Audit Findings and Classification in Pharmacovigilance
Table of contents
- Introduction
- Finding architecture
- Condition, criterion, evidence and risk
- Good wording
- Classification without false precision
- Significance factors
- Categories and local definitions
- Escalation and containment
- Immediate actions
- Linked processes
- CAPA and verification
- Trending and governance
- Repeat findings
- Reporting
- Worked examples
- References
- Regulatory Note
Introduction
An audit finding is a documented conclusion that evidence does not meet a defined criterion, or that an important improvement opportunity requires management attention. It is not a label attached to a person and it is not a substitute for risk assessment.
A useful finding is factual, reproducible and actionable. It explains what was expected, what was observed, why it matters and what happens next.
GVP Module IV supports a risk-based audit system. Organisations may use critical, major and minor categories, or another documented scale. The category is meaningful only when the procedure defines it and applies it consistently.
Finding architecture
Condition, criterion, evidence and risk
| Part | Meaning |
|---|---|
| Criterion | Requirement, approved procedure, contract or control objective |
| Condition | What the auditor observed |
| Evidence | Records, samples, interviews, system data or other support |
| Risk | Actual or potential effect on patients, reporting, integrity or control |
Example: “The procedure requires monthly reconciliation of safety reports from the distributor. In six monthly reconciliations, two had no documented review and one was completed after the reporting cycle. The missing evidence prevents demonstration that overdue reports were identified.” This is stronger than “reconciliation is weak”.
Good wording
Use neutral language. Identify the sample or period and separate known facts from inference. Avoid “always”, “never” and “all” unless the evidence supports them.
Do not insert an untested root cause into the finding. If there is an immediate risk, state the risk and recommended containment clearly, while leaving the causal investigation to the CAPA process.
Classification without false precision
Classification prioritises attention; it does not replace judgement.
Significance factors
Consider patient impact, regulatory obligation, effect on case processing or signal management, scope, duration, data integrity, recurrence likelihood, detectability, third-party dependence, systemic nature and repeat status.
The same documentation gap can have different significance in different contexts. A missing date on a low-risk checklist is not equivalent to an untraceable safety-data transfer.
Categories and local definitions
A documented three-category model might use:
- Critical: serious or immediate threat to the PV system, patient protection, compliance or data integrity requiring urgent escalation and containment.
- Major: significant weakness that could materially affect compliance or reliability of a critical process, even if no harm is demonstrated.
- Minor: limited deviation or isolated weakness that does not materially undermine the overall control, but requires correction or learning.
These are operating definitions, not a universal EU legal grading system. Record the decision, rationale and approver. Do not downgrade a systemic issue because only a few examples appeared in the sample.
Escalation and containment
Immediate actions
Escalate before the final report when evidence suggests an ongoing missed obligation, unreliable safety data, serious patient risk or data-integrity concern. The business owner and quality function should determine containment; the QPPV should be involved when the issue may affect the PV system or benefit–risk information.
Containment can include stopping a defective transfer, reviewing affected cases, adding an independent check, preserving records or notifying governance. It is a prudent control while facts are established, not proof that a breach occurred.
Linked processes
A finding may link to deviation management, CAPA, change control, vendor oversight, training, validation, signal management or regulatory reporting. Show those links so the same risk is not tracked in disconnected systems. Avoid duplicate records merely to make a dashboard look complete.
CAPA and verification
Higher-risk findings generally need faster containment, clearer senior visibility and more rigorous effectiveness verification. Lower-risk findings may be managed through routine correction and trend review. The proportionality rationale should be recorded.
Closure should not be based only on action completion. Verify that the control works and that recurrence risk is acceptably controlled. See Audit CAPAs in Pharmacovigilance for the connected lifecycle.
Trending and governance
Repeat findings
A repeat finding is evidence that the prior response did not remove or control the causal pathway, or that a related process has the same weakness. Revisit the earlier root-cause analysis, action design, effectiveness test and scope.
Reporting
Useful reporting includes findings by process and category, overdue actions and approved extensions, repeat themes, time to containment, effectiveness outcomes, cross-product or vendor themes, and accepted risks. A falling finding count is not proof of improvement because audit scope and sampling may have changed.
Worked examples
Isolated documentation gap. One training record lacks a date while assignment, completion and competency evidence are present. Correct the record and check adjacent records under the local procedure.
Systemic reconciliation weakness. Distributors use different fields, the reconciliation is not risk-based and overdue items are invisible. This may be major because the interface can affect case completeness and timeliness; containment, impact assessment and a system CAPA are appropriate.
Unreliable safety data. A transfer log cannot establish which case-file version was sent or received. Preserve records, determine scope, assess reporting impact and escalate data-integrity implications. The final category follows the evidence and procedure.
References
- EMA, GVP Module IV: Pharmacovigilance audits
- EMA, GVP Module I: Pharmacovigilance systems and quality systems
- EMA, GVP Module II: Pharmacovigilance system master file
- ICH Q9(R1), Quality Risk Management
Regulatory Note
Critical, major and minor are common operational categories, not a single EU-wide legal grading system. Apply the approved procedure, applicable law and competent-authority expectations for the relevant product and jurisdiction.