CAPA Effectiveness Verification: How to Prove Your Corrective Action Actually Worked
CAPA effectiveness verificationcorrective and preventive actionCAPA software

CAPA Effectiveness Verification: How to Prove Your Corrective Action Actually Worked

Closing a corrective action is easy. Proving the problem stopped is the part that changes anything, and it is the step most manufacturers skip. Here is how risk ranking, structured root cause analysis and a recorded effectiveness verification turn CAPA from paperwork into a loop that actually closes, with a worked example where the fix improved on-time delivery from 78 to 85 percent and still failed.

Q

Qualis Team

16 min read

It is 4pm on a Thursday and your biggest customer is on the phone about late deliveries. Again.

You know this one. You raised it eight months ago. Someone investigated it, someone put a fix in place, and someone ticked the box marked Closed. You can still picture the meeting.

So why is it back?

Because nobody ever checked whether the fix worked. That missing step is called CAPA effectiveness verification, and skipping it is the most expensive habit in manufacturing quality.

The corrective action was closed on the day the fix was applied, not on the day the problem stopped happening. Those are two very different days, and only one of them is worth anything. The difference between them is what separates a quality system that actually improves your plant from a filing cabinet that quietly documents its decline.

Quality engineer reviewing machined parts and a tablet at a clean shop floor workbench

Where the corrective action quietly breaks

Walk into almost any small or mid sized manufacturer and the corrective action process looks roughly like this.

A problem shows up. A customer complains, an auditor writes a finding, or an operator flags a batch. Someone opens a spreadsheet row, or starts an email thread, or writes it on a whiteboard in the quality office.

Then four things go wrong, in the same order, every time:

  • Nothing is ranked. The problem that shouts loudest gets worked on. The problem that quietly ships defective parts to your best customer waits.
  • The cause is guessed. The first plausible explanation becomes the official one, because there is no structure forcing anyone to dig past it.
  • The fix has no owner and no date. "We will retrain the team" is not an action. It is a sentence.
  • Nobody ever goes back. The row gets coloured green. The thread goes quiet. Eight months later, the customer calls.

That last one is the expensive one. Everything before it is wasted effort if you never find out whether it worked.

A corrective action that is closed but never verified is not a fix. It is a hope with a reference number.

What CAPA effectiveness verification actually means

Strip away the jargon and it is one question, asked at the right moment:

Did the problem stop?

Not "did we do the thing we said we would do". You already know that. The question is whether the thing you did actually changed the outcome, measured against a number you agreed on in advance, after enough time has passed for the problem to come back if it was going to.

That means three commitments, made at the start, not at the end:

  1. How you will measure it. Track on-time delivery for 60 days. Sample 100 parts. Audit the records for a month.
  2. What counts as success. On-time delivery above 95 percent. Zero out of tolerance parts. No missed calibrations.
  3. Who signs it off. A named person who is not the person who did the fix.

Write those three down when you open the corrective action, and the ending writes itself. Leave them out, and "closed" means nothing more than "we got bored of it".

Step one: work out which problem is worth your Tuesday

You do not have time to fix everything properly. So the first job is not investigating. It is ranking.

Qualis uses the same risk scoring that quality engineers have used on FMEAs for decades. You score three things from 1 to 10:

  • Severity. If this reaches the customer, how bad is it?
  • Occurrence. How often does it actually happen?
  • Detection. How likely are you to catch it before it ships? (A high score here is bad news: it means you probably will not.)

Multiply the three together and you get a Risk Priority Number, or RPN.

Diagram showing Severity times Occurrence times Detection equals Priority, the formula behind a Risk Priority Number

The maths is deliberately blunt, and that is the point. A field failure scoring 8 for severity, 5 for occurrence and 6 for detection lands on an RPN of 240. Qualis works it out the moment you enter the three scores and bands it automatically: under 50 is low, under 100 medium, under 200 high, and 200 or above critical. So that one is critical, and it goes to the top of the pile.

