Corrective and Preventive Action: ISO 13485’s Proven Engine

Corrective and preventive action is the clause where ISO 13485 stops being a filing system and starts being a safety system. Every other requirement in the standard produces information — complaints, audit findings, nonconforming product, supplier defects, post-market signals. Corrective and preventive action is the only process that is obligated to do something with it. And since February 2, 2026, when the FDA's Quality Management System Regulation took effect and pulled ISO 13485:2016 into federal law by reference, the way a device manufacturer runs corrective and preventive action is no longer just an auditor's concern. It is an investigator's.

Direct Answer: Corrective and preventive action (CAPA) under ISO 13485 is the documented loop that identifies a problem or potential problem, investigates it to root cause at a depth proportionate to the risk, implements action, verifies that the action was effective, and records the whole chain as evidence. ISO 13485 splits it across two clauses — 8.5.2 for corrective action (problems that happened) and 8.5.3 for preventive action (problems that have not happened yet). Unlike ISO 9001:2015, which folded preventive action into risk-based thinking, ISO 13485 deliberately kept both. Corrective and preventive action is the standard's improvement engine, and under the FDA QMSR it is now federally inspectable.

Corrective and preventive action under ISO 13485

Across 200+ certification and surveillance audits, Management Systems International (MSI) has watched a consistent pattern hold: the corrective and preventive action file is the first place a competent auditor goes and the last place an organization has actually invested. Design controls get attention because they are visible. The medical device file gets attention because it is unmistakably required. Corrective and preventive action gets a spreadsheet, an owner who inherited it, and a quiet backlog of open records nobody wants to explain.

This guide walks the entire loop — what the clauses actually demand, the seven operational steps, the five failure modes that reliably produce findings, what changed when the FDA QMSR replaced the old Quality System Regulation, what the next edition of ISO 9001 adds to the picture, and how a corrective and preventive action system that works becomes the single most persuasive piece of evidence a device organization can put in front of a regulator.


THE REQUIREMENT

What Is Corrective and Preventive Action Under ISO 13485?

Two clauses. One loop. Zero shortcuts.

The single most common misconception about corrective and preventive action is that CAPA is one process. It is not. ISO 13485:2016 writes it as two distinct requirements, sitting side by side in Clause 8.5:

  • Clause 8.5.2 — Corrective action. Action to eliminate the cause of a nonconformity that has already occurred, to prevent it from recurring. The organization must document a procedure covering review of the nonconformity, determination of cause, evaluation of the need for action, planning and documenting the action, verification that the action does not adversely affect the ability to meet regulatory requirements or device safety and performance, and review of the effectiveness of the action taken.
  • Clause 8.5.3 — Preventive action. Action to eliminate the cause of a potential nonconformity, to prevent it from occurring at all. Same procedural rigor. Different trigger.

Two clauses, two triggers, one shared discipline. In practice, most device organizations run them through a single procedure with a classification field — and that is fine, provided the records demonstrate that preventive action is genuinely happening and not just a checkbox that nobody has ever ticked. An empty preventive action register is one of the fastest findings an experienced auditor can write.

Direct Answer: ISO 13485 places corrective and preventive action in Clause 8.5.2 and Clause 8.5.3 respectively. Corrective action addresses causes of nonconformities that occurred; preventive action addresses causes of nonconformities that could occur. Both require a documented procedure, root cause determination, action planning, verification that the action does not compromise regulatory compliance or device safety, and a review of effectiveness. Corrective and preventive action records are among the first documents an FDA investigator or notified body auditor will request.

It matters that ISO 13485 keeps its own architecture here. The standard deliberately retained the pre-Annex SL structure — it is not built on the harmonized ten-clause backbone that ISO 9001, ISO 14001, and ISO 45001 share. So a team arriving from ISO 9001 looking for “Clause 10.2” will not find it. The corrective and preventive action requirements live at 8.5.2 and 8.5.3, and the surrounding furniture — document control at 4.2.4, records at 4.2.5, the medical device file at 4.2.3 — sits where ISO 9001:2008 left it. MSI's guide to document control across the standards maps this difference clause by clause, and the free document control maturity check scores your own version of it in about six minutes.

If you are writing the document rather than researching the clause, MSI's cross-standard pillar on how to write a corrective action procedure covers the drafting decisions that determine whether the finished document works — the two failures that account for most recurring findings, and what each of the five standards forces into the procedure that the others do not.


THE DIVERGENCE

Why ISO 13485 Kept Preventive Action When ISO 9001 Dropped It

Deliberate. Defensible. Device-specific.

