Common EudraVigilance Inspection Findings
- Common EudraVigilance Inspection Findings
- Introduction
- How Inspectors Review EudraVigilance Activities
- Common Finding Categories (Summary)
- EudraVigilance Inspection Checklist (Inspection‑Ready)
- Sample Case‑Trace and Reconciliation Example
- Reconciliation Process: Practical Implementation Details
- Concrete Metrics and KPIs with Expected Tolerances
- Governance Considerations and Inspection Relevance
- Practical Tips for Inspection Presentation (Operational)
- Root Causes and CAPA Emphasis (Condensed)
- Key Takeaways
- References
Introduction
EudraVigilance-related activities are routinely reviewed during pharmacovigilance inspections.
Inspectors recognise that EudraVigilance sits at the centre of many critical pharmacovigilance processes, including:
- Adverse event reporting
- Signal management
- Literature monitoring
- Product data management
- Regulatory compliance monitoring
As a result, deficiencies affecting EudraVigilance frequently attract regulatory attention.
Inspectors generally evaluate not just whether reports were submitted, but whether the governance system ensures reliable, timely and complete reporting. For QPPVs, converting high‑level observations into inspection‑ready artefacts is essential to demonstrate control and continuous improvement.
How Inspectors Review EudraVigilance Activities
Inspection review commonly includes:
- Reporting compliance
- Submission timeliness
- Acknowledgement management
- Reconciliation activities
- Signal detection processes
- Access governance
- Vendor oversight
- Deviation management
- CAPA effectiveness
Inspectors often trace individual activities from source documentation through to EudraVigilance records. This case‑trace approach permits assessment of whether procedures are implemented in practice.
Common Finding Categories (Summary)
- Late reporting (serious individual case safety reports, follow‑up, literature)
- Failure to monitor acknowledgements (rejections/acceptances not acted on)
- Weak reconciliation processes (missing or infrequent reconciliations; unresolved discrepancies)
- Inadequate signal management oversight
- Access governance deficiencies (inactive users, shared accounts, missing reviews)
- Vendor oversight failures (missing KPIs, weak governance)
- Inadequate deviation management and weak CAPAs
- Poor documentation and traceability
- Insufficient QPPV oversight and visibility of compliance risks
The remainder of this article converts these high‑level observations into inspection‑ready content: a checklist inspectors would expect to see satisfied, a worked case‑trace and reconciliation example, concrete metrics/KPIs with tolerances, and governance considerations tied to inspection relevance.
EudraVigilance Inspection Checklist (Inspection‑Ready)
Use the checklist below to prepare inspection evidence. For each item, maintain demonstrable artefacts (procedures, logs, screenshots, reports, meeting minutes) and be ready to present them during a trace.
For each checklist item inspectors will typically ask: "Can you show me the record and how it demonstrates compliance?" Ensure artefacts are version controlled and indexed.
- Reporting Timeliness and Completeness
- Evidence required:
- Case processing timestamps from initial receipt to EV submission (date/time stamps).
- Case initial assessment note (seriousness, expectedness, causality).
- EV transmission receipts and message headers (message IDs, Acknowledgement codes).
- Submission queues or logs showing submission date/time.
- Procedure references (GVP Module VI timelines).
-
Inspector focus:
- Percent of serious ICSRs submitted within regulatory timelines (15 days for serious unexpected; 7 days initial for fatal/life‑threatening in certain regulations).
- Evidence of late submissions and documented justification/CAPA.
-
Acknowledgement and Rejection Management
- Evidence required:
- Daily/weekly acknowledgement monitoring log.
- Rejection investigation notes, root cause analysis and corrective actions.
- Re‑transmission evidence after correction.
-
Inspector focus:
- Mechanism for capturing and escalating rejections.
- Time from rejection to resolution (target tolerance).
-
Reconciliation Activities (Inbound / Outbound)
- Evidence required:
- Reconciliation SOP/procedure describing frequency, scope (EV downloads vs. local safety system), roles.
- Reconciliation logs with columns: EV case ID, local case ID, download date, process date, discrepancy, action, closure date.
- Sample reconciliations and attachments (e.g., email trail, screenshots).
-
Inspector focus:
- Frequency of reconciliations (monthly/weekly as per risk).
- Evidence that discrepancies are resolved promptly with root cause and CAPA if recurring.
-
Case Processing and Traceability
- Evidence required:
- A complete case file for several sampled cases (source document, triage notes, causality assessment, submission).
