EudraVigilance Registration and Access Management
- EudraVigilance Registration and Access Management
- Introduction
- Why Registration Matters
- Organisational Registration
- User Registration
- Role-Based Access
- Training Requirements
- Access Lifecycle Management
- Periodic Access Reviews
- Segregation of Duties
- Access Governance and Data Integrity
- Relationship with EVDAS
- Relationship with Reporting Activities
- QPPV Oversight
- Inspection Perspective
- Governance Expectations
- Practical Checklist — Inspection-Ready (Operational)
- Role–Permission Table (Operational Matrix)
- Step-by-Step Procedures — Registration (Organisation and User)
- Step-by-Step Procedures — Periodic Review and Role Changes
- Step-by-Step Procedures — Recordkeeping, Retrieval and Retention
- Roles and Responsibilities (Governance Mapping)
- Examples of Inspection Evidence Packages
- Practical Implementation Tips (Operationalise SOPs)
- Key Takeaways
- References
Introduction
Access to EudraVigilance is controlled by the European Medicines Agency (EMA).
Before organisations can submit reports, download data, access EVDAS outputs or perform other authorised activities, both the organisation and its users must complete the appropriate registration and training requirements.
Although registration is often viewed as an administrative task, access governance forms an important component of pharmacovigilance compliance.
Poor control of user access can create operational, compliance, security and inspection risks.
For QPPVs, understanding how access is governed is important because EudraVigilance access directly supports reporting compliance, signal management and safety surveillance activities.
Why Registration Matters
EudraVigilance contains sensitive regulatory information.
Access must therefore be controlled to ensure:
- Appropriate use
- Data integrity
- User accountability
- Security
- Regulatory compliance
The registration process helps ensure that only authorised individuals gain access to the system.
Organisational Registration
Before users can access EudraVigilance, an organisation must be registered.
The registration process establishes:
- Organisation identity
- Regulatory role
- Authorised contacts
- Administrative responsibilities
Examples of organisations requiring registration may include:
- Marketing Authorisation Holders
- Sponsors
- National Competent Authorities
- Pharmacovigilance service providers
- Regulatory partners
Registration requirements may vary depending on organisational role and intended use of the system.
Regulatory context: organisational registration links to obligations under Regulation (EC) No 726/2004, Directive 2001/83/EC and implementing acts for pharmacovigilance. EMA requirements for organisational identifiers, authorised contacts and declaration of responsibilities support traceability and accountability expected under GVP Module I.
User Registration
Individual users must also be registered.
Registration generally requires:
- User identification
- Contact information
- Role assignment
- Training completion
- Approval workflows
User accounts should never be shared between individuals.
Access should always be attributable to a specific user.
Regulatory context: individual accountability and training are requirements consistent with GVP Module I and local competent authority expectations. Evidence of identity verification and training readiness is routinely requested during inspections.
Role-Based Access
EudraVigilance access is role-based.
Different users may receive different permissions depending on their responsibilities.
Examples may include:
- Reporting users
- EVDAS users
- Administrators
- Compliance users
- Signal management users
Role-based access helps ensure that users receive only the permissions required to perform their duties.
A clear role-permission matrix and documented justification for privileged roles form important elements of pharmacovigilance governance and are commonly inspected.
Training Requirements
Training forms an important component of EudraVigilance access management.
Before obtaining access, users may be required to complete applicable EMA training programmes.
Training helps ensure that users understand:
- System functionality
- Regulatory expectations
- Reporting processes
- Data handling responsibilities
Organisations should maintain evidence of training completion where appropriate.
During inspections, auditors will typically request training records linked to active EudraVigilance users.
Access Lifecycle Management
Access governance should extend beyond initial registration.
Effective lifecycle management includes:
- User onboarding
- Role changes
- Periodic review
- Suspension where necessary
- User deactivation
Access controls should reflect organisational changes as they occur.
Procedural clarity and demonstrable execution of lifecycle steps (with audit trails) are essential for inspection readiness.
Periodic Access Reviews
Periodic review of user access is considered good governance practice.
Reviews may assess:
- Active users
- Assigned permissions
- Role appropriateness
- Training status
- Dormant accounts
Periodic review helps identify access that is no longer required.
