EU Pharmacovigilance Inspection Findings: Cross-Functional and Interface Controls
- EU Pharmacovigilance Inspection Findings: Cross-Functional and Interface Controls
- Introduction
- 1. Why Interfaces Matter in Pharmacovigilance
- 2. Regulatory Framework
- 3. Responsibility, Accountability and Oversight
- 4. What Inspectors Mean by an Interface Problem
- 5. The End-to-End Inspection Method
- 6. Central Pharmacovigilance and Affiliates
- 7. Pharmacovigilance and Regulatory Affairs
- 8. Pharmacovigilance and Medical Information
- 9. Pharmacovigilance and Clinical/Development Functions
- 10. Pharmacovigilance and Quality
- 11. Pharmacovigilance and EudraVigilance
- 12. Pharmacovigilance and Vendors
- 13. Data and Technology Interfaces
- 14. Interfaces Created by Organisational Change
- 15. Interfaces Created by Multiple Legal Entities
- 16. Responsibility Matrices: Useful but Not Sufficient
- 17. Contracts and Agreements: What They Establish
- 18. How Inspectors Test an Interface
- 19. Sampling Across the Boundary
- 20. Potential Failure Patterns
- The hand-off is defined but not monitored
- Both functions believe the other owns the task
- Local and central procedures diverge
- Information is transferred without the information needed to act
- Exceptions leave the normal workflow
- The interface changes without change control
- Oversight measures activity but not outcome
- 21. When an Interface Problem Becomes a Systemic Deficiency
- 22. Root-Cause Analysis at Interfaces
- 23. Example: A Cross-Functional ICSR Interface
- 24. Example: Quality Event With PV Impact
- 25. Example: Affiliate-to-Central Escalation
- 26. QPPV Oversight of Interfaces
- 27. Interface Metrics and Their Limitations
- 28. CAPA for Interface Findings
- 29. Effectiveness Verification
- 30. What Inspectors May Ask
- 31. Practical Self-Inspection Framework
- 32. Relationship to Published Inspection Evidence
- 33. Inspection Readiness: The Evidence Chain
- 34. Key Takeaways
- 35. References
- Regulatory Note
Introduction
A pharmacovigilance system rarely operates inside a single department. Safety information may begin with a patient, healthcare professional, affiliate, clinical study, medical-information contact, product complaint, literature source or external service provider. It can then pass through several functions before reaching the pharmacovigilance organisation and, where required, a competent authority or EudraVigilance.
The regulatory responsibility may remain with the marketing authorisation holder even when individual activities are distributed across functions, companies, countries or contractors. This creates an inspection problem that cannot be solved by examining individual procedures in isolation. An inspector can find that each department has a procedure and still identify a weakness in the way those departments interact.
This article examines that interface problem. It focuses on how an inspector can determine whether responsibilities, information flows, escalation routes and oversight actually work across organisational boundaries.
The article deliberately does not repeat the detailed inspection analysis of PSMF, ICSR processing, signal management, PSURs, vendors or EudraVigilance already covered elsewhere in the QPPV.com library. Instead, it asks a different question: what happens where one pharmacovigilance control ends and another function's responsibility begins?
1. Why Interfaces Matter in Pharmacovigilance
An interface is a point at which an activity, responsibility, information flow, decision or control passes between people, functions, organisations or systems.
The risk is not necessarily that either side is incapable of performing its own task. The risk is that the transition between them is poorly controlled.
For example, a medical-information function may correctly receive a safety-related contact, while pharmacovigilance correctly processes reports that it receives. If the mechanism for recognising and transferring potentially reportable information from medical information to pharmacovigilance is incomplete, the overall system can fail despite both functions having apparently adequate procedures.
The same logic applies to an affiliate that receives a report, a vendor that processes it, a quality unit that manages a deviation, or a regulatory function that receives a safety-related authority communication.
Interfaces therefore have three dimensions:
- information — what must move from one party to another;
- responsibility — who must act and who remains accountable; and
- control — how the organisation knows the transfer occurred correctly and on time.
