What Is a CAR? A Practical Guide to Corrective Action Requests and Nonconformities

Quick Summary

A Corrective Action Request (CAR) is basically a structured way to deal with a problem that keeps coming back. Instead of just fixing it and moving on, a CAR helps you figure out why it happened and put the right measures in place so it doesn’t happen again – following ISO 9001 Clause 10.2.

Organizations must understand that CARs (Corrective Action Requests) and NCs (nonconformities) matter more than they often think. In any organization -whether manufacturing, service, healthcare, consulting, or any other discipline – things go wrong. A customer complaint, a missed requirement, a failed audit finding. The instinctive response is often to fix the issue quickly and move on. But quick fixes don’t prevent recurrence. That’s where a Corrective Action Request (CAR) comes in. A CAR is not just about fixing a problem; it’s about understanding why it happened and ensuring it doesn’t happen again. This guide breaks down CARs in a practical, usable way so you can apply them effectively – not just document them.

What Is a Corrective Action Request (CAR)?

A CAR is a formal request to investigate a problem (nonconformity), identify its root cause, and implement actions to prevent recurrence. Once those actions are in place, verifying that the solution actually works is equally essential. At its core, a CAR answers three critical questions:

  • What went wrong?
  • Why did it go wrong?
  • What will prevent it from happening again?

A CAR is triggered when an issue is systemic, recurring, or significant enough that it cannot be ignored.

When Should You Raise a CAR? Understanding ISO 9001 Clause 10.2

Not every problem needs a CAR. Overusing CARs creates bureaucracy; underusing them allows problems to repeat. According to ISO 9001 Clause 10.2, which governs nonconformity and corrective action, a CAR is appropriate when:

  • There is a customer complaint
  • An audit finding identifies a gap
  • A process fails to meet stated requirements
  • A problem is recurring
  • The risk or impact is high

A simple rule of thumb: if fixing the issue alone doesn’t give you confidence it won’t happen again, you need a CAR. ISO 9001 Clause 10.2.1(b) also makes clear that not all nonconformities require a full root cause analysis (RCA). Sometimes the NC is a straightforward failure to implement — not requiring an RCA. Knowing this distinction is important.

CAR vs. Correction: What Is the Difference?

This is where many organizations go wrong.
“Correction” means fixing the immediate problem – for example, replacing a defective part.
A Corrective Action Request (CAR) means eliminating the root cause – for example, fixing the process that allowed defective parts to be produced in the first place.
A CAR always goes beyond the symptom. It targets the system, not just the outcome.

The CAR Process: Step-by-Step


Step 1: Identify and Define the Problem
Start with a clear, factual description:

  • What happened?
  • Where and when did it occur?
  • What requirement was not met?

Those involved often carry biases. Experience – while valuable – can make individuals predisposed to certain conclusions. Avoid opinions. Stick to evidence.

Weak statement: “Process failed due to negligence.”
Strong statement: “On the shop floor, the inspection step was skipped in 3 out of 10 sampled cases on March 12.”

Clarity at this stage determines the quality of everything that follows.

Step 2: Containment – Immediate Action to Stabilize the Situation
Before diving into root cause analysis, stabilize the situation. In some cases, the existing condition could lead to accidents, product loss, injury, or environmental harm. Containment actions include the following:

  • Quarantining defective products
  • Informing affected stakeholders
  • Implementing temporary process checks
  • Stopping a production line to prevent further loss

Containment is not the final solution – it is damage control.

Step 3: Root Cause Analysis (RCA) – The Heart of the CAR Process
Root cause analysis is where most CAR efforts fail. The goal is to move beyond what happened to why and how it happened. Common RCA tools include:

  • 5 Whys – iteratively asking “why” to drill down to the systemic cause
  • Fishbone (Ishikawa) Diagram – mapping cause-and-effect relationships across categories
  • Process Mapping – visualizing where in a workflow the failure occurred

A key principle: if your root cause sounds like human error, you probably haven’t gone deep enough. Instead of “operator forgot,” ask:

  • Why was the process dependent on memory?
  • Why was there no fail-safe mechanism?

True root causes are usually process, system, or design weaknesses – not individual mistakes. Sometimes they are as simple as a lack of communication, lack of understanding, or failure to appreciate risk before proceeding.

