GVP Module VI: Sources of Individual Case Safety Reports
- GVP Module VI: Sources of Individual Case Safety Reports
- Introduction
- 1. The Source Framework in GVP Module VI
- 2. What Is a Spontaneous Report?
- 3. Primary Source and Source of the Report Are Different Concepts
- 4. Multiple Primary Sources
- 5. Solicited Does Not Mean "Less Important"
- 6. Stimulated Reporting Is Not Automatically Solicited Reporting
- 7. Medical Information and Product Information Services
- 8. Internet and Digital Sources
- 9. Regulatory Authorities and Other Organisations
- 10. Source Classification Should Be Determined Early
- 11. Source Does Not Replace ICSR Validation
- 12. Source Classification and Case Origin Must Be Kept Distinct
- 13. Why the Distinction Matters for Day 0 and Reporting
- 14. Source Classification as an Inspection Control
- 15. Why Source Classification Matters
- References
- Regulatory Note
- 13. Healthcare Professional Reports
- 14. Consumer and Patient Reports
- 15. Reports From Competent Authorities
- 16. Reports From Business Partners
- 17. Affiliate Reports
- 18. Literature as a Source
- 19. A Literature Article Does Not Automatically Determine Case Origin
- 20. Clinical Trials and Study Sources
- 21. Non-Interventional Studies and Other Organised Systems
- 22. Patient Support Programmes
- 23. Registries
- 24. Market Research
- 25. Digital Platforms and Social Media
- 26. Poison Control and Other Specialist Organisations
- 27. Company Employees
- 28. Legal Claims and Litigation
- 29. Media and Press Reports
- 30. Source Hierarchy Is Not Evidence Hierarchy
- 31. Source Changes During the Case Lifecycle
- 32. Source and Duplicate Management
- 33. Source Classification and Data Standards
- 34. Source-Control Questions for the PV System
- 35. Difficult Scenario: Same Event, Two Channels
- 36. Difficult Scenario: Patient Support Programme With a Voluntary Report
- 37. Difficult Scenario: Study Publication Identified by MLM
- 38. Difficult Scenario: Sales Representative Receives a Report
- 39. Difficult Scenario: Medical Information Enquiry
- 40. Difficult Scenario: Social-Media Post
- 41. Difficult Scenario: Safety Communication Followed by a Report
- 42. Difficult Scenario: Regulatory Authority Case
- 43. Difficult Scenario: Partner Receives the Case Late
- 44. Difficult Scenario: The Source Is Unclear
- 45. Source Classification and Day 0
- 46. Source Classification and Follow-Up
- 47. Source Classification and Data Interpretation
- 48. Source Classification and Signal Detection
- 49. Inspection Perspective: Can You Reconstruct the Source Pathway?
- 50. Inspection Perspective: Testing Interfaces
- 51. Inspection Perspective: Procedure Versus Actual Flow
- 52. Common Failure Modes
- Failure 1: Treating every report as spontaneous
- Failure 2: Treating every unsolicited communication as a solicited report
- Failure 3: Confusing source with primary reporter
- Failure 4: Losing the original awareness date
- Failure 5: Relying on the PV mailbox as the only intake control
- Failure 6: Treating the platform as the source category
- Failure 7: Automatically classifying literature cases as spontaneous
- Failure 8: Treating source classification as permanent
- 53. Practical Source-Control Checklist
- 54. Relationship With the Other Module VI Articles
- 55. Key Takeaways
- References
- Regulatory Note
Introduction
An individual case safety report can enter a pharmacovigilance system through many different routes. Understanding the route is not merely an administrative exercise. The source can determine how the information should be classified, which reporting rules apply, how the reporting clock is established, what additional controls are required and how the case should subsequently be interpreted.
GVP Module VI requires marketing authorisation holders and competent authorities to take appropriate measures to collect and collate reports of suspected adverse reactions originating from unsolicited and solicited sources. The pharmacovigilance system should acquire sufficient information for scientific evaluation and should support timely validation and exchange of reports.
The central distinction is therefore not simply "where did the message arrive?" It is what was the origin and nature of the information?
A report received through a company mailbox can be spontaneous. A report received through the same mailbox can be solicited. A case identified in a publication can have a literature origin but may itself describe a study participant rather than a spontaneous observation. A patient support programme can generate solicited information even when the adverse event was volunteered by the patient.
The source classification must consequently be based on the underlying circumstances rather than the technical channel through which the information reached pharmacovigilance.
