If you've sat through a quality meeting where "RCA" and "CAPA" got used interchangeably, you've watched a corrective action fail before it was written. The two are not the same thing, and the difference between root cause analysis and corrective action isn't academic — it's the difference between a problem that stays fixed and one that comes back with an auditor attached.
Here's the plain-language version I give every new supervisor and maintenance tech, the way it actually plays out on a forging floor.
The definitions, without the standards-speak
RCA — root cause analysis — is an investigation. Something went wrong: a cracked forging, a machine fire, a customer return. RCA is the disciplined process of working backward from the symptom to the underlying condition that made the failure possible. The output of an RCA is knowledge: a cause you can point at, supported by evidence. Tools like 5 Why, fishbone diagrams, and fault trees are all just different vehicles for the same trip.
CAPA — corrective and preventive action — is a commitment. It's the documented plan that takes what the RCA found and does something about it: a specific action, an owner, a due date, and a check afterward to confirm it worked. The output of a CAPA is change: a modified process, an added control, an updated standard.
The shortest version I know: RCA finds the cause. CAPA fixes it and keeps it fixed. One is diagnosis, the other is treatment. You wouldn't accept a doctor who only diagnosed, and you shouldn't accept one who prescribed without diagnosing. Yet plants do both constantly — RCAs that end in a binder, and CAPAs written ten minutes after the defect with no investigation behind them.
Corrective vs preventive: the two halves of CAPA
CAPA bundles two related but distinct ideas, and auditors will probe whether you know the difference:
- Corrective action deals with a nonconformance that already happened. The die failed, the parts shipped, the customer called. Corrective action removes the cause so this specific failure doesn't recur.
- Preventive action deals with a failure that hasn't happened yet. You found the cause on press #2 — preventive action asks whether presses #1 and #3 have the same latent condition, and fixes them before they fail too.
There's also a third thing that gets confused with both: correction (or containment). Quarantining the suspect lot, sorting good parts from bad, rushing replacements to the customer — that's damage control, not corrective action. It addresses the parts, not the process. Necessary, immediate, and completely insufficient on its own. Plenty of "corrective actions" I've reviewed were really just corrections wearing a nicer title.
Why auditors ask for both
Every serious quality standard — ISO 9001, IATF 16949, AS9100 — requires that when a nonconformity occurs, you evaluate the need to eliminate its cause, not just its symptoms. That's why an auditor reviewing your CAPA file is really asking two questions:
- "Show me how you determined the cause." That's the RCA. If your CAPA record has a corrective action but no analysis behind it, the auditor reads that as guessing. A CAPA without an RCA is an answer without the math shown.
- "Show me that the action addresses that cause — and that you verified it worked." That's the CAPA proper. An RCA without a CAPA is a diagnosis nobody treated, and a finding that recurs after a "closed" CAPA is one of the fastest ways to turn a minor audit finding into a major one.
The two documents have to agree with each other. If the RCA says the cause was a missing PM on the heat exchanger, and the corrective action says "retrained operators," the auditor doesn't need to be a forging expert to see the disconnect — the fix doesn't touch the cause. That mismatch is the single most common thread I've seen pulled in audits.
A worked flow: from defect to closed CAPA
Here's the whole cycle in one pass, the shape it takes when it's working:
2. contain — Suspect heat lot quarantined; last known-good part identified; customer shipments checked. (Correction, not corrective action.)
3. rca — 5 Why at the press, same shift: cracks trace to billets forged below temperature after an unlogged press stoppage; pump overheated because a heat exchanger dropped off the PM schedule after a coolant-system modification.
4. corrective action — Heat exchanger added to PM schedule; low-temp interlock added at the press. Owner: maintenance lead. Due: 30 days.
5. preventive action — Management-of-change checklist updated so equipment modifications trigger a PM-schedule review; other presses audited for the same gap.
6. verify — After 90 days: PM completion records checked, interlock tested, trim scrap reviewed. No recurrence.
7. close — CAPA closed with evidence attached: RCA record, work orders, interlock test, scrap data.
Notice where the RCA sits: one step, in the middle, feeding everything after it. Steps 4 through 7 are only as good as step 3. Skip or shortcut the RCA and every downstream step inherits the guess.
Who owns which piece
One reason the two get blurred is that they naturally belong to different people, and nobody says so out loud. The RCA belongs to whoever is closest to the failing process — the cell lead, the maintenance tech, the operator who was standing there. They're the ones who can walk the chain of causes and check each link against reality. The CAPA belongs to the quality system: someone has to log it, assign the owner, chase the due date, schedule the effectiveness check, and keep the record an auditor can follow.
Trouble starts when either side tries to do the other's job. A quality engineer writing an RCA from a desk produces a plausible story that the floor quietly knows is wrong. A cell lead left to run the CAPA paperwork lets the verification date slide because there's a press down. Let the floor find the cause, let the system manage the fix, and make the handoff between them explicit — a named owner and a real due date, not "we talked about it at the morning meeting."
The classic failure: a CAPA that restates the symptom
The most common broken CAPA in existence looks like this:
Problem: Parts cracked at trim. Root cause: Parts were cracked. Corrective action: Instructed operators to watch for cracks. Status: Closed.
Every line is a restatement of the symptom. The "root cause" is the defect wearing a different sentence. The "action" is inspection, which catches the failure without preventing it. Nothing in the record explains why the cracks happened, so nothing in the record can stop them from happening again. This CAPA will be reopened — by the next occurrence or by the next auditor, whichever arrives first.
The tell is simple: if you can delete the RCA section and the corrective action still makes sense, the corrective action isn't connected to a cause. "Watch for cracks" works with any root cause because it's tied to none of them. A real corrective action only makes sense in light of the specific cause it removes — which is exactly what makes it verifiable, and exactly what an auditor is trained to check.
If your CAPAs keep looking like the one above, the fix usually isn't a better form — it's a better investigation habit. Get the RCA done at the machine, while the evidence is fresh, and the CAPA almost writes itself.
One more thing. Root Cause AI walks your team through the root cause analysis conversationally and hands the result off as a structured, audit-ready record — so the cause your CAPA cites is one you actually found, with the evidence attached.