GVP Module VII: PSUR Quality Control and Inspection Readiness
- GVP Module VII: PSUR Quality Control and Inspection Readiness
- Introduction
- 1. What PSUR Quality Control Means
- 2. Quality Is Built Into the Process
- 3. The PSUR Quality System and Module I
- 4. Scope Control
- 5. Regulatory Calendar Control
- 6. Data Completeness
- 7. Data Accuracy
- 8. Reproducibility
- 9. Scientific Quality Control
- 10. Cross-Process Reconciliation
- 11. Quality Control of Benefit-Risk Conclusions
- 12. Review Independence
- 13. Version Control
- 14. Regulatory Submission Control
- 15. Submission Deadline Versus Internal Deadline
- 16. Deviations and Late Submission Risk
- 17. Record Management
- 18. Inspection Readiness Is a Continuous State
- Key Takeaways
- References
- Regulatory Note
- 19. Quality Control of Case Data
- 20. Literature Data
- 21. Signal Management Interface
- 22. RMP Interface
- 23. Product Information Interface
- 24. Exposure Data
- 25. Benefit Information
- 26. Quality Control of Tables and Figures
- 27. Medical Terminology
- 28. Copy-Forward Controls
- 29. Previous Regulatory Requests
- 30. Quality Control of Regulatory Responses
- 31. Vendor-Generated Content
- 32. Cross-Functional Review
- 33. Management Review
- 34. QPPV Oversight
- 35. Inspection Question: Show Me the Data
- 36. Inspection Question: Why Did You Reach This Conclusion?
- 37. Inspection Question: What Changed Since the Last PSUR?
- 38. Inspection Question: What Did You Do With the Regulator's Conclusion?
- 39. Common Quality-System Failure Modes
- 40. CAPA and Effectiveness
- 41. Risk-Based QC
- 42. Inspection-Ready Evidence Matrix
- 43. A Practical Final QC Gate
- 44. Key Takeaways
- References
- Regulatory Note
- 45. Inspection Scenario: The PSUR Was Submitted on Time but Was Poor Quality
- 46. Inspection Scenario: The Number Cannot Be Reproduced
- 47. Inspection Scenario: The PSUR and Signal Process Disagree
- 48. Inspection Scenario: The RMP Was Not Updated After a PSUR Finding
- 49. Inspection Scenario: Regulatory Request Was Addressed Informally
- 50. Inspection Scenario: A Vendor Produced the Analysis
- 51. Inspection Scenario: A Previous CAPA Was Declared Effective
- 52. Inspection Scenario: Different Versions of the PSUR Exist
- 53. Inspection Scenario: The QPPV Only Signed the Final Document
- 54. PSUR Quality Metrics
- 55. Trend Analysis of Quality Findings
- 56. Management Escalation
- 57. Business Continuity
- 58. Data Integrity
- 59. Inspection Readiness Test
- 60. A Mature PSUR Control Model
- 61. Common Mistakes to Avoid
- 62. Practical Minimum Evidence Set
- 63. Final Inspection Checklist
- 64. Key Takeaways
- References
- Regulatory Note
Introduction
A PSUR is not only a scientific report. It is the output of a connected pharmacovigilance process involving case management, literature monitoring, signal management, risk management, benefit assessment, product-information maintenance, regulatory intelligence, data extraction, medical review, quality control and submission governance.
GVP Module VII therefore treats quality as a system-level responsibility rather than as a final editorial check.
The marketing authorisation holder should have structures and processes for the preparation, quality control, review and submission of PSURs, including follow-up during and after assessment. These arrangements should be documented within the pharmacovigilance quality system. ๎cite๎turn0search24๎
The practical objective is simple:
The organisation should be able to demonstrate that the PSUR is accurate, complete, scientifically defensible, submitted on time and supported by traceable evidence.
1. What PSUR Quality Control Means
PSUR quality control should address more than grammar, formatting and typographical errors.
At minimum, the quality system should provide confidence in:
- scope;
- data completeness;
- data accuracy;
- calculations;
- scientific assessment;
- benefit-risk conclusions;
- consistency with other PV processes;
- regulatory compliance;
- document integrity;
- and submission readiness.
A beautifully written PSUR can still be deficient if its source data are incomplete or its conclusions cannot be traced to evidence.