1. The Source Framework in GVP Module VI
GVP Module VI distinguishes, in the post-authorisation setting, between reports originating from unsolicited sources and those reported as solicited. Spontaneous reports are a principal category of unsolicited reports.
A useful conceptual model is:
Individual safety information
โ
โโโ Unsolicited
โ โโโ Spontaneous
โ โโโ Other unsolicited communications
โ
โโโ Solicited
โโโ Organised data collection system
โโโ Clinical study
โโโ Non-interventional study
โโโ Patient support programme
โโโ Registry
โโโ Other organised system
This is a conceptual map rather than a replacement for the detailed definitions and source-specific rules in the applicable guidance.
2. What Is a Spontaneous Report?
GVP Module VI describes a spontaneous report as an unsolicited communication by a healthcare professional or consumer to a competent authority, marketing authorisation holder or another organisation that describes one or more suspected adverse reactions in a patient who received one or more medicinal products. It does not derive from a study or organised data-collection system.
Several consequences follow from this definition.
First, unsolicited is important. The information was not generated because the reporter was participating in a system designed to collect safety information.
Second, a spontaneous report does not require a healthcare professional reporter. Consumers and patients can provide spontaneous reports.
Third, spontaneous reporting is not limited to reports sent directly to the MAH. Reports can reach competent authorities or other organisations and subsequently enter the relevant pharmacovigilance processes.
3. Primary Source and Source of the Report Are Different Concepts
The primary source is the person who reports the facts about the individual case. GVP Module VI, reflecting ICH terminology, distinguishes healthcare professionals and consumers as types of primary source. The primary source may be a healthcare professional such as a physician, dentist, pharmacist, nurse or other medically qualified person, or a consumer such as a patient, relative, carer or other non-healthcare professional.
This should not be confused with the broader source category of the case.
For example:
A physician sends an adverse reaction report after receiving a routine clinical call from a patient.
The primary source may be the physician, while the case may be classified as spontaneous.
Conversely:
A patient reports an adverse event through a patient support programme in which adverse events are routinely solicited.
The patient may be the primary source, but the information is not thereby spontaneous.
Source classification and primary-source identification answer different questions.
4. Multiple Primary Sources
More than one person can provide information about the same case.
For example, a patient may initially report an event and a treating physician may subsequently provide clinical confirmation. In such circumstances, the case record should preserve the relevant primary-source information rather than arbitrarily replacing one source with another.
GVP Module VI states that where several primary sources provide information on the same case, the details of all primary sources should be provided in the ICSR, including their qualifications where applicable.
This matters because source identity can affect the clinical interpretation and evidentiary value of the information.
5. Solicited Does Not Mean "Less Important"
A common operational misconception is that spontaneous reports are inherently more important than solicited reports.
That is incorrect.
A solicited report is still pharmacovigilance information and may meet the criteria for an ICSR. The key question is whether the information originated from an organised data-collection system and whether the applicable criteria for reporting are met.
Solicited reports can be particularly valuable because the underlying programme may collect structured information about exposure, treatment, clinical outcomes or defined populations.
At the same time, organised collection creates additional responsibilities: the organisation needs to understand the design of the system, the population covered, the reporting process, the data flow and the criteria used to identify and process suspected adverse reactions.
6. Stimulated Reporting Is Not Automatically Solicited Reporting
GVP Module VI specifically identifies certain forms of stimulated reporting as spontaneous reporting, including reports resulting from direct healthcare professional communication, publication in the press, questioning of healthcare professionals by company representatives, communication from patient organisations to their members and class-action litigation.
This is an important distinction.
The fact that a company, authority or other organisation has communicated safety information does not automatically convert a subsequent unsolicited report into a solicited report from an organised data-collection system.
The underlying circumstances need to be assessed.
7. Medical Information and Product Information Services
Unsolicited reports received through medical enquiry or product-information services can fall within spontaneous reporting when they are not associated with an organised data-collection system. GVP Module VI expressly identifies such unsolicited reports among situations to be considered as spontaneous reports.
This creates an important operational interface.
Medical information personnel may be the first recipients of safety information even though they are not part of the central PV case-processing team. The PV system therefore needs a controlled mechanism for recognising, transferring and documenting potential safety reports.
The relevant question is not simply:
"Did the message arrive in the PV mailbox?"
It is:
"Could safety information have been received elsewhere in the organisation, and can the organisation demonstrate that it will reach pharmacovigilance without avoidable delay?"