- Audit trail from safety database showing edits, user IDs and timestamps.
- Evidence of linkage to EV message (message ID, timestamps).
-
Inspector focus:
- Clear chain of custody from source to EV submission.
- No missing documents or undocumented decisions.
-
Signal Management Controls
- Evidence required:
- EVDAS output review logs, meeting minutes, escalation records.
- Signal assessment templates and decision documentation.
- Timelines for signal assessment and communication.
-
Inspector focus:
- Frequency of EVDAS, literature screening and documented assessments, governance for escalation.
-
Access and User Governance
- Evidence required:
- User access inventory for EV and safety systems (user, role, date granted, date removed).
- Access review logs and approvals.
- Evidence of termination or role change actions.
-
Inspector focus:
- Timeliness of access removal, appropriateness of permissions, absence of shared accounts.
-
Vendor Oversight and Contracts
- Evidence required:
- Contracts and delegation agreements specifying PV responsibilities.
- Vendor SOPs, training records, metrics (SLAs) and periodic oversight reports.
- Recent vendor performance reviews and audits.
-
Inspector focus:
- Evidence that delegated activities are performed to the same standards, escalation pathways, and QPPV oversight.
-
Deviation, CAPA and Continuous Improvement
- Evidence required:
- Deviation logs, investigations, root cause analyses.
- CAPA plans with timelines, owners, and verification records.
- Evidence of implementation and effectiveness checks.
-
Inspector focus:
- If a deviation occurred, is there a robust investigation and sustained corrective actions?
-
Documentation and Record Keeping
- Evidence required:
- Policies, SOPs (version controlled).
- Training logs specific to EV activities.
- Archive and retention evidence.
-
Inspector focus:
- Completeness and availability of records; version lifecycle management.
-
QPPV Oversight and Governance
- Evidence required:
- KPI reports reviewed by QPPV or designee.
- Meeting minutes showing QPPV involvement in escalations.
- Risk registers and mitigation actions related to EV operations.
- Inspector focus:
- QPPV has visibility and authority to remedy deficiencies; documented escalation and decision records.
Use this checklist to assemble a binder or electronic dossier mapped to sample case traces and KPIs.
Sample Case‑Trace and Reconciliation Example
Below is a step‑by‑step worked example showing the documents and reconciliation entries an inspector will expect to see when tracing a single case. This example demonstrates how to present evidence in an inspection.
Scenario: Spontaneous serious adverse reaction reported by a healthcare professional (HCP) in EU, requiring expedited submission to EudraVigilance.
- Receipt and Triage
- Source document: Faxed CIOMS form received 2026‑03‑10 08:15 CET. Filename: CIOMS_20260310_0001.pdf.
- Mailbox entry: SafetyInbox entry 2026‑03‑10 08:15 (email header/screenshot).
-
Triage note: Pharmacovigilance nurse triaged the report at 2026‑03‑10 09:00; assessment: serious, required expedited submission. Triage template completed and saved in case folder.
-
Case Creation in Safety Database
- Case created: SAFETYDB Case ID SDB‑2026‑000123 on 2026‑03‑10 09:10 by user 'triage.user'.
- Initial assessment recorded: seriousness = hospitalization; suspected drug = ProductX (EU MAH).
-
Attachments: scanned CIOMS form uploaded; triage note saved.
-
Medical Review and Causality
- Medical assessor review: 2026‑03‑10 11:00 by 'med.assessor' with documented causality: reasonable possibility.
-
Follow‑up tasks: request additional lab reports from reporter (email sent 2026‑03‑10 11:05; copy in case file).
-
EV Submission
- EV message prepared and validated in local EV gateway: 2026‑03‑10 13:20.
- EV message transmitted: 2026‑03‑10 13:25, EV message ID EVMSG‑20260310‑A0001.
-
EV acknowledgement: Received 2026‑03‑10 13:26 — "Accepted" (ack code: AOK‑20260310‑0001). Screenshot of EV transmission and acknowledgement saved in case folder.
-
Reconciliation Entry (Outbound)
- Reconciliation log (Outbound Submissions; monthly reconciliations):
- Row:
- Local Case ID: SDB‑2026‑000123
- EV Message ID: EVMSG‑20260310‑A0001
- Transmission Date: 2026‑03‑10 13:25
- EV Ack Status: Accepted
- Reconciliation Date: 2026‑03‑31
- Reconciler: reconciliation.lead
- Discrepancy: None
- Action/Notes: Confirmed submission present in EV and local DB. Closed 2026‑03‑31.
