How Often Should a PSMF be Reviewed?

Regulations don't mandate a fixed PSMF review interval. Organisations should update the PSMF promptly after significant changes (QPPV appointment, deputy changes, vendors, safety database updates, restructures, inspection findings) and may perform formal periodic reviews (quarterly, semi‑annual or annual). Inspectors expect the PSMF to reflect actual practice; treat it as a continuously maintained living document.

Audio Lesson 9 min

The Pharmacovigilance System Master File (PSMF) should be maintained as a living document that accurately reflects the current pharmacovigilance system at all times.

There is No Universal Review Frequency

Regulations generally focus on ensuring that the PSMF remains accurate and current rather than prescribing a specific review interval.

Organisations should establish review processes that ensure significant changes are reflected promptly.

Events That Should Trigger a Review

Periodic Reviews

Many organisations perform formal quarterly, semi-annual or annual reviews of the PSMF to confirm continued accuracy.

These reviews often complement change-driven updates.

Inspection Perspective

Inspectors frequently compare the PSMF against actual practice. Discrepancies may indicate weaknesses in oversight, governance or document maintenance.

Practical Perspective

The best review frequency is one that ensures the PSMF always reflects reality. Effective organisations treat the PSMF as a continuously maintained management document rather than a periodic compliance exercise.

QPPV Oversight

A complete and inspection-ready PSMF must describe not just structures and processes, but also how the Qualified Person responsible for Pharmacovigilance (QPPV) is appointed, supported and overseen. QPPV oversight is central to PSMF accuracy, PV system performance and regulatory compliance. The sections below expand practical, regulatory and inspection-relevant detail on QPPV oversight and how it should be reflected in PSMF maintenance and review processes.

Regulatory Context

Roles and Responsibilities — What Oversight Means

QPPV oversight is more than a job title. It encompasses:

These responsibilities must be documented and demonstrable in the PSMF.

Practical Implementation — Building an Oversight Framework

Use a structured programme to make QPPV oversight operational and auditable:

  1. Governance and Authority
  2. Maintain a written PV governance charter or terms of reference that document the QPPV’s reporting line, decision-making authority, and escalation routes to senior management and regulatory affairs.
  3. Include a RACI (Responsible, Accountable, Consulted, Informed) matrix for key PV activities (case processing, aggregate reporting, signal management, audits, inspections) showing the QPPV’s accountabilities.

  4. Delegation and Deputies

  5. Keep a delegation log that records delegated tasks, names, limits of delegation, effective dates and revocation. Update the PSMF each time delegation changes.
  6. Deputies must be named with CVs, contact details and documented training/competence records. Include arrangements for 24/7 availability or on-call rotas where applicable.

  7. Availability and Contactability

  8. Document how the QPPV is continuously available (on-call rota, contact details, emergency escalation plan) and include evidence of availability testing (e.g., periodic contact checks, call logs).
  9. For multinational companies with remote affiliates, describe how the QPPV maintains oversight (regular meetings, access to case management systems, review of affiliate reports).

  10. Oversight of Third Parties

  11. Include vendor oversight processes in the PSMF: vendor qualification, PV obligations in contracts (MAH responsibilities retained), service level agreements, audit schedules and follow-up of CAPAs.
  12. Ensure the QPPV has documented means to access vendor systems and data necessary to meet regulatory obligations (case data, signal outputs, audit findings).

  13. Meetings, Reviews and Records

  14. Schedule regular governance meetings chaired by or attended by the QPPV (monthly PV operations review, quarterly PV compliance review, annual management review). Maintain minutes signed/approved by the QPPV and file them with PSMF evidence.
  15. Maintain a calendar of oversight activities (audits, training, system changes) that the QPPV uses to plan and evidence reviews.

  16. SOPs and Documentation

  17. Develop SOPs describing QPPV oversight processes: sign-off authorities, review of aggregate reports, oversight of clinical trial safety, handling of safety signals and PSUR/PBRER approval workflows.
  18. Store QPPV-relevant documents in the PSMF and ensure they are version controlled with review dates.

  19. Training and Competency

  20. Keep records of initial and ongoing training for the QPPV and deputies. Document competency assessments and development plans.
  21. Include evidence of training on regulatory changes, safety database updates and inspection readiness.

Oversight of Affiliates and Global Arrangements

Governance, Management and Escalation

Performance Monitoring and KPIs

Define and monitor KPIs that the QPPV uses to judge system performance. Useful KPIs include:

Include KPI dashboards, trend analyses and QPPV review sign-offs in the PSMF to demonstrate proactive oversight.

Inspection Relevance — What Inspectors Look For

Inspectors assess both the existence of the QPPV role and the effectiveness of oversight. Typical inspection expectations and evidence requests include:

Failure to demonstrate effective QPPV oversight is a common inspection finding and often triggers requests for corrective action plans.

Practical Evidence to Maintain in the PSMF

To make PSMF reviews efficient and inspection-ready, maintain the following items as living records:

Updating the PSMF in Response to QPPV Changes

Example Oversight Schedule (Practical Template)

Governance Discussion — Board and Executive Engagement

Inspection-Ready Checklist for the PSMF

This checklist is structured to be inspection-ready: each item is paired with the typical inspection question, the evidence to present, where to store it in the PSMF and practical presentation tips.

