality one?

ISO 14001 requires two things a quality corrective action procedure does not contain. First, correction must include mitigating adverse environmental impacts — a distinct activity addressing harm already released, separate from stopping the condition and separate from removing the cause. Second, the action must be appropriate to the significance of the effects, including the environmental impacts, which means significance rather than cost or convenience decides how much investigation an event receives.

Significance decides the response, not cost

Clause 10.2 requires corrective actions to be appropriate to the significance of the effects encountered, including the environmental impacts. In practice, most organizations triage by cost or by visibility. Those are the wrong variables, and they fail in a predictable direction: a small-volume release to a sensitive receptor scores low on both and high on significance.

The environmental corrective action procedure therefore has to route from the aspects and impacts register rather than from a generic severity matrix. The register already holds the significance determination. Where the corrective action procedure carries its own separate scale, the two drift apart within a year and the organization ends up with two answers to the same question. This is one of the interfaces worth naming on both sides, the same way ISO 14001 continual improvement depends on the corrective action loop actually removing causes rather than closing tickets.

The compliance chain, and the link where it breaks

Environmental nonconformities frequently involve a compliance obligation, and that creates a chain the corrective action procedure has to carry to its end. A compliance evaluation under Clause 9.1.2 identifies a shortfall. That shortfall is a nonconformity. It routes to Clause 10.2 for corrective action. And then the organization's knowledge and understanding of its compliance status has to be updated to reflect the resolution.

The last link is the one that breaks. The action completes, the finding closes, and the compliance register still reads non-compliant — or, worse, still reads compliant because it was never updated when the shortfall was found. MSI's article on evaluation of compliance covers the register side; the corrective action procedure owns the write-back, and it needs to be a required field at closure rather than a good habit.

TRANSITIONING TO THE 2026 EDITION

ISO 14001:2026 Procedure Templates and Guides — The Whole EMS, in a Week

Built for one specific person: the experienced EHS manager who does not need the standard explained, needs the documented spine revised against the 2026 text, and has a 30 April 2029 deadline. Every 2026-edition environmental procedure — corrective action included, with mitigation separated from correction and significance routing from the aspects register — plus the transition course, in one purchase. Editable Word, mapped change by change, written to the 2026 clause numbering rather than adapted from 2015 documents.

Get the ISO 14001:2026 bundle →

If you need the environmental corrective action document on its own rather than the whole transition set, the ISO 14001:2026 corrective action procedure template is available separately and carries the same mitigation, significance and compliance write-back structure.


ISO 45001

What ISO 45001 Forces Into Your Corrective action procedure

Participate. Rank. Reassess.

ISO 45001 Clause 10.2 covers incident, nonconformity and corrective action together, and it is the longest of the five. It carries three obligations that exist nowhere else, and all three change the shape of the document rather than adding a line to it.

Participation, not consultation

The clause requires the organization to evaluate the need for corrective action to eliminate the root causes with the participation of workers and the involvement of other relevant interested parties. The word is participation, and ISO 45001 distinguishes it from consultation deliberately: consultation is seeking views before deciding, participation is taking part in the decision.

That cannot be discharged from an office. A corrective action procedure satisfying this clause names who takes part in the cause evaluation, records their involvement as part of the investigation record rather than as an attendance list, and defines what happens when the workers closest to the work disagree with the conclusion. The disagreement route is the part that is almost never written, and it is the part that makes the participation real rather than nominal.

Clause 10.2 also requires the results to be communicated to workers and, where they exist, workers’ representatives. That is a second obligation hiding inside the first, and it belongs in the corrective action procedure as a step with an owner rather than as an assumption that findings circulate on their own. In most organizations they do not.

The hierarchy of controls, applied honestly

Clause 10.2 requires action to be determined and implemented in accordance with the hierarchy of controls. That has a specific and uncomfortable implication for the corrective action procedure: retraining and reminders sit at the bottom of the hierarchy, and they are the most common corrective actions recorded in any safety system.

A procedure that honours the clause forces the question in order — can the hazard be eliminated, substituted, engineered out, or controlled administratively, before personal protective equipment or instruction is selected — and requires a recorded reason whenever the chosen action rests at the lower levels. Not a prohibition. A recorded reason. That single field changes the distribution of actions in a safety system faster than any amount of training on root cause technique, because it makes the easy answer visible as a choice.

