ISO 9001 corrective action, defined in clause 10.2, is a five-step loop: react to the nonconformity, evaluate whether its cause needs to be eliminated, implement the action, review whether the action worked, and update your risks and quality system if needed. You must also keep records of the nonconformity, the actions taken, and the results — that is clause 10.2.2.
That is the whole requirement. The standard does not demand an 8D report for every scratched part, a software system, or a committee. It demands honest cause-finding and proof, later, that the fix held. Most audit findings against 10.2 come from two habits: writing "operator error" as the root cause, and closing the record the same day the action was taken.
This article walks through each step, shows a record structure that fits on one form, and explains when a simple correction — no CAPA — is the right call.
What Clause 10.2 Requires, Step by Step
Clause 10.2 fits on half a page of the standard. When a nonconformity occurs — including one raised by a customer complaint — you must do the following, in order.
- React to it. Control and correct the problem. Quarantine the parts, rework or scrap them, notify the customer if bad product shipped. Deal with the consequences first.
- Evaluate the need for action to eliminate the cause. Ask two questions: could this happen again, and could it happen somewhere else? If the answer to both is no, you can stop here — record why.
- Find the cause and act. Review the nonconformity, determine the root cause, and check whether similar nonconformities exist or could occur elsewhere. Then implement action that removes the cause — not action that reminds people to be careful.
- Review effectiveness. After enough time has passed to generate evidence, check whether the nonconformity came back. If it did, the action failed. Reopen it.
- Update the system. If the problem revealed a risk you missed, update your risks and opportunities from clause 6.1. If it revealed a broken procedure, change the procedure. This step connects one bad part back to the QMS itself.
Clause 10.2.2 adds the record requirement. You must retain documented information showing the nature of the nonconformity, the actions you took, and the results of the corrective action. One form can hold all three.
Where Nonconformities Come From
A corrective action system needs inputs. In a small manufacturer, they come from a handful of places.
- Nonconforming outputs (clause 8.7). Scrap, rework, sorted lots, returns. Your 8.7 records capture each bad output and its disposition; the recurring ones feed 10.2.
- Customer complaints. Clause 10.2.1 names complaints explicitly. A complaint is a nonconformity that escaped, so it almost always deserves cause analysis — not just an apology and a replacement part.
- Internal audit findings (clause 9.2). Every audit nonconformity requires correction and corrective action. The auditor reports it; you own the fix.
- External audit findings. Your registrar's findings run through the same 10.2 process, and the registrar will verify your response at the next visit.
- Supplier problems (clause 8.4). Bad incoming material is your nonconformity to record, even when the fix belongs to the supplier.
- Trends from data analysis (clause 9.1.3) and management review (clause 9.3). Three "one-off" events in a quarter are a trend, and a trend is a nonconformity with better camouflage.
Root-Cause Honesty: Why 5-Why Turns Into "Operator Error"
Five-why is a fine tool. The failure is not the tool — it is stopping at the first answer that blames a person. Done badly, every chain ends the same way. The part was bad. Why? The operator set the wrong speed. Why? Operator error. Close the record, retrain, move on.
"Operator error" is a symptom, not a cause. A root cause is the condition in your system that allowed the error. Keep asking: why could the operator set the wrong speed? Maybe the setup sheet lists three speeds for three alloys and nothing on the traveler says which alloy this job used. Maybe there is no setup sheet. Maybe two fixtures look identical and only one is correct. Those are causes. Each one points to a fix that does not depend on people being perfect: a mistake-proofed setup, a revised traveler, a labeled fixture, or a defined competence requirement under clause 7.2 — not a lecture.
A quick honesty test: if your corrective action is "retrained the operator" or "told them to be more careful," you have not found the cause. Auditors read closed CAPAs in sequence. Ten records that all end in retraining tell them your cause analysis is theater, and that is itself a finding against 10.2.
An NCR/CAPA Record That Fits on One Form
You do not need CAPA software. A 10-100 person shop can run clause 10.2 on one form or one spreadsheet tab. Here is a structure that covers 10.2.1, 10.2.2, and the disposition records clause 8.7 requires.