-
Attachments: Screenshot of EV search result showing EV case; link to EV message ID.
-
Downloaded Case (Inbound) — Example if the MAH is not the original reporter
- EV download received 2026‑04‑02 for associated reporter update: EV case EVMSG‑20260310‑A0001‑UPD.
-
Processing note: Downloaded case linked to SDB‑2026‑000123 on 2026‑04‑02 10:10 and follow‑up assigned.
-
Follow‑up and Closure
- Lab report received 2026‑04‑05; medical assessor updated case 2026‑04‑06.
- Follow‑up submitted to EV 2026‑04‑06 14:10 (follow‑up message ID EVMSG‑20260406‑F0001).
-
Reconciliation log updated to reflect follow‑up transmitted and acknowledged.
-
Evidence Pack for Inspection
- File list:
- Source CIOMS form (PDF)
- SafetyInbox email header (screenshot)
- Case creation audit trail (SAFETYDB export)
- Triage and medical assessment notes (PDF)
- EV transmission log (CSV or screenshot)
- EV acknowledgement screenshot (Accepted)
- Outbound reconciliation log entry with closure note (Excel/PDF)
- Follow‑up message logs and acknowledgements
-
Presentation:
- Provide timeline (chronological table) with hyperlinks to documents.
- Provide reconciliation extracts showing linkage between local case ID and EV message ID.
-
Reconciliation Discrepancy Example (if occurred)
-
If EV acknowledgement had been "Rejected: Invalid reaction term", example workflow:
- Reconciliation log entry would show EV Ack Status = Rejected; Reconciliation Date; Discrepancy = "Invalid reaction term".
- Investigation log: Root cause = mapping table outdated; corrective action = update mapping file; re‑submission date/time and evidence.
- CAPA: Training for case processors on reaction term selection and scheduled mapping updates. CAPA owner, target date and effectiveness review documented.
-
Inspection Trace Demonstration
- Inspector request: "Trace Case SDB‑2026‑000123 from receipt to EV submission and reconciliation closure."
- Response: Present timeline table, then open each artefact in sequence (source → case in SAFETYDB → EV message → EV acknowledgement → reconciliation log).
- Ensure all artefacts are cross‑referenced and names consistent.
This worked example demonstrates the minimum set of artefacts and the logical sequence inspectors expect. The same approach should be applied when preparing multiple sample traces across different outcome types (serious/non‑serious, literature, clinical trial cases, vendor‑processed cases).
Reconciliation Process: Practical Implementation Details
A robust reconciliation process should be documented, risk‑based and operational. Below are practical steps to implement and evidence maintenance:
- Define Scope and Frequency
- Outbound (Local DB → EV): Minimum monthly; increased to weekly for high‑volume products or when recurring issues occur.
- Inbound (EV downloads → Local DB): Daily or immediate processing for critical products; weekly minimum for routine monitoring.
-
Scheduled reconciliations documented in SOP.
-
Define Roles and Responsibilities
- Reconciliation Owner: accountable for performing reconciliation.
- Case Processor: resolves discrepancies and corrects submissions.
- Quality Reviewer: verifies closure and signs off.
-
QPPV: receives monthly KPI summary and any escalations.
-
Standardise Reconciliation Log Structure
- Minimal columns:
- Local Case ID
- EV Case/Message ID
- Reporter Country
- Suspected Product
- Transmission Date
- EV Ack Status
- Reconciliation Date
- Discrepancy Description
- Action Taken
- Responsible Person
- Closure Date
- Reference to Supporting Files (hyperlinks)
-
Use time‑stamped entries and version control.
-
Discrepancy Workflow
- Triage: classify discrepancy (transmission rejected, missing local link, duplicate).
- Investigation: root cause analysis documented within 5 working days.
- Correction/Resubmission: target within 10 working days for non‑critical; sooner for critical cases.
-
CAPA trigger: repeating discrepancy (e.g., >3 similar events in 3 months) automatically triggers CAPA review.
-
Evidence and Audit Trail
- Store screenshots of EV searches showing message IDs.
- Save EV acknowledgement XMLs or receipts.
- Maintain exported reconciliation reports (PDF/CSV) in quality system.
-
Preserve case audit trails from safety database.
-
Example Reconciliation Cadence (Operational)
- Daily: Monitor EV acknowledgements; triage rejections immediately.
- Weekly: Reconcile inbound downloads to local DB; escalate unresolved items.