An effective inspection examines all three.
2. Regulatory Framework
The EU pharmacovigilance framework places responsibility for the pharmacovigilance system on the marketing authorisation holder while allowing defined activities to be performed by other parties. EMA's current pharmacovigilance-system Q&A states that an MAH may subcontract certain activities but retains ultimate responsibility for the pharmacovigilance system and for the completeness and accuracy of the PSMF. It also states that detailed written agreements should define relevant roles and responsibilities. citeturn0search1
GVP Module III identifies the roles and responsibilities of the MAH, QPPV, quality system, computerised systems and contracts or agreements as matters that may be examined during inspection. It also identifies significant changes in contracted activities, organisational changes and changes in the pharmacovigilance database as relevant considerations for re-inspection. citeturn0search22
The legal and GVP framework therefore supports an important distinction: delegation of an activity does not automatically transfer the MAH's ultimate pharmacovigilance responsibility.
This does not mean that every operational interface must be controlled through the same mechanism. The appropriate control depends on the activity, its regulatory significance and the parties involved.
3. Responsibility, Accountability and Oversight
Three concepts should be kept separate.
Responsibility concerns who performs an activity.
Accountability concerns who remains answerable for the outcome within the regulatory framework.
Oversight concerns how the accountable organisation knows that the activity is being performed appropriately.
A responsibility matrix can show that an affiliate performs local case intake. A contract can state that a vendor performs literature screening. Neither document, by itself, demonstrates effective oversight.
During inspection, the evidence chain may therefore look like:
Regulatory obligation
↓
Assigned responsibility
↓
Operational procedure
↓
Information transfer
↓
Performance evidence
↓
Oversight / escalation
↓
Corrective action when required
A weakness at any transition can affect the reliability of the system.
4. What Inspectors Mean by an Interface Problem
An interface problem is not simply a disagreement between departments. It is a failure or weakness in a control that depends on more than one party.
Examples include:
- a report reaching a non-PV function but not being transferred to PV as expected;
- an affiliate using a local process that does not align with the central PV process;
- a vendor generating safety data that the MAH cannot adequately reconcile;
- a regulatory communication not reaching the function responsible for safety assessment;
- a quality investigation being closed without determining whether the PV system was affected;
- or a system change altering a safety workflow without appropriate PV assessment.
These are illustrative failure patterns, not statements that each has been observed as a published inspection finding.
5. The End-to-End Inspection Method
The strongest way to examine an interface is to follow a real transaction rather than review only documents describing the transaction.
For example, an inspector could select a safety report and trace it through:
Original source
↓
Receiving function
↓
Transfer to PV
↓
Case intake
↓
Assessment
↓
Submission
↓
Acknowledgement
↓
Reconciliation
↓
Management / oversight information
At each point the inspector can ask:
- Who was responsible?
- When did the information arrive?
- What evidence records the transfer?
- What rule determined the next action?
- What happened when information was incomplete or late?
- Who monitored the interface?
This approach is often more informative than asking each function whether it follows its SOP.
6. Central Pharmacovigilance and Affiliates
Multinational systems create interfaces between the central PV organisation and national or regional affiliates. Local teams may receive safety information, communicate with competent authorities, support local risk-minimisation measures or perform other activities defined within the pharmacovigilance system.
The central organisation needs sufficient visibility to understand whether those arrangements operate as intended. Conversely, affiliates need clear instructions about what must be transferred, when, through which channel and with what documentation.
Potential controls include written procedures, responsibility matrices, training, escalation pathways, performance monitoring, reconciliations, periodic oversight and audit activity. The appropriate combination depends on the organisation and the activities concerned.
An inspection may select one or more affiliates and compare the documented central arrangement with local practice. The purpose is not to require every country to operate identically. The question is whether the local variation remains within the controlled pharmacovigilance system.