When ISO 9001 moved to the 2015 edition, it removed the standalone preventive action clause and absorbed the intent into Clause 6.1, risks and opportunities. The logic was sound for general quality management: if you are systematically identifying and treating risk during planning, you are already doing preventive action, and a separate clause is redundant machinery. ISO 14001 and ISO 45001 followed the same path.

ISO 13485 did not follow. It kept preventive action as an explicit, separately auditable requirement — and that decision was not an oversight. In a medical device context, the distinction between “we manage risk during design” and “we take documented action on a potential nonconformity we have detected in the running system” is the distinction between a hazard analysis and a recall that never happened. Risk-based thinking is anticipatory. Preventive action is responsive to a signal — a trend in complaint data, a supplier drifting toward the edge of specification, a competitor's field safety notice on a similar device. Corrective and preventive action, taken together, gives the device organization a formal home for both halves.

“In quality, a corrective action tells you what you survived. A preventive action tells you what you never had to.”

— Diana Lynn, President, Management Systems International

The practical consequence for an organization holding both ISO 9001 and ISO 13485 is that one corrective and preventive action procedure can serve both, but it must be written to the stricter parent. Build to ISO 13485's requirements and ISO 9001 Clause 10.2 is satisfied automatically. Build to ISO 9001 alone and the preventive action records will not exist when the notified body asks for them. MSI's work on integrated management systems is built on exactly this principle: write once, to the highest bar, and satisfy every standard in scope.

Direct Answer: ISO 9001:2015 removed the preventive action clause and folded it into risk-based thinking under Clause 6.1. ISO 13485:2016 kept preventive action as a standalone requirement at Clause 8.5.3 because device risk demands a documented, auditable response to potential nonconformities detected in the operating system — not only risk anticipated during design. An organization certified to both standards should write one corrective and preventive action procedure to the ISO 13485 bar; doing so satisfies ISO 9001 Clause 10.2 at the same time.

THE DOCUMENT THIS ARTICLE DESCRIBES

ISO 13485 Corrective Action Procedure Template — Clauses 8.5.2 and 8.5.3

Everything below this box describes what a corrective and preventive action procedure has to contain. This is that procedure, already written — a complete, editable Microsoft Word document rather than an outline with the hard parts left blank. Correction and corrective action separated at the form, so a record cannot close on containment alone. Root cause method selected by risk tier instead of by whoever is assigned. Effectiveness review with a defined interval and pre-declared evidence, which is the step Clause 8.5.2 requires and most systems quietly skip. The preventive action route at 8.5.3 given its own trigger list, so the register does not sit empty until the week before an audit. And the regulatory-impact check written in as a gate, because since February 2026 the records this procedure creates are inspectable under 21 CFR Part 820.

Bracketed placeholders appear only where a value is genuinely yours to set — thresholds, roles, intervals, retention periods. Every judgment call is already made and annotated from 200+ audits attended.

SEE THE ISO 13485 CORRECTIVE ACTION TEMPLATE →

Holding ISO 9001 and ISO 13485 together? The combined ISO 9001 + ISO 13485 version covers Clause 10.2 and Clauses 8.5.2 / 8.5.3 in one register and carries an integration decision record naming every divergence, so the auditor's question is already answered in writing. Not sure where your current process actually sits? The free Nonconformity and Corrective Action Maturity Check scores eight elements across four levels in about six minutes. Your score and band appear immediately, no details required. If the result is useful on its own, take it and act on it.

THE PROCESS

The Seven Steps of the Corrective and Preventive Action Loop

Catch. Correct. Continually improve.

A working corrective and preventive action procedure has seven steps. Organizations that skip one usually skip the same one — step six.

1. Identification and Intake

Define the triggers explicitly in the procedure, or the system will only ever see what someone remembers to report. The standard set: customer complaints, internal audit findings, external audit findings, nonconforming product, supplier nonconformity, process monitoring data out of control, post-market surveillance and vigilance signals, servicing and installation reports, and management review outputs. Each needs a named route into the corrective and preventive action system and a named person who owns intake.

Complaint handling deserves special mention because ISO 13485 Clause 8.2.2 is explicit: if a complaint is not investigated, the justification must be documented. That is one of the most reliably missed records in the entire standard — and it is trivially easy for an investigator to sample.

2. Evaluation, Risk Assessment, and Escalation

Not every issue deserves a full corrective and preventive action record. Trying to run one for every deviation collapses the system under its own weight — and an overloaded CAPA queue is itself a finding. The procedure needs a documented triage: assess severity, scope, detectability, and patient risk, then decide whether the issue is handled as a correction, escalated to corrective action, or routed to preventive action.

