EU Pharmacovigilance Inspection Findings: ICSR and Case-Processing Controls
- EU Pharmacovigilance Inspection Findings: ICSR and Case-Processing Controls
- Introduction
- 1. The inspection question: can the MAH reconstruct the case lifecycle?
- 2. Regulatory frame: legal duties, GVP guidance, and operational controls
- 3. The evidence set an inspector may ask to see
- 4. Start at the source: receipt, validity, and the reporting clock
- 5. Medical review, coding, and source fidelity
- 6. Electronic transmission: a sent message is not the end of the control
- 7. What the published inspection evidence says
- 8. Illustrative failure patterns and how to test them
- 9. Root cause, CAPA, and QPPV oversight
- 10. Practical inspection-readiness review
- Key Takeaways
- References
- Regulatory Note
Introduction
An individual case safety report (ICSR) is both a clinical record and a regulatory data submission. Inspectors can therefore test more than whether a message reached EudraVigilance on time. They can follow the information from the first point at which the marketing authorisation holder (MAH) became aware of a suspected adverse reaction, through validity assessment and medical processing, into the submitted message, its acknowledgement, any follow-up, and the quality system that should detect and correct failures.
This article focuses on that inspection trail. It does not repeat the full operational account of ICSR data quality, coding, or reconciliation in GVP Module VI: Data Quality, Case Processing Controls and Reconciliation. Instead, it asks what an inspector can reasonably test, what records make the process verifiable, and how the MAH should investigate a control weakness.
The distinction between published findings and examples matters. The EMA Pharmacovigilance Inspectors Working Group (PhV IWG) reported specific ICSR-related findings in its 2024 annual report; those are identified below as reported findings. Other failure patterns are labelled illustrative. They should not be read as a claim that a named company or inspection experienced them.
1. The inspection question: can the MAH reconstruct the case lifecycle?
The MAH should be able to explain what happened to an ICSR and support that account with consistent records. An inspector may start from an incoming email, a literature hit, a patient-support programme record, a vendor transfer, or an EudraVigilance case and ask the organisation to show each relevant decision and hand-off.
The trace may include:
- when and where the information was first received;
- when it entered the MAH's pharmacovigilance process;
- how the report was screened for validity, seriousness, and reporting scope;
- how the source information was represented in the safety database;
- what medical assessment, coding, and follow-up were performed;
- whether the applicable submission clock was met;
- what EudraVigilance acknowledgement or error message followed;
- how amendments, duplicates, reconciliation exceptions, and quality issues were resolved; and
- how the process was monitored and escalated.
The inspection objective is not to demand one particular database design. It is to test whether the documented process, actual records, system outputs, and oversight evidence tell the same story.
2. Regulatory frame: legal duties, GVP guidance, and operational controls
The legal obligations arise principally from Directive 2001/83/EC, Regulation (EC) No 726/2004, and Commission Implementing Regulation (EU) No 520/2012, as amended. For marketing authorisation holders, the quality system must support collection, assessment, recording, and submission of suspected adverse reaction reports; accurate and verifiable data; and compliance with applicable reporting time limits. The MAH retains responsibility for pharmacovigilance tasks it subcontracts. [1–3]
GVP Module VI explains how the legal framework applies to collection, management, validation, follow-up, data quality, and electronic submission of ICSRs. Its text distinguishes legal requirements, commonly signalled by “shall,” from implementation guidance, commonly signalled by “should.” The distinction should be preserved in procedures and inspection responses: a recommended control can be sensible and important without being a standalone statutory requirement. [4]
For the inspection process, the current GVP Module III Revision 2 took effect on 10 September 2026. It incorporates changes associated with Commission Implementing Regulation (EU) 2025/1466, including inspection of third parties further subcontracted for pharmacovigilance tasks, clarifies remote inspections, and strengthens the risk-based inspection cycle. A third party performing pharmacovigilance tasks may be inspected to verify its capability to support the MAH's compliance. The specific ICSR requirements remain grounded in the applicable legislation and GVP Module VI. [5]
Operational controls—such as risk-based quality review, exception dashboards, or second-person review of selected cases—should be described as the MAH's chosen means of controlling its process unless a particular legal or product-specific obligation makes them mandatory.
