Spring special until 15 September: 30% off qualifying HACCP and FSSC 22000 courses. Enter code SPRING30 at checkout and the discount is applied before you pay. See the HACCP and FSSC 22000 courses

Corrective Action and Root Cause Analysis: How to Close an Audit Finding So It Stays Closed

Home / Guides / Corrective action and root cause analysis

Audit findings Β· Root cause and CAPA

A correction fixes the product or the moment. A corrective action removes the cause so the finding cannot return. ISO 22000:2018 keeps them apart: nonconformity control at clause 8.9 and corrective action under improvement at clause 10. Codex CXC 1-1969, revised 2022, requires corrective actions at every critical control point under principle 5. A finding stays closed only when effectiveness is verified with records gathered after implementation.

Key facts

  • Correction Fixes the product or the immediate situation
  • Corrective action Removes the cause of the nonconformity
  • ISO 22000:2018 Clause 8.9 nonconformity control, clause 10 improvement
  • Codex CXC 1-1969, revised 2022, principle 5 establish corrective actions
  • R638 of 2018 Regulation 10(1)(c) requires routine assessment of training impact
  • Rejected root cause Human error, operator retrained, with no system cause
  • Close out test Evidence of effectiveness over a defined period after implementation
  • Training RCA overview R649 Β· RCA one day R1,250 Β· Internal auditing R3,500

If your findings keep coming back, the problem is the investigation

If you are the person who fills in the corrective action column and you have written “operator retrained” more than once this year, start with the four hour overview and move up to the one day course when you need to facilitate an investigation for other people.

An Overview of Root Cause Analysis, R649
Root Cause Analysis One-Day, R1,250
Written and taught by a registered Lead Auditor with Exemplar Global and IRCA, who reads corrective action responses from South African manufacturers every week. Self paced online with lifetime access.

What is the difference between a correction and a corrective action?

A correction deals with the thing in front of you. You stop the line, quarantine the pallet, switch the detector back on, reprint the label. A corrective action deals with the reason it happened and removes that reason. ISO 22000:2018 separates the two, handling immediate control of nonconformity at clause 8.9 and corrective action under improvement at clause 10. Most rejected responses stop at the correction.

The confusion has a cost. When a site writes “the chiller was reset to 4 degrees Celsius and product was checked” and calls that a corrective action, nothing about the plant has changed. The chiller will drift again, because whatever allowed it to run above specification for a full shift without anyone noticing is still there: the alarm that nobody hears on night shift, the temperature log that gets filled in from memory at the end of the shift, the maintenance schedule that skipped the condenser clean.

Auditors are trained to read a response and ask one question of it: if we ran this plant for another year with exactly this change in place, could the same failure happen again? If the answer is yes, the response contained a correction and nothing else. Codex CXC 1-1969, General Principles of Food Hygiene, revised 2022 (2023 edition), builds the same expectation into principle 5, establish corrective actions, which requires that action at a critical control point deals with the affected product and returns the step to control, not simply that somebody adjusted a dial.

Correction, corrective action, preventive action and continual improvement

Correction handles the output. Corrective action handles the cause. Preventive action handles the same cause where it has not yet failed, and continual improvement raises performance that already conforms. The four words get used on audit forms as if they were interchangeable. ISO 22000:2018 covers the first two directly and carries the preventive intent through planning and clause 10 rather than a separate preventive action clause.

Term What it acts on Trigger Food plant example
Correction The affected product or the immediate situation A nonconformity has occurred Hold and reject the 62 crates produced while the metal detector was off
Corrective action The cause of the nonconformity Investigation has identified why it happened Fit an interlock so the conveyor cannot run unless the detector is in run mode with reject enabled
Preventive action The same cause elsewhere, before it fails A cause is found that could exist on other lines, shifts or sites Check the isolator wiring on lines 1, 3 and 4 and on the sister site’s packing hall
Continual improvement Performance that already conforms A decision to raise the standard, not a failure Move from a manual start-up check to automatic logging of every detector test with a time stamp

Preventive action is the cheapest credit an auditor will ever give you, and almost nobody claims it. Find a cause on line 2 and the auditor expects you to have looked at lines 1, 3 and 4 and to have said so in writing. Continual improvement is not the place to park a failure either. Writing “we will consider automating this as part of continual improvement” in a corrective action response reads as a plan to do nothing, and experienced auditors read it that way.

