Archived Revision: You are viewing historical Version 1 of this article. View current active version →

Audio Lesson 15 min

EU Pharmacovigilance Inspection Findings: Data Integrity, Traceability and the Evidence Chain

Purpose and Scope

A pharmacovigilance inspection ultimately depends on evidence. An organisation may have appropriate procedures, trained personnel and a well-designed quality system, but an inspector must still be able to establish that safety information was received, processed, assessed, reported and governed as described. That requires records that are sufficiently reliable and traceable to reconstruct what happened.

This article examines data integrity and traceability from that inspection perspective. It is not a general data-integrity guide for all pharmaceutical operations. Its focus is the pharmacovigilance system: the records, systems, interfaces and decisions that allow an inspector to move from a regulatory requirement to the underlying evidence.

The subject is broader than the accuracy of individual data fields. A case may contain a correct date while the organisation cannot establish who entered it or when it was changed. A signal decision may be scientifically reasonable while the supporting analysis cannot be reconstructed. A procedure may require reconciliation while the organisation cannot demonstrate which records were reconciled or how exceptions were resolved. These are different problems, but all can weaken the evidence chain.

The central inspection question is therefore:

Can the organisation demonstrate, through reliable and traceable evidence, what happened to safety information and why the resulting pharmacovigilance decision was made?

Why Data Integrity Matters in Pharmacovigilance

Pharmacovigilance is an information-dependent regulatory system. Decisions about individual cases, aggregate safety, signals, risk-management measures and regulatory reporting depend on information being transferred between people, processes and systems. Each transfer creates an opportunity for information to be lost, altered, duplicated or disconnected from its source.

The resulting risk is not limited to incorrect data. An inability to reconstruct the history of information can itself undermine confidence in the process. For example, if a serious case was expedited correctly but the organisation cannot demonstrate when the report became known to it, the inspection question is different from simply asking whether the final submission was made.

Traceability therefore connects data quality with process control. The inspector needs to understand not only whether an outcome appears correct, but whether the organisation can demonstrate how it arrived there.

Regulatory Framework

The EU pharmacovigilance framework establishes quality-system requirements for pharmacovigilance activities and requires appropriate documentation and record management. GVP Module I describes the quality-system principles applicable to the pharmacovigilance system, while Module II addresses the pharmacovigilance system master file and Module III addresses pharmacovigilance inspections.

The detailed controls appropriate to a particular record depend on the activity. ICSR processing, signal management, aggregate reporting, risk management, quality management and electronic systems have different operational characteristics. Data-integrity controls should therefore be understood in relation to the process they support rather than as an isolated set of generic technical rules.

The distinction between binding legislation, GVP guidance, EMA procedures and recommended operational practice remains important. An organisation may adopt a particular technical control as its chosen method of meeting a quality objective; that does not necessarily make the technical method itself an EU legal requirement.

Data quality concerns whether information is fit for its intended purpose. Data integrity concerns whether the information and its history remain reliable and appropriately controlled throughout its lifecycle.

A useful inspection distinction is:

Situation Primary question
Incorrect value Is the data accurate?
Missing value Is the record complete?
Conflicting values Which source is authoritative and why?
Unexplained change Can the change be reconstructed?
Missing audit trail Can system activity be attributed and reconstructed?
Uncontrolled spreadsheet Are calculations and changes appropriately controlled?
Broken interface Was information transferred completely and accurately?
Unclear approval Can the decision and its authorisation be demonstrated?

These categories can overlap. A data-integrity weakness can contribute to a data-quality problem, but not every data-quality error is a data-integrity failure.

This distinction matters for inspection findings because the appropriate root cause and CAPA depend on the actual failure mechanism.

The Pharmacovigilance Evidence Chain

For inspection purposes, a pharmacovigilance activity can often be represented as a chain:

Source information
      ↓
Receipt / capture
      ↓
Data entry or transfer
      ↓
Processing
      ↓
Medical / scientific assessment
      ↓
Decision
      ↓
Review / approval
      ↓
Regulatory submission or other action
      ↓
Retained evidence

The chain is rarely linear in practice. Information may return to an earlier stage through follow-up, corrections or new evidence. Multiple systems may hold different parts of the record. An inspector therefore needs to be able to navigate both forward and backward through the chain.

