9.2 Reviewing and Negotiating CAPA Plans

Key Takeaways

  • CQA BoK II.D.2 (Evaluate) requires judging CAPA plan acceptability—including actions, responsibilities, and schedule—against finding significance, risk, and the auditee’s CAPA procedure.
  • Acceptable plans show a clear finding→cause→action chain, realistic milestones, interim containment when risk remains, and defined effectiveness checks.
  • Negotiation is professional and evidence-based: push for stronger controls or tighter timing when risk warrants; do not trade away criteria or invent root causes for the auditee.
  • Schedule evaluation balances urgency (customer/regulatory/product risk) with feasibility; aggressive dates without resources are as unacceptable as open-ended delays.
  • Exam trap: approving any signed plan; or the auditor rewriting the entire CAPA as the auditee’s substitute process owner.
Last updated: August 2026

9.2 Reviewing and Negotiating CAPA Plans (CQA BoK II.D.2 — Evaluate)

/practice/cqaPractice questions with detailed explanations

After findings are reported, the auditee (or supplier) typically submits a corrective action plan. BoK II.D.2 tests whether you can evaluate that plan’s acceptability—including timing—and professionally negotiate improvements. This is still Evaluate, not “become the process owner.”

Why Plan Review Matters

Verification (II.D.3) can only confirm what was planned and done. If the plan never addresses root cause, verification may “pass” implementation of a useless action. Plan review is the control gate that protects the audit program’s integrity and the customer’s risk posture.

Stakeholder needPlan review contribution
Customer / clientConfidence that serious findings will be fixed on time
Auditee managementClear expectations; fewer late surprises
Auditor / programTraceable acceptance decisions; defensible escalation later
Regulators / certifiersEvidence that NCs are managed systematically

Inputs to Plan Acceptability

Evaluate plans against multiple inputs—not only politeness of the wording:

  1. Original finding — criteria, evidence, significance/severity, unique ID
  2. Risk — product safety, compliance, customer impact, process criticality
  3. Auditee CAPA procedure — required elements, approval levels, time limits
  4. Contract / scheme rules — customer quality agreements, certification body response times
  5. Extent of condition — one instance vs systemic pattern
  6. Prior history — repeat findings, overdue CAPAs, previous ineffective closures

A minor administrative NC and a systemic safety-related NC do not deserve identical plan scrutiny depth—but both need logical completeness.

CAPA Plan Acceptability Checklist

A. Scope and linkage

  • Plan references the correct finding ID(s) and restates the problem accurately.
  • Root cause (or investigation plan with due date) is stated and plausibly explains the evidence.
  • Actions map cause → control, not only symptoms.
  • Related processes/products/sites affected by extent analysis are included or justified as out of scope.

B. Action quality

Acceptable action traitsUnacceptable traits
Specific and verifiable (“implement barcode match gate in ERP module X”)Vague (“improve awareness”)
Addresses system, not only one personPure blame without process change
Includes interim containment if risk continuesOpen risk with no protection
Defines deliverables (doc rev, training, software change, validation)“Will try harder”
Considers side effects / change controlUncontrolled change risks new failures

C. Responsibility and resources

  • Named owners for each action line item.
  • Evidence that owners have authority and bandwidth (or escalation if not).
  • Cross-functional support identified when needed (IT, Engineering, HR, Supplier Quality).
  • Customer approval steps included when the quality agreement requires them.

D. Schedule and milestones

Schedules should be risk-based and resource-realistic.

Schedule patternEvaluation
Immediate containment within hours/days for ongoing product riskExpected for high risk
Investigation complete with interim actions, then systemic fix on a staged timelineOften acceptable if risk controlled
18-month due date for a simple document correction with no interim controlUsually unacceptable
All majors due “tomorrow” with no resourcesNot credible; negotiate realistic plan with interim controls
Open-ended “ongoing” with no milestonesNot acceptable for formal CAPA closure tracking

Break complex CAPAs into milestones: investigation complete → interim controls live → permanent change implemented → training/effectiveness criteria ready → request verification.

E. Effectiveness criteria (designed up front)

Even before full verification, the plan should state how success will be judged (metrics, period, sample, audit method). “We’ll know it when we see it” is not an acceptable effectiveness plan for significant findings.

Negotiation: What It Is and Is Not

Negotiation means professional dialogue to improve plan quality and timing while remaining objective and criteria-based.

Negotiation isNegotiation is not
Requesting clearer actions tied to root causeTrading away the finding because the auditee is upset
Aligning due dates to risk and resourcesAccepting indefinite delay for major safety issues
Clarifying evidence needed at verificationWriting the entire CAPA for the auditee as default
Escalating when agreement cannot be reachedPublic shaming or personal attacks
Documenting agreed plan changesSilent side deals not reflected in records

Practical negotiation moves

  1. Mirror the risk: “Because product was released without inspection evidence, we need interim release controls by date X, not only a document rewrite in Q4.”
  2. Ask for the chain: “Help me see how action 3 removes the root cause you stated.”
  3. Offer structure, not ownership: Suggest missing elements (effectiveness metric, extent check) without dictating the technical design solution if the auditee owns the process.
  4. Use procedure and agreement language: Point to the auditee’s CAPA SOP or customer response-time clauses.
  5. Record the outcome: Accepted plan, conditional acceptance with required revisions, or rejection with reasons and escalation path.