What does an auditor actually want in a corrective action response?

What you did about the product, how far you looked, what the cause was and how you know, what you changed, who owns it and by when, proof the change is in place, and proof it worked. Those are the seven things an auditor wants in writing. The last one is what most responses omit, and it decides whether the finding stays closed at the next audit.

The response is a document that a stranger has to be able to follow without phoning you. Assume the person reading it was not in your plant, does not know your line numbers, and will be comparing your words to the evidence you attached. Vague verbs are the enemy: “reviewed”, “reinforced”, “emphasised”, “sensitised”, “monitored going forward” and “ongoing” all describe activity without describing change. Replace each of them with something a person could photograph.

The seven things a corrective action response must contain

  • Correction. What happened to the affected product or situation, with quantities and batch codes.
  • Extent and containment. How far back you looked, how far forward, and what you found.
  • Root cause. Stated as a system condition, with the method used and the evidence that supports it.
  • Corrective action. The specific change to a document, a machine, a process or a control.
  • Responsibility and target date. A named role and a real date, not “immediate” or “ongoing”.
  • Verification of implementation. Objective evidence the change exists, attached and referenced.
  • Verification of effectiveness. Records from after the change, over a stated period, showing no recurrence.

The version of this I see most often arrives as one page with a training register stapled to the back. The register shows a date, eight names, eight signatures and the title of the procedure. It proves eight people sat in a room for an hour. It does not tell me what the investigation found, whether anyone watched those eight people do the job afterwards, or what would stop the ninth person failing the same way next month. I send those back with one question: what changed in the plant?

The auditor also reads for consistency. If your root cause is a wiring design fault and your corrective action is a toolbox talk, the response contradicts itself and will come back. If your root cause is a training gap and your effectiveness evidence is a signature on a register, you have asserted effectiveness instead of proving it.

Worked example: a metal detector found switched off at line start

This is a hypothetical worked example, not a client case, and no real company is described. A ready meals plant runs chilled meals on four packing lines. At 07:10 during a certification audit, the auditor finds the metal detector on line 2 switched off. The line started at 06:00. The CCP log for line 2 already carries a signature against a 06:00 start-up test that was never performed.

The finding as the auditor wrote it

The metal detector at the CCP on packing line 2 was found switched off at 07:10 with production in progress since 06:00. The start-up test piece challenge required by the CCP monitoring procedure had not been performed, and the CCP record for 06:00 had been signed as complete.Hypothetical non-conformity wording, worked example only

Correction

Line 2 stopped at 07:12. The detector was switched on and challenged with the ferrous, non-ferrous and stainless test pieces named in the site CCP specification, in the pack orientation the procedure states, and the reject mechanism was confirmed to operate. All product produced between 06:00 and 07:12 was identified by batch code, 62 crates, and placed on hold under a numbered hold notice.

Containment and extent

The 62 crates were passed back through the verified detector, with the rejects retained for examination. None had been dispatched. The team then looked backwards, which is the step most sites skip: they pulled 90 days of line 2 CCP logs and compared every start-up signature time against the line’s own machine start time from the packing line control system. Eleven start-up records across the period carried times that did not match the line start. That is the real extent of the problem, and finding it before the auditor does changes the whole conversation.

Root cause, done badly and then done properly

The five whys done badly runs like this: the detector was off, because the operator did not switch it on, because the operator did not follow the procedure, because the operator was not paying attention. Cause: human error. Four whys and the chain has landed on a person, which is where an unfacilitated five whys almost always lands.

Run at the machine with the operator, the shift supervisor, an electrician and quality present, the same technique produced a different chain. The detector was off because it did not come back on after the wet clean. It did not come back on because its supply is on the same isolator as the wash-down circuit and has to be switched on separately at the panel, a change made during a refit two years ago. Nothing stopped the line running with the detector off, because there is no interlock between detector run status and the conveyor. Nobody caught it, because the start-up check is recorded on the daily CCP log, and the CCP logs are issued from the quality office with the day’s paperwork at 07:00, an hour after the early line start. And the operator had been signed off as competent on the CCP procedure after a classroom session with a written test, never observed performing a start-up on a live line.

