Audit Findings and Classification in Pharmacovigilance
- Audit Findings and Classification in Pharmacovigilance
- Introduction
- What Is an Audit Finding?
- Purpose of Classification and Governance Interfaces
- Risk-Based Classification Framework
- Decision Criteria — Detailed Considerations
- Classification Definitions (Inspection‑oriented)
- Escalation Thresholds and Timelines (Inspection-ready)
- Immediate Actions and Containment
- Root Cause Analysis and CAPA Linkage
- Sample Finding Template (Inspection-ready)
- Sample CAPA Template (Inspection-ready)
- Audit Checklist to Support Findings and CAPAs (Inspection-Ready)
- Metrics, Reporting and Governance Oversight
- Inspection Relevance — What Inspectors Want to See
- Handling Repeat Findings — Governance and Inspector Expectations
- Examples of Common Findings Mapped to the Matrix (Illustrative)
- Recordkeeping and Traceability
- Characteristics of Mature Finding Management
- Key Takeaways
- References
Introduction
Audit findings are the primary outputs of pharmacovigilance (PV) audits. They provide documented evidence of:
- Process weaknesses
- Control failures
- Compliance concerns
- Governance gaps
- Improvement opportunities
Identification of findings is necessary but insufficient. Organisations must also determine significance, risk, escalation requirements and remediation priorities. Classification provides that structure and ensures consistent prioritisation, appropriate management visibility and traceable remediation. This article sets out an inspection-ready approach: a severity decision matrix, explicit escalation thresholds and timelines, sample finding and CAPA templates and an audit checklist that supports implementation and inspection evidence.
Regulatory context (for reference): EMA Good Pharmacovigilance Practices (GVP) Modules I, III and IV, ICH Q9 (Quality Risk Management) and national pharmacovigilance legislation require systems of quality assurance and effective corrective and preventive actions. Inspectors routinely review the whole lifecycle from finding identification through CAPA implementation and effectiveness verification.
What Is an Audit Finding?
An audit finding is a documented observation supported by objective evidence that indicates:
- A requirement has not been met
- A control is ineffective
- A process is not functioning as intended
- A risk requires attention
Findings must be objective, evidence-based, reproducible and clearly documented. Opinions without evidence are not findings for regulatory or inspection purposes.
Purpose of Classification and Governance Interfaces
Classification translates observations into risk-based actions and governance escalation. It determines urgency, management visibility, CAPA priority, resource allocation and follow-up activities. Classification should reflect risk rather than auditor preference and be supported by governance: roles, decision authorities, reporting lines and escalation paths must be defined and demonstrable.
Typical governance interfaces:
- Audit Team (identifies finding)
- Quality Assurance (QA) / Audit Owner (validates classification)
- Pharmacovigilance Lead / QPPV (clinical/regulatory impact review)
- Head of Compliance / Legal (regulatory and corporate risk assessment)
- Senior Management / Executive Committee (for critical findings)
- PV Steering or Compliance Committee (periodic oversight and risk acceptance)
Documented responsibilities, delegation of authority and records of decisions are inspection focal points.
Risk-Based Classification Framework
Classification should be based on a documented decision framework that considers multiple dimensions. The matrix below operationalises common frameworks into a scorecard suitable for inspection evidence.
Severity decision matrix (score-based)
- Score each dimension 0–3 where:
- 0 = No impact / Not applicable
- 1 = Low impact
- 2 = Moderate impact
- 3 = High impact
Dimensions: - Patient Safety Impact (PSI) - Regulatory Impact (RI) - Data Integrity Impact (DII) - Systemic Impact (SI) - Detectability (Detect; inverted: high score = low detectability = greater concern)
Numeric scoring example (sum total 0–15). Classification thresholds (example, organisational policy should record exact thresholds):
- Critical: total score 12–15
- Major: total score 7–11
- Minor: total score 3–6
- Observation: total score 0–2
Example: A failure to submit a serious adverse event (PSI=3, RI=3, DII=2, SI=2, Detect=2) → total 12 → Critical.
This quantitative approach provides auditable rationale. For inspection readiness, retain the completed scorecard with each finding documented in the finding register.
Decision Criteria — Detailed Considerations
- Patient Safety Impact: Could the issue lead to direct patient harm, increased severity of adverse events, or missed signals?
- Regulatory Impact: Could the deficiency result in regulatory non‑compliance, market action, recall or inspection concern?
- Data Integrity Impact: Could data be altered, lost or rendered unreliable for safety decision-making?
- Systemic Impact: Is the issue isolated to a person or site, or is it pervasive across systems, vendors or processes?
- Detectability: Would routine monitoring or normal operations detect the failure, or could it persist unnoticed?
