GVP Module IV: Pharmacovigilance Audits
- GVP Module IV: Pharmacovigilance Audits
- Introduction
- 1. What GVP Module IV Covers
- 2. Audit Is an Assurance Activity
- 3. Audit Versus Inspection
- 4. Audit Versus Routine Quality Control
- 5. Why Independence Matters
- 6. Risk-Based Audit Planning
- 7. The Audit Universe
- 8. Audit Scope Should Be Explicit
- 9. Audit Criteria
- 10. Evidence-Based Auditing
- 11. Sampling
- 12. Audit Findings
- 13. Audit Programme Governance
- 14. The Audit Schedule Should Be Defensible
- 15. QPPV Involvement in the Audit Programme
- 16. Auditing the Pharmacovigilance System Itself
- 17. Auditing Vendors
- 18. Audit of Safety Data Exchange
- 19. Auditing Computerised Systems
- 20. Audit Interviews
- 21. Auditing Training and Competence
- 22. Reporting Audit Results
- 23. Classification of Findings
- 24. Root-Cause Analysis
- 25. CAPA Following an Audit
- 26. CAPA Effectiveness
- 27. Recurring Findings
- 28. Audit Follow-Up
- 29. Audit Programme Metrics
- 30. Inspection Findings Relevant to Audit Programmes
- 31. Common Audit-Programme Failures
- 32. An Inspection-Ready Audit Trail
- 33. A Practical Pharmacovigilance Audit Example
- 34. Example: A Timeline Finding
- 35. Example: A Vendor Appears Compliant
- 36. Example: A Recurring Finding
- 37. Audit Programme as a Risk Sensor
- 38. What a QPPV Should Review
- 39. What an Inspector May Ask About Audits
- 40. Audit Readiness Is Not the Same as Inspection Preparation
- 41. Relationship With Other GVP Modules
- 42. Audit Evidence and the PSMF
- 43. Audit and Management Review
- 44. What Good Looks Like
- 45. Final Principles
- Key Takeaways
- References
- Regulatory Note
Introduction
Pharmacovigilance audits provide an independent assessment of whether the pharmacovigilance system is appropriately designed, implemented and controlled.
Within the EU GVP framework, auditing is not simply an exercise in checking whether standard operating procedures exist. An effective audit programme should provide assurance that important parts of the pharmacovigilance system operate as intended and that weaknesses are identified, corrected and followed through to effectiveness.
GVP Module IV is therefore particularly relevant to the QPPV, the audit function, pharmacovigilance management and senior governance.
A useful distinction is:
Operational quality control
β
Routine monitoring
β
Management oversight
β
Independent audit
β
Regulatory inspection
These activities are related but are not interchangeable. Audit provides an independent assurance layer within the pharmacovigilance quality system.
1. What GVP Module IV Covers
GVP Module IV addresses pharmacovigilance audits as part of the quality system.
The module is concerned with principles such as:
- audit strategy and planning;
- independence and objectivity;
- risk-based audit selection;
- audit scope and objectives;
- audit execution;
- reporting;
- findings;
- corrective and preventive action;
- follow-up;
- and management of the overall audit programme.
The module should be read together with the broader GVP quality-system framework and the applicable legal requirements.
2. Audit Is an Assurance Activity
The purpose of an audit is not simply to discover errors.
An audit provides an independent assessment of whether a defined area meets specified criteria and whether the controls supporting that area are functioning effectively.
The audit question is therefore broader than:
"Did this case contain an error?"
It may instead be:
"Is the case-management process appropriately designed, consistently implemented and adequately controlled to ensure that important regulatory and pharmacovigilance obligations are met?"
This distinction matters because a single error may be an isolated event, while a pattern of errors may indicate a systemic control weakness.
3. Audit Versus Inspection
Audit and inspection should not be confused.
An audit is an independent assessment performed within the quality framework to provide assurance and identify opportunities for improvement or corrective action.
A regulatory inspection is performed by a competent authority or regulatory body to assess compliance with applicable requirements.
The two activities may examine similar processes, but their purposes, authority and consequences differ.
A strong internal audit programme should help an organisation identify weaknesses before they become inspection findings. It should not, however, be designed merely as a rehearsal for an inspection.
4. Audit Versus Routine Quality Control
Routine quality control is generally embedded within the operational process.
Examples include:
- case QC;
- reconciliation;
- second-person review;
- automated system controls;
- timeline monitoring;
- and report verification.
