Archived Revision: You are viewing historical Version 1 of this article. View current active version →

Audio Lesson 25 min

EU Pharmacovigilance Inspection Findings: Lifecycle Management and Continuity of Pharmacovigilance Controls

Purpose and Scope

Pharmacovigilance systems do not remain static during the life of a medicinal product. Products enter and leave portfolios, marketing authorisations are transferred, companies merge or divest businesses, indications and territories change, safety responsibilities move between organisations, and information technology and service arrangements are replaced.

These events are not pharmacovigilance activities in themselves, but they can materially change the system through which pharmacovigilance obligations are fulfilled. An inspection may therefore examine not only whether the pharmacovigilance system is appropriate at a given point in time, but whether the organisation maintained control while that system was changing.

The central inspection question is:

How did the organisation ensure continuity, control and traceability of pharmacovigilance responsibilities while the product, organisation or system changed?

This article focuses on that inspection perspective. It does not reproduce detailed requirements for marketing-authorisation transfers, product variations, safety reporting, RMPs, PSMFs or individual PV processes. Instead, it examines the interfaces created when lifecycle events alter those processes.

Why Lifecycle Changes Matter to Pharmacovigilance

A lifecycle event can alter several parts of the pharmacovigilance system simultaneously. A transfer of a marketing authorisation can change the legal MAH, QPPV arrangements, PSMF, safety database, contracts, reporting responsibilities and access to historical records. An acquisition may bring products, personnel and systems into an existing PV organisation. A divestment can require the separation of data, responsibilities and services while preserving the information necessary to fulfil continuing obligations.

The risk is therefore not simply that one document becomes outdated. The deeper risk is a discontinuity between the old and new arrangements.

A useful inspection model is:

lifecycle event → impact assessment → transition design → implementation → verification → stable-state oversight

An organisation that can demonstrate each stage is better positioned to show that the pharmacovigilance system remained controlled throughout the transition.

Regulatory Framework

The EU framework places continuing responsibility for the pharmacovigilance system on the marketing authorisation holder. Commission Implementing Regulation (EU) No 520/2012 requires the PSMF to be accurate and to reflect the pharmacovigilance system in place, and requires it to be kept up to date and subject to version control. The current consolidated Regulation was amended by Commission Implementing Regulation (EU) 2025/1466. citeturn0search0turn0search1

GVP Module II explains that changes to the pharmacovigilance system should be managed through appropriate change control and specifically identifies changes such as safety-database changes, significant outsourced services and organisational changes including takeovers, mergers and transfers of PSMF management as matters that can require attention. It also emphasises keeping the QPPV informed of relevant changes. citeturn0search25

For a transfer of a centralised marketing authorisation, EMA procedural guidance provides for transfer arrangements and updated pharmacovigilance-system information, including the transferee's QPPV arrangements. citeturn0search4turn0search26

These sources establish the regulatory foundation. The more detailed transition controls described later in this article are generally recommended operational practices or inspection-testing approaches, not universal legal requirements.

Lifecycle Event Versus Pharmacovigilance Change

The first management task is to distinguish the commercial or regulatory event from its pharmacovigilance consequences.

For example, an acquisition may be legally completed on a defined date, but the pharmacovigilance transition may involve months of work involving data migration, agreements, training, system access, QPPV oversight and reconciliation. Similarly, a new indication may be approved through a regulatory process while the PV organisation must assess the resulting effect on safety surveillance, risk management, literature monitoring, aggregate reporting and workload.

The inspection question is therefore not simply whether the legal event occurred correctly. It is whether the organisation identified the PV consequences early enough and controlled them through implementation.