8. Internet and Digital Sources
Unsolicited reports of suspected adverse reactions collected from the internet or digital media can also constitute spontaneous reports, subject to the applicable GVP Module VI requirements.
Digital source management therefore needs to distinguish between:
- an unsolicited report posted by an individual;
- information deliberately collected through an organised programme;
- a publication or other literature source;
- and content that does not contain sufficient information to constitute an individual case.
The mere presence of an adverse-event statement on a website does not automatically make it a valid ICSR. The applicable validation criteria still have to be assessed.
9. Regulatory Authorities and Other Organisations
Safety information may reach a competent authority, regional pharmacovigilance centre, poison control centre, partner organisation or another organisation before reaching the MAH.
GVP Module VI's definition of spontaneous reporting recognises communications to competent authorities, MAHs and other organisations.
The MAH therefore needs appropriate interfaces for receiving safety information from external organisations and partners.
These interfaces should address at least:
- responsibility for receipt;
- transmission mechanisms;
- date and time of awareness where relevant;
- case identification;
- duplicate risk;
- escalation;
- reconciliation;
- and documentation.
10. Source Classification Should Be Determined Early
Source classification should occur sufficiently early in case processing to ensure that the appropriate workflow is followed.
A useful workflow is:
Safety information received
โ
Identify origin of information
โ
Unsolicited or solicited?
โ
Identify specific source category
โ
Assess ICSR validity
โ
Determine applicable reporting pathway
โ
Process and submit as required
The classification should remain traceable when later information changes the understanding of the case.
11. Source Does Not Replace ICSR Validation
A report from a recognised source is not automatically a valid ICSR.
The four minimum elements still need to be assessed: an identifiable reporter, an identifiable patient, a suspected adverse reaction/event and a suspected medicinal product, applying the applicable current criteria.
Likewise, a report from an apparently informal source is not automatically invalid simply because the source is unusual.
This distinction is central to good case processing:
source classification tells the organisation how the information arose; validation determines whether the information constitutes a reportable individual case.
12. Source Classification and Case Origin Must Be Kept Distinct
A further distinction is needed between source classification, case origin and primary source.
These terms can overlap operationally but they are not interchangeable.
For example, a published article may be the source through which an MAH learns about a case. The underlying case may nevertheless originate from a clinical trial, a non-interventional study or spontaneous reporting. The fact that the case was discovered in literature does not by itself determine its regulatory origin.
Similarly, a patient may be the primary source of information while the information is collected through a structured patient support programme. The primary source is therefore not sufficient to classify the report as spontaneous.
A robust case-processing model should be able to answer three separate questions:
- How did the MAH receive the information?
- Under what circumstances was the safety information generated or collected?
- Who provided the primary clinical information?
Keeping these dimensions separate is particularly important for literature cases, clinical-trial cases, patient-support programmes and other organised data-collection systems. The dedicated Module VI articles on these sources should be used for the detailed rules.
13. Why the Distinction Matters for Day 0 and Reporting
Source classification and case origin can affect how the organisation determines the applicable processing pathway and reporting clock. A case discovered through one channel should not automatically inherit the timing or classification rules of that channel without assessing the underlying circumstances.
For example, a literature-monitoring process may identify a publication describing a clinical-study participant. The publication is the route of discovery, but the underlying case origin may be study-related. Conversely, a publication may describe an unsolicited spontaneous report. These situations should not be treated as equivalent merely because both entered the PV system through literature monitoring.
The case record should preserve sufficient information to reconstruct the reasoning used to establish the applicable pathway.
14. Source Classification as an Inspection Control
During an inspection, an apparently simple database field such as "source = spontaneous" may lead to broader questions:
- What was the original source?
- Was the information solicited?
- Was it generated within an organised data-collection system?
- Who was the primary source?
- When did the MAH become aware?
- Was the classification supported by the original information?
- Could the same source have generated other cases that were classified differently?
The organisation should therefore be able to demonstrate that source classification is based on controlled rules and appropriate evidence rather than processor habit.
15. Why Source Classification Matters
Correct source classification can affect:
- the reporting category;
- case-processing workflow;
- Day 0 determination;
- follow-up responsibilities;
- duplicate assessment;
- regulatory submission pathway;
- aggregate-data interpretation;
- signal detection;
- and inspection evidence.
A source field in a safety database should therefore not be treated as a cosmetic metadata field.
It is part of the clinical and regulatory context of the case.
References
- European Medicines Agency. Good Pharmacovigilance Practices (GVP), Module VI โ Collection, management and submission of reports of suspected adverse reactions to medicinal products, Rev. 2.