Audit operates at a different level.
It should evaluate whether the control framework itself is appropriate and effective.
For example, a case-processing QC programme may demonstrate that individual cases are reviewed. An audit can examine whether the QC programme is appropriately designed, risk-based, documented, performed and followed up.
5. Why Independence Matters
An audit needs sufficient independence from the activity being audited to provide credible assurance.
The person or function auditing a process should not simply audit its own work without appropriate safeguards.
Independence does not necessarily mean that every pharmacovigilance audit must be performed by an external consultant. Organisations can have internal audit capability, provided appropriate independence and objectivity are maintained.
The practical question is whether the auditor can assess the area objectively and report findings without inappropriate influence from the process owner.
6. Risk-Based Audit Planning
A pharmacovigilance audit programme should be risk-based.
This means audit resources should be directed according to the potential significance of weaknesses and the characteristics of the pharmacovigilance system.
Relevant considerations can include:
- regulatory significance;
- patient-safety impact;
- complexity;
- process criticality;
- previous findings;
- known control weaknesses;
- major system changes;
- new vendors;
- organisational changes;
- inspection history;
- performance trends;
- and time since the area was last audited.
Risk-based planning does not mean that low-risk activities can automatically be ignored forever. It means that the programme should be justified and proportionate.
7. The Audit Universe
A useful starting point is an audit universe representing the important components of the pharmacovigilance system.
It can include:
- the global or EU pharmacovigilance system;
- QPPV oversight;
- case management;
- literature monitoring;
- signal management;
- aggregate reporting;
- risk management;
- safety communication;
- post-authorisation studies;
- safety databases;
- vendors and partners;
- interfaces with clinical development;
- quality management;
- training;
- computerised systems;
- and local or affiliate processes.
The audit universe provides structure for risk assessment and programme planning.
8. Audit Scope Should Be Explicit
Each individual audit should have a defined scope.
The scope should make clear what is being assessed and what is outside the audit.
For example:
"Assessment of the vendor's processing of EU individual case safety reports received from spontaneous sources, including intake, triage, data entry, medical review, quality control, regulatory reporting and reconciliation for the period JanuaryβJune 2026."
A precise scope makes the resulting conclusions more meaningful and reduces ambiguity about what was actually tested.
9. Audit Criteria
An audit requires defined criteria against which evidence is assessed.
Potential criteria can include:
- applicable legislation;
- GVP guidance;
- approved procedures;
- contractual requirements;
- safety-data exchange agreements;
- quality standards;
- system specifications;
- and other documented requirements.
The criteria should be appropriate to the audit objective.
The auditor should distinguish between a regulatory requirement, an internal company requirement and a recommendation or good practice.
10. Evidence-Based Auditing
Audit conclusions should be based on sufficient and appropriate evidence.
Evidence may include:
- records;
- system data;
- interviews;
- procedures;
- training records;
- metrics;
- quality-control results;
- samples;
- vendor records;
- and previous findings.
The auditor should be able to explain how the evidence supports the conclusion.
A statement such as "the process appears compliant" is weak if the auditor cannot identify what was reviewed and why the evidence was sufficient.
11. Sampling
Many pharmacovigilance audits use sampling because reviewing every transaction may not be practical.
The sampling approach should be appropriate to the audit objective and risk.
Important considerations include:
- population size;
- selection method;
- risk characteristics;
- period covered;
- relevant product or case types;
- known exceptions;
- and the limitations of the sample.
A sample is evidence about the audited population, but it does not automatically prove that every transaction is compliant.
The audit report should therefore avoid conclusions broader than the evidence supports.
12. Audit Findings
A finding should clearly describe the observed condition, the applicable criterion and the evidence supporting the conclusion.
A useful structure is:
Criterion
β
Observed condition
β
Evidence
β
Risk / significance
β
Finding
β
Corrective action
The finding should be sufficiently specific for the process owner to understand what needs to be addressed.
The final chunk will examine audit programme governance, CAPA and effectiveness, QPPV oversight, vendors, inspection relevance and practical audit failure examples.
13. Audit Programme Governance
An audit programme should be governed as a programme rather than as a collection of unrelated audits.
Programme governance should address:
- the audit universe;
- risk assessment;
- audit frequency and prioritisation;
- planned and completed audits;
- significant findings;
- overdue actions;
- emerging risks;
- and management reporting.