Retraining a person who already knew how is the most common ineffective corrective action in any management system, and the one that reliably produces the same finding twelve months later.

Assess the hazards the fix creates — before implementing it

Clause 10.2 e) requires the organization to assess occupational health and safety risks that relate to new or changed hazards prior to taking action. This is the safety counterpart to the device standard's 8.5.2 e), and it is equally often missing.

The pattern it exists to prevent is familiar to anyone who has run an integrated system. A guard is added and the machine is now cleaned through a smaller aperture. A bund is installed and drums are now lifted over a wall. A door is locked and the fire route is longer. Each is a competent response to the original finding that introduces a hazard nobody assessed, because the assessment happened when the project was scoped and the corrective action was not treated as a project.

In the corrective action procedure this is a gate: the proposed action is assessed for new or changed hazards, and the assessment is recorded, before implementation is authorised. Placement matters. Put it after implementation and it becomes a retrospective note. It is also the clearest example of why environmental and safety corrective actions have to be run as one process where both systems exist — the bund is an environmental control and a manual handling hazard, and only an integrated document sees both.

THE ISO 45001 DOCUMENT

The ISO 45001 Corrective Action Procedure Template and Guide

The Clause 10.2 incident, nonconformity and corrective action procedure in editable Word — with worker participation written into the investigation record rather than bolted on, the hierarchy of controls applied as a forced sequence with a recorded reason whenever an action rests at administrative or PPE, and the new-and-changed-hazard assessment placed as a gate before implementation rather than a note after it. Every judgment call made and explained.

See the ISO 45001 template →


ISO 7101

What ISO 7101 Forces Into Your Corrective action procedure

Gather. Act. Tell.

ISO 7101:2023 is the first international consensus standard for healthcare quality management, written by ISO/TC 304 rather than the committee behind ISO 9001. Its corrective action requirement sits at Clause 10.2 and it is the most prescriptive of the five, which is unusual and worth understanding rather than resenting.

Nine sources converging on one process

Where ISO 9001 leaves intake largely to the organization, ISO 7101 names the sources that feed the improvement process — among them incidents and near misses, complaints and service user feedback, audit findings, clinical outcome and performance data, risk assessment output, workforce feedback, and the results of compliance and regulatory activity. A healthcare corrective action procedure therefore has to be built around a wide intake rather than an audit-finding funnel.

That is a bigger drafting change than it sounds. Most procedures are written for one intake channel and then have other channels attached to them, which produces the parallel-workflow pattern: complaints handled in one system, incidents in another, audit findings in a third, and nothing that lets anyone see the same cause appearing in all three. The intake list belongs in Section 2 of the document, enumerated, with a named owner for each channel.

Eight elements, mandatory in the action itself

ISO 7101 also specifies what the action has to contain rather than only what the process has to do — what will be done, who owns it, by when, what resources are committed, how effectiveness will be measured, how it will be communicated, how it will be recorded, and how it will be reviewed. Eight elements. A free-text action field satisfies none of them reliably, which means the form design, not the procedure prose, is what determines conformity here.

DIRECT ANSWER

What makes an ISO 7101 corrective action procedure different in healthcare?

Three things. The intake is named rather than left open — nine sources converge on one process, so the corrective action procedure has to be built for wide intake rather than audit findings alone. The action itself has eight mandatory elements, which makes form design the point of conformity rather than procedure prose. And the service user affected is told what happened and what is being done about it — a communication obligation to the individual that no other standard in this family contains.

Telling the service user

The obligation that separates ISO 7101 from everything else in this family is the duty to communicate with the affected service user. Not the aggregate reporting that ISO 45001 requires to workers, and not the customer notification that a quality system might trigger commercially — a duty owed to the individual person affected, about what happened and what is being done.

In the corrective action procedure this is a step with an owner, a timeframe, a record, and a defined route for the case where communication is clinically contraindicated or the person cannot be reached. Healthcare organizations in jurisdictions with a statutory duty of candour will already recognise the shape; the standard's requirement runs alongside the statutory one rather than replacing it, and the procedure should reference both. MSI's guide to ISO 7101 documentation sets out where this document sits in the build order.