Risk assessment panel in Qualis showing severity 8, occurrence 5 and detection 6 producing a Risk Priority Number of 240, banded critical

The number is not a scientific truth. It is a tiebreaker. When two people each think their problem is the urgent one, an RPN gives you something better than seniority to decide with.

It also does something quieter and more useful: because Detection is one of the three multipliers, a problem you cannot currently catch scores higher than an identical problem you can. Your ranking automatically favours the defects that are getting out of the building.

Step two: find the real cause, not the loudest one

Here is where most corrective actions go wrong, and it is rarely because people are lazy. It is because "root cause" gets filled in from memory in ninety seconds.

Qualis makes you pick a method first, and then gives you the structure for it.

5 Whys, when the chain of cause and effect is fairly linear. You ask why five times, and the answers are recorded as a chain, not as a paragraph.

Five Whys analysis in Qualis tracing an actuator leak from a seal to a missing control plan classification

Read that chain again and notice what happened. The problem started as "the actuator is leaking", which sounds like a seal problem you fix by changing seals. Five questions later it is a control plan problem: the characteristic was never classified as critical, so nobody ever put an in-process check on it. Change the seals and it comes back. Change the control plan and it does not.

Fishbone, also called Ishikawa, when the causes are tangled and come from several directions at once. Qualis lays out the classic six categories: People, Machine, Method, Material, Measurement and Environment, and you fill in what belongs under each.

Fishbone Ishikawa diagram in Qualis with causes of paint adhesion failure grouped under People, Machine, Method, Material, Measurement and Environment

The value of the fishbone is not the drawing. It is that the six empty boxes force you to look in the five places you were not already looking. Nobody writes "humidity in the prep area is not monitored" from memory. They write it because the Environment box was sitting there, empty, looking at them.

Pareto, when the same problem has several contributing factors and you want to know which few of them cause most of it.

Whichever you choose, it ends in one plain sentence: the root cause statement. That sentence is what the fix has to attack.

Step three: name the fix, and name who owns it

An action plan in Qualis is not a text box. Each action is its own numbered line with a type, an owner, a due date and a completion date.

The type matters more than it looks. Every action is either corrective (stop the problem that already happened) or preventive (stop it happening somewhere it has not happened yet). Most plants are good at the first and never get to the second, which is exactly why the same class of defect keeps reappearing on different parts.

Action plan in Qualis showing a corrective action and a preventive action, each with an owner and a completion date

Two completed actions, both with names against them, both with dates. At this point, in most systems, this corrective action is done. Somebody closes it and moves on.

This is precisely where it gets interesting.

Step four: the question almost nobody asks

Let us follow that late delivery problem all the way through, using the worked example that ships in the Qualis demo data.

The complaint came from a customer. It scored 5 for severity, 6 for occurrence and 5 for detection, so an RPN of 150, which lands in the High band. The team ran a Pareto analysis and found four contributing factors.

Pareto analysis in Qualis showing four contributing factors to late deliveries with a cumulative percentage line

Quality hold notification delay was the big one at 45 percent. So the root cause statement pointed at communication: quality holds were not reaching the shipping department fast enough. Two actions followed, one corrective (automate the quality hold notification) and one preventive (a daily shipping status review). Both were completed on time.

And then, sixty days later, somebody actually checked.

Verification panel in Qualis showing a Not Effective result, with verification method, success criteria, verifier and notes

On-time delivery went from 78 percent to 85 percent. Real improvement. Genuinely better than before.

The target was 95 percent.

So the result is recorded as Not Effective, with the reason written down in plain language: the root cause analysis was incomplete, and the production planning issues (30 percent of the Pareto, sitting right there in the chart) were never addressed. A new corrective action was opened with a broader scope.

Read that again, because it is the whole argument for doing this properly. The fix worked. It just did not work enough. In a spreadsheet, 78 to 85 percent looks like a win and the row goes green. Here it triggers a second round, because success was defined as a number before anyone started.