Scenario — Negotiate the schedule

Supplier CAPA for a major labeling NC proposes permanent artwork system change in 12 months, with no interim control. Customer risk is high (wrong clinical labels).

Weak auditor response: “OK, see you in a year.”
Strong evaluate + negotiate response: Require immediate containment and interim 100% inspection / barcode check within days; staged permanent system change with interim milestones; effectiveness monitoring of complaint and internal reject codes monthly; escalate if supplier refuses interim protection.

Conditional Acceptance and Rejection

Not every plan is binary pass/fail on first submission.

DecisionWhen usedFollow-through
AcceptElements complete; schedule risk-appropriate; owners clearTrack milestones; plan verification
Conditional acceptCore direction sound; minor gaps (metric clarity, missing training audience)Written conditions and resubmittal date
Reject / returnNo root cause, actions unrelated, schedule ignores risk, ownership missingDocument reasons; require resubmittal; escalate if late
EscalateRepeat refusal, political blockage, regulatory exposureClient, certification body rules, senior management per program

Document why you accepted or rejected. Future auditors and management review need the trail.

Special Contexts

Internal audits

Plan review may be performed by the lead auditor, audit program manager, or process owner’s management per procedure. Independence matters when the reviewer is too close to the failure.

Supplier (second-party) audits

Customer quality agreements often set response and closure clocks. Negotiation includes commercial leverage—but auditors still need objective evaluation of technical adequacy, not only “supplier promised hard.”

Certification / third-party

Schemes may define nonconformity response timelines and evidence packages. Auditors evaluate against scheme rules plus good CAPA practice.

Multi-site / corporate CAPA

When the root is corporate (shared ERP), site-level plans that only retrain local staff are incomplete. Negotiate elevation to the level that can change the system.

Red Flags During Plan Review

Red flagWhy it matters
Investigation due after “effectiveness complete”Logic inverted
Same CAPA text reused for unrelated NCsNot problem-specific
Due date equals verification date with no implementation windowNo time to show sustained control
Owner is on leave / vacant roleSchedule not credible
Actions increase risk elsewhere without change controlSide-effect blindness
Plan disputes the finding facts without new evidenceRe-litigation instead of CAPA
“Awaiting budget” with no interim risk controlRisk left open

Worked Example — Accept or Negotiate?

Finding: Temperature-sensitive components stored outside validated range for 11 days (logger data); criteria = validated 2–8°C storage.

Plan submitted:

  • Cause: “Door left open.”
  • Action: Email reminder to staff.
  • Due: 6 months.
  • Effectiveness: none stated.

Evaluation: Reject/return. Cause likely incomplete (why alarms failed, why door ajar possible, mapping/logger response). Action is low on effectiveness hierarchy. Schedule not aligned to product risk. Missing containment of exposed product disposition history.

Negotiated expectations: Immediate product impact assessment and disposition; alarm challenge testing; door/alarm engineering or procedural interlocks; short-interval monitoring; training with competency check; effectiveness = alarm response metrics + no excursions beyond defined limits for defined period; earlier due dates for interim controls.

Interface with Reporting and Ethics

Plan review must stay consistent with the issued finding. Do not “negotiate” the finding out of existence without evidence that it was factually wrong (that is correction of the audit record, a different process). Confidentiality and professional conduct still apply—supplier negotiations may be commercially sensitive.

Exam Anchors

  • Evaluate plan adequacy + schedule, not signatures alone.
  • Negotiate for risk-proportional strength and timing.
  • Demand linkage finding → cause → action → effectiveness plan.
  • Use conditional acceptance and documented rejection when needed.
  • Know when to escalate rather than endlessly re-negotiate a non-viable plan.
Test Your Knowledge

A high-risk major nonconformity has ongoing product exposure. The auditee’s CAPA plan proposes only a procedure rewrite due in nine months and no interim controls. What is the most appropriate II.D.2 response?

A
B
C
D
Test Your Knowledge

Which CAPA plan element most directly helps the auditor evaluate whether proposed actions address the real issue?

A
B
C
D
Test Your Knowledge

During negotiation, the plant manager asks the auditor to delete a major finding in exchange for an aggressive CAPA on a minor finding. What should the auditor do?

A
B
C
D
Test Your Knowledge

A CAPA plan for a systemic ERP control gap is owned only by a temporary intern with no IT authority, due in two weeks, with no milestone for system change approval. How should schedule and responsibility be evaluated?

A
B
C
D