EudraVigilance Inspection Findings and Failure Modes
EudraVigilance is not inspected as an isolated software application. It sits inside regulated pharmacovigilance processes: individual case safety report (ICSR) collection and submission, data quality, signal detection, access to regulatory safety data, and the quality system that governs those activities. An inspector may therefore start with an EudraVigilance transaction but follow the evidence upstream to case receipt or downstream to a signal decision, deviation, CAPA or management review.
Published EMA inspection information provides a useful evidence base. In the Pharmacovigilance Inspectors' Working Group annual report for 2024, management and reporting of adverse reactions was the largest finding category in CHMP-requested human pharmacovigilance inspections. EMA recorded 22 findings in this area: 12 major and 10 minor. The major findings included issues relating to submission and follow-up, medical review and MedDRA coding, literature screening, and receipt and collation of ICSRs from all sources. Earlier EU reporting covering 2019–2022 also highlighted quality of ICSR reporting in EudraVigilance, including coding errors, failure to meet minimum valid-case information and insufficient follow-up.
These are real published categories. They should be distinguished from the illustrative failure modes later in this article, which explain how weaknesses can arise operationally without claiming that a specific scenario was observed in an inspection.
- EudraVigilance Inspection Findings and Failure Modes
- Regulatory and Inspection Framework
- What Published Inspection Data Actually Show
- How an Inspector Can Trace an ICSR
- Data Quality, Follow-Up and Coding
- Signal Management and EudraVigilance Data
- Access and Registration Governance
- Vendors and Outsourced Reporting
- Deviations and CAPA
- Illustrative Failure Modes
- Inspection Questions and Evidence
- Practical Readiness Model
- Key Takeaways
- References
- Regulatory Note
Regulatory and Inspection Framework
EU pharmacovigilance inspections are conducted to determine whether marketing authorisation holders comply with pharmacovigilance obligations. GVP Module III describes the planning, conduct, reporting and follow-up of inspections, while the Union procedures provide a common framework for inspection preparation and follow-up.
EudraVigilance-related evidence can arise within several inspection domains:
- management and reporting of adverse reactions;
- signal management;
- computerised systems;
- the pharmacovigilance quality system;
- contracts and agreements;
- training;
- QPPV oversight; and
- the PSMF.
The legal and regulatory requirement is therefore broader than "EudraVigilance compliance". The MAH must operate an effective pharmacovigilance system that collects, manages, transmits and evaluates safety information correctly and on time.
What Published Inspection Data Actually Show
The 2024 EMA annual report categorised 87 deficiencies from CHMP-requested human pharmacovigilance inspections: 29 major and 58 minor, with no critical findings recorded in that inspection set. The three largest finding areas were management/reporting of adverse reactions, quality management systems and the PSMF.
Within adverse-reaction management and reporting, EMA specifically described major findings connected with submission and follow-up processes, medical review/MedDRA coding, literature screening, and receipt/collation of ICSRs. These published categories justify discussing those areas as genuine inspection risks.
They do not justify claiming that every late case, rejection, access issue or reconciliation discrepancy is a "common inspection finding" unless supported by inspection data. Good reference writing should preserve that distinction.
How an Inspector Can Trace an ICSR
A case trace can test several systems at once. The inspector may begin with a report visible in EudraVigilance or with a source record and ask the organisation to reconstruct the complete path.
A defensible trace should be able to show:
source receipt → validity assessment → case creation → coding and medical review → regulatory due date → E2B(R3) message → transmission → acknowledgement → follow-up → final case history.
The evidence can sit in different systems, but the chain should remain reconstructable.
Receipt and clock start
GVP Module VI defines the principles for determining when an organisation becomes aware of a report and when regulatory reporting timeframes begin. The trace should therefore show the original date of receipt and how information from affiliates, vendors, medical information, literature, partners or other sources reaches the pharmacovigilance system.
A weakness at this first step can make later "on-time submission" metrics misleading if the organisation measures timeliness from database entry rather than the true regulatory clock start.
Validity and case quality
A valid ICSR requires the minimum information defined in GVP Module VI: an identifiable reporter, an identifiable patient, a suspected adverse reaction and a suspected medicinal product. The inspector can test whether missing information was recognised, whether appropriate follow-up was sought and whether invalid or incomplete reports were managed consistently.
Case quality extends beyond validity. Coding, seriousness, medical interpretation, expectedness where relevant, product identification and case narrative may all affect the value of the report for regulatory evaluation and signal detection.
Submission and acknowledgement
For reportable post-authorisation ICSRs in the EU, serious valid ICSRs are generally submitted within 15 days and non-serious valid ICSRs within 90 days, according to the applicable GVP Module VI rules. Submission should use the current ICH E2B(R3) framework and EudraVigilance business rules.
Transmission is not the end of the process. The organisation needs to know whether the message was accepted or rejected and to act appropriately on acknowledgement information. A technically generated message that never enters EudraVigilance does not demonstrate successful regulatory reporting.