3. The evidence set an inspector may ask to see
A defensible ICSR process is evidenced across several connected records, not by an SOP alone. Depending on inspection scope, useful material may include:
- intake logs or source-system records showing first receipt and transfer;
- triage and validity decisions, including their dates and rationale;
- the source document and the case's audit trail;
- seriousness assessment, medical review, and coding history;
- follow-up attempts and responses;
- reporting-deadline calculations and submission records;
- E2B(R3) messages and EudraVigilance acknowledgements, including errors and corrections;
- duplicate checks and decisions on linked or nullified cases;
- reconciliation records between source, vendor, safety database, and transmission records;
- QC results, deviations, CAPAs, and effectiveness checks; and
- performance information reviewed by the pharmacovigilance system and relevant management.
The set should let an independent reviewer distinguish what the reporter said, what the MAH assessed, what the system transmitted, and what action followed. If a record was corrected or a message resubmitted, the history should show the change, the reason, the responsible person, and the resulting disposition.
A gap in one record is not automatically proof of a systemic failure. The inspection significance depends on the applicable requirement, the case's impact, whether similar cases may be affected, and whether the quality system detected and addressed the issue.
4. Start at the source: receipt, validity, and the reporting clock
Receipt and awareness
The inspection trail begins before a case appears in the safety database. A report may first reach a call centre, medical-information team, affiliate, vendor, patient-support programme, market-research provider, or another company function. The organisation needs defined arrangements so that potentially reportable information is recognised and transferred without losing the original receipt date or source context.
An inspector may compare the source timestamp with intake logs, vendor transfer files, case creation, and the date used to calculate the reporting deadline. The key question is whether the MAH can show how it identified the applicable awareness date under its procedures and the relevant rules. A database “created date” does not by itself establish when the company first became aware of the information.
Validity is a threshold, not a measure of case quality
GVP Module VI describes the minimum elements used to validate an ICSR: an identifiable patient, an identifiable reporter, a suspected adverse reaction, and a suspect medicinal product. A report meeting the minimum criteria should not be held back simply because other clinically useful information is missing. Follow-up may improve the case, but it does not replace timely handling of a valid report. [4]
Inspectors may test whether staff apply the validity criteria consistently, preserve uncertainty when a required element is incomplete, and record why a report was not considered valid. They may also examine how the organisation reassesses an initially incomplete report if later information supplies a missing element.
Seriousness and the applicable reporting period
For post-authorisation reporting under Article 107(3) of Directive 2001/83/EC, MAHs submit serious suspected adverse reactions occurring in the Union and in third countries within 15 days after gaining knowledge of the event. Non-serious suspected adverse reactions occurring in the Union are submitted within 90 days. Other legal provisions apply to competent authorities, clinical trials, and particular product or use contexts; the relevant population and route should be checked rather than assuming one rule covers every report. [1]
A control should make it possible to see which deadline applied, what event triggered the clock, and whether the initial submission met it. Follow-up information may require an amended report; it does not reset the initial clock. If the organisation uses internal targets shorter than the legal limit, it should distinguish those service targets from the legal deadline.
Seriousness should be assessed against the regulatory criteria, not inferred from an event's intensity, expectedness, or apparent causal relationship alone. The record should show the available facts supporting the seriousness assessment and how new information changed it, where applicable.
Follow-up without delaying the initial report
Follow-up can be important to clinical assessment, but the attempt to obtain more information should not become a reason to delay an otherwise due report. An inspector may examine whether follow-up questions were appropriate to the case, whether attempts and responses were documented, and whether the case was updated when material information arrived.
A useful test is to select cases with incomplete clinical details and compare the documented follow-up plan with what happened next. For example, the record may need to show whether the reporter was contacted, whether no response was received, and whether the assessment remained limited by missing information. The example is illustrative; the legal and GVP requirements depend on the report and applicable circumstances.
5. Medical review, coding, and source fidelity
Structured fields make cases searchable, but they can also conceal loss of meaning. The inspection question is whether the submitted case remains faithful to the source while making the available information usable for safety monitoring.
Inspectors may compare the source document, narrative, coded reactions, seriousness fields, suspect and concomitant product data, and medical comments. They may look for contradictions that should have been clarified, unexplained transformations of uncertainty into certainty, or a clinically important fact that disappeared during processing.
Medical review should be traceable to available evidence and the MAH's procedures. It should not imply that an MAH can determine causality from every report. The report should distinguish the primary source's view from the MAH's assessment and preserve uncertainty when the facts do not support a stronger conclusion.
