ISO 9001 corrective action: a 7-step process (with an example)

The same complaint from the same customer, for the third time this year. Each time, a nonconformity was raised, the product was quarantined, someone had a word with the operator and the form was closed. And each time, it came back. If that sounds familiar, the problem isn’t that your team isn’t working. It’s that they’re fixing the symptom and nobody is going after the cause.

That’s what corrective action is for. In ISO 9001 it sits in clause 10.2, and it’s one of the requirements auditors look at most closely, because it shows whether your system learns or just fights fires. In this guide you’ll see exactly what the standard requires, a 7-step corrective action process, a real example of a corrective action record, and the mistakes that turn corrective action into paperwork.

The short answer: a corrective action is what you do to eliminate the cause of a nonconformity so it doesn’t happen again. The process has seven steps: contain and correct, decide whether corrective action is needed, find the root cause, look for similar cases, carry out the plan, verify effectiveness, and close by updating the system. There’s a full example further down. If you want an editable version, the free guide includes the form and the step-by-step method.

Free resource by QualityWeb 360

What ISO 9001 requires for corrective action (clause 10.2)

The requirement is in ISO 9001 clause 10 (Improvement). Section 10.2.1 says that when a nonconformity occurs, including one arising from a complaint, the organization shall:

  • a) React: take action to control and correct it, and deal with the consequences.
  • b) Evaluate the need to eliminate the cause, so it doesn’t recur or occur elsewhere: review and analyze the nonconformity, determine its causes, and determine whether similar nonconformities exist or could potentially occur.
  • c) Implement any action needed.
  • d) Review the effectiveness of the action taken.
  • e) Update risks and opportunities determined during planning, if necessary.
  • f) Make changes to the quality management system, if necessary.

Section 10.2.2 adds that you must retain documented information as evidence of the nature of the nonconformity, the actions taken and their results, including effectiveness. In plain terms: the auditor will ask for the record, and the record has to tell the whole story.

One important nuance: corrective actions must be appropriate to the effects of the nonconformity. A misprinted label doesn’t call for the same effort as a batch rejected by a customer.

Correction, corrective action, preventive action and improvement

These four terms get used interchangeably, and they aren’t the same. Keeping them straight saves findings:

  • Correction: fixes the specific case. You quarantine, rework, notify the customer. It puts out today’s fire.
  • Corrective action: removes the cause so it doesn’t recur. It changes the process, not just the output.
  • Preventive action: ISO 9001:2015 no longer has a section by that name. The idea didn’t disappear; it was absorbed into the risk-based thinking of clause 6.1. If your procedure still has a “preventive action” form, that’s not wrong, but it’s worth linking it to your risk register.
  • Improvement action: starts from an opportunity rather than a problem. That’s clauses 10.1 and 10.3.

Before all of this comes the nonconformity itself: what it is, how to grade it as major, minor or an observation, and how to document it. We cover that in our guide to ISO 9001 nonconformities: types and how to manage them. This guide starts at the next moment: the nonconformity is logged, so now what?

The corrective action process in 7 steps

1. Contain and correct

First, stop the problem from doing more damage: quarantine suspect product, halt the process if needed, tell the customer if it already reached them. Write down what you did and when. This is part a) of the standard and almost every company does it well, because it’s urgent. The mistake is stopping here.

2. Decide whether corrective action is needed

Not every nonconformity needs a full corrective action. An isolated, low-impact error with no reasonable chance of recurring can be closed with a correction. What you do need is a written rule for the decision: for example, always open a corrective action when the nonconformity is major, comes from a customer, is recurring or affects a legal requirement. That way the decision doesn’t depend on who’s deciding that day.

3. Find the root cause

This is where everything is won or lost. “Operator error” or “lack of training” on their own aren’t root causes; they’re usually symptoms. Two methods handle most cases:

  • The 5 Whys: keep asking why until you reach something you can change in the process. It works well when there’s a single causal chain.
  • Fishbone (Ishikawa) diagram: review possible causes by category (method, machine, material, people, measurement, environment). Useful when several causes may be at play.

Do the analysis with the people who know the process, not just from the quality office. And test the cause with data before acting: if the cause is real, removing it should make the problem go away.

4. Look for similar cases

The standard requires it and hardly anyone does it: ask whether the same cause could be producing the problem on another line, another shift, another product or another supplier. If the die on line 2 wore out without anyone noticing, what about the ones on lines 1 and 3? This step turns a local fix into a system improvement.

5. Define and carry out the plan

Every action needs three things: what will be done, who owns it and by when. An action without a date isn’t an action, it’s an intention. Favor actions that change the process (a check, a fixture, a new method) over actions that rely on people remembering (a notice, a toolbox talk).