| Field | What to write | Weak version auditors flag |
|---|---|---|
| NCR number, date, raised by | A unique ID and who found the problem | Number sequences with gaps — auditors ask where NCR 042 went |
| Description | What happened: part number, quantity, and the requirement that was not met | "Part bad," with no requirement cited |
| Immediate correction and disposition | Contain and correct: quarantine, rework, scrap, or use-as-is with a customer concession (clause 8.7) | Blank, or "fixed it" |
| Corrective action needed? (yes/no) | Your 10.2.1 evaluation, with a one-line reason either way | Always yes (paperwork bloat) or always no (a dodge) |
| Root cause | The system condition that allowed the failure | "Operator error" or "lack of attention" |
| Extent check | Where else the same cause could bite — other parts, lines, shifts | Skipped entirely |
| Action, owner, due date | The change that removes the cause, one named owner, a real date | "Ongoing," with no owner |
| Effectiveness review | Evidence checked after time has passed: recurrence data or a follow-up audit, dated and signed | Signed the same day as the action |
| Risk / QMS update | The change made: risk register, procedure revision, or "none needed" | Skipped entirely |
If you are building this from scratch, your options are: write the procedure and form yourself from the clause text, adapt a purchased template set, or have the full document set drafted for you — ISO Delivered's flat $8,000 documentation package is one option, covering about 44 documents (4 manuals and policies, 15 procedures, 10 work instructions, 15 forms), delivered 2-4 weeks after its questionnaire. Whoever writes it, keep the form to one page. A form people dread is a form people avoid, and an unrecorded nonconformity is worse than an ugly record.
Effectiveness Review: The Step Everyone Skips
Ask a certification auditor which 10.2 finding they write most often, and the common answer is the missing effectiveness review. Shops react well. Many find real causes. Then the record gets closed the same afternoon the fix went in, with "effective" written in the last box before any evidence existed.
Make the review mechanical. Put a "review on" date on every CAPA when you implement the action. Where you can, have someone other than the action owner do the check. Look at real data: scrap rates for that part, the complaint log, the next internal audit of that process. If the problem came back, the action was not effective — reopen the record and dig deeper. Repeat nonconformities sitting behind closed, "effective" CAPAs are how a minor finding turns into a major one.
Effectiveness also feeds management review. Clause 9.3.2 lists nonconformities and corrective actions as a required input, so open-and-closed CAPA status belongs on that agenda, not just in a binder.
When Correction Alone Is Legitimate
The standard says to evaluate the need for action to eliminate the cause. It does not say every nonconformity gets a full CAPA. That evaluation is a real decision, and "no corrective action required" is a compliant answer when you record the reason.
Correction alone fits when the event is genuinely isolated, low-risk, and the cause is already understood. A mislabeled box caught at final inspection because one label printed crooked. A single part scrapped for a tool chip you found and replaced on the spot. Record the nonconformity, record the correction, write one line — "isolated event, cause known, low risk, no action to eliminate cause required" — and move on.
Two guardrails keep this honest. First, complaints and customer escapes almost always deserve cause analysis, because the failure reached a customer. Second, track your correction-only NCRs and look at them in aggregate under clause 9.1.3. The third "isolated" label jam this quarter is not isolated. It is a trend, and a trend converts correction-only events into a corrective action whether you planned one or not.
Frequently asked questions
What is the difference between correction and corrective action in ISO 9001?
A correction fixes the bad output itself: rework the part, replace the shipment, sort the lot. A corrective action eliminates the cause so the problem does not recur. Clause 10.2 requires the correction every time, but corrective action only when your evaluation says the cause needs to be eliminated. Record both, and record the reason when you decide correction alone is enough.
Does every nonconformity need a CAPA?
No. Clause 10.2.1 tells you to evaluate the need for action to eliminate the cause, which means "no corrective action required" is a valid outcome for an isolated, low-risk event with a known cause. Write a one-line justification on the NCR. Customer complaints and escapes should nearly always get full cause analysis, and repeated "one-off" events must be treated as a trend.
Is preventive action still part of ISO 9001?
Not as a separate clause. The 2015 revision removed the standalone preventive action requirement and folded the idea into risk-based thinking under clause 6.1. You address potential problems when you plan the QMS, and clause 10.2 requires you to update those planned risks when a real nonconformity shows your planning missed something.
What records does clause 10.2.2 require?
Two things: evidence of the nature of the nonconformities and the actions taken, and evidence of the results of any corrective action. A single NCR/CAPA form or spreadsheet row covering the description, correction, root cause, action, and effectiveness review satisfies both. Keep the records retrievable, because auditors sample them at every audit.
How long should a corrective action stay open before the effectiveness review?
The standard sets no fixed time. It needs to stay open long enough to generate evidence that the problem did not recur — commonly 30 to 90 days, or a set number of production runs of the affected part. Set the review date when you implement the action so the check happens on schedule. Closing the record the same day you act is one of the mistakes auditors catch most often.
What do auditors check about corrective action during a certification audit?
They sample your NCR and CAPA records and look for real root causes rather than "operator error," actions that were implemented on time, and effectiveness reviews backed by evidence. They also cross-check: whether customer complaints entered the system, whether repeat nonconformities hide behind closed CAPAs, and whether CAPA status appears in your management review inputs under clause 9.3.