Document the rationale for each dimension. Inspectors commonly request evidence of the scoring logic and the governance endorsement of classification.
Classification Definitions (Inspection‑oriented)
- Critical: Findings that present an immediate significant risk to patient safety, result in regulatory non‑compliance with likely immediate consequences, or show a profound control failure (e.g., systemic failure to report serious adverse reactions, missing PV system entirely). Critical findings require immediate escalation and high‑level oversight.
- Major: Findings that present significant risk but do not meet the threshold for critical. These require timely remediation, management involvement and robust CAPAs (e.g., repeated delayed reporting, inadequate vendor oversight).
- Minor: Findings that indicate localized or low-risk deficiencies (e.g., single documentation lapse) but require correction and monitoring to prevent escalation.
- Observation: Low-risk opportunities for improvement, process optimisation or early‑stage risks; tracked but not subject to the same escalation rigour.
Regulatory context: Inspectors assess whether the classification corresponds to impact and whether corresponding governance and CAPA actions were commensurate.
Escalation Thresholds and Timelines (Inspection-ready)
The following escalation thresholds are presented as an inspection-ready template. Organisations must adopt formal timelines in SOPs and make them available during inspections. These thresholds reflect typical expectations used in PV and QA practice and align with the need for timely management action required under GVP and ICH Q9 principles.
Critical findings (example thresholds) - Immediate notification (documented) to QPPV, Head of PV and Head of QA within 4 hours of discovery (or by the next business hour if discovered out-of-hours) — record method and recipients. - Formal management notification (email + logged entry in finding register) within 24 hours. - Preliminary containment actions initiated within 24 hours; documented immediate actions recorded in the finding file. - Formal CAPA plan (initial action plan) submitted within 3 business days. Plan must include interim containment, root cause analysis start date, owner and target dates. - Implementation of high-priority corrective actions within 15 calendar days (or shorter if patient safety demands); full remediation timeline to be defined in the CAPA with justification. - Effectiveness check(s) initiated within 30 calendar days and completed as defined by the CAPA (e.g., after sustained operation for a defined period, typically 30–90 days depending on the control). - Senior management briefing and escalation to Executive Committee within the next scheduled meeting and ad hoc if required.
Major findings (example thresholds) - Notification to QPPV and Head of QA within 48 hours. - CAPA plan submitted within 10 business days with owner, resource estimates and milestones. - High priority corrective actions implemented within 30 calendar days where feasible; other actions implemented within 30–90 days depending on complexity. - Effectiveness verification completed within 90 calendar days or as defined in the plan. - Report to PV Steering/Compliance Committee at next meeting.
Minor findings (example thresholds) - Notification to audit owner and local management within 5 business days. - CAPA plan submitted within 30 calendar days. - Implementation within 90 calendar days. - Effectiveness verification within 6 months.
Observations (example thresholds) - Logged in the observation tracker. - Reviewed in quarterly audit or quality committee meetings. - Actioned as continuous improvement; timelines discretionary.
Documentation for inspectors: show timestamped notifications, meeting minutes, CAPA plan submissions, evidence of execution, and effectiveness checks in a single accessible dossier.
Note: These example timelines are widely used as inspection-ready references. Organisations must define and justify their own timelines in quality documentation and ensure consistent application.
Immediate Actions and Containment
For findings with patient safety or regulatory impact, documented immediate actions (containment) must be recorded separately from longer-term CAPAs. Containment examples include temporary process changes, retrospective data reviews, systems lockdowns or communications with external partners. Containment actions should have owners, start dates, end dates and supporting evidence.
Inspectors expect to see distinction between interim containment (short-term relief) and permanent corrective actions; both should be traceable in the finding file.
Root Cause Analysis and CAPA Linkage
Findings document the "what". Root cause analysis explains the "why". For inspection readiness, the following are expected:
- A documented root cause methodology (e.g., 5 Whys, Fishbone, Fault Tree) applied and recorded.
- Linkage between root cause(s) and each CAPA action (each action addresses a specific root cause).
- Risk assessment of residual risk after CAPA.
- Evidence that planned CAPAs are feasible (resource allocation, timelines, approvals).
Regulators assess whether CAPAs are adequate and proportionate to root causes and overall risk.
Sample Finding Template (Inspection-ready)
Include the completed template as supporting evidence to auditors and inspectors. Save a copy in the central finding register and in the audit file.