2. Quality Is Built Into the Process
The strongest PSUR controls operate throughout preparation rather than being concentrated at the end.
A useful model is:
Planning
โ
Data acquisition
โ
Data validation
โ
Scientific analysis
โ
Drafting
โ
Cross-functional review
โ
Quality control
โ
Final approval
โ
Submission
โ
Regulatory follow-up
Each stage should have defined responsibilities and appropriate records.
3. The PSUR Quality System and Module I
Module VII connects PSUR quality systems with the broader pharmacovigilance quality system described in GVP Module I.
The PSUR process should therefore not operate as an isolated specialist activity.
The organisation should have controlled interfaces with:
- ICSR processing;
- literature monitoring;
- signal management;
- risk management;
- PASS and other studies;
- medical information where relevant;
- product-information management;
- regulatory affairs;
- safety communications;
- vendor oversight;
- and management governance.
These interfaces should make responsibilities and information flows clear.
4. Scope Control
One of the first quality controls is confirming that the correct products and active substances are included.
Scope controls should consider, as applicable:
- active substance or combination;
- EURD entry;
- DLP;
- reporting interval;
- applicable indications;
- formulations and routes;
- relevant marketing authorisations;
- MAH changes;
- and special regulatory arrangements.
A scope error can propagate through the entire PSUR, affecting data retrieval, analysis, conclusions and submission.
5. Regulatory Calendar Control
The organisation should independently verify the applicable reporting and submission dates.
The current EMA PSUR page states that the EURD list is legally binding, overrides the standard reporting cycle and is updated regularly. The current EURD list was updated on 29 July 2026. ๎cite๎turn0search0๎turn0search7๎
Calendar control should therefore not depend on an old internal spreadsheet or an employee's memory.
A controlled process should identify:
- current DLP;
- legally applicable submission deadline;
- PSUSA procedure where relevant;
- internal milestones;
- responsible owners;
- and escalation points.
6. Data Completeness
A PSUR should incorporate relevant information from the available sources required by its structure and applicable circumstances.
The organisation should have a documented method for identifying and obtaining information from relevant PV processes.
Examples include:
- ICSRs;
- literature;
- clinical trials;
- PASS;
- signal-management activities;
- regulatory actions;
- product-information changes;
- exposure information;
- and benefit information.
The quality control process should verify that required inputs were considered and that unexplained gaps are identified.
7. Data Accuracy
Accuracy means that information presented in the PSUR corresponds to the underlying source data.
Module VII specifically describes source-data verification for summary tabulations against the MAH's safety database and expects documentation of the database retrieval parameters and quality control performed. ๎cite๎turn0search24๎
Practical controls can include:
- independent verification of counts;
- reproducible database queries;
- controlled extraction dates;
- parameter records;
- reconciliation with source systems;
- and documented resolution of discrepancies.
8. Reproducibility
A strong PSUR process allows another qualified person to understand how important numbers were produced.
For significant datasets, the organisation should be able to identify:
- source system;
- extraction date;
- extraction criteria;
- relevant filters;
- transformation steps;
- reviewer;
- quality-control result;
- and final value used in the PSUR.
This does not require every PSUR to contain technical database documentation. The underlying records should nevertheless exist within the quality system.
9. Scientific Quality Control
Scientific review should assess whether the interpretation is supported by the evidence.
Reviewers should challenge, where appropriate:
- unexplained trends;
- inconsistent conclusions;
- unsupported causal language;
- inappropriate comparisons;
- overlooked confounding;
- unexplained differences between datasets;
- and conclusions that do not reflect uncertainty.
A scientific review should therefore be more than proofreading.
10. Cross-Process Reconciliation
A PSUR should be consistent with the wider PV system, while recognising that different processes may use different definitions, time windows and decision points.
Useful reconciliation checks can include comparison with:
- signal-management records;
- RMP status;
- previous PSUR conclusions;
- regulatory actions;
- product-information changes;
- ongoing studies;
- and significant safety communications.
Apparent differences should be investigated and explained rather than mechanically forced into identical values.
11. Quality Control of Benefit-Risk Conclusions
The final benefit-risk conclusion requires particular scrutiny.
The reviewer should ask:
- Does the conclusion reflect the evidence presented?
- Are important risks adequately characterised?
- Are important benefits considered?
- Are relevant indications and populations addressed?
