16.1 Seven Basic Tools, Root Cause & PDCA

Key Takeaways

  • BoK V.A (Analyze) requires identifying, interpreting, and analyzing the seven basic tools, root-cause methods (especially 5 Whys), and PDCA in audit and CAPA contexts.
  • Match tool to purpose: Pareto (vital few), fishbone (structured causes), flowchart (process path), control chart (stability over time), check sheet (data collection), scatter (association), histogram (distribution shape).
  • Control limits come from process variation; specification limits are customer/engineering requirements—do not treat them as interchangeable on SPC charts.
  • 5 Whys must reach controllable system causes; stopping at “operator error” without testing deeper enablers is a classic shallow CAPA pattern auditors challenge.
  • PDCA (Plan–Do–Check–Act) closes improvement loops; missing Check/Act leaves changes unmeasured and unstandardized—common exam and field failure mode.
Last updated: August 2026

16.1 Seven Basic Tools, Root Cause & PDCA (CQA BoK V.A — Analyze)

/practice/cqaPractice questions with detailed explanations

Quality auditors live in the gap between claimed process control and demonstrated process control. When auditees wave charts, fishbones, or “we did a 5-Why,” your job is to analyze whether the tool fits the data, whether conclusions follow from evidence, and whether actions address causes—not symptoms. BoK V.A sits at Analyze level: read the graphic or narrative, interpret patterns, and judge fitness for purpose.

Why basic tools matter on a CQA exam

The seven basic tools (often attributed to Kaoru Ishikawa) remain the language of shop-floor problem solving. Auditors encounter them in:

  • Process and product audits (defect Pareto, check sheets at the line)
  • System audits (CAPA packages, management-review charts)
  • Supplier audits (process capability evidence, control charts)
  • Verification of effectiveness (did the metric improve after CAPA?)

Exam stems often present a chart description or tool choice scenario. Answer by matching question type (frequency, root cause brainstorming, distribution shape, correlation, process flow, control vs. specification) to the right tool—then ask whether the auditee used it correctly.

The Seven Basic Quality Tools

ToolPrimary purposeTypical audit use
Pareto chartSeparate the vital few from the useful many (often 80/20)Prioritize defect types, complaint codes, audit finding categories
Cause-and-effect (fishbone / Ishikawa)Structure possible causes by categoryCAPA brainstorming; evaluate completeness of cause hypotheses
Flowchart / process mapShow process steps, decisions, handoffsScope audits; find missing controls, rework loops, unclear ownership
Control chart (SPC)Distinguish common vs. special-cause variation over timeProcess stability claims; “in control” vs. “meets spec” confusion
Check sheetStructured data collection at the point of workSampling evidence; verify data integrity of later charts
Scatter diagramExplore association between two continuous variablesClaims that “X drives Y”; measurement/process correlation stories
HistogramDisplay distribution shape, center, spreadCapability discussions; multi-modal processes; specification comparison

Know each tool well enough to name it from a description, pick it for a stated analytical goal, and spot classic misuse.

1. Pareto chart

A Pareto chart ranks categories by frequency (or cost/severity) and often shows a cumulative percentage line. The insight: few categories usually drive most problems.

Audit analysis cues:

  • Are categories mutually exclusive and consistently coded?
  • Is the measure frequency, cost, risk, or something else—and was ranking done on the right measure?
  • Did the team attack the top bars, or a politically convenient small bar?
  • After CAPA, did the top categories shrink (effectiveness), or did the problem merely reclassify?

Scenario — Pareto for audit planning. An internal audit program tallies 120 nonconformities: documentation (48), training (22), calibration (18), supplier control (15), identification/traceability (10), other (7). A lead auditor using Pareto focuses deeper sampling on document control and training—not equal time on every clause. That is sound prioritization if documentation findings are truly high risk, not just easy to write.

Misuse: Ranking by “ease of fix” instead of impact; combining unrelated codes so one bar looks dominant; using Pareto on too few data points and treating noise as vital few.

2. Cause-and-effect (fishbone) diagram

The fishbone organizes potential causes under bones such as Man/People, Machine, Method, Material, Measurement, Environment (6M) or service variants (Policies, Procedures, People, Plant/Technology). It is a structured brainstorming tool, not proof of root cause.

Audit analysis cues:

  • Are bones populated with specific, evidence-linked hypotheses—or empty slogans?
  • Did investigation stop at the first popular bone (“People”)?
  • Were likely causes tested (data, observation, trial) before CAPA locked in?
  • Does the final root cause appear on the diagram and explain the problem statement?

