What it is for
8D — eight disciplines — is a structured method for responding to a defect whose cause is not yet known. It came out of the automotive industry and is most closely associated with Ford, and it remains the default vehicle for supplier corrective action across manufacturing: when a customer rejects a shipment, an 8D is usually what they ask for.
What distinguishes it from generic root cause analysis is that it is built around a customer who is currently exposed. That produces two features other frameworks lack: a formal containment step that happens before anyone understands the problem, and a requirement to explain not only why the defect occurred but why it escaped detection. Both exist because the customer cannot wait for the investigation to finish.
The count is now nine steps despite the name. A planning discipline, D0, was added ahead of the original eight after enough teams launched full investigations into problems that did not warrant them.
| Method | Built around | Best when |
|---|---|---|
| 8D | A customer-facing corrective action with containment and formal closure | A defect has escaped and someone external is waiting |
| A3 | One page and a coaching dialogue | Developing people's problem-solving alongside solving the problem |
| DMAIC | A statistical improvement cycle | Reducing variation in a process that is running, not responding to an escape |
| PDCA | An iterative improvement loop | Continuous improvement where the cycle repeats indefinitely |
| CAPA | A regulated corrective and preventive action record | Regulated industries where the audit trail is the requirement |
They are not rivals. An 8D's D4 might well use DMAIC's analytical tooling, and a CAPA record in a regulated plant is frequently an 8D wearing the required paperwork.
D0
Define
Prepare and respond
D0 was added to the original eight because teams kept starting the process before deciding whether they should. It does two things. First, if a customer is currently receiving defective product or anyone is at risk, an emergency response action goes in immediately — that is not containment in the D3 sense, it is stopping the bleeding.
Second, it screens. 8D is expensive: a cross-functional team, weeks of elapsed time, and a document trail. It earns that cost when the cause is genuinely unknown, the problem recurs, or the consequences are serious. When someone already knows what broke and how to fix it, running an 8D produces a well-documented account of something you could have corrected on Tuesday.
The symptom needs a number even at this stage. “Customer complaints about fit” is not a symptom; “eleven units rejected at incoming inspection across three shipments, all on the same bore diameter” is.
D1
Define
Form the team
The composition failure is predictable and expensive: a team of engineers and quality staff with nobody from the line. Process knowledge sits with the people who run the process, and they usually know within a day which of the plausible causes is real. Teams without them spend three weeks rediscovering it.
Three roles need naming rather than assuming. The champion is senior enough to release resources and remove obstacles, and is not the team leader. The leader runs the process and owns the document. The subject matter experts are there for specific disciplines and need not attend everything.
Keep it small. Four to eight people is the working range; past that the meetings become briefings and the analysis stops happening in the room.
D2
Define
Describe the problem
More 8Ds fail here than at root cause analysis, and the failures at D4 are usually consequences of a weak D2. A vague problem statement lets the team investigate everything, which means investigating nothing.
Split the statement into the object (what thing has the problem) and the defect (what is wrong with it), then quantify: how many, how often, since when, on which lines, which shifts, which lots. The point of the numbers is not rigour for its own sake — it is that patterns in the numbers eliminate candidate causes before anyone tests anything.
D2 worksheet
Is / is-not
Fill both columns. Every boundary in the right-hand column is a constraint a real root cause has to satisfy.
| Is | Is not | |
|---|---|---|
| What | ||
| Where | ||
| When | ||
| How big | ||
| Who / which |
Type directly into the cells. Nothing is saved — copy it out before you close the tab.
The is-not column is the half people skip, and it does most of the work. Every boundary you can draw — present on line two but not line three, on the night shift but not the day shift, since April but not before — is a constraint that a real root cause must satisfy. A theory that cannot explain why the problem is absent where it is absent is not yet a theory.
D3
Contain & analyse
Contain it
Interim containment protects the customer while you work out what is actually wrong. It is a filter, not a fix, and treating it as one is the single most common way an 8D goes wrong.
Two things make containment real. It has to cover every location — work in progress, finished stock, product on a truck, product on the customer's shelf, product already installed. A containment that catches everything on the line and nothing in the warehouse is a containment that will be discovered by the customer.
And its effectiveness has to be measured. If you have added a hundred-percent inspection step, sample the output of that step: what percentage of defects is it actually catching? Inspection is a famously leaky control, and a containment assumed to be perfect is a second undetected failure sitting on top of the first.