- Is uncertainty acknowledged?
- Are proposed actions proportionate to the evidence?
- Is the rationale for no action explicit where appropriate?
The conclusion should be traceable to the preceding scientific evaluation.
12. Review Independence
The organisation should define appropriate review responsibilities and independence within its quality system.
Not every section requires a separate independent author and reviewer, but significant scientific and compliance risks should receive appropriate challenge.
The reviewer should have sufficient expertise and sufficient separation from the original work to identify material errors.
13. Version Control
PSUR preparation frequently involves multiple drafts and multiple contributors.
Controlled document management should make it clear:
- which version was reviewed;
- which version was approved;
- who approved it;
- when approval occurred;
- and which version was submitted.
Uncontrolled local copies create a significant traceability risk.
14. Regulatory Submission Control
Submission should itself be a controlled process.
The organisation should verify:
- correct report;
- correct procedure;
- correct products;
- correct submission destination;
- required format;
- required supporting documents;
- and applicable deadline.
EMA's current procedural guidance confirms that PSUR format and content are legally required and that the legally binding submission deadline is established through the applicable EURD framework. ๎cite๎turn0search0๎
15. Submission Deadline Versus Internal Deadline
The regulatory deadline is not an appropriate internal target.
A mature process establishes internal deadlines sufficiently ahead of the legal deadline to provide time for:
- quality control;
- management review;
- correction of errors;
- technical validation;
- and submission problems.
The internal schedule should include contingency rather than assuming that every activity will occur exactly as planned.
16. Deviations and Late Submission Risk
Significant deviations from established PSUR preparation or submission procedures should be documented and appropriately managed.
Module VII specifically identifies non-submission and submission outside the correct schedule or timeframe as PSUR quality-system failure modes. It also expects significant deviations to be documented and appropriate corrective and preventive action to be taken. ๎cite๎turn0search24๎
The response should address both the immediate issue and the underlying process weakness where applicable.
17. Record Management
PSUR records should support reconstruction of the preparation and regulatory history.
Records can include:
- source-data extracts;
- reconciliation records;
- review comments;
- QC checklists;
- approvals;
- submission evidence;
- regulatory correspondence;
- assessment reports;
- and implementation records.
The objective is not to create unnecessary paperwork. It is to retain evidence proportionate to the significance of the activity.
18. Inspection Readiness Is a Continuous State
Inspection readiness should not begin when an inspection announcement arrives.
The organisation should maintain evidence continuously so that significant PSUR activities can be reconstructed without emergency document collection.
A useful test is:
Could an independent reviewer reconstruct why this PSUR contains these data, these conclusions and these actions?
If the answer is no, the process has a traceability weakness.
Key Takeaways
PSUR quality is a property of the underlying pharmacovigilance system, not merely the final document.
The strongest controls address scope, data completeness, data accuracy, scientific assessment, cross-process consistency, document control, submission and regulatory follow-up.
Inspection readiness follows naturally from good process control: the organisation retains enough evidence to reconstruct how information moved from source systems into the final scientific conclusion and regulatory action.
References
- European Medicines Agency. GVP Module VII โ Periodic Safety Update Report. ๎cite๎turn0search24๎
- European Medicines Agency. Periodic safety update reports (PSURs), including current preparation and assessment guidance. ๎cite๎turn0search0๎
- European Medicines Agency. GVP Module I โ Pharmacovigilance systems and their quality systems.
- European Commission. Commission Implementing Regulation (EU) No 520/2012, as amended.
- European Medicines Agency. EU reference dates (EURD) list and frequency of PSUR submission. ๎cite๎turn0search7๎
Regulatory Note
This article is an educational explanation of PSUR quality control and inspection readiness. It does not replace current EU legislation, GVP Module VII, GVP Module I, EMA procedural guidance, the current EURD list or an organisation's approved procedures.
Regulatory requirements and guidance may change. Before preparing or submitting a PSUR, the current applicable regulatory documents and procedural requirements should be verified.
Examples and inspection considerations are illustrative unless an authoritative source is specifically identified.
19. Quality Control of Case Data
The PSUR may depend on large volumes of individual case safety information. Quality control should therefore examine not only the final numbers but also the process by which the numbers were generated.