A strong system makes the relationships between these records understandable. A weak system may contain every individual document but leave the connections between them uncertain.

Source Data and Provenance

The starting point of the evidence chain is the source of the safety information. Depending on the activity, the source may be a spontaneous report, healthcare professional communication, patient report, literature article, clinical or non-interventional study information, regulatory communication, partner transmission or another legitimate source.

The organisation should be able to establish the provenance of information sufficiently to support the pharmacovigilance activity. The level of detail required depends on the process and applicable requirements. The purpose is not to create unnecessary duplication, but to preserve the information necessary to understand where material safety information came from and how it entered the system.

During inspection, provenance can become particularly important when the data in the final safety database differs from the original source. A transformation may be legitimate, such as standardisation or coding, but the organisation should be able to explain the transformation and, where necessary, trace the resulting information back to the source.

Capture and Receipt Controls

The point at which information enters the pharmacovigilance system is a critical control point. The organisation needs an appropriate mechanism for identifying and recording receipt, routing the information to the responsible process and establishing relevant dates.

Potential inspection evidence can include intake records, correspondence, electronic transmission logs, workflow timestamps and case-creation records. The exact evidence will vary by intake channel.

A potential failure pattern is an unexplained gap between receipt of information and its appearance in the safety system. That gap does not automatically demonstrate a reportable compliance failure; its significance depends on the information involved, applicable timelines and the organisation's process. It does, however, create a traceability question that the organisation should be able to answer.

Manual Data Transfer

Manual transfer between systems or records introduces an additional control point because a person becomes part of the data-transfer mechanism. Examples include transferring information from email into a safety database, copying information between databases, manually preparing reconciliation files or entering data from documents.

Manual activity is not inherently unacceptable. The inspection concern is whether the organisation has appropriate controls over activities that can change or reproduce safety information.

Relevant controls may include defined procedures, independent checks where appropriate, reconciliation, controlled templates, restricted access, documented review and exception handling. The correct combination depends on the risk and complexity of the activity.

Electronic Systems and Audit Trails

Electronic systems can provide powerful traceability because they may record user identity, timestamps, changes and workflow events. An audit trail is useful only when it is appropriately configured, retained and accessible for the intended purpose.

The existence of an audit trail does not by itself establish data integrity. Inspectors may need to determine whether relevant events are captured, whether users can make changes outside the controlled workflow, how privileged access is governed and whether the organisation reviews system-generated information when appropriate.

Conversely, not every system used in pharmacovigilance will provide the same technical audit-trail functionality. The organisation's control framework should reflect the system's characteristics and the risk associated with the activity.

Spreadsheets and End-User Tools

Spreadsheets can become part of the pharmacovigilance evidence chain even when they are not the primary safety database. They may support reconciliation, tracking, metrics, literature processes, signal analyses, oversight activities or CAPA monitoring.

Inspection significance depends on what the spreadsheet does. A simple administrative list and a spreadsheet that determines which cases are reported are not equivalent risks.

Where a spreadsheet materially affects a pharmacovigilance decision or record, inspectors may reasonably examine version control, access, formula integrity, change history, review and reconciliation with authoritative systems. These controls are examples of risk-based operational practice; the exact technical method is not universally prescribed by GVP.

Interfaces Between Systems

Pharmacovigilance systems frequently exchange information with other systems. An interface may connect a safety database with a reporting gateway, document-management system, medical-information platform, clinical system, regulatory repository or partner system.

The critical inspection question is whether the organisation understands what information should cross the interface and how it assures that the transfer works as intended.

Evidence may include interface specifications, validation or testing records, transmission logs, reconciliation, exception reports, incident records and change controls. Where an interface fails, the organisation should have an appropriate mechanism for detecting and managing the failure rather than assuming that successful transmission is guaranteed.