Scenario. A packaging line ships wrong labels. Fishbone lists “operator error,” “printer jam,” “unclear WI,” “similar SKU artwork,” “no barcode verify,” and “rush orders.” A strong CAPA package shows verification that the scan gate was not forced and artwork IDs look alike—then implements error-proofing. A weak package circles “operator error” and stops.

3. Flowcharts and process maps

Flowcharts show sequence: operations, decisions, delays, inspections, transports. SIPOC and value-stream maps (often taught with Lean) extend the idea with suppliers, inputs, outputs, customers, and waste.

Audit analysis cues:

  • Does the map match as-is reality (walk the process), or only the as-documented ideal?
  • Where are control points, records, and decision authority?
  • Are there undocumented shadow processes, rework loops, or dual systems?
  • Does the audit trail follow the actual path of product/data?

Scenario. Procedure shows inspection then pack. Floor flow shows pack first “when rushed,” with inspection later from samples. The flowchart discrepancy is objective evidence of process nonconformity and control risk—even if final quality “usually” passes.

4. Control charts (SPC charts)

Control charts plot process data over time with a center line and control limits based on process variation (not customer specifications). They help detect special causes (points beyond limits, runs, trends, patterns) versus common-cause variation.

ConceptMeaning for auditors
In statistical controlProcess stable; predictable common-cause variation
Out of controlSpecial cause likely; investigate assignable cause
Within specificationOutput meets customer/engineering limits—not the same as “in control”
CapabilityAbility to meet specs given stability assumptions

Critical exam distinction: A process can be in control but incapable (stable around the wrong mean or with wide natural variation). It can also be capable on average yet unstable (occasional special causes create risk). Auditors challenge slogans like “our SPC proves quality” when charts are mis-scaled, limits are set to specs, or operators never react to signals.

Scenario. Operator shows an X-bar chart with limits equal to print-spec tolerance. Points never go “out.” Analysis: those are specification limits misused as control limits. True control limits may be tighter or wider; without correct limits, special causes hide and capability claims are unsupported.

5. Check sheets

Check sheets are simple forms for tallying events by type, location, shift, or defect location (concentration diagrams). They are the upstream integrity of later Pareto and histograms.

Audit analysis cues:

  • Who fills the sheet, when, and is training consistent?
  • Are categories clear? Is there a “miscellaneous” dump that hides patterns?
  • Is data collected at the source or reconstructed later from memory?
  • Do electronic “check sheets” allow forced completion without real observation?

Scenario. Defect check sheet shows zero “scratches” for a month after a customer complaint surge. Investigation finds scratches re-coded as “cosmetic other” after a supervisor discouraged bad news. Tool was correct; data culture invalidated analysis.

6. Scatter diagrams

Scatter plots show paired observations of two variables (e.g., temperature vs. viscosity, experience months vs. error rate). They suggest association, not automatically causation.

Audit analysis cues:

  • Sample size and range adequate?
  • Outliers explained or deleted without rationale?
  • Lurking variables (shift, machine, lot) mixed into one cloud?
  • Does the claimed relationship drive process settings or CAPA?

Scenario. Supplier claims humidity “causes” dimensional drift and shows a scatter with weak visual slope and n = 8. Auditor requests more data stratified by tool wear—the stronger driver. Correlation claims need strength, stratification, and process knowledge.

7. Histograms

Histograms group continuous data into bins to reveal shape: normal-ish, skewed, bimodal, truncated at a limit (inspection screening).

Audit analysis cues:

  • Bin width appropriate (too few bins hide structure; too many create noise)?
  • Spec limits overlaid for visual capability?
  • Bimodality hinting at two machines, two shifts, or two populations mixed?
  • Truncation at LSL/USL suggesting 100% sort rather than process control?

Scenario. Histogram of fill weight is bimodal. Root investigation finds two fillers combined in one dataset. “Process average is fine” was misleading; one filler is low and one high. Tool analysis drives a better sampling and maintenance plan.

Root cause analysis and the 5 Whys

Root cause analysis (RCA) seeks the systemic reason a problem exists so solutions prevent recurrence. Methods include 5 Whys, fishbone, fault tree, barrier analysis, and failure mode analysis. For V.A, master 5 Whys depth and pitfalls.