Important controls can include:
- confirmation of the reporting interval;
- appropriate case-selection criteria;
- reconciliation between source systems;
- duplicate handling;
- seriousness classification;
- medical terminology consistency;
- and confirmation that relevant cases have not been inadvertently excluded.
The precise controls should reflect the nature of the data and the organisation's procedures.
20. Literature Data
Literature information can affect both case counts and the scientific assessment.
Quality control should consider whether:
- the applicable literature-monitoring process was completed;
- relevant publications were identified;
- cases arising from literature were appropriately processed;
- duplicate publications were handled;
- and important literature findings were reflected in the safety evaluation.
The PSUR should not be treated as independent of the organisation's literature-monitoring system.
21. Signal Management Interface
The PSUR and signal-management processes should provide mutually intelligible safety information.
The organisation should be able to explain, for example, why:
- a signal under evaluation is discussed in the PSUR;
- a previously evaluated signal is no longer considered a significant concern;
- or an issue discussed in the PSUR has not been classified as a formal signal.
Different process terminology does not necessarily represent a contradiction. What matters is that the scientific reasoning is documented and coherent.
22. RMP Interface
The PSUR should also be reconciled with the current RMP where applicable.
Quality control should identify whether:
- important risks are consistently characterised;
- missing information remains aligned;
- ongoing pharmacovigilance activities are accurately described;
- additional risk minimisation remains appropriate;
- and new safety findings require RMP consideration.
A PSUR that identifies a major change in the safety profile without any documented consideration of RMP implications warrants additional review.
23. Product Information Interface
Product information can change during a PSUR reporting cycle.
The PSUR should therefore use the appropriate reference information and accurately describe relevant changes during the interval.
Quality control should verify, where applicable:
- version and effective date;
- affected indications or populations;
- relevant safety wording;
- regulatory status;
- and consistency with the safety assessment.
The objective is not simply textual matching. The organisation should understand why differences exist and whether they affect the interpretation of the safety profile.
24. Exposure Data
Exposure estimates can influence interpretation of event counts and reporting rates.
Quality control should consider:
- source of exposure data;
- methodology;
- assumptions;
- units;
- reporting period;
- product scope;
- and important limitations.
A precise-looking exposure estimate can still be misleading if the underlying assumptions are weak.
25. Benefit Information
PSUR quality control should not focus exclusively on safety.
Relevant benefit information should be considered where required to support the integrated benefit-risk evaluation.
Review should assess whether:
- important new benefit information was identified;
- relevant clinical evidence was considered;
- the benefit assessment is consistent with the product's indications;
- and the final benefit-risk conclusion appropriately integrates both sides of the assessment.
26. Quality Control of Tables and Figures
Tables and figures can contain transcription, calculation or labelling errors even when the underlying analysis is correct.
Controls should therefore verify:
- totals;
- denominators;
- percentages;
- units;
- dates;
- labels;
- footnotes;
- source references;
- and consistency between tables, figures and narrative text.
A table should be traceable to its underlying source data.
27. Medical Terminology
Consistent use of standardised medical terminology is an important quality consideration.
Where MedDRA or another controlled terminology is used, the organisation should ensure that the terminology version and coding approach are appropriate for the analysis.
A change in terminology can alter apparent trends and should therefore be understood when comparing data across reporting periods.
28. Copy-Forward Controls
PSUR preparation often uses material from previous reports.
Copy-forward can improve consistency but also creates a risk of carrying obsolete information into a new report.
Quality control should challenge:
- unchanged conclusions;
- old product information;
- outdated regulatory actions;
- closed studies described as ongoing;
- obsolete risk-minimisation measures;
- and statements that no longer reflect the current safety profile.
Every copied conclusion should remain valid for the new reporting interval.
29. Previous Regulatory Requests
Previous competent-authority requests should be tracked into subsequent PSURs where applicable.
The organisation should be able to identify:
- what was requested;
- the agreed response timing;
- what response was provided;
- whether the issue was fully addressed;
- and whether further follow-up was required.
Module VII specifically expects mechanisms to ensure that requests made during PSUR assessment are properly addressed. ๎cite๎turn0search24๎
30. Quality Control of Regulatory Responses
A regulatory response should undergo appropriate scientific and quality review before submission.
The reviewer should confirm that:
- the question has been understood correctly;
- the response directly answers it;
- supporting evidence is complete;
- numerical information is verified;
- conclusions are medically defensible;
- and commitments are clearly identified.
