Global vs EU PSMF
- Global vs EU PSMF
- Introduction
- Why This Question Exists
- Regulatory Context (concise)
- Models Explained (brief)
- Key Governance Questions
- Implementation Guidance β Decision Framework
- Implementation Plan β Step-by-Step
- Operational Templates
- Inspection Relevance β What Inspectors Look For
- Practical Examples β Mapping Global to EU PSMF Sections
- Checklists (operational and inspection-ready)
- Change Control and Maintenance Procedures (operational detail)
- Governance Discussion β Roles and Responsibilities
- Common Inspection Findings and How Documentation Addresses Them
- Example Operational Use-Cases
- Practical Mapping Examples (templates you can copy)
- Measurement and KPIs
- Templates and Checklists β Quick Reference
- Characteristics of a Strong Model (restated with operational context)
- Which Model Is Best? (operational guidance)
- Key Takeaways
- References
Introduction
As pharmaceutical organisations expand internationally, the relationship between global pharmacovigilance governance and regional regulatory requirements becomes increasingly complex.
One of the most common questions asked by QPPVs, pharmacovigilance leaders and consultants is:
Should we maintain a global PSMF, an EU PSMF, or both?
The answer depends on:
- Organisational structure
- Product portfolio
- Geographic footprint
- Outsourcing model
- Governance maturity
There is no universally correct solution. Each approach carries advantages, disadvantages and inspection considerations. Understanding these trade-offs and how to operationalise a compliant, inspection-ready solution is essential when designing a sustainable pharmacovigilance governance model.
This article expands the conceptual discussion with detailed implementation guidance, operational templates and inspection-focused checklists and decision aids to make the topic actionable.
Why This Question Exists
Pharmacovigilance systems are often global while regulatory obligations are frequently regional. For example, a company may:
- Use one safety database globally
- Operate one signal management process
- Maintain one quality system
- Use common vendors worldwide
At the same time, regional obligations differ (e.g., EU GVP expectations for the PSMF; local reporting timelines; local contact points). The challenge lies in how to document a global operating model while remaining inspection-ready for regional regulators.
Regulatory Context (concise)
- EMA GVP Module II provides the EU requirements for the Pharmacovigilance System Master File (PSMF) and is the primary reference for EU-centred documentation expectations.
- Other regions may expect similar system-level documentation; however, a formal PSMF as defined in GVP Module II is a regulatory requirement for the EU market and, for centrally authorised products, for MAs held within the EU/EEA.
- The QPPV requirement (residence in the EEA for the EU QPPV) and local qualified persons for pharmacovigilance (where applicable) are part of the governance that must be reflected in the EU PSMF.
- Inspectors use the PSMF to gain rapid insight into governance, personnel, processes, systems and vendors supporting pharmacovigilance activities.
Regulatory references: EMA GVP Module II; GVP Module I (systems and quality); GVP Module III (inspections); Regulation (EC) No 726/2004; Directive 2001/83/EC.
Models Explained (brief)
- Global-centric: One primary global PSMF describing enterprise-wide pharmacovigilance activities, with regional annexes or supplements.
- EU-centric: A primary EU PSMF focused on the EU legal entity/MAHs and EU compliance requirements; global governance documents are referenced as necessary.
- Hybrid: A global master supplemented by regional PSMFs (or regional annexes) that extract and localise the information needed for specific regulatory contexts.
Each model is acceptable if it is implemented with clear ownership, consistent content, and inspection-ready cross-references.
Key Governance Questions
Successful implementation requires explicit decisions and documented governance, including:
- Document ownership and custodianship (who is accountable for the global PSMF and for each regional PSMF or annex).
- Authoritative source(s) of truth (which system holds the master data for org charts, vendor lists, product lists).
- Update triggers and SLAs (what events trigger PSMF updates and within what timeframe).
- Version control and change control (how updates are approved, recorded and archived).
- Evidence linking (how evidence of statements in the PSMFβe.g. training records, contracts, SOPsβis stored and made available for inspections).
- RACI matrix for maintenance and inspection response.
Below we provide practical templates and actionable implementation guidance to operationalise these governance topics.