This is where the risk file connects. ISO 14971 is the risk management standard ISO 13485 Clause 7.1 points to, and a corrective and preventive action record that changes the hazard picture must feed back into the risk management file. If your CAPA system and your ISO 14971 file do not talk to each other, you have two systems and one of them is lying. That interface is a closure field, not an intention — which is why MSI's ISO 13485 risk management procedure template names what feeds risk and what risk hands on, and why the guide to writing a risk management procedure treats corrective action as one of the three interfaces that fail most often. If you would rather see where yours stands first, score your current risk process free — about six minutes, no details required.

Escalation criteria also belong here: at what threshold does an issue trigger a field safety corrective action, a regulatory notification, or an advisory notice? Those criteria must be written down before you need them, not improvised while the clock runs.

3. Root Cause Analysis — Proportionate to Risk

The governing principle: the depth of investigation should be proportionate to the level of risk. A low-risk labeling typo does not need a fault tree. A sterilization excursion does.

The procedure should name the methods and say when each applies. ASQ's root cause analysis resources catalogue the standard toolkit — 5 Whys for simple, single-thread causes; fishbone (Ishikawa) when the cause could sit in any of several categories; FMEA when you are analyzing failure modes across a design or process; fault tree analysis when a serious harm needs to be traced backward through combinations of contributing events.

Two tells that root cause analysis has failed, both of which auditors recognize instantly. First: the root cause is “human error.” Human error is a symptom, not a cause — the cause is whatever made the error possible and undetected. Second: the corrective action is “retrain the operator.” Retraining is almost never a root cause fix; it is what organizations write when they have not found one.

Note also that root cause work performed for corrective and preventive action frequently surfaces preventive opportunities elsewhere — the same failure mode sitting undetected in an adjacent product line or process. Capturing that is the whole point of Clause 8.5.3.

4. Action Planning

Every action in a corrective and preventive action plan needs three attributes an auditor can verify: an owner (a person, not a department), a due date, and a definition of what “done” looks like. Plans that fail audit are almost always plans that fail one of those three. The plan must also address the “similar nonconformities elsewhere” question — ISO 13485 expects the organization to determine whether the same cause is present in other processes, products, or sites.

5. Implementation — Including the Impact Check

Actions land in procedures, work instructions, tooling, specifications, supplier agreements, or training. This is also where ISO 13485 adds a requirement ISO 9001 does not: before implementing, the organization must verify that the corrective and preventive action does not adversely affect the ability to conform to regulatory requirements or the safety and performance of the device. Changing a process to fix one problem can create another, and in a device context that consequence can reach a patient.

If the action touches a design output, it becomes a design change under Clause 7.3.9 — which, since the QMSR, is federal law in the United States for finished devices in commercial distribution. MSI covers that intersection in its guide to change management automation across ISO 9001 and ISO 13485. Where the action lands in production — a revised work instruction, a new inspection point, a changed acceptance criterion — it lands inside the Clause 7.5 production and service procedure, which is where an investigator will look for evidence that it actually took hold. Where it lands in competence — a revised qualification, a re-evaluation after training — it lands inside the Clause 6.2 human resource management procedure, which is where the evaluation-of-effectiveness record has to exist before “retrain the operator” can ever be a defensible action.

6. Verification of Effectiveness — The Step Everyone Skips

This is the step that separates a corrective and preventive action system from a ticketing system, and it is the step most organizations quietly do not perform.

Completion is not effectiveness. “The procedure was revised” is completion. “The revised procedure has been in effect for two quarters and the defect rate that triggered this record has not recurred” is effectiveness. The standard requires the latter. That means the record must define, up front, what evidence will demonstrate that the action worked, over what period, and measured how. Then someone has to go back and look.

MSI's methodology for internal audit follow-up draws the same bright line, and it applies identically to corrective and preventive action: a record is only truly closed when the root cause was correctly identified, objective evidence shows the action was implemented, and the condition that produced the nonconformity no longer exists. Anything less is paperwork. Auditors themselves are now working to a newer rulebook here: ISO 19011:2026 published on May 27, 2026 and cancelled the 2018 edition outright, with no transition period. If your internal audit programme still cites the withdrawn edition in its procedure, that is a documentation finding waiting to be written.

7. Documentation and Closure

Every step generates a record, and the records must be retained and retrievable under Clause 4.2.5. The corrective and preventive action file is not merely an audit artifact — over time it becomes the organization's institutional memory of what actually goes wrong and what actually fixes it. That is a genuine asset. Organizations that mine their CAPA data for patterns typically find that a small number of root causes are responsible for the majority of their findings, which is exactly the insight leadership needs to allocate resources intelligently.