A fishbone run over the same problem sorted those into method, machine, measurement and people, and made it obvious that three separate barriers were missing at once. An is and is not analysis confirmed the pattern: the failure occurred on line 2 and not lines 1, 3 and 4, on early starts and not on shift changeovers, and after wet cleans and not after dry changeovers. That is the signature of the isolator, not the signature of one careless person.

Root cause as finally stated

The CCP start-up verification on line 2 depended on one operator remembering two separate manual actions after a wet clean, with no engineering interlock, no independent release before first production, and no monitoring record on the line at the time the check was due. Competence had been assessed off the line, so the assessment could not have detected that the operator did not know the detector needed switching on separately.

Corrective actions

Engineering rewired the detector to its own supply, restored on line power-up, and fitted an interlock that prevents the conveyor running unless the detector is in run mode with the reject device enabled. Quality moved CCP log issue to shift handover so the record is on the line before first product, added a documented line clearance release by the shift supervisor as a gate before the first crate, and changed CCP competence assessment from written test to observed practical sign-off at a live start-up. Start-up time against machine start time went onto the internal audit checklist and the monthly CCP verification schedule.

Verification of implementation

Engineering job card and completed interlock function test, dated and signed. Panel and interlock photographs. The procedure revision with its new revision number and issue date. The revised line clearance form in use. Observed practical assessment records for all eight line 2 operators. The updated internal audit checklist.

Verification of effectiveness

Over the eight weeks after implementation, covering 61 line starts, every start-up record was checked against the line control system start time and all matched. Quality ran nine unannounced checks at early starts and found the detector running with reject enabled every time. The interlock was function tested at each weekly preventive maintenance and passed. The effectiveness review, with the period and the sample stated, was signed off at the monthly food safety team meeting.

Learn to run the investigation, not just fill in the form

If you are the person who has to sit at the machine with an operator, an electrician and a supervisor and keep the questions moving past “human error”, the one day course teaches the facilitation, not only the technique.

Root Cause Analysis One-Day, R1,250
Internal and Supplier Auditing Practices, R3,500
SAATCA registered training centre TC No. 065, listed on SAATCA’s public register of online registered providers. QR verifiable certificate the day you pass.

Which root cause technique should you use, and when?

Five whys suits a simple chain. Fishbone suits several interacting factors. Fault tree suits a failure with several independent routes. Is and is not defines a fuzzy problem before you explain it, and change analysis answers why something that worked yesterday failed today. Those five cover almost everything a food plant needs. The mistake is using five whys for everything because it is the only one anyone was taught.

Technique Best used when What it produces How it fails Time required
Five whys A single, simple causal chain and you need an answer today A short written chain from the event to a system condition Follows one line only, and stops at the operator because that is the easiest place to stop 20 to 45 minutes with the right people in the room
Fishbone (Ishikawa) Several factors interact, or the team disagrees about the cause Sorted candidate causes under method, machine, material, people, measurement and environment Generates a wall of possibilities and no ranking, so nothing gets tested 60 to 90 minutes, plus verification of each candidate
Fault tree analysis A serious failure with more than one independent route to the same outcome, such as a recall or a CCP loss A logic diagram showing which combinations of failures produce the top event Needs real technical knowledge of the system, and gets guessed at when that knowledge is missing Half a day upwards, usually across two sessions
Is and is not analysis Before you explain anything, when the problem is fuzzy or intermittent A sharp problem statement: where it happens and where it does not, when and when not, on what and not on what Treated as paperwork rather than as evidence, so the pattern in the data is never read 45 to 60 minutes, mostly spent pulling records
Change analysis Something that ran correctly for a long period suddenly fails A list of what changed in equipment, supplier, personnel, method, shift pattern or environment People remember only the changes they made themselves, so the register has to be checked 30 to 60 minutes if change control records exist

Five whys is a single strand of reasoning applied to a system that usually failed for two or three reasons at once, and the strand ends wherever the group is willing to stop, which is usually at the operator. Reach for a fishbone or an is and is not the moment a second factor appears. Our root cause analysis course guide sets out how the two ASC courses differ in depth.