Implementation Guidance β Decision Framework
Use this decision tree to determine the appropriate architecture for your organisation. Follow step-by-step and document the result.
Decision tree (textual):
- Do you hold Marketing Authorisations (MAs) in the EU/EEA or are you legally responsible for EU pharmacovigilance obligations?
- Yes -> Continue to step 2.
-
No -> A global PSMF with regional references may suffice; ensure local documentation meets local regulator expectations.
-
Do you have a centralised global pharmacovigilance function that operates the safety database, signal management, and global SOPs?
- Yes -> Consider a hybrid or global-centric model with EU-specific annexes.
-
No -> If operations are regionally segregated, maintain EU-centric PSMF(s) for EU MAs.
-
Are there significant local differences in process, vendors, or roles between EU and other regions (e.g., local call centres, local safety databases, separate medical teams)?
- Yes -> Hybrid with regional PSMFs is likely preferable.
-
No -> Global-centric with short EU annexes is feasible.
-
Do you frequently undergo EU inspections or have high inspection risk (high volume of EU products, complex outsourcing)?
- Yes -> Prefer a clear EU-centric or well-structured hybrid model to aid inspector navigation.
-
No -> Global-centric is acceptable if inspection navigation is demonstrably effective.
-
Is organisational governance fragmented across affiliates/BU?
- Yes -> Hybrid or EU-centric models help localise responsibilities.
- No -> Global-centric can reduce duplication.
Document the decision and the rationale in an explicit governance memo and record it as the basis for your PSMF architecture.
Implementation Plan β Step-by-Step
A practical implementation plan for converting from an ad-hoc set of documents to a controlled PSMF architecture.
Phases:
- Assessment (4β8 weeks)
- Inventory existing documents: global SOPs, regional SOPs, vendor contracts, org charts, system inventories, product lists, clinical trials PV lists.
- Map responsibilities: who is QPPV, who maintains vendor lists, who runs the safety database.
- Identify gaps against GVP Module II requirements.
-
Output: Gap analysis report and recommended PSMF architecture (global, EU, or hybrid).
-
Design (4β6 weeks)
- Finalise architecture and governance (owners, RACI).
- Create document templates and index (see templates below).
- Agree on authoritative data sources (HR system for org charts; vendor management system for vendor lists; PV system for product lists).
-
Define update triggers and SLAs.
-
Build (6β12 weeks)
- Draft the global PSMF and EU PSMF (or global + annexes).
- Create cross-referencing system (links, annex IDs).
- Prepare supporting evidence repositories and indexing.
-
Prepare version control and change control processes.
-
Validate & Approve (2β4 weeks)
- Peer review by QPPV and Legal.
- Management approval and sign-off.
-
Training for document owners on maintenance process.
-
Roll-out (ongoing)
- Publish documents in controlled document repository.
- Communicate to stakeholders.
-
Set recurring review cadence (annual) and event-driven update processes.
-
Inspection readiness (continuous)
- Maintain inspection packs (PSMF extracts, evidence bundles).
- Conduct mock inspections focused on PSMF navigation and evidence retrieval.
Operational Templates
Below are practical templates you can adopt or adapt. Each is immediately operational and intended to be included in SOPs or the PSMF itself as annexes.
Template: PSMF Master Index (example fields)
- Section ID (per GVP Module II)
- Section title
- Version
- Owner (name, role, contact)
- Location (global PSMF / EU PSMF / Annex X)
- Last updated date
- Evidence (link to SOPs, contracts, HR records)
- Notes (local differences, exceptions)
Example table (markdown):
| Section ID | Section title | Version | Owner | Location | Last updated | Evidence link | Notes |
|---|---|---|---|---|---|---|---|
| 1 | Pharmacovigilance system description | 1.2 | Head PV Ops | Global PSMF (Annex EU-1) | 2026-05-10 | /evidence/pv-system.pdf | EU specifics in Annex EU-1 |
| 2 | Organisation and staffing | 2.0 | Global HR / QPPV | EU PSMF | 2026-03-22 | /evidence/org-chart.pdf | QPPV resident in EEA |
This index becomes the operational control panel for inspectors and internal governance.