Finding ID: F-YYYY-XXX Audit ID / Report ref: Date discovered: Auditor: Audit area / site / vendor: Reported to (name, role, date/time, method):
- Requirement (normative reference, SOP, regulation):
- Condition (concise, evidence referenced: document IDs, screenshots, extract dates):
- Evidence (list attachments with filenames and custody information, e.g., PDF, system export):
- Risk description (patient safety, regulatory, data integrity, business continuity):
- Severity scoring (PSI / RI / DII / SI / Detect) with numeric scores and total:
- Classification (Critical / Major / Minor / Observation) — include classification rationale tied to scoring:
- Is issue systemic? (Yes / No) — if yes, provide scope statement (sites, products, systems affected):
- Immediate containment actions (who, action, start date, evidence):
- Root cause analysis (method used, date completed, summary):
- Proposed CAPA actions (reference to CAPA IDs if assigned):
- Responsible owner(s) for CAPA:
- Escalation level (e.g., QPPV, Head of PV, Executive):
- Reporting to external stakeholders required? (Regulators, partners — list):
- Planned dates (CAPA plan submission, implementation, effectiveness check):
- Current status (Open / In progress / On hold / Closed):
- Closure evidence (documents, approvals, verification outcomes):
- Notes / Audit trail (version history of the finding document):
For inspection readiness, include the electronic audit trail that shows who edited the finding entry and when.
Sample CAPA Template (Inspection-ready)
CAPA ID: CAPA-YYYY-XXXX Linked Finding(s): F-YYYY-XXX Date opened: Owner: Sponsor (senior manager): Priority (Critical/Major/Minor): Root cause(s) addressed:
Corrective actions (for immediate past nonconformance) - Action ID: - Description: - Rationale: (how the action addresses root cause) - Owner: - Start date: - Target completion date: - Dependencies / resources required: - Implementation evidence (list items that will demonstrate completion)
Preventive actions (to prevent recurrence) - Action ID: - Description: - Owner: - Start date: - Target completion date: - Evidence required:
Success criteria (measurable) - What will demonstrate effectiveness? (metrics, sample size, pass/fail) - Pre-defined acceptance criteria
Effectiveness verification plan - Method (e.g., re-audit, targeted sample review, monitoring signal) - Timing (e.g., 30, 60, 90 days post-implementation or after sustained period as justified) - Sample size / scope - Owner of verification - Documentation required
Residual risk assessment - Pre-CAPA risk score: - Post-CAPA estimated risk score: - Risk acceptance (who and when)
Closure approvals - QA sign-off (name, role, date) - PV/QPPV sign-off (name, role, date) - Executive sign-off (for critical CAPAs) (name, role, date)
Change control / training actions - Change request IDs (if SOPs or systems are revised) - Training plan (groups, materials, completion evidence)
Audit trail - Record of updates, reassignments, delays, and rationale for extensions
For inspections, provide the full CAPA file including evidence of implementation and effectiveness checks. The CAPA file should be organised and indexed.
Audit Checklist to Support Findings and CAPAs (Inspection-Ready)
Use this checklist during post-audit processing, CAPA creation and pre-inspection dossier assembly. Track each item as completed and include evidence links.
Audit finding and classification checklist - [ ] Finding documented using the standard finding template (all fields complete) - [ ] Objective evidence attached and referenced (with custody chain) - [ ] Severity decision matrix completed with numeric scoring - [ ] Classification rationale documented and approved by QA - [ ] Risk assessment attached (residual risk if CAPA implemented) - [ ] Immediate containment actions documented (if applicable) - [ ] Root cause analysis performed and documented; method stated - [ ] CAPA(s) created with owner, timelines and measurable success criteria - [ ] Escalation notifications logged with timestamps (who, when, method) - [ ] CAPA approval route documented (QA, PV, Executive if required) - [ ] Change control initiated for procedural/system changes (if applicable) - [ ] Training plan defined and evidence of completion required - [ ] Effectiveness verification plan included with dates, scope and owner - [ ] Evidence of implementation uploaded (screenshots, training records, approvals) - [ ] Effectiveness verification performed and documented (results and follow-up) - [ ] CAPA closed with signatures and date, with final risk assessment - [ ] Finding cross-referenced in management reporting and KPIs - [ ] Documents and records retained according to retention policy and retrievable for inspection
Pre-inspection dossier checklist (for selected findings) - [ ] Full audit report and executive summary - [ ] Finding register extract showing current status - [ ] All finding templates and completed severity decision matrices - [ ] Full CAPA files with implementation and effectiveness evidence - [ ] Meeting minutes demonstrating governance escalation and decisions - [ ] Email/communication logs for regulatory notifications if any - [ ] Trend analyses and metrics demonstrating systemic action - [ ] Traceability matrix linking findings → CAPAs → evidence
This checklist should be version-controlled and referenced in the audit report or dossier provided to inspectors.