How do you tell a real root cause from a convenient one?

Apply three tests. Removal: if this condition were removed, would the event have been prevented? Control: is this something the organisation can actually change? Explanation: does it explain everything the evidence shows, including why the failure happened here and not somewhere else? A cause that fails any one of the three is a stopping point somebody chose, not a cause.

A less formal test works better than any of the three in practice: a real root cause is uncomfortable, because it usually points at a decision made higher up the organisation than the person standing at the machine. The isolator in the worked example was wired that way during a refit signed off by management. The CCP logs were issued at 07:00 because the quality office opens at 07:00. Both are organisational decisions. A convenient root cause is comfortable for everyone present and costs nothing to fix, which is exactly why it gets written down.

Watch for the tell-tale phrases. “Failure to follow procedure” is a restatement of the finding, not a cause. “Lack of awareness” is a claim about a mental state that no evidence can support or refute. “Communication breakdown” names a category and stops. “Supplier error” is only a root cause once you have explained why your incoming controls did not detect it. Each of these can be pushed one or two levels further with a question about design: what in the way this activity is set up made the wrong outcome possible?

Why “human error” and “operator retrained” get rejected

Retraining addresses a symptom. If the person did not know, training was the cause and retraining is part of the answer. If the person knew and the system still allowed the failure, the system is the cause and retraining changes nothing. Auditors reject “human error, operator retrained” because it hands the problem to an individual who can be replaced next month by another individual who will fail the same way.

South African law is unusually helpful here, because R638 of 2018 does not treat training as a box to tick. Regulation 10(1) requires competence and then requires you to check whether the training actually did anything:

routine assessments are conducted to determine the impact of the trainingRegulation 10(1)(c), R638 of 2018, Government Gazette 41730, 22 June 2018

training programmes and records are kept and routinely updated, as applicable, and are made available to an inspector on requestRegulation 10(1)(d), R638 of 2018, Government Gazette 41730, 22 June 2018

Read those two together and a signature on an attendance register is not evidence of anything. If you are going to claim training as part of a corrective action, you owe an assessment of impact, which in a plant means an observed practical, a competency check on the line, or a documented supervisor verification some weeks later. Keeping those records is covered in our guide to the food safety records every South African food business must keep.

Better alternatives to writing “retrained”

When the investigation points at a person, ask what would have made the correct action the easy one. Design the error out with an interlock, a physical fit that only accepts the right part, or a system that will not accept a record out of sequence. Add an independent check at the point of risk, such as a second person releasing the line before first production. Change the timing so the record is available when the task happens. Simplify a procedure that requires memory of two separate actions in the right order. Change how competence is assessed, from written test to observed practice.

When “the system allowed it” is really a culture problem

If people at your site sign records for checks they did not perform, retraining will not touch it. That behaviour comes from what gets rewarded and what gets ignored, which is what this course is actually about. Managers and supervisors are the audience.

Food Safety and Quality Culture for Management and Supervisors, R1,195
See the culture training page
12 hours, self paced online, lifetime access. More than 3,600 course enrolments to date.

Weak versus strong corrective action response, compared

The same finding can be answered in two pages or in two lines. The table takes the metal detector finding from the worked example and puts both responses beside each other, field by field, in the wording sites actually submit. The weak column is not a caricature.

