EudraVigilance Registration and Access Management

EudraVigilance access is built around registered organisations, individual EMA accounts and role-based approvals. This article explains the current EMA Account Management and Organisation Management Service workflow, the roles of the QPPV or responsible person, trusted deputies, EVDAS and level 2B access, transmission modes, training and lifecycle controls.

Take test

EudraVigilance Registration and Access Management

EudraVigilance registration is not simply the creation of a username. Access depends on the relationship between a registered organisation, an identifiable individual, the regulatory role that individual performs and the permissions needed for that role. The model is designed to support accountability, privacy, data integrity and controlled access to pharmacovigilance information.

Since 2018, EudraVigilance human registration has been integrated with EMA Account Management and the Organisation Management Service (OMS) in the SPOR environment. Current registration therefore begins with two distinct identities: the organisation must exist in OMS and the individual must have an active EMA account. EudraVigilance roles are then requested and approved within that framework.

Why Registration and Access Matter

EudraVigilance supports electronic ICSR exchange and access to regulatory safety data. Different functions expose different capabilities and levels of information. A user who submits an ICSR, a user who reviews EVDAS outputs and a user with level 2B access to case narratives do not necessarily need the same permissions.

The governance objective is therefore least necessary access with clear accountability, while also ensuring that critical pharmacovigilance activities can continue during absence, organisational change or technical disruption.

The Current Registration Architecture

The registration process can be understood as five connected layers:

EMA account → OMS organisation → EudraVigilance organisation registration → user role → application-specific access.

EMA account

Every user needs an active EMA account. Users who already access other EMA-hosted applications normally use the same credentials rather than creating a separate EudraVigilance identity.

The account identifies the individual. It should not be shared, and access should remain attributable to the person performing the activity.

Organisation Management Service

Organisations register electronically in OMS through the SPOR portal. Headquarters, affiliates and virtual affiliates are represented according to the EudraVigilance registration model and current registration manual.

The OMS record establishes the organisational identity that is later linked to EudraVigilance roles and responsibilities. Errors in organisation structure can therefore affect access, partner identification and user administration.

EudraVigilance organisation registration

The organisation then completes the EudraVigilance registration steps and provides the required registration documentation. The detailed process varies according to stakeholder type and reporting mode.

Marketing authorisation holders, sponsors and national competent authorities have different responsible roles. Third-party service providers do not simply register as independent production MAHs; where they provide EudraVigilance services, their access is linked to the organisation on whose behalf they act according to the current EMA model.

QPPV, Responsible Person and Regulatory Contact Point

For a marketing authorisation holder, the EU QPPV is a central EudraVigilance registration role. EMA states that the QPPV must be registered in EudraVigilance. Commercial and non-commercial sponsors and national competent authorities nominate a responsible person (RP) for EudraVigilance.

These roles are not interchangeable merely because both administer access. Their regulatory context differs: the QPPV role arises from medicines pharmacovigilance legislation for MAHs, whereas the RP is the designated EudraVigilance responsible role for other stakeholder groups.

MAHs must also provide a regulatory contact point. EMA allows this to be an individual or a department, and the QPPV can maintain those details in the EudraVigilance restricted area.

Changes in QPPV or responsible person

EMA's current registration guidance states that when the QPPV or RP changes, the organisation should nominate a replacement within 10 calendar days. The existing QPPV/RP should not be removed from EudraVigilance until the replacement is registered.

This is an important continuity control because the QPPV/RP role carries user-administration and access-approval responsibilities in the EudraVigilance model.

Trusted Deputies

The QPPV or RP can delegate specified user-registration and affiliate-registration functions to a trusted deputy within the same organisation. The trusted deputy role is an EMA access-management construct; it should not be confused automatically with an organisation's broader "Deputy QPPV" continuity arrangement.

A trusted deputy can support user and affiliate administration and, where permitted, approve certain access requests. Delegation should remain controlled so that the organisation can explain who has authority to approve access and why.

User Roles and Application-Specific Access

Once the organisation is registered, individual users request the EudraVigilance role that matches their work. The approval path depends on the organisation and role. General users typically request access through EMA Account Management and await approval by the organisation's QPPV or RP; users working through a contract research organisation or other service provider may require contributor-type access linked to each organisation they support.

The key governance principle is that access follows responsibility. A user's job title alone should not determine privileges.

EVWEB Access

EVWEB is EMA's web interface for creating, sending and viewing ICSRs and acknowledgement messages and for performing related queries. It can be used as a primary reporting route or, depending on organisational design, as a contingency route.

