EVIDENCE LOOP / 01
One finding, several different control questions.
A usable supplier corrective action request, often shortened to SCAR, does not collapse containment, rework, cause analysis and recurrence prevention into one “resolved” status. It records what failed, which work is controlled now, why it happened and escaped, what changes, how implementation is proved and how the buyer will decide whether the action worked.
State the requirement and objective finding evidence
Identify the supplier legal entity and production site, product or SKU, purchase order, lot or process, controlling specification and revision, unmet requirement, observed result, date, location and source files. Preserve the supplier’s response as a separate field rather than editing the original finding.
The ISO 9001 Auditing Practices Group library includes public papers on documenting, reviewing and closing nonconformities and on effectiveness. The library states that its guidance is informative, context-dependent and not a specified requirement or universal industry benchmark.
A label such as “bad quality” is not reviewable. Record the requirement, the actual evidence and the exact gap between them.
Bound the affected and potentially affected work
Record affected quantities, serial or lot identifiers, production dates, inventory, work in process, goods in transit, shipped units, related products or processes and any evidence gap. Classify the buyer impact using the contract, product risk and destination requirements applicable to this order; do not copy a generic severity label without its decision consequence.
Keep confirmed affected work, potentially affected work and not-yet-assessed work distinct. The request should state which work is on hold, which may continue and who owns the extent review.
Anchor the finding to the approved quality-control baseline →
Require immediate containment, disposition and correction
Define how affected and suspect work is identified, segregated and prevented from unintended production or shipment. Record inventory checks, stop-work or hold scope, customer or logistics notifications, disposition authority, rework or replacement instructions, verification method, owner and due time.
Correction may repair, rework, replace or otherwise address detected nonconforming work. It does not by itself explain or remove the cause. The official ISO 9001 APG nonconformity review paper distinguishes correction from corrective action and describes objective evidence across correction, cause analysis, implementation and effectiveness before closure. It remains informative guidance, not a product-specific acceptance rule.
Test occurrence and escape causes with evidence
Ask both why the nonconformity occurred and why the existing controls did not detect or prevent it. Record considered factors, evidence for or against each factor, confirmed causes, contributing conditions, extent across similar products or processes, and unresolved uncertainty.
Do not accept “operator error,” “carelessness” or a completed diagram as cause evidence on its own. The APG paper cautions against stopping at the first failure factor and asks whether the cause is systemic or accidental. A 5 Whys, fishbone diagram or other tool can structure analysis, but the completed form is not proof that the selected cause is true.
Approve actions tied to each supported cause
For each confirmed cause, record the proposed change, owner, due date, affected documents, equipment, tooling, materials, software, training, process controls, inspection steps and related products or sites. Define how the action prevents recurrence or improves detection, plus what evidence will show that the plan was implemented.
The U.S. Department of Energy’s public Project Management Lexicon describes a corrective action plan as documenting assumptions, constraints, responsibility, commitment dates, the action plan, verification steps and completion documentation. This is useful field-level government guidance, not a sourcing contract or a requirement imposed on every supplier.
ISO 10007:2017 provides lifecycle configuration-management guidance. Use controlled revisions and status records when the approved action changes a material, component, drawing, method, tooling, process, site or critical sub-supplier.
Verify that the approved action was implemented as defined
Check the effective date or serial/lot boundary, approved document revisions, training or competence records, changed control settings, equipment or tooling evidence, updated inspection records and traceability to corrected or newly produced work. Record partial, late or differently implemented actions as exceptions rather than silently accepting them.
Where corrected product or a changed process needs inspection, define the exact population, method, sample, acceptance criteria and reviewer. A photo may show one visible state; it does not prove the whole affected scope, the underlying cause or sustained implementation.
Use in-process evidence for the next continue, correct, reinspect or hold decision →
Keep final-lot inspection and shipment release as a separate decision →
Define and run an effectiveness check
Before approving the action, define what evidence, population, period or number of lots will test recurrence and detection. State the metric or observation, acceptance threshold, data owner, review date, related complaints or findings to check and what triggers escalation or broader review.
Implementation asks whether the change was put in place. Effectiveness asks whether the action resolved the cause under the defined evidence window. If there has not yet been enough production, time or opportunity to test effectiveness, keep the request open in an effectiveness-pending state.
Record an authorised buyer close-or-reopen decision
The buyer’s authorised reviewer should record the finding version, containment and correction evidence, accepted cause analysis, implemented action revision, effectiveness evidence, remaining risk, open related issues, decision date and signature or accountable identity.
Close only the defined request and scope. Reopen or create a linked request when the same condition recurs, the action is not implemented as approved, effectiveness criteria fail, the affected extent expands or new evidence changes the cause analysis. Closing a SCAR does not automatically release shipment, final payment, contractual acceptance or destination-market compliance.