A technically complete response that does not address the regulator's actual concern is not an effective response.
31. Vendor-Generated Content
Some PSUR inputs may be generated or processed by vendors.
The MAH remains responsible for ensuring the quality of the information used in its PSUR.
Vendor oversight should therefore address:
- defined responsibilities;
- agreed specifications;
- data-transfer controls;
- quality checks;
- deviation management;
- escalation;
- and audit or oversight arrangements appropriate to the risk.
Outsourcing an activity does not outsource accountability for the quality of the final PSUR.
32. Cross-Functional Review
A PSUR commonly requires contributions from multiple functions.
Depending on the product and organisation, these may include:
- pharmacovigilance;
- medical;
- epidemiology;
- clinical development;
- regulatory affairs;
- statistics;
- risk management;
- quality assurance;
- and other specialist functions.
The quality system should define how conflicting comments are resolved and how final scientific accountability is established.
33. Management Review
Management review should focus on significant risks and decisions rather than merely approving the document.
Useful questions include:
- Are there material unresolved safety issues?
- Is the evidence sufficient for the proposed conclusion?
- Are major regulatory commitments understood?
- Are there resource or timing risks?
- Is the organisation prepared for possible regulatory questions?
The depth of management involvement should be proportionate to the significance of the PSUR.
34. QPPV Oversight
The QPPV has a specific role in ensuring that the pharmacovigilance system enables compliance with PSUR requirements.
Current GVP Module VII states that QPPV responsibilities include ensuring the necessary quality, correctness and completeness of PSUR data, ensuring full responses to authority requests within agreed timelines, and maintaining awareness of assessment conclusions and regulatory outcomes so appropriate action occurs. ๎cite๎turn0search25๎
This means QPPV oversight should extend beyond the final signature.
The QPPV should have appropriate assurance that the process is controlled from data generation through regulatory follow-up.
35. Inspection Question: Show Me the Data
An inspector may select a number from the PSUR and ask:
Where did this number come from?
A robust system should be able to move backwards through the evidence chain:
PSUR table
โ
Analysis dataset
โ
Extraction/query
โ
Source database
โ
Underlying records
The exact technical architecture may differ between organisations, but the principle of traceability remains.
36. Inspection Question: Why Did You Reach This Conclusion?
The inspector may then ask why the organisation reached a particular scientific conclusion.
The answer should not be merely:
"That was the medical reviewer's judgement."
The organisation should be able to identify the evidence, analytical reasoning, clinical context and relevant uncertainty that support the judgement.
Expert judgement is legitimate. Unexplained judgement is weak evidence.
37. Inspection Question: What Changed Since the Last PSUR?
An inspector may compare consecutive PSURs.
The organisation should be able to explain meaningful changes in:
- safety findings;
- exposure;
- benefit assessment;
- risk characterisation;
- RMP;
- product information;
- regulatory actions;
- and benefit-risk conclusions.
A completely unchanged report is not automatically wrong, but the organisation should be able to demonstrate that the current reporting interval was genuinely reassessed.
38. Inspection Question: What Did You Do With the Regulator's Conclusion?
The organisation should be able to show the chain from assessment outcome to implementation.
Evidence may include:
- impact assessment;
- action tracker;
- regulatory submissions;
- updated product information;
- RMP changes;
- communication records;
- and completion verification.
The final evidence should show not only that an action was assigned but that it was completed and appropriately verified.
39. Common Quality-System Failure Modes
Illustrative failures include:
- incorrect PSUR scope;
- missed regulatory deadlines;
- unexplained data discrepancies;
- incomplete source-data verification;
- unsupported scientific conclusions;
- outdated copy-forward text;
- unresolved previous regulatory requests;
- inadequate vendor oversight;
- inconsistent product information;
- and failure to document significant deviations.
These examples are not automatically regulatory findings. Their significance depends on the circumstances, impact and effectiveness of the overall quality system.
40. CAPA and Effectiveness
Where a significant PSUR quality failure occurs, CAPA should address the actual system weakness.
For example, if a deadline was missed because the internal calendar relied on an obsolete EURD list, simply reminding staff to check the calendar may not address the root cause.
An effective CAPA might instead require:
- controlled regulatory-source monitoring;
- defined ownership;
- change notification;
- independent calendar verification;
- and periodic effectiveness checks.
