9.2 Reviewing and Negotiating CAPA Plans
Key Takeaways
- CQA BoK II.D.2 (Evaluate) requires judging CAPA plan acceptability—including actions, responsibilities, and schedule—against finding significance, risk, and the auditee’s CAPA procedure.
- Acceptable plans show a clear finding→cause→action chain, realistic milestones, interim containment when risk remains, and defined effectiveness checks.
- Negotiation is professional and evidence-based: push for stronger controls or tighter timing when risk warrants; do not trade away criteria or invent root causes for the auditee.
- Schedule evaluation balances urgency (customer/regulatory/product risk) with feasibility; aggressive dates without resources are as unacceptable as open-ended delays.
- Exam trap: approving any signed plan; or the auditor rewriting the entire CAPA as the auditee’s substitute process owner.
9.2 Reviewing and Negotiating CAPA Plans (CQA BoK II.D.2 — Evaluate)
/practice/cqaPractice questions with detailed explanations
After findings are reported, the auditee (or supplier) typically submits a corrective action plan. BoK II.D.2 tests whether you can evaluate that plan’s acceptability—including timing—and professionally negotiate improvements. This is still Evaluate, not “become the process owner.”
Why Plan Review Matters
Verification (II.D.3) can only confirm what was planned and done. If the plan never addresses root cause, verification may “pass” implementation of a useless action. Plan review is the control gate that protects the audit program’s integrity and the customer’s risk posture.
| Stakeholder need | Plan review contribution |
|---|---|
| Customer / client | Confidence that serious findings will be fixed on time |
| Auditee management | Clear expectations; fewer late surprises |
| Auditor / program | Traceable acceptance decisions; defensible escalation later |
| Regulators / certifiers | Evidence that NCs are managed systematically |
Inputs to Plan Acceptability
Evaluate plans against multiple inputs—not only politeness of the wording:
- Original finding — criteria, evidence, significance/severity, unique ID
- Risk — product safety, compliance, customer impact, process criticality
- Auditee CAPA procedure — required elements, approval levels, time limits
- Contract / scheme rules — customer quality agreements, certification body response times
- Extent of condition — one instance vs systemic pattern
- Prior history — repeat findings, overdue CAPAs, previous ineffective closures
A minor administrative NC and a systemic safety-related NC do not deserve identical plan scrutiny depth—but both need logical completeness.
CAPA Plan Acceptability Checklist
A. Scope and linkage
- Plan references the correct finding ID(s) and restates the problem accurately.
- Root cause (or investigation plan with due date) is stated and plausibly explains the evidence.
- Actions map cause → control, not only symptoms.
- Related processes/products/sites affected by extent analysis are included or justified as out of scope.
B. Action quality
| Acceptable action traits | Unacceptable traits |
|---|---|
| Specific and verifiable (“implement barcode match gate in ERP module X”) | Vague (“improve awareness”) |
| Addresses system, not only one person | Pure blame without process change |
| Includes interim containment if risk continues | Open risk with no protection |
| Defines deliverables (doc rev, training, software change, validation) | “Will try harder” |
| Considers side effects / change control | Uncontrolled change risks new failures |
C. Responsibility and resources
- Named owners for each action line item.
- Evidence that owners have authority and bandwidth (or escalation if not).
- Cross-functional support identified when needed (IT, Engineering, HR, Supplier Quality).
- Customer approval steps included when the quality agreement requires them.
D. Schedule and milestones
Schedules should be risk-based and resource-realistic.
| Schedule pattern | Evaluation |
|---|---|
| Immediate containment within hours/days for ongoing product risk | Expected for high risk |
| Investigation complete with interim actions, then systemic fix on a staged timeline | Often acceptable if risk controlled |
| 18-month due date for a simple document correction with no interim control | Usually unacceptable |
| All majors due “tomorrow” with no resources | Not credible; negotiate realistic plan with interim controls |
| Open-ended “ongoing” with no milestones | Not acceptable for formal CAPA closure tracking |
Break complex CAPAs into milestones: investigation complete → interim controls live → permanent change implemented → training/effectiveness criteria ready → request verification.
E. Effectiveness criteria (designed up front)
Even before full verification, the plan should state how success will be judged (metrics, period, sample, audit method). “We’ll know it when we see it” is not an acceptable effectiveness plan for significant findings.
Negotiation: What It Is and Is Not
Negotiation means professional dialogue to improve plan quality and timing while remaining objective and criteria-based.
| Negotiation is | Negotiation is not |
|---|---|
| Requesting clearer actions tied to root cause | Trading away the finding because the auditee is upset |
| Aligning due dates to risk and resources | Accepting indefinite delay for major safety issues |
| Clarifying evidence needed at verification | Writing the entire CAPA for the auditee as default |
| Escalating when agreement cannot be reached | Public shaming or personal attacks |
| Documenting agreed plan changes | Silent side deals not reflected in records |
Practical negotiation moves
- Mirror the risk: “Because product was released without inspection evidence, we need interim release controls by date X, not only a document rewrite in Q4.”