Field Weak response as submitted Strong response as submitted
Correction Metal detector was switched on immediately. Line 2 stopped 07:12. Detector switched on and challenged with ferrous, non-ferrous and stainless test pieces per CCP specification, reject verified. 62 crates produced 06:00 to 07:12 identified by batch code and held under hold notice 2026/041.
Extent Not stated. Held product re-passed through the verified detector, rejects retained, none dispatched. 90 days of line 2 CCP logs compared against machine start times from the line control system: 11 start-up records carried times inconsistent with the line start.
Method used Not stated. Five whys facilitated at the machine with operator, shift supervisor, electrician and QA, confirmed by fishbone and by an is and is not analysis across lines, shift types and clean types.
Root cause Human error. Operator failed to follow the CCP procedure. CCP start-up verification depended on one operator performing two separate manual actions after a wet clean, with no interlock, no independent release before first production, and no CCP record available on the line at the time the check was due. Competence had been assessed by written test off the line.
Corrective action Operator was retrained on the CCP procedure and signed the training register. All operators to be reminded in the next toolbox talk. Detector rewired to its own supply restored on line power-up. Conveyor interlock fitted so the line cannot run unless the detector is in run mode with reject enabled. CCP log issue moved to shift handover. Supervisor line clearance release added before first production. CCP competence assessment changed to observed practical sign-off at a live start-up.
Preventive extension All operators to be retrained. Isolator wiring and interlock status checked on lines 1, 3 and 4 and at the sister site packing hall. Two further lines found without interlocks and scheduled in the same engineering work order.
Responsibility and date QA Manager, immediate. Engineering Manager for rewire and interlock, completed 24 July 2026. QA Manager for log issue, procedure and assessment change, completed 31 July 2026. Named in each attachment.
Verification of implementation Training register attached. Job card 8842 and interlock function test record, panel photographs, procedure QP-CCP-02 revision 6 dated 31 July 2026, revised line clearance form in use, observed practical assessment records for all eight line 2 operators, updated internal audit checklist.
Verification of effectiveness No further incidents have been reported. Eight weeks after implementation, 61 line starts: all start-up records matched the line control system start times. Nine unannounced early start checks by QA, detector running with reject enabled on all nine. Interlock function tested at each weekly PM, all passed. No product held for a missed start-up check. Reviewed and signed at the food safety team meeting of 29 September 2026.
Likely outcome Returned for more information, or closed and repeated at the next audit. Closed on the evidence, and the same finding does not reappear because the failure route no longer exists.

How do you prove effectiveness instead of asserting it?

Effectiveness evidence is generated after the change, over a defined period, under normal operating conditions. “No further incidents have been reported” is an assertion, because absence of a report is not the same as absence of a failure, particularly when the original failure went unreported for 90 days. Name the period, name the sample, and show the records that would have caught a recurrence if there had been one.

Choose the review period by how often the activity occurs, not by the calendar. A control used at every line start can be judged after 60 starts. A control used at monthly stock take needs three or four cycles. A seasonal control cannot honestly be declared effective until the season runs. Say that in the response rather than pretending a two week review covers an annual activity.

Routine records from the changed activity carry weight when they are read as a set rather than sampled from the top of the pile. Independent checks carry more, which is where your internal audit programme earns its keep: an internal audit of the same activity after implementation is the strongest close-out evidence a site can generate for itself. System data that nobody can write by hand carries most of all, such as time stamps, control system logs, weighbridge records or access control data, because none of it can be reconstructed at the end of the shift. The internal and supplier auditing guide covers how to build a programme that produces evidence of that quality.

The best close-out I have been handed came from a site that sent nothing for six weeks and then sent three months of monitoring data. Every record from the changed activity in date order, with the two occasions the new check caught a problem marked up rather than buried, and a one page note from their internal auditor who had gone back and audited the same activity after the change. It took ten minutes to accept, because there was nothing left to ask them.

Corrective action timeframes and what happens if you miss them

The deadline is in your audit report and in the certification programme your certificate is issued against, and it varies by scheme and by finding category. Most schemes distinguish an early deadline for evidence of correction and a stated root cause from a longer close-out period, and serious findings can trigger a follow-up visit. Read the protocol you are certified against rather than relying on a number you half remember.

Missing a response deadline is a certification decision issue, not a paperwork issue: it can hold up the certificate, force an extension audit, move the audit outcome, or in the worst case suspend certification. It also changes how the next auditor reads your site, because a missed deadline says something about management review and resourcing that the auditor will go looking for elsewhere.

Missed deadlines are rarely laziness. The site writes an honest corrective action requiring engineering work, capital approval or a supplier change, then discovers the work cannot be finished inside the window. Separate what you can complete immediately from what needs a project, submit the interim control alongside the plan, and state the dates for the permanent fix. A properly evidenced interim control with a firm implementation date is a far stronger submission than a cosmetic action delivered on time.

How repeat findings destroy an audit grade

A repeat finding is not treated as one more non-conformity. It is treated as evidence that the previous corrective action was ineffective and that the system which verified and closed it does not work. Schemes commonly escalate the category of a repeated non-conformity, and the auditor’s attention moves from the finding itself to internal auditing, management review and the corrective action process as a whole.