CAPA should therefore improve the system rather than merely document the event.
41. Risk-Based QC
Not every PSUR statement requires the same intensity of review.
A risk-based QC approach can give greater scrutiny to:
- major safety conclusions;
- important numerical analyses;
- regulatory commitments;
- benefit-risk conclusions;
- product-information proposals;
- and data elements known to be error-prone.
The organisation should nevertheless ensure that mandatory quality controls are consistently performed.
42. Inspection-Ready Evidence Matrix
A practical evidence matrix can link major PSUR components to their supporting records:
| PSUR element | Evidence that may support it |
|---|---|
| Scope | Regulatory assessment / EURD record |
| ICSR data | Safety database extraction and QC |
| Literature | Literature-monitoring records |
| Signals | Signal-management records |
| Exposure | Source data and methodology |
| Benefits | Clinical/benefit evidence |
| RMP | Current approved RMP and assessment |
| Product information | Controlled product-information versions |
| Regulatory actions | Authority correspondence and decisions |
| Benefit-risk conclusion | Scientific assessment and review records |
| Submission | Submission confirmation |
| Follow-up | Action and implementation records |
The exact evidence set should be adapted to the organisation and product.
43. A Practical Final QC Gate
Before final approval, the organisation can use a structured gate covering five dimensions:
Regulatory
- Correct scope?
- Correct DLP and deadline?
- Correct procedure and submission route?
Data
- Complete?
- Accurate?
- Reconciled?
- Traceable?
Science
- Adequate assessment?
- Important uncertainty addressed?
- Benefit-risk conclusion supported?
Governance
- Required reviews complete?
- QPPV oversight appropriate?
- Regulatory requests addressed?
Submission
- Correct final version?
- Correct supporting documents?
- Submission evidence retained?
44. Key Takeaways
Inspection readiness is the consequence of controlled PSUR preparation rather than a separate documentation exercise.
The organisation should be able to trace important information from its source, through analysis and scientific assessment, into the final PSUR and then into regulatory follow-up.
Quality control should challenge data, science, regulatory compliance and governance. It should not be reduced to proofreading.
The QPPV's role is system-level oversight: assurance that the pharmacovigilance system enables accurate, complete and timely PSUR preparation and that regulatory outcomes are appropriately acted upon. ๎cite๎turn0search25๎
References
- European Medicines Agency. GVP Module VII โ Periodic Safety Update Report. ๎cite๎turn0search24๎
- European Medicines Agency. Periodic safety update reports (PSURs). ๎cite๎turn0search0๎
- European Medicines Agency. GVP Module I โ Pharmacovigilance systems and their quality systems.
- European Commission. Commission Implementing Regulation (EU) No 520/2012, as amended.
- European Medicines Agency. EU reference dates (EURD) list. ๎cite๎turn0search7๎
- European Medicines Agency. PSUR/PSUSA procedural timetables. ๎cite๎turn0search1๎
Regulatory Note
This article is an educational explanation of PSUR quality control and inspection readiness. It does not replace current EU legislation, GVP Module VII, GVP Module I, EMA procedural guidance, the current EURD list or an organisation's approved procedures.
Regulatory requirements and guidance may change. Before preparing or submitting a PSUR, the current applicable regulatory documents and procedural requirements should be verified.
Examples and inspection considerations are illustrative unless an authoritative source is specifically identified.
45. Inspection Scenario: The PSUR Was Submitted on Time but Was Poor Quality
Timeliness does not compensate for inadequate scientific or data quality.
A PSUR can be submitted before the legal deadline and still have material deficiencies in:
- data completeness;
- analysis;
- scientific assessment;
- benefit-risk evaluation;
- or regulatory follow-up.
The quality system should therefore treat on-time submission and scientific quality as separate control objectives.
46. Inspection Scenario: The Number Cannot Be Reproduced
Suppose an inspector selects a table containing an important case count. The responsible team can identify the safety database but cannot reproduce the number because the original query parameters were not retained.
This creates a traceability weakness.
The organisation should retain sufficient information about significant data retrievals to allow reconstruction of the analysis.
The exact level of technical detail should be proportionate to the complexity and significance of the dataset.