Direct Answer: The corrective and preventive action loop under ISO 13485 runs seven steps: identify and intake the issue from a defined trigger list, evaluate and risk-assess it, investigate to root cause at a depth proportionate to risk, plan actions with owners and dates, implement while verifying no adverse effect on regulatory compliance or device safety, verify effectiveness against pre-defined evidence, and document closure. Step six — effectiveness verification — is the one most organizations skip, and it is the one auditors sample hardest.

TWENTY-EIGHT YEARS OF PRACTICE, WRITTEN DOWN

Sixteen Sections. No Blanks Anywhere. Every Record Has a Retention Period.

A corrective and preventive action procedure does not work in isolation. It is fed by complaint handling, internal audit, nonconforming product, supplier control and risk — and it hands work to production, competence and management review. MSI's ISO Procedure Templates & Guides are those documents, written to ISO 9001, ISO 13485, ISO 14001:2026, ISO 45001 or ISO 7101 rather than find-and-replaced between them.

Not outlines with the hard parts left blank. The judgment calls are already made and explained, the decisions that are genuinely yours are marked, and every element carries MSI notes from 200+ audits attended — where it usually fails, why it fails structurally rather than through carelessness, and what a working version looks like. Corrective action, risk management, document and records control, purchasing and supplier control, monitoring and measuring equipment, human resource management, sales management, and control of production and service are all published now, written to one architecture so the set interlocks.

SEE THE PROCEDURE TEMPLATES & GUIDES →

Every family has a free maturity check built from it — eight elements, four levels, scored on whether the process holds on a busy week. Your score and band appear immediately. If the result is useful on its own, take it and act on it.

THE REGULATOR

What the FDA QMSR Changed for Corrective and Preventive Action

Inspectable. Federal. Now.

On February 2, 2026, the FDA's Quality Management System Regulation replaced the Quality System Regulation. 21 CFR Part 820 now incorporates ISO 13485:2016 by reference. For corrective and preventive action, three consequences matter more than the rest.

1. ISO 13485's CAPA clauses are now U.S. federal requirements. Clauses 8.5.2 and 8.5.3 are not “the international standard” anymore. For finished devices in commercial distribution in the United States, they are law.

2. Management review and internal audit reports are now inspectable. Under the old QSR, FDA investigators could not demand them. That exemption is gone. Since corrective and preventive action status is a mandatory management review input, the review record now exposes your CAPA performance directly to the investigator.

3. The inspection method changed. The FDA retired the Quality System Inspection Technique (QSIT) and moved to the Inspection of Medical Device Manufacturers Compliance Program 7382.850. The people walking through your building are working from a new script.

The practical translation: a corrective and preventive action backlog that used to be an internal embarrassment is now an inspectable liability. Historically, quality-system deficiencies have been among the most frequently cited categories in device FDA warning letters, and corrective and preventive action sits at the center of that category. MSI's detailed breakdown of the QMSR alignment with ISO 13485 walks through what device organizations need to have in place.

This is not a U.S.-only story. The Medical Device Single Audit Program (MDSAP) lets a single audit satisfy multiple national regulators, and the EU Medical Device Regulation expects a quality system that ISO 13485 satisfies. Harmonization work through the International Medical Device Regulators Forum continues to converge these expectations, and accreditation of the bodies that audit you now runs through Global ACI, which unified the former IAF and ILAC frameworks on January 1, 2026. One well-run corrective and preventive action system now answers to nearly every regulator a device company will meet.

Direct Answer: The FDA QMSR, effective February 2, 2026, incorporates ISO 13485:2016 into 21 CFR Part 820 by reference — making the standard's corrective and preventive action clauses (8.5.2 and 8.5.3) U.S. federal requirements for finished devices in commercial distribution. Management review and internal audit reports, previously exempt from FDA inspection, are now inspectable. Because CAPA status is a required management review input, corrective and preventive action performance is now visible to FDA investigators in a way it was not before.

THE FAILURE MODES

Five Ways a Corrective and Preventive Action System Quietly Dies

Recognizable. Recurring. Repairable.

Across 200+ audits attended, MSI has watched corrective and preventive action systems fail in the same five ways. None of them is exotic. All of them are visible from the outside.

FAILURE 1 — THE AGING BACKLOG

Records get opened and never closed. The investigator pulls the corrective and preventive action log, sorts by open date, and finds something from two years ago. What that record proves is not that one problem went unfixed — it is that the system has no mechanism for ensuring anything gets fixed. That is a systemic finding, and it is far worse than the original issue.

FAILURE 2 — CLOSURE WITHOUT EFFECTIVENESS

Records close the day the action completes. Nobody returns. Two quarters later the same nonconformity reappears under a new record number, and the corrective and preventive action log now contains the evidence of its own failure — three records, same root cause, three separate closures.

