Audit Programme Management in Pharmacovigilance
Table of contents
- Introduction
- Programme design
- Audit universe
- Risk assessment
- Planning and governance
- Rolling plan
- Independence, competence and resources
- Delivering assurance
- Scope and evidence
- Outsourced activities
- Findings and improvement
- CAPA and follow-up
- Metrics and maturity
- Programme records
- References
- Regulatory Note
Introduction
An individual audit tests a defined area at a point in time. An audit programme is the governed system that decides what assurance is needed, how work is prioritised, how results are followed up and how the programme learns.
GVP Module IV expects pharmacovigilance audits to be planned and conducted using a risk-based approach. It does not require one scoring matrix or fixed frequency for every process. The programme should cover the PV system, respond to material change and retain the reasoning behind its priorities.
Programme design
Audit universe
The audit universe is the set of processes, interfaces, products, locations, systems, service providers and governance activities that could affect PV. It may include case intake and submission, literature, signals, aggregate reports, risk management, the PSMF, affiliates, vendors, validated systems, interfaces, training and continuity.
The universe should reflect acquisitions, new products, new technologies, organisational changes and emerging risks. A list of department names is not enough if the risk sits in an interface between them.
Risk assessment
Consider impact, likelihood, detectability, change, prior findings, control performance, data quality, third-party dependence and regulatory significance. A numerical score can help compare items, but it is a decision aid, not an objective measure of compliance.
Record the rationale in plain language: “included this cycle because a new vendor, a new intake channel and a prior overdue reconciliation create a combined risk to case completeness and timeliness” is more informative than “high score”.
Planning and governance
Rolling plan
A rolling plan can show the audit area and scope, risk rationale, planned window, lead and independence, dependencies, and follow-up route. It should allow reactive audits or focused reviews when a material change, serious finding, safety concern or regulatory event alters the risk profile.
A stable annual calendar is not evidence of a risk-based programme if the programme cannot respond to new information.
Independence, competence and resources
Auditors should be sufficiently independent from the activity assessed and competent for the scope. Independence can be managed through reporting lines, conflict checks, co-sourcing or independent review. Competence includes audit technique and relevant PV, clinical, data, quality and regulatory understanding.
Resource planning should include preparation, fieldwork, report review, translation, vendor coordination, follow-up and effectiveness checks. Unrealistic plans create overdue audits and shallow work.
Delivering assurance
Scope and evidence
Each audit should have an objective, criteria, scope, approach and sampling rationale. Test whether the process works in practice, not only whether a procedure exists.
Evidence may include records, system data, audit trails, training, contracts, decisions, metrics, interviews and observation. Sampling should be described so another reviewer can understand what was selected and what limitations remain.
A programme can use system audits, process audits, vendor audits, focused reviews, remote audits or follow-up audits when the method answers the assurance question.
Outsourced activities
Outsourcing execution does not outsource the MAH’s oversight responsibility. Consider provider criticality, interfaces, performance data, previous issues, access to records and the ability to audit or obtain equivalent assurance.
Coordinate vendor work with contracts, quality agreements, service-level data and CAPA follow-up. A desktop questionnaire may be useful, but is not automatically equivalent to an audit.
Findings and improvement
CAPA and follow-up
Monitor identification, classification, containment, CAPA, due dates, extensions, effectiveness and closure. An administratively closed but ineffective finding is not assurance.
Follow-up depth should reflect risk. A high-risk system failure may need a targeted re-audit or independent sample review; a limited documentation gap may need evidence review and trend monitoring. Record the rationale.
Metrics and maturity
Useful metrics describe coverage and control: risk-prioritised coverage of the universe, overdue audits and reasons, repeat findings, time to CAPA approval, effectiveness outcomes, vendor coverage and changes made after emerging risks.
No metric is a universal pass threshold. A mature programme combines metrics with narrative interpretation and management decisions.
Programme records
Retain the current audit universe and change log, risk assessment and prioritisation rationale, approved plan and changes, auditor competence and independence evidence, scopes, reports, workpapers, finding and CAPA links, follow-up, governance minutes and QPPV visibility.
The programme tells a longitudinal story. Inspectors may ask why an area or vendor was not audited, how a repeat finding was handled, or how the programme changed after an acquisition. The answer should be traceable to recorded risk assessment.
References
- EMA, GVP Module IV: Pharmacovigilance audits
- EMA, GVP Module I: PV systems and quality systems
- EMA, GVP Module II: PV system master file
- ICH Q9(R1), Quality Risk Management
Regulatory Note
A risk-based audit programme is required in principle, but the universe, scoring method, frequency, sampling approach and metrics should be proportionate to the organisation’s PV system. These examples are operating patterns, not universal regulatory thresholds.