Inspection relevance: competent authorities expect documented periodic access review outcomes, evidence of corrective actions and retention of review records.
Segregation of Duties
Organisations should consider whether access assignments create inappropriate concentrations of responsibility.
Examples may include situations where a single user can:
- Create reports
- Approve reports
- Modify records
- Perform oversight activities
Appropriate segregation of duties may help reduce compliance risks.
During inspections, auditors will look for separation between operational reporting users and oversight/approval roles, or for formal compensating controls when segregation cannot be achieved.
Access Governance and Data Integrity
Access controls contribute directly to data integrity.
Poorly controlled access may increase the risk of:
- Unauthorised changes
- Inappropriate data access
- Operational errors
- Security incidents
Governance controls help maintain confidence in system data.
Relationship with EVDAS
Access governance also affects EVDAS activities.
Users performing signal detection activities require appropriate access to analytical outputs.
Organisations should understand:
- Who has EVDAS access
- Why access is required
- How access is reviewed
For more information see:
[[evdas-and-signal-detection]]
Relationship with Reporting Activities
Reporting users require access appropriate to their responsibilities.
This may include:
- EVWEB access
- Reporting permissions
- Acknowledgement review activities
Access should align with operational responsibilities.
For additional information see:
[[eudravigilance-reporting]]
QPPV Oversight
The QPPV is not usually responsible for creating user accounts.
However, regulators generally expect the QPPV to understand:
- How access is governed
- How users are trained
- How reviews are performed
- How significant issues are escalated
The QPPV should have confidence that access controls support pharmacovigilance compliance.
QPPV responsibilities should be recorded in governance documentation and may be tested during inspections by requesting evidence of QPPV oversight interactions and decisions.
Inspection Perspective
Inspectors may review access governance during pharmacovigilance inspections.
Review activities may include:
- User listings
- Access procedures
- Training records
- Access reviews
- Governance documentation
Inspectors often seek evidence demonstrating that access is appropriately controlled and periodically reviewed.
Common inspection findings include inactive users retaining access, missing access reviews, inadequate documentation, unclear responsibilities, training deficiencies and weak governance controls. Many findings arise because access management is viewed as an IT activity rather than a pharmacovigilance governance activity.
Governance Expectations
Governance for EudraVigilance registration and access should be formalised in SOPs, work instructions and role descriptions. Key governance elements include:
- Defined ownership (e.g., PV Access Owner, Organisation Administrator)
- Clear role definitions and permission mapping
- Approved access request and approval workflows
- Recordkeeping requirements and retention policy
- Periodic review schedule and evidence of execution
- Escalation pathways for non-compliance or security incidents
- Integration with HR and IT change processes
- Audit and monitoring activities, including internal audits
Regulatory context: governance should align with GVP Module I – Pharmacovigilance Systems and Their Quality Systems and relevant EU legislation. Inspectors expect a documented governance framework complete with assigned roles, responsibilities and documented, demonstrably followed procedures.
Practical Checklist — Inspection-Ready (Operational)
This practical checklist identifies the records and demonstrations that inspectors commonly require. Keep these items current, indexed and readily retrievable.
Preparation (organisational)
- Organisational registration confirmation from EMA (registration reference, date)
- Organisational registration form and supporting documents (legal entity ID, MA numbers, proof of authorisation)
- List of authorised organisation contacts and roles (Org Admin(s), Safety Contact, QPPV details)
- Organisation-level SOP(s) for EudraVigilance access and user management
- Governance matrix showing owners of access processes
User onboarding and accounts
- Current extract of all active EudraVigilance users (name, job title, email, role, organisation)
- Evidence of identity verification for each user (HR record, passport copy, business email)
- Training records tied to EudraVigilance access (EMA training completion, internal training sign-off)
- Access request and approval forms for each active account (signed or system-approved)
- Role justification for privileged accounts (business need, duration)
Access lifecycle and reviews
- Periodic access review schedules and completed review reports (date, reviewer, findings)
- Evidence of account changes following role changes, suspensions and terminations
- Dormant account report and remediation evidence (deactivated or justified)
Technical and audit records
- System audit trail extracts showing user activity (for a representative period)
- Records of admin actions (user creation, role changes), including timestamp and approver
- Incident logs related to EudraVigilance access or security (investigation and corrective actions)
- Access rights exception logs and compensating control evidence
Retention and recordkeeping
- Document retention policy referencing applicable regulations and company policy
- Index of stored evidence locations (DMS folder structure, filenames, access controls)
- Archive procedures for decommissioned user records
Inspection requests (what inspectors will typically ask for)
- “Show me all active users and their roles” — provide an export
- “Show training evidence for reporting users” — provide certificates/records
- “Provide your last periodic access review report” — provide documentation
- “Demonstrate how a user was onboarded and later deactivated” — provide the full trail
- “Show your SOP and governance matrix” — provide signed versions and review history
Operational readiness: ensure the checklist items are available in electronic form, indexed and the responsible owners are able to present them within the inspection timeframe.