Step 4: Develop a Corrective Action Plan (CAP)
The Corrective Action Plan defines what will eliminate the root cause. Effective corrective actions may include:

  • Changing the process design
  • Adding automated controls or validation
  • Improving training systems that build genuine competency (not just retraining individuals)
  • Modifying procedures or product design

Weak actions – like reminding staff to “be more careful” – rarely prevent recurrence.
Strong actions – like introducing a mandatory checklist with sign-off or automating a validation step – address the system. Ask yourself: Will this action still prevent recurrence even if workers are tired, busy, or new to the role?

Step 5: Implement the Corrective Action Plan
Execute the plan by assigning clear responsibility, setting deadlines, and allocating resources. This is where many CARs stall — not due to poor ideas, but weak follow-through.
After implementing the corrective action, also assess for:

  • Residual risks – gaps that the CA may not fully close
  • Consequential risks – new problems the CA may inadvertently create
  • Efficiency impacts – whether the CA makes workers less productive

Step 6: Verify Effectiveness – The Step Most Organizations Skip
A CAR is not complete until its effectiveness is proven. Ask:

  • Did the corrective action work?
  • Has the issue stopped recurring?
  • Is the process now stable?

Verification can be performed by process owners, but it is also common practice to include effectiveness verification as an objective during subsequent quality audits. Verification methods include:

  • Data review over time
  • Follow-up internal audits
  • Monitoring of process performance metrics

Common Pitfalls in the CAR Process – and How to Avoid Them

Jumping to Solutions
Proposing fixes before understanding the cause is one of the most common mistakes. Enforce root cause analysis before any action planning begins.
Blaming People Instead of Processes
Human error is rarely the true root cause. Always ask, “What in the system allowed the error to occur?” Even apparent human incompetence may trace back to failures in the HR process, training design, or workload management.
Weak Corrective Actions
Actions like “retrain staff” rarely prevent recurrence on their own. Focus on systemic changes that remove the conditions enabling the problem.
No Follow-Up or Verification
Closing CARs without verifying effectiveness defeats the entire purpose. Make effectiveness verification a mandatory step – not an optional one.

Why CARs Drive Continual Improvement

A nonconformity drives correction and corrective action. When the CAR process is practical (not bureaucratic), it becomes a catalyst for continual improvement under ISO 9001. To keep the process effective:

  • Keep forms simple and focused
  • Train people in root cause thinking, not just template-filling
  • Use CARs selectively for meaningful issues
  • Review trends across CARs to identify systemic patterns

Done right, CARs become a learning engine for the organization.

Conclusion: A CAR Is a Disciplined Way of Thinking

A CAR is more than a form. It is a disciplined way of thinking that shifts an organization from reacting to preventing. Risk must be appreciated at every stage. Rather than blaming individuals, organizations should build a culture of systemic understanding. Just fixing a problem does not improve the system-root cause analysis is essential.
The most important thing to remember: a CAR is successful not when the problem is fixed but when it cannot happen again.

__

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

What Happens if You Fail an ISO Audit? A Survivor’s Guide

Quick summary

You don’t really “fail” an ISO audit – you receive nonconformities (NCs), which are simply gaps between your documented process and actual practice. Organizations typically get 30 to 90 days to address them through root cause analysis and corrective action. Handled well, an ISO audit is one of the most practical tools for improving your management system.

In a perfect world, an audit is like a gap analysis to help a business get better. However, for most professionals, failing an audit feels like an exam grade on a report card that their boss (and their customers) will see. This concept of pass and fail in an audit is a wrong perception. The failure myth and the reality of non-conformities (NCs) need understanding. This anxiety that comes from the results of an audit implies a lack of understanding of the objectives of an audit as envisaged in clause 9.2 of ISO 9001 and other standards in the harmonized structure as well as any other management system based on the ISM Code or other industry standards. In the world of ISO (9001, 27001, 14001, etc.), the word “fail” is therefore a misnomer. You don’t usually fail an audit – you receive NCs. NCs drive correction and CA and, therefore, are one of the drivers of the continual improvement of the management system (MS).

Why the fear of ISO audit failure persists

The emotional hurdle of acknowledging why people worry has many reasons, including some places where organizations often tie audit reports to bonuses, professional reputation, or fear of losing a major contract. If the true purpose of an MS is to produce conforming products and services and ensure continual improvement of the MS, it is essential to create the environment of quality where NCs are welcomed.