The programme should be capable of changing when the risk profile changes.
For example, a major safety database migration, significant vendor failure or serious inspection finding may justify bringing an area forward in the audit programme.
14. The Audit Schedule Should Be Defensible
A regulator or auditor may ask why a particular area has not been audited recently.
The answer should not simply be that it was not on the calendar.
The organisation should be able to explain the risk assessment that supported the scheduling decision.
A documented rationale is particularly important for areas that are critical to the pharmacovigilance system but have not recently been audited.
15. QPPV Involvement in the Audit Programme
The QPPV does not necessarily perform pharmacovigilance audits, but should have appropriate visibility of audit activity relevant to the pharmacovigilance system.
The QPPV should be able to understand:
- significant audit findings;
- systemic weaknesses;
- overdue CAPAs;
- recurring findings;
- risks affecting regulatory compliance;
- and whether the overall audit programme provides meaningful assurance.
The exact governance arrangement depends on the organisation, but material pharmacovigilance risks should not be hidden from QPPV oversight.
16. Auditing the Pharmacovigilance System Itself
A programme should not focus exclusively on individual operational activities.
The pharmacovigilance system should also be assessed at a system level.
A system-level audit may consider:
- governance;
- roles and responsibilities;
- QPPV oversight;
- quality management;
- regulatory intelligence;
- change management;
- issue escalation;
- vendor oversight;
- management reporting;
- and the interaction between major PV processes.
This can reveal weaknesses that individual process audits may miss.
17. Auditing Vendors
Outsourced pharmacovigilance activities remain part of the MAH's system.
Vendor audits should therefore be based on the importance and risk of the outsourced activity.
Relevant considerations can include:
- volume of work;
- criticality;
- patient-safety impact;
- regulatory reporting responsibilities;
- geographic scope;
- previous performance;
- previous audit findings;
- quality issues;
- and significant organisational or system changes.
A vendor should not be considered adequately controlled merely because it passed an initial qualification assessment.
18. Audit of Safety Data Exchange
Safety-data exchange interfaces can be particularly important audit subjects.
An audit may examine whether:
- responsibilities are clearly defined;
- agreements are current;
- data are transferred within required timelines;
- reconciliations occur;
- discrepancies are investigated;
- escalation works;
- and changes to the relationship are controlled.
Weak interfaces can create failures even when each individual organisation has apparently adequate internal procedures.
19. Auditing Computerised Systems
Computerised systems can be included within pharmacovigilance audits when their functionality, data or controls are relevant to the audit objective.
Areas of interest can include:
- access control;
- audit trails;
- data integrity;
- system interfaces;
- validation status;
- change control;
- backup and recovery;
- configuration;
- and system-generated timestamps or reports.
The audit scope should distinguish between a pharmacovigilance-process audit and a specialist IT or computerised-system validation audit. Where specialist expertise is needed, the appropriate expertise should be included.
20. Audit Interviews
Interviews can provide important evidence about how a process actually operates.
However, interview statements should not automatically be treated as sufficient evidence of effective implementation.
A useful approach is:
What the procedure says
β
What the person says
β
What the records show
β
What the system demonstrates
Differences between these layers can reveal training, process-design or implementation weaknesses.
21. Auditing Training and Competence
Training records can demonstrate that required training was assigned and completed, but an audit should consider whether personnel are actually capable of performing the relevant activity.
Depending on the process, evidence can include:
- role-specific training;
- qualification records;
- supervised activities;
- competency assessments;
- quality-control results;
- error trends;
- and retraining following significant changes.
Training should be considered in the context of the risk of the activity rather than as a purely administrative requirement.
22. Reporting Audit Results
The audit report should communicate the results clearly enough for management to understand the risk and for process owners to take effective action.
A useful report normally identifies:
- audit objective;
- scope;
- criteria;
- period and locations covered;
- methodology;
- limitations;
- findings;
- overall conclusion;
- and agreed actions where applicable.
The report should not obscure important findings behind excessive narrative.
23. Classification of Findings
Finding classification should be based on a defined methodology.
Organisations may use categories such as critical, major and minor, or another established framework.
The exact terminology is less important than consistency and a defensible rationale.
Classification should consider factors such as:
- regulatory significance;
- patient-safety implications;
- duration;
- extent;
- recurrence;
- detectability;
- and systemic impact.
