Corrective action

Nonconformities & CAPA

Log a nonconformity, find its root cause, correct it, and verify the fix worked before you close it, the ISO 27001 / 9001 Clause 10 loop.

Start free See pricing
Nonconformities & CAPA walkthrough
app.keelgrc.com/nonconformities
Quality
Nonconformities & CAPA
9
Open NCs
6
Root-caused
4
Actions due
1
Overdue
NonconformitySourceSeverityActionStatus
Missing supplier recordsInternal auditMajorCorrective actionOpen
Uncontrolled documentInternal auditMinorRoot cause doneIn progress
Late management reviewManagement reviewMinorScheduledOpen
Calibration overdueProcess checkMajorCorrective actionOverdue

Finding a gap is only half the job. Proving you fixed it is the rest. Keel turns a nonconformity into a tracked loop the way ISO 27001 and ISO 9001 Clause 10 expect: capture what went wrong, analyze the root cause, assign corrective actions, and, critically, verify the fix actually worked before the record can close. It’s the hub your internal audits and security incidents feed into.

Corrective action falls apart in a spreadsheet

An auditor flags a nonconformity, someone notes it, and weeks later nobody’s sure whether it was really fixed, or whether the fix held. Without a root-cause step and an effectiveness check, “closed” means “we stopped talking about it,” which is exactly what an auditor probes.

What nonconformities & capa does

Log from any source

Capture a nonconformity from an internal audit finding, a security incident, a risk, or a failed control, with severity (observation / minor / major), an owner, and a due date.

Guided root-cause analysis

Work the root cause with a guided 5 Whys or Fishbone (cause-and-effect) method, so closure addresses why it happened, not just the symptom. The method and analysis are recorded on the nonconformity.

Corrective actions with owners

Break the fix into concrete corrective actions, each with an owner and due date, and track them to done, so remediation has a clear path from “found” to “fixed.”

An effectiveness gate before closure

A nonconformity can’t be closed until you’ve recorded how you verified the corrective action worked and confirmed it, the Clause 10 effectiveness check, enforced by the workflow rather than left to a checkbox.

A clear lifecycle

Each nonconformity moves through open → root cause → corrective action → verifying → closed, with a register that shows what’s open, in progress, overdue, and done at a glance.

Why it matters

  • Turn audit findings and incidents into tracked corrective action, not notes
  • Address root causes with a guided 5 Whys / Fishbone, not guesses
  • Prove the fix worked with a required effectiveness check before closing
  • Give an auditor a defensible Clause 10 record on demand

Get audit-ready, and prove it

Nonconformities & CAPA is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.

Start free

Frequently asked questions

What is CAPA?

Corrective and preventive action: the process of logging a nonconformity, finding its root cause, acting to correct it, and verifying the action was effective. ISO 27001 and ISO 9001 Clause 10 require it, and auditors check that closure is backed by an effectiveness check.

What root-cause methods are supported?

A guided 5 Whys and a Fishbone (cause-and-effect) framework across the common categories: People, Process, Technology, Environment, Management, Measurement. You record the method and the analysis on the nonconformity.

Why can’t I close a nonconformity immediately?

Because Clause 10 asks you to confirm the corrective action was effective. Keel requires you to record how you verified effectiveness and confirm it before the record can be closed, so “closed” is defensible.

Where do nonconformities come from?

You can log them directly, and they’re designed to be fed by internal audits and the security incident register, both of which route their findings into a corrective-action record here.