GVP Module VI Inspection Findings: Common ICSR Case-Processing Deficiencies

A practical inspection-focused guide to recurring weaknesses in individual case safety report processing and the evidence that demonstrates effective control.

Audio Lesson 20 min
Knowledge Assessment Test your understanding of this article. Take the assessment →

GVP Module VI Inspection Findings: Common ICSR Case-Processing Deficiencies

Introduction

An ICSR process can appear compliant when viewed through procedures, training records and system configuration alone. A pharmacovigilance inspection examines something more demanding: whether the organisation actually receives, assesses, processes, follows up, submits and maintains safety reports in accordance with its obligations, and whether the controls operate effectively in practice.

This article focuses on the inspection perspective of GVP Module VI. It does not attempt to reproduce the Module VI requirements already addressed in the other articles in this series. Instead, it brings the requirements together around the types of evidence, control failures and process weaknesses that an inspector may investigate.

The distinction between a documented process and an effective process is central.

A procedure can be compliant on paper while the implemented process is not.

1. What an Inspector Is Trying to Establish

For ICSR processing, an inspection may seek evidence that the organisation can reliably demonstrate:

  1. reports enter the PV system appropriately;
  2. potentially valid reports are identified and assessed;
  3. valid ICSRs are processed within applicable timelines;
  4. clinical and regulatory assessments are appropriate;
  5. relevant information is followed up when useful;
  6. duplicates are identified and managed;
  7. electronic submissions are accurate and traceable;
  8. rejected or failed transmissions are controlled;
  9. incoming information is reconciled;
  10. changes and corrections are managed;
  11. records are complete and attributable; and
  12. management knows when the process is not working effectively.

These are not twelve isolated controls. They form one case-processing system.

2. The Inspector's Evidence Trail

A useful inspection model is to reconstruct a case from source to regulatory output:

Source received
      ↓
Date of awareness established
      ↓
Triage / validity assessment
      ↓
Case creation
      ↓
Medical and regulatory assessment
      ↓
Follow-up where appropriate
      ↓
QC / review
      ↓
Submission decision
      ↓
E2B transmission
      ↓
EV acknowledgement
      ↓
Reconciliation
      ↓
Follow-up / amendment / correction

An inspector may select cases at different points in this chain and ask the organisation to demonstrate what happened.

A strong system should produce a coherent story from the records without requiring an individual processor to explain events from memory.

3. Deficiency Pattern: Reports Do Not Enter the PV System Reliably

The first failure can occur before a case is ever created.

Potential vulnerabilities include:

The inspection question is not simply whether a procedure says that reports should be forwarded. It is whether the organisation can demonstrate that reports are actually identified and transferred into the PV process within the required framework.

4. Deficiency Pattern: Day Zero Is Not Controlled

The date on which the organisation becomes aware of a report can determine the regulatory reporting timeline.

Weaknesses may arise when:

A robust process preserves the evidence needed to establish the relevant date of awareness.

5. Deficiency Pattern: Invalidity and Incompleteness Are Confused

One recurring conceptual risk is treating a case as invalid simply because it lacks information that would be desirable for a good-quality case.

The minimum criteria for a valid ICSR should be distinguished from the broader clinical information that may be obtained through follow-up.

An inspection may therefore examine cases rejected as "invalid" and ask:

6. Deficiency Pattern: Seriousness Is Applied Mechanically

Seriousness assessment must be based on the applicable regulatory criteria and the information available in the case.

A common control weakness is a simplistic rule such as "hospitalisation = serious" without examining the actual circumstances or applicable criteria.

Conversely, an organisation may fail to recognise a serious case because the source used informal terminology or did not explicitly use the word "serious".

The inspection focus should therefore be on the reasoning and evidence supporting the seriousness assessment.

7. Deficiency Pattern: Death Is Treated as Cause of Death

A fatal outcome requires careful clinical interpretation.

A report stating that a patient died does not automatically establish that the medicinal product caused the death or that a specific adverse reaction caused it.

An inspector may examine whether the organisation:

This is particularly important in cases where the initial source provides little information beyond the fact of death.