Reconciliation as a Traceability Control

Reconciliation is particularly valuable because it tests relationships between records rather than merely inspecting individual records.

For example, reconciliation can help establish that information expected in one system is present in another, that relevant discrepancies have been investigated and that exceptions are resolved. The method, frequency and scope should be appropriate to the systems and process involved.

A reconciliation record stating that two populations matched may be insufficient if the organisation cannot demonstrate what populations were compared, when the comparison occurred, which criteria were applied and how exceptions were handled. The evidence should be proportionate to the significance of the reconciliation.

Version Control and Document History

Documents supporting pharmacovigilance decisions should be controlled so that the organisation can establish which version applied at the relevant time.

This becomes important when an inspector reconstructs a historical event. A current procedure may differ from the procedure that governed the activity when the event occurred. Similarly, a current analysis may not show the assumptions or data available when an earlier safety decision was made.

Historical reconstruction does not necessarily require retention of every intermediate working document. It requires sufficient controlled records to demonstrate the basis for material activities and decisions in accordance with applicable record-management requirements.

Decisions Need Evidence, Not Just Conclusions

A pharmacovigilance system produces many decisions: case seriousness and expectedness assessments, reportability decisions, signal evaluations, aggregate conclusions, risk-management decisions and responses to new information.

An inspection does not necessarily require a lengthy narrative for every routine decision. The evidence should nevertheless be sufficient to demonstrate the basis of material decisions and the application of the relevant process.

A recurring weakness can arise when the final conclusion is retained but the supporting analysis is not readily reconstructable. In such circumstances, the organisation may be able to state what it decided without demonstrating why the decision was reasonable at the time.

Traceability of Changes

Changes to pharmacovigilance records are a normal part of case follow-up and data maintenance. A follow-up report can legitimately change information; a medical assessment can be updated when new evidence becomes available; coding can be corrected.

The inspection concern is therefore not whether records ever change. It is whether material changes are controlled and sufficiently attributable to establish what changed, why it changed and, where necessary, who performed or approved the change.

This is particularly important for retrospective corrections. A system in which users can overwrite historical information without preserving the original state can make reconstruction difficult even if the final record is correct.

What Inspectors May Trace

An inspector may select a safety activity and work through several connected records rather than reviewing each document in isolation. For example:

Safety source
  ↓
Intake record
  ↓
Safety database
  ↓
Medical assessment
  ↓
Follow-up history
  ↓
Submission record
  ↓
Reconciliation / oversight evidence

The purpose of such testing is to determine whether the records tell a coherent story. Differences do not automatically constitute deficiencies; legitimate transformations and corrections occur. The organisation should, however, be able to explain material differences and provide the evidence supporting them.

Data Integrity Across Organisational Boundaries

The evidence chain can cross company boundaries. Affiliates, license partners, contract service providers and other organisations may create or process safety information before it reaches the MAH's central pharmacovigilance system.

The same principle applies: the organisation should understand the hand-offs that matter, the information exchanged, the responsibilities assigned and the controls used to detect failures.

A contract or safety data exchange agreement can define responsibilities, but the existence of the document does not by itself prove that the interface works. Operational evidence remains necessary.

Privileged Access and Segregation of Activities

Access rights can affect data integrity because users with broad privileges may be able to create, modify or delete information beyond the normal workflow.

Risk-based access management can include role definition, periodic review, controlled provisioning and appropriate management of privileged accounts. Where the system supports it, activity performed under privileged access should remain attributable.

Segregation of duties can be relevant where a single individual could otherwise create and approve a material change without independent control. The appropriate degree of segregation depends on the process, system and organisation. It should not be presented as a universal requirement for every pharmacovigilance activity.

Data Migration and System Change

System migration creates a particularly important traceability problem because historical records may move from one technical environment to another. A successful migration requires more than confirming that a new database is operational.

