Industry

ISO 13485 Clause 8: Measurement, Analysis, Improvement and CAPA

Equip IgeraSolutions
September 25, 2026
9 min read
ISO 13485 Clause 8: Measurement, Analysis, Improvement and CAPA
🎧 Listen with AI Voice

2-minute executive summary

⚡ Quick Answer in 30s

ISO 13485 Clause 8 explained: feedback, internal audits, nonconforming product, data analysis and CAPA — and why "improvement" doesn't mean what ISO 9001 says.

✓ Citing current regulationsSee detailed guide below ↓

ISO 13485 Clause 8: Measurement, Analysis, Improvement and CAPA

ISO 13485:2016 Clause 8 requires manufacturers to plan and implement the monitoring, measurement, analysis and improvement processes needed to demonstrate that a product conforms to requirements, that the quality management system conforms to the standard, and that the QMS is maintained as effective — through feedback, internal audits, process and product monitoring, control of nonconforming product, data analysis and a documented CAPA (Corrective and Preventive Action) system. Unlike ISO 9001, Clause 8 does not ask an organisation to pursue continual improvement of the QMS as an explicit, standalone objective; it asks the organisation to keep the system effective and compliant.

Definition: Clause 8 of ISO 13485:2016 ("Measurement, Analysis and Improvement") groups the processes an organisation uses to check that its products and its QMS are working as intended, and to act when they are not. It covers feedback and complaint handling, internal audit, monitoring and measurement of processes and product, control of nonconforming product, analysis of data, and corrective and preventive action.

Why Clause 8 exists: closing the loop on a regulated product

A quality management system that only documents design and production controls is incomplete without a mechanism to check, afterwards, whether those controls actually worked in the real world. Clause 8 is that mechanism. It sits at the end of the ISO 13485 structure for a reason: everything upstream — design controls, purchasing, production, servicing — eventually generates signals (a complaint, a failed inspection, an audit finding, a trend in returned units) that need to be captured, analysed and, where justified, acted on. Clause 8 is where those signals are turned into evidence and, when needed, into action.

Feedback and complaint handling

ISO 13485 requires a documented procedure for gathering and reviewing feedback from production and post-production activities, and a formal process for handling complaints. In a medical device context, this activity does not stand alone: it connects to post-market surveillance and vigilance obligations under the applicable regulatory framework for the markets where the device is placed. Those regulatory frameworks set their own reporting triggers, timelines and forms, and these vary by jurisdiction and by the classification and risk profile of the device — so an organisation should confirm its exact reporting obligations with the applicable regulation and, where relevant, its notified body or regulatory authority rather than relying on generic guidance.

What Clause 8 itself requires, independent of any specific regulatory timeline, is that the organisation:

  • Has a defined procedure for receiving, logging and evaluating complaints and other feedback.
  • Determines whether a complaint represents an event that is reportable under applicable post-market surveillance or vigilance regulations, and documents that determination.
  • Investigates complaints, records the investigation (or documents and justifies why an investigation was not carried out), and keeps the outcome traceable.
  • Feeds complaint data into the CAPA and risk management processes rather than treating each complaint as an isolated event.

Internal audit

Clause 8.2.4 (in most editions' numbering) requires periodic internal audits to verify that the QMS conforms to the planned arrangements, to the requirements of ISO 13485 itself, and to the QMS requirements the organisation has set for itself — and that the system is effectively implemented and maintained. Audits are planned with a programme that takes into account the status and importance of the processes and areas audited, and the results of previous audits. Findings must lead to timely correction and, where warranted, corrective action, and follow-up verification should confirm that the action taken was effective.

Monitoring and measurement of processes and product

Two related but distinct activities sit here. Process monitoring checks that the processes of the QMS achieve their planned results — using suitable methods that reflect the ability and criticality of each process. Product monitoring checks that product characteristics have been met at appropriate stages, with records that identify the person authorising release of product for the next stage or for delivery, and keeps that identification traceable. For product that requires implantation or that carries elevated risk, records of monitoring and measurement typically need to be more detailed and more clearly traceable to enable investigation if something goes wrong downstream.

Control of nonconforming product

Nonconforming product must be identified and controlled to prevent unintended use or delivery. The organisation documents a procedure that defines the controls, responsibilities and authorities for identification, documentation, segregation, evaluation and disposition of nonconforming product, including — where applicable — product discovered after delivery. Rework is permitted but must itself be controlled, documented and, where it could affect conformity, re-verified. Where nonconforming product is detected after delivery or use has started, the organisation must document the actions taken in response, including any advisory notice or field action, in a manner consistent with its post-market surveillance obligations.

Analysis of data

Clause 8.4 requires the organisation to determine, collect and analyse appropriate data to demonstrate the suitability, adequacy and effectiveness of the QMS, and to identify opportunities for improvement. The standard specifies sources this analysis must draw on, including feedback, conformity to product requirements, characteristics and trends of processes and product (including opportunities for preventive action), suppliers, audits, and service reports where servicing is a specified requirement. This is where trend analysis lives: a single complaint may not warrant CAPA, but a pattern across a product family, a supplier or a process step usually does.