Role–Permission Table (Operational Matrix)
The table below is a practical, example role–permission matrix for EudraVigilance. Organisations should adapt the matrix to their internal processes and apply the principle of least privilege. For inspection purposes, provide the organisation-specific matrix showing who holds each role and justification for any exceptions.
| Role name | Create ICSRs | Submit ICSRs | Acknowledge / Receive Messages | Download EVDAS Outputs | View EVDAS Analyses | Manage Users (Org Admin) | Configure Org Details | View Audit Trail / Logs | Approve Access Requests | Comment / Review Reports |
|---|---|---|---|---|---|---|---|---|---|---|
| Organisation Administrator (Org Admin) | ☐ | ☐ | ☐ | ☐ | ☐ | ✓ | ✓ | ✓ | ✓ | ☐ |
| System Administrator (IT) | ☐ | ☐ | ☐ | ☐ | ☐ | ✓* | ✓* | ✓ | ☐ | ☐ |
| Safety/Reporting User | ✓ | ✓ | ✓ | ☐ | ☐ | ☐ | ☐ | ☐ | ☐ | ✓ |
| EVDAS Analyst / Signal Analyst | ☐ | ☐ | ☐ | ✓ | ✓ | ☐ | ☐ | ☐ | ☐ | ✓ |
| QPPV / Delegate | ☐ | ☐ | ☐ | ✓ | ✓ | ☐ | ☐ | ✓ | ✓ | ✓ |
| Compliance Auditor / Reviewer | ☐ | ☐ | ☐ | ✓ | ✓ | ☐ | ☐ | ✓ | ☐ | ✓ |
| External PV Service Provider | (limited) | (limited) | (limited) | (by agreement) | (by agreement) | ☐ | ☐ | ☐ | ☐ | ✓ |
Notes: - ✓ = permission normally granted; ☐ = normally not granted - *IT System Administrator should have technical account management rights but no access to perform safety operations unless specifically authorised and documented (compensating controls required). - External providers must have written contracts defining permitted activities and must be reflected in the organisation's user list and governance documentation. - For inspection: provide the populated matrix that maps real users to these roles, including justification and contract references for external users.
Step-by-Step Procedures — Registration (Organisation and User)
These stepwise procedures are intended to be integrated into SOPs and used as a checklist for each registration event. Document each step and retain records.
A. Organisation Registration (typical steps)
- Identify need for registration (new MAH, sponsor, service provider). Record business justification.
- Gather required documentation:
- Legal entity identifier and proof of legal status
- Marketing authorisation numbers (if applicable)
- Authorised signatory details
- QPPV contact details and delegated safety contacts
- Contractual documentation for third-party providers
- Nominate Organisation Administrator(s) and record their details.
- Complete EMA organisation registration process (submit required forms electronically via the EMA-provided mechanism).
- Receive and record EMA registration confirmation (reference number and effective date).
- Update internal systems and governance documents to reflect registration (SOPs, governance matrix, DMS).
- Notify stakeholders (QPPV, PV lead, IT security, HR) and publish internal guidance for onboarding users.
Records to retain: registration submission form, confirmation, correspondence with EMA, internal approval and governance updates.
B. User Registration and Account Creation (typical steps)
- Access request initiation:
- User completes an access request form or raises a ticket in the access management system.
- Request includes justification, requested role(s), start date, and line manager approval.
