# Nonconformity & Corrective Action (CAPA)

> Mandatory record – ISO 9001/27001 cl.10.2. The improvement engine:
> every NC needs root cause (not just a fix) + effectiveness check.

| Field | Value |
|-------|-------|
| CAPA ID | NC-YYYY-NNN |
| Opened | YYYY-MM-DD |
| Source | Audit / incident / complaint / review |
| Detected by | @name |
| Owner | @name |
| Status | Open / Root cause / Implementing / Verify / Closed |

## 1. Nonconformity description

What requirement was not met, where, when – factual, evidence-based.

- **Requirement**: clause / policy / spec violated
- **What happened**: observed condition
- **Evidence**: record/photo/log reference

## 2. Immediate correction (containment)

The quick fix to stop the bleeding – done first, does NOT close CAPA.

| Action | By | Date |
|--------|-----|------|
| Containment step | @name | |

## 3. Root cause analysis

> The most-failed step – auditors check that root cause ≠ symptom.

```mermaid
flowchart LR
    P[Problem] --> W1[Why 1] --> W2[Why 2] --> W3[Why 3] --> W4[Why 4] --> W5[Why 5: root cause]
```

- Method: 5 Whys / fishbone / fault tree
- **Root cause**: systemic reason, not "human error"

## 4. Corrective action

Address the ROOT cause so it cannot recur:

| Action | Eliminates root cause? | Owner | Due | Done |
|--------|------------------------|-------|-----|------|
| Systemic fix | yes – how | @name | | |

## 5. Effectiveness verification

- Check date: YYYY-MM-DD (≥ enough time to show recurrence stopped)
- Evidence: metric / re-audit / observation
- Result: effective – close / not effective – reopen at step 3

## 6. Closure

| Signed | Role | Date |
|--------|------|------|
| | Quality/ISMS manager | |

## 7. Linkages

- Feeds management review input (cl.9.3)
- Updates risk register if new risk surfaced
- Procedure change if root cause was process gap