A weak close-out is therefore more expensive than the original finding. Close a minor finding with “operator retrained” and the same observation comes back with a heavier category, drags your internal audit programme into scope, and raises questions about every other closed finding in the file. Certification bodies look at trends across audit cycles, and FSSC 22000 Version 7, published in May 2026 and covered in our guide to what is changing in Version 7, keeps food safety culture and quality management among its additional requirement themes, so repeat findings are read as a culture signal as well as a technical one.

I have opened a file at a surveillance audit and found the same observation I had raised the year before, close to word for word, with a new date on the response and a new name in the training column. The operator named in the first response had left the site. The person who replaced them had signed the same register. Nobody had ever asked why the task was possible to get wrong, so the reason was still there on the floor, waiting to be found by whoever looked next.

If you know a finding is a repeat, say so first in your response and explain what was wrong with the previous investigation. Auditors respond well to a site that says the earlier root cause stopped at the operator, here is what we missed, here is the system cause. They respond badly to a site that resubmits the same paragraph with a new date.

The two courses that stop repeat findings at source

Most repeat findings trace back to two gaps: internal audits that do not test effectiveness, and a HACCP team that cannot analyse a control failure. If you sit on the food safety team or run the internal audit programme, these are the two that pay for themselves at the next certification audit.

Internal and Supplier Auditing Practices, R3,500
HACCP for Supervisors and HACCP Teams, R2,730
Both self paced online with lifetime access. Implementation support available through our consulting arm at ascfoodsafety.com.

How do you set up a CAPA system?

A CAPA system is one register, one form, one set of rules about who investigates what, and one meeting where open items are reviewed. Sites that run corrective actions out of email and memory close findings twice and lose the evidence. The register should carry every source of finding in one place: internal audits, certification audits, customer complaints, CCP and OPRP deviations, environmental monitoring results, supplier issues and inspector visits.

If your CCP deviations are the findings that keep recurring, the underlying HACCP work is set out in our HACCP training guide for South Africa.

What the register needs to hold

Minimum fields for a working CAPA register

  • Unique reference and source. Internal audit, certification audit, complaint, deviation, inspection or supplier.
  • Category and risk. So that the depth of investigation matches the severity, and small things do not consume the same effort as serious ones.
  • Correction taken and product disposition. With batch codes and quantities.
  • Investigation method and root cause. Named technique, stated system cause.
  • Corrective action, owner and target date. One owner, one date, no shared ownership.
  • Implementation verified by and on. A different person from the one who did the work.
  • Effectiveness verified by, on, and over what period. The field almost every register is missing.
  • Repeat flag. Linking the reference of any earlier finding on the same subject.

Set a triage rule so effort matches risk. A minor housekeeping observation does not need a fishbone. A CCP failure, a customer complaint about foreign matter, an allergen incident or any repeat finding does, and should be investigated by a small team rather than one person. Write the rule down, because the alternative is that every finding gets the same shallow treatment.

Effectiveness verification gets scheduled as a diary item at the moment the action is implemented, not left to be remembered, which is why so many registers show actions implemented and never verified. Open CAPA items sit as a standing agenda item at the food safety team meeting and at management review, with the count of overdue items reported every month. Ownership of the prerequisite programmes underneath most findings is covered in our guide to prerequisite programmes and GMP, and if you are still deciding which scheme you are answering to, start with which food safety certification your business needs.

Own the whole system, not just the response form

If you are the person who has to design the CCP controls, the verification schedule and the corrective action rules for a certified site, this is the course that puts those pieces together. Take it after HACCP for Supervisors and HACCP Teams, R2,730, or take both in the pathway bundle and save R1,575.

Advanced HACCP System Implementation, R3,950
HACCP Mastery Pathway Bundle, R6,300
FoodBev SETA accredited provider No. 587/00337/1900 Β· B-BBEE Level 1 Β· No VAT is charged on training, so the price shown is the price paid.

Frequently asked questions

What is the difference between a correction and a corrective action?