- Ask for the chain: “Help me see how action 3 removes the root cause you stated.”
- Offer structure, not ownership: Suggest missing elements (effectiveness metric, extent check) without dictating the technical design solution if the auditee owns the process.
- Use procedure and agreement language: Point to the auditee’s CAPA SOP or customer response-time clauses.
- Record the outcome: Accepted plan, conditional acceptance with required revisions, or rejection with reasons and escalation path.
Scenario — Negotiate the schedule
Supplier CAPA for a major labeling NC proposes permanent artwork system change in 12 months, with no interim control. Customer risk is high (wrong clinical labels).
Weak auditor response: “OK, see you in a year.”
Strong evaluate + negotiate response: Require immediate containment and interim 100% inspection / barcode check within days; staged permanent system change with interim milestones; effectiveness monitoring of complaint and internal reject codes monthly; escalate if supplier refuses interim protection.
Conditional Acceptance and Rejection
Not every plan is binary pass/fail on first submission.
| Decision | When used | Follow-through |
|---|---|---|
| Accept | Elements complete; schedule risk-appropriate; owners clear | Track milestones; plan verification |
| Conditional accept | Core direction sound; minor gaps (metric clarity, missing training audience) | Written conditions and resubmittal date |
| Reject / return | No root cause, actions unrelated, schedule ignores risk, ownership missing | Document reasons; require resubmittal; escalate if late |
| Escalate | Repeat refusal, political blockage, regulatory exposure | Client, certification body rules, senior management per program |
Document why you accepted or rejected. Future auditors and management review need the trail.
Special Contexts
Internal audits
Plan review may be performed by the lead auditor, audit program manager, or process owner’s management per procedure. Independence matters when the reviewer is too close to the failure.
Supplier (second-party) audits
Customer quality agreements often set response and closure clocks. Negotiation includes commercial leverage—but auditors still need objective evaluation of technical adequacy, not only “supplier promised hard.”
Certification / third-party
Schemes may define nonconformity response timelines and evidence packages. Auditors evaluate against scheme rules plus good CAPA practice.
Multi-site / corporate CAPA
When the root is corporate (shared ERP), site-level plans that only retrain local staff are incomplete. Negotiate elevation to the level that can change the system.
Red Flags During Plan Review
| Red flag | Why it matters |
|---|---|
| Investigation due after “effectiveness complete” | Logic inverted |
| Same CAPA text reused for unrelated NCs | Not problem-specific |
| Due date equals verification date with no implementation window | No time to show sustained control |
| Owner is on leave / vacant role | Schedule not credible |
| Actions increase risk elsewhere without change control | Side-effect blindness |
| Plan disputes the finding facts without new evidence | Re-litigation instead of CAPA |
| “Awaiting budget” with no interim risk control | Risk left open |
Worked Example — Accept or Negotiate?
Finding: Temperature-sensitive components stored outside validated range for 11 days (logger data); criteria = validated 2–8°C storage.
Plan submitted:
- Cause: “Door left open.”
- Action: Email reminder to staff.
- Due: 6 months.
- Effectiveness: none stated.
Evaluation: Reject/return. Cause likely incomplete (why alarms failed, why door ajar possible, mapping/logger response). Action is low on effectiveness hierarchy. Schedule not aligned to product risk. Missing containment of exposed product disposition history.
Negotiated expectations: Immediate product impact assessment and disposition; alarm challenge testing; door/alarm engineering or procedural interlocks; short-interval monitoring; training with competency check; effectiveness = alarm response metrics + no excursions beyond defined limits for defined period; earlier due dates for interim controls.
Interface with Reporting and Ethics
Plan review must stay consistent with the issued finding. Do not “negotiate” the finding out of existence without evidence that it was factually wrong (that is correction of the audit record, a different process). Confidentiality and professional conduct still apply—supplier negotiations may be commercially sensitive.
Exam Anchors
- Evaluate plan adequacy + schedule, not signatures alone.
- Negotiate for risk-proportional strength and timing.
- Demand linkage finding → cause → action → effectiveness plan.
- Use conditional acceptance and documented rejection when needed.
- Know when to escalate rather than endlessly re-negotiate a non-viable plan.
A high-risk major nonconformity has ongoing product exposure. The auditee’s CAPA plan proposes only a procedure rewrite due in nine months and no interim controls. What is the most appropriate II.D.2 response?
Which CAPA plan element most directly helps the auditor evaluate whether proposed actions address the real issue?
During negotiation, the plant manager asks the auditor to delete a major finding in exchange for an aggressive CAPA on a minor finding. What should the auditor do?
A CAPA plan for a systemic ERP control gap is owned only by a temporary intern with no IT authority, due in two weeks, with no milestone for system change approval. How should schedule and responsibility be evaluated?