Containment is also expensive and visible, which is useful. The cost of sorting, inspecting and expediting is the clock pressure that keeps D4 moving. Teams that let containment become comfortable stop finishing 8Ds.
D4
Contain & analyse
Find the root cause
This is the discipline the whole framework exists for, and it asks for something stronger than most root cause work delivers. A cause is not established because it is plausible, or because everyone in the room nodded. It is established when you can demonstrate control over the effect — introduce the suspected cause and the defect appears; remove it and the defect goes away.
8D also insists on a second question that most root cause methods omit. Something caused the defect, and something separately failed to catch it.
Occurrence
Why did the defect happen?
The process condition that produced it. Fixing this stops it being made.
Escape
Why did it reach the customer?
The control that should have caught it and did not. Fixing this stops it getting out.
Systemic
Why did our system allow both?
Optional in some variants, and the one that prevents the next problem rather than this one.
Splitting these matters because they usually have different owners and different fixes. A tooling wear problem and an inspection gauge that was never capable of detecting it are two corrective actions, and closing only the first guarantees you learn about the next occurrence from your customer again.
Tools, and their limits
- Five whys — cheap, fast, and prone to stopping at whichever answer the most senior person in the room finds satisfying. Useful for a first pass, weak as evidence on its own.
- Fishbone (Ishikawa) — good for generating candidate causes across categories so nothing whole is overlooked. It generates hypotheses; it does not test them.
- Is / is-not — carried forward from D2, and the most under-used. Eliminating causes that cannot explain the boundaries is faster than confirming the one that can.
- Designed experiment or comparative analysis — what actually closes D4. Good parts against bad parts, held condition against changed condition.
A useful discipline: before accepting a cause, write down what you would expect to observe if it were true and what you would expect if it were false. If both look the same, you have a story rather than a cause.
D5
Correct
Choose the corrective action
D5 selects and proves; D6 implements. Keeping them separate is deliberate, because the temptation once a cause is found is to change the process on Monday and find out afterwards.
Verification here means demonstrating, off-line or on a controlled trial, that the chosen action removes the defect. It also means asking what else the change touches — a tighter tolerance that solves your defect and creates a scrap problem upstream is not a corrective action, it is a transfer.
Where several options exist, choose against explicit criteria rather than by preference: effectiveness, cost, time to implement, and where the action sits on the hierarchy of controls. An action that eliminates the possibility of the defect beats one that detects it, which beats one that asks people to be careful. Corrective actions consisting of retraining and reminders are the weakest form and the most frequently chosen, because they are cheap and require nobody to change anything.
D6
Correct
Implement and validate
Validation is not verification repeated. Verification proved the fix works under controlled conditions; validation proves it works in the real process, at volume, across shifts and operators and material lots, for long enough that a quiet period is not mistaken for a solution.
The step everyone forgets is removing containment. A hundred-percent inspection put in place at D3 and never withdrawn is a permanent cost, and worse, it masks whether the corrective action worked — you cannot tell whether the defect stopped occurring or is simply still being caught. Removing containment is part of the validation, not housekeeping afterwards.
Update the things that carry the change forward at the same time: control plan, work instructions, inspection criteria, and whatever the operator actually reads. A corrective action that lives only in the 8D document reverts at the next personnel change.
D7
Prevent
Prevent recurrence
D7 is where 8D stops being problem-solving and becomes organisational learning, and it is the discipline most often reduced to a sentence. The question it asks is not “how do we stop this defect” — D5 and D6 did that — but “what in our system allowed this to be possible, and where else is that true?”
Two distinct activities:
- Systemic change. Update the FMEA so the failure mode is now rated for what you actually observed. Change the control plan, the design standard, the supplier requirement, the checklist. If the failure was possible because a standard permitted it, the standard is the corrective action.
- Read-across. Apply the finding to every similar part, process, line and plant. This is the highest-value step in the entire framework and the one most reliably skipped, because by D7 the team is tired and the customer is satisfied. An organisation that reads across turns one expensive failure into many prevented ones; one that does not will run a nearly identical 8D on a neighbouring line within the year.
D8
Prevent
Close and recognise
Recognition reads as a soft addition to a technical process, and it is there for a practical reason: 8D work is unglamorous, sits on top of people's existing jobs, and is conducted under customer pressure. Teams that are never thanked staff the next one reluctantly.
The more consequential half of D8 is the archive. A closed 8D is an asset only if it is findable — indexed by failure mode and part family rather than by date and customer complaint number. Most organisations have solved their current problem before, in a document nobody can locate.