“The only bad NC is the one you do not know about.” – Dr. IJ Arora, QMII

Understanding ISO audit nonconformities: major NC, minor NC, and OFI


Since we are going to prioritize NCs and work on them, let me start by briefly defining these terms.

Finding typeDefinitionImpact on certification
Major nonconformityTotal breakdown of a process against a requirement, or evidence that a requirement does not exist. Implies a risk under clause 6.1 of ISO 9001.Can delay certification
Minor nonconformity (NC)A lapse that doesn’t jeopardize the whole system (e.g., one person missed a training log). The system exists but failed in implementation.Requires corrective action within agreed window
Opportunity for Improvement (OFI)A suggestion from the auditor – not a failure, but a chance to remedy or improve the management system.No direct certification impact

The 48-hour rule: what to do immediately after an ISO audit

Most audits have an immediate aftermath – the 48-hour rule -0 in that the organization post-audit has an internal meeting (we recommend and teach it in lead auditor courses taught by QMII). We teach not to panic. The organization, the various process owners, and the quality managers are reminded that ISO standards give a remediation window. Usually, organizations have 30 to 90 days to address major NCs. Very often this window is decided by the organization itself for internal audits and by the CB (certifying body) for third-party audits.

How to communicate audit findings to leadership

During the closing meeting the auditor presents the findings. A survivor’s tip from QMII experience is that an organization has to be mature and never argue, but at the same time be sure to clarify. Ensure you understand exactly why the auditor flagged a process. Be a true professional to establish that the NC is based on a requirement and not on the whims and fancies of the auditor. NC, remember, is the nonfulfillment of a requirement. Quality managers and the entire organizational team must learn how to socialize the news with the leadership in a mature manner. Don’t start by stating the organization failed.

Example framing for leadership: “Auditors identified three key areas where our current documentation doesn’t match our practice, and we have a 60-day window to align them.”

Corrective action process under ISO 9001 clause 10.2

It is worth repeating here that an NC drives correction and corrective action (CA). Yes, it would have been ideal if managers and users of the system had discovered it. Now the shortcoming has been discovered at the audit. Therefore, the path to redemption is CA, which means root cause analysis (RCA) in the agreed time. If it is an NC that needs immediate redemption, the organization does corrections (immediate actions) and follows with CA under clause 10.2 of ISO 9001.

Root cause analysis: going beyond the quick fix

RCA is not simply fixing the mistake. ISO fundamentals require organizations to explain why it happened – that is RCA. That way the organization has the best shot at improving the MS and avoiding reoccurrence. For example, if a document wasn’t signed, the fix isn’t just signing it — it’s changing the system so it can’t be forgotten.

Building your corrective action plan: evidence and closure

The CA plan involves how to document your comeback. It involves evidence gathering. In a subsequent audit, the auditors will look to verifying that the NC has been closed. They will need evidence that the new process is working.

Key steps in the ISO corrective action and closure process

  • Conduct an internal debrief within 48 hours of the audit closing meeting
  • Classify each finding: major NC, minor NC, or OFI
  • Assign process owners and agree on a remediation timeline (30-90 days)
  • Perform root cause analysis (RCA) for each NC – do not stop at the symptom
  • Implement correction (immediate fix) and corrective action (systemic fix)
  • Gather objective evidence that the new process is operating effectively
  • Submit the CA response to the certifying body within the agreed window
  • Verify closure in the next internal or third-party audit cycle

Turning an ISO audit into a competitive advantage

There is often a clean house effect because of the audit. An audit finding often gives the quality manager the political capital to finally fix broken processes that leadership ignored previously. The audit also helps in building a quality culture. The organization moves from a compliance mindset of we must, to quality because it makes us better. Remember, the certificate on the wall is just paper unless the robust processes built to get that paper are where the real value is created.

What ISO auditors are really looking for

Don’t consider the auditors as the police. They are evaluators and they want organizations they are auditing to pass because it means the standard is being upheld globally. They come looking for conformity. They are bad auditors who come looking for NCs.

The transparency principle: why hiding issues makes things worse
Remember, “documentation is king” is a deceptive policy. “If it isn’t written down, it didn’t happen” is not correct. Transparency wins. If you try to hide a mistake and the auditor finds it, a minor NC quickly becomes a major one due to a lack of management integrity. In a mature organization, the intent of leadership should be to turn the audit into a competitive advantage.