Coding controls should provide for appropriate terminology selection, consistent coding conventions, and review of errors that can affect analysis. Where a MedDRA version, hierarchy, or coding choice materially affects how a case is retrieved, the organisation should be able to reconstruct the decision and correct it in a controlled way. This article does not prescribe a particular QC sampling percentage; sampling design is an operational choice that should match the process risks and applicable requirements.
6. Electronic transmission: a sent message is not the end of the control
EU electronic ICSR reporting uses the ICH E2B(R3)/ISO ICSR standard and related EU implementation requirements. EMA's technical guidance describes the transmission process and message types; it also cautions that successful transmission or a message delivery notification does not necessarily mean the receiving system accepted the ICSR content. [6, 7]
The inspection trail should therefore distinguish:
- message delivery — the electronic package reached the gateway or recipient;
- business validation — the message passed applicable structural and business rules; and
- case processing by the receiver — the receiving system accepted and handled the report as intended.
A control that records only “sent” can miss rejected messages, unresolved validation errors, or a failure to correct and resubmit. Inspectors may reconcile the internal submission log against message acknowledgements, error queues, resubmissions, and case status. Where an acknowledgement contains errors, the record should show who reviewed them, what was corrected, and how timeliness was assessed.
The MAH should also be able to explain its handling of amended, follow-up, duplicate, or nullified cases. Each operation should preserve the relationship to earlier transmissions and leave a traceable reason for the action. Duplicate management must avoid both losing information and creating unrecognised multiple submissions; it requires documented assessment under the applicable rules and technical guidance. [3, 5]
7. What the published inspection evidence says
The EMA PhV IWG annual report for 2024 provides a direct, public example of reported case-processing findings. In CHMP-requested human pharmacovigilance inspections conducted during 2024, the report recorded 87 deficiencies: none critical, 29 major, and 58 minor. The most common categories were management and reporting of adverse reactions, the quality management system, and the PSMF. [8]
Within “management and reporting of adverse reactions,” the report recorded 22 findings. Twelve were major. The reported subcategories included three findings relating to submission and follow-up processes, two to medical review and MedDRA coding, two to literature screening, and two to receipt and collation of ICSRs from all sources at a single EU collection point. Ten findings were minor; three concerned submission and follow-up, with others related to literature screening and receipt/collation of reports. [8]
These are findings in the report's defined inspection population. They should not be generalised as prevalence estimates for all EU inspections, all MAHs, or all case-processing systems. Their practical value is that they show where actual deficiencies were recorded and suggest the range of activities an inspection may examine: source capture, hand-offs, medical processing, literature, follow-up, and submission.
The report does not provide a detailed public narrative for each individual finding. This article therefore does not infer company-specific facts, root causes, or inspector questions from the category counts.
8. Illustrative failure patterns and how to test them
The following examples are illustrative, not claims about published inspection cases. Each pairs a possible control failure with evidence that could help determine its scope.
| Illustrative pattern | Evidence to inspect | Initial scope question |
|---|---|---|
| A report reaches a company contact before it reaches the PV database | Source timestamps, transfer logs, case records, contract and training material | Were other channels or affiliates exposed to the same transfer delay? |
| Valid reports are held while staff seek additional details | Validity decisions, follow-up attempts, clock calculations, submission history | Did the approach affect other cases or only the selected report? |
| An E2B(R3) message is transmitted but an error acknowledgement is not resolved | Message and acknowledgement files, error queue, resubmission evidence | Did similar errors remain unresolved or affect other recipients? |
| Narrative, seriousness, coded event, or source document do not agree | Source, audit trail, medical review, coding history, QC record | Is the mismatch isolated, recurring, or caused by a shared rule or system configuration? |
| A vendor's case-transfer output is not reconciled to the MAH's receipt record | Contract, transfer logs, reconciliation exceptions, vendor oversight | Can the MAH establish that all expected cases were received, and were omissions assessed for reporting impact? |
A single discrepancy should lead to a proportionate investigation, not an automatic declaration that the whole system failed. The MAH should establish the case facts, the applicable requirement, the likely impact, and whether the same control or data population may have been affected elsewhere.
9. Root cause, CAPA, and QPPV oversight
Correcting one case does not establish that the process is controlled. A useful investigation distinguishes the immediate case error from the condition that permitted it, the control expected to detect it, and the reason any detection control did or did not work.