- International Council for Harmonisation. ICH E2D(R1), Post-Approval Safety Data: Definitions and Standards for Management and Reporting of Individual Case Safety Reports.
- European Medicines Agency. GVP Module VI guidance on primary sources and collection of individual safety reports.
Regulatory Note
This article explains the source framework in GVP Module VI for educational purposes. It does not replace the current GVP text, applicable EU legislation, ICH E2D(R1), EudraVigilance technical documentation, national requirements or approved company procedures. Source classification should always be assessed against the circumstances of the individual report and the current applicable regulatory framework.
13. Healthcare Professional Reports
Healthcare professionals are a major source of spontaneous safety information. They may report directly to the MAH, to a competent authority, through a medical information function, through a local affiliate or through another established channel.
The organisation should not assume that all healthcare professional reports arrive through a single route.
A report may also be stimulated without becoming part of an organised data-collection system. GVP Module VI specifically recognises certain stimulated communications as spontaneous reports. ๎cite๎turn0search17๎
The operational control is therefore the interface between the communication activity and pharmacovigilance.
14. Consumer and Patient Reports
Patients, consumers, relatives and carers can provide safety information.
A consumer report should not be treated as inherently lower quality or automatically rejected because it lacks medical terminology. The organisation should capture the information provided, assess its validity and seek appropriate medical clarification where useful.
Consumer reports may contain valuable information about symptoms, timing, treatment changes and outcomes that may not be apparent from formal medical documentation.
The absence of medical confirmation does not by itself convert a report into a non-case when the applicable minimum criteria are otherwise satisfied.
15. Reports From Competent Authorities
Competent authorities can transmit or otherwise communicate safety information to an MAH.
Such reports may originate from spontaneous reporting systems, regulatory enquiries, other national sources or international information exchange.
The MAH should have a controlled process for identifying whether the authority communication represents:
- a new ICSR;
- follow-up information for an existing case;
- a potential duplicate;
- or information that does not meet the criteria for an individual case.
The source authority should remain traceable in the case record.
16. Reports From Business Partners
Licensing partners, distributors, co-marketing partners and other organisations may receive safety information before the MAH.
The relevant agreement should establish how safety information is transferred and how responsibilities are divided.
A common failure is to assume that a contractual transfer period is equivalent to the regulatory reporting clock. It is not necessarily so.
The MAH needs controls that ensure information reaches the appropriate pharmacovigilance process in time for the applicable regulatory obligations.
17. Affiliate Reports
Global organisations frequently receive the same safety information through local affiliates and central functions.
Affiliate processes should therefore define:
- who receives safety information locally;
- how it is identified;
- when it is transferred;
- how awareness dates are preserved;
- how local regulatory obligations interact with global processing;
- and how duplicates are controlled.
A central database cannot compensate for an uncontrolled local intake process.
18. Literature as a Source
Medical literature is an important source of suspected adverse reaction information, but literature is conceptually different from a person directly submitting a spontaneous report.
GVP Module VI contains specific requirements for literature monitoring and for determining the reporting clock for cases identified through literature monitoring. EMA's published Q&A states that MAHs should perform global literature searches systematically and at least weekly in widely used reference databases, with specific rules for Day 0 for cases identified through that activity. ๎cite๎turn0search1๎
The literature article in this series addresses Medical Literature Monitoring in detail. G3 should therefore establish literature as a source category without duplicating the specialist MLM methodology.
19. A Literature Article Does Not Automatically Determine Case Origin
The fact that an ICSR is discovered in a publication does not, by itself, establish that it is a spontaneous case.
The underlying information needs to be examined.
For example, a published case report may describe an individual patient whose adverse reaction was reported spontaneously to the treating physician. That publication is a literature source through which the MAH learns about the case.
In contrast, a publication may describe a clinical trial or organised post-authorisation study. The underlying case may then have a solicited or study-related origin even though the MAH discovered it through literature monitoring.
This distinction is particularly important when literature-derived cases are reconciled with study systems and aggregate data.
20. Clinical Trials and Study Sources
Clinical-trial safety information follows a regulatory framework that is distinct from ordinary post-authorisation spontaneous reporting.
The organisation must determine whether the information is part of a clinical-trial safety-reporting process, a post-authorisation PV process or another applicable pathway.
This is why a study source should not simply be relabelled "spontaneous" because the information was received by the PV department.