One caution worth stating plainly, because it affects how you use this section: ISO 7101 is new, adoption is early, and sub-clause numbering should be verified against your own copy of the standard before it is written into a controlled document. The obligations above are stable. The exact references are worth checking.

THE ISO 7101 DOCUMENT

The ISO 7101 Corrective Action Procedure Template and Guide

Healthcare's version, and the broadest of the five — the nine named sources enumerated as intake channels with an owner each, the eight mandatory action elements built into the record form rather than left to a free-text box, and the service user communication step written with an owner, a timeframe and a defined route for when disclosure is clinically contraindicated. Editable Word, written to ISO 7101's own structure rather than adapted from a quality base.

See the ISO 7101 template →


THE FIRST DRAFTING FAILURE

Why One Form Ruins a Corrective action procedure

Two. Jobs. Separate.

Everything above is standard-specific. What follows is true across all five, and it is the section worth reading even if you only run one system.

The most damaging single decision in a corrective action procedure is to capture correction and corrective action on the same form, in the same field, with one signature closing both. It is an easy decision to make. It looks efficient. It reduces paperwork. It is chosen deliberately by competent people who are trying to keep the system usable, and it produces a specific, predictable pathology.

How the failure actually unfolds

A nonconformity is raised. The originator does the obvious and necessary thing: quarantines the material, decides the disposition, records it. That entry is real work, honestly recorded. The form has one action field, so the disposition goes in it. There is a closure box below. The material has been dealt with, so the box is ticked.

The disposition record has now become the corrective action record. Nobody decided that. Nobody was negligent. The form permitted it, and under time pressure a form that permits something will get it. The finding is closed, correctly by the document's own rules, and no cause was ever examined.

Run this pattern for two years and the closure metrics are excellent. Ninety-four per cent closed within thirty days. The same six things keep happening. Both facts are true, and they are the same fact.

This is why recurrence is such a reliable diagnostic. If findings repeat in a system whose closure rate is strong, the problem is almost never effort or root cause technique. It is that the corrective action procedure never required a cause to be removed before permitting closure.

DIRECT ANSWER

Why do the same findings keep recurring when our closure rate is high?

Because a high closure rate measures correction, not cause removal. When a corrective action procedure captures both on one form with one closure signature, the disposition record becomes the corrective action record by default — the finding closes correctly by the document's own rules and no cause is ever examined. Recurrence alongside strong closure metrics is the signature of this failure, and it is fixed in the form design rather than in training.

What to write instead

  • Two records, explicitly linked. The correction record can close on its own — the material was dealt with, and that is a complete piece of work. The corrective action record is separate, opens only when the evaluation says a cause needs eliminating, and carries its own owner, its own dates and its own closure test.
  • A decision point between them, with criteria. The evaluation of the need for action is a real step every standard requires. Give it written criteria — severity, recurrence, regulatory or safety exposure, environmental significance — so that no corrective action required is a defensible recorded decision rather than a gap.
  • Different closure tests. Correction closes when the thing is dealt with. Corrective action closes when the condition that produced it no longer exists, verified against evidence, at an interval after implementation.
  • Different signatures. If the same person can close both without anyone else looking, the separation is nominal. At minimum the cause evaluation and the effectiveness verification need a second name.
  • Both counted separately in the metrics. Report corrections closed and corrective actions verified effective as two numbers. One number hides the failure; two numbers make it visible in a month.

THE DOCUMENTS THEMSELVES

ISO Procedure Templates and Guides — Written to a Finish, Not an Outline

Complete, editable Word procedures with the judgment calls already made and explained, bracketed placeholders only where a value is genuinely yours to set, and the same eight-element maturity ladder the free check scores against. Every procedure follows the same sixteen-section architecture, so adopting one teaches your people how to read the next. Written to each standard's own clauses rather than adapted from another — and purchasers receive the updated template at no charge when the standard it is built to is revised, which matters with ISO 9001:2026 expected in September.