The organisation should be able to demonstrate how migration requirements were defined, how data were transferred, how completeness and accuracy were assessed and how discrepancies were handled. Where historical audit-trail information cannot be migrated in its original technical form, the organisation should have an appropriate documented strategy for preserving the information needed for regulatory reconstruction.

The specific validation and migration approach depends on the system and its intended use. The inspection focus is whether the organisation can demonstrate that the migration did not compromise the reliability or retrievability of pharmacovigilance records.

Data Retention and Retrieval

A record has limited inspection value if it cannot be retrieved when required. Retention controls therefore form part of the evidence chain.

Inspectors may request historical records from a defined period, sometimes across systems or organisational changes. The organisation should be able to identify where relevant records reside, retrieve them in an understandable form and establish their relationship to the pharmacovigilance activity being examined.

A historical archive that preserves files but loses the context needed to interpret them can create a traceability problem even if no record has technically been deleted.

23. When a Data Discrepancy Becomes an Inspection Concern

Not every discrepancy discovered during inspection is a data-integrity finding. Pharmacovigilance systems contain legitimate corrections, transformations, reconciliations and updates. The significance of a discrepancy depends on its nature, materiality, detectability and effect on the reliability of the pharmacovigilance process.

A useful assessment asks four questions. First, what is different? Second, why is it different? Third, can the organisation demonstrate that explanation from contemporaneous evidence? Fourth, did the discrepancy affect a safety assessment, reporting obligation, regulatory decision or ability to reconstruct the activity?

A minor transcription error that was promptly detected and corrected through a controlled process is fundamentally different from an unexplained alteration of a serious case that cannot be reconstructed. The distinction should be made from evidence rather than from the mere presence of an error.

24. Data Integrity Versus Process Failure

A process can fail even when the underlying data remain accurate. Conversely, data can be inaccurate without evidence of deliberate or uncontrolled alteration.

For example, a reconciliation may have been performed incorrectly but still leave the underlying databases unchanged. That is principally a process-control problem. If historical values were overwritten and the system cannot establish what the original values were, the problem additionally concerns traceability and data integrity.

This distinction matters for root-cause analysis. Treating every data problem as a generic "data integrity issue" can produce inappropriate CAPA and obscure the actual control failure.

25. Potential Inspection Finding Patterns

The following are analytical categories for self-inspection. They are illustrative patterns, not claims that a regulator has recorded each example as a finding.

Unexplained data changes

Material information has changed, but the organisation cannot establish the reason, timing or responsible user.

Incomplete auditability

The system does not retain sufficient information to reconstruct relevant activity.

Uncontrolled manual transfer

Safety information is repeatedly transferred manually without controls proportionate to the associated risk.

Interface failure without detection

An important electronic transfer can fail or omit information without an effective mechanism identifying the problem.

Reconciliation without resolution

Reconciliations identify discrepancies but there is insufficient evidence that exceptions were investigated and resolved.

Historical reconstruction weakness

The organisation can produce the current record but cannot reliably reconstruct the state of the record or decision at the relevant historical time.

Uncontrolled end-user computing

A spreadsheet or other end-user tool materially influences pharmacovigilance activity without controls proportionate to its function.

Inadequate access governance

Users have access inconsistent with their responsibilities, or privileged activity is not sufficiently controlled or attributable.

26. How an Inspector Can Test a Data-Integrity Control

An effective inspection test begins with a real pharmacovigilance transaction rather than a policy statement.

For example, the inspector may select a serious adverse reaction and establish when it was received, when it entered the safety database, what information was initially recorded, who assessed it, what follow-up occurred, when the report was submitted and whether subsequent changes can be reconstructed.

The inspector can then compare the evidence across systems. A discrepancy does not automatically establish non-compliance; the organisation's explanation and supporting records determine its significance.

This approach can be extended to aggregate processes. An inspector may select a signal decision and trace the source data, analysis, review, decision record and subsequent regulatory action. The question becomes whether the evidence chain supports the conclusion.