Final thought: the ISO audit as a tool for management system growth

Consider the audit as a tool for growth. Use it to continually improve the MS, provide better and needed resources, and be able to appreciate the risks if resources are not available.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.

Clause vs. Capability: Why Mature Auditors Evaluate Organizational Capability, Not Just ISO Clauses

What really is the purpose of a management system (MS)? As its basic expectation, the organization would like to produce confirming products and services. Yes, it would like to see continual improvement and by the repeated use of the PDCA (plan, do, check, act) cycle reduce the waste, improve ROI (return on investment), have less product returns, less dissatisfied customers and growth in its product sale. Toward this end a management system is created. So that the wheel does not have to be reinvented the ISO standards provide the clauses to enable create that MS. Sounds all great, but the question is with time auditors settle down checking that requirements of clauses are met by seeking proof in terms of backup paperwork. The MS soon becomes audit driven and auditors who lack this maturity become slaves of the clauses. They lose the maturity to audit if the MS is actually meeting the objectives based on the policy. For example, let us say, as an auditor you are auditing a world-class manufacturing facility. You walk in, and everything is immaculate. The quality manual is a meticulously detailed work of art, referencing every relevant ISO standard. You randomly pull a procedure, and it’s perfectly aligned with the corresponding clause. You ask for competency records and a training record appears instantly. It seems perfect. But is this organization truly capable of achieving its objectives consistently and improving over time, is a question not asked.

For years, audits (especially for certification) have often been focused heavily on clause compliance. An auditor arrives with a checklist. “Does your procedure meet Clause 8.6?” Check. “Have you addressed 9.1.2?” Check. It’s a binary system, a binary “yes” or “no” for conformance. The auditors often don’t even make the effort to see if as per ISO 9001 clause 8.6 the release of the product was carried out correctly. How many product returns took place. While ensuring conformance to standards it is important, mature auditors are increasingly recognizing that this approach alone is insufficient. A perfect checklist can sometimes mask a struggling, fragile organization. This is where the distinction between auditing to a standard (clause-based) and auditing for performance (capability-based) becomes crucial. The forthcoming ISO 9001 revision expected in September 2026 is not changing the fundamental requirements but is now insisting on better functioning of the management system. The limits of clause-based auditing without proof of the system actually producing a confirming product and or service are now clear.

The standards are well thought of, and these ISO standards are valuable tools. They provide a structured framework of best practices. Auditing against them is necessary, particularly for demonstrating minimum adherence and achieving certification. However, a clause-based audit often provides a limited view:

  • By focusing only on documentation and not seeking proof of Implementation is a pitfall into which auditors fall. The organization might have a procedure (the “clause” says you need one), but is anyone actually using it? Is it effective? A compliant procedure that’s ignored yields zero real-world value.
  • Clause based auditing makes auditing easy for auditors. However, it does not systematically give continual improvement. It encourages a check-box mentality where organizations might view auditing solely as an exercise in getting through the checklist without focusing on why these processes exist and how they contribute to results.
  • This auditing to clauses gives a snapshot in time and misses out on resiliency. A compliance audit assesses the system “at the moment” of the audit. It doesn’t tell you if the organization can maintain that level of performance during periods of growth, stress, or market shifts.
  • The clause-based auditing can often inadvertently reinforce silos. Clause-by-clause auditing can strengthen a departmental focus rather than a process-oriented one. You might audit the QA department’s compliance perfectly, but how do they interact with Engineering? With Purchasing? Do the departments work together as teams to achieve the organizational policy?

This cluses-based auditing is particularly the drawback of the certifying bodies. They need the proof to each clause and so need those check lists as evidence of what they audited for giving a certificate. Organizations using ISO 19011 for internal auditing should be focused on the true performance of their management system. The clauses should not become the masters. The clauses are the servants of the organization which help it meet objectives in a systematic manner.  There is therefore a need for auditing to move toward capability assessment.