Types of Lifecycle Events Relevant to Inspection

The following categories can have materially different transition risks:

Lifecycle event Typical PV implications to assess
Transfer of marketing authorisation Responsibilities, QPPV, PSMF, data, reporting, agreements and historical records
Acquisition Portfolio integration, systems, people, vendors, procedures and governance
Divestment Separation of systems, data, services, responsibilities and records
Merger or reorganisation New organisational structure, responsibilities, procedures and system interfaces
New product introduction PV system inclusion, product scope, training, reporting and risk management
New indication or major lifecycle change Safety surveillance, workload, risk-management and aggregate-reporting implications
New territory or market expansion Local requirements, affiliates, reporting and safety-information flows
Safety database migration Data integrity, validation, reconciliation and historical reconstruction
Major outsourcing change Service continuity, agreements, oversight and access to records
Discontinuation or withdrawal Continuing obligations, surveillance, records and responsibility after commercial activity ends

This table is a planning framework. The actual impact depends on the product, authorisation route, organisation and applicable requirements.

The Transition Impact Assessment

A lifecycle transition should begin with an assessment of what changes in the pharmacovigilance system, rather than with a list of documents that need to be edited.

A useful assessment asks:

The questions should be adapted to the event. Their purpose is to make dependencies visible before implementation.

Transfer of Marketing Authorisation

A transfer of a marketing authorisation is one of the clearest examples of a lifecycle event with direct pharmacovigilance implications. EMA's transfer guidance includes arrangements for the transferee's pharmacovigilance system and QPPV information. citeturn0search4turn0search26

From an inspection perspective, the critical issue is continuity. The organisation should be able to establish who was responsible at each relevant point and how safety information moved from the transferor's system into the transferee's controlled processes.

Questions can include whether open cases were transferred appropriately, whether reporting obligations remained covered during the transition, whether historical data remained retrievable, whether agreements reflected the new responsibilities and whether the PSMF accurately represented the post-transfer system.

The exact procedural requirements of a transfer depend on the authorisation route and regulatory procedure. The inspection principle is broader: responsibility must not become ambiguous merely because legal ownership changes.

Acquisitions and Mergers

Acquisitions and mergers can be more complex because multiple products and pharmacovigilance systems may be brought together. The receiving organisation may need to decide whether to retain existing processes temporarily, integrate them into its own system or redesign selected activities.

The risk of a poorly controlled integration is that the organisation assumes that its existing system automatically absorbs the acquired portfolio. In practice, differences may exist in case-processing procedures, safety databases, vendor arrangements, signal governance, reporting calendars, training, local contacts and historical records.

A mature transition therefore maps the acquired system before deciding what can be retired, what must be transferred and what must remain accessible during the transition.

Divestments and Separation

Divestment creates the reverse problem. Activities that previously operated within one pharmacovigilance system may need to be separated while historical responsibilities and records remain controlled.

A separation plan may need to address data access, copies or transfers of relevant records, reporting obligations, vendor contracts, affiliate responsibilities, system access, PSMF changes and the treatment of ongoing cases or studies.

The inspection concern is not simply whether the new organisation has a functioning system. The former organisation may still need to demonstrate how it fulfilled obligations during the period before transfer and how records supporting that period can be retrieved.

New Products and Portfolio Expansion

When a new product enters an MAH's portfolio, the organisation should assess whether the existing pharmacovigilance system can support the product's characteristics and obligations.

This may involve product scope in the PSMF, safety-database configuration, reporting arrangements, medical review, literature monitoring, signal management, RMP activities, additional risk-minimisation measures and training. Not every product requires a new process; the point is to assess the effect rather than assume that no change is necessary.

The PSMF framework is relevant because the PSMF must accurately reflect the pharmacovigilance system and its product scope. The QPPV should be informed of changes relevant to the system under their responsibility. citeturn0search24turn0search1

New Indications and Other Major Product Changes

A new indication can change the population exposed, clinical context, expected adverse-event profile and volume or type of safety information. It may therefore alter workload and the operation of existing PV controls even if the underlying safety database remains unchanged.

EMA notes that RMPs are updated throughout the medicine's lifetime and may require updating when the risk-management system changes or important pharmacovigilance or risk-minimisation milestones occur. citeturn0search6

The inspection perspective is to examine whether the organisation recognised such consequences and incorporated them into its pharmacovigilance planning, rather than treating the regulatory approval as an isolated Regulatory Affairs event.

Geographic Expansion

Entering additional territories can introduce new reporting pathways, local contacts, language requirements, literature sources, healthcare systems and national risk-minimisation arrangements.

