SQF Corrective Action (CAPA) Requirements — A Plain-English Guide
Not affiliated with SQFI. Educational summary — always work from the current SQF Code edition and your certification body's guidance.
If you're SQF-certified (or working toward it), corrective and preventive actions are one of the areas auditors scrutinize most. Here's what the standard expects, in plain language for a small or mid-size food manufacturer.
Where it lives in the SQF Code
Corrective and preventive action sits under clause 2.5.3 (Manufacturing). In essence it requires you to have a documented, implemented method describing how corrections and corrective actions are determined, implemented, and verified — including identification of root cause — and to keep records of all investigation and resolution of non-conformities.
What you must do
- Trigger a CAPA from any non-conformance. Recent editions expect CAPA to address issues from many sources: critical-limit deviations, customer complaints, audit findings, non-conforming product, verification failures, product withdrawals/recalls, regulatory infractions, and negative system trends.
- Separate "correction" from "corrective action."
- Correction = the immediate action to fix the detected problem (e.g., put product on hold).
- Corrective action = action that eliminates the cause so it doesn't happen again.
- Document a root cause analysis — expected as corrective-action evidence for every minor and major non-conformance. (A 5 Whys or fishbone analysis is the common approach.)
- Assign responsibility and timescales — a designated person/team, with due dates.
- Verify effectiveness — record that the corrective action was implemented and actually worked, before you consider it closed.
- Keep the records — investigations, corrections, corrective actions, and verification. SQFI generally recommends having at least ~90 days of records available before a site audit (keep more for safety).
What auditors look for
- A CAPA for each prior non-conformity, with a documented root cause — not just "retrained the operator."
- Evidence of verification of effectiveness, not a CAPA closed the day it opened.
- Records that are complete and retrievable quickly during the audit.
- Demonstration that previous-audit findings were effectively closed and haven't recurred.
Common pitfalls (that become non-conformances)
- Closing CAPAs without a real root cause or without verifying the fix.
- Treating "operator error" as the root cause instead of asking why the error was possible.
- Records scattered across spreadsheets and email — slow to retrieve when the auditor asks.
- No owner or due date, so actions quietly slip past the closeout clock.
Get audit-ready
Start with our free SQF audit-prep checklist, CAPA log template, and 5 Whys / RCA worksheet.
When the spreadsheet gets risky at audit time, Qualitronyx enforces the SQF closed loop automatically — required root cause, verification before closure, owner/due-date reminders, and a one-click auditor-ready export.
Related: FSMA 21 CFR 117 corrective actions · Best CAPA software for small food manufacturers