Mature auditors both internal and external (second and third party) recognize these limitations. They seek to understand not just if a standard is being met, but how capable the organization is of delivering value and achieving its strategic objectives. Assessing organizational capability involves a shift from asking, “Do you have a process for xxx?” to asking, “How effective is your capability for xxx?” This change in attitude is essential for auditors if the organizations are to use the audit inputs to drive their systems to conformity. A capability assessment looks beyond mere existence and focuses on factors like integration and context, the need to understanding the ‘why’.

Instead of just verifying that process descriptions exist (ISO 9001 clause 4.4), mature auditors ask how these processes are integrated to support the organization’s unique context (ISO 9001 clause 4.1) and the strategic direction. Does everyone in the organization understand how their role connects to the high-level goals and the external landscape? The need is to go from clause which asks show me your ‘context of the organization’ document to capability. Mature auditors would perhaps ask the process owner to walk the auditor through how the analysis of the business context directly influences organizations risk planning and, consequently, the operational processes.

There is need for future auditing to look at process effectiveness and performance. Just checking for the existence of monitoring and measurement (ISO 9001 clause 9.1) isn’t enough. A capability approach evaluates what is measured, how it’s analyzed, and most importantly, what action is taken. The maturity in an auditor needs him/ her to move from clause questions as do you have key performance Indicators (KPIs) per ISO 9001 clause 6.2 to seeking evidence by moving to questions and evidence indicating capability.  Ask the organization to show the auditor how these specific KPIs (which are linked to your objectives) have helped you identify a problem area, leading to an improvement that resulted in measurable cost savings/quality increase.

Mature auditors look to ISO 9001 clause 7.2 competence and clause 7.1.6 organizational knowledge and should instead of reviewing training records (clause 7.2) which would be compliance should instead be assessing capability which involves understanding if the staff actually have the competence to perform their tasks and if that knowledge is shared and retained by the organization (clause 7.1.6). Therefore, from clause attitude of asking show me the training records for your machine operators the auditors would move to assessing capability by interviewing an operator and asking, can you explain the why behind this step? What would happen if this critical process parameter was out of tolerance? How do you ensure this critical operating knowledge isn’t lost when someone retires or leaves?

Mature auditors would need to look at leadership and organizational culture with a fresh look. This is perhaps the biggest differentiator. Compliance can often be achieved with minimal leadership engagement. Assessing capability requires evaluating the commitment of top management (clause 5.1). Do they promote a culture of quality, safety, and continuous improvement? Is “management commitment” tangible and felt throughout the organization? Here moving from clause wherein auditors asked to see minutes of the last management review meeting need to move to the capability assessment by asking to be shown the evidence where leadership has allocated resources specifically to address an identified strategic risk, resulting in a quantifiable change to operational capability. Perhaps asking leadership to provide evidence of how they encourage and process employee suggestions for improvement?

For mature auditing this shift matters. Mature auditors are pushing these boundaries because it delivers far greater value to the organization being audited and to its stakeholders. This change will drive real-world improvement. Compliance-based audits can identify deficiencies, but capability assessments identify opportunities for significant performance gains, cost reduction, and quality enhancement. The need is to enhances Business Resilience. A capable organization can adapt and respond to change more effectively than a merely compliant one. Evaluating capability helps identify potential weaknesses that compliance-based audits might miss, making the organization more robust.

Moreover, mature auditing elevates the audit function. Instead of an auditor focused only on clauses being a cost center, an auditor who can assess and provide insights into organizational capability becomes a strategic partner to management, adding real value to the business. Greater stakeholder confidence is the desirable outcome. Customers, regulators, and investors are increasingly looking for more than a certification certificate. They want assurance that the organization is robust, reliable, and capable of delivering on its promises. A mature audit providing an assessment of capability provides this greater assurance. That then is the path forward. Making this shift isn’t simple. It requires auditors to have not only deep knowledge of the standards but also a high level of business acumen, system thinking, and strong interviewing skills. It also requires the auditee organization to be open to a more holistic, collaborative, and potentially challenging audit process. The rewards to the organization are a more effective, efficient, and resilient organization and are well worth the effort. By focusing on capability rather than just compliance, auditors can transform the audit process from a bureaucratic exercise into a vital driver of organizational excellence.

This article was written by IJ, Principal Consultant at QMII. With extensive experience in ISO standards, auditing, and organizational transformation, IJ has guided global organizations in strengthening their management systems. His approach focuses on aligning ISO implementation with strategic business objectives to drive long-term performance improvement.