47. Inspection Scenario: The PSUR and Signal Process Disagree
Suppose a signal-management record describes an issue as under active evaluation while the PSUR describes the issue as not requiring further assessment.
The difference may be scientifically justified, but the organisation should be able to explain it.
The review should examine:
- dates of assessment;
- evidence available to each process;
- definitions used;
- regulatory context;
- and the rationale for the different conclusions.
The goal is not forced consistency. It is coherent, documented scientific reasoning.
48. Inspection Scenario: The RMP Was Not Updated After a PSUR Finding
A PSUR can identify a change in the safety profile that requires consideration of the RMP.
Failure to assess that interface can indicate a fragmented PV system.
The organisation should demonstrate that the PSUR finding was evaluated against the current RMP and that the decision to update or not update the RMP was documented.
49. Inspection Scenario: Regulatory Request Was Addressed Informally
A regulator may request additional information during assessment.
If the response was prepared through informal email exchanges but the organisation cannot identify the final approved response, evidence reviewed or responsible approvers, there may be a governance weakness.
Regulatory correspondence should be brought into controlled processes with sufficient traceability.
50. Inspection Scenario: A Vendor Produced the Analysis
If a vendor produced a major PSUR analysis, an inspector may ask how the MAH assured itself that the analysis was correct.
The answer should include the defined specification, applicable controls, review and verification activities rather than simply stating that the vendor is qualified.
Vendor qualification does not replace ongoing quality control of delivered work.
51. Inspection Scenario: A Previous CAPA Was Declared Effective
If a previous PSUR quality deviation resulted in CAPA, an inspector may ask what evidence demonstrated effectiveness.
The organisation should be able to show an objective measure appropriate to the root cause.
For example, if the problem was incorrect scope determination, effectiveness should test whether the revised process consistently identifies the correct scope across subsequent reporting cycles.
A training attendance record alone may not demonstrate effectiveness.
52. Inspection Scenario: Different Versions of the PSUR Exist
Multiple uncontrolled drafts can create uncertainty about which report was actually approved and submitted.
A controlled document-management process should establish:
Draft
โ
Reviewed version
โ
Approved version
โ
Submitted version
โ
Regulatory outcome
The submitted version should be uniquely identifiable and retained with appropriate submission evidence.
53. Inspection Scenario: The QPPV Only Signed the Final Document
A signature demonstrates approval but does not by itself demonstrate effective oversight.
For significant PSURs, the QPPV should have appropriate visibility of:
- major safety issues;
- material uncertainties;
- important regulatory requests;
- significant benefit-risk conclusions;
- and consequential regulatory actions.
The precise mechanism of oversight can vary by organisation.
The important point is that the QPPV should have sufficient assurance that the PV system is functioning effectively.
54. PSUR Quality Metrics
Organisations may use metrics to monitor PSUR process performance.
Potential measures include:
- on-time submission rate;
- number of significant QC findings;
- number of data reconciliations requiring correction;
- regulatory questions received;
- responses delivered within agreed timelines;
- major deviations;
- overdue actions;
- and recurring quality defects.
Metrics should be interpreted carefully.
A low number of QC findings can mean excellent quality, but it can also mean ineffective QC.
55. Trend Analysis of Quality Findings
Repeated minor errors can reveal a significant systemic weakness.
For example, repeated transcription errors across several PSURs may indicate inadequate source-data controls even if each individual error is corrected before submission.
Quality management should therefore examine trends rather than treating every deviation as an isolated event.
56. Management Escalation
Significant PSUR risks should have defined escalation routes.
Potential escalation triggers include:
- risk of missing a regulatory deadline;
- major data uncertainty;
- unresolved scientific disagreement;
- significant safety findings;
- inability to obtain required information;
- serious vendor failure;
- or a potentially material submission error.
Escalation should occur early enough to permit meaningful corrective action.
57. Business Continuity
PSUR preparation is deadline-driven and can depend on specialist personnel and systems.
The quality system should therefore consider continuity arrangements for:
- key personnel absence;
- safety database availability;
- regulatory-system outages;
- vendor disruption;
- and loss of critical source information.
Continuity planning should protect both submission timelines and scientific quality.
58. Data Integrity
PSUR records should be maintained in a way that protects their integrity throughout preparation and retention.
Important principles include:
- attributable records;
- controlled changes;
- appropriate access controls;
- preservation of approved versions;
- and reliable retention of source documents.