- Monthly: Full reconciliation of all outbound submissions against EV; QPPV review of summary metrics.
- Quarterly: Trend analysis of discrepancies and CAPA effectiveness.
Concrete Metrics and KPIs with Expected Tolerances
Below are practical KPIs tailored to EudraVigilance operations. Each KPI includes definition, frequency, target (expected tolerance), evidence, and suggested escalation/CAPA threshold. Targets should be adapted to company size, product portfolio risk and regulatory expectations; the examples below are defensible baselines aligning with GVP and common inspection expectations.
- KPI: On‑time Submission Rate (Serious ICSRs)
- Definition: Percent of serious individual case safety reports (ICSRs) submitted to EV within regulatory timelines from receipt/awareness.
- Frequency: Weekly and monthly reporting.
- Target: ≥ 98% within timeline; action threshold < 95%.
- Evidence: Submission logs, timestamps, case files.
-
Inspection relevance: Inspectors will sample late submissions and expect documented cause/CAPA.
-
KPI: Acknowledgement Resolution Time
- Definition: Median time from receipt of a rejection/accepted‑with‑warning acknowledgement to documented resolution (correction and re‑submission or decision).
- Frequency: Weekly monitoring; monthly report.
- Target: Median ≤ 3 working days; 95th percentile ≤ 10 working days.
- Evidence: Acknowledgement monitoring log, correction records, EV re‑submission receipts.
-
Escalation: If median > 3 days or > 10 unresolved rejections at month end, escalate to QPPV.
-
KPI: Reconciliation Completion Rate
- Definition: Percent of planned reconciliations completed on schedule (e.g., monthly reconciliations completed by 10th working day of next month).
- Frequency: Monthly.
- Target: 100% completion; minimum acceptable 95%.
- Evidence: Reconciliation logs and closure notes.
-
Inspection relevance: Inspectors expect routine and timely reconciliations.
-
KPI: Reconciliation Discrepancy Closure Time
- Definition: Average time to close reconciliation discrepancies.
- Frequency: Monthly with trend chart.
- Target: Mean ≤ 14 calendar days; 90th percentile ≤ 30 days.
- Evidence: Reconciliation logs, investigation and CAPA records.
-
CAPA trigger: Repeating discrepancies for same cause exceeding 5 occurrences in a quarter.
-
KPI: EV Download Processing Time
- Definition: Percent of downloaded EV cases processed into local safety database within target timeframe.
- Frequency: Weekly/monthly.
- Target: ≥ 95% processed within 5 working days of download.
- Evidence: EV download logs and local DB case creation timestamps.
-
Inspection relevance: Demonstrates timely handling of inbound regulatory reports.
-
KPI: Literature Case Processing Timeliness
- Definition: Percent of identified literature cases assessed and submitted (if qualifying) within required timelines.
- Frequency: Monthly.
- Target: ≥ 95% for qualifying literature ICSRs submitted within appropriate timelines.
-
Evidence: Literature screening logs, database entries, submission receipts.
-
KPI: Vendor Performance (if delegated)
- Definition: SLA compliance for vendor‑provided EV activities (e.g., % of cases processed within vendor SLA).
- Frequency: Monthly.
- Target: ≥ 98% SLA adherence; < 95% triggers escalation.
- Evidence: Vendor performance reports, SLAs, oversight meeting minutes.
-
Inspection relevance: Inspectors will verify that outsourcing does not degrade compliance and that MAH oversight is active.
-
KPI: Access Management Compliance
- Definition: Percent of required access reviews completed on schedule; percent of termination/role change actions completed within defined timeframe.
- Frequency: Quarterly.
- Target: 100% access reviews completed; user deactivation within 3 working days of termination.
-
Evidence: Access logs, HR change notifications, review sign‑offs.
-
KPI: Signal Review Timeliness
- Definition: Percent of EVDAS signals or internal signal triggers reviewed within target (e.g., 30 days).
- Frequency: Monthly.
- Target: ≥ 95% within 30 calendar days.
-
Evidence: EVDAS review logs, meeting minutes, decisions and follow‑up actions.
-
KPI: CAPA Implementation and Effectiveness
- Definition: Percent of CAPAs implemented by planned date and percent of CAPAs verified effective at follow‑up.
- Frequency: Quarterly.
- Target: 100% implemented by planned date; ≥ 90% effective at verification.
- Evidence: CAPA records, verification reports.