27. Sampling Strategy for Self-Inspection

Data-integrity testing is most useful when samples deliberately cross different risk points. A self-inspection should not select only clean, recently completed records.

Useful samples may include:

Sample Why it is informative
Recently modified case Tests change traceability
Case with follow-up Tests longitudinal reconstruction
Case crossing an affiliate boundary Tests hand-off controls
Case involving manual data entry Tests transfer controls
Case affected by system migration Tests historical integrity
Reconciliation exception Tests discrepancy management
Signal decision Tests analytical evidence chain
Recently changed procedure Tests document history
Vendor-generated record Tests outsourced traceability
Historical record Tests retention and retrieval

The sample design should reflect the pharmacovigilance system's actual risks.

28. Root-Cause Analysis

When a traceability weakness is identified, the root cause should be sought at the level of the failed control.

Consider an illustrative situation in which a case contained a material change but the audit trail did not identify the user. The immediate correction might be to restore appropriate system configuration. A deeper analysis would ask why the configuration was changed, whether the change was authorised, whether validation or change control assessed the effect on auditability, whether other environments were affected and how the issue escaped detection.

Possible root causes could include inadequate change control, incomplete system requirements, insufficient testing, inappropriate access privileges, weak vendor oversight or ineffective periodic review. The evidence should determine which explanation is justified.

29. CAPA for Data-Integrity Findings

An appropriate CAPA should address both the affected record and the control that allowed the problem to occur.

Depending on the circumstances, actions may include correcting records through a controlled process, assessing affected populations, restoring appropriate system configuration, strengthening requirements or testing, revising procedures, changing access controls, improving reconciliation or introducing monitoring.

The organisation should also consider whether the same failure mechanism could exist elsewhere. A system configuration problem affecting one workflow may have broader scope than the initial record in which it was discovered.

30. Effectiveness Verification

Effectiveness verification should test the control that was intended to prevent recurrence.

If the CAPA introduced an interface reconciliation, effectiveness should establish whether the reconciliation reliably detects the relevant failures over an appropriate period. If access governance was strengthened, effectiveness should test whether inappropriate access is now prevented or detected. If a system change was validated, effectiveness may require evidence that the relevant functionality continues to operate as intended after implementation.

Simply demonstrating that training occurred or that a procedure was revised does not establish effectiveness unless those actions directly address the identified root cause and the effectiveness criterion tests their intended result.

This links directly to the CAPA principles developed in I4.

31. Data Integrity and the QPPV

The QPPV does not need to perform technical system administration to exercise effective oversight of data integrity. The QPPV does need sufficient visibility of material weaknesses that could affect the reliability of pharmacovigilance information or the ability to demonstrate compliance.

Governance arrangements should allow significant system failures, recurring reconciliation problems, material data corrections, major migrations and serious audit or inspection issues to reach the appropriate pharmacovigilance decision-makers.

Where a material data-integrity problem is identified, QPPV oversight may include assessing whether the issue affects other pharmacovigilance processes, products, markets or historical records and whether regulatory communication or other action needs consideration.

The precise escalation mechanism is organisational and risk-based; the principle is that material information must reach those with responsibility and authority to act.

32. Vendor and Partner Evidence

Outsourced systems and processes can complicate data-integrity assessment because the MAH may not directly administer the relevant technology.

The organisation should nevertheless be able to demonstrate how the vendor's activities are controlled. Depending on the service, evidence may include contractual requirements, technical specifications, validation or qualification records, audit reports, service monitoring, incident management, reconciliation and change-control records.

A vendor's statement that a system is compliant is not equivalent to evidence that the specific pharmacovigilance process is controlled. Oversight should be based on the service actually provided and the risks associated with it.

33. Inspection Questions

The following are illustrative inspection questions, not an official EMA or national competent-authority checklist:

34. Building an Evidence-Ready Pharmacovigilance System

An evidence-ready system does not mean generating a record for every conceivable event. It means designing controls so that important activities leave sufficient evidence to reconstruct what happened.

