Audit Findings and Classification in Pharmacovigilance

A practical guide to audit findings, finding classification, risk assessment, escalation and inspection readiness.

Audio Lesson 10 min

Audit Findings and Classification in Pharmacovigilance

Introduction

Audit findings are the primary outputs of pharmacovigilance (PV) audits. They provide documented evidence of:

Identification of findings is necessary but insufficient. Organisations must also determine significance, risk, escalation requirements and remediation priorities. Classification provides that structure and ensures consistent prioritisation, appropriate management visibility and traceable remediation. This article sets out an inspection-ready approach: a severity decision matrix, explicit escalation thresholds and timelines, sample finding and CAPA templates and an audit checklist that supports implementation and inspection evidence.

Regulatory context (for reference): EMA Good Pharmacovigilance Practices (GVP) Modules I, III and IV, ICH Q9 (Quality Risk Management) and national pharmacovigilance legislation require systems of quality assurance and effective corrective and preventive actions. Inspectors routinely review the whole lifecycle from finding identification through CAPA implementation and effectiveness verification.

What Is an Audit Finding?

An audit finding is a documented observation supported by objective evidence that indicates:

Findings must be objective, evidence-based, reproducible and clearly documented. Opinions without evidence are not findings for regulatory or inspection purposes.

Purpose of Classification and Governance Interfaces

Classification translates observations into risk-based actions and governance escalation. It determines urgency, management visibility, CAPA priority, resource allocation and follow-up activities. Classification should reflect risk rather than auditor preference and be supported by governance: roles, decision authorities, reporting lines and escalation paths must be defined and demonstrable.

Typical governance interfaces:

Documented responsibilities, delegation of authority and records of decisions are inspection focal points.

Risk-Based Classification Framework

Classification should be based on a documented decision framework that considers multiple dimensions. The matrix below operationalises common frameworks into a scorecard suitable for inspection evidence.

Severity decision matrix (score-based)

Dimensions: - Patient Safety Impact (PSI) - Regulatory Impact (RI) - Data Integrity Impact (DII) - Systemic Impact (SI) - Detectability (Detect; inverted: high score = low detectability = greater concern)

Numeric scoring example (sum total 0–15). Classification thresholds (example, organisational policy should record exact thresholds):

Example: A failure to submit a serious adverse event (PSI=3, RI=3, DII=2, SI=2, Detect=2) → total 12 → Critical.

This quantitative approach provides auditable rationale. For inspection readiness, retain the completed scorecard with each finding documented in the finding register.

Decision Criteria — Detailed Considerations

Document the rationale for each dimension. Inspectors commonly request evidence of the scoring logic and the governance endorsement of classification.

Classification Definitions (Inspection‑oriented)

Regulatory context: Inspectors assess whether the classification corresponds to impact and whether corresponding governance and CAPA actions were commensurate.

Escalation Thresholds and Timelines (Inspection-ready)

The following escalation thresholds are presented as an inspection-ready template. Organisations must adopt formal timelines in SOPs and make them available during inspections. These thresholds reflect typical expectations used in PV and QA practice and align with the need for timely management action required under GVP and ICH Q9 principles.

Critical findings (example thresholds) - Immediate notification (documented) to QPPV, Head of PV and Head of QA within 4 hours of discovery (or by the next business hour if discovered out-of-hours) — record method and recipients. - Formal management notification (email + logged entry in finding register) within 24 hours. - Preliminary containment actions initiated within 24 hours; documented immediate actions recorded in the finding file. - Formal CAPA plan (initial action plan) submitted within 3 business days. Plan must include interim containment, root cause analysis start date, owner and target dates. - Implementation of high-priority corrective actions within 15 calendar days (or shorter if patient safety demands); full remediation timeline to be defined in the CAPA with justification. - Effectiveness check(s) initiated within 30 calendar days and completed as defined by the CAPA (e.g., after sustained operation for a defined period, typically 30–90 days depending on the control). - Senior management briefing and escalation to Executive Committee within the next scheduled meeting and ad hoc if required.

Major findings (example thresholds) - Notification to QPPV and Head of QA within 48 hours. - CAPA plan submitted within 10 business days with owner, resource estimates and milestones. - High priority corrective actions implemented within 30 calendar days where feasible; other actions implemented within 30–90 days depending on complexity. - Effectiveness verification completed within 90 calendar days or as defined in the plan. - Report to PV Steering/Compliance Committee at next meeting.

Minor findings (example thresholds) - Notification to audit owner and local management within 5 business days. - CAPA plan submitted within 30 calendar days. - Implementation within 90 calendar days. - Effectiveness verification within 6 months.

Observations (example thresholds) - Logged in the observation tracker. - Reviewed in quarterly audit or quality committee meetings. - Actioned as continuous improvement; timelines discretionary.

Documentation for inspectors: show timestamped notifications, meeting minutes, CAPA plan submissions, evidence of execution, and effectiveness checks in a single accessible dossier.

Note: These example timelines are widely used as inspection-ready references. Organisations must define and justify their own timelines in quality documentation and ensure consistent application.

Immediate Actions and Containment

For findings with patient safety or regulatory impact, documented immediate actions (containment) must be recorded separately from longer-term CAPAs. Containment examples include temporary process changes, retrospective data reviews, systems lockdowns or communications with external partners. Containment actions should have owners, start dates, end dates and supporting evidence.

Inspectors expect to see distinction between interim containment (short-term relief) and permanent corrective actions; both should be traceable in the finding file.

Root Cause Analysis and CAPA Linkage

Findings document the "what". Root cause analysis explains the "why". For inspection readiness, the following are expected:

Regulators assess whether CAPAs are adequate and proportionate to root causes and overall risk.

Sample Finding Template (Inspection-ready)

Include the completed template as supporting evidence to auditors and inspectors. Save a copy in the central finding register and in the audit file.

Finding ID: F-YYYY-XXX Audit ID / Report ref: Date discovered: Auditor: Audit area / site / vendor: Reported to (name, role, date/time, method):

For inspection readiness, include the electronic audit trail that shows who edited the finding entry and when.

Sample CAPA Template (Inspection-ready)

CAPA ID: CAPA-YYYY-XXXX Linked Finding(s): F-YYYY-XXX Date opened: Owner: Sponsor (senior manager): Priority (Critical/Major/Minor): Root cause(s) addressed:

Corrective actions (for immediate past nonconformance) - Action ID: - Description: - Rationale: (how the action addresses root cause) - Owner: - Start date: - Target completion date: - Dependencies / resources required: - Implementation evidence (list items that will demonstrate completion)

Preventive actions (to prevent recurrence) - Action ID: - Description: - Owner: - Start date: - Target completion date: - Evidence required:

Success criteria (measurable) - What will demonstrate effectiveness? (metrics, sample size, pass/fail) - Pre-defined acceptance criteria

Effectiveness verification plan - Method (e.g., re-audit, targeted sample review, monitoring signal) - Timing (e.g., 30, 60, 90 days post-implementation or after sustained period as justified) - Sample size / scope - Owner of verification - Documentation required

Residual risk assessment - Pre-CAPA risk score: - Post-CAPA estimated risk score: - Risk acceptance (who and when)

Closure approvals - QA sign-off (name, role, date) - PV/QPPV sign-off (name, role, date) - Executive sign-off (for critical CAPAs) (name, role, date)

Change control / training actions - Change request IDs (if SOPs or systems are revised) - Training plan (groups, materials, completion evidence)

Audit trail - Record of updates, reassignments, delays, and rationale for extensions

For inspections, provide the full CAPA file including evidence of implementation and effectiveness checks. The CAPA file should be organised and indexed.

Audit Checklist to Support Findings and CAPAs (Inspection-Ready)

Use this checklist during post-audit processing, CAPA creation and pre-inspection dossier assembly. Track each item as completed and include evidence links.

Audit finding and classification checklist - [ ] Finding documented using the standard finding template (all fields complete) - [ ] Objective evidence attached and referenced (with custody chain) - [ ] Severity decision matrix completed with numeric scoring - [ ] Classification rationale documented and approved by QA - [ ] Risk assessment attached (residual risk if CAPA implemented) - [ ] Immediate containment actions documented (if applicable) - [ ] Root cause analysis performed and documented; method stated - [ ] CAPA(s) created with owner, timelines and measurable success criteria - [ ] Escalation notifications logged with timestamps (who, when, method) - [ ] CAPA approval route documented (QA, PV, Executive if required) - [ ] Change control initiated for procedural/system changes (if applicable) - [ ] Training plan defined and evidence of completion required - [ ] Effectiveness verification plan included with dates, scope and owner - [ ] Evidence of implementation uploaded (screenshots, training records, approvals) - [ ] Effectiveness verification performed and documented (results and follow-up) - [ ] CAPA closed with signatures and date, with final risk assessment - [ ] Finding cross-referenced in management reporting and KPIs - [ ] Documents and records retained according to retention policy and retrievable for inspection

Pre-inspection dossier checklist (for selected findings) - [ ] Full audit report and executive summary - [ ] Finding register extract showing current status - [ ] All finding templates and completed severity decision matrices - [ ] Full CAPA files with implementation and effectiveness evidence - [ ] Meeting minutes demonstrating governance escalation and decisions - [ ] Email/communication logs for regulatory notifications if any - [ ] Trend analyses and metrics demonstrating systemic action - [ ] Traceability matrix linking findings → CAPAs → evidence

This checklist should be version-controlled and referenced in the audit report or dossier provided to inspectors.

Metrics, Reporting and Governance Oversight

Inspection bodies evaluate not only individual findings but also the governance system that oversees finding management. Organisations should demonstrate:

Governance should also include periodic independent assessment of CAPA effectiveness (e.g., QA verification, re‑audit, external review).

Inspection Relevance — What Inspectors Want to See

Inspectors typically request: - The audit report and related finding files - The finding register and severity scorecards - CAPA plans, implementation evidence and effectiveness verification - Evidence of management escalation and decision-making - Root cause analysis documentation - Communications with regulators or partners relating to the finding - Evidence of systemic review and preventive measures for repeat issues

Inspectors evaluate: - Appropriateness of classification relative to impact - Timeliness of escalation and corrective actions - Robustness of root cause analysis - Linkage between findings and CAPAs (traceability) - Evidence that CAPAs achieved the intended risk reduction - Repeat findings and organisational learning mechanisms

To be inspection-ready, maintain a single accessible dossier per finding that includes the templates above together with the audit checklist items completed.

Handling Repeat Findings — Governance and Inspector Expectations

Repeat findings signal CAPA ineffectiveness or governance failure. Regulators expect to see: - Evidence that prior CAPAs were reviewed for adequacy at the time of recurrence - Updated root cause analysis that explains recurrence - Strengthened CAPAs or escalated governance interventions (e.g., executive oversight, external review) - Demonstrable institutional learning (policy changes, training, process redesign)

Document decisions to escalate repeat issues to higher governance levels and preserve minutes proving managerial involvement.

Examples of Common Findings Mapped to the Matrix (Illustrative)

  1. Failure to submit serious adverse reaction reports to the competent authority in the required timeframe:
  2. PSI: 3, RI: 3, DII: 1, SI: 2, Detect: 3 → total 12 → Critical
  3. Escalation: immediate QPPV notification; regulatory communication planned.

  4. Single instance of missing consent form in safety database (data entry error, isolated):

  5. PSI: 1, RI: 1, DII: 1, SI: 0, Detect: 1 → total 4 → Minor
  6. Escalation: local management action, CAPA in routine timeframe.

  7. Vendor PV oversight gaps found across multiple sites (audit program not executed):

  8. PSI: 2, RI: 3, DII: 2, SI: 3, Detect: 2 → total 12 → Critical
  9. Escalation: QPPV and Procurement, contract review, immediate vendor remediation plan.

For each example, include evidence of the scorecard, notification timestamps and CAPA file.

Recordkeeping and Traceability

For regulatory inspections, records must be: - Complete and retrievable - Time-stamped and version controlled - Sufficient to demonstrate chain of custody and decisions - Indexed by finding ID, CAPA ID and audit ID for cross-reference

An electronic finding/CAPA management system with audit trail is preferred. Where manual systems are used, ensure a documented change control and retention policy.

Characteristics of Mature Finding Management

High-performing organisations demonstrate: - Consistent, documented classification applying the decision matrix - Timely, evidence-based escalation and documented containment where required - Root cause analysis that informs proportionate CAPAs - Measurable success criteria and documented effectiveness verification - Governance that provides appropriate oversight and decision records - Use of findings for continuous improvement and systemic risk reduction

Inspectors expect evidence of both process and outcome — not just closed CAPAs but proof that risk was reduced.

Key Takeaways

References

  1. EMA Good Pharmacovigilance Practices (GVP) Module IV – Pharmacovigilance Audits.
  2. EMA Good Pharmacovigilance Practices (GVP) Module I – Pharmacovigilance Systems and Their Quality Systems.
  3. EMA Good Pharmacovigilance Practices (GVP) Module III – Pharmacovigilance Inspections.
  4. Regulation (EC) No 726/2004.
  5. Directive 2001/83/EC.
  6. Commission Implementing Regulation (EU) No 520/2012.
  7. ICH Q9 Quality Risk Management.
  8. ICH E2E Pharmacovigilance Planning.

Last reviewed: 2026-06-11