Diagram showing a verification step branching to either Close or a New CAPA

Qualis records one of three results: Effective, Partially Effective, or Not Effective. Only the first one lets the story end.

The number that tells you if any of this is real

Once effectiveness is a recorded field rather than a feeling, you can add up the results. That gives you a number most quality systems never put in front of you.

Corrective and preventive actions list in Qualis showing total, open, overdue, pending verification and effectiveness rate

That Effectiveness Rate is not a vanity number. It is the share of your verified corrective actions that were judged fully effective. In this example it is 67 percent, which means roughly one in three did not fully solve the problem it was raised for.

Sit with that for a second, because it is the honest shape of quality work everywhere. Problems are hard, first attempts often miss, and a third of them missing is not a scandal. Not knowing is the scandal, because without that number you cannot tell the difference between a quality process that is getting better and one that is just getting busier.

Next to it sits Pending Verification: the corrective actions where the work is done but the proof is not in yet. In a spreadsheet, those are invisible. They look identical to the finished ones.

Why "closed" is not the same as "fixed"

There is a reason auditors go straight for this.

ISO 9001:2015 sets out what an organisation has to do when a nonconformity occurs, and buried in the middle of clause 10.2.1 is a five word requirement that most quality manuals quietly under deliver on:

"review the effectiveness of any corrective action taken"

That is a shall, not a nice to have. And the clause immediately after it, 10.2.2, closes the loophole: you have to retain documented information as evidence of both "the nature of the nonconformities and any subsequent actions taken" and "the results of any corrective action". Results, not activities.

The automotive and aerospace standards built on top of ISO 9001 are stricter again, not looser. So the audit goes the same way every time: the auditor picks three closed corrective actions and asks to see what changed afterwards. If the answer is a completed action list and nothing else, that is a finding, and it is one of the easiest findings in the business to write.

Beyond the audit, there is the money. Rework, scrap, expedited freight, credit notes and the engineering time spent solving the same problem twice all sit in the same bucket, and none of it appears on a line of your P&L labelled "quality". It shows up as margin that was there in the quote and gone by the invoice.

This is also where the software market gets awkward, and it is worth being precise rather than rude about it.

Look across the manufacturing ERP market and the same pattern shows up again and again. Capturing a non-conformance is close to universal. Recording some kind of corrective action is common. Structured root cause analysis is rare. Effectiveness verification is rarer still. The steps drop off in exactly the order that makes the process feel complete while quietly removing the part that proves anything.

Odoo is a fair example, because it is one of the better ones. Its Quality app gives you a quality alert with a Root Cause field, a priority rating and dedicated Corrective Actions and Preventive Actions tabs, which is genuinely more than many tools offer. But those tabs are free text describing what should be done, and the published documentation does not go on to a verification step that records whether it worked. (That app is also Enterprise edition only: the open source Community edition ships no quality module at all.) Tellingly, the Odoo app store carries paid third party modules that exist specifically to add CAPA, 8D and corrective action effectiveness tracking on top.

Where corrective action management is genuinely strong, it usually sits somewhere other than the core ERP. Sometimes it is a separately licensed add on. Sometimes the risk scoring lives in one object and the corrective action in another, so the two never meet on one screen. Sometimes it is a third party extension from the marketplace. And often it is a full quality management system in its own database next to your ERP, which brings its own tax:

  • The corrective action knows a part number as text, not as a link to the actual part.
  • Nobody outside the quality office ever opens it.
  • The same information gets typed twice, and the two copies disagree within a month.

Those dedicated quality platforms are good software. They are also, for the most part, impossible to price without talking to a salesperson: check the pricing pages of the best known names and you will mostly find "contact us". The handful that do publish start their entry tiers in the tens of thousands per year. For a plant that mainly needs corrective actions to work properly, that is a large decision to make about one process.

Qualis takes the third path: the corrective action lives in the same system as the part, the supplier, the customer and the non-conformance that started it. Raising a corrective action from a non-conformance report is a link, not a retype.