7. Pharmacovigilance and Regulatory Affairs
Safety information frequently crosses the boundary between pharmacovigilance and regulatory affairs. Examples include authority questions, variations, safety referrals, changes to product information, urgent safety communications and regulatory correspondence containing safety information.
The critical control is not simply that the two functions communicate. The organisation should be able to demonstrate how safety-relevant information is recognised, routed, assessed and escalated.
An inspector may examine a regulatory communication and trace it backwards to determine when it was received, who assessed its safety implications, whether the QPPV or appropriate PV governance was involved, what actions followed and whether any related reporting or risk-management obligations were triggered.
8. Pharmacovigilance and Medical Information
Medical-information channels can be important sources of adverse-reaction information. The interface therefore needs a clear method for identifying potentially reportable safety information and transferring it to pharmacovigilance.
The control must address more than forwarding an email. It should define how relevant information is recognised, what information accompanies the transfer, when the transfer occurs and how the receiving PV organisation knows that the hand-off has occurred.
A useful inspection test is to sample contacts received by medical information and determine whether the organisation's classification and transfer process operated consistently. This can reveal weaknesses that would not be visible in the PV database itself.
9. Pharmacovigilance and Clinical/Development Functions
Although the detailed regulatory framework differs between development and post-authorisation activities, safety information can cross those organisational boundaries. A post-authorisation system may need awareness of relevant information arising from clinical development, studies, investigator communications or other safety processes within the organisation.
The inspection question is therefore how the organisation prevents safety information from becoming trapped inside a functional silo.
Controls may include defined interfaces, escalation criteria, governance forums, reconciliation processes and documented responsibilities. The exact arrangement should reflect the organisation's activities and legal obligations.
10. Pharmacovigilance and Quality
Quality functions can interact with PV through deviations, CAPA, audits, document management, training, change control and quality risk management.
A key interface question is whether a quality event that affects pharmacovigilance is recognised as a pharmacovigilance-system issue.
For example, a system incident involving a safety database may initially be managed as an IT or quality event. If the incident could affect case processing or reporting, the PV impact needs to be assessed through the organisation's established governance process.
Similarly, a recurring PV deviation should not disappear into a quality system where its pharmacovigilance implications are no longer visible to the QPPV or relevant PV governance.
The control is therefore the connection between the quality event and pharmacovigilance impact assessment.
11. Pharmacovigilance and EudraVigilance
The interface with EudraVigilance is both organisational and technical. Case processing, submission, acknowledgement handling and reconciliation may involve different people, systems or service providers.
An organisation can therefore have a technically functional gateway while still having an inadequate operational control if rejected messages, acknowledgements, reconciliation exceptions or changes in configuration are not appropriately managed.
EMA's inspection Q&A notes that MAHs may use vendor-provided electronic systems but remain responsible for validation of the pharmacovigilance processes supported by those systems and should ensure that relevant qualification documentation is available for inspection. citeturn0search0
The broader lesson is that a system boundary does not eliminate the regulatory process boundary.
12. Pharmacovigilance and Vendors
Vendor interfaces are a particularly visible example of distributed responsibility. Outsourcing may involve case intake, case processing, literature monitoring, safety databases, signal support, reporting or other activities.
The interface must establish what the vendor does, what the MAH retains, what information is exchanged, how performance is monitored and how problems are escalated.
A contract can define the relationship, but inspection evidence needs to show that the relationship operates in practice. Useful evidence may include performance metrics, reconciliations, quality events, audits, oversight meetings, escalation records and documented corrective actions.
The distinction is important because a vendor problem can become an MAH pharmacovigilance problem if the MAH's oversight control does not detect or address it.
13. Data and Technology Interfaces
Modern pharmacovigilance systems depend on multiple information systems. Safety data may move between intake channels, safety databases, document-management systems, reporting gateways, analytics platforms and enterprise systems.
The inspection risk arises when the organisation treats each system boundary as a technical issue rather than as part of the pharmacovigilance control environment.