The dedicated G16 article addresses the clinical-trial interface, including sponsor, investigator and MAH responsibilities and the distinction between clinical-trial safety reporting and post-authorisation ICSR processing. The repository already contains that dedicated article. ๎cite๎turn214file1๎
21. Non-Interventional Studies and Other Organised Systems
A non-interventional study can constitute an organised data-collection system. The same is true of certain registries, patient support programmes and other structured programmes.
The existence of an adverse event in such a system therefore requires assessment of the source context before classification.
The dedicated G18 article covers these organised data-collection systems and solicited sources in greater depth. ๎cite๎turn206file1๎
22. Patient Support Programmes
Patient support programmes can generate substantial safety information.
The fact that a patient volunteers an adverse event during a programme does not necessarily make the report spontaneous. If the programme is organised to collect information systematically, the relevant information may be solicited.
The classification therefore depends on the design and operation of the programme, not simply on whether the patient volunteered the words.
The dedicated G15 article addresses PSPs, including solicited versus spontaneous classification, validity, vendor oversight and inspection scenarios. ๎cite๎turn208file0๎
23. Registries
Registries can occupy different positions in the pharmacovigilance framework depending on their design and purpose.
A registry established primarily to collect structured information about a defined population can constitute an organised data-collection system. Safety information arising from it should therefore be assessed according to the applicable solicited-source framework.
The organisation should understand:
- who enters the data;
- why the registry exists;
- whether exposure is systematically recorded;
- whether adverse events are actively collected;
- how cases are identified;
- and how information reaches pharmacovigilance.
24. Market Research
Market research can also generate safety information, but its classification depends on how the information was obtained and whether the activity constitutes an organised data-collection system.
A spontaneous statement made during an ordinary market-research interaction should not automatically be classified solely by the name of the programme. Conversely, a structured activity designed to collect safety information may have solicited characteristics.
The underlying methodology must therefore be documented.
25. Digital Platforms and Social Media
Digital channels create a particularly important source-classification challenge because the same platform may contain multiple kinds of information.
Examples include:
- an unsolicited patient post;
- a structured company programme;
- a public comment following a safety communication;
- a published scientific article;
- a discussion of a clinical trial;
- or a statement that contains no identifiable individual patient.
The organisation should avoid treating the platform itself as the source category.
The relevant question remains how the safety information arose.
26. Poison Control and Other Specialist Organisations
Reports can originate from specialist organisations such as poison control centres or regional pharmacovigilance centres.
These organisations may receive information from healthcare professionals, consumers or other sources and may then communicate it to an MAH or competent authority.
The MAH should preserve the source chain sufficiently to understand both the organisation that transmitted the information and, where available and relevant, the person who originally reported the facts.
27. Company Employees
Employees can be recipients of safety information even when their primary role is not pharmacovigilance.
A sales representative may hear a suspected adverse reaction. A medical-information specialist may receive a patient complaint. A regulatory colleague may receive a safety-related authority communication.
The PV system should therefore be designed around where safety information can arise, not merely around the formal PV department.
Training and escalation arrangements should make these interfaces reliable.
28. Legal Claims and Litigation
Safety information can arise in legal proceedings.
GVP Module VI identifies reports arising from class-action litigation among situations that can be considered spontaneous reports. ๎cite๎turn0search17๎
The presence of legal context does not eliminate the need for ordinary ICSR validation. The organisation should assess whether the material contains information about an individual patient, a suspected reaction and a suspected medicinal product and whether an identifiable reporter is present according to the applicable framework.
29. Media and Press Reports
Press coverage can stimulate reporting and can itself contain safety information.
The organisation should distinguish between:
- an article that merely repeats an already known general safety concern;
- an article containing information about an identifiable individual patient;
- and a subsequent unsolicited report stimulated by the publication.
These can have different implications for ICSR processing.
30. Source Hierarchy Is Not Evidence Hierarchy
A common mistake is to assume that one source category is inherently more credible than another.
A physician report may contain limited information. A consumer report may contain detailed chronology. A clinical study may contain highly structured data but still require clinical interpretation.
The organisation should assess the information itself, the identity and role of the source, the context in which it was generated and the available supporting evidence.
31. Source Changes During the Case Lifecycle
The source context can become clearer during follow-up.
For example, a case initially received as a spontaneous consumer report may later be found to originate from a patient enrolled in a structured programme. The case should then be reassessed according to the applicable source rules.
Likewise, a literature case initially appearing spontaneous may be identified as study-derived after the full publication is reviewed.