See the full template library →


THE SECOND DRAFTING FAILURE

The Effectiveness Review Your Corrective action procedure Probably Does Not Have

Later. Evidence. Honest.

All five standards require a review of the effectiveness of the corrective action taken. Almost every corrective action procedure contains the sentence. Almost none of them contains a step that could actually perform it.

The tell is a signature dated the same day the action completed. That signature verifies that something was done. Effectiveness is a claim about what happened afterwards, and on the day the action completes there is nothing afterwards to look at. The review is satisfied on paper and unperformed in fact, and the corrective action procedure is what permitted it — because it asked for a signature without specifying when, against what, or by whom.

DIRECT ANSWER

How do you write an effectiveness review that actually verifies effect?

Separate it from completion in time, in evidence and in ownership. The corrective action procedure sets a defined interval after implementation before the review can occur; names the evidence that will be examined, chosen when the action is planned rather than when it is reviewed; assigns it to someone other than the person who implemented the action; and provides a route for not effective that reopens the cause analysis rather than extending the deadline. A signature dated the day the action completed verifies completion, not effect.

The four things the step needs

An interval, defined before the action starts. Long enough for the process to have run under normal conditions and produced observable output. The right interval is a function of cycle frequency, not of the calendar: a change to a monthly process cannot be verified in a fortnight, and a change to a process that runs forty times a day can be. Write the rule, not a single number.

Named evidence, chosen at planning time. This is the discipline that does the most work. Deciding what would demonstrate effectiveness while the action is being planned forces a testable statement of what the action is supposed to change. Deciding it at review time invites whatever is available to be read as success. Scrap rate for that defect mode over the following quarter. Recurrence count across the identified similar processes. Compliance status confirmed at the next evaluation. Named in advance, examined later.

A different person. The implementer is the worst-placed reviewer, not through dishonesty but because they know what they intended and will read ambiguous evidence generously. This is the same principle that keeps auditors off their own work, and it applies here for the same reason. MSI's article on internal audit follow-up covers the verification question from the auditor's side of the same interface.

A real route for ‘not effective’. If the only options are effective and extend the deadline, the review has no teeth. Not effective has to reopen the cause analysis — because a correctly implemented action that did not work is strong evidence the cause was misidentified, which is a more useful finding than a missed date. A corrective action procedure that cannot record its own failure cannot improve.

Where the results are supposed to go

Corrective action status is a named management review input in every one of these standards. That is the loop closing at the system level, and it is where a well-drafted corrective action procedure earns its keep: the review sees recurrence data, effectiveness verification outcomes, and overdue actions as evidence about the management system rather than as a status table.

What arrives at that meeting is determined by what the procedure required to be recorded. If the corrective action procedure captured one number, leadership sees one number.

WHERE THE LOOP CLOSES

ISO Management Review Tool Kits — Make Corrective Action Status a Real Input

Corrective action status is a required management review input in ISO 9001, ISO 13485, ISO 14001, ISO 45001 and ISO 7101 — and it is the input most often presented as a closure percentage that tells leadership nothing. The Tool Kits give each required input a producing role, a frequency and a place the record lives before the meeting opens, so the review examines whether causes are being removed rather than whether forms are being closed.

See the Management Review Tool Kits →


THE DOCUMENT ITSELF

The Sections a Corrective action procedure Actually Needs

Trigger. Route. Record.

Structure is the easy part of a procedure, and it is where most template libraries stop. What follows is the set of sections where the hard decisions live, with what each one has to settle. MSI writes every procedure to the same sixteen-section architecture, which is what makes a library compound rather than accumulate — but the sections below are the ones specific to this document. If you are writing several procedures rather than one, the order you build them in changes how much rework you do — MSI's guide to ISO procedure order sets out the sequence and why corrective action depends on three documents existing first.

1. Triggers — every channel a nonconformity can arrive by

Enumerate them. Internal audit findings, external audit findings, customer complaints, supplier nonconformities, in-process and final inspection rejects, process monitoring excursions, incidents and near misses, compliance evaluation shortfalls, regulatory observations, service user feedback, employee reports. If a channel is not listed, it will be handled somewhere else, and the organization will not see the same cause arriving three different ways. Two triggers almost nobody writes down are worth adding: an action that has been extended twice, and a recurrence of something previously closed.