For an interface carrying safety-critical information, the organisation should be able to explain what information moves, under what rules, how completeness is controlled and what happens when the transfer fails. Relevant evidence may include interface specifications, validation or qualification records, reconciliation controls, change controls, incident records and monitoring results.
EMA's inspection guidance specifically identifies fitness for purpose of computerised systems and validation or qualification evidence as inspection considerations. citeturn0search20turn0search0
14. Interfaces Created by Organisational Change
Interfaces are especially vulnerable during mergers, acquisitions, divestments, changes of service provider, database migrations and major reorganisations.
GVP Module III identifies organisational changes, including mergers and acquisitions, changes in the pharmacovigilance database and significant changes in contracted activities as matters that may be relevant when planning a re-inspection. citeturn0search20
This reflects a practical principle: the risk is not confined to the change itself. The change can alter who receives information, who makes decisions, which system is authoritative, which procedure applies and how the QPPV receives oversight information.
An effective change process therefore assesses the pharmacovigilance interfaces affected by the change rather than treating organisational restructuring as purely administrative.
15. Interfaces Created by Multiple Legal Entities
A global pharmaceutical organisation may contain several legal entities involved in commercialisation, local activities or contracted services. The operational structure can therefore become more complex than the legal responsibility visible in an individual procedure.
An inspection may test whether the organisation can explain the relationship between the MAH and other entities involved in pharmacovigilance activities, including who performs the activity and how the MAH exercises oversight.
The PSMF provides an important system-level description, but the inspection evidence should extend into the underlying agreements, procedures and operational records.
16. Responsibility Matrices: Useful but Not Sufficient
Responsibility assignment matrices are valuable because they make interfaces visible. They can identify who performs an activity, who approves it, who must be consulted and who needs information.
They become weak controls when they are treated as proof that the interface works.
An inspector may select one responsibility from the matrix and ask for evidence that the assigned party actually performs it, that the receiving function recognises the hand-off, and that exceptions are escalated appropriately.
The strongest use of a responsibility matrix is therefore as an index into the operating system, not as a substitute for evidence of operation.
17. Contracts and Agreements: What They Establish
Written agreements are important where pharmacovigilance activities involve other parties. They can define responsibilities, information exchange, timelines, quality expectations, escalation and access to records.
However, a contractual provision does not demonstrate that the agreed process is followed.
For example, an agreement may require a vendor to transmit safety information within a defined period. An inspection can then examine actual transactions, timestamps and exception records to determine whether the contractual control operates.
EMA's current pharmacovigilance-system Q&A explicitly states that detailed written agreements should be in place when activities are delegated and that the MAH retains ultimate responsibility for the pharmacovigilance system. citeturn0search1
18. How Inspectors Test an Interface
An effective inspection test usually starts with a real event and moves across the boundary.
A generic method is:
Select an event
↓
Identify the originating function
↓
Establish awareness date
↓
Identify the required receiving function
↓
Trace the transfer
↓
Trace the receiving action
↓
Review escalation and exception handling
↓
Review oversight evidence
↓
Compare with documented responsibilities
The event could be an ICSR, authority request, system incident, vendor exception, quality deviation, signal, safety communication or other safety-relevant transaction.
The value of the method is that it tests the interface under real operating conditions.
19. Sampling Across the Boundary
Sampling should not be limited to successful transactions. If the objective is to assess the effectiveness of an interface, exception cases can be particularly informative.
Useful samples may include:
- late transfers;
- incomplete transfers;
- rejected submissions;
- escalated quality events;
- vendor deviations;
- affiliate reporting discrepancies;
- system incidents;
- authority requests requiring cross-functional action; and
- cases in which responsibility changed during processing.
The purpose is not to search for errors mechanically. It is to determine whether the interface control can detect, contain and correct deviations.
20. Potential Failure Patterns
The following patterns are useful for internal assessment. They are illustrative categories, not claims of published inspection findings unless separately cited.
The hand-off is defined but not monitored
A procedure specifies that Function A transfers information to Function B, but no one monitors whether transfers occur within the required timeframe.