6. Verify effectiveness

This is the step most often skipped and the one auditors check most. Verifying effectiveness isn’t confirming the action was done. It’s confirming that the problem didn’t come back. Set the criterion and the time frame when you open the action, not when you close it. For example: “zero rejects from this cause in the next three batches” or “no complaints on this issue for 60 days”. If the problem reappears within that window, that wasn’t the cause, and you go back to step 3.

7. Close and update the system

Once effectiveness is confirmed, close the action and check what else needs to change: the procedure or work instruction, the control plan, the risk register, training. That’s parts e) and f) of the standard. Record everything with dates, because it’s the evidence 10.2.2 requires.

Corrective action example: a completed record

Here’s what a well-documented corrective action looks like. The case: a metal parts manufacturer receives a complaint because a batch arrived with burrs outside specification.

FieldWhat was recorded
Reference and sourceCA-2026-014 · Customer complaint, March 3
DescriptionBatch 2231 of brackets with burrs on the cut edge, outside drawing tolerance. 1,200 parts affected.
CorrectionWarehouse stock put on hold, 100% inspection of batches 2229 to 2233, replacement parts shipped to the customer within 48 hours.
Corrective action needed?Yes: customer complaint and second occurrence this year.
Root cause analysis (5 Whys)Burr → worn die edge → die exceeded its service life → no record of strokes per die → maintenance plan was calendar-based, not usage-based. Root cause: die maintenance not controlled by stroke count.
Similar casesAll 14 active dies reviewed: 3 more were beyond their recommended service life.
Action plan1) Stroke counters on all 4 presses (Maintenance, March 30). 2) Sharpening plan based on stroke count (Maintenance, April 15). 3) Edge check on the first part of every shift (Production, April 5).
Effectiveness criterionZero burr rejects in the next 10 batches and no complaints on this issue for 90 days.
VerificationJuly 12: 14 batches with no burr rejects, no complaints. Effective.
Closure and QMS changesDie maintenance instruction and cutting-process risk register updated. Closed July 12.

Notice three things: the root cause is something you can change in the process, not a person; effectiveness has a measurable criterion set from the start; and the closure leaves the system changed, not just the form filled in.

The mistakes auditors find most often

  • Root cause = “human error”. If the action is “retrain the operator”, the auditor will ask why the process allowed the error.
  • Actions with no date or owner. “Improve inspection” can’t be verified.
  • Closing without verifying effectiveness. The most common finding under clause 10.2. Done isn’t the same as effective.
  • Actions left open for months. A list with dozens of overdue actions says more about your system than any procedure.
  • The same nonconformity, again and again. If it recurs, the previous action wasn’t effective, and the auditor will spot it in the history.

Many corrective actions start in an internal audit. If you want findings to be well written from the outset, see how to conduct an ISO 9001 internal audit step by step.

How to follow up without chasing people

The process works on paper. What breaks is the follow-up: the action lives in a spreadsheet, the evidence in an email and the reminder in the quality manager’s head. Once you have twenty open actions, the time goes into chasing owners instead of analyzing causes.

If that’s your bottleneck, there are two ways forward. One is to tidy up the workflow: we explain how to reduce nonconformity response time with digital workflows. The other is to bring the whole cycle into one place: QualityWeb 360’s corrective action module links the nonconformity to its cause, its actions, owners with due dates and the effectiveness check, and sends reminders when something falls due. When the auditor asks for a closed action, the whole story is on one screen.

Frequently asked questions about ISO 9001 corrective action

What is the difference between correction and corrective action?

A correction fixes the specific case: quarantining, reworking or replacing product. A corrective action removes the cause so the problem doesn’t recur. Every nonconformity needs a correction; not every one needs a corrective action.

Does every nonconformity require a corrective action?

No. ISO 9001 asks you to evaluate the need based on the effects of the nonconformity. The best practice is a written rule, for example opening a corrective action for every major, customer, recurring or legally relevant nonconformity.

Which methods work for root cause analysis?

The most common are the 5 Whys, for problems with a single causal chain, and the fishbone (Ishikawa) diagram, when there are several possible causes. For complex problems or automotive customers, the 8D methodology is also widely used.

How do you verify the effectiveness of a corrective action?

By showing with data that the problem didn’t recur within a defined period. The criterion is set when the action is opened, for example zero rejects from that cause in the next ten batches. Confirming the action was carried out is not the same as verifying effectiveness.

Does preventive action still exist in ISO 9001?

Not as a separate clause. Since the 2015 version, preventive action has been replaced by the risk-based approach of clause 6.1. You can keep using the term in your system as long as you link it to risk management.

What happens if corrective actions aren’t closed?

Open or overdue actions lead to audit findings and, if there are many or they relate to major nonconformities, can put certification at risk. And a problem whose cause wasn’t removed will come back.

Corrective action is the core of ISO 9001 clause 10: the part of the system that proves your company learns from its mistakes instead of repeating them.