Presentation and Governance of KPIs - KPI Dashboard: Maintain a monthly dashboard with trend lines (3–12 months) and traffic light indicators (Green/Amber/Red). Each red KPI must include immediate action plan and QPPV summary. - Escalation Matrix: Define clear escalation levels (Operational Lead → Head of PV → QPPV) with thresholds linked to KPI breaches. - Minutes: Archive governance meeting minutes where KPIs and risks are discussed; QPPV must attend or be briefed.
Regulatory Context - KPI selection and tolerances should reflect GVP Modules I, VI and IX and Commission Implementing Regulation (EU) No 520/2012 requirements for submission and database interaction. - Inspectors will expect metrics to map to regulatory timelines and demonstrate control and continuous monitoring.
Governance Considerations and Inspection Relevance
Robust governance ties operational controls to oversight and decision making. The following governance artefacts are frequently reviewed in inspections.
- Roles and Accountability
- Ensure RACI matrices explicitly identify responsibilities for: triage, case processing, EV submission, acknowledgement monitoring, reconciliation, signal assessment, vendor oversight and KPI reporting.
-
QPPV accountability: sign‑off on major decisions, view of high‑level metrics, authority to require immediate remedial actions.
-
Escalation Pathways
- Define escalation thresholds (e.g., number/percentage of late reports, unresolved rejections, vendor SLA breaches).
-
Document required actions at each escalation level and evidence of execution.
-
Oversight Cadence
- Operational daily monitoring (acknowledgements).
- Weekly operational review (backlog, rejections).
- Monthly governance review (KPIs, reconciliation summary, deviations).
-
Quarterly senior management/PV risk review (trend and CAPA effectiveness).
-
Quality Assurance and Audit
- Schedule periodic PV system audits that include EV processes and reconciliation evidence.
-
Use audit findings to inform risk‑based quality improvement and to test KPI reliability.
-
Record Retention and Accessibility
- Maintain indexed inspection packs (electronic binder) per the inspection checklist.
-
Ensure rapid retrieval (within minutes to hours) of requested case traces during on‑site inspections.
-
Training and Competency
- Maintain role‑based training records focused on EV processes, acknowledgement handling, reconciliation procedures and regulatory timelines.
- Evidence of periodic competency checks and refreshers.
Inspection Relevance - Inspectors will sample cases, review reconciliations and test KPI reliability. Demonstrating a living governance system — not only checklists — is critical. - Presenting objective metrics with trend analysis and active management responses is more persuasive than ad hoc narrative explanations. - Prepare to demonstrate closure of previous inspection findings with documented effectiveness verification.
Practical Tips for Inspection Presentation (Operational)
- Prepare a small set of representative case traces that collectively demonstrate:
- A serious spontaneous ICSR with timely submission and reconciliation.
- A rejected EV transmission with investigation and corrective action.
- An EV download processed and linked to a local case.
- A vendor‑processed case with documented oversight.
- Create a one‑page timeline for each trace, with hyperlinks to each supporting document.
- Maintain an index mapping checklist items to file names and locations.
- Ensure KPI dashboards are exportable (PDF/printed) and show the period relevant to the inspection.
Root Causes and CAPA Emphasis (Condensed)
Findings often stem from common root causes: resource constraints, weak governance, poor procedural design, inadequate training and lack of monitoring. CAPAs should be measurable, time‑bound and include effectiveness checks tied to KPIs (e.g., reduction in late submissions from X% to target Y% over Z months).
Key Takeaways
- Convert high‑level observations into inspection‑ready artefacts: checklist items, reconciled case traces and KPI evidence.
- Implement systematic reconciliation processes with documented logs, roles and closure timelines.
- Use concrete KPIs with tolerances, escalation thresholds and governance to demonstrate control.
- QPPV oversight should be evidenced by KPI reviews, escalations and recorded decisions.
- Inspectors expect traceability, prompt acknowledgement handling and effective vendor oversight.
References
- EMA Good Pharmacovigilance Practices (GVP) Module III – Pharmacovigilance Inspections.
- EMA Good Pharmacovigilance Practices (GVP) Module I – Pharmacovigilance Systems and Their Quality Systems.
- EMA Good Pharmacovigilance Practices (GVP) Module VI – Collection, Management and Submission of Reports of Suspected Adverse Reactions.
- EMA Good Pharmacovigilance Practices (GVP) Module IX – Signal Management.
- Regulation (EC) No 726/2004.
- Directive 2001/83/EC.
- Commission Implementing Regulation (EU) No 520/2012.