The whole loop, end to end

Put the four steps together and the shape is simple. It is not a checklist. It is a loop, and the loop only closes when the evidence says it can.

Diagram of the corrective action loop: Raise, Rank, Investigate, Fix, Verify, with a return arrow from Verify back to Rank

  1. Raise it from wherever it came from: a non-conformance report, a customer complaint, an audit finding, a deviation or an observation. The source is recorded, so you can later ask which sources produce your worst problems.
  2. Rank it with severity, occurrence and detection, so the critical work rises above the noisy work.
  3. Investigate it with 5 Whys, a fishbone or a Pareto, and finish with a written root cause statement.
  4. Fix it with numbered actions, each one typed corrective or preventive, each one owned by a person with a date.
  5. Verify it against the success criteria you set at the start. The verifier is recorded by name, and good practice is to make that somebody other than the person who did the work.

If it was effective, it closes, and the record stays as evidence for the next audit. If it was not, the loop runs again with what you learned, which is exactly what happened to that late delivery problem.

Every step of that is recorded against the same numbered record, with a full version history, so the question "who changed what, and when" has an answer that does not depend on anyone's memory.

Frequently Asked Questions

What is CAPA effectiveness verification?

It is the final step of a corrective action, where you check whether the problem actually stopped rather than whether the fix was applied. You agree a measurement method and a success criterion when you open the action, wait long enough for the problem to reappear if it was going to, then record the result as Effective, Partially Effective or Not Effective, signed off by a named verifier.

What is the difference between an NCR and a CAPA?

A non-conformance report records a specific thing that went wrong: this batch, this part, this delivery. It answers "what do we do with the affected goods". A corrective and preventive action asks the bigger question: why did this happen at all, and what stops it happening again. One non-conformance can be handled on its own; a pattern of them should raise a corrective action.

How do you calculate a Risk Priority Number?

Score severity, occurrence and detection from 1 to 10, then multiply the three together. The result runs from 1 to 1000. In Qualis, anything under 50 is banded as low risk, under 100 medium, under 200 high, and 200 or above critical. The score is calculated automatically as soon as the three inputs are entered, so it cannot be quietly overwritten.

How long should you wait before verifying a corrective action?

Long enough that the problem would have come back if the fix had not worked. There is no universal number, because it depends on how often the problem occurs. A defect that appears on every third batch can be verified in weeks. A failure that shows up twice a year cannot. The practical rule is to set the window in advance, based on production volume rather than the calendar, and write it into the verification method when you open the action.

Do I need a separate quality management system, or can my ERP handle CAPA?

If your corrective actions need to reference parts, suppliers, customers and non-conformances that already live in your ERP, keeping them in the same system removes an entire category of double entry and disagreement. A dedicated quality management system is worth it when you have regulatory obligations that go well beyond corrective action, such as validated document control or electronic signatures. For a discrete manufacturer holding a general quality certification, an ERP that handles the full loop, including verification, usually covers it.

What happens if the corrective action is not effective?

That is a valid, recordable outcome, not a failure to be hidden. The result is stored as Not Effective along with the evidence and the reason, and a new corrective action is opened with a wider scope, informed by what the first attempt ruled out. Both records stay linked, which means your history shows the honest version: two attempts, and what was learned in between.

The bottom line

Closing a corrective action is easy. Proving it worked is the part that changes anything.

The plants that stop having the same 4pm phone call are not the ones with the thickest quality manual. They are the ones that decided, up front, what success would look like, then went back sixty days later and checked.

If you want to see what that looks like when it lives inside your ERP instead of beside it, with the part, the supplier and the non-conformance all one click away, take a look at Qualis. Your next audit will go looking for exactly this.

If you would like to read more about how quality gates work earlier in the process, our post on production genealogy and lot traceability covers how to trace a defect back to the batch it came from, and purchase order approval workflows covers the same idea of a decision that has to be recorded rather than remembered.

Appreciate this post
Share

Comments

Loading comments...

Related articles