Source classification should therefore be treated as a controlled data element that can be corrected when new evidence changes the assessment.
32. Source and Duplicate Management
The same underlying case can appear through multiple sources.
For example:
Patient report
โ
MAH
Physician report
โ
Competent authority
Published case report
โ
Literature monitoring
These may all describe the same patient and event.
The organisation therefore needs source information to support duplicate detection rather than treating every source as an independent case.
The dedicated duplicate-management articles in the repository address this in greater depth. ๎cite๎turn218file1๎turn218file2๎
33. Source Classification and Data Standards
Source classification should be represented consistently in the safety database and electronic reporting process.
The organisation should define how source categories map to the relevant ICSR data elements and how multiple sources are represented.
The objective is not merely standardisation for its own sake. Consistent source data support:
- regulatory reporting;
- reconciliation;
- duplicate detection;
- aggregate analysis;
- signal detection;
- and inspection traceability.
34. Source-Control Questions for the PV System
For each major intake channel, the organisation should be able to answer:
- Can safety information arrive here?
- Who is responsible for recognising it?
- What constitutes the awareness date?
- How is the information transferred to PV?
- How is source classification determined?
- How are duplicates identified?
- What reporting pathway applies?
- How is the transfer monitored?
- What happens when the process fails?
- Can the complete pathway be demonstrated during an inspection?
These questions turn the abstract concept of "sources" into a practical PV-system control.
35. Difficult Scenario: Same Event, Two Channels
A patient reports an adverse reaction directly to the MAH. Two weeks later, a physician sends a report describing the same patient and event to the competent authority, which forwards it to the MAH.
The second communication should not automatically become a second case.
The organisation should compare the information and determine whether it represents a duplicate, follow-up information or a genuinely different case.
The source fields should preserve the relevant reporting pathways.
36. Difficult Scenario: Patient Support Programme With a Voluntary Report
A patient enrolled in a patient support programme volunteers that they experienced nausea.
The statement may feel spontaneous because the patient volunteered it without being directly asked about nausea.
That observation alone does not determine the source classification. The organisation must examine the structure of the programme and whether the information was collected within an organised data-collection system.
The distinction is between the patient's manner of describing the event and the context in which the information was collected.
37. Difficult Scenario: Study Publication Identified by MLM
A weekly literature search identifies a publication describing an adverse reaction in a patient who participated in a clinical study.
The MAH should not automatically classify the case as a spontaneous literature case merely because MLM identified the publication.
The underlying study context should be assessed. The source of discovery and the underlying origin of the safety information are related but distinct concepts.
This is one reason literature cases require careful review of the full publication.
38. Difficult Scenario: Sales Representative Receives a Report
A sales representative receives a telephone call from a physician describing a suspected adverse reaction.
The report has not yet reached the PV department.
The fact that the recipient is a commercial employee does not remove the information from the pharmacovigilance system. The organisation needs an established mechanism by which safety information received by non-PV personnel is recognised and transferred.
A system that works only after information reaches PV is incomplete if information can be lost before that point.
39. Difficult Scenario: Medical Information Enquiry
A patient contacts medical information asking whether dizziness is a known adverse reaction. During the conversation, the patient describes experiencing dizziness after taking the medicinal product.
The organisation should assess whether the communication contains an individual suspected adverse reaction and whether it meets the applicable validation criteria.
It should not be classified merely as a routine information enquiry because the original reason for contact was a product question.
40. Difficult Scenario: Social-Media Post
A public post states:
"I started Product X last month and have been vomiting every day."
The organisation must consider the applicable rules for internet and digital-media reports, including whether the information can be associated with an identifiable patient and reporter and whether the content meets the minimum criteria.
The platform name does not determine the classification.
41. Difficult Scenario: Safety Communication Followed by a Report
An MAH issues a safety communication and a physician subsequently contacts the company to report a suspected adverse reaction.
The report may still be spontaneous. GVP Module VI expressly recognises certain stimulated reporting following direct healthcare-professional communication and other safety communications as spontaneous reporting. ๎cite๎turn0search17๎
The fact that the communication stimulated the report should not be confused with participation in an organised data-collection system.
42. Difficult Scenario: Regulatory Authority Case
A competent authority forwards an ICSR to the MAH.
The MAH should establish whether the report is:
- new;
- a duplicate;
- follow-up information;
- or another type of communication.
The authority's transmission is the source pathway, but the original primary source may be a healthcare professional or consumer.
Both dimensions can be important and should not be collapsed into a single generic "authority" label.
