Register / MIQ-ART-003

NCR vs. CAPA: What's the Difference, and How Should They Connect?

Nonconformance reports and corrective action are different tools for different jobs. Here’s where one ends, where the other begins, and why the link between them is where most quality systems leak.

Document No.
MIQ-ART-003
Revision
A
Effective Date
May 27, 2026
Category
Corrective Action
Prepared By
My ISO Consultants

Ask three quality managers where an NCR ends and a CAPA begins and you’ll get three answers, usually shaped by whatever their last system forced them to do. The confusion isn’t academic. When the boundary is fuzzy, one of two failure modes takes over: every nonconformance spawns a full root-cause investigation (and the team drowns), or none of them do (and the same defect returns every quarter).

Here’s the clean version of the distinction, and the part that matters more than the definitions: the link between the two.

The NCR: deal with the thing in front of you

A nonconformance report records that something failed to meet a requirement: a part out of spec, a process step skipped, a service delivered wrong, a supplier shipment that fails receiving inspection. The NCR’s job is narrow and immediate:

  1. Identify what doesn’t conform, against which requirement.
  2. Contain it: stop it from reaching a customer or the next operation.
  3. Disposition it: rework, repair, use-as-is with concession, scrap, return to supplier.
  4. Record the decision and who made it.

That’s it. An NCR is fundamentally about the nonconforming output: the physical part, the failed batch, the wrong invoice. ISO 9001 covers this in clause 8.7. A good NCR can be opened and closed the same day, and most should be.

The CAPA: deal with why it happened

A corrective action answers a different question: what caused this, and what will prevent it from happening again? That’s clause 10.2 territory, and it involves work an NCR never requires:

  • Root cause analysis: actually investigating, not writing “operator error” in a box.
  • Action on the cause: a process change, a fixture, a revised document, new training.
  • Effectiveness verification: coming back later to confirm the problem actually stopped recurring, which is the step manual systems skip most often.

(The “PA” in CAPA, preventive action, is worth a footnote: ISO 9001:2015 folded standalone preventive action into risk-based thinking. Most modern systems treat CAPA and corrective action as synonyms, with prevention handled through risk registers and the corrective actions themselves.)

The boundary in one sentence

The NCR fixes the part. The CAPA fixes the process. Closing an NCR means the nonconforming output is dealt with. Closing a CAPA means the cause is dealt with. You can complete the first without ever touching the second, and that’s often correct.

Not every NCR deserves a CAPA

This surprises people implementing their first formal system: escalating every nonconformance to root-cause investigation is a mistake, and clause 10.2 doesn’t ask for it. The standard says to evaluate the need for action to eliminate the cause. Reasonable triggers for opening a CAPA:

  • Recurrence: the same failure mode showing up repeatedly.
  • Severity: anything that reached a customer, affected safety, or cost real money.
  • Trend: a category of NCRs climbing over time even if no single one is severe.
  • Audit findings and complaints, which enter the same corrective-action loop from a different door.

A quality system with 200 NCRs and 12 well-chosen, well-verified CAPAs a year is usually far healthier than one with 200 of each.

Here’s the operational problem, and it’s the reason this article exists: the NCR-to-CAPA connection is a relationship between records, and spreadsheets are terrible at relationships.

In a typical manual QMS, NCRs live in one spreadsheet and corrective actions in another. The link between them is a reference number typed into a cell, when someone remembers. Which means the questions that actually protect you have no reliable answers:

  • Has this failure mode occurred before? Requires searching free-text descriptions written by different people on different days.
  • Which NCRs led to this CAPA? Requires the cross-reference having been typed correctly, twice.
  • Did the corrective action work? Requires someone noticing that the same defect reappeared three months later, logged by someone else, described in different words.

So recurrence, the single most important trigger for corrective action, is precisely the thing a spreadsheet system can’t see. Each nonconformance arrives as if it were the first of its kind.

What a closed loop looks like

In a well-built system, the chain is navigable in both directions:

NCR → disposition → (evaluation) → CAPA → root cause → actions → effectiveness check → closure, with every arrow being an actual link, not a typed reference. Structured failure-mode categories instead of free text, so trends are queryable. Effectiveness checks with due dates that escalate when they’re missed, because an unverified corrective action is just a hopeful memo.

When auditors talk about a “closed-loop” quality system, this is the loop. And when we’re brought in to rescue a struggling QMS, an open loop is what we usually find: dispositions happening, investigations happening, and a gap where the connection between them should be.

The takeaway

Keep the tools distinct: NCRs for the output, fast and lightweight; CAPAs for the cause, fewer and deeper. Spend your rigor on the connection between them, because the difference between recording quality events and actually learning from them lives entirely in that link.

MIQ-ART-003 · Rev A · 4 min read · Uncontrolled when printed← Back to the Register

Reading About It Is the Slow Way.

Request early access and a consultant will walk you through the system live, on your processes, not canned demo data.

Request Early Access