8. Deficiency Pattern: Follow-Up Is Generic Rather Than Purposeful

The organisation may have a documented follow-up procedure but still perform ineffective follow-up.

Potential weaknesses include:

The detailed follow-up methodology is addressed in G19 β€” Follow-Up of Individual Case Safety Reports.

9. Deficiency Pattern: Case Data Do Not Match the Source

Data-entry errors can alter the meaning of a case.

Examples include incorrect dates, product information, reaction terms, seriousness, outcome or reporter details.

An inspector may compare source documents with the safety database and ask whether the quality-control process is capable of detecting material discrepancies.

The issue is not whether a database contains any errors. Complex PV systems will occasionally contain errors. The critical questions are whether material errors are prevented, detected, corrected and trended.

10. Deficiency Pattern: Duplicate Management Is Weak

Duplicate cases can distort individual-case and aggregate safety information.

Potential weaknesses include:

GVP Module VI Addendum I specifically addresses duplicate management and should be considered alongside the main Module VI requirements.

11. Deficiency Pattern: Electronic Submission Is Treated as an IT Process

A technically functioning gateway does not by itself demonstrate compliant ICSR submission.

The organisation should be able to demonstrate control over:

EMA's current EudraVigilance electronic-reporting information describes quality assurance and compliance monitoring of ICSR submissions, including automated monitoring of reporting timelines. ξˆ€citeξˆ‚turn0search1

12. Deficiency Pattern: Rejected Messages Are Not Controlled

A message leaving the sender's system does not necessarily mean that the regulatory reporting process has successfully completed.

An inspector may sample rejected messages and ask:

EMA's Module VI process describes technical validation of messages received by EudraVigilance, making validation status an important part of the submission lifecycle. ξˆ€citeξˆ‚turn0search20

13. Deficiency Pattern: Reconciliation Is Performed but Exceptions Are Not Resolved

A reconciliation report can exist without being an effective control.

For example, a monthly reconciliation may identify ten discrepancies every month, while the same discrepancies remain unresolved for extended periods.

An inspector may reasonably ask:

What does the organisation do when reconciliation identifies a discrepancy?

The answer should include ownership, investigation, correction, escalation and closureβ€”not merely production of the reconciliation report.

14. Inspection Evidence Should Demonstrate Effective Implementation

EMA's inspection coordination material explicitly identifies documentation concerning validation of processes and qualification of systems as important evidence likely to be requested during inspections, including where electronic activities are outsourced. ξˆ€citeξˆ‚turn0search0

For ICSR processing, useful evidence may therefore include:

The next chunk will examine how inspectors can move from individual case findings to systemic deficiencies, including sampling, timelines, outsourced processing, CAPA effectiveness and difficult inspection scenarios.

15. From Case Error to Systemic Deficiency

An inspection finding should not be based only on the existence of an isolated processing error. The significance of an observation depends on factors such as its regulatory impact, recurrence, detectability, duration, affected population and the effectiveness of existing controls.

A useful internal assessment therefore asks:

  1. What happened in the sampled case?
  2. What requirement or control was not met?
  3. Could the same failure exist in other cases?
  4. How long could the failure have existed?
  5. How likely was the existing control to detect it?
  6. Did the organisation identify the problem before inspection?
  7. Was the root cause correctly understood?
  8. Did the corrective action address the system rather than only the sampled case?

Correcting the sampled case is not necessarily sufficient if the underlying process remains vulnerable.

16. Sampling Strategy

An inspection sample may be deliberately heterogeneous.

Cases may be selected because they are:

Inspection readiness therefore requires confidence in the underlying population rather than preparation of a small set of unusually clean demonstration cases.

17. Timeline Testing

ICSR compliance can be tested by reconstructing relevant dates rather than accepting a database field at face value.

For a sampled case, an inspector may compare:

Original source
      ↓
Actual receipt / awareness
      ↓
Internal forwarding
      ↓
Case creation
      ↓
Validation
      ↓
Medical assessment
      ↓
Submission
      ↓
Acknowledgement
      ↓
Follow-up / amendment

Differences between these dates can reveal weaknesses in intake controls, vendor interfaces, date-of-awareness governance or submission monitoring.