2. The evaluation decision, with criteria that have numbers in them

Not every nonconformity earns a corrective action. Write the criteria that make the decision: severity tier, recurrence within a defined window, regulatory or safety exposure, environmental significance drawn from the aspects register, service user harm. Give the decision a named owner and a recorded rationale. A defensible no is one of the most valuable outputs a corrective action procedure produces, and it only exists if the criteria are written.

3. Similar and potential occurrences

Every one of the five requires the organization to determine whether similar nonconformities exist or could potentially occur. In practice this is the most frequently skipped sub-requirement in the clause, because it is the one that expands the work. Write it as a scoped question — which other products, lines, sites, shifts, service areas or processes share this mechanism — with the scope examined recorded. Recording which areas were checked is what makes the answer evidence rather than assertion.

4. Roles, with a named alternate on every gate

Assign one accountable owner per stage and a named alternate for every gating role. Procedures stall at named individuals who are on leave, and the stall is invisible until the report. Where the roles named do not exist on your org chart, the procedure is fiction — a common failure in adopted documents, which tend to assume a Quality Director in organizations that have never had one.

5. The records table, with no blanks

Every record: what it is, where it lives, who owns it, how long it is kept. All five standards require documented information on the nature of the nonconformities, the actions taken, and the results. An undetermined retention period reads, to anyone examining it, as a decision never made. This is also the interface to document and records control, and both documents should name it.

6. Indicators — measure the intake, not only the output

Closure rate and average days to close are the standard pair, and both measure administrative throughput. Add measures that describe whether the system is working: recurrence rate for previously closed causes, proportion of actions verified effective at review, distribution of actions across the hierarchy of controls where ISO 45001 applies, and intake volume by channel.

That last one is the most undervalued measure in the set. A corrective action procedure only ever sees what people are willing to raise, so a falling intake is ambiguous — it means either fewer problems or less reporting, and those are opposite conditions. Intake by channel, trended, is the earliest available signal that the system has stopped being used, and it arrives long before an auditor does.

7. Review triggers that are event-based

An annual review is a backstop, not a trigger. Real triggers: a change to the standard or to applicable regulation, a change to the software the process runs in, a finding raised against the procedure itself, a recurrence of a previously closed cause, a reorganisation that moves an owning role. A platform migration silently invalidates half of most procedures and nobody re-reads them when the tool changes.


TWO WORKED EXAMPLES

What a Corrective action procedure Looks Like When It Works

Small. Cause. Consequence.

Both examples are composites drawn from patterns MSI has seen repeatedly across 200+ audits attended. They are deliberately different in shape, because the two failure modes they illustrate are the two a corrective action procedure most needs to survive.

Example one: the low-value part with the high-value consequence

A retaining clip costing a few cents is found out of specification at final assembly. Severity triage keys on part value and unit cost, and the event is coded low. Disposition is straightforward: the batch is scrapped and replacements are pulled from stock. Closed in two days, no corrective action, and by the rules of the procedure that is entirely correct.

Four months later a field failure traces back to the same clip in units built before the nonconformity was detected. The clip was a low-value part in a load-bearing position. Nothing in the triage criteria asked about consequence — only about cost.

The drafting lesson is precise and it applies to every one of the five standards: triage on effect, not on value. ISO 13485 requires proportionality to the effects of the nonconformity. ISO 14001 requires appropriateness to the significance of the impacts. ISO 45001 requires appropriateness to the effects or potential effects. None of them says cost. A corrective action procedure whose severity matrix is built from value will systematically under-respond to exactly the events that matter most, and it will do so consistently, which is what makes it hard to notice.

The correction to the document is one row in the triage criteria: what does this item do in the finished product, the process, or the service — and what happens if it does not do it? A clip in a load path answers that question differently from a clip in a cosmetic trim, at the same unit cost.

Example two: the entry that closed twice

A nonconformity is raised against a work instruction that does not reflect how a process actually runs. Cause is determined as document not updated after process change. The corrective action is to update the work instruction. Implemented, verified, closed. Correct, on its own terms.

