EudraVigilance Registration and Access Management

Understanding EudraVigilance registration, user management, access governance, training requirements and QPPV oversight responsibilities.

Audio Lesson 10 min

EudraVigilance Registration and Access Management

Introduction

Access to EudraVigilance is controlled by the European Medicines Agency (EMA).

Before organisations can submit reports, download data, access EVDAS outputs or perform other authorised activities, both the organisation and its users must complete the appropriate registration and training requirements.

Although registration is often viewed as an administrative task, access governance forms an important component of pharmacovigilance compliance.

Poor control of user access can create operational, compliance, security and inspection risks.

For QPPVs, understanding how access is governed is important because EudraVigilance access directly supports reporting compliance, signal management and safety surveillance activities.

Why Registration Matters

EudraVigilance contains sensitive regulatory information.

Access must therefore be controlled to ensure:

The registration process helps ensure that only authorised individuals gain access to the system.

Organisational Registration

Before users can access EudraVigilance, an organisation must be registered.

The registration process establishes:

Examples of organisations requiring registration may include:

Registration requirements may vary depending on organisational role and intended use of the system.

Regulatory context: organisational registration links to obligations under Regulation (EC) No 726/2004, Directive 2001/83/EC and implementing acts for pharmacovigilance. EMA requirements for organisational identifiers, authorised contacts and declaration of responsibilities support traceability and accountability expected under GVP Module I.

User Registration

Individual users must also be registered.

Registration generally requires:

User accounts should never be shared between individuals.

Access should always be attributable to a specific user.

Regulatory context: individual accountability and training are requirements consistent with GVP Module I and local competent authority expectations. Evidence of identity verification and training readiness is routinely requested during inspections.

Role-Based Access

EudraVigilance access is role-based.

Different users may receive different permissions depending on their responsibilities.

Examples may include:

Role-based access helps ensure that users receive only the permissions required to perform their duties.

A clear role-permission matrix and documented justification for privileged roles form important elements of pharmacovigilance governance and are commonly inspected.

Training Requirements

Training forms an important component of EudraVigilance access management.

Before obtaining access, users may be required to complete applicable EMA training programmes.

Training helps ensure that users understand:

Organisations should maintain evidence of training completion where appropriate.

During inspections, auditors will typically request training records linked to active EudraVigilance users.

Access Lifecycle Management

Access governance should extend beyond initial registration.

Effective lifecycle management includes:

Access controls should reflect organisational changes as they occur.

Procedural clarity and demonstrable execution of lifecycle steps (with audit trails) are essential for inspection readiness.

Periodic Access Reviews

Periodic review of user access is considered good governance practice.

Reviews may assess:

Periodic review helps identify access that is no longer required.

Inspection relevance: competent authorities expect documented periodic access review outcomes, evidence of corrective actions and retention of review records.

Segregation of Duties

Organisations should consider whether access assignments create inappropriate concentrations of responsibility.

Examples may include situations where a single user can:

Appropriate segregation of duties may help reduce compliance risks.

During inspections, auditors will look for separation between operational reporting users and oversight/approval roles, or for formal compensating controls when segregation cannot be achieved.

Access Governance and Data Integrity

Access controls contribute directly to data integrity.

Poorly controlled access may increase the risk of:

Governance controls help maintain confidence in system data.

Relationship with EVDAS

Access governance also affects EVDAS activities.

Users performing signal detection activities require appropriate access to analytical outputs.

Organisations should understand:

For more information see:

[[evdas-and-signal-detection]]

Relationship with Reporting Activities

Reporting users require access appropriate to their responsibilities.

This may include:

Access should align with operational responsibilities.

For additional information see:

[[eudravigilance-reporting]]

QPPV Oversight

The QPPV is not usually responsible for creating user accounts.

However, regulators generally expect the QPPV to understand:

The QPPV should have confidence that access controls support pharmacovigilance compliance.

QPPV responsibilities should be recorded in governance documentation and may be tested during inspections by requesting evidence of QPPV oversight interactions and decisions.

Inspection Perspective

Inspectors may review access governance during pharmacovigilance inspections.

Review activities may include:

Inspectors often seek evidence demonstrating that access is appropriately controlled and periodically reviewed.