The strongest systems tend to make evidence generation part of normal workflow. Timestamps are generated by controlled systems; changes are attributable; reconciliations produce records; decisions are documented at the point they are made; approvals are linked to the relevant version; exceptions enter controlled workflows rather than disappearing into informal correspondence.

This approach reduces dependence on retrospective reconstruction and makes inspection preparation a consequence of ordinary system operation rather than a separate exercise performed immediately before inspection.

35. A Practical Data-Integrity Self-Inspection Framework

A useful internal assessment can be organised into six questions:

  1. Source — Can we establish where the information came from?
  2. Capture — Can we establish when and how it entered the system?
  3. Transformation — Can we explain material coding, transfer or modification?
  4. Decision — Can we reconstruct the assessment and decision?
  5. Action — Can we demonstrate the resulting reporting or risk-management action?
  6. Retention — Can we retrieve and interpret the evidence later?

If the answer to any question is no, the next step is not automatically to create another document. The organisation should identify why the evidence is unavailable and whether the underlying process requires improvement.

36. Relationship to the Inspection Series

Data integrity and traceability provide an underlying evidentiary layer for the other inspection domains covered in this series. A PSMF finding depends on being able to establish what the system actually does. A cross-functional finding depends on evidence of what crossed an organisational boundary. CAPA effectiveness depends on reliable evidence that the corrected control continues to work.

The next domain-specific articles can therefore use the same evidence-chain perspective without repeating this article's technical discussion.

The recurring model remains:

requirement → process → data → evidence → decision → action → verification.

37. Key Takeaways

38. References

  1. European Commission. Commission Implementing Regulation (EU) No 520/2012, as amended, on the performance of pharmacovigilance activities. urlEUR-Lex — Regulation 520/2012https://eur-lex.europa.eu/eli/reg_impl/2012/520/oj
  2. European Medicines Agency. Good pharmacovigilance practices (GVP) Module I — Pharmacovigilance systems and their quality systems, current revision. urlEMA GVP Module Ihttps://www.ema.europa.eu/en/human-regulatory-overview/post-authorisation/pharmacovigilance-post-authorisation/good-pharmacovigilance-practices-gvp/gvp-modules
  3. European Medicines Agency. Good pharmacovigilance practices (GVP) Module II — Pharmacovigilance system master file, current revision. urlEMA GVP Module IIhttps://www.ema.europa.eu/en/human-regulatory-overview/post-authorisation/pharmacovigilance-post-authorisation/good-pharmacovigilance-practices-gvp/gvp-modules
  4. European Medicines Agency. Good pharmacovigilance practices (GVP) Module III — Pharmacovigilance inspections, current revision. urlEMA GVP Module IIIhttps://www.ema.europa.eu/en/human-regulatory-overview/post-authorisation/pharmacovigilance-post-authorisation/good-pharmacovigilance-practices-gvp/gvp-modules
  5. European Medicines Agency. Good pharmacovigilance practices (GVP) Module VI — Collection, management and submission of reports of suspected adverse reactions to medicinal products, current revision. urlEMA GVP Module VIhttps://www.ema.europa.eu/en/human-regulatory-overview/post-authorisation/pharmacovigilance-post-authorisation/good-pharmacovigilance-practices-gvp/gvp-modules
  6. European Medicines Agency. Good pharmacovigilance practices (GVP) Module IX — Signal management, current revision. urlEMA GVP Module IXhttps://www.ema.europa.eu/en/human-regulatory-overview/post-authorisation/pharmacovigilance-post-authorisation/good-pharmacovigilance-practices-gvp/gvp-modules
  7. European Medicines Agency. Annual report of the Pharmacovigilance Inspectors' Working Group for 2024, published inspection activity and findings. urlEMA PhV IWG Annual Report 2024https://www.ema.europa.eu/en/documents/report/annual-report-pharmacovigilance-inspectors-working-group-2024_en.pdf
  8. European Medicines Agency. Pharmacovigilance inspections, including EU inspection procedures and coordination. urlEMA pharmacovigilance inspectionshttps://www.ema.europa.eu/en/human-regulatory-overview/post-authorisation/pharmacovigilance-post-authorisation/pharmacovigilance-inspections

