Services Combination Products Approach Industries Insights About Book a consultation

Prefer email? info@dpdynamicsol.com

Quality Systems

CAPA Effectiveness Checks That Actually Close the Loop

"Retrained the operator. Training records on file. CAPA closed." Twelve months later the same nonconformance appears at the same process step. Nothing in that record was false — the training happened, the records exist, the action was completed. What was never established is whether the problem stopped.

Key takeaways

  • Completing an action is not the same as proving it worked. Most effectiveness checks verify implementation and stop there.
  • Define the signal, the acceptance criteria, and the observation window before the action is implemented — not after the data arrives.
  • The window has to cover enough opportunities for the failure to recur. A clean run of 100 units only shows the rate is below about 3%.
  • "Does not adversely affect the finished device" is half the requirement, and the half most often skipped.
  • A failed effectiveness check is the strongest evidence you have that the investigation stopped at a symptom.

What the requirement actually says

ISO 13485:2016 requires that corrective action be reviewed for effectiveness, and says the same for preventive action. Since the FDA's Quality Management System Regulation incorporates ISO 13485 into 21 CFR Part 820, that obligation carried straight through the QMSR transition — and the predecessor language in Part 820 was, if anything, blunter: verify or validate the corrective action to ensure it is effective and does not adversely affect the finished device.

Two things in that sentence are worth slowing down for. The requirement is about effectiveness, not completion. And it has a second half — the action must not have made something else worse. Most CAPA records address neither.

Completion is not effectiveness

These are different questions answered by different evidence, and conflating them is the single most common reason a closed CAPA does not survive review.

QuestionWhat it demonstratesTypical evidence
Did we do what we said we would?Implementation — the action was completedTraining records, revised SOP, signed work order, updated drawing, installed fixture
Did the problem stop?EffectivenessPost-implementation data measured against predefined criteria across a defined window
A one-question test. If your effectiveness check could have been written and signed on the day the action was completed, it is a completion check. Effectiveness cannot be established at the moment of implementation, because no evidence exists yet.

What a real effectiveness check requires

1. A signal you can actually measure

Name what will be observed, and confirm it is somewhere the failure would genuinely appear. A recurring in-process defect caught at final inspection will never show up in complaint data, so an effectiveness check built on complaint trends would have passed no matter what happened. Matching the signal to the failure's detection point sounds obvious and is missed constantly.

2. Acceptance criteria fixed in advance

Write down what result will count as effective before the action is implemented. Criteria composed after the data arrives are not criteria; they are a rationalisation of whatever happened. This is the same discipline as writing a statistical analysis plan before unblinding — and it exists for the same reason.

3. An observation window sized to detect recurrence

This is where most otherwise-reasonable CAPAs quietly fail, and it deserves its own section below.

4. Someone other than the implementer

The person who designed and implemented the action is the last person who should be the sole judge of whether it worked. This is not about doubting anyone's integrity; it is that the implementer has already concluded the action was correct, and reviews conducted by people who expect to find nothing tend to find nothing.

Sizing the window: what a clean run actually proves

Observing zero recurrences means nothing on its own. It only becomes evidence when you have observed enough opportunities for the failure to have shown itself had it still been present.

For attribute data, the relationship is simple. After n units with zero recurrences, the 95% upper confidence bound on the true rate is approximately 3/n — the familiar "rule of three." Turning that around gives an uncomfortable table:

Units observed with zero recurrencesTrue rate could still be as high as
309.5%
505.8%
1003.0%
1502.0%
3001.0%

Read the third row carefully. If the nonconformance that triggered your CAPA was running at 2%, and you close the CAPA after 100 consecutive conforming units, the upper bound on the current rate is about 3% — higher than where you started. The clean run is real, and it demonstrates nothing.

To show with 95% confidence that the rate is now below its historical value, the number of consecutive conforming units you need is:

n ln(1C) ln(1p)

where C is the confidence level (0.95) and p is the historical rate you want to rule out. This is the same zero-failure reasoning as the success-run theorem in our sample size article, applied to recurrence instead of reliability.

Historical nonconformance rateConsecutive conforming units needed (95% confidence)
10%29
5%59
2%149
1%299
0.5%598

The practical consequence is that rare problems are expensive to prove fixed. A defect occurring at 0.5% needs roughly 600 clean units before a zero-recurrence claim carries statistical weight. That is often more than a single production run, which means either the window spans several runs or the effectiveness argument has to rest on something other than counting — a validated process change, a poka-yoke that makes the failure mode physically impossible, or a designed experiment demonstrating the mechanism was removed.