Depending on the evidence, scope assessment may include other cases processed by the same workflow, source, vendor, staff group, database configuration, procedure, or time period. The MAH should document why that population is appropriate and how it evaluated reporting consequences, data correction, regulatory communication, and any safety impact.
CAPA should address the demonstrated cause and define what evidence will show that the revised control works. If the cause concerns a missing hand-off, the effectiveness check should test the transfer in operation. If it concerns acknowledgement handling, test a representative set of messages and their disposition. If a change affects case assessment, the check should examine actual cases against the revised criteria. A completed procedure revision or training session alone does not demonstrate effectiveness.
The QPPV needs information sufficient to oversee significant weaknesses in the safety reporting system. That can include late or missed reports, recurring processing errors, serious unresolved transmission exceptions, vendor performance issues, data-quality trends, and CAPAs whose effectiveness is uncertain. The form and frequency of QPPV review depend on the organisation's quality system and risk; the evidence should show that important issues were made visible, assessed, and followed through.
10. Practical inspection-readiness review
A focused self-inspection can sample the whole chain rather than checking isolated stages:
- Select cases across sources, seriousness categories, vendors, and reporting routes.
- Trace the earliest available source record through the MAH's awareness-date decision.
- Reperform the validity, seriousness, and reporting-scope assessment from the information available at the time.
- Compare source, narrative, structured data, medical review, coding, and audit history.
- Recalculate the legal deadline and inspect initial and follow-up transmissions.
- Review delivery notifications, acknowledgements, validation errors, resubmissions, and final status.
- Match the case to reconciliation, QC, deviation, CAPA, and performance records where relevant.
- Check whether recurring or high-impact issues reached the QPPV and appropriate management.
- Assess whether third parties and any further subcontractors handling PV tasks can produce the records and support the inspection scope.
- Record the sample design, exceptions, impact assessment, decisions, and any limitation of the review.
A self-inspection should not be designed to manufacture a clean sample. Its value is in revealing where the evidence trail is weak and whether the system can identify and correct that weakness before an authority does.
Key Takeaways
- ICSR inspection readiness is demonstrated by a traceable case lifecycle, not a procedure or “sent” status alone.
- Preserve the distinction between the legal reporting duty, GVP implementation guidance, and the MAH's chosen operational controls.
- The initial awareness date, report validity, seriousness, applicable scope, and acknowledgement handling each have different evidence needs.
- The EMA PhV IWG's 2024 report documents findings across submission and follow-up, medical review and coding, literature screening, and case collection. These findings apply to the report's defined inspection population.
- Treat other failure scenarios as illustrative unless an authoritative source identifies them as actual findings.
- Investigate discrepancies proportionately, assess their population and reporting impact, and make CAPA effectiveness test the control in operation.
- QPPV oversight depends on timely visibility of material case-processing weaknesses and follow-through on their resolution.
References
- Directive 2001/83/EC, especially Article 107, as amended. EUR-Lex consolidated text.
- Regulation (EC) No 726/2004, including provisions on EudraVigilance and pharmacovigilance obligations. EUR-Lex.
- Commission Implementing Regulation (EU) No 520/2012, as amended, including Articles 11–13 on MAH pharmacovigilance quality systems, accuracy and verifiability of ICSR submissions, and record management. EUR-Lex consolidated text; Commission Implementing Regulation (EU) 2025/1466. EUR-Lex.
- European Medicines Agency. Guideline on good pharmacovigilance practices (GVP), Module VI: Collection, management and submission of reports of suspected adverse reactions to medicinal products, Revision 2 (2017). PDF.
- European Medicines Agency. Guideline on good pharmacovigilance practices (GVP), Module III: Pharmacovigilance inspections, Revision 2, effective 10 September 2026. PDF.
- European Medicines Agency. European Union Individual Case Safety Report (ICSR) Implementation Guide. PDF.
- European Medicines Agency. EudraVigilance: electronic reporting. Guidance page.
- European Medicines Agency, Pharmacovigilance Inspectors Working Group. Annual report for 2024, EMA/INS/PhV/122716/2025. PDF.
Regulatory Note
This article is an educational guide to EU pharmacovigilance inspection readiness. It does not replace current legislation, current EMA guidance, technical EudraVigilance documentation, product-specific obligations, competent-authority instructions, or the MAH's approved procedures. Apply the versions and requirements relevant to the activity and reporting date. Illustrative examples are not reported inspection findings.