CAPA: corrective and preventive action

The CAPA system is the mechanism through which Clause 8's other activities produce change. It has two distinct halves, and mixing them up is one of the most common sources of confusion:

  • Corrective action eliminates the cause of a nonconformity that has already occurred, to prevent recurrence. It requires reviewing the nonconformity, determining its causes, evaluating the need for action to ensure it does not recur, determining and implementing the needed action, documenting the results, and reviewing the effectiveness of the corrective action taken.
  • Preventive action eliminates the cause of a potential nonconformity — one that has not yet occurred — to prevent its occurrence. It follows a parallel logic: identify potential nonconformities and their causes, evaluate the need for action, implement it, document it, and review its effectiveness.

ISO 13485 explicitly requires that corrective and preventive action be evaluated for any effect on the ability to meet regulatory requirements and on product safety and performance, and that changes resulting from CAPA be reviewed and, where required, validated or verified before implementation. This regulatory link is one of the clearest differences from a generic quality system: a CAPA in a medical device company is not just a quality record, it is potentially a regulatory event.

2

Separate, distinct disciplines within one CAPA system: corrective action (react to a nonconformity that already happened) and preventive action (act on a potential nonconformity before it happens). Auditors routinely find these conflated into a single generic "action" record, which weakens traceability for both.

The key point most teams get wrong: "improvement" in ISO 13485 vs ISO 9001

This is one of the most frequently misunderstood aspects of ISO 13485, and it is worth stating precisely. ISO 9001 treats continual improvement of the QMS as an explicit, standing requirement — organisations are expected to actively and continuously enhance the suitability, adequacy and effectiveness of their management system over time. ISO 13485 does not carry that same explicit continual-improvement mandate. Instead, ISO 13485 requires the organisation to demonstrate that the QMS is effectively implemented and maintained, and that its processes achieve their planned results consistently, in a regulated environment where uncontrolled or unplanned change to a validated process or product can itself introduce risk.

This is not a licence to be static. Clause 8 still requires the organisation to identify and implement necessary changes through CAPA, to analyse data for opportunities to improve, and to act on nonconformities and audit findings. What is different is the framing and the constraint: in ISO 13485, any change — including one aimed at "improving" something — has to be evaluated for its effect on product safety, performance and regulatory conformity, and controlled accordingly, rather than pursued as an open-ended, continuous optimisation of the system for its own sake. In practice, this means changes to a validated process typically require a documented change control and, where appropriate, re-validation, rather than being rolled out simply because a trend analysis suggested an efficiency gain.

Practical impact: what this changes in how the system runs day to day

For a quality team, the ISO 9001 vs ISO 13485 distinction on improvement translates into concrete operational habits:

  • CAPA effectiveness reviews are not optional paperwork — auditors expect to see that the organisation went back and checked whether the corrective action actually worked, with objective evidence, not just a closed record.
  • Trend data (complaints, nonconformities, audit findings, process monitoring results) needs a defined review cadence and a documented threshold for when a trend triggers CAPA, rather than being reviewed only when something goes visibly wrong.
  • Changes proposed through CAPA or data analysis go through change control before implementation, with an assessment of impact on regulatory status and on validated processes — "we improved it" is not, on its own, sufficient justification in an audit.
  • Complaint handling and CAPA cannot be siloed from each other or from risk management — an auditor will trace a single complaint through investigation, disposition of any nonconforming product, CAPA (if triggered), and back into risk documentation, and expects that trail to be coherent.

// Demo IgeraIndustria — Clause 8 query

Quality Manager: Do we have an open CAPA linked to the Class IIb device complaint trend from last quarter, and what was the documented root cause?

IgeraIndustria: CAPA-2025-0041, opened from Complaint Trend Report CTR-Q3, references three complaints tied to the same lot family. Root cause per the investigation record: a seal specification tolerance drift identified during process monitoring. Corrective action and effectiveness review status, plus the linked risk file update, are documented in the same record — cited with the exact section reference.

Common audit findings on Clause 8

Auditors and notified body assessors repeatedly flag a recognisable set of issues in this area:

  • CAPA records closed without an effectiveness review, or with an effectiveness review that is not based on objective evidence.
  • Corrective and preventive action conflated into one generic process, making it unclear whether the organisation is reacting to an existing problem or preventing a potential one — and whether the required steps for each were actually followed.
  • Complaint investigations that don't clearly link to the reportability determination — no documented rationale for why an event was, or was not, escalated under post-market surveillance or vigilance requirements.
  • Internal audit programmes that don't reflect risk — the same shallow checklist applied to every area regardless of criticality or history of findings.
  • Data analysis that is descriptive but not actionable — trends are charted and reported but never clearly tied to a decision about whether CAPA is warranted.
  • Nonconforming product records with gaps in the disposition chain — segregation, evaluation and authorisation for release not clearly traceable to a named, authorised individual.
  • Changes implemented following a CAPA without documented change control or re-validation of the affected process.

Most of these findings share a common thread: the individual activities (complaints, audits, monitoring, CAPA) exist and are documented, but the links between them — the traceability that shows one feeds into the next — are weak or missing. That traceability is exactly what an auditor is trained to pull on.