Internal audit classifications should not automatically be assumed to have the same legal meaning as regulatory inspection classifications.
24. Root-Cause Analysis
A good audit finding should lead to an appropriate investigation of why the problem occurred.
A superficial root cause might be:
"The employee did not follow the SOP."
A deeper investigation may ask why the employee failed to follow it.
Possible causes can include:
- unclear instructions;
- inadequate training;
- system design;
- workload;
- conflicting procedures;
- poor supervision;
- inadequate quality control;
- vendor interface problems;
- or an unrealistic process.
The objective is to identify the cause that must be addressed to prevent recurrence.
25. CAPA Following an Audit
Audit findings should be addressed through an appropriate corrective and preventive action process.
A CAPA should normally identify:
- immediate containment where necessary;
- root cause;
- corrective action;
- preventive action where appropriate;
- responsible owner;
- target date;
- and effectiveness assessment.
Not every finding requires a complex CAPA. The response should be proportionate to the risk.
26. CAPA Effectiveness
Closing a CAPA administratively is not the same as demonstrating that the underlying problem has been corrected.
Effectiveness assessment should ask whether the implemented action actually prevented or reduced recurrence.
For example, if a vendor repeatedly misses reporting timelines, completing a training session may be insufficient evidence of effectiveness. Subsequent performance data may be needed.
27. Recurring Findings
Repeated findings are particularly important.
A recurring finding may indicate that previous corrective actions did not address the underlying cause or that the control environment remains inadequate.
The audit programme should therefore examine trends across audits rather than treating each finding as an isolated event.
Useful trend categories can include:
- recurring process failures;
- repeated vendor findings;
- repeated data-quality issues;
- recurring overdue activities;
- and repeated failures in CAPA effectiveness.
28. Audit Follow-Up
Follow-up should verify whether agreed actions have been implemented and, where required, whether they have been effective.
Evidence may include:
- revised procedures;
- system changes;
- training records;
- subsequent monitoring results;
- quality-control data;
- repeat testing;
- or a follow-up audit.
A finding should not disappear from the audit programme simply because a process owner states that an action is complete.
29. Audit Programme Metrics
Useful audit-programme metrics may include:
- audits completed versus planned;
- overdue audits;
- findings by category;
- overdue CAPAs;
- recurring findings;
- time to CAPA completion;
- CAPA effectiveness results;
- vendor audit performance;
- and significant risk areas without recent audit coverage.
Metrics should be interpreted rather than simply reported.
A programme that completes 100% of its scheduled audits may still be weak if the schedule systematically avoids high-risk areas.
30. Inspection Findings Relevant to Audit Programmes
Regulatory inspections may identify weaknesses such as:
- inadequate audit coverage;
- insufficient independence;
- ineffective risk-based planning;
- failure to audit critical outsourced activities;
- weak follow-up;
- ineffective CAPA;
- or failure to escalate significant audit findings.
These issues demonstrate why audit should be viewed as a pharmacovigilance control rather than a calendar-driven compliance activity.
31. Common Audit-Programme Failures
Calendar-driven auditing
Audits are scheduled according to fixed cycles without meaningful risk assessment.
Auditing easy areas
Low-complexity activities receive disproportionate attention while critical interfaces remain untested.
Excessive reliance on SOP review
The audit confirms that documents exist but does not test actual implementation.
Weak vendor auditing
Critical outsourced activities are assumed to be controlled because a contract and KPI dashboard exist.
Findings without root cause
The organisation corrects the immediate problem without addressing the systemic cause.
CAPA closure without effectiveness
Actions are marked complete without evidence that recurrence risk has been reduced.
No trend analysis
Recurring findings remain invisible because each audit is considered separately.
32. An Inspection-Ready Audit Trail
A mature audit programme should be able to demonstrate:
Risk assessment
β
Audit plan
β
Audit scope and criteria
β
Audit evidence
β
Findings
β
Risk assessment
β
CAPA
β
Follow-up
β
Effectiveness
β
Management/QPPV oversight
This chain provides evidence that audit is functioning as part of the quality system rather than as an administrative exercise.
The final chunk will consolidate Module IV requirements, provide practical audit examples and inspection questions, and include References and the Regulatory Note.
33. A Practical Pharmacovigilance Audit Example
Consider a marketing authorisation holder that has outsourced a substantial proportion of individual case safety report processing to a specialist vendor.
