Skip to main content
v2026.11,610 entries · CC-BY 4.0

CAPA Report and Plan Structure: The Six Sections Auditors Check

The CAPA record structure that holds up under audit: problem statement, extent-of-condition, root cause with evidence, an action plan with owners and dates, effectiveness criteria, and closure approval.

Ask about CAPA Report and Plan Structure: The Six Sections Auditors Check

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Written and maintained by CASRAI Editorial Board

Last updated

A CAPA that gets closed on paper but reopened during the next inspection almost always has the same problem: the record itself is missing a section, not the investigation behind it. Auditors don’t re-run your root-cause analysis — they read the record and check whether it contains the specific evidence a complete CAPA is supposed to contain. This guide lays out the six sections a CAPA report and action plan needs to survive that read, what belongs in each one, and the structural gaps that show up most often as inspection findings.

What a CAPA record has to demonstrate, structurally

A CAPA (Corrective and Preventive Action) is a process — investigate, correct, prevent, verify. The record of that process is a separate thing, and it’s the record an auditor actually evaluates. A CAPA can be substantively well-investigated and still fail an audit if the write-up doesn’t make that investigation visible: a root cause stated as a conclusion with no supporting evidence, an action plan with no named owner or date, or a closure with no documented check that the fix worked. The underlying quality-system requirement for this is not CASRAI-specific — ISO 9001:2015 Section 10.2 (general quality management) and ISO 13485:2016 Sections 8.5.2–8.5.3 (medical device quality management, incorporated into FDA’s device Quality Management System Regulation effective February 2, 2026) both require corrective action to be documented, not just performed. A missing section in the record is treated the same as a missing step in the process.

1. Problem statement: describe the finding, not your interpretation of it

The problem statement is where CAPA records most often go wrong first, because it’s written after the investigation instead of before it. A problem statement written with the root cause already baked in (“operator failed to follow SOP due to inadequate training”) pre-commits the investigation to one conclusion before the evidence is gathered. A defensible problem statement describes only what was observed, when, where, and by what method it was detected — for example: “During a routine SOP compliance check on [date], batch record review for lot [X] showed three consecutive entries missing the second-operator verification signature required by SOP-014 Section 6.2.” No cause, no blame, no fix — just the observable fact that triggered the CAPA. Everything downstream in the record traces back to this statement, so it has to be precise enough that someone with no prior context can read it and understand exactly what happened.

2. Extent-of-condition: the section most CAPA records skip entirely

Extent-of-condition asks a question the problem statement doesn’t: does this same condition exist anywhere else — other lots, other operators, other lines, other sites, other time periods — before the finding was caught? This is the section auditors specifically probe for, because its absence is what turns a single-instance correction into a CAPA that never actually contained the problem. If the missing-signature example above is followed by an extent-of-condition review that finds the same gap in four other lots processed under the same shift pattern, the corrective action has to address all of them, not just the one that happened to get caught during review. A CAPA record with no extent-of-condition section, or one that states a scope without showing what was actually checked to establish it (which batches, which date range, which query or log was pulled), reads as an assumption rather than an assessment — and assumptions about scope are a recurring citation in FDA Form 483 observations against CAPA systems.

3. Root cause analysis: with evidence, not an assertion

The record needs to show the method used (5-Whys, fishbone/Ishikawa, fault-tree, or a formal root-cause-analysis template) and the evidence that supports the conclusion the method produced — interview notes, training records, equipment logs, prior deviation history, document version history. “Operator error” is not a root cause on its own; it’s a symptom that still needs a “why” behind it — unclear procedure wording, missing verification step, inadequate training design, or a system that made the error easy to make and hard to catch. A root cause section that states a conclusion with no evidence trail attached is one of the most common reasons a CAPA gets reopened: an auditor or a later, similar deviation exposes that the stated cause was never actually substantiated.

4. Action plan: named owners, real dates, and the corrective/preventive distinction

Every action needs three things in the record, individually, not as a paragraph: what the action is, who owns it by name or role, and the date it’s due (and, once complete, the date it closed). A plan that says “retrain staff and update procedure” with no owner and no date is not an action plan an auditor can verify against — there’s nothing to check it against. The plan should also separate correction (the immediate fix to the specific instance — correcting the flagged batch record), corrective action (the systemic change addressing the root cause in the process where it occurred — revising SOP-014’s verification step), and preventive action (extending that fix to other processes, sites, or products where the same root cause could plausibly recur, informed directly by what the extent-of-condition review found). Collapsing all three into one undifferentiated line item is a structural gap, not just a formatting preference — it hides whether the systemic and preventive layers were ever actually planned.