The organisation should establish how information from the new territory enters the pharmacovigilance system and how responsibilities are divided between central and local functions. Where third parties or affiliates are involved, the interfaces should be controlled and represented accurately in the relevant system documentation.

A lifecycle inspection may therefore select one new market and trace a report from local receipt through central processing and any applicable regulatory action. This connects the lifecycle question to the cross-functional interface and evidence-chain principles established earlier in the series.

System Changes During Lifecycle Events

Lifecycle events frequently coincide with technology changes. A transfer may require migration to another safety database; an acquisition may require integration of two systems; a divestment may require separation of access and data; a vendor change may alter interfaces.

These changes should be assessed not only for technical functionality but also for their effect on the continuity and traceability of pharmacovigilance records. GVP Module II specifically identifies safety-database changes, including transferred or migrated data, as changes relevant to PSMF change control. citeturn0search25

The evidence expected during inspection may therefore include migration requirements, testing, reconciliation, deviation management, access controls and records demonstrating that historical information remains usable.

The QPPV During Lifecycle Transitions

The QPPV's role is especially important because lifecycle events can change the capacity, functioning and compliance of the pharmacovigilance system. GVP Module II identifies several changes that should routinely and promptly be notified to the QPPV, including the inclusion of products, significant outsourced services, organisational changes and changes affecting workload. citeturn0search24

The QPPV does not need to personally execute every transition task. Effective oversight requires sufficient visibility to understand the implications of the change, challenge inadequate arrangements and ensure that material risks are escalated and addressed.

Evidence of oversight may include transition governance records, risk assessments, escalation decisions, review of significant deviations, confirmation of readiness and post-transition monitoring. These are examples of evidence, not a universal prescribed QPPV checklist.

17. Responsibility During the Transition Period

The transition period is often the most difficult part of a lifecycle event because the future operating model may be defined while the former model is still active. The organisation must therefore establish responsibilities for the period between decision and steady-state implementation.

A useful transition plan identifies who performs each safety-critical activity before, during and after the change. This is particularly important for activities with continuous obligations, such as receipt and processing of safety information, expedited reporting, signal management and responses to regulatory requests.

The allocation of responsibility should be operationally understandable. A contract or project plan can support the arrangement, but personnel performing the activity should know which process applies and where escalation should go.

18. Cutover and Implementation Dates

A lifecycle project may contain several dates: legal completion, regulatory approval, system cutover, operational handover and the date on which the new organisation assumes full responsibility. These dates should not be treated as interchangeable.

For inspection purposes, the organisation should be able to explain which arrangement applied on the date of a particular safety event. A case received near a transfer date is a useful test because its history can cross the old and new operating models.

The relevant evidence might include controlled transition records, system timestamps, responsibility matrices, communications and handover documentation. The exact documents will depend on the transition.

19. Open Cases and Ongoing Safety Activities

Open safety cases require particular attention because they continue to evolve after the lifecycle event. Follow-up information may arrive after a transfer, a serious case may require additional reporting, or a medical assessment may need to be revisited.

The transition plan should therefore identify how open cases are identified, transferred or retained, who is responsible for follow-up and how reporting obligations are protected. The same principle applies to ongoing signals, aggregate reports, safety studies, RMP activities, effectiveness evaluations and regulatory commitments.

An inspection may select an activity that was open at the time of transition and reconstruct what happened before and after the handover. This can reveal whether the transition was designed around static data transfer or around continuity of the actual pharmacovigilance process.

20. Historical Data and Records

Historical data have continuing value because they provide the context for current safety assessments and demonstrate how the pharmacovigilance system operated at earlier points in time.

A transfer or organisational separation should therefore consider not only current records but the ability to retrieve and interpret historical records. This includes case histories, reporting records, signal evaluations, aggregate assessments, audit and inspection records, relevant quality records and other evidence required to reconstruct past activities.

The exact retention obligations vary by record and applicable legal requirements. The inspection principle is that a lifecycle change should not make relevant historical pharmacovigilance evidence inaccessible or uninterpretable.