Both functions believe the other owns the task
The responsibility matrix is ambiguous or the practical interpretation differs between teams.
Local and central procedures diverge
An affiliate operates differently from the central process without a documented rationale or adequate control of the variation.
Information is transferred without the information needed to act
The receiving function receives an incomplete data set and has no effective mechanism for obtaining the missing information.
Exceptions leave the normal workflow
A failed transfer enters an informal email or spreadsheet process and is no longer visible to the principal control system.
The interface changes without change control
A system, vendor, organisational or procedural change alters the hand-off without an adequate impact assessment.
Oversight measures activity but not outcome
A KPI shows that transfers occurred, but does not establish whether the receiving function could act correctly or within the applicable timeframe.
21. When an Interface Problem Becomes a Systemic Deficiency
Not every interface discrepancy has the same significance.
The assessment should consider at least:
- the regulatory obligation affected;
- whether patient-safety information could be delayed or lost;
- duration and recurrence;
- number of products, countries or transactions affected;
- whether the organisation detected the problem itself;
- whether an effective backup control existed;
- and whether the underlying interface was governed adequately.
A single late transfer may be an isolated operational error. Repeated late transfers across several functions may indicate that the organisation has no effective control over the interface.
The key question is therefore not simply how many errors occurred, but what the errors reveal about the control system.
22. Root-Cause Analysis at Interfaces
Interface failures often produce superficial root causes such as "human error" or "communication issue". Those descriptions rarely explain why the control allowed the error to occur or persist.
A stronger analysis asks:
- Was the responsibility clear?
- Was the required information defined?
- Was the transfer mechanism reliable?
- Was the timing requirement understood?
- Was there a monitoring control?
- Could the receiving function detect missing information?
- Was escalation defined?
- Did training reflect the current process?
- Did a recent change alter the interface?
- Did management receive information showing that the interface was failing?
This converts an interpersonal problem into an assessable process problem.
23. Example: A Cross-Functional ICSR Interface
Consider an illustrative case in which a medical-information team receives a customer contact containing a suspected adverse reaction.
The procedure requires transfer to pharmacovigilance. The contact is transferred, but the transfer occurs after the relevant information has been sitting in the medical-information queue for several days.
A superficial investigation might conclude that an employee failed to forward the report promptly.
An inspection-oriented analysis would go further:
- When did the medical-information team become aware?
- What criteria identify a potential adverse reaction?
- Does the system flag such contacts automatically?
- Who monitors the queue?
- Is the transfer timestamp retained?
- Does PV reconcile expected and received transfers?
- Has the problem occurred before?
- Does the QPPV receive information about such delays?
If the answer reveals that no one monitors the interface, the underlying issue is a control deficiency rather than simply an individual delay.
24. Example: Quality Event With PV Impact
In another illustrative scenario, a safety database becomes unavailable for several hours. IT records the event and the quality organisation opens a deviation.
The critical interface question is whether the event is assessed for pharmacovigilance impact.
An effective process should establish whether cases could not be entered, assessed or submitted; whether reporting timelines could be affected; whether a contingency process was activated; and whether potentially affected transactions were identified and reconciled after restoration.
The point is not that every IT incident is a PV deviation. The point is that the organisation needs a controlled mechanism for determining when an IT or quality event has pharmacovigilance consequences.
25. Example: Affiliate-to-Central Escalation
Suppose an affiliate receives a serious safety communication from a national competent authority. The affiliate informs its local regulatory team, which assumes that the central organisation has already been informed through another channel.
An inspection could reconstruct the communication chain and identify whether the system contained a single authoritative route for escalation, whether receipt was acknowledged and whether the central PV organisation was able to demonstrate awareness and action.
Again, the failure is not necessarily that a particular employee misunderstood an email. The systemic question is whether the interface was designed so that an important communication could be lost through overlapping responsibilities.