Eleven months later the same finding is raised against a different work instruction in the same area. Cause: document not updated after process change. Action: update the work instruction. Implemented, verified, closed.

Both entries are individually defensible. Together they are a system finding, and no step in the procedure was capable of seeing it — because each event was evaluated in isolation and the similar-occurrences question was answered against products rather than against the mechanism. The actual cause is upstream: process changes are being made without triggering a documentation review, which is a change control failure appearing in the corrective action log wearing a document control costume.

When the same cause code appears twice, the second entry is not a second problem. It is evidence that the first analysis stopped one level too early.

Two drafting corrections follow. First, the similar-occurrences question is asked against the mechanism, not the artifact: where else could a process change happen without a documentation review? Second, the procedure carries a recurrence trigger — a repeat cause code within a defined window automatically escalates to a review of the analysis itself, not a new instance of the same action. Without that trigger the log can run indefinitely, closing correctly every time, while the mechanism producing the findings goes permanently unexamined. Related change control patterns are covered in MSI's work on ISO 9001 change management.

IF YOU WANT A SECOND PAIR OF EYES

Talk Through Your Own Procedure — 760-434-9141

If you have a document and you are not sure whether it does these things, a planning session with MSI walks your existing procedure against the clause your certificate is issued to and names what is missing and what is simply written differently — which are not the same finding and should not get the same response. No obligation, and if the honest answer is that your procedure is sound, that is the answer you will get.

Call 760-434-9141 →


SCORING YOUR OWN

How to Tell Whether Your Corrective action procedure Is Working

Score. Diagnose. Decide.

A single verdict on a corrective action procedure is not much use, because most organizations are not uniformly weak. They are strong on intake and weak on effectiveness verification, or strong on analysis and weak on the similar-occurrences question. Scoring element by element tells you which one to fix first, and that is the only part of the answer that changes what you do on Monday.

The eight elements MSI scores, each across four levels — Documented, Controlled, Measured, Anticipatory — described as observable behaviour rather than intention:

  • Intake — every channel enumerated, each with an owner, and the volume by channel trended rather than aggregated.
  • Separation — correction, mitigation where the standard requires it, and corrective action recorded distinctly, with different closure tests.
  • Evaluation — the need for action decided against written criteria, with a defensible recorded no available.
  • Cause analysis — proportionate to effect, reaching the mechanism rather than the artifact, and involving the people who do the work where the standard requires it.
  • Extent — similar and potential occurrences determined against the mechanism, with the scope examined recorded.
  • Action selection — proportionate, ranked by the hierarchy of controls where applicable, and assessed for the hazards or risks the action itself introduces.
  • Effectiveness — verified at a defined interval after implementation, against evidence named at planning time, by someone other than the implementer.
  • Interfaces — risk register, change control, document control, compliance status and management review, each named on both sides.

Worth saying outright: Controlled is a legitimate place to stop. A well-implemented certified system sits there and works. Conformity is a threshold, not a destination, and a corrective action procedure pushed to the top rung on every element describes a system nobody will run. The point of the ladder is to show you the rung above the one you are on, not to imply that anything below the top is a deficiency.

START HERE IF YOU START ANYWHERE

The Free Corrective Action Maturity Check — Eight Elements, About Six Minutes

Score your own process against the eight elements above, on how it behaves on a busy week rather than on how the document describes it. Your score, your band and the element most organizations score lowest on appear immediately, with nothing to enter first. Enter your details afterwards and you also get the element-by-element breakdown and the full maturity framework, with a blank scoring worksheet to take into your next management review. Covers all five standards, whether or not you are certified.

Score your process free →


THE WIDER SYSTEM

Where the Corrective action procedure Sits

Feeds. Serves. Connects.