5 Whys method (linear drilling):

  1. State the problem precisely (what, where, when, extent).
  2. Ask why that problem occurred; answer with a factual cause.
  3. Ask why that cause exists; continue until a controllable systemic cause emerges.
  4. Verify: if this cause is fixed, would the problem be unlikely to recur?
  5. Document evidence for each link—not opinions alone.

Depth rules auditors use:

Weak 5-Why stopStronger continuation
“Operator error”Why did the system allow/ encourage that error?
“Training not effective”Why was competence not verified? Why is the job error-prone?
“Procedure not followed”Why is the procedure unusable, unavailable, or conflicting with incentives?
“Machine failed”Why did preventive maintenance / detection fail?

Scenario — 5 Whys in CAPA evaluation. Problem: three lots released without required torque data.

  1. Why? Release checklist marked complete without torque sheet attached.
  2. Why? ERP release step does not require torque record upload.
  3. Why? System configured for legacy product family without torque.
  4. Why? Change control for new product family did not include MES/ERP gate update.
  5. Why? Change-control checklist lacks IT systems impact review.

Root-oriented actions address change control + system gate, not only “retrain releasers.” An auditor analyzing this chain judges whether CAPA matches the deepest actionable causes supported by evidence.

Limits of 5 Whys: Single linear path can miss multi-factor failures; biased facilitators steer to preferred answers; stopping too early or too abstract (“culture”) without actionable control. Pair with fishbone when many factors interact; require data checks between whys.

PDCA (Plan–Do–Check–Act)

PDCA (Deming/Shewhart cycle) is the fundamental improvement loop:

PhaseFocusAudit evidence you may sample
PlanDefine problem, goals, method, measures, ownersProject charter, baseline data, risk assessment, resource plan
DoPilot or implement change on small scaleTrial records, training for pilot, controlled deployment
CheckCompare results to plan; study dataMetrics before/after, audit of trial, customer feedback
ActStandardize success or adjust and re-loop; institutionalize learningUpdated procedures, training rollout, control plan, management review

Related cycles: SDCA (Standardize–Do–Check–Act) stabilizes a process before improvement; DMAIC (next section) is a project-structured variant for deeper problems. Auditors should recognize PDCA in continuous-improvement stories, CAPA effectiveness checks, and management-system “continual improvement” claims (e.g., ISO 9001 spirit).

Scenario — PDCA without Check/Act. A plant “implements” a new inspection checklist (Plan/Do) but never compares escape rates or revises the controlled document after local tweaks. Auditors find tribal versions at stations. Finding: improvement not closed through Check (measure effect) and Act (standardize and control).

How auditors use these tools end-to-end

  1. Planning: Pareto of past NCs, risk, and customer issues to focus checklist depth.
  2. Performance: Flowchart vs. floor; check sheets for sampling tallies; interview with data.
  3. Analysis of findings: Group issues; assess significance.
  4. CAPA evaluation: Fishbone/5 Whys quality; PDCA completeness.
  5. Effectiveness: Control charts/histograms/Pareto before–after.

Exam traps for V.A

  • Choosing a scatter when the need is frequency ranking (Pareto), or Pareto when the need is time-order signals (control chart).
  • Treating control limits as spec limits.
  • Accepting fishbone or 5-Why theater without tested causes.
  • Confusing correction of a defect with systemic root-cause elimination.
  • Believing any chart equals “statistical process control.”

Key analysis checklist (portable)

When you see a quality tool on the exam or in the field, ask: What question was this tool meant to answer? Is the data trustworthy? Does the conclusion follow? Is the next action aligned with the conclusion? That four-question habit is Analyze-level mastery for BoK V.A.

Test Your Knowledge

An auditor reviews a packaging defect summary. Management wants to focus improvement on the few defect types that generate most scrap cost. Which basic quality tool best supports that prioritization?

A
B
C
D
Test Your Knowledge

A process owner displays an X-bar chart with upper and lower limits set exactly equal to the engineering specification limits and claims the process is “in statistical control” because no points fall outside those lines. What is the strongest analytical concern?

A
B
C
D
Test Your Knowledge

A CAPA for mislabeled product lists root cause as “operator error” after a single Why and only retrains staff. Using 5 Whys analysis expectations, how should an auditor evaluate this?

A
B
C
D
Test Your Knowledge

A site implements a new work instruction (Plan and Do) but never compares defect rates to baseline and never updates the controlled document after local edits. Which PDCA weakness is most evident?

A
B
C
D