21. PSMF Changes During Lifecycle Events

The PSMF is one of the clearest inspection indicators of whether the organisation has controlled a lifecycle transition. Regulation 520/2012 requires the PSMF to be accurate, current and version controlled, while GVP Module II provides detailed expectations for change control and organisational changes. citeturn0search0turn0search25

The inspection question is not simply whether a revised PSMF exists. The inspector may compare the PSMF with the actual transition arrangement and with evidence from the period immediately before and after implementation.

Potential discrepancies include an obsolete QPPV arrangement, an incorrect product list, outdated outsourcing information, an inaccurate description of safety systems or responsibilities that changed without corresponding documentation.

These are analytical examples. Unless specifically attributed to an authority, they should not be presented as published findings.

22. Contracts, Agreements and Responsibility Boundaries

Lifecycle events frequently require changes to contracts and safety data exchange arrangements. The important question is whether the contractual arrangement corresponds to the operational reality.

An agreement may identify a service provider as responsible for case processing, for example, while the organisation's actual workflow assigns important activities elsewhere. Conversely, an activity may be operationally transferred before the contractual and quality arrangements are updated.

Inspection testing can compare the agreement, PSMF, procedure, responsibility matrix and actual transaction. A coherent system should allow the organisation to explain any differences and demonstrate which arrangement was controlling at the relevant time.

23. Training and Competence During Transition

Lifecycle changes often introduce new systems, procedures, products or responsibilities. Training should therefore be considered as part of transition readiness rather than as an activity performed after implementation.

The appropriate approach depends on the change. Personnel may need training on new procedures, new systems, new product characteristics or revised escalation routes. Where responsibilities transfer between organisations, both sides may need sufficient knowledge to maintain continuity during the handover.

Completion records alone do not establish readiness. The organisation should consider whether personnel performing safety-critical activities were able to perform the revised process effectively when the new arrangement became operational. This connects lifecycle management with the competence principles developed in I7.

24. Vendor and Affiliate Transitions

Changes in vendors or affiliates can occur independently or as part of a broader lifecycle event. They can affect case intake, processing, literature, reporting, signal management, risk-minimisation implementation and other activities.

The transition should establish how responsibility moves between the outgoing and incoming parties, how records are preserved and how performance is monitored during the handover.

A common analytical failure pattern is a gap between contractual transition and operational transition: the new provider is formally appointed but has not yet demonstrated that it can perform the relevant activity, while the outgoing provider has already reduced its involvement. The appropriate inspection assessment would depend on the evidence and any actual effect on pharmacovigilance performance.

25. Regulatory Commitments and Ongoing Obligations

Lifecycle changes do not necessarily eliminate existing pharmacovigilance commitments. An organisation may have ongoing regulatory requests, post-authorisation studies, risk-minimisation activities, safety variations, commitments arising from previous assessments or inspection CAPAs.

The transition plan should identify which obligations remain active, who assumes responsibility and where the evidence is maintained. Otherwise, an organisational change can create a gap in ownership even though the underlying regulatory obligation continues.

This is particularly important for commitments whose origin predates the current organisational structure. Historical ownership should be reconstructed sufficiently to establish why and how the current organisation is responsible for completing the activity.

26. Discontinuation and Withdrawal

Discontinuation of commercial activity is not necessarily equivalent to the immediate end of all pharmacovigilance responsibilities. The applicable obligations depend on the legal and regulatory circumstances, the product and the markets concerned.

From an inspection perspective, the key issue is whether the organisation assessed what pharmacovigilance activities and records remain necessary after commercial discontinuation or withdrawal and established responsibility for them.

A weak transition can occur when a product is removed from an operational portfolio and associated systems or personnel are retired without considering ongoing safety information, regulatory requests, historical records or obligations that continue after the commercial event.

The article does not prescribe a single post-discontinuation model because the applicable obligations are circumstance-dependent.

27. Post-Transition Verification

A transition should not be considered controlled solely because the planned cutover occurred. Verification should establish that the new arrangement operates as intended.

Useful verification may include sampling recent cases, testing reporting workflows, reviewing reconciliation results, confirming system access, checking vendor performance, reviewing outstanding regulatory commitments and confirming that the PSMF accurately describes the implemented system.