FAILURE 3 — THE EMPTY PREVENTIVE REGISTER

Clause 8.5.3 exists. The procedure mentions it. The register contains zero records, or three records all opened the week before the audit. Preventive action is the half of corrective and preventive action that requires the organization to look up from the fire it is currently fighting — and it is the half that vanishes first when a quality team is under-resourced.

FAILURE 4 — RETRAINING AS ROOT CAUSE

Pull ten closed records. If the action on eight of them is “retrain the operator,” the root cause analysis is not happening. Retraining fixes a knowledge gap. It does nothing about a process that permits the error, a fixture that allows the part in backwards, or a specification that was ambiguous to begin with.

FAILURE 5 — CAPA AS PAPERWORK

The deepest failure, and the one that produces all the others. When the organization treats corrective and preventive action as a compliance obligation rather than a learning mechanism, people optimize for closing records quickly instead of solving problems permanently. Everything downstream degrades from there.

Direct Answer: The five most common corrective and preventive action failures under ISO 13485 are: an aging backlog of open records, closure at completion rather than at verified effectiveness, an empty or last-minute preventive action register, “retraining” substituted for genuine root cause analysis, and treating CAPA as paperwork instead of a learning system. Each is visible to an auditor within minutes of opening the log, and each produces a systemic finding rather than an isolated one.

MSI's analysis of the top maintenance risks certified companies overlook and its list of the most common post-certification mistakes both land on the same conclusion from different directions: certification is not the hard part. Keeping the improvement loop alive between audits is. MSI's guide to sustaining improvement under ISO 13485 traces the same decay pattern in device organizations specifically. If you would rather measure the decay than describe it, the free Nonconformity and Corrective Action Maturity Check scores your process against all five of these failure modes and tells you which one is actually costing you.


THE LEADERSHIP LOOP

How Corrective and Preventive Action Feeds Management Review

Data. Decisions. Direction.

ISO 13485 Clause 5.6 requires management review, and it names corrective action and preventive action as explicit, separate inputs. This is not a formality. It is the mechanism by which the corrective and preventive action system stops being a quality department problem and becomes a leadership one.

A management review that receives a corrective and preventive action count — “we opened 14, closed 11” — has received nothing useful. A management review that receives root cause categories, time-to-closure trends, recurrence rates, and effectiveness verification pass rates has received a diagnosis. The first produces a nod. The second produces a resource decision.

Since the QMSR made management review records FDA-inspectable, this input has an additional dimension. An investigator reading a management review that shows leadership examining corrective and preventive action effectiveness — and allocating resources in response — is reading evidence of a system that works. An investigator reading a review that lists a CAPA count and moves on is reading something else entirely. MSI's guidance on running an ISO management review covers the input structure in detail, and the ISO 13485 management review playbook walks a first-time device review end to end.

Direct Answer: ISO 13485 Clause 5.6 names corrective action and preventive action as separate mandatory management review inputs. Leadership should receive root cause categories, time-to-closure trends, recurrence rates, and effectiveness verification pass rates — not a raw count of records opened and closed. Because the FDA QMSR made management review records inspectable as of February 2026, the review is now where an investigator can see whether corrective and preventive action is genuinely governed or merely tallied.

THE REVIEW THE FDA CAN NOW READ

ISO Management Review Toolkits — Clause by Clause

Every mandatory input, structured and ready — including the corrective action and preventive action sections that now sit in front of an FDA investigator. Agenda, input templates, the data presentation format that turns a CAPA count into a trend leadership can act on, the minutes tracker, and the output structure that turns a review into documented decisions with owners attached. Choose the toolkit for the standard you hold: ISO 9001, ISO 13485, ISO 14001:2026, ISO 45001, ISO 7101, or the integrated combinations. Built from 200+ audits attended, watching registrars read management review records for all of it.

SEE THE MANAGEMENT REVIEW TOOLKITS →

Device organizations go straight to the Medical Device ISO 13485 Management Review Tool Kit, which is written to Clause 5.6 rather than adapted from a Clause 9.3 quality base — the two clauses do not carry the same input list, and the difference is exactly where an inspection-era review record fails.

ONE SYSTEM, MANY STANDARDS

One CAPA Process Can Serve Every Standard You Hold

Write once. Satisfy all.

Device organizations rarely hold ISO 13485 alone. Many also carry ISO 9001 because a customer requires it, ISO 14001 because of an ESG mandate or a supply chain questionnaire, and ISO 45001 because manufacturing operations demand it. Running four separate improvement procedures is a self-inflicted wound.