EMA's current EudraVigilance framework includes compliance monitoring of ICSR reporting, making the accuracy and traceability of relevant dates particularly important.

18. Outsourced Case Processing

Outsourcing does not remove the MAH's responsibility for oversight of the pharmacovigilance system.

An inspector may examine the interface between the MAH and service provider, including:

A vendor's statement that a case was processed according to its procedure is not, by itself, evidence that the MAH's regulatory obligations were effectively controlled.

19. Affiliate Interfaces

Global organisations may receive information through multiple affiliates before the information reaches the EU PV organisation.

Potential failure points include:

An inspection may therefore test the complete pathway rather than examining only the central PV department.

20. Case Processing and Medical Review

The quality of case processing cannot be evaluated solely by checking whether mandatory fields are populated.

Medical review should be capable of identifying clinically meaningful inconsistencies, such as:

The precise allocation of medical-review responsibilities varies between organisations, but the system should demonstrate appropriate competence and escalation.

21. Case Narrative Quality

A case narrative should allow a reviewer to understand the clinically relevant sequence of events.

Inspection weaknesses may include:

The purpose of a narrative is not literary quality. It is accurate, traceable clinical communication.

22. Corrections and Amendments

An inspection may examine cases that were corrected after submission.

Relevant questions include:

Repeated amendments involving the same data element may indicate a process weakness rather than independent isolated errors.

23. CAPA Effectiveness

A CAPA should address the cause of the problem, not merely its visible manifestation.

For example, if delayed transmission occurs because acknowledgement messages are not monitored, retraining processors may be inadequate if the underlying monitoring system remains unchanged.

Effective CAPA may require:

Effectiveness should subsequently be demonstrated using objective evidence.

24. Recurrence as a Warning Signal

Repeated similar case-processing errors should trigger consideration of systemic causes.

Examples include repeated:

Trend analysis should therefore look beyond the individual error and ask whether the same failure mode is recurring across products, countries, vendors, processors or systems.

25. System Changes and Case Processing

A major safety-database migration, interface change or workflow redesign can create temporary or persistent risks.

Inspection evidence may include:

EMA inspection guidance identifies validation of processes and qualification of systems as important inspection evidence, including where relevant activities are outsourced.

26. Vendor System Evidence

Where an outsourced provider uses a safety database or electronic interface, the MAH should understand what evidence demonstrates that the relevant process is controlled.

This does not necessarily mean duplicating every vendor qualification activity. It means that the MAH should be able to demonstrate appropriate oversight and assurance that the outsourced process supports compliance.

27. Difficult Inspection Scenario: One Late Case

Suppose an inspector identifies one case submitted after the applicable deadline.

The correct response is not simply to explain why that case was late.

The organisation should also determine whether the event was isolated, whether similar cases were affected, what control failed, whether reporting-compliance data were complete and whether corrective action was effective.

An isolated event with a robust investigation and effective controls is materially different from an apparently isolated event discovered because the organisation lacks the ability to identify recurrence.

28. Difficult Inspection Scenario: Perfect Procedure, Poor Records

The organisation's procedure describes an excellent process, but sampled cases contain missing evidence of review, follow-up decisions or reconciliation.

This creates a gap between documented process and demonstrated implementation.

During an inspection, the record of what actually happened generally has greater evidentiary value than a statement of what should have happened.

29. Difficult Inspection Scenario: Good Metrics, Bad Cases

A department may report high compliance percentages while sampled cases reveal clinically important errors.

This can indicate that the metric is measuring the wrong outcome or that the denominator excludes relevant failures.

Quality metrics should therefore be tested against actual case evidence.

30. Difficult Inspection Scenario: Vendor KPI Is Green

A vendor may meet its contractual processing KPI while the MAH still experiences regulatory deficiencies.

For example, a vendor may process cases within a contractual number of hours while an upstream affiliate transfer process causes the regulatory Day 0 to be missed.