The exact verification should reflect the risks of the transition. A simple product transfer may require less extensive testing than a merger involving multiple safety databases and service providers.

28. Monitoring the Transition After Go-Live

Some failures become visible only after implementation. Workload may increase unexpectedly, interfaces may produce exceptions, personnel may misunderstand responsibilities or historical records may prove difficult to retrieve.

Post-transition monitoring should therefore continue long enough to identify meaningful problems. Compliance-monitoring indicators can be particularly useful when they are linked to the risks identified during the transition assessment.

The purpose is not to create a special metric for every project. It is to determine whether the controls identified as critical during planning are actually functioning after the change.

29. How an Inspector Can Test Lifecycle Continuity

A lifecycle inspection can be approached through a real transaction that crosses the change boundary.

For example:

Lifecycle event
      ↓
Transition impact assessment
      ↓
Pre-transition responsibility
      ↓
Handover / cutover
      ↓
Post-transition responsibility
      ↓
Actual safety transaction
      ↓
Monitoring / verification

The inspector can select a case, report, signal or regulatory commitment associated with the transition and trace it through these stages.

The question is whether the organisation's documented transition model corresponds to operational evidence.

30. Potential Inspection Finding Patterns

The following are illustrative analytical categories, not claims about published regulator findings:

Unclear responsibility at cutover

The organisation cannot establish who was responsible for a safety activity during a defined transition period.

Incomplete impact assessment

The project addressed the commercial or legal event but did not assess material pharmacovigilance consequences.

Inadequate historical-data strategy

Relevant historical safety information cannot be readily retrieved or interpreted after the transition.

PSMF does not reflect the implemented system

The documented system remains inconsistent with the post-transition operating model.

Incomplete handover of open activities

Cases, signals, studies or regulatory commitments were not clearly assigned to an accountable function.

Transition without adequate readiness evidence

The new process became operational without sufficient evidence that personnel, systems or service providers were ready.

Post-transition problems not detected

The organisation lacked monitoring capable of identifying deterioration in the newly implemented arrangement.

These categories should be used for self-assessment, not represented as official inspection terminology unless supported by a cited authority.

31. Root-Cause Analysis of Lifecycle Findings

When a lifecycle-related deficiency is identified, root-cause analysis should examine the transition mechanism rather than simply correcting the affected record.

For example, if an open case was not transferred correctly, possible causes might include an incomplete inventory, unclear ownership, inadequate system reconciliation, insufficient training or a project governance weakness. The evidence should determine the actual cause.

A useful question is why the transition control failed to detect the problem before or shortly after cutover. That connects lifecycle remediation to the CAPA-effectiveness principles established in I4.

32. CAPA and Effectiveness

Corrective action should address the specific failure while considering whether the same transition mechanism could have affected other products, activities or historical periods.

Effectiveness verification should test the control that was intended to prevent recurrence. If the weakness was incomplete transfer of open cases, effectiveness might involve a defined review of transferred populations and follow-up outcomes. If the weakness involved outdated system documentation, effectiveness should establish that subsequent material changes now trigger appropriate review.

The objective is not to demonstrate that the project team completed its action list. It is to demonstrate that the pharmacovigilance control now works.

33. QPPV Inspection Questions

The following are illustrative questions, not an official regulator checklist:

34. Practical Self-Inspection Framework

A lifecycle transition can be self-inspected using seven questions:

  1. Ownership — Is responsibility unambiguous at every stage?
  2. Scope — Were all affected products, activities and territories identified?
  3. Continuity — Could safety activities continue without an uncontrolled gap?
  4. Evidence — Can the transition and its consequences be reconstructed?
  5. Readiness — Were systems, people and partners ready before assuming responsibility?
  6. Verification — Was the new arrangement tested after implementation?
  7. Governance — Did the QPPV and appropriate management functions have sufficient visibility and authority?

A "no" answer should trigger assessment rather than automatically being classified as a regulatory deficiency.