Template: RACI for PSMF Maintenance
- Responsible: Document owner (e.g., Head PV Ops) β drafts updates.
- Accountable: QPPV (for accuracy and compliance).
- Consulted: Legal, Regulatory Affairs, Local Affiliate PV leads.
- Informed: Senior Management, Global QA.
Record RACI in PSMF governance section and implement in SOPs.
Template: Version Control Log (change history)
- Version number
- Date
- Author
- Summary of change
- Reason for change (e.g., regulatory, organisational, inspection finding)
- Approved by (name, role)
- Link to approved version
Keep log within the PSMF or in the document management system.
Template: Evidence Mapping Table (example)
Use this to map statements in the PSMF to supporting evidence for inspection.
| PSMF statement (excerpt) | Evidence type | Location | Owner | Retrieval time estimate |
|---|---|---|---|---|
| "QPPV is resident in EEA" | QPPV employment contract; CV | HR folder / Evidence pack | HR / QPPV | 15 minutes |
| "PV SOP v3 applies globally" | SOP document; change control | SOP repository | QA | 10 minutes |
| "Vendor X processes adverse events" | Contract; subcontractor list; audit report | Vendor folder | Vendor management | 30 minutes |
This mapping is essential for inspection preparedness.
Template: PSMF Update Trigger Checklist
Event triggers (if any of the following occur, review PSMF sections within defined SLAs):
- New MA or product launch (30 days) β update product list and responsibilities.
- Change of QPPV or local QPPV (7 days) β update contact details, contracts.
- New vendor engaged for PV activities (30 days) β update vendor list, evidence.
- Major process change (after go-live) β update process descriptions (14 days).
- Organisational change affecting PV roles (14 days).
- Inspection findings (immediate; corrective action schedule).
Define SLA per event and record in the PSMF governance section.
Template: Vendor Mapping Table
Map global vendor entries to EU-relevant information.
| Vendor name | Services provided | Global PSMF ref | EU PSMF ref | Contract owner | Local site (if EU) | Last audit date | CVs on file |
|---|---|---|---|---|---|---|---|
| Vendor A | Safety database hosting | G-VEND-001 | EU-Annex-V1 | Procurement | Ireland | 2025-11-04 | Yes |
Template: Inspection Pack Index (for EU inspections)
Prepare a ready-to-hand inspection pack aligned to the PSMF:
- Cover letter and PSMF version
- Executive summary (1 page)
- Organisation chart and QPPV contact
- Evidence mapping table (top 20 statements likely to be queried)
- SOP list with versions
- Vendor list and recent audit reports
- Safety database access (read-only) procedure
- Training matrix
- Recent compliance/performance metrics (e.g., reporting timelines)
- Change control log (last 12 months)
- Previous inspection reports and CAPAs (if applicable)
Include retrieval times for each item (to demonstrate inspection readiness).
Inspection Relevance β What Inspectors Look For
Inspectors focus on effective implementation and traceability. Key inspection criteria:
- Clarity: Can an inspector quickly find the QPPV, org chart, vendor list, and evidence?
- Currency: Are documents up to date and is the last update date visible?
- Accuracy: Do documents reflect the operational reality (e.g., actual SOPs followed, actual vendors used)?
- Traceability: Can statements in the PSMF be linked to documentary evidence (contracts, SOPs, training records)?
- Ownership and accountability: Is it clear who is responsible for each element?
- Change control: Are updates controlled, approved and logged?
- Local compliance: Are EU-specific requirements (e.g., QPPV in EEA) clearly documented and evidenced?
For each area, include the likely evidence inspectors will request and ensure rapid retrieval is feasible.