Common inspection findings include inactive users retaining access, missing access reviews, inadequate documentation, unclear responsibilities, training deficiencies and weak governance controls. Many findings arise because access management is viewed as an IT activity rather than a pharmacovigilance governance activity.

Governance Expectations

Governance for EudraVigilance registration and access should be formalised in SOPs, work instructions and role descriptions. Key governance elements include:

Regulatory context: governance should align with GVP Module I – Pharmacovigilance Systems and Their Quality Systems and relevant EU legislation. Inspectors expect a documented governance framework complete with assigned roles, responsibilities and documented, demonstrably followed procedures.


Practical Checklist — Inspection-Ready (Operational)

This practical checklist identifies the records and demonstrations that inspectors commonly require. Keep these items current, indexed and readily retrievable.

Preparation (organisational)

User onboarding and accounts

Access lifecycle and reviews

Technical and audit records

Retention and recordkeeping

Inspection requests (what inspectors will typically ask for)

Operational readiness: ensure the checklist items are available in electronic form, indexed and the responsible owners are able to present them within the inspection timeframe.


Role–Permission Table (Operational Matrix)

The table below is a practical, example role–permission matrix for EudraVigilance. Organisations should adapt the matrix to their internal processes and apply the principle of least privilege. For inspection purposes, provide the organisation-specific matrix showing who holds each role and justification for any exceptions.

Role name Create ICSRs Submit ICSRs Acknowledge / Receive Messages Download EVDAS Outputs View EVDAS Analyses Manage Users (Org Admin) Configure Org Details View Audit Trail / Logs Approve Access Requests Comment / Review Reports
Organisation Administrator (Org Admin)
System Administrator (IT) ✓* ✓*
Safety/Reporting User
EVDAS Analyst / Signal Analyst
QPPV / Delegate
Compliance Auditor / Reviewer
External PV Service Provider (limited) (limited) (limited) (by agreement) (by agreement)

Notes: - ✓ = permission normally granted; ☐ = normally not granted - *IT System Administrator should have technical account management rights but no access to perform safety operations unless specifically authorised and documented (compensating controls required). - External providers must have written contracts defining permitted activities and must be reflected in the organisation's user list and governance documentation. - For inspection: provide the populated matrix that maps real users to these roles, including justification and contract references for external users.


Step-by-Step Procedures — Registration (Organisation and User)

These stepwise procedures are intended to be integrated into SOPs and used as a checklist for each registration event. Document each step and retain records.

A. Organisation Registration (typical steps)

  1. Identify need for registration (new MAH, sponsor, service provider). Record business justification.
  2. Gather required documentation:
  3. Legal entity identifier and proof of legal status
  4. Marketing authorisation numbers (if applicable)
  5. Authorised signatory details
  6. QPPV contact details and delegated safety contacts
  7. Contractual documentation for third-party providers
  8. Nominate Organisation Administrator(s) and record their details.
  9. Complete EMA organisation registration process (submit required forms electronically via the EMA-provided mechanism).
  10. Receive and record EMA registration confirmation (reference number and effective date).
  11. Update internal systems and governance documents to reflect registration (SOPs, governance matrix, DMS).
  12. Notify stakeholders (QPPV, PV lead, IT security, HR) and publish internal guidance for onboarding users.

Records to retain: registration submission form, confirmation, correspondence with EMA, internal approval and governance updates.

B. User Registration and Account Creation (typical steps)

  1. Access request initiation:
  2. User completes an access request form or raises a ticket in the access management system.
  3. Request includes justification, requested role(s), start date, and line manager approval.
  4. Identity verification:
  5. Confirm identity via HR records and corporate email; for contractors, obtain identity and contractual authorisation.
  6. Training verification:
  7. Verify completion of required EMA and internal EudraVigilance training modules.
  8. For new users, schedule or confirm completion prior to submission of access.
  9. Approval workflow:
  10. Org Admin reviews request for completeness and appropriateness.
  11. QPPV or nominated delegate reviews and approves role if required by governance (for reporting or privileged roles).
  12. Creation of account:
  13. Org Admin or authorised technical admin creates user account in EudraVigilance.
  14. System captures metadata: creator, approver, timestamp, role assigned.
  15. First login and verification:
  16. User performs initial login, accepts terms of use and completes any mandatory system checks (e.g., two-factor authentication).
  17. Record creation:
  18. Save access request form, approvals, training evidence, and user account metadata in the designated DMS.
  19. Communicate access:
  20. Notify user of access details and responsibilities; provide quick-reference guidance.