35. Evidence Package for a Lifecycle Transition

A strong inspection evidence package should allow the organisation to reconstruct the transition without relying on project-team memory.

Depending on the event, relevant evidence may include the impact assessment, transition plan, responsibility mapping, regulatory correspondence, contracts and amendments, system-change records, data-migration evidence, training records, handover records, PSMF versions, monitoring results, deviations, CAPA and post-transition verification.

The evidence should be connected. A folder containing hundreds of documents is not necessarily a coherent evidence package. The organisation should be able to show which evidence supports each material transition decision and how implementation was verified.

36. What Inspectors May Compare

Lifecycle inspections are particularly suited to comparison testing because the event creates multiple sources of evidence.

An inspector may compare:

Source Compared with Inspection purpose
Transition plan Actual implementation Whether planned controls occurred
Responsibility matrix Actual case workflow Whether responsibilities operated as assigned
PSMF Current organisation Whether the system description is accurate
Contract/SDEA Operational activity Whether contractual and operational arrangements align
Training records Staff performance Whether readiness was achieved
Migration report Safety database records Whether transferred data are complete and usable
Monitoring results Post-transition events Whether the new control was effective
Regulatory commitments Current ownership Whether obligations remained controlled

Differences are not automatically deficiencies. A mature system should, however, be able to explain material differences and show how changes were governed.

37. Historical Reconstruction

One of the strongest inspection tests is to select an event that occurred close to the transition date and reconstruct it using contemporaneous records.

For example, a serious case received shortly before a marketing-authorisation transfer may have been entered into the transferor's system, followed up after the transfer and reported under the transferee's responsibility. The organisation should be able to explain the chain of responsibility and demonstrate that the case remained controlled throughout.

This test connects lifecycle management directly with the evidence-chain principles described in I5. The question is not simply whether the final case is correct, but whether the organisation can reconstruct how responsibility and information moved across the transition.

38. Lifecycle Changes and the PSMF Logbook

The PSMF logbook provides an additional historical record of changes to the PSMF. Regulation 520/2012 requires the MAH to record relevant alterations to PSMF content in the logbook, subject to the regulatory provisions governing the logbook. citeturn0search1

For inspection purposes, the logbook can help connect an organisational or system event to the corresponding change in the documented pharmacovigilance system.

It should not, however, be treated as a substitute for the underlying transition evidence. A log entry can show that a PSMF change occurred; it does not by itself demonstrate that the operational transition was effective.

39. Lifecycle Events and Change Control

Lifecycle management demonstrates why pharmacovigilance change control needs to extend beyond document revision. A controlled change requires an understanding of what will change, what could be affected, who is responsible, how implementation will occur and how the result will be verified.

GVP Module II specifically describes the need for robust processes to remain informed of relevant changes so that the PSMF can be maintained. It identifies database changes, significant outsourced services and organisational changes such as takeovers and mergers among examples of important changes. citeturn0search25

The operational mechanism by which an MAH achieves this is organisation-specific. The inspection objective is to establish whether the mechanism works.

40. Lifecycle Transitions and Compliance Monitoring

The transition should feed into the organisation's compliance-monitoring framework where appropriate. If the impact assessment identifies particular risks, monitoring can be designed to detect whether those risks materialise after implementation.

For example, a transition involving a new case-processing vendor may warrant attention to timeliness and reconciliation. A safety-database migration may warrant monitoring of data-transfer exceptions. A portfolio acquisition may warrant review of training completion and performance indicators.

These are illustrative examples. Monitoring should be proportionate to the identified risk rather than generated mechanically for every lifecycle event.

41. Lifecycle Transitions and Inspection Readiness

Inspection readiness should not be confused with assembling a transition file immediately before inspection. The strongest evidence is generated during the transition itself.

A contemporaneous impact assessment, controlled handover, documented testing, recorded deviations and post-transition monitoring are more persuasive than retrospective statements that the transition was successful.

This is consistent with the broader inspection principle developed across I1–I8: the inspector is testing whether the organisation's control system produced reliable evidence of effective operation.

42. What a Mature Lifecycle Process Looks Like

A mature process treats lifecycle events as changes to a controlled pharmacovigilance system rather than as isolated business or regulatory projects.

