Audit CAPAs in Pharmacovigilance
Table of contents
- Introduction
- What a CAPA must accomplish
- Corrective versus preventive action
- Finding, root cause, action and evidence
- Root-cause analysis
- Choosing proportionate methods
- Avoiding shallow causes
- Designing the CAPA
- Ownership and due dates
- Containment and remediation
- Effectiveness checking
- What to measure
- What to do when CAPA fails
- Governance and inspection readiness
- QPPV visibility
- Vendors and partners
- Practical CAPA record
- References
- Regulatory Note
Introduction
A pharmacovigilance audit is useful only when its conclusions change the system. The audit report identifies a condition, the criterion provides the benchmark, and the evidence shows what happened. A corrective and preventive action (CAPA) record turns that finding into controlled change.
CAPA is not a second name for “make the document better”. The response should contain the problem, correct what is already wrong, address why it happened, and provide evidence that the control now works.
GVP Module IV supports a risk-based audit system. It does not prescribe one universal CAPA template, severity scale or effectiveness metric. Those details belong in the organisation’s procedure, provided the system is documented, proportionate, traceable and effective.
What a CAPA must accomplish
A strong CAPA answers six questions: what was found, why it matters, what was contained, why the control failed, what will change, and what evidence will show that the change is sustained.
Corrective versus preventive action
Corrective action addresses an observed non-conformity and its consequences: for example, correcting missed submissions or reviewing affected case records. Preventive action addresses conditions that could allow the same or a related failure elsewhere, such as an uncontrolled interface, unclear decision rights or an ineffective verification control.
One action can do both. The important issue is whether the package addresses the causal pathway.
Finding, root cause, action and evidence
| Field | Question |
|---|---|
| Finding | What condition was observed against which criterion? |
| Impact/risk | Why does it matter for patients, compliance or system control? |
| Root cause | Why did the control permit it? |
| Action | What changes, who owns it, and by when? |
| Effectiveness evidence | How will the organisation test that it works? |
A revised SOP alone is rarely sufficient. If the failure arose from a system configuration or data hand-off, changing the SOP may leave the causal pathway unchanged.
Root-cause analysis
Root-cause analysis should be proportionate to risk, complexity and recurrence potential. It is an investigation, not a request for the last person involved to explain why they made a mistake.
Choosing proportionate methods
For a contained documentation error, a focused review may be enough. For a missed regulatory submission involving several systems and vendors, the review may need process mapping, record sampling, interviews, timeline reconstruction and technical analysis.
Ask which control should have prevented or detected the failure, whether it was designed adequately, whether it was available and understood, whether it was executed as written, and whether the same weakness could occur elsewhere.
The “five whys” method can structure discussion, but it is not proof of one cause. Fishbone diagrams, barrier analysis and causal mapping are also tools; the method should fit the problem.
Avoiding shallow causes
“Human error”, “lack of training” and “oversight failure” are often descriptions of the final step. If training is a cause, explain why a trained person could not reliably perform the task: unclear instructions, insufficient practice, poor usability, competing priorities or absent verification.
A credible root-cause statement is testable: “The affiliate-to-global hand-off relied on an untracked mailbox and reconciliation did not show overdue items; ownership of late cases was therefore not visible.” That statement points to specific remediation and effectiveness evidence.
Designing the CAPA
Ownership and due dates
Every action needs one accountable owner, even when several functions contribute. Due dates should reflect patient and compliance risk, dependencies, validation and containment. A universal number of days is not a GVP requirement; if a date changes, retain the original commitment, rationale, approval and interim controls.
Containment and remediation
Containment reduces current exposure while permanent change is designed. It may include retrospective review, added quality control, temporary staffing or direct escalation.
Remediation corrects affected records or outputs. Define population, sampling or full-review rationale, decision rules, documentation and how newly identified issues will be handled.
“Improve oversight” is not testable. “Add a monthly overdue-case reconciliation owned by the case-management lead, with QPPV review of exceptions and documented sign-off” is testable, though its suitability still depends on risk and process design.
Effectiveness checking
An effectiveness check asks whether the action solved the problem and reduced recurrence risk. It is not the same as confirming that an SOP was approved or training was completed.
What to measure
Choose evidence that matches the failure mode:
- targeted samples of cases, submissions, reconciliations or signals;
- error-rate comparison before and after the change;
- audit-trail review showing the new workflow was followed;
- evidence that escalation occurred when triggered;
- observation or interviews confirming the control is usable;
- trend review across products, countries or vendors.
Define the population, sampling rationale, acceptance criteria, reviewer and timing where practical. A favourable aggregate KPI can hide a serious exception; review the exceptions, not only the average.
What to do when CAPA fails
An ineffective CAPA should remain visible. Re-open or extend it under the governing procedure, reassess the risk, apply additional containment and revisit the root-cause analysis. Repeated closure and reopening without learning is itself a governance signal.
Governance and inspection readiness
QPPV visibility
The QPPV need not own every CAPA, but should have appropriate visibility of significant PV findings, systemic risks, overdue remediation, repeat findings and actions affecting the PV system or benefit–risk evaluation.
PSMF and quality records should tell one story: what was identified, how it was assessed, what was done and how effectiveness was verified.
Vendors and partners
Outsourcing execution does not outsource the MAH’s oversight responsibility. The CAPA should identify contractual obligations, data interfaces, evidence required from the provider and how the MAH will verify completion. “The vendor was informed” is not evidence of remediation.
Practical CAPA record
An inspection-ready record can contain the finding, linked requirement, evidence, scope, impact assessment, containment, root-cause method, actions, owners, due dates, governance review, effectiveness protocol, result and closure approval.
The best CAPA records are concise because the reasoning is clear, not because important facts are omitted.
References
- EMA, GVP Module IV: Pharmacovigilance audits
- EMA, GVP Module II: Pharmacovigilance system master file
- EMA, GVP overview
- ICH Q9(R1), Quality Risk Management
Regulatory Note
EU legislation and GVP establish pharmacovigilance quality requirements, but they do not create one mandatory CAPA form, universal severity threshold or single effectiveness-check method. Apply approved procedures and the requirements of the relevant jurisdiction, product and procedure.