A correction deals with the thing in front of you. You stop the line, quarantine the product, switch the equipment on, reprint the label. A corrective action deals with the reason the thing happened and removes that reason so the same failure cannot occur again. ISO 22000:2018 handles the immediate control of nonconformity at clause 8.9 and corrective action under improvement at clause 10. A response that contains only corrections will be rejected.

Is human error ever an acceptable root cause?

Almost never on its own. Human error describes what happened, not why the system permitted it. If a person could switch a critical control point off, sign a record for a check they did not perform, or use the wrong label without anything stopping them, the design of the control is the cause. Auditors reject human error because it points at a person who can be replaced tomorrow by another person who will do the same thing.

Why is retraining not a corrective action?

Retraining addresses a symptom. It is a valid part of a response when the investigation shows the training itself was wrong, missing, or assessed only in a classroom. It is not a corrective action when the person already knew the procedure and the system allowed the failure anyway. Regulation 10(1)(c) of R638 of 2018 requires routine assessments to determine the impact of training, which is exactly the evidence a retraining claim needs and rarely has.

How long do I have to respond to a non-conformity?

The deadline sits in the audit report and in the certification programme your certificate is issued against, and it differs by scheme and by finding category. Most schemes separate an early deadline for evidence of correction and a root cause plan from a longer window for close out. Read the protocol rather than working from memory, and diarise the date the day the report arrives, not the week it is due.

What evidence proves a corrective action was effective?

Records generated after the change was implemented, over a defined period, showing the failure did not recur under normal operating conditions. Implementation evidence shows you did something: a job card, a revised procedure, a signed training record. Effectiveness evidence shows it worked: a run of monitoring records, an internal audit of the same activity, an unannounced check, a trend with no recurrence, and an explicit statement of the period reviewed.

Do five whys work in a food plant?

Five whys works well for simple, single chain problems and it is fast, which is why it is the most used technique on the floor. Its weakness is that it follows one line of reasoning and usually stops at the operator, because the operator is the easiest place for the chain to end. Use it for straightforward failures, and pair it with a fishbone or an is and is not analysis when more than one factor is in play.

What happens if the same finding comes back at the next audit?

A repeat finding is treated as evidence that the previous corrective action was not effective, which moves the auditor’s attention from the finding to the management system that closed it. Schemes commonly escalate the category of a repeated non-conformity, and repeats affect the grade or outcome of the audit and the confidence a certification body places in your internal auditing and management review.

Does ISO 22000 still require preventive action?

ISO 22000:2018 does not carry a separate preventive action clause of the kind older management system standards used. The preventive intent sits in planning to address risks and opportunities and in the improvement requirements at clause 10. Many audit report forms still have a preventive action box. Use it for the systemic extension of your corrective action: the other lines, shifts, products or sites where the same cause could exist but has not yet failed.

Who should carry out the root cause analysis?

The people who own the process, facilitated by someone trained in the technique and independent enough to keep asking the uncomfortable question. A root cause analysis written by the quality manager alone, at a desk, describes what the quality manager believes. One run with the operator, the line supervisor, engineering and quality in the room at the machine produces causes that can actually be tested against evidence.

About the author. Mthokozisi Nkosi is a food scientist, a registered Lead Auditor with Exemplar Global and IRCA, an HPCSA registered Environmental Health Practitioner, and one of four SAATCA registered R638:2018 Lead Implementers. He holds an MSc in International Public Health, an MSc in Data Science, an MBA and a BSc in Agriculture (Food Science and Technology), and is completing a PhD in Public Health. He founded ASC Food Safety Consultants, a SAATCA registered training centre (TC No. 065) and FoodBev SETA accredited provider, and reads corrective action responses from South African food manufacturers every week as a working certification and second party auditor. Connect on LinkedIn.

ASC Food Safety Training Β· Leading with Science. Ensuring Food Safety. Β· Fully online, serving all of South Africa and beyond Β· info@ascfoodsafety.com Β· WhatsApp +27 61 483 0381 Β· SAATCA registered training centre (TC No. 065) Β· FoodBev SETA accredited provider No. 587/00337/1900 Β· B-BBEE Level 1 Β· Registered Lead Auditor (Exemplar Global and IRCA) Β· Consulting and document toolkits at ascfoodsafety.com