Practical Examples β Mapping Global to EU PSMF Sections
Example mapping table to create an annex that extracts EU-relevant content from the global PSMF.
| GVP Module II section | Global PSMF location | EU PSMF (Annex) content | Evidence links |
|---|---|---|---|
| Organisation and Staffing | Global Section 2 | EU Annex: Org chart (MA holder); QPPV details; local PV contacts | /evidence/org-eu.pdf |
| Systems and Databases | Global Section 4 | EU Annex: Access, backup, local hosting issues; access for EU operations | /evidence/db-hosting.pdf |
| Vendor oversight | Global Vendor list | EU Annex: vendors with EU responsibilities; EU contracts; SLA excerpts | /evidence/vendor-eu.zip |
| Product List | Global product inventory | EU Annex: list of products authorised in EU with MA numbers | /evidence/eu-product-list.csv |
Create an automated or manual process to keep these mappings current.
Checklists (operational and inspection-ready)
Use these checklists to operationalise PSMF maintenance and inspection readiness.
Annual PSMF Review Checklist
- [ ] Confirm PSMF index reflects current organisational structure.
- [ ] Validate QPPV and local PV contact details.
- [ ] Reconcile product lists between global safety database and regulatory registries.
- [ ] Verify vendor list and audit status (last audit within defined timeframe).
- [ ] Confirm SOP versions referenced are current.
- [ ] Update PSMF version control log.
- [ ] Run evidence retrieval test (time to retrieve top 10 items β€60 minutes).
- [ ] QPPV sign-off on accuracy.
Pre-Inspection PSMF Checklist (48β72 hours before inspection)
- [ ] Produce PSMF executive summary (1 page) and index.
- [ ] Prepare inspection pack index and evidence bundles.
- [ ] Confirm QPPV availability and briefing.
- [ ] Confirm access rights for inspectors (e.g., read-only view of database).
- [ ] Confirm contact list for vendors and local affiliates.
- [ ] Ensure hard copies or PDF snapshots of critical evidence are available.
- [ ] Run a walk-through of likely inspection questions and evidence retrieval.
M&A Integration Checklist (for absorbing legacy PSMFs)
- [ ] Identify all legacy PSMFs and owners.
- [ ] Map overlapping vendors, systems and processes.
- [ ] Reconcile product lists and MA ownership.
- [ ] Identify conflicts in governance and resolve via documented decision.
- [ ] Update the global PSMF and EU annexes accordingly.
- [ ] Archive legacy documents with cross-references for audit trail.
Change Control and Maintenance Procedures (operational detail)
- Define explicit events that trigger PSMF change (see PSMF Update Trigger Checklist).
- Establish SLAs for updates (e.g., QPPV change: within 7 calendar days; vendor change: within 30 calendar days).
- Use an electronic change control system to log proposed changes, reviewers, approvals and implementation date.
- Require QPPV approval for changes affecting regulatory compliance elements.
- Keep an audit trail for each PSMF update with attachments linking to evidence.
Example change control workflow (textual):
- Change identified (originator opens change request).
- Impact assessment by Document Owner & Regulatory.
- Draft update in staging area.
- Consultation with QA, Legal, Local Affiliates as required.
- QPPV approval (Accountable sign-off).
- Publication to controlled repository; update index and version log.
- Notification to stakeholders and training if required.
Governance Discussion β Roles and Responsibilities
Clear role definitions reduce inspection risk:
- QPPV (Accountable): Certifies that PSMF statements reflect compliance with EU requirements; approves EU PSMF versions.
- Head of PV / PV Operations (Responsible): Maintains PSMF content, coordinates evidence collection.
- Global QA (Consulted): Ensures PSMF references to quality systems are accurate.
- Legal / Regulatory Affairs (Consulted): Reviews statements with regulatory or legal implications.
- Local PV Leads / Affiliates (Informed/Consulted): Provide local updates and evidence.
- Document Control (Responsible): Maintains version control and publishes approved versions.
Embed the RACI in the PSMF governance section so inspectors can see how responsibilities are allocated.
Common Inspection Findings and How Documentation Addresses Them
Typical findings and the documentation controls that prevent them:
- Inconsistency between documents -> Use a single master index and evidence mapping to ensure alignment.
- Outdated QPPV contact details -> Implement SLA-triggered updates and proof via employment documentation.
- Vendor list omissions -> Use authoritative vendor management system as source-of-truth; cross-reference in PSMF.
- Poor evidence traceability -> Maintain an evidence mapping table linking each significant PSMF claim to documents.
