
ISO 9001 Corrective Action Procedure: A Step-by-Step Guide for 2026
A corrective action process is how a quality management system learns from its mistakes. Done well, the same problem does not come back. Done badly, it produces a stack of closed forms and recurring defects. This guide sets out a practical ISO 9001 corrective action procedure based on clause 10.2 of ISO 9001:2026, published in September 2026, that satisfies auditors and actually prevents recurrence.
Correction vs corrective action
ISO 9001:2026 defines corrective action in clause 3 as action to eliminate the cause of a nonconformity and to prevent it recurring. That is different from a correction, which deals with the immediate problem.
- Nonconformity: 40 housings machined 0.3 mm out of tolerance.
- Correction: quarantine the batch, rework or scrap, inform the customer if anything shipped.
- Corrective action: find out why (a worn fixture with no maintenance interval) and fix the cause (add the fixture to the preventive maintenance plan, add a first-off check).
Not every nonconformity needs a full corrective action. Annex A of the 2026 edition notes that you decide the extent of investigation based on the risk of recurrence, the actual or potential impact and customer requirements. Corrective actions must be appropriate to the effects of the nonconformity.
Where nonconformities come from
- Internal and external audits (9.2)
- Customer complaints and returns, which the standard notes can be a source of nonconformities
- Nonconforming outputs found in production or service delivery (8.7), including after delivery
- Supplier failures (8.4)
- Monitoring, measurement and analysis results (9.1.3) and management review (9.3)
Capture all of them in one place. A CAPA management software log stops issues being lost in email and makes trends visible.
The ISO 9001 corrective action procedure, step by step
Step 1: Record the nonconformity clearly
Write an objective problem statement: what happened, where, when, how many units or cases, and which requirement was not met (customer specification, procedure or ISO 9001 clause). Vague statements such as "quality issue on line 2" lead to vague investigations.
Step 2: React, control and correct
Clause 10.2.1 a) requires you to react to the nonconformity and, as applicable, take action to control and correct it and deal with the consequences. For nonconforming products or services, 8.7 lists the options: correction; segregation, containment, return or suspension of provision; informing the customer; and acceptance under concession. When you correct an output, verify it conforms afterwards.
Step 3: Decide whether corrective action is needed
Evaluate the need to eliminate the cause so the problem does not recur or occur elsewhere. A one-off transcription error caught at review may need only a correction. A safety-related defect, a repeat complaint or a systemic audit finding needs the full process. Record the decision and the reason either way.
Step 4: Find the root cause
Review the nonconformity and determine its causes using a structured method:
- 5 Whys for straightforward problems.
- Fishbone (Ishikawa) diagrams across people, methods, machines, materials, measurement and environment.
- Fault tree analysis for complex failures with several contributing events.
Treat "human error" as a starting point rather than a root cause. Ask why the error was possible: unclear instructions, poor layout, fatigue or missing error-proofing. Clause 8.5.1 g) already requires actions to prevent human error.
Step 5: Check for similar nonconformities
Clause 10.2.1 b) 3) asks whether similar nonconformities exist or could occur. If fixture wear caused the problem on one machine, check every machine with the same fixture design. This step is often skipped and auditors look for it.
Step 6: Plan and implement the action
Define what will be done, who owns it, by when and with what resources. If the action changes the QMS itself (a new process, a reorganised responsibility, a different supplier strategy), treat it as a planned change under 6.3 and consider how it will be communicated and how its effectiveness and results will be reviewed. Update affected procedures through document control and tell the people affected.
Step 7: Review effectiveness
Clause 10.2.1 d) requires you to review the effectiveness of the corrective action taken. Set the success criterion when you plan the action, for example "no recurrence in the next 1,000 units" or "zero repeat complaints for three months", then check it. Completing the task is not the same as proving it worked. If it did not work, go back to the root cause.
Step 8: Update risks, opportunities and the QMS
This is the step 2015-era procedures most often miss. Clause 10.2.1 e) requires you to update the risks and opportunities determined during planning, if necessary, and 10.2.1 f) to make changes to the QMS if necessary. In ISO 9001:2026 risks (6.1.2) and opportunities (6.1.3) are handled separately, so a significant nonconformity should prompt a look at your risk register and, sometimes, an opportunity you had not seen.
Step 9: Keep the evidence
Clause 10.2.2 requires documented information on the nature of the nonconformity, the actions taken and the results of any corrective action. Lock completed records so they cannot be altered.
What auditors look for
- Root causes that go beyond "operator error" or "retrained staff".
- Evidence that similar nonconformities were checked for elsewhere.
- An effectiveness criterion defined up front and evidence it was met.
- Links to updated risks, procedures and, where relevant, planned QMS changes.
- Timely action. Clause 9.2.2 d) asks for correction and corrective action from audits without undue delay.
Feeding trends into management review, as clause 9.3.2 requires, turns individual fixes into continual improvement under clause 10.1.
Running the procedure in software
Spreadsheets and email make it easy to miss deadlines and lose evidence. An ISO 9001 software platform such as SmartISO keeps the nonconformity, investigation, actions, effectiveness check and document changes in one record, with reminders and a full history. Findings raised in ISO audit software flow straight into the same workflow.
Frequently asked questions
Does ISO 9001:2026 require preventive action?
There is no separate preventive action clause. Prevention is handled through risk-based thinking: you determine, analyse and evaluate risks and plan proportionate actions under 6.1.2. The clause 3 definition notes that corrective action prevents recurrence while preventive action prevents occurrence.
Who should own a corrective action?
Usually the owner of the process where the nonconformity occurred, with the quality team overseeing the system. Ownership should sit with someone who has authority to change the process.
How long should a corrective action take?
ISO 9001 sets no deadline. Set timelines by risk: containment immediately, investigation within days or weeks, and an effectiveness review once enough time or volume has passed to prove the fix.
What changed in clause 10.2 in the 2026 edition?
The steps are largely the same. The bigger change is around it: risks and opportunities are now separate (6.1.2 and 6.1.3), so updating them after a nonconformity means reviewing both, and continual improvement is consolidated into clause 10.1.