Compliance 14 min read

FDA 483s and ISO Nonconformities: One CAPA System

J

Jared Clark

August 23, 2026

Why These Two Findings Feel Like They Speak Different Languages

An FDA Form 483 and an ISO nonconformity report can land on the same desk in the same month and describe, in different words, the exact same gap in your quality system. I've sat across the table from quality directors holding both documents at once, convinced they now owe two separate remediation projects. In my view, that assumption is the single most expensive mistake a regulated manufacturer makes after a bad inspection cycle.

The confusion is understandable. FDA issues a 483 under Section 704(b) of the Federal Food, Drug, and Cosmetic Act, at the close of an inspection, listing conditions an investigator believes may violate the FD&C Act or its regulations. Your ISO certification body issues a nonconformity report under the audit rules in ISO/IEC 17021-1:2015, tied to a contractual certification scheme, not a statute. One is a federal enforcement instrument. The other is a private commercial agreement about whether you keep a certificate. But underneath the paperwork, both are usually pointing at the same broken process: a CAPA that didn't verify effectiveness, a deviation that wasn't investigated to root cause, a document control system that let an obsolete SOP stay on the floor.

Handling them "at once" doesn't mean juggling two response letters. It means building one investigation and one corrective action that happens to generate two different closure documents.

The Structural Differences You Still Have to Respect

Before you merge anything, you need to understand where these two systems genuinely diverge, because a corrective action that satisfies an ISO auditor won't automatically satisfy an FDA investigator, and vice versa.

Dimension FDA Form 483 ISO Nonconformity (Major/Minor)
Legal basis FD&C Act §704(b) Certification body contract under ISO/IEC 17021-1:2015
Issued by FDA investigator (federal employee) Accredited third-party auditor
Formal severity tiers None on the form itself; observations are listed, not ranked Formally classified as major or minor
Typical response window FDA's own practice, cited repeatedly in Warning Letters, treats 15 business days as the expectation Often 90 days to close a major NC, though the exact window is set by the certification body's program, not the standard itself
Escalation if ignored Warning Letter, import alert, injunction, consent decree Certificate suspension, then withdrawal
Closure mechanism FDA reviews your written response and may re-inspect; there is no certificate to reinstate, only enforcement posture to de-escalate Certification body reviews evidence, sometimes requires a follow-up audit, then issues a closure confirmation
Public visibility 483s are subject to FOIA release, though FOIA'd 483s are typically heavily redacted and can take months to years to obtain; Warning Letters are posted publicly and immediately Certification status is public in the CB's registry; the nonconformity text itself is usually confidential between you and the CB

Notice what that table tells you about incentives. FDA has no ongoing commercial relationship with you, so the only lever it has is enforcement severity. Your certification body has a renewal fee riding on your account, so its lever is the certificate itself. That's not cynicism, it's just how the two systems are built, and it explains why an ISO auditor will often accept a well-documented corrective action plan that an FDA investigator would consider incomplete without objective evidence of implementation.

Where the Overlap Actually Lives

The overlap isn't in the paperwork. It's in root cause analysis and effectiveness verification, which both systems demand and which most companies do badly regardless of which one is asking.

21 CFR 820.100(a) requires device manufacturers to establish and maintain CAPA procedures that include analyzing quality data to identify existing and potential causes, and verifying that the corrective action was effective without creating new problems. As of February 2, 2026, that requirement is no longer just an analog of the ISO standard — FDA's Quality Management System Regulation (QMSR) amended Part 820 to incorporate ISO 13485:2016 by reference, so clause 8.5.2's requirement to determine causes, evaluate the need for action, implement it, and review the effectiveness of the action taken is, for device manufacturers, the same regulatory text as 820.100(a), not merely a parallel one. They aren't two requirements asking the same question in different vocabulary anymore. For devices, they're one requirement.

The same pattern holds on the drug side. 21 CFR 211.192 requires a written record of any investigation into an unexplained discrepancy or a failure to meet specifications, extended to other batches that may be associated. ISO 9001:2015 clause 10.2.1 requires you to react to the nonconformity, evaluate the need for action to eliminate the cause so it does not recur, and implement any action needed. Same logic, same sequence: contain, investigate, correct, verify.

Here's the takeaway from this section: if your root cause investigation is genuinely rigorous, one investigation file will satisfy both an FDA CAPA reviewer and an ISO auditor, because both are checking for the same three things:

  • Did you find the actual cause, not just the symptom?
  • Did your action address that cause?
  • Did you prove, with data, that the action worked?