- Unclear ownership -> Publish RACI and training logs showing responsible persons understand duties.
Addressing each of the above requires both accurate content and demonstrable process controls.
Example Operational Use-Cases
-
EU inspection request for PSMF: Provide EU PSMF (or EU Annex), executive summary, evidence mapping table and inspection pack. Provide a named point-of-contact (QPPV or delegate) and time estimates for retrieving additional evidence.
-
New MA in EU: Trigger PSMF update via change control; update product list, local affiliate contact, QPPV oversight activities; record update in version log; prepare evidence (MA certificate, local PV contact).
-
Vendor change: Update vendor mapping table and contracts; run risk assessment for pharmacovigilance activities; update SOPs and evidence; schedule audit if performing core PV activities.
Practical Mapping Examples (templates you can copy)
Product mapping CSV example (fields):
- product_id, product_name, active_substance, MAH_name, MA_number, EU_status (Y/N), global_db_product_id, last_update_date, PSMF_section_ref
Vendor mapping CSV example:
- vendor_id, vendor_name, services, global_psmf_ref, eu_psmf_ref, contract_reference, site_location, last_audit_date, risk_rating
Org chart mapping (fields):
- employee_id, name, role, pv_role (Yes/No), QPPV_delegate (Yes/No), legal_entity, EEA_resident (Yes/No), PSMF_contact_section
These machine-readable mappings enable automated reconciliation and reduce manual inconsistency.
Measurement and KPIs
Track metrics to show governance effectiveness and support inspection readiness:
- Time to update PSMF after triggering event (target vs actual).
- Percentage of PSMF statements with mapped evidence.
- Time to retrieve top 20 evidence items (minutes).
- Percentage of vendors with completed audits within defined cadence.
- Number of inconsistencies found in annual cross-checks.
Report KPIs to senior management and include summaries in PSMF governance section.
Templates and Checklists β Quick Reference
- PSMF Master Index template
- RACI matrix template
- Version control log template
- Evidence mapping table template
- Vendor mapping template
- Pre-inspection pack index template
- PSMF update trigger checklist
- Annual review checklist
- M&A integration checklist
(Embed these templates in your document management system and reference them within the PSMF.)
Characteristics of a Strong Model (restated with operational context)
Regardless of the chosen architecture, strong implementations are:
- Clear: Document purpose and navigation aids (index, executive summary).
- Consistent: Single authoritative sources, reconciled inventories.
- Owned: Named owners and RACI recorded.
- Maintainable: Defined triggers, SLAs, and change control.
- Inspection-ready: Evidence mapping, inspection packs, retrieval time targets.
Which Model Is Best? (operational guidance)
- Small organisations: Simpler, centralised PSMF is typically sufficient. Ensure rapid evidence retrieval and QPPV oversight is demonstrable.
- Medium organisations: EU-centric or hybrid models often balance regulatory clarity and operational efficiency.
- Large multinationals: Hybrid models with a global PSMF and regional annexes provide scalability if governance and cross-referencing are robust.
Make the decision according to operational realities and document the rationale and governance approach.
Key Takeaways
- Global and EU PSMFs serve different purposes. The design should prioritise clarity and inspection-readiness over elegance.
- Implement a documented decision framework for choosing architecture, and codify governance (owners, RACI, SLAs).
- Use master indices, evidence mapping, vendor mapping, and inspection packs to reduce inspection risk.
- Maintain controlled change control processes and KPIs to demonstrate ongoing compliance.
- Hybrid models are common and effective when supported by strong governance and tooling.
References
- EMA Good Pharmacovigilance Practices (GVP) Module II β Pharmacovigilance System Master File.
- EMA Good Pharmacovigilance Practices (GVP) Module I β Pharmacovigilance Systems and Their Quality Systems.
- EMA Good Pharmacovigilance Practices (GVP) Module III β Pharmacovigilance Inspections.
- Regulation (EC) No 726/2004.
- Directive 2001/83/EC.
- Commission Implementing Regulation (EU) No 520/2012.
- EMA Questions and Answers on Pharmacovigilance System Master Files.