Data Quality, Follow-Up and Coding
Published EMA inspection data justify particular attention to ICSR quality because coding, follow-up and medical review have featured in actual finding categories. These areas matter because EudraVigilance is not merely a transmission repository; its data support signal detection and regulatory assessment.
Follow-up quality
Follow-up should be clinically purposeful. A process that sends generic requests without prioritising information needed to validate or characterise the case can appear compliant while adding little value. The quality question is whether important missing information was recognised and pursued proportionately.
MedDRA and product coding
Coding errors can alter how cases are retrieved, aggregated and screened. Inspectors may therefore examine coding conventions, training, quality control and how terminology-version changes are governed. The objective is not to achieve identical wording across all users, but to demonstrate consistent application of controlled conventions and medically defensible coding decisions.
Product identification is equally important. Incorrect or ambiguous product information can affect routing, duplicate detection and the interpretation of the case.
Signal Management and EudraVigilance Data
EudraVigilance also supports signal detection and assessment. GVP Module IX governs signal management, while EVDAS provides authorised users with analytical access to EudraVigilance data.
An inspection can therefore move from an ICSR reporting issue to a broader question: if cases were missing, late or miscoded, did the defect affect signal detection or an ongoing safety assessment?
This is why the Union follow-up procedure explicitly contemplates the downstream signal-management consequences of missed ICSR submissions. Where a significant number of reports require later submission, inspectors may notify the relevant authorities so that the resulting EudraVigilance data and any validated signals can be handled appropriately.
Access and Registration Governance
EudraVigilance access is role-based and tied to registered organisations and individual EMA accounts. Access governance supports accountability, data protection and operational continuity.
An inspector can reasonably test whether:
- active users have an operational need for their roles;
- the QPPV, responsible person or trusted deputy performs the approvals allocated to them in the EMA registration model;
- leavers and role changes are handled promptly;
- privileged EVDAS or level 2B access is justified;
- training requirements relevant to the user's function are met; and
- outsourced users are correctly linked to the MAH or sponsor they support.
Periodic access review is a useful control, but EU pharmacovigilance guidance does not prescribe a universal quarterly or annual review interval for every organisation. The frequency should be risk-based and defined in the organisation's own controlled process.
Vendors and Outsourced Reporting
A service provider may perform case processing, E2B generation, gateway operation, literature surveillance or other EudraVigilance-related activities. Outsourcing changes who executes the work; it does not remove the MAH's responsibility for the pharmacovigilance system.
Inspection evidence can therefore include agreements defining responsibilities, interfaces between organisations, training and qualification evidence, issue escalation, performance monitoring, audit or assurance activity where appropriate, and access to the underlying records.
The most important question is whether the MAH can detect and manage failure. A dashboard showing excellent vendor performance is not persuasive if the calculation excludes cases before vendor intake or if rejected transmissions are outside the metric.
Deviations and CAPA
A deviation is useful only if the investigation identifies what failed, which records or obligations were affected and whether the same weakness could exist elsewhere. CAPA should then address the cause rather than simply the visible event.
For example, a late ICSR caused by an interface outage may require more than retransmission. The organisation may need to determine the affected time window, identify all potentially missed cases, assess whether regulatory timelines were breached, examine monitoring controls and test whether the corrective action would detect recurrence.
Effectiveness checks should match the CAPA objective. If the corrective action is intended to improve rejection handling, evidence of fewer unresolved rejections or earlier detection is more meaningful than documenting that staff completed retraining.
Illustrative Failure Modes
The following scenarios are hypothetical and are not presented as published inspection findings.
The compliance clock starts too late
The dashboard measures from safety-database entry, but affiliates or vendors sometimes hold reports for days before entry. The apparent 100% on-time submission rate therefore does not reflect the true regulatory clock.
Acknowledgements are stored but not governed
The gateway archives ACK messages automatically, yet no process distinguishes accepted, rejected and warning outcomes or ensures that rejections are resolved within the applicable reporting timeframe.
Reconciliation exists only as a calendar task
A monthly reconciliation is signed as complete even though discrepancies remain unresolved and recurring mismatches are not trended. Frequency alone does not establish effectiveness.
Coding quality is measured without clinical relevance
A coding QC metric records agreement between two processors but does not examine whether the selected term accurately represents the source information. High agreement can therefore coexist with systematic miscoding.
Vendor metrics start at vendor receipt
The vendor meets all contractual timelines, but the MAH cannot see delays occurring before cases reach the vendor. Oversight is technically accurate yet incomplete.
Missing cases are corrected without assessing downstream impact
Late submissions are transmitted after discovery, but the organisation does not assess whether previous signal-detection outputs or aggregate analyses were affected by the missing data.
Inspection Questions and Evidence
A practical way to prepare for inspection is to ask whether the organisation can demonstrate control rather than whether it can produce a particular checklist. Potential questions include:
- How is the true regulatory receipt date established across all intake channels?
