Ask a premarket team where corrective and preventive action (CAPA) sits on the priority list, and it usually lands below design controls, risk management, and the submission itself. The reasoning is easy to follow. Nothing has shipped, so there are no complaints to investigate, no returned product to analyze, and no field failures to trend. Standing up a full CAPA program before there is anything to correct looks like paying for a process nobody will touch for a year.
|
ADVERTISEMENT |
That instinct is half right. A development-stage company doesn’t need the CAPA program a commercial manufacturer runs, with trending dashboards, escalation tiers, and a monthly review board. What it needs is a CAPA process that works and is sized to the volume of quality events a company actually generates before launch. Those two things get confused constantly, and the confusion costs in both directions: Teams that skip CAPA entirely, and teams that copy a 40-page procedure from a consultant and then drown in it.
What an auditor checks first
Look at what the U.S. Food and Drug Administration actually cites. In fiscal year 2025, the FDA recorded roughly 2,660 device-related Form 483 citations, and the single most frequent one was inadequate CAPA procedures under 21 CFR 820.100(a), accounting for 279 observations, or about one in 10 of all device citations. Complaint handling came second.
Read the citation language carefully. Inspectors write up procedures, not volume. No manufacturer has ever been cited for having too few CAPAs. They get cited because the procedure is missing a required element, because the procedure exists, but the records show it wasn’t followed, or because actions were closed without anyone verifying they worked.
That distinction is the whole argument for premarket teams. The bar an auditor applies is qualitative. Does a documented procedure exist, does it define its inputs, and can you show one example of the loop closing from problem to root cause to action to verification? A company with four well-run CAPA records clears that bar. A company with 60 sloppy ones does not.
ISO 13485:2016 makes the documented procedure explicit in Clause 8.5.2, one of the few places in the standard where a procedure is mandated by name. As of Feb. 2, 2026, that clause is FDA’s requirement, too. The Quality Management System Regulation (QMSR) amended 21 CFR Part 820 to incorporate ISO 13485:2016 by reference, FDA retired the Quality System Inspection Technique on the same date, and inspections now run under compliance program 7382.850. Early post-QMSR observations cite ISO clauses directly rather than legacy Part 820 sections. Your corrective action procedure is now a regulatory document in both jurisdictions, which is an argument for writing it once, correctly, rather than twice.
The clock starts earlier than most teams assume
For a 510(k) device, the FDA is clear that facility inspections aren’t part of the clearance process. The agency’s own guidance states there is no preapproval inspection as a prerequisite to 510(k) clearance, followed immediately by the warning that a manufacturer should be prepared for a quality system inspection at any time after clearance is granted.
Read that sentence again, and the timeline problem should become obvious. Nobody checks your CAPA process before clearance, but an inspector can check it the day after. There’s no grace period written into the regulation, no ramp-up window, and no allowance for a company that was busy launching. The system must exist on Day One of commercial distribution, which means it has to be built during the phase when it feels least necessary.
Europe removes even that ambiguity. A notified body audits the quality management system before the CE certificate is issued, and CAPA is a standard part of that assessment. The same holds for ISO 13485 certification anywhere in the world. Stage 1 of a certification audit almost always produces findings, each one has to be answered with a documented corrective action, and the Stage 2 auditor will pull those records specifically to see how the process performed. If any of them carry a completed effectiveness check, that is the strongest evidence available that the system functions.
The quality events are already happening
Premarket work generates plenty of material for a CAPA system. For example:
• A supplier ships components outside the agreed specification.
• A verification protocol fails because the acceptance criteria were written against the wrong requirement.
• Someone discovers that three design reviews were held without recorded attendees.
• An internal audit turns up document control gaps ahead of certification.
Every one of those is a legitimate CAPA input under 8.5.2, and every one of them is happening right now inside companies that describe themselves as not having any quality events yet. The events are real. The capture mechanism is missing, so they get resolved over Slack, in a design review, or in someone’s head, and the evidence of resolution vanishes with the conversation.
The cost of that gap arrives later, when an auditor asks how the supplier issue was handled, and the honest answer is that the team fixed it and moved on with no record of the investigation, the root cause, or the check that confirmed the fix held. Reconstructing that history from memory and email threads, 18 months after the fact, takes far longer than logging it would have taken at the time. Cleanup always costs more than setup.
What minimal but real actually looks like
The standard itself supports scaling. Clause 8.5.2 requires that corrective actions be taken without undue delay and be proportionate to the effects of the nonconformities encountered. Proportionate cuts both ways. A minor documentation error doesn’t warrant a formal eight-discipline investigation, and a supplier defect with patient-safety implications warrants considerably more than a one-line note.
A defensible premarket CAPA process comes down to six things, and none of them require a large team:
1. One documented procedure that names its data sources: supplier nonconformances, internal audit findings, verification and validation failures, design review actions, and, once you are commercial, complaints and service records.
2. A written decision rule that separates a correction from a corrective action so the team knows what gets logged and what gets escalated.
3. Investigation depth scaled to risk, with the reasoning for the depth recorded rather than assumed.
4. Documented action, including verification that the action doesn’t adversely affect the ability to meet regulatory requirements.
5. An effectiveness check with a defined method and a defined date; that’s the element auditors find missing most often.
6. Records that feed management review so quality events are visible to leadership rather than buried in a folder.
Six elements, one procedure, and a place to store the records: That’s a week of setup work if the templates already exist, and several weeks of drafting and internal review if they don’t.
The opposite failure is just as costly
Overcorrection is the other trap. A team that takes CAPA seriously for the first time often responds by routing every typo, every meeting that ran long, and every misfiled document into a formal CAPA. Twelve months later there are 40 open records, none closed, and none verified.
An auditor reading 40 open CAPAs with no effectiveness checks reaches a conclusion faster than one reading four closed ones, because an unmanaged backlog is direct evidence that the documented process isn’t being followed. The volume becomes the finding. Getting the trigger right matters more than getting the coverage broad, which is why what should actually trigger a CAPA is the first question to answer before writing the procedure, not after.
The same logic governs everything else in a premarket quality system. Teams don’t need more QMS. They need a right-sized QMS to stop paying the hidden tax on engineering and regulatory time, and CAPA is one of the places where that principle most clearly applies.
Build a right-sized CAPA program
Two things make lightweight CAPA hold up under audit: a procedure written to the standard, and a system that connects quality events to the records they affect.
Writing compliant templates and procedures from scratch is where most of the time goes. Manually drafting and validating the full set of SOPs a premarket team needs for regulatory readiness runs to roughly 400 hours of work, which is the real reason CAPA gets deferred. It’s rarely a philosophical objection to the process. It’s a calculation about where a small team spends its next 40 hours.
Greenlight Guru removes that first cost. The CAPA workflow ships preconfigured with root cause analysis, effectiveness checks, and approvals built into the record, and it arrives alongside more than 80 audit-tested templates written by medtech professionals rather than adapted from a generic quality platform. Each quality event links to the design controls, risk records, and supplier records it touches, so an auditor tracing a supplier nonconformance to its resolution follows a connected path instead of a manual reconstruction. Companies running the full system see a 3.5 times reduction in the likelihood of major audit findings.
To see how that looks inside the system, schedule a free demo of Greenlight Guru.
Published Aug. 14, 2026, by Greenlight Guru.

Add new comment