The specific technical controls depend on the organisation's systems and quality framework.
59. Inspection Readiness Test
A useful periodic test is to select a completed PSUR and ask an independent reviewer to reconstruct it using only the controlled records.
The reviewer should be able to identify:
- why the PSUR was required;
- what scope was used;
- what data were collected;
- how important analyses were performed;
- who reviewed the scientific conclusions;
- what was submitted;
- what the regulator concluded;
- and what actions followed.
Any unexplained gap identifies an opportunity for improvement.
60. A Mature PSUR Control Model
A mature process can be summarised as:
REGULATORY CONTROL
โ
Correct obligation / scope / deadline
โ
DATA CONTROL
โ
Complete / accurate / reproducible data
โ
SCIENTIFIC CONTROL
โ
Critical assessment / benefit-risk
โ
GOVERNANCE CONTROL
โ
Review / QPPV oversight / escalation
โ
SUBMISSION CONTROL
โ
Correct version / route / evidence
โ
FOLLOW-UP CONTROL
โ
Assessment / action / implementation / effectiveness
This is the practical meaning of inspection readiness: each transition is controlled and supported by evidence.
61. Common Mistakes to Avoid
The following mistakes are particularly avoidable:
- relying on a manually maintained regulatory calendar without controlled verification;
- performing final QC too late to correct material issues;
- retaining final numbers without the underlying retrieval logic;
- copying previous PSUR conclusions without reassessment;
- treating vendor output as automatically reliable;
- failing to reconcile major differences with signal or RMP processes;
- retaining approvals but not the evidence supporting the approval;
- and assuming that a successful submission means the process was effective.
62. Practical Minimum Evidence Set
For a proportionate baseline, an organisation should be able to produce evidence of:
- applicable reporting obligation;
- scope determination;
- data sources and extraction;
- significant reconciliation/QC;
- scientific review;
- final approval;
- submission;
- regulatory correspondence;
- assessment outcome;
- and implementation of required actions.
Additional records should be retained where the complexity or risk of the PSUR warrants them.
63. Final Inspection Checklist
Regulatory
- Correct EURD and reporting obligation verified?
- DLP and deadline verified?
- Scope documented?
Data
- Source data complete?
- Key numbers reproducible?
- Reconciliations documented?
Scientific
- Important safety issues assessed?
- Benefit information considered?
- Benefit-risk conclusion supported?
Governance
- Appropriate reviewers involved?
- Regulatory requests addressed?
- QPPV oversight demonstrated?
- Deviations managed?
Document and submission
- Final version controlled?
- Submission evidence retained?
- Regulatory correspondence controlled?
Follow-up
- Assessment outcome recorded?
- Impact assessment completed?
- Actions implemented?
- Effectiveness evaluated where required?
64. Key Takeaways
The inspection-ready PSUR is not simply a high-quality PDF.
It is the visible endpoint of a controlled system that can demonstrate:
why the report was required โ what information was collected โ how it was verified โ how it was scientifically interpreted โ who approved it โ what was submitted โ what the regulator concluded โ what the organisation did afterwards.
This approach also makes continuous improvement possible. When a deviation occurs, the organisation can identify where the control chain failed and strengthen the relevant process rather than merely correcting the final document.
References
- European Medicines Agency. GVP Module VII โ Periodic Safety Update Report. ๎cite๎turn0search24๎
- European Medicines Agency. Periodic safety update reports (PSURs). ๎cite๎turn0search0๎
- European Medicines Agency. GVP Module I โ Pharmacovigilance systems and their quality systems.
- European Commission. Commission Implementing Regulation (EU) No 520/2012, as amended.
- European Medicines Agency. EU reference dates (EURD) list. ๎cite๎turn0search7๎
- European Medicines Agency. PSUR/PSUSA procedural timetables. ๎cite๎turn0search1๎
Regulatory Note
This article is an educational explanation of PSUR quality control and inspection readiness. It does not replace current EU legislation, GVP Module VII, GVP Module I, EMA procedural guidance, the current EURD list or an organisation's approved procedures.
Regulatory requirements and guidance may change. Before preparing or submitting a PSUR, the current applicable regulatory documents and procedural requirements should be verified.
Examples and inspection considerations are illustrative unless an authoritative source is specifically identified.