5. Effectiveness criteria: defined before closure, not written to justify it

Effectiveness criteria describe, in advance, what “this worked” will look like and how long the record will wait to check — for example: “zero missing-signature findings in the next three consecutive internal audits of SOP-014-governed batch records, reviewed no sooner than 90 days after implementation.” Criteria written after the fact, to match whatever happened to be observed, don’t demonstrate the action actually worked; they demonstrate the record was closed. This is also where the extent-of-condition scope matters again — effectiveness has to be checked across the full scope the CAPA was supposed to cover, not only the single instance that originally triggered it.

6. Closure approval: what the signature is actually attesting to

Closure is a distinct, dated approval step, not an implicit consequence of the last action item being marked complete. The approver’s signature attests specifically that: the root cause was substantiated with evidence, the action plan was fully executed, the effectiveness criteria were met and documented, and the extent-of-condition scope was addressed in full — not just that time has passed since the actions were implemented. A record with actions marked “complete” but no separate closure approval, or a closure dated the same day as the last action with no effectiveness-check interval in between, is a pattern inspection readiness reviews flag specifically, because it suggests the effectiveness check didn’t actually happen on the schedule the record itself defined.

A CAPA record structure you can adapt

The six sections above, as a working outline for a CAPA report/plan template:

  1. Problem statement — what was observed, when, where, how detected. No cause, no blame.
  2. Extent-of-condition — what was checked (scope, date range, method) and what else, if anything, showed the same condition.
  3. Root cause analysis — method used, evidence reviewed, conclusion.
  4. Action plan — correction / corrective action / preventive action, each with a named owner and a due date.
  5. Effectiveness criteria — the pass/fail check defined in advance, plus the interval before it’s applied.
  6. Closure approval — named approver, date, and an explicit statement that criteria 1–5 were each satisfied.

This mirrors how a documented quality management system expects corrective action to be recorded under ISO 13485 and ICH Q10, and it’s the same structure a 21 CFR Part 820 / QMSR inspection or an ISO 13485 audit will look for section-by-section, whether your organization’s actual template uses these exact six labels or its own equivalent headings.

Structural findings inspectors cite most often

  • No extent-of-condition section, or one with a stated scope but no evidence of what was actually checked to establish it.
  • Root cause stated without evidence — a conclusion with no interview notes, logs, or records behind it.
  • “Retraining” as the only corrective action, with no change to the procedure, system, or control that let the error happen — addresses the person, not the process.
  • Action items with no named owner or date, making the plan unverifiable against a timeline.
  • Effectiveness verification skipped or undocumented — the CAPA is closed the same day the last action is implemented, with no interval to actually observe whether the fix held.
  • No separate closure approval — the record just stops once the last action is marked complete, with no dated sign-off attesting the whole record was reviewed.

Each of these is a structural gap in the record, independent of whether the underlying investigation was actually done well — which is exactly why they’re so commonly cited: they’re checkable from the document itself, in minutes, without an auditor needing to re-investigate anything.

Frequently Asked Questions

What’s the difference between a CAPA report and a CAPA plan?

In practice the two are usually the same document, or two tightly linked sections of one record: the “report” covers the problem statement, extent-of-condition, and root cause (the investigation), while the “plan” covers the action items, owners, dates, and effectiveness criteria (the response). Auditors expect to trace from one into the other within a single record, not across separate, loosely-connected documents.

Does every CAPA need a full extent-of-condition review?

Yes, at minimum as a documented decision, even if the conclusion is “scope limited to this single instance.” Skipping the section entirely, rather than stating and supporting a narrow scope, is what draws scrutiny — the record needs to show the question was actually asked and checked, not just answered by omission.

How long should a CAPA stay open before effectiveness is checked?

There’s no single regulatory number; the interval has to be long enough to actually observe whether the corrective and preventive actions held under normal operating conditions — a full production cycle, a defined number of subsequent audits, or a fixed calendar interval (commonly 60–90 days) are all defensible choices, but the interval and the specific criterion for “effective” both need to be written into the record before closure, not decided retroactively.

Can a CAPA be closed if the corrective action is still “in progress”?

No — closure approval attests that the action plan was fully executed and effectiveness was verified, so an open action item is incompatible with closure. Partial completion should keep the record open, or split the CAPA into completed and still-open action items rather than closing the whole record prematurely.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 44,322 indexed passages, and every answer cites the ones it drew on.