Where IgeraIndustria fits

Clause 8 generates a lot of interlinked documentation: complaint logs, audit reports, monitoring records, nonconformity dispositions, CAPA files, data analysis reports. Finding the exact record that answers an auditor's question — or confirming, before the audit, that the trail from a complaint to its CAPA to its effectiveness review is complete — is largely a retrieval problem. IgeraIndustria indexes a company's own QMS documents and answers questions in seconds, citing the exact source document and section, rather than requiring a manual search across procedures, complaint logs and CAPA records.

Spending hours tracing a complaint through to its CAPA and effectiveness review before an audit? IgeraIndustria answers directly from your own QMS documents, with the exact source cited.

Try it free for 14 days
Summary
  • Clause 8 covers feedback/complaints, internal audit, process and product monitoring, control of nonconforming product, data analysis and CAPA.
  • Complaint handling connects to post-market surveillance and vigilance obligations, but exact reporting timelines and triggers depend on the applicable regulation and device classification — always verify against the current regulatory text for the relevant market.
  • The key ISO 9001 difference: ISO 13485 requires the QMS to be demonstrably effective and maintained, not continually improved as an explicit, standalone objective — changes must be controlled and evaluated for regulatory and safety impact, not pursued as open-ended optimisation.
  • The most common audit findings involve broken traceability between activities (complaint → CAPA → effectiveness review) rather than any single missing activity.
  • IgeraIndustria indexes CAPA files, complaint logs, audit reports and procedures, answering with the exact document and section cited.
Disclaimer

This article is for informational purposes only and does not constitute certification, legal or regulatory advice. ISO 13485 certification, interpretation of specific clauses, and post-market surveillance/vigilance reporting obligations depend on your product classification, target markets and current regulatory text. Consult a qualified quality/regulatory consultant or your notified body before making compliance decisions.

FAQ

What is the main purpose of Clause 8 in ISO 13485?

Clause 8 sets out how an organisation monitors, measures and analyses its QMS and its products, and how it acts on the results — through feedback, internal audit, nonconforming product control, data analysis and CAPA — to demonstrate that the system is effective and stays that way.

Does ISO 13485 require continual improvement like ISO 9001?

No, not in the same explicit sense. ISO 13485 requires the organisation to demonstrate that the QMS is effectively implemented and maintained. It still requires acting on nonconformities, complaints and data through CAPA, but any resulting change must be controlled and assessed for its effect on regulatory conformity and product safety, rather than pursued as an open-ended continual-improvement objective.

What is the difference between corrective and preventive action?

Corrective action addresses a nonconformity that has already occurred, to stop it recurring. Preventive action addresses a potential nonconformity that has not yet occurred, to stop it from happening in the first place. Both require identifying the cause, evaluating and implementing action, and reviewing effectiveness.

Do all complaints have to be reported to a regulator?

Not automatically. The organisation must evaluate each complaint against the post-market surveillance and vigilance reporting criteria that apply to its device and market, and document that determination. Exact criteria and timelines vary by jurisdiction and device classification, so this should be checked against the current applicable regulation.

Can a CAPA be closed as soon as the corrective action is implemented?

No. ISO 13485 requires a review of the effectiveness of the corrective (or preventive) action taken, meaning objective evidence that the action actually addressed the cause, before the CAPA can reasonably be considered closed.

Who can authorise the release of nonconforming product after rework?

The organisation's own documented procedure defines the responsibilities and authorities for this decision. What Clause 8 requires is that the authorisation is by a defined, competent role, that it is recorded, and that any product requiring re-verification after rework is actually re-verified before release.

How does IgeraIndustria help with Clause 8 documentation?

IgeraIndustria is an AI assistant that answers directly from a company's own QMS documents — complaint logs, audit reports, CAPA files, monitoring records — citing the exact source, so quality teams can trace a record such as a complaint through to its CAPA and effectiveness review in seconds instead of searching manually across systems.

#ISO 13485 Clause 8#CAPA medical devices#ISO 13485 corrective and preventive action#ISO 13485 internal audit#ISO 13485 vs ISO 9001#nonconforming product ISO 13485#post-market surveillance QMS#medical device quality management

Ask this article

IA 2026

Igera's AI answers questions citing the facts and regulations in this article

2 of 2 free queries

Suggested questions (click to test):

Diagnóstico Interactivo 60s

Technical Compliance & Industrial Operations Diagnostic

Analyze speed of access to regulations (CTE, OSH, CE) in your plant or jobsite

Pregunta 1 de 3

How do technicians and operators access safety protocols and manuals?

Was this article helpful?

⚙️IgeraIndustriaOperations Template
GUÍA DESCARGABLE (TXT)

Preventive Maintenance & ISO 9001/45001 Industrial Checklist

Floor inspection template for machine operations, failure tracking and unplanned downtime reduction.

  • Shift inspection standardization for plant operators
  • Up to 40% faster anomaly response times
  • Full traceability for ISO audits and HSE compliance

Instant download · No card · 100% spam-free

Share this article

Help spread knowledge by sharing this content with your network