A corrective action procedure is not a standalone document and the most common structural weakness in a management system is a set of procedures that were each written well and never introduced to one another. Five interfaces matter enough to name in the document itself, on both sides:

  • Risk management — ISO 9001 10.2.1 e) requires the write-back, and ISO 45001 requires existing risk assessments to be reviewed. The risk management procedure has to name the same interface or the link is one-directional and dies.
  • Change control — every corrective action is a change, and an unassessed change is how a fix creates the next finding.
  • Document and records control — a large proportion of corrective actions terminate in a document revision, which means the two procedures are in constant contact.
  • Internal audit — the largest single intake channel in most systems, and the one whose follow-up discipline determines whether findings are closed or resolved. MSI's internal audit work and the ISO 19011:2026 internal audit procedure guidance both sit on this boundary — and ISO 19011:2026 withdrew the 2018 edition outright on 27 May 2026 with no transition period, so procedures still citing the old edition are carrying a documentation finding.
  • Management review — corrective action status is a required input in all five standards, which makes the corrective action procedure a supplier to the governance layer rather than a quality department artifact.

Getting those five named on both sides is most of what separates a library that compounds from a folder that accumulates. Organizations building more than one procedure at a time usually find it faster to adopt a set written to interlock than to reconcile documents drafted independently — which is the argument for taking a standard as a set rather than a procedure at a time. Where the work needs an outside view, MSI's ISO consulting engagements start from the same architecture, and SurePath and SureResults carry it into implementation and year-round maintenance respectively.

For leadership weighing whether any of this is worth the investment, the ISO Executive Decision Briefs are leadership-level videos on what a management system is supposed to produce. Free, no form — watch them before committing budget rather than after.


COMMON QUESTIONS

Corrective action procedure — Questions People Ask While Drafting

Ask. Answer. Apply.

Do I need a documented corrective action procedure?

ISO 13485 mandates one by name at Clause 8.5.2, so for a device organization the answer is unambiguously yes — and since 2 February 2026 it is an FDA-inspectable document under 21 CFR Part 820 as well. ISO 9001, ISO 14001, ISO 45001 and ISO 7101 do not use the phrase ‘documented procedure,’ but all four require documented information on the nature of nonconformities, the actions taken and the results, and all four require the process to be consistent and repeatable. In practice a documented corrective action procedure is how organizations demonstrate that, and MSI has not seen a system pass surveillance repeatedly without one.

How long should a corrective action procedure be?

Long enough to force every decision the process requires and short enough that the person doing the work will read it. In practice that is usually fifteen to thirty pages for the procedure, with the forms, register and desk-level work instruction as appendices. Length is the wrong measure: the test is whether a competent person who has never seen your system could raise, evaluate, investigate, action, verify and close a nonconformity using only the document. If they would have to ask someone, the procedure is a description rather than an instrument.

Can one corrective action procedure cover several standards?

Yes, and for organizations running integrated systems it is usually the better answer — provided every divergence is identified and decided in writing rather than averaged away. Quality and environment is the pairing that catches people out most, because the shared harmonized structure makes one process look obviously right. The document has to carry the strictest requirement in each case: worker participation from ISO 45001, mitigation and significance routing from ISO 14001, the risk-register write-back from ISO 9001, and the regulatory verification and preventive action route from ISO 13485. What does not work is one document with the standard's name changed at the top, because the obligations genuinely differ.

Does preventive action still exist?

It depends which standard governs you, and this catches people running two systems. ISO 9001 removed preventive action in 2015 and distributed its intent into risk-based thinking at Clause 6.1. ISO 13485 retains it as a distinct requirement at Clause 8.5.3. ISO 14001 and ISO 45001 follow the ISO 9001 approach. A corrective action procedure for a device organization needs the preventive action route; a quality-only document that still contains one is describing a structure the standard no longer has.

How many root cause techniques should the corrective action procedure specify?

Specify a small set and the criteria for choosing between them, rather than mandating one or leaving it open. Five Whys is adequate for straightforward single-path events and inadequate for anything with interacting causes. Fishbone and fault tree analysis earn their overhead on complex or high-consequence events. The decision that belongs in the procedure is which technique applies at which severity tier — because a mandated heavyweight method on trivial events is the fastest route to a system people work around.

What interval should the effectiveness review use?

Long enough for the process to have run under normal conditions and produced observable output, which makes it a function of cycle frequency rather than of the calendar. Write the rule rather than a single number: a change to a process running many times a day can be verified in weeks, a change to a monthly process cannot. Tie the review to a named piece of evidence chosen when the action was planned, and give not effective a route that reopens the cause analysis rather than extending the deadline.