Regulatory Note

This article is an educational analysis of data integrity, traceability and evidence in EU pharmacovigilance inspections. It distinguishes regulatory requirements and guidance from recommended operational practice and illustrative inspection scenarios. The analytical categories and questions presented as illustrative must not be interpreted as published regulatory findings or official inspection checklists. Current legislation, GVP guidance, Union procedures, national requirements and product-specific obligations should be checked before using this material for operational or regulatory decisions.

39. Interpreting Evidence During an Inspection

The strength of an evidence chain depends on the relationship between records, not simply on the number of records produced. An organisation may provide a large volume of documents while leaving the critical relationship between source, action and decision uncertain.

A useful inspection approach is therefore to ask whether each important assertion can be supported by contemporaneous evidence and whether the evidence is internally consistent. Where records conflict, the organisation should be able to explain the conflict using controlled evidence rather than relying solely on recollection.

This is especially relevant when personnel have changed roles or when systems have been replaced. Institutional memory can help explain a historical process, but it is weaker than contemporaneous documentation for reconstructing a material regulatory activity.

40. Data Integrity and Organisational Change

Mergers, acquisitions, divestments, outsourcing transitions and reorganisations can change where pharmacovigilance data are stored and who controls them. The resulting risks are not limited to the transition date. Historical records may remain relevant for years after a system or organisational arrangement has changed.

A robust transition therefore considers data ownership, retention, accessibility, interfaces, responsibilities, system changes and historical reconstruction. The PSMF and associated quality documentation should remain consistent with the resulting system.

Inspectors may select a historical record that predates the current organisation and ask the current MAH to reconstruct how that record was managed. The organisation should have an appropriate strategy for such historical evidence rather than assuming that responsibility ended when the organisational structure changed.

41. Data Integrity and Inspection Responses

If an inspection identifies a data-integrity concern, the response should avoid prematurely narrowing the issue to the individual record in which it was discovered.

The organisation should assess whether the problem could affect other records, users, systems, products, markets or historical periods. The scope assessment should be evidence-based and proportionate to the nature of the issue.

Where uncertainty remains because historical evidence is unavailable, that uncertainty should itself be recognised in the risk assessment. A confident statement that records were unaffected is difficult to support if the organisation cannot demonstrate the basis for reaching that conclusion.

42. Regulatory Reporting and Data Integrity

Regulatory reporting adds particular significance to traceability because safety information can move from internal systems into legally relevant submissions.

An organisation should be able to establish how reportable information was identified, processed, reviewed and submitted, including the relevant dates and any material corrections. The precise evidence will depend on the reporting process and systems involved.

An apparent match between an internal case and an external submission does not necessarily prove that the entire reporting process was controlled. An inspector may examine how the organisation knows that the correct information was selected and transferred and how discrepancies were detected.

43. Signal Management and Analytical Traceability

Signal management illustrates why traceability extends beyond transactional data. A signal conclusion depends on data sources, analytical methods, clinical or scientific interpretation, review and decision-making.

An inspector may therefore ask not only for the final signal assessment but also for the evidence supporting the analysis. The organisation should be able to establish what information was considered, what analytical approach was used, what material assumptions applied and how the resulting conclusion was reviewed.

The appropriate degree of documentation depends on the signal-management process. The objective is to preserve sufficient evidence to reconstruct the material reasoning behind the decision.

44. Aggregate Reports and Historical Reconstruction

The same principle applies to PSURs, PBRERs and other aggregate safety assessments. An aggregate conclusion should be traceable to the underlying data and analysis to an extent appropriate to the process.

If an inspector challenges a historical conclusion, the organisation may need to demonstrate which data were available at the time, how they were evaluated and what governance process led to the conclusion. A later analysis using updated information cannot automatically substitute for evidence of the historical decision-making process.