REQUEST RECORD / 02
Minimum fields for a reviewable corrective action request
| Control field | Supplier response must identify | Buyer review asks | Keep open when |
|---|---|---|---|
| Finding | Requirement, actual result, evidence, product/order/process and revision | Is the gap objective, traceable and understood without rewriting the original finding? | The requirement or evidence is ambiguous or disputed without a visible record |
| Affected extent | Confirmed, potential and unassessed quantities, locations, lots and related work | Does the scope cover inventory, work in process, transit and similar conditions where relevant? | Affected or suspect work cannot be bounded |
| Containment | Identification, segregation, stop/hold scope, notifications, owner and timing | Can uncontrolled work still move, mix, ship or reach a later stage? | Immediate exposure remains uncontrolled |
| Correction | Disposition, rework/replacement instruction, affected-unit identity and verification | Were corrected units checked against the defined requirement? | Corrected work is untraceable or unverified |
| Cause analysis | Occurrence and escape causes, considered factors, supporting evidence and extent | Does evidence support the cause beyond a label, tool or first failure factor? | The cause is assumed, incomplete or contradicted |
| Corrective action | Action per cause, owner, due date, changed controls and affected configurations | Does each action address recurrence or detection without creating an uncontrolled change? | Actions are generic, ownerless or disconnected from supported causes |
| Implementation | Effective boundary, approved revisions, records, training and verification results | Was the approved action implemented across the defined scope? | Evidence shows only an intention, sample or partial implementation |
| Effectiveness and closure | Evidence window, criteria, results, related recurrence review and accountable sign-off | Did the action work, and does the buyer own the close-or-reopen decision? | Effectiveness is untested, failed or awaiting enough evidence |
DECISION STATES / 03
Keep each request in one explicit state
| State | Minimum record | Permitted next action |
|---|---|---|
| Draft | Proposed finding, requirement, evidence and scope owner | Verify and issue the controlled request |
| Issued | Request ID/version, supplier, finding, due dates and buyer authority | Begin the required response and immediate controls |
| Containment open | Affected extent and immediate controls remain incomplete or unverified | Control exposure before relying on later analysis |
| Cause unsupported | Assumptions, missing evidence or contradictory factors are visible | Continue analysis; do not approve permanent action as cause-based |
| Action approved | Supported causes, approved actions, owners, dates and configuration impact | Implement only the approved plan and record exceptions |
| Implementation evidence due | Action is scheduled or claimed complete, but defined proof is outstanding | Collect and review implementation evidence |
| Effectiveness pending | Implementation accepted; evidence window or recurrence review remains open | Monitor the defined population, period or lots |
| Closed | All defined evidence, effectiveness result and authorised buyer decision recorded | Archive the request; maintain linked controls and separate release decisions |
| Reopened | Recurrence, failed criteria, expanded scope or changed cause evidence recorded | Re-control exposure and revise the linked analysis or action |
METHOD / 04
How this checklist was prepared
Currawong Web’s China-side verification desk reviewed the official and first-party sources below on 30 July 2026. The ISO APG library and paper support the distinctions among nonconformity, correction, corrective action, implementation and effectiveness; the DOE lexicon supports accountable action-plan fields; ISO 10007 supports controlled change records. Graco’s supplier page is used only as a real buyer-specific example of an 8D response workflow.
The eight-control workflow, request table and decision states are our evidence-control synthesis for global sourcing. We did not review any reader’s supplier, factory, product, process, lot, finding, contract, sampling plan or destination-market requirements. This is general evidence-organising guidance, not an imposed supplier requirement, investigation, inspection instruction, certification, legal advice, supplier approval, shipment release or quality guarantee.
PRIMARY SOURCES / 05
Official and first-party sources used for this guide
Links and page content were checked on 30 July 2026. Re-open the buyer’s contract, supplier manual, applicable standards and product or destination rules before a material decision because requirements and records can change.
- ISO 9001 Auditing Practices Group libraryOfficial ISO committee page linking nonconformity and effectiveness papers; the page explicitly limits the papers to informative, context-dependent guidance rather than specified requirements.
- ISO 9001 Auditing Practices Group — Review of nonconformityOfficial informative paper used for correction, corrective action, cause analysis, implementation, effectiveness and closure concepts; not treated as a product rule or universal buyer requirement.
- U.S. Department of Energy — Project Management LexiconOfficial public lexicon used for corrective-action-plan fields including responsibility, commitment dates, verification steps and completion documentation.
- Graco — Supplier Corrective Action RequestFirst-party supplier requirement showing one buyer’s 8D workflow, containment, cause verification and supplier-quality review. It is an operational example, not a universal sourcing standard.
- ISO 10007:2017Official ISO record for configuration-management guidance across a product or service lifecycle; ISO lists the edition as current and confirmed in 2023.
COMMON QUESTIONS / 06
Keep response format, evidence and authority separate
- Is a correction enough to close a SCAR?
- Not when the request also requires cause removal and recurrence prevention. Correction addresses the detected work; the buyer should separately review supported causes, corrective action, implementation and effectiveness.
- Must every supplier use an 8D report?
- No. 8D is one response format, not a universal requirement for every buyer. Use the contract or supplier manual that governs the order, while keeping the evidence and decision fields needed for the actual finding.
- Is “operator error” a root cause?
- It is an assertion to investigate. Ask what system, method, training, equipment, material, measurement, workload or detection conditions allowed the error and what evidence supports the proposed cause.
- Can photos close the request?
- Photos can support a bounded observation, correction or implementation record. They do not automatically prove affected extent, cause, sustained implementation or effectiveness across the defined evidence window.
- When should a closed request be reopened?
- Reopen or create a linked request when the condition recurs, the approved action was not implemented, effectiveness criteria fail, affected scope expands or new evidence changes the cause analysis.
- Does closing a SCAR release payment or shipment?
- No. A corrective-action closure and a production, inspection, shipment, payment, contractual-acceptance or destination-compliance decision have different scopes and authorities unless the governing records explicitly connect them.