Closure with the customer is a separate act from closure internally, and worth confirming explicitly. Supplier quality organisations track open 8Ds, and a technically finished investigation that was never formally closed goes on generating escalations.
Where 8Ds go wrong
The failures are not exotic and they cluster in the same four places every time.
- Containment that becomes permanentThe sort or the added inspection stays in place for years. It carries a real cost, and worse, it hides whether the corrective action worked at all — you cannot tell whether the defect stopped occurring or is simply still being caught.
- Root cause by consensusThe team agrees on the most plausible explanation and moves on. Plausibility is not evidence. If you cannot make the defect appear and disappear by manipulating the suspected cause, you have a hypothesis.
- No escape pointThe occurrence cause is found and fixed; nobody asks why the control system missed it. The next different defect escapes through exactly the same gap.
- Corrective actions made of trainingRetraining and reminders sit at the bottom of the hierarchy of controls, cost nothing, require nobody to change anything, and are the most commonly chosen action. They almost never hold.
- D7 written in one lineThe customer is satisfied, the team is tired, and read-across — the highest-value step in the framework — gets a sentence. The identical problem then appears on a neighbouring line within the year.
- The document as the deliverableThe form gets completed to the required standard and nothing in the plant changes. This is the failure that makes engineers cynical about the method, and it is a failure of the organisation rather than of the framework.
A useful audit question for any closed 8D: what would we have to do differently to make this defect happen again on purpose? If nobody can answer, the root cause was never established.
Running one that works
- Spend the time at D2. A precise problem description eliminates more candidate causes than a week of investigation. Most D4 failures are D2 failures arriving late.
- Put a line operator on the team. Not as a courtesy — as the person most likely to know which of the plausible causes is real.
- Keep the containment cost visible. It is the clock. Teams that stop feeling it stop finishing.
- Write both causes down separately. Occurrence and escape, in two boxes, with two owners. Merging them is how the escape point disappears.
- Verify before, validate after, and remove containment. Removing it is part of validation, not a tidying task afterwards.
- Schedule the read-across. Give D7 a date and an owner outside the immediate team, because the immediate team's motivation ends when the customer closes.
- File it by failure mode. An archive indexed by complaint number is an archive nobody searches.
The framework itself is unremarkable — define, contain, analyse, correct, prevent, in a fixed order with gates. What makes it work in one plant and not another is whether the gates are real: whether anyone is actually willing to say that D4 is not finished, while the customer is waiting and the containment cost is running.
Common questions
What does 8D stand for?
Eight Disciplines. It is a structured problem-solving method that came out of the automotive industry and is most closely associated with Ford, now used widely in manufacturing quality and supplier corrective action. Modern versions run D0 through D8, since a planning step was added ahead of the original eight.
When should you not use 8D?
When the cause is already known and the fix is understood, when the problem is a one-off with trivial consequences, or when what you actually have is a project rather than a defect. 8D costs a cross-functional team and weeks of elapsed time; it earns that when the cause is genuinely unknown, the problem recurs, or the consequences are serious.
What is the difference between containment and corrective action?
Containment is a temporary filter that protects the customer while the cause is still unknown, typically sorting or added inspection. Corrective action removes the cause so the defect is no longer produced. Containment is applied at D3, before anyone knows what is wrong; corrective action comes at D5 and D6, and part of D6 is removing the containment.
Why does 8D ask for two root causes?
Because two separate things went wrong. Something in the process caused the defect, and something in the control system failed to detect it before it reached the customer. These usually have different owners and different fixes, and closing only the occurrence cause leaves the detection gap in place for the next failure.
What is the difference between verification and validation?
Verification happens before implementation and shows, under controlled conditions, that the chosen corrective action removes the defect without creating another problem. Validation happens after implementation and shows the action works in the real process at volume, across shifts, operators and material lots, over enough time that a quiet period is not mistaken for a solution.
How long should an 8D take?
Customers commonly require initial containment within about 24 hours and a first full submission within roughly ten working days, though the specific requirements vary by customer and industry. The deadline pressure sits on D3 and D4; D7, which has no external deadline attached, is consequently the discipline most often left thin.
How does 8D compare with A3 or DMAIC?
They overlap heavily and differ in emphasis. 8D is built around a customer-facing corrective action with formal containment and closure, which is why it dominates supplier quality. A3 is a lean problem-solving format organised around one page and a coaching dialogue. DMAIC is the Six Sigma cycle, heavier on statistical analysis and better suited to reducing variation than to responding to a specific escape.