The MAH should therefore evaluate the entire end-to-end process rather than treating individual vendor KPIs as proof of overall compliance.

31. Difficult Inspection Scenario: EudraVigilance Acknowledgement Exists

An acknowledgement message demonstrates interaction with the EudraVigilance system, but it should not be interpreted without considering its status and the complete submission lifecycle.

The organisation should be able to determine whether the message was accepted, rejected or otherwise requires action, and whether corrective action was completed where necessary.

32. Internal Mock Inspection Approach

A practical exercise can reproduce the inspection evidence trail.

Select a mixed sample and ask an independent reviewer to answer, without relying on the processor's memory:

Any question that cannot be answered from the controlled record is a potential inspection-readiness weakness.

33. The QPPV Perspective

The QPPV does not need to personally process every ICSR. The QPPV does need sufficient oversight to understand whether the system is capable of meeting its pharmacovigilance responsibilities.

Useful QPPV oversight questions include:

The QPPV's role is therefore not merely to review compliance dashboards. It includes understanding whether those dashboards represent the effectiveness of the underlying PV system.

34. From Inspection Observation to Management Action

A mature organisation should be able to convert an inspection observation into a structured improvement cycle:

Observation
    ↓
Immediate containment
    ↓
Impact assessment
    ↓
Population / systemic assessment
    ↓
Root-cause analysis
    ↓
CAPA
    ↓
Implementation
    ↓
Effectiveness verification
    ↓
Management / QPPV oversight

This prevents the organisation from treating each inspection finding as a standalone administrative event.

The final chunk will consolidate the inspection checklist, evidence matrix, common deficiency patterns, References and Regulatory Note.

35. Practical Inspection Evidence Matrix

Inspection question Evidence an effective system should be able to produce
When was the report received? Source record, intake record and controlled awareness-date evidence
Why was it processed as an ICSR? Validity assessment and supporting source information
How was seriousness assessed? Clinical information, assessment rationale and case history
Was follow-up considered? Follow-up assessment, requests and responses where applicable
Was the case submitted on time? Case timeline, submission record and EudraVigilance acknowledgement
Were transmission errors handled? Rejection/error record, investigation and resubmission evidence
Were duplicates controlled? Duplicate assessment and linkage/merger history
Was important information corrected? Amendment history and regulatory submission evidence
Were errors identified? QC records, deviations and error-trending data
Were systemic issues addressed? Root-cause analysis, CAPA and effectiveness evidence
Were vendors controlled? Oversight records, performance data and escalation evidence
Was the system changed? Change control, validation/qualification and migration evidence

The precise evidence set depends on the process and applicable requirements. The principle is that important regulatory decisions should be reconstructable from controlled records.

36. Common Deficiency Pattern: Day-0 Uncertainty

A recurring weakness is failure to establish when the organisation became aware of a report.

This may occur when information moves through several functions before reaching PV, when affiliates use different definitions, or when vendors receive information outside the formal PV channel.

An inspection-ready organisation should have a clear rule for awareness date and controls capable of identifying delayed transfers.

37. Common Deficiency Pattern: Validity Confused With Clinical Completeness

A report can satisfy the minimum criteria for an ICSR while still lacking clinically useful information.

A common weakness is either:

The correct distinction is important for both compliance and safety-data quality.

38. Common Deficiency Pattern: Seriousness Used as a Shortcut

Seriousness should be based on the applicable criteria and available information.

Hospitalisation, for example, should not be treated as automatically demonstrating that the suspected adverse reaction itself caused or required hospitalisation without appropriate clinical assessment.

Likewise, a fatal outcome does not establish the cause of death.

Inspection-ready processing demonstrates the reasoning supporting the classification.

39. Common Deficiency Pattern: Follow-Up as a Mechanical Exercise

A procedure may require follow-up while the actual requests are generic, repetitive or unrelated to the clinical uncertainty.

Inspectors may therefore examine whether follow-up decisions are clinically purposeful rather than simply whether a follow-up email was sent.

The dedicated G19 article addresses this subject in detail.