Organisations using EVWEB are often called webtraders in EMA documentation. The current registration and electronic-reporting guidance should be consulted because the required setup differs from gateway trading.

EVWEB access should be limited to users who need the functions. Where EVWEB is used as a contingency route, governance should confirm that appropriately trained users can actually access it when the gateway or local system is unavailable.

EVDAS Access

The EudraVigilance Data Analysis System (EVDAS) provides authorised access to analytical outputs used in signal management. Users request the EVDAS role through the Manage Access area of their EMA account and await approval by the organisation's QPPV or RP.

For MAHs, EVDAS access does not mean unrestricted access to every detail of every ICSR. EMA's EudraVigilance access policy defines levels of data access according to stakeholder and purpose.

Access should therefore be governed in relation to actual signal-management responsibilities. If a user changes role and no longer performs signal work, continued EVDAS access should be reassessed.

Level 2B Access

Level 2B is an additional MAH access right that can be assigned by the QPPV or trusted deputy to registered EVWEB or EVDAS users. It includes access to case narratives in accordance with the EudraVigilance access policy and may be used to support signal management or other pharmacovigilance assessment where review of ICSR detail is warranted.

Because level 2B provides more detailed case information, its assignment should be purposeful and traceable. The fact that a user already has EVDAS access does not automatically mean that level 2B is required.

Production and XCOMP

EudraVigilance has production and external compliance testing (XCOMP) environments. Current EMA registration arrangements allow MAHs, NCAs and sponsors to use the same single-sign-on identity for both, with the organisation's production registration creating an XCOMP profile under the current self-service model.

The environments have different purposes:

IT vendors and third-party service providers can use XCOMP for testing according to EMA's vendor-registration rules even where they are not eligible to register independently as production MAHs or sponsors.

Reporting Mode: EVWEB, Gateway and EV Post

Organisations can report electronically through the modes supported by EMA. Broadly, these include EVWEB/webtrader use and gateway or EV Post approaches.

Gateway reporting requires additional technical setup and quality-assurance testing because the organisation's system exchanges E2B(R3) messages directly with EMA. EMA's current electronic-reporting page sets out different testing steps for new gateways, EVWEB users, major changes and third-party service providers.

A user profile configured as a gateway trader is not simply interchangeable with an EVWEB webtrader profile. EMA specifically notes that organisations wishing to use EVWEB or EVPOST in addition to gateway trading may need an appropriate Affiliate or Virtual Affiliate webtrader profile.

This distinction is operationally important when designing business continuity. A contingency route is only real if the required organisation profile, user roles, training and procedures are already in place.

Training and Competency

Training requirements depend on the activity. EMA provides formal EudraVigilance training and support modules, including training on registration, system components, E2B(R3), EVWEB and EVDAS.

For organisations intending to register a first-user QPPV/RP or begin EVWEB ICSR reporting for the first time, EMA requires evidence that at least one user has successfully completed the applicable competency assessment or knowledge evaluation before the organisation can initiate electronic reporting in production.

This is more specific than the generic statement that "all EudraVigilance users require certification". Organisations should identify the exact EMA training or competency requirement for each function and supplement it with role-specific internal training where needed.

Access Lifecycle Management

Good access governance extends through the full joiner-mover-leaver lifecycle.

Joiners

Before access is approved, the organisation should understand the user's role, required application, necessary level of detail and training status. Privileges should not be copied automatically from another employee merely because job titles match.

Movers

A role change can require both new access and removal of old privileges. Moving from case processing to a non-PV function, for example, may remove the need for EVWEB or EVDAS even if the individual remains employed by the same company.

Leavers

Access should be removed promptly when the user no longer requires it. The organisation's procedure should connect HR, identity management and pharmacovigilance administration sufficiently to prevent orphaned access.

Periodic review

Periodic review of EudraVigilance access is good operational practice because role changes are not always captured perfectly by event-driven processes. However, EMA does not prescribe a universal quarterly or annual access-review frequency for every MAH. The interval should be defined and justified within the organisation's quality system.

Segregation of Duties and Accountability

EudraVigilance itself is role-based, but pharmacovigilance organisations should also consider how access interacts with their internal process. A user may have technical capability to perform several actions without necessarily being authorised by company procedure to make all associated decisions.

Segregation of duties should therefore be risk-based. Small organisations may be unable to separate every technical and quality role; where that occurs, compensating controls such as independent review, audit-trail monitoring or secondary approval may provide appropriate assurance.

The important point is not to impose a generic segregation model. It is to ensure that access does not undermine accountability, independent review or data integrity in the organisation's actual process.