- How does the organisation know that all reportable ICSRs were submitted within the applicable timeframe?
- How are rejected messages identified and resolved?
- How are coding quality and medical review controlled?
- How are literature-derived ICSRs integrated into the reporting process?
- What evidence shows that affiliates and vendors transmit safety information completely and promptly?
- How are EudraVigilance data used in signal management, and what happens if source data are later found to be incomplete?
- How are privileged users approved and removed?
- What significant EudraVigilance-related deviations occurred, and how was their impact assessed?
- How does the QPPV obtain visibility of material reporting or signal-management risks?
These are illustrative inspection questions. The actual scope depends on the inspection mandate, product portfolio, previous compliance information and issues identified during the inspection.
Practical Readiness Model
An experienced PV team can organise evidence into five connected layers.
Layer 1 — obligation. Identify the legal or GVP requirement: for example, serious ICSR submission within 15 days.
Layer 2 — process. Show the controlled workflow translating the requirement into intake, assessment, submission and acknowledgement handling.
Layer 3 — transaction evidence. Demonstrate the process using real cases, system audit trails, messages and acknowledgements.
Layer 4 — monitoring. Show how exceptions, late cases, rejections, missing reports or quality trends are detected.
Layer 5 — governance. Demonstrate how significant weaknesses are escalated, investigated and corrected and how the QPPV and management receive appropriate visibility.
This structure is more robust than assembling an "inspection binder" disconnected from routine operations.
Key Takeaways
EudraVigilance-related inspection risk is principally a test of the pharmacovigilance system around the database. Published EMA data show that management and reporting of adverse reactions remains a significant inspection area, with actual findings involving submission/follow-up, medical review and MedDRA coding, literature screening and collection of ICSRs.
Those documented finding categories should be distinguished from hypothetical examples. A useful inspection-readiness article should not manufacture detailed findings, tolerances or required evidence that regulators have not published.
The strongest evidence is traceability: the organisation can reconstruct a case from source receipt to accepted EudraVigilance submission, explain the medical and coding decisions, demonstrate how failures are detected, and show how reporting defects feed into signal management, CAPA and QPPV oversight where relevant.
References
- European Medicines Agency. Annual Report of the Pharmacovigilance Inspectors' Working Group for 2024. EMA/INS/PhV/122716/2025. https://www.ema.europa.eu/en/documents/report/annual-report-pharmacovigilance-inspectors-working-group-2024_en.pdf
- European Medicines Agency. Report on pharmacovigilance tasks from EU Member States and EMA, 2019–2022. https://www.ema.europa.eu/en/documents/report/report-pharmacovigilance-tasks-eu-member-states-and-european-medicines-agency-ema-2019-2022_en.pdf
- European Medicines Agency. GVP Module III – Pharmacovigilance inspections (Rev. 1). EMA/119871/2012 Rev. 1. https://www.ema.europa.eu/en/documents/scientific-guideline/guideline-good-pharmacovigilance-practices-module-iii-pharmacovigilance-inspections_en.pdf
- European Medicines Agency. Union procedure on the preparation, conduct and reporting of EU pharmacovigilance inspections and Union procedure on the follow-up of pharmacovigilance inspections. Available from EMA pharmacovigilance inspection procedures. https://www.ema.europa.eu/en/human-regulatory-overview/marketing-authorisation/compliance-marketing-authorisation/pharmacovigilance-inspections-veterinary-medicines/pharmacovigilance-inspection-procedures-human
- European Medicines Agency. GVP Module VI – Collection, management and submission of reports of suspected adverse reactions (Rev. 2). EMA/873138/2011 Rev. 2. https://www.ema.europa.eu/en/documents/regulatory-procedural-guideline/guideline-good-pharmacovigilance-practices-gvp-module-vi-collection-management-submission-reports-suspected-adverse-reactions-medicinal-products-rev-2_en.pdf
- European Medicines Agency. GVP Module IX – Signal management (Rev. 1) and Addendum I. Available from the EMA GVP collection. https://www.ema.europa.eu/en/human-regulatory-overview/post-authorisation/pharmacovigilance-post-authorisation/good-pharmacovigilance-practices-gvp
- European Medicines Agency. EudraVigilance: electronic reporting. https://www.ema.europa.eu/en/human-regulatory-overview/research-development/pharmacovigilance-research-development/eudravigilance/eudravigilance-electronic-reporting
Regulatory Note
This article distinguishes published inspection evidence from illustrative operational failure modes. The 2024 EMA inspection report and the 2019–2022 pharmacovigilance task report are authoritative sources for the actual finding categories described. Hypothetical case traces, inspection questions and control models are presented as recommended practice or illustrative scenarios, not as documented regulatory findings. Applicable legal obligations and GVP requirements should be determined from the current EU legislation, GVP and procedure relevant to the activity.