The corrective and preventive action machinery is substantially the same across all of them. ISO 9001 Clause 10.2, ISO 14001 Clause 10.2, and ISO 45001 Clause 10.2 all require reaction, root cause evaluation, action, effectiveness review, and retained documented information. ISO 13485 requires the same plus explicit preventive action, the regulatory-impact check, and heavier record retention. Write the procedure to the ISO 13485 bar, add the environmental and safety triggers to the intake list, and one corrective and preventive action process now serves the whole certificate portfolio.

The divergences are real and they are specific. ISO 9001 requires the risk register to be updated as part of the action. ISO 13485 requires action without undue delay and the verification that the fix has not compromised regulatory compliance or device safety. ISO 14001:2026 scales action to environmental significance and carries the compliance obligation chain. ISO 45001 requires worker participation in evaluating the cause and a hierarchy-of-controls step at action selection. ISO 7101 requires the service user to be told. MSI's cross-standard guide to writing a corrective action procedure reads down that column in full, and the integrated ISO 9001 + ISO 14001 + ISO 45001 improvement procedure is what it looks like when three of them are carried in a single register.

That principle only survives contact with an auditor if the divergences are recorded rather than assumed. Where two standards genuinely ask for different things, the procedure has to name the point of divergence, state which requirement was followed, and record why — which is exactly what MSI's combined ISO 9001 + ISO 13485 corrective action procedure and the integrated ISO 9001 + ISO 13485 risk template carry as a standing appendix. When the auditor asks why one obligation was met and not the other, the answer is already written down instead of reconstructed in the room.

MSI's companion guides make the same point from the quality and environmental sides: continual improvement in ISO 9001 and continual improvement in ISO 14001 both stall at the same place — the corrective-action engine — and both are repaired by the same discipline. The quality improvement culture that makes any of it stick is built on the loop, not on the poster.

This is also the practical case for ISO consulting that spans standards rather than specializing in one. A consultant who only knows ISO 13485 will write you a device procedure. A consultant who knows the family will write you one procedure that carries every standard you hold and every standard you will add. For organizations running CAPA, document control, training, audit, and FMEA modules on a single platform, MSI's alliance with CAQ AG Factory Systems connects the procedure to the software that enforces it.


WHAT IS COMING

Why ISO 9001:2026 Matters to Corrective and Preventive Action

Culture. Reporting. Evidence.

ISO 13485 is not being revised on this cycle, so a device organization can be forgiven for tuning out the next edition of ISO 9001. That would be a mistake for anyone holding both certificates — which, in the device sector, is most people. The Final Draft International Standard ballot closed on July 9, 2026, and publication is now confirmed for September 16, 2026, with a transition period to follow. The technical content is frozen. This is no longer a date to watch for; it is a date to plan against.

Corrective action stays where it is, at Clause 10.2. What changes sits upstream of it, in leadership. The 2026 edition introduces an explicit quality culture obligation at Clause 5.1 — a requirement with no predecessor in the 2008 or 2015 editions. Top management is expected to promote and support a culture consistent with the quality policy, and to be able to show it.

Read that against Failure 5 above and the connection is immediate. A corrective and preventive action system only ever sees what people are willing to report. In an organization where raising a problem is treated as creating one, the intake list is complete on paper and empty in practice — complaints get logged, but the near-miss on the line, the operator's workaround, and the supplier drift nobody wants to escalate never enter the system at all. The register looks healthy. The failure rate does not move.

Where the new clause has teeth is in the evidence it will require, and the corrective and preventive action file is the most persuasive evidence available. Reporting volume from the floor rather than only from customers. Time from detection to intake. The proportion of records that originate internally rather than externally. The absence of retaliation in how findings are handled. An auditor looking for proof of quality culture will not accept a poster, and MSI's work on why quality systems drive retention covers the same organizational mechanics from the workforce side.

There is a practical sequencing point in the confirmed date. A procedure written now to the 2015 edition will need revisiting; one written now with the intake metrics already instrumented will not. The same logic applies on the environmental side, where ISO 14001:2026 published on April 15, 2026 and the transition deadline is already fixed at April 2029. Organizations carrying more than one certificate get one chance to make these edits together rather than three times over — MSI's guide to the combined ISO 9001 and ISO 14001 transition sequences it as a single project, and the ISO 2026 transition deadline breakdown does the arithmetic on both clocks.

Direct Answer: ISO 9001:2026 publishes on September 16, 2026. It keeps corrective action at Clause 10.2 but adds a new quality-culture requirement at Clause 5.1 that has no predecessor in earlier editions. For organizations holding ISO 9001 alongside ISO 13485, the practical link is direct: a corrective and preventive action system only records what people are willing to report, so internal reporting volume, detection-to-intake time, and the internal-versus-external origin of records become the most credible objective evidence that the culture obligation is being met. ISO 13485 is not being revised on this cycle and its Clause 8.5.2 and 8.5.3 requirements are unchanged.

