Free tool · CAPA record self-review
Pick one real CAPA and test whether its logic holds up — before an auditor or regulatory authority exposes the gaps for you.
The quick scan takes about 10-15 minutes for one CAPA. You don’t have to finish in one sitting — your review is saved as you type and will be here when you come back.
Pick one CAPA that’s representative. Ideally one where you have a feeling that some things might be challenging to explain during the next external audit or FDA inspection.
Pick the phase of the CAPA (e.g., initiation or investigation). Only the sections that are reviewable at that phase are expected — the rest can wait.
Work through the sections. Mark each item OK, Gap, or N/A — and write down what you find.
Print your review with all findings and fix prompts, or download a backup to continue later.
The guidance behind the checks — open what you need.
Pick one CAPA. Real, recent, and representative.
Good candidates:
Poor candidates:
Individual items that don’t apply: mark them N/A and give the reason in the section’s Notes field. Don’t leave items blank or mark N/A without explanation.
Example: “N/A — no containment required, single unit replaced on site before investigation began.”
Preventive-only CAPAs (no nonconformity occurred): Section 2 (Correction & containment) may be largely N/A. Document the rationale at the top of that section’s Notes field, and include only preventive actions in Section 5.
CAPAs that haven’t reached a phase yet: the phase selector above handles this — sections beyond the current phase aren’t expected yet. Review what exists now and come back as the CAPA progresses; your review is saved.
Weaknesses are the point. The tool is designed to find them before someone else does.
If a section rates “Needs work”: use the Fix prompt to document what needs to change and who owns the revision, set a target date, and re-review the section after revisions are made.
If a section rates “High risk”: do not close the CAPA until this is resolved. Escalate to the CAPA owner, functional leadership, or quality leadership — CAPAs are not solely a quality responsibility.
Weaknesses cascade. A vague problem statement leads to an unfocused investigation, a root cause that doesn’t actually explain the issue, and actions that don’t prevent recurrence. Missing containment undermines the risk assessment and the effectiveness criteria. If one section is High risk, re-examine the sections that follow it.
Not every CAPA needs the same depth of investigation or the same rigor of documentation. A low-risk process gap and a patient safety event require different levels of response. The stress test evaluates whether the response is justified — not whether it is maximal. Do what the situation requires. Document why. Stop when sufficient.
CAPA under review: CAPA-2025-018 — Dashboard risk score display failure
| Checklist item | What the reviewer recorded |
|---|---|
| Source of issue identified | ✓ Customer complaint (CC-2025-031) |
| Detection method documented | ✓ Reported by clinical informatics manager via support portal |
| Corrective or preventive CAPA | ✓ Corrective — actual nonconformity occurred |
| Problem statement uses observable facts | ✓ “Risk score dashboard displayed ‘---’ instead of numeric scores for 23 ICU patients at Memorial Hospital on Jan 21, 1:47–5:23 AM. Requirement REQ-112 states scores must display within 30 seconds.” |
| Scope defined | ✓ 1 of 12 sites, ICU only, 23 patients, 3.5-hour window |
| No assumed causes in problem statement | ✓ Statement describes the gap, not the reason |
| Language precise | ✓ No vague generalities |
| CAPA scope/boundaries defined | ✓ “This CAPA covers the display failure at Memorial Hospital. Performance at other sites will be assessed as part of the investigation but is not in scope for corrective action unless evidence shows they are affected.” |
| Escalation justified | ✓ Patient safety (clinical decisions affected), requirement violation, potential systemic cause |
| Evidence referenced | ✓ CC-2025-031, error logs (attached), REQ-112, deployment record v3.4.1 |
Notes: Problem statement is clear and well-scoped. No assumed causes. Evidence trail is strong. Escalation to CAPA justified — meets patient safety and requirement-violation criteria.
Fix prompt: No revision needed. Section confidence: Strong.
Section 4 — Investigation & root cause logic. What a useful Fix prompt looks like when a section has a weakness:
“Root cause statement currently reads: ‘Human error — the deployment engineer did not test under ICU load conditions.’ This stops at the person. The investigation needs to go further: Why was ICU-specific testing not part of the deployment process? Why did the timeout change not trigger a risk review? QA Engineer (J. Martinez) to revise root cause analysis by Feb 14. Revised analysis must trace the cause chain to the process/system gap, not the individual.”
Weaknesses are the point. The tool is designed to find them before someone else does.
Builds itself from your answers above. Add the top weaknesses and your recommendation, then print.
The quick scan asks the key questions. Subscribers get the deep version:
Delivered by email, along with my honest, practical advice on NC & CAPA. No fluff. Unsubscribe anytime.