The arithmetic assumes independence. These numbers hold when units are independent and the process is stable. If the failure mode is tied to a supplier lot, a tool change, an operator, or a season, unit count is the wrong frame entirely — you need enough lots, tools, operators, or calendar coverage for the condition to have recurred.

Windows are measured in opportunities, not months

"We monitored for three months" is a duration, not a window. The question underneath it is how many opportunities for the failure occurred in those three months. Three months of a line running one lot a quarter gives you a single opportunity, and a single opportunity proves nothing.

Define the window in terms of the thing that actually varies:

  • Supplier-related failures — enough incoming lots from enough suppliers, including at least one changeover
  • Operator- or shift-related failures — coverage of the operators and shifts involved, not just the day shift that received the retraining first
  • Tool- or fixture-related failures — enough cycles to reach the wear regime where the problem originally appeared
  • Environment- or season-related failures — a window that spans the relevant conditions, which may mean waiting

A window that closes before the process has had a fair chance to fail is not evidence of effectiveness. It is evidence of patience running out.

The half everyone skips: adverse effects

A corrective action is a change, and changes propagate. The requirement to confirm the action "does not adversely affect the finished device" exists because fixing one thing routinely breaks another, and the CAPA is where that should be caught.

Worth asking explicitly, and recording the answers:

  • Did the change introduce a new failure mode, or shift an existing one somewhere else in the process?
  • Did tightening one specification push a related characteristic closer to its own limit?
  • Did an added inspection step create a bottleneck that now pressures throughput — and therefore behaviour — elsewhere?
  • Did a design change invalidate any prior verification, validation, or stability data?

This is also the natural junction between CAPA and risk management. A corrective action that changes the design or the process is new information about your device, and it should flow into the risk management file rather than living only in the CAPA record. An auditor who finds a design-altering corrective action with no corresponding risk file update has found a broken feedback loop, and will keep pulling on it.

Where effectiveness checks go wrong

  1. The effectiveness check is a completion check. "Training delivered, records attached." The most common finding, and the easiest to spot.
  2. Criteria written after the data. If acceptance criteria and results appear in the record with the same date, expect the question.
  3. Too few opportunities. A window chosen by convenience rather than by what would be needed to detect recurrence.
  4. The wrong signal. Monitoring a channel where the failure would never have appeared.
  5. Implementer as sole judge. No independent review of the conclusion.
  6. "No recurrence reported." Absence of reports is not evidence when nobody was actively looking. Passive non-observation is not monitoring.
  7. The adverse-effect half ignored. Half the requirement, unaddressed.
  8. The CAPA closed before the window closes. Closure dated before the monitoring period ends is a self-documenting finding.
  9. A failed check that changes nothing. The check fails, a note is added, the CAPA closes anyway.

When the check fails, it has done its job

An effectiveness check that fails is not an embarrassment. It is the control working — it caught something before the next batch, the next complaint, or the next inspection did. What matters is what happens next, and the answer is that the CAPA does not close.

A failure means one of three things: the action was wrong, the implementation did not hold, or the root cause was wrong. In practice it is usually the third. A corrective action aimed at a symptom will often produce a short quiet period followed by recurrence, which is exactly the pattern a properly sized window is built to reveal. Treat a failed effectiveness check as the strongest available evidence that the investigation stopped too early, and reopen the analysis rather than reissuing the same action with more emphasis.

What to document

An effectiveness check that will survive review states, before the action is implemented: the specific signal to be monitored and where it will be observed; the baseline rate or condition being compared against; the acceptance criteria that will define success; the observation window expressed in opportunities — units, lots, cycles, or shifts — with the rationale for its size; who will perform the assessment, and their independence from implementation; what happens if the criteria are not met; and confirmation that adverse effects on the finished device and related processes were considered.

Written that way, closure stops being an administrative act and becomes the documented conclusion of an argument — which is the standard every other claim in your quality system is held to.

This article is general information, not regulatory or legal advice. Clause references should be confirmed against the current text of the applicable standards and regulations, and CAPA decisions must be made by qualified personnel with reference to your own procedures, product, and process.

David Plescia, Founder & Principal Consultant, DP Dynamic Solutions David Plescia Founder & Principal Consultant, DP Dynamic Solutions · 25+ years in medtech quality
Let's talk

Are your CAPAs closing or just ending?

We review CAPA systems the way an investigator would — whether effectiveness criteria are set in advance, whether the observation window could detect recurrence, and whether closure is supported by evidence or by elapsed time.