Common Pharmacovigilance Audit Failures

A practical guide to weak audit universes, poor risk assessment, ineffective CAPAs, limited independence and weak governance.

Take test

Common Pharmacovigilance Audit Failures

Introduction

An audit programme may look active because audits are scheduled, reports are issued and CAPAs are opened. That activity does not by itself demonstrate assurance.

The following are potential failure modes and inspection questions, not a claim that every organisation has the same deficiencies or that the examples are findings from a particular authority. The useful test is whether the programme can show risk-based coverage, independent evidence, effective follow-up and learning.

Failure patterns

Treating the audit universe as a static list

A list of departments may omit interfaces, new vendors, digital channels, acquired products, validated systems or local processes. Keep a change-controlled universe and explain what changed after acquisitions, product launches or major process changes.

Using a scoring model without judgement

A numerical matrix can obscure a high-risk interface or create false precision. Record the narrative rationale, assumptions, data sources and management decision. Revisit the score when controls, exposure or evidence change.

Auditing documents rather than controls

A current SOP is not proof that a process works. Test records, system data, audit trails, exceptions, training, decisions and hand-offs.

Confusing independence with outsourcing

An external auditor can still have a conflict or an insufficient understanding of PV. Verify competence, independence, scope, access to evidence and review arrangements.

Treating vendors as outside the programme

Service providers may perform critical case, literature, signal or reporting activities. The programme should use a risk-based combination of audit, performance data, quality agreements, access to records and follow-up.

Writing findings that cannot drive action

“Process not robust” is not a finding. State criterion, condition, evidence, scope and risk so the CAPA is specific.

Closing CAPAs on completion alone

Approved procedures and completed training are outputs. Effectiveness evidence should show whether the changed control works and whether recurrence risk is reduced.

Reporting only counts

The number of audits or findings can be misleading. Add coverage, repeat themes, overdue actions, effectiveness outcomes and decisions taken.

Strengthening the programme

A practical control set

A defensible programme maintains:

Questions for a self-check

Ask: What could affect case completeness or timeliness? Which interfaces are least visible? Which controls have changed? Which prior findings recur? Which vendor dependencies are critical? What evidence would disprove our assumption that the process works?

Governance and follow-up

The QPPV and governance forums should see significant findings, systemic risks, repeat findings, overdue actions and ineffective CAPAs. Escalation should be proportionate and documented.

A programme should be able to explain why an area was not audited, why a follow-up was sufficient, and what changed after a serious issue. Those explanations should be traceable to records, not reconstructed for an inspection.

References

Regulatory Note

The patterns are practical risk-management examples. They are not a list of universal inspection findings, mandatory audit frequencies or legal severity thresholds. Use applicable law, GVP and approved procedures.

Revision History

Last reviewed: 2026-09-06