Our closure rate is above ninety per cent. Is our corrective action procedure working?

That number alone cannot answer the question, because closure measures correction and not cause removal. The diagnostic pair is closure rate alongside recurrence rate for previously closed causes. Strong closure with visible recurrence is the signature of a procedure that captures correction and corrective action on one form — findings close correctly by the document's own rules and no cause is ever examined. Add the second number and the picture resolves within a month.

What changes for corrective action under ISO 9001:2026?

The FDIS ballot closed on 9 July 2026 and publication is expected around September 2026, with corrective action expected to remain at Clause 10.2. Build to the edition your certificate is currently issued against, and structure the document so that clause numbers live in a cross-reference table rather than being quoted throughout the body — then the transition is a table update rather than a rewrite. MSI's ISO 9001 templates are rebuilt to the new edition and reissued to purchasers at no charge when it publishes.


WHAT TO DO NEXT

Writing the Corrective action procedure That Holds

Separate. Verify. Connect.

If you take three things from this into your own document: separate correction from corrective action at the form, not in the prose. Put an interval, named evidence and a different signature on the effectiveness review. Name the five interfaces on both sides.

Everything else is refinement. Those three decide whether the corrective action procedure removes causes or records activity, and all three are made at the drafting stage by whoever is holding the page.

Score what you have first — the free corrective action maturity check takes about six minutes and asks for nothing before it gives you an answer. If the result says the document needs rebuilding rather than adjusting, the ISO procedure templates and guides are complete working procedures with the judgment calls already made. If you would rather talk it through with someone who has read a few hundred of these, call MSI on 760-434-9141 and ask for a planning session.

References — Sources and Further Reading

KEEP READING

Related Reading

GUIDE

CAPA Under ISO 13485

The device side in depth — complaint intake, the reportability clock, and the link into risk management.

GUIDE

Internal Audit Follow-Up

The verification question from the auditor's side of the same interface.

GUIDE

Continual Improvement in ISO 9001

Clause 10.3 — the forward engine that only compounds when the reactive one removes causes.

GUIDE

ISO 14001 Continual Improvement

Proving the chain on the environmental side, with baselines rather than statements of intent.

TEMPLATE

Risk Management Procedure Template

The other side of the Clause 10.2.1 e) interface — register design across all five standards.

GUIDE

Human Resource Management Procedure

Why retraining a person who already knew how is the most common ineffective action.

GUIDE

Quality Improvement Culture

The seven sub-requirements inside Clause 10.2, and the ones organizations skip.

GUIDE

Evaluation of Compliance

The compliance register the environmental corrective action chain has to write back to.

GUIDE

Control of Monitoring and Measuring Equipment

The out-of-tolerance impact assessment — a corrective action trigger most registers miss.

GUIDE

ISO 13485 Management Review

Where corrective and preventive action status lands among the twelve Clause 5.6.2 inputs.

STANDARD

ISO 9001 — Quality

The quality management standard, and what certification to it actually involves.

STANDARD

ISO 13485 — Medical Devices

The device QMS standard, and how QMSR changed what it means in the United States.

STANDARD

ISO 14001 — Environmental

The environmental management standard, now in its 2026 edition.

STANDARD

ISO 7101 — Healthcare Quality

The first international standard for healthcare quality management systems.

ASSESSMENT

The Portrait

An independent operational assessment that traces a real work order through every hand.

GUIDE

ISO 9001 and 14001 Transition

Running both revisions as one programme rather than two — and why that is the cheaper plan.

GUIDE

ISO Procedure Order

The sequence to build procedures in, and the rework the wrong order guarantees.

GUIDE

ISO 7101 Documentation

The order to build a healthcare quality management system's documents in.

ABOUT MANAGEMENT SYSTEMS INTERNATIONAL (MSI)

Diana Lynn is President and Principal ISO Consultant at Management Systems International (MSI), a consulting firm she co-founded in 1998. With 28 years of experience including extensive AS9100 work in MSI’s early years, MSI’s track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.

MSI is veteran-owned and female-owned. msi-international.com · 760-434-9141


Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 13 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply