Audit Findings and Classification in Pharmacovigilance

A practical framework for evidence-based audit findings, significance assessment, escalation, CAPA linkage and governance.

Take test

Audit Findings and Classification in Pharmacovigilance

Introduction

An audit finding is a documented conclusion that evidence does not meet a defined criterion, or that an important improvement opportunity requires management attention. It is not a label attached to a person and it is not a substitute for risk assessment.

A useful finding is factual, reproducible and actionable. It explains what was expected, what was observed, why it matters and what happens next.

GVP Module IV supports a risk-based audit system. Organisations may use critical, major and minor categories, or another documented scale. The category is meaningful only when the procedure defines it and applies it consistently.

Finding architecture

Condition, criterion, evidence and risk

Part Meaning
Criterion Requirement, approved procedure, contract or control objective
Condition What the auditor observed
Evidence Records, samples, interviews, system data or other support
Risk Actual or potential effect on patients, reporting, integrity or control

Example: “The procedure requires monthly reconciliation of safety reports from the distributor. In six monthly reconciliations, two had no documented review and one was completed after the reporting cycle. The missing evidence prevents demonstration that overdue reports were identified.” This is stronger than “reconciliation is weak”.

Good wording

Use neutral language. Identify the sample or period and separate known facts from inference. Avoid “always”, “never” and “all” unless the evidence supports them.

Do not insert an untested root cause into the finding. If there is an immediate risk, state the risk and recommended containment clearly, while leaving the causal investigation to the CAPA process.

Classification without false precision

Classification prioritises attention; it does not replace judgement.

Significance factors

Consider patient impact, regulatory obligation, effect on case processing or signal management, scope, duration, data integrity, recurrence likelihood, detectability, third-party dependence, systemic nature and repeat status.

The same documentation gap can have different significance in different contexts. A missing date on a low-risk checklist is not equivalent to an untraceable safety-data transfer.

Categories and local definitions

A documented three-category model might use:

These are operating definitions, not a universal EU legal grading system. Record the decision, rationale and approver. Do not downgrade a systemic issue because only a few examples appeared in the sample.

Escalation and containment

Immediate actions

Escalate before the final report when evidence suggests an ongoing missed obligation, unreliable safety data, serious patient risk or data-integrity concern. The business owner and quality function should determine containment; the QPPV should be involved when the issue may affect the PV system or benefit–risk information.

Containment can include stopping a defective transfer, reviewing affected cases, adding an independent check, preserving records or notifying governance. It is a prudent control while facts are established, not proof that a breach occurred.

Linked processes

A finding may link to deviation management, CAPA, change control, vendor oversight, training, validation, signal management or regulatory reporting. Show those links so the same risk is not tracked in disconnected systems. Avoid duplicate records merely to make a dashboard look complete.

CAPA and verification

Higher-risk findings generally need faster containment, clearer senior visibility and more rigorous effectiveness verification. Lower-risk findings may be managed through routine correction and trend review. The proportionality rationale should be recorded.

Closure should not be based only on action completion. Verify that the control works and that recurrence risk is acceptably controlled. See Audit CAPAs in Pharmacovigilance for the connected lifecycle.

Repeat findings

A repeat finding is evidence that the prior response did not remove or control the causal pathway, or that a related process has the same weakness. Revisit the earlier root-cause analysis, action design, effectiveness test and scope.

Reporting

Useful reporting includes findings by process and category, overdue actions and approved extensions, repeat themes, time to containment, effectiveness outcomes, cross-product or vendor themes, and accepted risks. A falling finding count is not proof of improvement because audit scope and sampling may have changed.

Worked examples

Isolated documentation gap. One training record lacks a date while assignment, completion and competency evidence are present. Correct the record and check adjacent records under the local procedure.

Systemic reconciliation weakness. Distributors use different fields, the reconciliation is not risk-based and overdue items are invisible. This may be major because the interface can affect case completeness and timeliness; containment, impact assessment and a system CAPA are appropriate.

Unreliable safety data. A transfer log cannot establish which case-file version was sent or received. Preserve records, determine scope, assess reporting impact and escalate data-integrity implications. The final category follows the evidence and procedure.

References

Regulatory Note

Critical, major and minor are common operational categories, not a single EU-wide legal grading system. Apply the approved procedure, applicable law and competent-authority expectations for the relevant product and jurisdiction.

Revision History

Last reviewed: 2026-09-06