- Identity verification:
- Confirm identity via HR records and corporate email; for contractors, obtain identity and contractual authorisation.
- Training verification:
- Verify completion of required EMA and internal EudraVigilance training modules.
- For new users, schedule or confirm completion prior to submission of access.
- Approval workflow:
- Org Admin reviews request for completeness and appropriateness.
- QPPV or nominated delegate reviews and approves role if required by governance (for reporting or privileged roles).
- Creation of account:
- Org Admin or authorised technical admin creates user account in EudraVigilance.
- System captures metadata: creator, approver, timestamp, role assigned.
- First login and verification:
- User performs initial login, accepts terms of use and completes any mandatory system checks (e.g., two-factor authentication).
- Record creation:
- Save access request form, approvals, training evidence, and user account metadata in the designated DMS.
- Communicate access:
- Notify user of access details and responsibilities; provide quick-reference guidance.
Records to retain: access request form, approval emails/signatures, training certificates, user creation logs, initial login confirmation.
Step-by-Step Procedures — Periodic Review and Role Changes
A. Periodic Access Review (recommended cadence defined in SOP; typical 6–12 months)
- Schedule and ownership:
- PV Access Owner schedules review and notifies stakeholders (Org Admin, QPPV).
- Extract data:
- Produce an export of current users and assigned roles from EudraVigilance.
- Supplement with internal HR data (employment status, contract end dates).
- Review criteria:
- Active employment/contract status
- Appropriateness of assigned role(s) given current duties
- Training currency (within defined validity period)
- Volume and nature of system activity (identify dormant or unusual accounts)
- Triage findings:
- For each discrepancy, document required action: deactivate, change role, re-train, or justify retention.
- Approval and remediation:
- Org Admin executes account changes following documented approvals.
- QPPV or delegate approves exceptions where required.
- Reporting:
- Produce a signed review report listing reviewers, date, actions taken and outstanding items.
- Record retention:
- Store review report and evidence of changes in DMS.
Inspection relevance: ensure the review report clearly maps to the user export and documents the outcome for each account.
B. Role Changes, Suspensions and Terminations
- Trigger event:
- Role change may be triggered by HR update, organisational re-assignment, termination or security incident.
- Access change request:
- Submit a change request with reason, requested new role or deactivation date, and approvers.
- Approvals:
- Line manager and Org Admin must approve role changes; QPPV approves safety-critical role changes when appropriate.
- Change execution:
- Org Admin or authorised personnel makes changes in EudraVigilance and captures timestamp and approver.
- Evidence capture:
- Save change request, approvals and post-change confirmation in DMS.
- Post-change verification:
- Conduct a follow-up check to verify that access aligns with the new role and that no unintended permissions remain.
- Incident handling:
- For security incidents, immediately suspend accounts pending investigation and document actions.
Records to retain: change request, approvals, activity logs showing change, post-change verification.
Step-by-Step Procedures — Recordkeeping, Retrieval and Retention
Well-structured recordkeeping is essential for regulatory accountability and inspection readiness.
A. What to record
- Organisation registration files and EMA confirmation
- User access request and approval artifacts
- Training records linked to access approval
- Account creation metadata (creator, approver, timestamp)
- System audit logs and admin actions (user creation, role changes)
- Periodic access review reports and remediation evidence
- Exception approvals and compensating controls documentation
- Security incident reports involving EV access
- Contracts and SLAs for external providers with defined scope of access
B. How to store records (practical implementation)
- Centralised Document Management System (DMS) with controlled access and versioning
- Unique folder structure and filenames (e.g., /PV/EudraVigilance/OrgRegistration/YYYY-MM-DD_OrgName_Registration.pdf)
- Link user-specific records to user IDs and the populated role–permission matrix
- Maintain an index (spreadsheet or database) summarising all stored evidence, owners and retention end-dates
- Ensure backup and disaster recovery for records, in line with IT policy
C. Retention considerations and regulatory context
- Retention must comply with applicable laws and regulations (GVP Module I requires maintenance of pharmacovigilance system records; local laws may specify minimum retention).