A risk-based audit might examine:
- the safety-data exchange agreement;
- case intake and triage;
- reporting timelines;
- data entry and coding;
- medical review;
- quality control;
- reconciliation;
- deviation management;
- escalation;
- vendor performance monitoring;
- training and competence;
- and CAPA from previous findings.
The audit should not stop at reviewing the contract. It should test whether the controls described by the contract and procedures actually operate.
34. Example: A Timeline Finding
Suppose sampling identifies several cases submitted after the applicable regulatory deadline.
The immediate finding may be straightforward, but the audit should investigate the system behind the failures.
Questions could include:
- Were the cases received late?
- Was triage delayed?
- Was the regulatory clock calculated correctly?
- Did the vendor have sufficient staffing?
- Were cases placed on hold unnecessarily?
- Did the system generate appropriate alerts?
- Was escalation triggered?
- Did management know about the trend?
- Had similar findings occurred previously?
This prevents an audit from reducing a systemic problem to individual employee error.
35. Example: A Vendor Appears Compliant
A vendor may have excellent KPI results while still having an important control weakness.
For example, a KPI may show that cases are processed within agreed timelines, but an audit could identify unreliable reconciliation between the vendor database and the MAH safety database.
The lesson is that performance metrics should be tested against the underlying process and data.
36. Example: A Recurring Finding
Suppose an audit identifies inadequate documentation of medical review. A CAPA is completed by revising the SOP and retraining staff.
A later audit identifies the same problem.
The recurrence should trigger a deeper assessment.
Possible causes could include:
- the revised procedure being impractical;
- insufficient system support;
- unclear ownership;
- inadequate supervision;
- or a quality-control process that does not detect the problem.
The second finding should not simply result in another identical training action.
37. Audit Programme as a Risk Sensor
The audit programme itself can provide useful information about the health of the pharmacovigilance system.
For example, an increase in findings involving:
- vendors;
- data integrity;
- overdue activities;
- CAPA effectiveness;
- or system changes
may indicate an emerging systemic risk.
Management should therefore consider trends across audits rather than reviewing each report independently.
38. What a QPPV Should Review
A QPPV reviewing the audit programme should consider more than the number of audits completed.
Useful questions include:
- Are high-risk areas receiving appropriate coverage?
- Are important vendors included?
- Are systemic findings recurring?
- Are CAPAs completed on time?
- Are CAPAs actually effective?
- Are serious findings escalated appropriately?
- Does audit coverage reflect major changes in the PV system?
- Are there areas where assurance remains weak?
This is the difference between audit administration and audit oversight.
39. What an Inspector May Ask About Audits
During a pharmacovigilance inspection, questions may include:
- Show me your pharmacovigilance audit strategy.
- How did you determine the audit frequency?
- How is risk assessed?
- How are critical vendors considered?
- How is auditor independence maintained?
- Show me a recent audit report.
- How were the findings classified?
- Show me the associated CAPA.
- How did you determine that the CAPA was effective?
- How are recurring findings identified?
- How does the QPPV receive information about significant findings?
- What happens when an audit is overdue?
The ability to answer these questions should come from the normal operation of the quality system, not from an inspection-specific reconstruction.
40. Audit Readiness Is Not the Same as Inspection Preparation
An organisation sometimes attempts to become inspection-ready by performing a large number of internal audits immediately before an expected inspection.
This can be useful for identifying weaknesses, but it is not a substitute for a functioning audit programme.
Inspection readiness should be the consequence of sustained system control:
Risk assessment
β
Appropriate audit coverage
β
Findings
β
Effective CAPA
β
Trend analysis
β
Management oversight
β
Continuous improvement
41. Relationship With Other GVP Modules
Module IV should not be studied in isolation.
Its audit principles interact with other GVP areas, particularly:
- Module I for pharmacovigilance systems and quality systems;
- Module II for the PSMF;
- Module III for pharmacovigilance inspections;
- Module V for risk-management systems;
- Module VI for individual case safety reports;
- Module IX for signal management;
- and Module XVI for risk-minimisation measures.
An audit programme that ignores these interfaces may miss important system risks.
42. Audit Evidence and the PSMF
The PSMF should contain or provide access to information relevant to the pharmacovigilance system and its quality framework as required by the applicable requirements.
Audit documentation should therefore be managed in a way that allows appropriate information about the audit programme, significant findings and related actions to be retrieved when needed.
The exact documentation location depends on the organisation's document architecture.
