Skip to main content
Term Acronym Family Short definition Definition Synonyms
CAPA — Corrective and Preventive Action CAPA Quality/GxP

Corrective and Preventive Action: actions to address the causes of quality problems and prevent recurrence or occurrence.

CAPA stands for Corrective and Preventive Action. It brings together actions used to investigate quality problems, address their causes and manage the risk of recurrence or future occurrence.

A correction addresses a detected problem. A corrective action addresses its cause to prevent recurrence. A preventive action addresses the cause of a potential problem before it occurs.

A useful CAPA record identifies the issue, supporting evidence, investigation, actions, owners and deadlines. It also defines how effectiveness will be assessed: completing an action is not enough if the same problem continues.

Family: Quality / GxP. Apply the terminology and process required by your organisation’s quality system.

Discuss your quality improvement process

ISO 27001 ISO 27001 Standards & frameworks

International standard for information security management systems.

ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS).

An ISMS organises how an organisation manages information security risks. It connects responsibilities, risk assessment, selected controls, monitoring and improvement, with the aim of protecting information confidentiality, integrity and availability.

The standard can be applied by organisations of different sizes and sectors. Implementing an ISMS and obtaining independent certification are distinct steps; a reference to the standard alone does not demonstrate certification.

Variant: ISO27001. Family: Standards and frameworks.

Read the risk assessment guide · Discuss your ISMS needs

Reference: ISO — ISO/IEC 27001.

ISO27001
ITIL ITIL

Framework for managing IT and digital services.

ITIL is a widely used framework for managing IT and digital services. Its practices help organisations organise service delivery, clarify responsibilities and improve outcomes for users and the business.

In daily operations, it can inform how a team handles incidents and requests, investigates recurring problems and prepares changes. The practices should be adapted to the organisation’s needs and risks rather than treated as a requirement to introduce a large administrative system.

ITIL is a management framework, not a ticketing product. A tool can support the practices, but responsibilities, decisions and review routines still need to be defined.

Historical expansion: Information Technology Infrastructure Library. Family: Service management frameworks.

Discuss your service management needs

Reference: PeopleCert — ITIL.

PDCA PDCA Methods

Plan–Do–Check–Act: a continuous improvement cycle for planning, testing, checking results and acting on what has been learned.

Plan–Do–Check–Act: a continuous improvement cycle for planning, testing, checking results and acting on what has been learned.

Each cycle connects an objective, a tested action and a decision based on results. Completing an action is not enough: its effectiveness must be assessed before expanding or adjusting it.

Read the practical PDCA guide and IT example