26. QPPV Oversight of Interfaces
The QPPV cannot personally supervise every transaction crossing every interface. Effective oversight therefore depends on the system providing appropriate visibility of material risks and performance.
Useful evidence may include governance reports, significant-deviation escalation, vendor and affiliate oversight, audit results, KPI/KRI trends, inspection outcomes, major change assessments and documented decisions on systemic issues.
A QPPV should be able to explain how the organisation knows that critical interfaces are functioning, what happens when they fail and how material deficiencies are escalated.
The evidence should demonstrate actual oversight rather than simply the QPPV's presence on a distribution list.
27. Interface Metrics and Their Limitations
Metrics can help detect interface weaknesses, but their design matters.
A metric such as "percentage of reports transferred" may show activity without showing whether the transfer was timely, complete or usable.
More informative measures may examine dimensions such as:
| Dimension | Example question |
|---|---|
| Completeness | Did all expected transactions reach the receiving function? |
| Timeliness | Did the transfer occur within the applicable control timeframe? |
| Quality | Did the receiving function receive enough information to act? |
| Exceptions | How many transfers failed or required escalation? |
| Recurrence | Are the same interface failures repeating? |
| Resolution | Are exceptions investigated and closed effectively? |
| Outcome | Did the receiving function complete the required downstream action? |
These are examples of control-design considerations, not universal regulatory KPI requirements.
28. CAPA for Interface Findings
Corrective action should match the failed control.
If responsibility was unclear, the CAPA may require clarification of ownership and associated documentation. If information was incomplete, the data requirements or transfer mechanism may need redesign. If monitoring was absent, an appropriate control may need to be introduced. If the problem arose from organisational change, change-control governance may require strengthening.
Simply retraining the individuals involved is unlikely to be sufficient where the process itself permits the same failure to recur.
29. Effectiveness Verification
Effectiveness should test the interface that failed.
For a transfer-timeliness problem, an effectiveness review might sample transactions after implementation and assess both completeness and timeliness.
For a data-quality problem, it might test whether the receiving function now obtains the information required for correct assessment.
For a governance problem, it might assess whether material exceptions are now visible through the appropriate oversight forum and whether escalation decisions occur as intended.
The measure should therefore be derived from the root cause and the control that was changed.
30. What Inspectors May Ask
The following are illustrative inspection questions, not a published regulator checklist:
- Which function owns the first step in this process?
- Who receives the information next?
- How is the transfer timestamp recorded?
- How does the receiving function know that it should expect the information?
- What happens when the transfer is late or incomplete?
- Who monitors exceptions?
- How are local and central responsibilities reconciled?
- What evidence demonstrates vendor performance?
- How are organisational changes assessed for interface impact?
- How does the QPPV receive information about material interface failures?
- Can you show us a recent example where an interface failure was detected and corrected?
- How do you know the corrective action was effective?
31. Practical Self-Inspection Framework
An organisation can assess a critical interface using six questions:
| Question | Evidence sought |
|---|---|
| What must cross the interface? | Defined data/information requirements |
| Who is responsible? | Current responsibility assignment |
| When must it happen? | Applicable timing/control requirement |
| How is completion demonstrated? | Transaction record, acknowledgement or reconciliation |
| What happens when it fails? | Exception, escalation and CAPA process |
| Who knows whether it works? | Oversight metrics, review and governance evidence |
A useful exercise is to select one real transaction and attempt to answer all six questions using records rather than interviews alone.
32. Relationship to Published Inspection Evidence
Cross-functional weaknesses are not necessarily reported as a separate inspection category. They may appear under categories such as adverse-reaction management and reporting, QMS, PSMF, QPPV, contracts and agreements, computerised systems or communication.
EMA's 2024 human pharmacovigilance inspection report illustrates why the interface perspective is useful: adverse-reaction management and reporting was the largest finding area, with findings involving submission and follow-up, medical review and coding, literature screening, and receipt and collation of ICSRs from all sources at a single EU collection point. QMS and PSMF were also among the three most common finding areas. citeturn0search19
The report does not classify these observations as a single "cross-functional interface" category. The interface model is therefore an analytical way of understanding how deficiencies can arise across boundaries, not a claim that regulators use this exact category.