- Organisational retention policy should state retention periods for:
- Active user records (while active + defined period)
- Deactivated user records (retain for the period required by pharmacovigilance and corporate policy)
- Periodic review reports (retain per audit schedule and regulatory requirements)
- Typical practice: retain PV-related records for the lifecycle of the product plus several years; confirm company policy and local legal requirements and document the policy in SOPs.
D. Retrieval and inspection readiness
- Maintain an index mapping inspection requests to file locations and owners
- Ensure responsible staff are trained to retrieve and present records within inspection timelines
- Prepare a “producer pack” for inspection: user export, access request forms, training evidence and access review result for a representative sample of users
- Ensure audit logs and system extracts are exportable in common formats (CSV/PDF) and that data integrity (hashes, audit trail provenance) can be demonstrated
Roles and Responsibilities (Governance Mapping)
Clear governance and accountability reduce inspection risk. The table below summarises recommended role responsibilities; these should be reflected in SOPs and the organisation’s governance matrix.
- QPPV: Oversight of PV system including assurance that access governance supports compliance; review and approval of privileged roles and exceptions; involvement in periodic reviews for safety-critical roles.
- PV Access Owner / PV Lead: Day-to-day owner of access governance; ensures procedures are followed; coordinates access reviews and training requirements.
- Organisation Administrator (Org Admin): Administers EudraVigilance organisational details and user provisioning; executes access requests in the system; maintains organisation user listings.
- Line Manager / Business Owner: Initiates access requests and approves role assignments for staff; confirms necessity of access during periodic reviews.
- IT / System Administrator: Provides technical support for account creation and system connectivity; does not perform safety operations unless specifically authorised and documented with compensating controls.
- HR: Supplies employment and contractor status data used in onboarding and periodic review.
- Compliance / Internal Audit: Performs periodic checks of access governance, audits adherence to SOPs and reports findings to the quality board.
- Third-party PV Providers: Must be included in governance documents, have defined roles and authorised access limited to contractual scope, and be subject to oversight and periodic review.
Inspection relevance: inspectors will commonly ask for the governance matrix and evidence that the persons listed actually execute the responsibilities assigned.
Examples of Inspection Evidence Packages
Prepare reusable evidence packages that can be tailored when an inspection is announced. Examples:
- Evidence package for sample reporting user:
- Access request form and approval
- Identity verification (HR record)
- Training certificates (EMA + internal)
- User creation log (timestamp + creator)
- Recent activity log extract showing submissions
-
Record of any role changes
-
Evidence package for privileged administrator:
- Role justification and approval
- Contractual or internal delegation documentation
- Periodic review records and compensating controls (if segregation cannot be achieved)
- Audit trail entries for admin actions
-
Incident handling records (if applicable)
-
Evidence package for periodic review:
- User export used for the review
- Review worksheet and checklist
- Signed review report and action log
- Evidence of execution of actions (deactivation logs, training assignments)
Practical Implementation Tips (Operationalise SOPs)
- Automate exports where possible: schedule monthly exports of user lists, audit logs and training status to a secure repository.
- Integrate with HR feeds: link employee termination and role-change events to a trigger for access review and deactivation.
- Use unique identifiers: ensure user records are tied to unique corporate IDs to avoid ambiguous records during inspections.
- Maintain a configurable review cadence: safety-critical roles may require more frequent review (e.g., quarterly) than less sensitive roles.
- Version control SOPs: maintain an SOP history and a change control log showing review and approval by responsible governance owners.
Key Takeaways
- EudraVigilance registration and access management are essential pharmacovigilance governance activities, not merely IT tasks.
- A documented role–permission matrix, standardised registration steps, periodic reviews and robust recordkeeping are necessary for compliance and inspection readiness.
- QPPV oversight and clear governance demonstrate organisational control and reduce inspection risk.
- Prepare inspection-ready evidence packages and maintain retrievable records to respond efficiently to inspector requests.
References
- EMA EudraVigilance Registration Manual.
- EMA EudraVigilance Training Materials.
- Regulation (EC) No 726/2004.
- Directive 2001/83/EC.
- Commission Implementing Regulation (EU) No 520/2012.
- GVP Module I – Pharmacovigilance Systems and Their Quality Systems.
- EMA EudraVigilance Documentation.