The Mistake: Running Two Parallel CAPA Systems

I've walked into facilities where the quality team maintains one CAPA log for "FDA items" and a separate nonconformity tracker for "ISO items," sometimes in different software, sometimes owned by different people. This duplicates investigation work, and worse, it creates inconsistency risk: if an FDA investigator ever asks to see your CAPA history during a future inspection and finds a related ISO nonconformity that wasn't cross-referenced, that gap itself becomes a new observation. Auditors and investigators both know how to ask "show me everywhere this problem shows up in your system," and a fragmented CAPA structure fails that test even when the underlying quality work was fine.

The fix is a single CAPA record with two output tags: one field for "regulatory driver" (483 observation number, Warning Letter citation, internal deviation, or ISO NC number) and one field for "closure audience" (FDA, certification body, or both). The investigation, root cause, containment, and effectiveness check are written once. The response letter to FDA and the corrective action evidence packet to your certification body are two different documents pulled from the same underlying record, formatted for two different readers.

Building the Combined Response When Both Hit at Once

Here's how I'd sequence it if an FDA 483 and an ISO major nonconformity land within the same quarter, which happens more often than people expect because an ISO surveillance audit and an FDA inspection triggered by the same underlying process failure tend to cluster around the same operational weak point.

  1. Contain before you compare. Whatever immediate risk exists, get product contained and the affected process stopped or controlled. Neither FDA nor your certification body will accept a sophisticated root cause narrative if you shipped more nonconforming product while writing it.

  2. Write one root cause investigation, scoped to the actual failure, not to the citation. Don't investigate "the 483 observation." Investigate the process failure the observation happened to catch. This matters because the ISO nonconformity, even if it uses different words, is very often describing the same failure from a different vantage point, and a narrowly scoped investigation will miss that connection.

  3. Map every citation to that one investigation. Build a simple crosswalk: 483 observation 1 → root cause investigation RCA-2026-014 → ISO NC-2026-009 → CAPA-2026-021. This crosswalk is the single artifact that proves to both parties you're not treating their finding as an isolated compliance exercise.

  4. Draft two closure documents from one evidence file. Your FDA response letter needs to speak to statutory risk and needs to commit to specific completion dates, because FDA reads vague timelines as a sign the correction isn't real. Your ISO corrective action report needs to speak to the certification body's audit criteria and reference the specific clause of the standard. Same underlying facts, different framing for different readers.

  5. Verify effectiveness before you close either one. This is the step most companies rush. Effectiveness verification means going back after the fix has been running for a defined period and confirming, with data, that the problem hasn't recurred. A corrective action closed without effectiveness data is the single most common reason a "corrected" issue reappears at the next inspection or the next surveillance audit, and reappearance is far more damaging than the original finding, because now it reads as a system that doesn't actually fix things.

What Happens If You Ignore One While Fixing the Other

I want to be direct about the asymmetry here, because I've seen companies pour resources into the FDA response and treat the ISO nonconformity as a formality, or the reverse.

If you let an ISO major nonconformity sit past your certification body's closure window, you risk certificate suspension. If your certificate lapses while you're also managing FDA scrutiny, that lapse itself becomes something FDA can ask about, because a suspended ISO certificate is a documented, third-party-verified statement that your quality system had an unresolved gap. It hands an investigator a citable fact instead of an inference.

If you treat the ISO nonconformity as the real work and let the FDA response slide past the practical 15-business-day window, the consequence is more severe and more public. FDA has repeatedly cited late or inadequate 483 responses as a factor in the decision to escalate to a Warning Letter, and Warning Letters are posted publicly and searchable by anyone, including your customers' quality departments. There's no equivalent public exposure for a slow ISO response, at least not directly, though a customer doing supplier due diligence who requests your ISO audit history will see it eventually.

Neither shortcut is safe. But if you have to sequence your attention under real resource constraints, the FDA response window is the one with the harder deadline and the more public downside.

Documentation Strategy: One Evidence File, Two Front Doors

The practical infrastructure for all of this is not complicated, and I'd rather you build it once than rebuild it under pressure during your next dual-finding event. Keep a master investigation record for every quality event, regardless of which system flagged it. Tag that record with every external citation that ever points to it. Store your effectiveness verification data against the investigation record, not against the individual citation, so that if the same root cause surfaces under a different citation number six months later, you can show a reviewer the entire history in one place instead of reconstructing it from memory.

This is also where a documented quality management system built to a recognized standard earns its keep beyond the certificate itself. Organizations working toward GMP certification often ask me whether investing in ISO structure actually helps with FDA readiness, and the honest answer is that a well-implemented management system, the kind built around ISO 13485 for device manufacturers, gives you exactly this kind of traceable, cross-referenced CAPA infrastructure as a byproduct of doing the standard correctly, not as a separate project layered on top of it.