33. Inspection Readiness: The Evidence Chain
A mature organisation should be able to move from a documented responsibility to operational evidence without relying on informal explanations.
For a critical interface, the evidence chain should generally be:
Requirement
↓
Defined responsibility
↓
Procedure / agreement
↓
Training / implementation
↓
Actual transaction
↓
Control / reconciliation
↓
Exception management
↓
Oversight
↓
Effectiveness evidence
The exact evidence will vary by process. The principle is that each link should be sufficiently controlled to support the next.
34. Key Takeaways
- Pharmacovigilance controls frequently depend on interfaces between functions, entities, systems and vendors.
- A procedure on each side of an interface does not demonstrate that the interface itself works.
- Responsibility, accountability and oversight should be distinguished.
- The most informative inspection test often follows a real transaction across the organisational boundary.
- Affiliates, regulatory affairs, medical information, quality, clinical functions, vendors and technology systems can all create material PV interfaces.
- Contracts and responsibility matrices define arrangements but do not by themselves prove effective implementation.
- Exceptions and failed transfers are often more informative than successful transactions when testing a control.
- Interface deficiencies should be assessed for systemic significance rather than automatically treated as isolated human errors.
- CAPA should address the failed control and its root cause, not merely retrain the people involved.
- Effectiveness verification should test whether the interface now operates reliably.
- The QPPV's oversight should be supported by evidence showing visibility of material interface risks and the ability to drive corrective action.
- Cross-functional findings may be recorded by regulators under other inspection categories; the interface model is an analytical framework for understanding them.
35. References
- European Medicines Agency. Good pharmacovigilance practices (GVP) Module III — Pharmacovigilance inspections, current published revision. urlEMA GVP Module IIIhttps://www.ema.europa.eu/en/documents/scientific-guideline/guideline-good-pharmacovigilance-practices-module-iii-pharmacovigilance-inspections_en.pdf
- European Medicines Agency. Pharmacovigilance system: questions and answers, including subcontracting and pharmacovigilance-system responsibilities. urlEMA pharmacovigilance system Q&Ahttps://www.ema.europa.eu/en/human-regulatory-overview/post-authorisation/pharmacovigilance-post-authorisation/pharmacovigilance-system-questions-answers
- European Medicines Agency. Coordination of pharmacovigilance inspections, including human pharmacovigilance inspection procedures and inspection Q&As. urlEMA coordination of pharmacovigilance inspectionshttps://www.ema.europa.eu/en/coordination-pharmacovigilance-inspections-0
- European Medicines Agency. Annual report of the Pharmacovigilance Inspectors' Working Group for 2024, EMA/INS/PhV/122716/2025. urlEMA PhV IWG Annual Report 2024https://www.ema.europa.eu/en/documents/report/annual-report-pharmacovigilance-inspectors-working-group-2024_en_0.pdf
- European Commission. Commission Implementing Regulation (EU) No 520/2012, as amended, on the performance of pharmacovigilance activities. urlEUR-Lex — Regulation 520/2012https://eur-lex.europa.eu/eli/reg_impl/2012/520/oj
- European Medicines Agency. Good pharmacovigilance practices (GVP) — current modules and guidance. urlEMA GVP overviewhttps://www.ema.europa.eu/en/human-regulatory-overview/post-authorisation/pharmacovigilance-post-authorisation/good-pharmacovigilance-practices-gvp
Regulatory Note
This article is an educational analysis of EU pharmacovigilance inspection and governance principles. It distinguishes legal and GVP requirements from recommended operational practice and illustrative inspection scenarios. The examples and inspection questions that are not attributed to an authoritative source are hypothetical and must not be represented as published inspection findings. Current legislation, GVP guidance, national requirements and product-specific obligations should be checked before the material is used for regulatory or operational decisions.