43. Difficult Scenario: Partner Receives the Case Late
A business partner receives a serious report and transfers it to the MAH several days later.
The organisation should investigate the delay rather than simply resetting the process at the moment the central PV team receives the case.
The relevant awareness-date rules and contractual interfaces should be assessed, and the organisation should determine whether other cases could have been affected.
This is an inspection issue because source interfaces are part of the PV system.
44. Difficult Scenario: The Source Is Unclear
A report arrives through an anonymous web form containing information about an individual patient and suspected adverse reaction but no reliable indication of how the person obtained the product.
The organisation should not invent a source category.
The available facts should be recorded, the applicable validation criteria assessed and, where useful, reasonable attempts made to clarify the source.
Unknown information should remain unknown rather than being converted into an unsupported database value.
45. Source Classification and Day 0
Source type can interact with the determination of the reporting clock.
This is particularly important for specialised sources such as literature monitoring, where EMA has published specific clarification of Day 0. For valid ICSRs identified through the weekly reference-database literature search, Day 0 is the date on which the search was conducted; other mandatory literature-monitoring activities have specific rules based on when sufficient information is identified. ๎cite๎turn0search1๎
The general principle is that organisations should not use a generic "date entered into the safety database" rule when the applicable regulatory framework establishes another relevant date.
46. Source Classification and Follow-Up
Different source types can require different follow-up strategies.
For a spontaneous physician report, the physician may be the most useful follow-up source.
For a patient support programme, the programme structure and designated contacts may be relevant.
For a literature case, follow-up may involve the publication authors or the underlying study team where appropriate.
For a regulatory-authority case, the authority may be an important source of clarification.
The source therefore informs not only classification but also the practical route for obtaining additional information.
47. Source Classification and Data Interpretation
Aggregate analyses should preserve sufficient source information to allow analysts to understand the composition of the safety database.
For example, a sudden increase in reports may reflect:
- a genuine increase in reporting;
- a new patient support programme;
- a regulatory request;
- a literature-monitoring change;
- a safety communication;
- or a partner-system migration.
Without reliable source classification, changes in reporting volume can be difficult to interpret.
48. Source Classification and Signal Detection
Signal detection also depends on understanding where reports originate.
A cluster generated by an organised programme may have different reporting characteristics from a spontaneous-reporting population.
This does not make one source intrinsically less useful, but it can affect interpretation of reporting frequencies and potential reporting biases.
Signal-management teams should therefore be able to understand important source characteristics in the underlying cases.
49. Inspection Perspective: Can You Reconstruct the Source Pathway?
An inspector may select an ICSR and ask:
Where did this information actually originate?
A strong system should allow the organisation to reconstruct:
Original source
โ
Person / organisation receiving information
โ
Date and time of awareness
โ
Transfer to PV
โ
Source classification
โ
Validation
โ
Case creation
โ
Submission / follow-up
If the organisation can show only the final database record, it may be difficult to demonstrate that the intake process itself was controlled.
50. Inspection Perspective: Testing Interfaces
A robust inspection exercise should not sample only cases already sitting in the central safety database.
Inspectors may examine interfaces where safety information can originate, such as:
- medical information;
- sales and field functions;
- affiliates;
- partners;
- patient programmes;
- literature monitoring;
- digital channels;
- clinical-development functions;
- and regulatory affairs.
The objective is to determine whether potential cases can enter the PV system reliably.
51. Inspection Perspective: Procedure Versus Actual Flow
A procedure may state that all adverse-event information is transferred to PV within a defined period.
The stronger evidence is the actual transaction history showing that the process works.
Inspection testing should therefore compare:
- the written procedure;
- training records;
- agreements;
- system workflows;
- actual case samples;
- deviations;
- reconciliations;
- and quality metrics.
A procedure is evidence of intended design. Case history and process records demonstrate implementation.
52. Common Failure Modes
Failure 1: Treating every report as spontaneous
This can misclassify organised data-collection systems and distort downstream analysis.
Failure 2: Treating every unsolicited communication as a solicited report
This can incorrectly classify ordinary stimulated or spontaneous reporting.
Failure 3: Confusing source with primary reporter
The person transmitting the case and the person who originally reported the facts may be different.
Failure 4: Losing the original awareness date
This can create reporting-timeline risk.
Failure 5: Relying on the PV mailbox as the only intake control
Safety information can arise elsewhere in the organisation.