FOUR PROCEDURES, ONE COURSE

Build the Four Procedures That Have to Talk to Each Other

MSI's guided course Catch. Correct. Continually Improve. walks you through building four connected procedures rather than one — risk management (Clause 6.1), nonconformity (8.7 and 10.2), corrective action (10.2), and continual improvement (10.3). These four are the ones most often written in isolation and then discovered, at the third surveillance visit, not to talk to each other. You leave with trigger definitions, root cause method selection by risk tier, the effectiveness verification pattern that survives surveillance audits, and the documentation structure auditors expect.

Written to ISO 9001 and transferable to the ISO 13485 clause structure — 8.5.2 and 8.5.3 in place of 10.2, with the regulatory-impact check added. Encoded with 28 years of MSI consulting experience. The template route hands you the finished document; this route builds it with you, which is the better choice if the people who will run the process need to understand why it is shaped the way it is.

SEE THE CORRECTIVE ACTION COURSE →

BUILDING IT RIGHT

Building Corrective and Preventive Action That Holds Under Inspection

Evidence. Not intention.

Management Systems International (MSI) has spent 28 years building management systems in regulated environments where the evidence has to survive contact with an investigator. Across 80+ certifications supported, 200+ audits attended, and 600+ professionals trained, the corrective and preventive action pattern that holds is consistently the same one.

  • Triage before you open. Not everything becomes a corrective and preventive action record. Define the threshold and defend it in the procedure.
  • Name the root cause method per risk tier. Do not leave it to whoever is assigned.
  • Define effectiveness evidence at the time you plan the action — not at the time you want to close.
  • Build the internal audit capability to test your own system before a registrar does. MSI's ISO Internal Auditor Workshop and internal audit services both exist for that purpose.
  • Review the log as leadership, quarterly — not annually at the management review, by which time the trend is history.
  • Measure the intake, not only the output. Under the incoming ISO 9001 culture clause this stops being good practice and becomes evidence.

If you want a structured read on where your ISO 13485 system currently stands before committing to anything, MSI publishes a free ISO 13485 self-scoring readiness tool — a spreadsheet that scores each requirement for documentation and implementation separately and produces a readiness view by clause. Most teams complete a first pass in a day or two, on their own, at no cost. MSI does not charge organizations to tell them what they already suspect. The work worth paying for starts after that: a planning session to sequence the response, or a direct project to build the system.

“Score your own system for free. Pay us to fix it, not to find it.”

— Diana Lynn, President, Management Systems International

Organizations building a device quality management system from scratch, or repairing one that is generating repeat findings, typically report that the corrective and preventive action procedure is the component that takes longest to get right and pays back fastest once it is. MSI's guidance on building a medical device quality management system, on what medical device startups get wrong about ISO 13485, and the plain-English overview of the standard itself all trace the same throughline.


TALK TO A CONSULTANT

Bring Us the CAPA Log. We'll Tell You What the Investigator Will See.

A planning session with MSI is a working conversation about your actual system — your open records, your recurrence pattern, your effectiveness verification practice, and what a QMSR-era inspection will make of them. From there the path is either a defined project to rebuild the procedure and train the team, or SurePath if you are pursuing ISO 13485 certification and want the whole system built once, correctly. If you are already certified and the problem is that the loop keeps decaying between audits, SureResults keeps it alive year-round.

28 years. 80+ certifications supported. 200+ audits attended. Veteran-owned, female-owned, and still the people who show up when the auditor does.

SCHEDULE A PLANNING SESSION — 760-434-9141 →

Or explore MSI's ISO consulting services and the industries we serve.

FREQUENTLY ASKED

Corrective and Preventive Action Under ISO 13485: Common Questions

Asked. Answered. Audited.

What is the difference between correction, corrective action, and preventive action?

A correction fixes the immediate problem — scrap the bad lot, replace the defective part. Corrective action eliminates the root cause so the problem does not recur. Preventive action eliminates the cause of a problem that has not happened yet but could. All three appear in a mature ISO 13485 system, and confusing them is one of the most common findings. A record that only documents the correction has not performed corrective and preventive action at all.

Which ISO 13485 clauses cover CAPA?

Clause 8.5.2 (corrective action) and Clause 8.5.3 (preventive action), with Clause 8.5.1 covering general improvement. Related requirements sit at 8.2.2 (complaint handling), 8.3 (control of nonconforming product), 8.2.4 (internal audit), and 5.6 (management review). Note that ISO 13485 retains the pre-Annex SL structure, so corrective and preventive action is not at “Clause 10.2” the way it is in ISO 9001, ISO 14001, and ISO 45001.

