Common Pharmacovigilance Audit Failures
- Common Pharmacovigilance Audit Failures
- Introduction
- Failure patterns
- Treating the audit universe as a static list
- Using a scoring model without judgement
- Auditing documents rather than controls
- Confusing independence with outsourcing
- Treating vendors as outside the programme
- Writing findings that cannot drive action
- Closing CAPAs on completion alone
- Reporting only counts
- Strengthening the programme
- Governance and follow-up
- References
- Regulatory Note
Introduction
An audit programme may look active because audits are scheduled, reports are issued and CAPAs are opened. That activity does not by itself demonstrate assurance.
The following are potential failure modes and inspection questions, not a claim that every organisation has the same deficiencies or that the examples are findings from a particular authority. The useful test is whether the programme can show risk-based coverage, independent evidence, effective follow-up and learning.
Failure patterns
Treating the audit universe as a static list
A list of departments may omit interfaces, new vendors, digital channels, acquired products, validated systems or local processes. Keep a change-controlled universe and explain what changed after acquisitions, product launches or major process changes.
Using a scoring model without judgement
A numerical matrix can obscure a high-risk interface or create false precision. Record the narrative rationale, assumptions, data sources and management decision. Revisit the score when controls, exposure or evidence change.
Auditing documents rather than controls
A current SOP is not proof that a process works. Test records, system data, audit trails, exceptions, training, decisions and hand-offs.
Confusing independence with outsourcing
An external auditor can still have a conflict or an insufficient understanding of PV. Verify competence, independence, scope, access to evidence and review arrangements.
Treating vendors as outside the programme
Service providers may perform critical case, literature, signal or reporting activities. The programme should use a risk-based combination of audit, performance data, quality agreements, access to records and follow-up.
Writing findings that cannot drive action
“Process not robust” is not a finding. State criterion, condition, evidence, scope and risk so the CAPA is specific.
Closing CAPAs on completion alone
Approved procedures and completed training are outputs. Effectiveness evidence should show whether the changed control works and whether recurrence risk is reduced.
Reporting only counts
The number of audits or findings can be misleading. Add coverage, repeat themes, overdue actions, effectiveness outcomes and decisions taken.
Strengthening the programme
A practical control set
A defensible programme maintains:
- a current risk-based audit universe;
- an approved rolling plan with rationale and changes;
- auditor competence and independence evidence;
- scopes, sampling and workpapers;
- finding and CAPA linkage;
- effectiveness verification;
- governance reporting and QPPV visibility;
- learning applied to future priorities.
Questions for a self-check
Ask: What could affect case completeness or timeliness? Which interfaces are least visible? Which controls have changed? Which prior findings recur? Which vendor dependencies are critical? What evidence would disprove our assumption that the process works?
Governance and follow-up
The QPPV and governance forums should see significant findings, systemic risks, repeat findings, overdue actions and ineffective CAPAs. Escalation should be proportionate and documented.
A programme should be able to explain why an area was not audited, why a follow-up was sufficient, and what changed after a serious issue. Those explanations should be traceable to records, not reconstructed for an inspection.
References
- EMA, GVP Module IV: Pharmacovigilance audits
- EMA, GVP Module I: PV systems and quality systems
- EMA, GVP Module II: PV system master file
- ICH Q9(R1), Quality Risk Management
Regulatory Note
The patterns are practical risk-management examples. They are not a list of universal inspection findings, mandatory audit frequencies or legal severity thresholds. Use applicable law, GVP and approved procedures.