45. Data Integrity in Risk-Minimisation Activities

Risk-minimisation activities can also generate evidence that needs to be reliable and traceable. Depending on the measure, this may include distribution records, educational-material dissemination, training records, controlled-access documentation, surveys, registries or effectiveness assessments.

The relevant inspection question is whether the retained evidence supports the claim that the activity was implemented and, where applicable, whether it achieved the intended objective.

For example, a record that educational material was sent is not necessarily evidence that the intended recipients received or used it. The appropriate evidence depends on the effectiveness question being asked.

46. Distinguishing Evidence Gaps From Evidence Volume

A common response to inspection preparation is to collect more documents. More documents do not necessarily create a stronger evidence chain.

The useful question is whether the evidence answers the reconstruction question. Ten records that all demonstrate that a procedure existed may be less useful than one controlled record demonstrating what happened in a particular transaction.

An evidence-ready system therefore prioritises relevant, attributable and interpretable records over indiscriminate document accumulation.

47. Governance Metrics for Data Integrity

Organisations may use metrics to monitor data-integrity risks, but metrics should be interpreted carefully. Examples could include reconciliation exceptions, unresolved interface failures, material data corrections, access-control exceptions, system incidents or recurring data-quality discrepancies.

A low number of reported issues does not automatically demonstrate a healthy system. A system that does not detect failures can appear better than a system with effective detection and transparent reporting.

Metrics should therefore be interpreted alongside detection capability, investigation quality, recurrence and the organisation's ability to demonstrate control effectiveness.

48. Practical Inspection Preparation

An organisation preparing for inspection can select several high-risk transactions and conduct an end-to-end reconstruction without creating new records solely for the exercise.

For each transaction, the team should attempt to answer:

The exercise is most useful when performed using the records that would actually be available during inspection.

49. What Good Looks Like

A well-controlled pharmacovigilance evidence chain does not eliminate all errors or manual activities. Instead, it makes important activities reconstructable and makes significant failures detectable.

The organisation knows which systems and records are authoritative, how information moves between them, where manual intervention occurs, how changes are controlled, how discrepancies are investigated and how material decisions are documented.

When an inspector asks a difficult historical question, the organisation can answer by following evidence through the system rather than reconstructing events from memory.

50. Final Inspection Framework

The data-integrity perspective can be reduced to a practical sequence:

Can we identify the source?
        ↓
Can we establish receipt and capture?
        ↓
Can we reconstruct transformations and changes?
        ↓
Can we establish who performed material activities?
        ↓
Can we reconstruct the decision?
        ↓
Can we demonstrate the resulting action?
        ↓
Can we retrieve the evidence later?

A weakness at any stage should prompt assessment of the underlying control. The objective is not perfect documentation; it is sufficient reliability, traceability and evidence to support safe and compliant pharmacovigilance activity.

51. Key Takeaways for Inspection Management

Data integrity should be managed as part of the pharmacovigilance system rather than as an isolated information-technology topic. The critical controls are distributed across intake, processing, review, reporting, quality management, system administration, outsourcing and record retention.

For the QPPV and pharmacovigilance leadership, the practical objective is to maintain visibility of material weaknesses in those controls and to ensure that significant issues are assessed for scope, patient-safety relevance and regulatory impact.

For inspection preparation, the most valuable exercise is often not another document review but an evidence-chain reconstruction using real historical transactions. That exercise can reveal weaknesses that a review of procedures alone will not identify.

Regulatory Note

This article is an educational analysis of data integrity, traceability and evidence in EU pharmacovigilance inspections. It distinguishes legal requirements and GVP guidance from recommended operational practice and illustrative inspection scenarios. The examples and inspection questions that are not explicitly attributed to an authoritative source are hypothetical and must not be interpreted as published inspection findings or official regulatory checklists. Current legislation, GVP guidance, Union procedures, national requirements and product-specific obligations should be checked before using this material for operational or regulatory decisions.

Revision History