Outsourced Users and Service Providers

CROs, vendors and other service providers may need EudraVigilance access to act on behalf of an MAH or sponsor. Current EMA guidance distinguishes these arrangements from direct production registration of the service provider as though it were the regulatory party.

Governance should establish:

The contractual relationship and the EudraVigilance role assignment should describe the same operational reality.

Business Continuity

Access management can become a patient-safety and compliance issue when only one person can perform a critical function. Continuity planning should consider whether the organisation has sufficient trained and authorised users for:

The existence of a deputy on an organisation chart is not sufficient if the individual lacks the necessary EMA role, training or system access at the time of an incident.

Potential Failure Modes

The following are illustrative scenarios rather than reported inspection findings.

A user has an EMA account but no valid organisational role

The employee can authenticate to EMA services but has not been linked to the correct EudraVigilance organisation or role. Authentication is therefore mistaken for authorisation.

A QPPV change creates an administration gap

The outgoing QPPV is removed before the replacement is registered, leaving the organisation without the expected approval path for user management. EMA's current 10-calendar-day replacement guidance and continuity rule are designed to prevent this situation.

EVDAS access persists after role change

A former signal scientist moves to another function but retains EVDAS and level 2B access because only HR systems were updated. Periodic review later identifies the discrepancy.

A gateway contingency plan assumes EVWEB access

The SOP states that EVWEB will be used during gateway failure, but the organisation has no webtrader profile or currently trained EVWEB users. The contingency exists on paper only.

Service-provider access is not tied to the MAH relationship

A contractor retains contributor access after the service agreement ends because offboarding between procurement, PV and access administration is not connected.

Inspection and Governance Considerations

An inspector or auditor may test whether the access model supports actual pharmacovigilance responsibilities. Potential questions include:

These are illustrative questions, not a prescribed inspection checklist.

Practical Access Review Checklist

A periodic or event-driven access review should be able to establish that:

Key Takeaways

EudraVigilance registration is an organisational and regulatory identity model, not just a password-management process. The current framework connects individual EMA accounts with OMS-registered organisations and EudraVigilance-specific roles.

For MAHs, the EU QPPV is a formal EudraVigilance registration role. Sponsors and NCAs use a responsible person. Trusted deputies can support delegated registration functions, while EVDAS and level 2B access require additional role approval according to EMA's access model.

Access governance should follow the user lifecycle and the pharmacovigilance process. The practical test is whether each person has the access needed to perform their regulated role—no more, no less—and whether critical activities can continue when people, vendors or systems change.

References

  1. European Medicines Agency. EudraVigilance: how to register. Current organisation, user, QPPV/RP, trusted-deputy, EVDAS and level 2B access guidance. https://www.ema.europa.eu/en/human-regulatory-overview/research-and-development/pharmacovigilance-research-and-development/eudravigilance/eudravigilance-how-register
  2. European Medicines Agency. EudraVigilance registration manual. EMA/13454/2020 Rev. 16, last updated 23 May 2025, available from the EudraVigilance electronic-reporting and registration pages.
  3. European Medicines Agency. EudraVigilance training and support. https://www.ema.europa.eu/en/human-regulatory-overview/research-development/pharmacovigilance-research-development/eudravigilance/eudravigilance-training-support
  4. European Medicines Agency. EudraVigilance system overview. https://www.ema.europa.eu/en/human-regulatory-overview/research-development/pharmacovigilance-research-development/eudravigilance/eudravigilance-system-overview
  5. European Medicines Agency. EudraVigilance: electronic reporting. https://www.ema.europa.eu/en/human-regulatory-overview/research-development/pharmacovigilance-research-development/eudravigilance/eudravigilance-electronic-reporting
  6. European Medicines Agency. EudraVigilance user manual for marketing authorisation holders — EVDAS access, EMA/167839/2016 Version 2.1, available from EMA training and support.
  7. European Medicines Agency. GVP Module I – Pharmacovigilance systems and their quality systems. EMA/541760/2011.

Regulatory Note

This article reflects EMA's current EudraVigilance human-registration model as available in September 2026. EMA accounts, OMS registration, QPPV/RP roles, EVDAS and level 2B access are described according to EMA procedural guidance. Internal access-review frequency, segregation models, continuity arrangements and review checklists are recommended operational practices unless a specific regulatory or EMA procedural requirement applies. Because registration processes and application roles can change, organisations should verify the current EMA registration manual and online guidance before implementing or changing access.

Revision History

Last reviewed: 2026-09-07