The important principle is traceability: the organisation should be able to demonstrate what was audited, what was found and what happened afterward.
43. Audit and Management Review
Audit results are one source of management information.
Management review should consider significant audit findings together with other indicators such as:
- quality metrics;
- inspections;
- deviations;
- CAPA;
- vendor performance;
- safety-system changes;
- and emerging regulatory risks.
This integrated view is more informative than considering audit findings in isolation.
44. What Good Looks Like
A mature pharmacovigilance audit programme has several characteristics:
- risk-based planning;
- appropriate independence;
- clear scope and criteria;
- evidence-based conclusions;
- proportionate findings;
- meaningful root-cause analysis;
- effective CAPA;
- documented follow-up;
- trend analysis;
- appropriate vendor coverage;
- QPPV and management oversight;
- and the ability to adapt when risks change.
It does not require every process to be audited every year or every finding to be classified as severe.
It requires the programme to provide credible assurance that important pharmacovigilance risks are being identified and controlled.
45. Final Principles
The practical principles of GVP Module IV can be summarised as follows:
- Audit is an independent assurance activity within the pharmacovigilance quality system.
- Audit is different from routine QC and different from regulatory inspection.
- Audit planning should be risk-based and defensible.
- Critical processes, interfaces and outsourced activities should receive appropriate attention.
- Audit scope and criteria should be explicit.
- Conclusions should be supported by sufficient evidence.
- Findings should address the actual control weakness rather than merely the visible error.
- Root-cause analysis should be proportionate but meaningful.
- CAPA should address recurrence risk, not simply close the finding administratively.
- CAPA effectiveness should be verified where appropriate.
- Recurring findings should be analysed as potential systemic signals.
- The QPPV should have appropriate oversight of significant audit results and systemic risks.
- The audit programme should adapt when the pharmacovigilance risk profile changes.
- The strongest audit programme produces evidence of sustained control rather than a large number of completed audits.
Key Takeaways
- GVP Module IV establishes the framework for pharmacovigilance auditing.
- Independence, objectivity and risk-based planning are central principles.
- An audit should test actual implementation, not merely document existence.
- Vendor and interface risks should be assessed according to their pharmacovigilance significance.
- Findings should be evidence-based and linked to clear criteria.
- CAPA completion is not sufficient without appropriate effectiveness assessment.
- Recurring findings can indicate systemic weaknesses.
- The QPPV should have meaningful visibility of significant audit risks.
- Audit trends can provide valuable information about the health of the overall PV system.
- Inspection readiness is strongest when it results from continuous audit, control and improvement rather than last-minute preparation.
References
- European Medicines Agency. Good Pharmacovigilance Practices (GVP), Module IV β Pharmacovigilance audits. Current version and applicable addenda should be consulted for detailed EU requirements and guidance.
- European Medicines Agency. Good Pharmacovigilance Practices (GVP), Module I β Pharmacovigilance systems and quality systems. Relevant for the relationship between auditing and the wider PV quality system.
- European Medicines Agency. Good Pharmacovigilance Practices (GVP), Module III β Pharmacovigilance inspections. Relevant for understanding the relationship between internal audit and regulatory inspection.
- European Parliament and Council. Directive 2001/83/EC, as amended. EU legal framework for medicinal products for human use and pharmacovigilance.
- European Parliament and Council. Regulation (EC) No 726/2004, as amended. Union framework for authorisation and supervision of medicinal products and relevant pharmacovigilance obligations.
- European Commission. Commission Implementing Regulation (EU) No 520/2012, as amended. Detailed rules concerning pharmacovigilance activities under the EU pharmaceutical framework.
Regulatory Note
This article is an educational and practical explanation of GVP Module IV. It does not replace the current GVP guideline, applicable EU legislation, regulatory decisions, inspection requirements or organisation-specific legal and quality-system assessments.
GVP guidance is periodically revised. Before using this article to make a live compliance decision, verify the current EMA version, effective date and applicable scope. Where applicable law or a legally operative regulatory decision establishes a requirement, that source should be consulted directly.
Audit finding classifications used by individual organisations are internal classifications unless otherwise stated. They should not be assumed to have the same legal meaning as classifications used by a competent authority during a regulatory inspection.
Examples in this article are educational examples designed to demonstrate audit reasoning. They are not descriptions of specific regulatory inspection cases unless an authoritative source is explicitly identified.