Records to retain: access request form, approval emails/signatures, training certificates, user creation logs, initial login confirmation.


Step-by-Step Procedures — Periodic Review and Role Changes

A. Periodic Access Review (recommended cadence defined in SOP; typical 6–12 months)

  1. Schedule and ownership:
  2. PV Access Owner schedules review and notifies stakeholders (Org Admin, QPPV).
  3. Extract data:
  4. Produce an export of current users and assigned roles from EudraVigilance.
  5. Supplement with internal HR data (employment status, contract end dates).
  6. Review criteria:
  7. Active employment/contract status
  8. Appropriateness of assigned role(s) given current duties
  9. Training currency (within defined validity period)
  10. Volume and nature of system activity (identify dormant or unusual accounts)
  11. Triage findings:
  12. For each discrepancy, document required action: deactivate, change role, re-train, or justify retention.
  13. Approval and remediation:
  14. Org Admin executes account changes following documented approvals.
  15. QPPV or delegate approves exceptions where required.
  16. Reporting:
  17. Produce a signed review report listing reviewers, date, actions taken and outstanding items.
  18. Record retention:
  19. Store review report and evidence of changes in DMS.

Inspection relevance: ensure the review report clearly maps to the user export and documents the outcome for each account.

B. Role Changes, Suspensions and Terminations

  1. Trigger event:
  2. Role change may be triggered by HR update, organisational re-assignment, termination or security incident.
  3. Access change request:
  4. Submit a change request with reason, requested new role or deactivation date, and approvers.
  5. Approvals:
  6. Line manager and Org Admin must approve role changes; QPPV approves safety-critical role changes when appropriate.
  7. Change execution:
  8. Org Admin or authorised personnel makes changes in EudraVigilance and captures timestamp and approver.
  9. Evidence capture:
  10. Save change request, approvals and post-change confirmation in DMS.
  11. Post-change verification:
  12. Conduct a follow-up check to verify that access aligns with the new role and that no unintended permissions remain.
  13. Incident handling:
  14. For security incidents, immediately suspend accounts pending investigation and document actions.

Records to retain: change request, approvals, activity logs showing change, post-change verification.


Step-by-Step Procedures — Recordkeeping, Retrieval and Retention

Well-structured recordkeeping is essential for regulatory accountability and inspection readiness.

A. What to record

B. How to store records (practical implementation)

C. Retention considerations and regulatory context

D. Retrieval and inspection readiness


Roles and Responsibilities (Governance Mapping)

Clear governance and accountability reduce inspection risk. The table below summarises recommended role responsibilities; these should be reflected in SOPs and the organisation’s governance matrix.

Inspection relevance: inspectors will commonly ask for the governance matrix and evidence that the persons listed actually execute the responsibilities assigned.


Examples of Inspection Evidence Packages

Prepare reusable evidence packages that can be tailored when an inspection is announced. Examples:

  1. Evidence package for sample reporting user:
  2. Access request form and approval
  3. Identity verification (HR record)
  4. Training certificates (EMA + internal)
  5. User creation log (timestamp + creator)
  6. Recent activity log extract showing submissions
  7. Record of any role changes

  8. Evidence package for privileged administrator:

  9. Role justification and approval
  10. Contractual or internal delegation documentation
  11. Periodic review records and compensating controls (if segregation cannot be achieved)
  12. Audit trail entries for admin actions
  13. Incident handling records (if applicable)

  14. Evidence package for periodic review:

  15. User export used for the review
  16. Review worksheet and checklist
  17. Signed review report and action log
  18. Evidence of execution of actions (deactivation logs, training assignments)

Practical Implementation Tips (Operationalise SOPs)


Key Takeaways

References

  1. EMA EudraVigilance Registration Manual.
  2. EMA EudraVigilance Training Materials.
  3. Regulation (EC) No 726/2004.
  4. Directive 2001/83/EC.
  5. Commission Implementing Regulation (EU) No 520/2012.
  6. GVP Module I – Pharmacovigilance Systems and Their Quality Systems.
  7. EMA EudraVigilance Documentation.

Last reviewed: 2026-06-11