Metrics, Reporting and Governance Oversight
Inspection bodies evaluate not only individual findings but also the governance system that oversees finding management. Organisations should demonstrate:
- A finding register with auditable metadata (ID, status, owner, dates, linked CAPAs)
- Regular reporting to PV governance bodies (monthly dashboards; executive summaries)
- KPIs that drive oversight: number of critical/major findings, ageing of open CAPAs, repeat findings, closure timeliness and effectiveness success rates
- Evidence of escalation decisions and rationale in committee minutes
- Resource allocation to CAPAs (budget, personnel)
- Trend analysis and preventive action programmes driven by audit outputs
Governance should also include periodic independent assessment of CAPA effectiveness (e.g., QA verification, re‑audit, external review).
Inspection Relevance — What Inspectors Want to See
Inspectors typically request: - The audit report and related finding files - The finding register and severity scorecards - CAPA plans, implementation evidence and effectiveness verification - Evidence of management escalation and decision-making - Root cause analysis documentation - Communications with regulators or partners relating to the finding - Evidence of systemic review and preventive measures for repeat issues
Inspectors evaluate: - Appropriateness of classification relative to impact - Timeliness of escalation and corrective actions - Robustness of root cause analysis - Linkage between findings and CAPAs (traceability) - Evidence that CAPAs achieved the intended risk reduction - Repeat findings and organisational learning mechanisms
To be inspection-ready, maintain a single accessible dossier per finding that includes the templates above together with the audit checklist items completed.
Handling Repeat Findings — Governance and Inspector Expectations
Repeat findings signal CAPA ineffectiveness or governance failure. Regulators expect to see: - Evidence that prior CAPAs were reviewed for adequacy at the time of recurrence - Updated root cause analysis that explains recurrence - Strengthened CAPAs or escalated governance interventions (e.g., executive oversight, external review) - Demonstrable institutional learning (policy changes, training, process redesign)
Document decisions to escalate repeat issues to higher governance levels and preserve minutes proving managerial involvement.
Examples of Common Findings Mapped to the Matrix (Illustrative)
- Failure to submit serious adverse reaction reports to the competent authority in the required timeframe:
- PSI: 3, RI: 3, DII: 1, SI: 2, Detect: 3 → total 12 → Critical
-
Escalation: immediate QPPV notification; regulatory communication planned.
-
Single instance of missing consent form in safety database (data entry error, isolated):
- PSI: 1, RI: 1, DII: 1, SI: 0, Detect: 1 → total 4 → Minor
-
Escalation: local management action, CAPA in routine timeframe.
-
Vendor PV oversight gaps found across multiple sites (audit program not executed):
- PSI: 2, RI: 3, DII: 2, SI: 3, Detect: 2 → total 12 → Critical
- Escalation: QPPV and Procurement, contract review, immediate vendor remediation plan.
For each example, include evidence of the scorecard, notification timestamps and CAPA file.
Recordkeeping and Traceability
For regulatory inspections, records must be: - Complete and retrievable - Time-stamped and version controlled - Sufficient to demonstrate chain of custody and decisions - Indexed by finding ID, CAPA ID and audit ID for cross-reference
An electronic finding/CAPA management system with audit trail is preferred. Where manual systems are used, ensure a documented change control and retention policy.
Characteristics of Mature Finding Management
High-performing organisations demonstrate: - Consistent, documented classification applying the decision matrix - Timely, evidence-based escalation and documented containment where required - Root cause analysis that informs proportionate CAPAs - Measurable success criteria and documented effectiveness verification - Governance that provides appropriate oversight and decision records - Use of findings for continuous improvement and systemic risk reduction
Inspectors expect evidence of both process and outcome — not just closed CAPAs but proof that risk was reduced.
Key Takeaways
- Use a documented severity decision matrix and retain completed scorecards with each finding to show objective classification.
- Define and record explicit escalation thresholds and timelines in SOPs and demonstrate compliance with timestamps and communications.
- Separate immediate containment from longer-term CAPAs and document both.
- Use structured, inspection-ready finding and CAPA templates that include root cause analysis, measurable success criteria and effectiveness verification plans.
- Maintain an audit checklist to ensure completeness of each finding dossier and to assemble inspection-ready evidence.
- Governance must be demonstrable: roles, committee minutes, approvals and resource allocation should be auditable.
- Inspectors review not only single findings but the system that manages findings; consistent documentation, traceability and evidence of organisational learning are essential.
References
- EMA Good Pharmacovigilance Practices (GVP) Module IV – Pharmacovigilance Audits.
- EMA Good Pharmacovigilance Practices (GVP) Module I – Pharmacovigilance Systems and Their Quality Systems.
- EMA Good Pharmacovigilance Practices (GVP) Module III – Pharmacovigilance Inspections.
- Regulation (EC) No 726/2004.
- Directive 2001/83/EC.
- Commission Implementing Regulation (EU) No 520/2012.
- ICH Q9 Quality Risk Management.
- ICH E2E Pharmacovigilance Planning.