How long should a CAPA record stay open?

ISO 13485 sets no fixed limit — but the organization must define its own timeframes in the procedure and then meet them, and effectiveness verification necessarily requires an observation period after implementation. What auditors actually penalize is not duration but drift: records open past their own committed dates with no documented justification. A corrective and preventive action system with defined timeframes and documented extensions is defensible. One with silent, aging records is not.

Does the FDA QMSR change how CAPA must be run?

It changes what is inspectable and by whom. Since February 2, 2026, 21 CFR Part 820 incorporates ISO 13485:2016 by reference, so the standard's corrective and preventive action clauses are now U.S. federal requirements for finished devices in commercial distribution. Management review and internal audit reports — previously exempt from FDA inspection — are now inspectable, and CAPA status is a mandatory management review input. The requirements did not get harder. The audience got bigger.

Does ISO 9001:2026 change corrective action for a device company?

Not the clause itself — corrective action stays at Clause 10.2, and ISO 13485 is not being revised on this cycle. What changes is upstream. The 2026 edition publishes on September 16, 2026 and introduces a quality-culture requirement at Clause 5.1 with no predecessor in earlier editions, and the most credible evidence of it is your intake data: how much gets reported internally rather than by customers, and how quickly. If you hold both certificates, your corrective and preventive action file becomes the exhibit for a clause that lives nowhere near it.

Can one CAPA procedure serve ISO 9001, ISO 13485, ISO 14001, and ISO 45001?

Yes — provided it is written to the ISO 13485 bar, which is the strictest. ISO 13485 requires explicit preventive action, a check that the action does not compromise regulatory compliance or device safety, and heavier record retention. Satisfy those and ISO 9001 Clause 10.2, ISO 14001 Clause 10.2, and ISO 45001 Clause 10.2 are satisfied automatically. Add the environmental and safety triggers to the intake list and one corrective and preventive action process carries the entire certificate portfolio — provided every point of divergence between the standards is recorded rather than assumed.

Is there a template for an ISO 13485 corrective action procedure?

Yes. MSI publishes an ISO 13485 corrective action procedure template covering Clauses 8.5.2 and 8.5.3, and a combined ISO 9001 + ISO 13485 version for organizations holding both certificates. Both are complete editable Word documents written as filled-in worked examples rather than outlines, with correction and corrective and preventive action separated at the form, root cause method selected by risk tier, effectiveness review given a defined interval, and the regulatory-impact check written in as a gate. If you want to know where your current process sits first, the free Nonconformity and Corrective Action Maturity Check scores eight elements in about six minutes.

What is the most common CAPA finding in a device audit?

Closure without effectiveness verification. The action was completed, the record was closed, and nobody returned to confirm the condition was actually eliminated. MSI client experience suggests this single failure accounts for more repeat findings than any other cause — because a corrective and preventive action record closed at completion rather than at verified effectiveness leaves the root cause alive and the organization believing it is dead.

FOR THE LEADERSHIP TEAM

Watch the ISO Executive Decision Briefs

Short video briefings for executives on the decisions only leadership can make — scope, resourcing, standard selection, and what a management system genuinely costs to run well. Free to watch, no scheduling required.

WATCH THE DECISION BRIEFS →

References & Authoritative Sources
  1. ISO 13485 — Medical devices, quality management systems, International Organization for Standardization.
  2. ISO 14971:2019 — Application of risk management to medical devices.
  3. ISO 9001 — Quality management systems, International Organization for Standardization.
  4. ISO 19011:2026 — Guidelines for auditing management systems.
  5. U.S. FDA — Quality Management System Regulation (QMSR).
  6. U.S. FDA — QMSR Frequently Asked Questions, including Compliance Program 7382.850.
  7. eCFR — 21 CFR Part 820, Quality Management System Regulation.
  8. U.S. FDA — Medical Device Single Audit Program (MDSAP).
  9. U.S. FDA — Warning Letters database.
  10. Regulation (EU) 2017/745 — Medical Device Regulation, EUR-Lex.
  11. International Medical Device Regulators Forum (IMDRF).
  12. ASQ — Root Cause Analysis resources.
  13. ASQ — Failure Mode and Effects Analysis (FMEA).
  14. AAMI — Association for the Advancement of Medical Instrumentation.
  15. Global ACI — international accreditation framework.


About Management Systems International (MSI)

Diana Lynn is President and Principal ISO Consultant at Management Systems International (MSI), a consulting firm she co-founded in 1998. With 28 years of experience including extensive AS9100 work in MSI's early years, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.

Veteran-owned. Female-owned. msi-international.com  ·  760-434-9141

Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 15 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply