1.3 CAPA Verification, Risk-Based, Surveillance & For-Cause

Key Takeaways

  • Audit purpose drives scope, sampling depth, criteria emphasis, and what "enough evidence" means
  • CAPA verification confirms implementation and effectiveness of corrective/preventive actions—not a full system re-audit unless scoped that way
  • Risk-based audits prioritize high-risk processes, changes, suppliers, or failure modes for deeper sampling
  • Accreditation/registration (certification) audits support formal recognition against scheme requirements; surveillance maintains confidence between recertification cycles
  • Compliance audits test conformity to specified requirements; for-cause audits respond to a specific trigger (escape, complaint spike, whistleblower, regulatory action)
Last updated: August 2026

Purpose is not the same as type or party

BoK I.A.3 asks you to recognize why an audit is performed. Purpose sits beside type (product/process/system) and party (first/second/third). A for-cause second-party process audit is a coherent label: purpose + party + type. On the exam, wrong answers often swap purpose labels (calling a routine surveillance visit "for-cause" because one minor NC was opened last year).

Planning chain: purpose → scope and objectives → criteria emphasis → sampling depth and methods → report conclusions tied to that purpose.


CAPA verification audits

CAPA verification determines whether corrective and preventive actions were implemented as planned and whether they were effective in eliminating recurrence (corrective) or occurrence (preventive).

Evidence depth typically includes:

  • Action plan commitments vs. actual changes (procedures, training, tooling, software)
  • Implementation dates and responsible parties
  • Objective evidence that the failure mode is controlled (post-action process data, audit trails, complaint trends, first-pass yield)
  • Check for side effects (new failure modes introduced by the fix)

Scope: Often narrow—centered on the CAPA records, related processes, and affected product/families. It is not automatically a full system audit. Expanding into unrelated clauses without a basis dilutes the purpose.

When used: After major nonconformities, customer escapes, internal audit findings with formal CAPA, regulatory commitments, or management-directed effectiveness checks.

Trap: Closing CAPA based only on "procedure revised" without performance evidence is implementation evidence, not necessarily effectiveness evidence. CQA items love this distinction.

Scenario

Three months after a CAPA for mislabeled kits, an auditor samples 50 recent labels, reviews training records for label control, and checks complaint codes for recurrence. Purpose: CAPA verification (effectiveness-focused).


Risk-based audits

A risk-based approach selects what, how deep, and how often to audit using risk information: severity of harm, occurrence history, detectability, process complexity, change magnitude, supplier criticality, regulatory exposure, or performance metrics.

Risk-based thinking is both:

  • A purpose/driver for scheduling and scoping audits ("we audit sterilization annually because patient risk is high")
  • A method within any audit (deeper samples where risk is higher)

Evidence depth: Higher risk → larger samples, more observation time, more tracing, less reliance on desk-only methods. Lower risk → lighter surveillance or extended intervals, always within scheme or regulatory minimums.

When used: Building the annual internal audit program, choosing supplier audit frequency, focusing certification time on high-risk processes, and justifying resource allocation to management.

Trap: "Risk-based" does not mean "skip inconvenient processes forever." It means prioritize—low-risk areas still need coverage over the cycle, just not equal depth every time.


Accreditation and registration (certification) purposes

In quality-auditor language you will see both registration and certification for management-system recognition; accreditation usually refers to recognition of a conformity assessment body (e.g., lab or certification body) by an accreditation body.

Purpose labelWho is typically auditedOutcome sought
Registration / certificationOrganization’s management systemCertificate of conformity to a standard (e.g., ISO 9001)
AccreditationLab, inspection body, certification body, etc.Formal recognition of competence to perform defined conformity assessment tasks

Evidence depth: Scheme rules define stages (e.g., Stage 1 readiness/document review, Stage 2 implementation), sampling of sites and processes, and required conclusions about conformity and effectiveness. Depth is system-level with process sampling sufficient to support a certification or accreditation decision.

When used: Initial certification, scope extensions, re-accreditation cycles, and assessments required by regulators or market access rules.


Compliance audits

A compliance audit verifies conformity to specified requirements—regulations, statutes, permits, customer mandatory clauses, or internal mandatory rules. The central question is: Are we meeting the "shalls"?