40. Common Deficiency Pattern: Reconciliation Without Investigation

An organisation may perform regular reconciliation but fail to investigate exceptions adequately.

A reconciliation control is effective only when discrepancies are identified, assigned, investigated, resolved or appropriately escalated.

A spreadsheet showing "matched" and "unmatched" counts is not by itself evidence of effective reconciliation.

41. Common Deficiency Pattern: Metrics That Hide Risk

Metrics can create false assurance when their definitions exclude important populations or focus only on average performance.

For example, a high overall on-time submission rate may conceal a small but recurring population of high-risk serious cases affected by the same process failure.

Metrics should therefore be segmented sufficiently to identify meaningful patterns.

42. Common Deficiency Pattern: CAPA Closes the Finding but Not the Cause

A CAPA may close after training, procedure revision or case correction without demonstrating that recurrence risk has actually been reduced.

An effective CAPA assessment should ask whether the intervention changed the underlying failure mechanism and whether objective evidence supports that conclusion.

43. Common Deficiency Pattern: Outsourcing Creates an Accountability Gap

The MAH may rely on vendor procedures while assuming that contractual KPIs demonstrate compliance.

This can fail when the vendor measures its own processing step but the regulatory risk occurs at an interface outside that step.

End-to-end ownership should therefore remain clear.

44. Common Deficiency Pattern: Inspection Preparation Is Too Narrow

Preparing only a small set of exemplary cases can conceal population-level weaknesses.

A stronger approach is to perform risk-based internal sampling across products, sources, affiliates, vendors, seriousness categories, submission outcomes and time periods.

45. Mock Inspection Exercise

A practical Module VI mock inspection can be conducted using a randomly selected sample supplemented by deliberately difficult cases.

For every case, the reviewer should attempt to reconstruct the complete lifecycle without asking the processor to explain undocumented decisions.

The exercise should record:

The goal is not to achieve a perfect sample. It is to determine whether the organisation can reliably demonstrate control over the underlying process.

46. Questions for Senior PV Management

Management review should consider more than compliance percentages.

Useful questions include:

  1. What are our most common ICSR errors?
  2. Are they increasing or decreasing?
  3. Which interfaces generate the greatest risk?
  4. Are serious or fatal cases disproportionately affected?
  5. Are vendor failures recurring?
  6. Are reconciliation exceptions ageing?
  7. Are CAPAs demonstrably effective?
  8. Have recent system changes altered case quality?
  9. Do our metrics correlate with case-sample findings?
  10. What would an inspector discover if they selected cases independently?

47. Key Takeaways

References

  1. European Medicines Agency. Good Pharmacovigilance Practices (GVP), Module VI β€” Collection, management and submission of reports of suspected adverse reactions to medicinal products.
  2. European Medicines Agency. Good Pharmacovigilance Practices (GVP), Module III β€” Pharmacovigilance inspections.
  3. European Medicines Agency. Pharmacovigilance inspection coordination and guidance material.
  4. European Medicines Agency. EudraVigilance electronic reporting and compliance monitoring guidance.
  5. European Commission. Commission Implementing Regulation (EU) No 520/2012, as amended.
  6. European Parliament and Council. Directive 2001/83/EC, as amended.
  7. International Council for Harmonisation. ICH E2D(R1) β€” Post-Approval Safety Data: Definitions and Standards for Management and Reporting of Individual Case Safety Reports.
  8. European Medicines Agency. EudraVigilance guidance, including ICSR electronic reporting and acknowledgement requirements.

Regulatory Note

This article is an educational interpretation of inspection risks associated with ICSR collection, management and submission under the EU pharmacovigilance framework. It does not replace current EU legislation, GVP modules, EudraVigilance technical documentation, applicable national requirements or an organisation's approved procedures.

Inspection findings vary according to the facts, evidence, regulatory context and scope of an individual inspection. The deficiency patterns described here are therefore learning patterns, not claims that every item has been formally classified as an inspection finding by an authority.

The practical scenarios are illustrative unless a specific authoritative source is identified. Organisations should verify current regulatory and technical requirements before implementing controls.

Revision History

Last reviewed: 2026-08-24