Failure 6: Treating the platform as the source category
A social-media platform, mailbox or database is a channel; it does not necessarily define the regulatory origin of the information.
Failure 7: Automatically classifying literature cases as spontaneous
The underlying publication may describe a study or other organised system.
Failure 8: Treating source classification as permanent
New information may require reassessment.
53. Practical Source-Control Checklist
A mature PV system should be able to demonstrate:
- a mapped inventory of safety-information entry points;
- defined ownership for each entry point;
- training appropriate to the function receiving safety information;
- controlled transfer into pharmacovigilance;
- preservation of relevant awareness dates;
- source classification rules;
- primary-source identification;
- handling of multiple primary sources;
- duplicate controls across sources;
- source-specific reporting rules;
- reconciliation of important interfaces;
- documented escalation for failures;
- quality metrics that identify source-interface problems;
- and inspection-ready evidence showing that the process works in practice.
54. Relationship With the Other Module VI Articles
G3 provides the source framework. It should therefore serve as the entry point to the dedicated source-specific articles rather than reproduce them.
- G14 addresses difficult validity and assessment scenarios.
- G15 addresses patient support programmes and solicited reports. ๎cite๎turn208file0๎
- G16 addresses clinical trials and ICSR management. ๎cite๎turn214file1๎
- G17 addresses Medical Literature Monitoring and literature ICSRs. ๎cite๎turn214file4๎
- G18 addresses other organised data-collection systems and solicited sources. ๎cite๎turn206file1๎
- G19 addresses follow-up after a case has entered the PV process. ๎cite๎turn215file0๎
This hub-and-spoke structure prevents G3 from becoming a second copy of the detailed specialist articles.
55. Key Takeaways
- ICSR source classification is a substantive pharmacovigilance activity, not merely a database field.
- GVP Module VI distinguishes unsolicited and solicited sources and defines spontaneous reporting within that framework. ๎cite๎turn0search17๎
- A spontaneous report is not limited to healthcare professionals; consumers can provide spontaneous reports.
- Solicited does not mean unimportant or automatically non-reportable.
- The source of a report and the primary source are different concepts.
- Multiple primary sources may need to be represented in the ICSR.
- Stimulated reporting can remain spontaneous when it does not arise from an organised data-collection system. ๎cite๎turn0search17๎
- Medical information, sales, affiliates, partners, digital channels and other functions can be safety-information entry points.
- Literature discovery does not automatically make the underlying case spontaneous; the underlying origin must be assessed.
- Clinical-trial and organised-system information must be considered in its appropriate regulatory context.
- Source classification should be reassessed when new information changes the understanding of the case.
- Source information supports duplicate detection, aggregate interpretation and signal detection.
- Inspection readiness requires the organisation to demonstrate the complete source-to-PV pathway, not merely the final database record.
References
- European Medicines Agency. Good Pharmacovigilance Practices (GVP), Module VI โ Collection, management and submission of reports of suspected adverse reactions to medicinal products, Rev. 2. The current EMA GVP index identifies Module VI Rev. 2 as the applicable adopted module and records its legal effective date as 22 November 2017. ๎cite๎turn0search0๎
- European Medicines Agency. GVP Module VI, Section VI.B.1 โ Collection of individual safety reports; unsolicited and solicited sources; spontaneous reports. ๎cite๎turn0search17๎
- European Medicines Agency. GVP Module VI, definitions concerning primary sources, healthcare professionals and consumers. ๎cite๎turn0search16๎
- International Council for Harmonisation. ICH E2D(R1), Post-Approval Safety Data: Definitions and Standards for Management and Reporting of Individual Case Safety Reports.
- European Medicines Agency. Medical literature monitoring and Day 0 Q&A. ๎cite๎turn0search1๎
- European Medicines Agency. EudraVigilance electronic reporting guidance and relevant reporting pathways. ๎cite๎turn0search4๎
- European Medicines Agency. Pharmacovigilance inspection coordination and related inspection guidance. ๎cite๎turn0search1๎
Regulatory Note
This article is an educational interpretation of the source framework for individual case safety reports. It does not replace current EU legislation, GVP Module VI, ICH E2D(R1), EudraVigilance technical documentation, applicable national requirements or an organisation's approved procedures.
Source classification should be based on the circumstances of the individual report. Where a source category is uncertain, the organisation should document the assessment and apply the current applicable regulatory guidance rather than infer a classification from the communication channel alone.
The practical scenarios in this article are illustrative. They are not presented as actual regulatory inspection cases unless a specific authoritative source is identified.