Contrast with a broader management system audit, which still checks conformity but also examines whether the system is effective and improving. Compliance audits can be deep but are often criteria-driven checklists mapped to legal or contractual "musts."

Evidence depth: Tight mapping of each requirement to objective evidence. Gaps are typically noncompliances with clear citation to the requirement. Effectiveness may be secondary unless the requirement itself demands effective control.

When used: Regulatory readiness, environmental permit conditions, data integrity rules, privacy mandates, or contractual compliance programs.

Trap: Calling every audit a compliance audit is sloppy. If the stem emphasizes improvement, process capability, and interaction of QMS processes, prefer system/management effectiveness language—not pure compliance.


Surveillance audits

Surveillance maintains confidence that the auditee continues to conform between major events (notably between certification and recertification). For accredited management-system certification, surveillance is periodic (commonly at least annually under ISO/IEC 17021-1 practice) and samples portions of the system over the cycle so that, across visits, the system is covered.

Evidence depth: Less than a full initial certification audit, but enough to detect significant system degradation. Focus areas often include previous nonconformities, changes, complaints, use of marks, and high-risk processes.

When used: Post-certification monitoring, ongoing supplier oversight schedules, and internal programs that "keep watch" on critical controls between comprehensive audits.

Trap: Surveillance is planned and periodic, not necessarily triggered by failure. Triggered audits are usually for-cause (below).


For-cause audits

A for-cause (or "for cause") audit is initiated because of a specific triggering event or serious concern: major escape, adverse event cluster, whistleblower allegation, regulatory warning, sudden metric crash, suspected data integrity failure, or credible rumor of process abandonment.

Evidence depth: Usually intense and focused on the trigger, related processes, time windows, and potentially implicated products or data. May expand if systemic failure is indicated. Timelines are compressed; access and preservation of evidence matter.

When used: Anytime risk of ongoing harm or major nonconformity demands immediate independent evaluation outside the routine schedule.

For-cause vs surveillance vs CAPA verification

PurposeTriggerTypical breadth
SurveillanceCalendar / scheme schedulePartial system sample
CAPA verificationClosed or due CAPA actionsActions and affected process
For-causeIncident or allegationTrigger-focused, expandable

A for-cause audit may generate CAPAs; a CAPA verification audit checks prior CAPAs. Do not mix the labels.


How purpose drives scope and evidence depth

PurposeScope tendencyEvidence depth tendency
CAPA verificationActions + related process/productImplementation + effectiveness metrics
Risk-based programHigh-risk processes firstDepth proportional to risk
Certification / accreditationSystem (or competence scope) per schemeScheme-defined sufficiency for decision
ComplianceRequirement set (law, permit, contract)Requirement-by-requirement evidence
SurveillancePartial system / agreed focus areasModerate; continuity of conformity
For-causeTrigger and related controlsDeep, time-bound, possibly forensic

Auditor takeaway: When writing or reviewing an audit plan, if you cannot state the purpose in one sentence, scope will drift and findings will not answer the client’s question. Purpose statements belong in the audit plan and opening meeting.

/practice/cqaPractice questions with detailed explanations

Key Takeaways

  • Purpose dictates scope, sampling, and what conclusion you must support.
  • CAPA verification tests implementation and effectiveness, not paperwork alone.
  • Risk-based auditing prioritizes depth; it does not permanently exempt low-risk areas.
  • Surveillance is scheduled confidence maintenance; for-cause is trigger-driven intensity.
  • Compliance focuses on "shall" conformity; certification/accreditation support formal recognition decisions.
Test Your Knowledge

Three weeks after a field action for incorrect software configuration, management directs an unscheduled audit of configuration management, release, and complaint coding for the affected product family. The primary purpose is best described as:

A
B
C
D
Test Your Knowledge

Which evidence set best supports CAPA effectiveness verification after a recurring packaging defect?

A
B
C
D
Test Your Knowledge

Under a risk-based internal audit program, which process would most justifiably receive the deepest sampling this year?

A
B
C
D
Test Your Knowledge

A certification body visits a certified client 12 months after initial certification to sample selected processes, follow up previous nonconformities, and confirm continued conformity. This visit is primarily a:

A
B
C
D