Core workflows

Run corrective actions (CAPA) that actually close

Turn findings into owned, dated actions with root-cause analysis, evidence of closure and a management-review-ready report.

6 min read · updated July 2026

Step-by-step

  1. 1

    Open Corrective Actions

    Everything raised across audits, incidents and management reviews.

    Open Corrective Actions
  2. 2

    Raise a new action

    Click New action. Link the source (audit finding, incident, buyer feedback), set owner, due date and root cause.

  3. 3

    Track root cause honestly

    Use the 5-Whys prompt to record the underlying cause, not the surface symptom. Auditors read this closely.

  4. 4

    Close with evidence

    Closure requires an evidence link — a screenshot, ticket, report or policy update. No evidence, no closure.

What corporate buyers look for
  • "How many open non-conformities do you have and what is their age?"
  • "Have any been open for more than 90 days?"
  • "How do you evidence closure?"

What this workflow produces: The CAPA export with age, root cause and evidence of closure is what mature buyers ask for in stage-two due diligence.

FAQ

What is a good CAPA closure time?

Aim for 30 days for minor and 90 days for major, or per your management policy. What matters most to buyers is that you have a defensible cadence.

Ready to run this in your workspace?

Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.

Related

ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation