From near-miss to CAPA: the handoff that decides safety maturity
The moment a near-miss becomes a corrective action is the single most important workflow in a safety program. We break down what the handoff looks like when it works, and what it costs when it does not.
QEHS Ethos Team
Founding team
The QEHS Ethos Team built the QEHS platform after a decade managing EHS programs in heavy industry. We write about safety culture, regulatory strategy, and how software can get out of the way.
12 min read
A near-miss that does not become a CAPA is a near-miss that does not exist. The report may be filed, but if no action is assigned, no owner is named, and no due date is set, the signal dies in a database.
The pattern we recommend: every near-miss with severity ≥ medium auto-spawns a CAPA record (pre-populated title, linked record, suggested owner based on location). A supervisor can close it out as no-action-required, but the decision is logged and counted. Over time, the ratio of open-CAPA-to-near-miss is itself a leading indicator.
The handoff is the seam where most near-miss programs leak. A near-miss is reported, the report sits in a queue, the queue is reviewed when someone has time, and by the time the review happens the scene has changed and the root cause is gone. The handoff that works moves the near-miss to a decision inside a defined window — the same shift, ideally, and no later than 48 hours — with the decision being one of three: a CAPA, a documented no-action with a reason, or an escalation. The decision, not the report, is the unit of work.
The severity grade is the input to the handoff, and the grade has to be simple enough to apply at the point of report. A three-level scale — low, medium, high — mapped to a default action is the one that holds: low to a logged no-action or a same-supervisor fix, medium to an auto-spawned CAPA with a 14-day SLA, high to an auto-spawned CAPA with a 48-hour SLA and a supervisor escalation. A five-level scale collapses to three in practice, and a scale without a default action per level is a taxonomy, not a workflow. The grade is the trigger; the trigger is what makes the handoff automatic.
- Open — the CAPA is created from the near-miss with the source linked, a suggested owner pulled from the location hierarchy, and a due date set from the SLA. The auto-spawn is the step that removes the manual hand-off.
- Assigned — the owner accepts or redirects the CAPA, and the root-cause analysis is scoped. A CAPA that is auto-spawned and never assigned is a CAPA that died at creation, and the unassigned rate is itself a leading indicator.
- In progress — the root cause is named, the corrective action is defined, and the action is underway. A CAPA that sits in progress past its due date escalates, automatically, to the next level.
- Closed — the action is implemented and the owner records the verification. Closure without verification is the failure mode that lets the same near-miss return.
- Verified — a second party confirms the action broke the cause chain. The verified-CAPA rate, not the closed-CAPA rate, is the maturity measure.
The no-action decision is the one that has to be defensible, because it is the one that looks like inaction. A near-miss closed as no-action has to carry a reason — the hazard was already controlled, the condition was a one-off, the report was a duplicate — and the reason has to be reviewable. A no-action rate that rises without a reason pattern is the signal that the handoff is filtering for ease rather than for risk, and the audit question is always whether the no-action decisions would hold under the scrutiny of an incident on the same hazard.
The ratio that matters is the open-CAPA-to-near-miss ratio, and it is a leading indicator that a board can read. A program where the ratio is rising is a program where reporting is outpacing closure — healthy if the closure rate is also rising, unhealthy if it is not. A program where the ratio is flat and low is a program where either the near-misses are not being reported or the CAPAs are being closed without cause, and the two are indistinguishable without the verified-CAPA rate. The two numbers together — the open-CAPA-to-near-miss ratio and the verified-CAPA rate — are the maturity dashboard for the handoff.
The link to root cause analysis is the one that separates a CAPA program from a ticketing system. A CAPA without an RCA is a corrective action against a symptom; a CAPA with an RCA that stopped at human error is a corrective action against a person. The discipline is to push the RCA to a system cause — the procedure that was unclear, the control that was absent, the design that allowed the error — and to define the corrective action against the system. The verified-CAPA rate is the measure of whether the RCA reached the system level, because a system-level action changes the condition and a person-level action waits for the next person to make the same error.
- Configure the near-miss form so a severity grade on submit drives the default action — low to no-action, medium to a 14-day CAPA, high to a 48-hour CAPA with an escalation.
- Auto-spawn the CAPA from the near-miss with the source linked, the owner suggested from the location hierarchy, and the due date set from the SLA.
- Enforce the lifecycle — a CAPA past due escalates automatically; a closure requires a root cause and a verification method; a verification requires a second party.
- Report the open-CAPA-to-near-miss ratio and the verified-CAPA rate on the management-review dashboard, not in a side report.
- Review the no-action decisions quarterly against the incident record — a no-action on a hazard that later produced an incident is the decision that has to be re-examined.
The handoff is the workflow that decides whether a near-miss program is a safety program or a data-entry program. The near-miss that becomes a CAPA, the CAPA that closes against a root cause, and the closure that a second party verifies are the three steps that turn a report into a control. For the related concepts, see the near-miss, CAPA, and root cause analysis glossary entries; for the upstream post, the leading indicators and TRIR piece, and for the downstream, the incident investigation best practices post.
The just-culture question is the one that decides whether the handoff produces reports or silence. A no-blame program that protects the honest error and a no-accountability program that excuses the reckless one look the same on the poster and behave differently on the floor. The distinction the program has to make — and make in writing — is between an honest error (a system cause, addressed at the system), a risky behavior (a person cause, addressed at the person, with coaching or consequence), and a reckless act (a deliberate violation, addressed with discipline). A near-miss program that treats every report as an honest error is a program that loses the reckless acts to the no-blame shield, and the loss is the one an incident investigation finds too late. The handoff that works grades the report by cause, not just by severity, and routes the reckless act out of the CAPA system and into the conduct system. The grading is the protection the honest reporter needs, because a program that punishes the report is a program that does not get the next one.
The trend review is the step that turns a CAPA program into a safety program. A CAPA that closes a cause is a single-event fix; a trend that closes a recurring cause is a system fix, and the system fix is the one that prevents the next event. The platform that tags every CAPA with a root-cause category and reports the categories over time is the platform that surfaces the recurring cause — the same three slips on the same staircase across three sites in a quarter is the signal that the staircase, not the slipper, is the hazard. The trend review is a standing input to the management review, and the trends that do not reach the review are the trends that do not get the system fix. The trend that closes is the trend that the platform flags automatically — a count of root-cause categories that crosses a threshold is the trigger for a systemic CAPA, and the systemic CAPA is the one that changes the condition for every site, not just the one that reported.