Before implementation, the organisation identifies affected responsibilities, products, activities, systems, records and interfaces. During implementation, it maintains clear ownership and protects continuity. After implementation, it verifies that the new arrangement works and monitors for emerging problems.

The QPPV has sufficient visibility to challenge the transition where necessary, while operational responsibilities remain with the functions assigned to perform them.

43. Common Weak Approaches

Several approaches can create avoidable inspection risk:

Treating the legal effective date as the entire transition. The legal event may be only one of several operational milestones.

Updating the PSMF after implementation without assessing the underlying system. A document update cannot compensate for an uncontrolled transition.

Assuming portfolio integration is automatic. Acquired products may operate under different processes, systems and agreements.

Transferring current data while neglecting historical evidence. Historical records may remain necessary to reconstruct earlier pharmacovigilance activities.

Ending the outgoing provider's involvement too early. Handover should be based on demonstrated readiness rather than administrative appointment alone.

Closing the project at cutover. Post-transition verification is necessary when the risk warrants it.

These are potential failure modes for self-assessment, not statements of published inspection findings.

44. Relationship to the Other Inspection Articles

Lifecycle management provides a useful integration point for the series.

A transition can expose a PSMF governance weakness, an interface failure, a data-integrity problem, inadequate training, ineffective compliance monitoring or a failure of CAPA effectiveness. The lifecycle article therefore does not replace those domain-specific analyses; it shows how they can interact during a period of organisational change.

The common inspection model is:

change → risk assessment → control → evidence → implementation → verification → oversight.

45. Key Takeaways

46. References

  1. European Commission. Commission Implementing Regulation (EU) No 520/2012, as amended by Commission Implementing Regulation (EU) 2025/1466. urlEUR-Lex — Regulation 520/2012https://eur-lex.europa.eu/eli/reg_impl/2012/520/2026-02-12/eng
  2. European Medicines Agency. GVP Module I — Pharmacovigilance systems and their quality systems, current revision. urlEMA GVP Module Ihttps://www.ema.europa.eu/en/human-regulatory-overview/post-authorisation/pharmacovigilance-post-authorisation/good-pharmacovigilance-practices-gvp/gvp-modules
  3. European Medicines Agency. GVP Module II — Pharmacovigilance system master file, current revision. urlEMA GVP Module IIhttps://www.ema.europa.eu/en/human-regulatory-overview/post-authorisation/pharmacovigilance-post-authorisation/good-pharmacovigilance-practices-gvp/gvp-modules
  4. European Medicines Agency. GVP Module III — Pharmacovigilance inspections, current revision. urlEMA GVP Module IIIhttps://www.ema.europa.eu/en/human-regulatory-overview/post-authorisation/pharmacovigilance-post-authorisation/good-pharmacovigilance-practices-gvp/gvp-modules
  5. European Medicines Agency. Transfer of a marketing authorisation templates and procedural guidance, current EMA material. urlEMA transfer of marketing authorisation guidancehttps://www.ema.europa.eu/en/human-regulatory-overview/post-authorisation/transfer-marketing-authorisation-questions-answers/transfer-marketing-authorisation-templates
  6. European Medicines Agency. Risk management plans, including lifecycle updating of RMPs. urlEMA risk management planshttps://www.ema.europa.eu/en/human-regulatory-overview/marketing-authorisation/pharmacovigilance-marketing-authorisation/risk-management/risk-management-plans

Regulatory Note

This article is an educational analysis of lifecycle management and continuity of pharmacovigilance controls from an EU inspection perspective. It distinguishes legal requirements and GVP guidance from recommended operational practice and illustrative inspection scenarios. The failure patterns and inspection questions that are not explicitly attributed to an authoritative source are hypothetical and must not be interpreted as published inspection findings or official regulatory checklists. Applicable requirements can depend on the marketing-authorisation route, product, Member State and circumstances of the lifecycle event. Current legislation, GVP guidance, EMA procedures, national requirements and product-specific obligations should therefore be checked before operational or regulatory decisions are made.

Revision History