A Word on the Medical Device Single Audit Program

If you manufacture medical devices sold into the U.S., Canada, Australia, Brazil, or Japan, it's worth knowing that these regulators already built a version of the combined approach at the program level. The Medical Device Single Audit Program allows a single audit, conducted by an MDSAP-recognized auditing organization, to satisfy the regulatory requirements of all five participating jurisdictions simultaneously, rather than hosting five separate inspections. MDSAP doesn't replace FDA's authority to conduct its own for-cause inspections, and it doesn't replace your ISO 13485 certification audit, but it's proof that regulators themselves have concluded a single, well-run audit against a harmonized set of criteria is more efficient than parallel, disconnected ones. The logic that justifies MDSAP at the regulatory level is the same logic that should justify a unified CAPA system at the company level.

The Bottom Line

An FDA 483 and an ISO nonconformity are legally and commercially distinct instruments, issued by different parties, carrying different deadlines and different consequences. Treat the deadlines and the audiences as different, because they are. But treat the underlying investigation as one thing, because it is. The quality system failure that produced the 483 observation and the quality system failure that produced the nonconformity report are, in my experience, the same failure wearing two names. Build your CAPA process to find that single failure once, fix it once, and prove it stayed fixed once. Everything else is just formatting the same evidence for two different readers.

Frequently Asked Questions

Can one root cause investigation satisfy both an FDA CAPA and an ISO corrective action?

Yes, in most cases — and for devices, the two requirements aren't just similar anymore, they're the same text. FDA's Quality Management System Regulation (QMSR) amended 21 CFR Part 820, effective February 2, 2026, to incorporate ISO 13485:2016 by reference, so the CAPA requirement in 820.100 and the corrective action requirement in ISO 13485:2016 clause 8.5.2 are now one requirement for device manufacturers, not two parallel ones. On the drug side, 21 CFR 211.192 and ISO 9001:2015 clause 10.2.1 remain separate standards that still call for the same core sequence: identify the actual cause, correct it, and verify the correction worked. Either way, a single, sufficiently rigorous investigation record can be formatted into two separate closure documents for the two different audiences.

What happens if an ISO nonconformity is still open when FDA arrives for an inspection?

An open ISO nonconformity isn't automatically an FDA violation, but if the underlying issue overlaps with something an FDA investigator is examining, an unresolved nonconformity in your own records can undercut your credibility during the inspection. It's better to disclose it proactively as evidence your quality system is actively catching and working issues, rather than have the investigator discover it independently.

Do I need two separate CAPA systems, one for FDA and one for ISO?

No. Maintaining separate systems increases the risk of inconsistent root cause conclusions and makes it harder to demonstrate a coherent quality system during either an FDA inspection or an ISO audit. A single CAPA record tagged with the relevant regulatory or certification citations, closed with audience-specific documentation, is more defensible and less resource-intensive.

How long do I have to respond to an FDA 483 compared to an ISO nonconformity?

FDA's consistent practice, referenced repeatedly in published Warning Letters, treats 15 business days as the expected window for a written response to a Form 483. Certification bodies typically require closure of a major nonconformity within a window they set themselves, commonly around 90 days, under the general audit framework of ISO/IEC 17021-1:2015. Always confirm the exact deadline with your specific certification body, since it isn't fixed by the ISO standard itself.

Does having ISO 13485 certification protect a device manufacturer from receiving an FDA 483?

No, not automatically — but the two are no longer the fully separate tracks this question implies. FDA's Quality Management System Regulation (QMSR) amended 21 CFR Part 820, effective February 2, 2026, to incorporate ISO 13485:2016 by reference as the quality system requirement for device manufacturers, so conformance to ISO 13485:2016 is now the substance of Part 820 compliance for devices rather than a separate, analogous standard. What ISO certification still doesn't buy you is immunity from inspection: FDA assesses your system against the incorporated standard directly and can issue a 483 regardless of your certification status, and your certification body's findings don't bind FDA's. A well-run ISO 13485 system tends to reduce the frequency and severity of 483 observations because it's now, in substance, the same system FDA is inspecting against, but certification alone does not exempt a facility from inspection or from receiving observations.

If you're holding a 483 and an ISO nonconformity right now and trying to work out whether they're the same underlying problem, that's the exact question Certify Consulting helps clients answer — talk to us before you build two response projects instead of one.

Last updated: 2026-08-23

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.