Practical notes for inspections - Pre-pack an inspection folder: a short "inspection pack" containing the PSMF index, version control sheet, QPPV appointment, delegation log, governance minutes and 3–5 key evidence items. Provide both electronic and printed forms as requested. - Cross-reference: Ensure every evidence item has a unique identifier and a cross-reference entry in the PSMF index so inspectors can quickly locate originals. - Redaction practice: For case examples, pre-redact personal data consistently with GDPR and local law; retain a clear mapping in a protected file (not in the pre-supplied pack) to reconstitute if required by regulator under secure conditions. - Access and confidentiality: Ensure the inspection team has the means to view restricted items under supervision; maintain audit logs of what was provided.

Sample PSMF Index (Inspection-Ready) — With Version Control and Evidence Retention

The sample index below follows GVP Module II structure and emphasises traceable evidence links, version control and retention requirements. Tailor to your company structure, portfolio size and jurisdictional needs.

  1. Cover page and PSMF administration
  2. 1.1 PSMF title, MAH name, site of responsible person
  3. 1.2 PSMF version history (see template below)
  4. 1.3 Master index (this section references every item below with unique evidence IDs)
  5. 1.4 Document control SOP
  6. Evidence examples: version history (EVID-0001), document control SOP (EVID-0002)
  7. Retention: Maintain version history indefinitely; SOPs retained for life of product + 5 years (or local requirement)

  8. Organisation and Governance

  9. 2.1 Organisational chart (PV function highlighted) (EVID-0101)
  10. 2.2 Governance charter / terms of reference (EVID-0102)
  11. 2.3 RACI matrix for key PV processes (EVID-0103)
  12. Retention: 5 years after change or product withdrawal; governance minutes retained 5 years (or per jurisdiction)

  13. Qualified Person responsible for Pharmacovigilance (QPPV)

  14. 3.1 QPPV appointment letter and contract (EVID-0201)
  15. 3.2 QPPV CV and declarations of interest (EVID-0202)
  16. 3.3 Deputies log and delegation records (EVID-0203)
  17. 3.4 Evidence of availability (on-call rota, call test logs) (EVID-0204)
  18. Retention: 5 years post-departure; appointment letters retained life of product + 5 years

  19. Pharmacovigilance System Description and SOPs

  20. 4.1 PSMF narrative describing the PV system (EVID-0301)
  21. 4.2 SOP index and current versions (EVID-0302)
  22. 4.3 Examples of SOP application (e.g., PSUR approval) (EVID-0303)
  23. Retention: SOPs retained for life of product + 5 years; application evidence 5–10 years depending on jurisdiction

  24. Systems and databases

  25. 5.1 Safety database details, supplier, validated status (EVID-0401)
  26. 5.2 System validation documentation and GxP compliance evidence (EVID-0402)
  27. 5.3 User access lists and change control records (EVID-0403)
  28. Retention: System validation life of system + 5 years; backup & archive retention per data policy/regulation

  29. Individual Case Safety Reports (ICSRs)

  30. 6.1 Case processing SOPs and flowcharts (EVID-0501)
  31. 6.2 Sample ICSR bundle(s) with cross-references (anonymised) (EVID-0502)
  32. 6.3 ICSR submission logs and gateway confirmations (EVID-0503)
  33. Retention: ICSRs retained in original format as per regulatory requirement (often life of product + X years; check local law—e.g., EU often minimum 10 years for PV records)

  34. Aggregate reporting and signal management

  35. 7.1 PSUR/PBRER process and archives (EVID-0601)
  36. 7.2 Signal management SOP and recent signal files (EVID-0602)
  37. 7.3 Risk management plans and safety communication examples (EVID-0603)
  38. Retention: 5–10 years after final report or product withdrawal as applicable

  39. Clinical trials and post-authorisation studies

  40. 8.1 Clinical safety oversight SOPs (EVID-0701)
  41. 8.2 Safety data flows from clinical systems to PV database (EVID-0702)
  42. 8.3 Investigator safety reports and SUSAR logs (EVID-0703)
  43. Retention: per clinical trial record policy and local regulations

  44. Vendor and supplier management

  45. 9.1 Vendor master list and PV responsibilities matrix (EVID-0801)
  46. 9.2 Contracts, SLAs and PV clauses (EVID-0802)
  47. 9.3 Recent vendor audit reports and CAPAs (EVID-0803)
  48. Retention: Contracts retained for contract lifecycle + 5 years (adjust per law); audit evidence retained until next audit + 5 years

  49. Inspections and audits

    • 10.1 Inspection history and responses (EVID-0901)
    • 10.2 Internal and vendor audit schedules/reports (EVID-0902)
    • 10.3 CAPA plans and closure evidence (EVID-0903)
    • Retention: Inspection records retained per regulator guidance (commonly life of product + 5 years)
  50. Training and personnel records

    • 11.1 Training matrix and records (EVID-1001)
    • 11.2 Competency assessments for QPPV and deputies (EVID-1002)
    • Retention: Personnel records per HR policy and local law (commonly 5–7 years)
  51. KPIs, management review and continuous improvement

    • 12.1 KPI dashboards and trend analyses (EVID-1101)
    • 12.2 Management review minutes and QPPV attestations (EVID-1102)
    • Retention: KPI records and management reviews retained for at least 5 years
  52. Backup, archive and evidence retention register

    • 13.1 IT backup and archiving policy for PV data (EVID-1201)
    • 13.2 Evidence retention register with retention periods and destruction authorisations (EVID-1202)
    • 13.3 Disaster recovery and continuity plans (EVID-1203)
    • Retention: Policy documents retained indefinitely; backups per retention schedule

Appendices - A. Glossary and abbreviations - B. List of marketing authorisations and products covered - C. Contact list for PV personnel and affiliates - D. Cross-reference table: PSMF sections vs. GVP Module II paragraphs

Version Control Template (Master Version History)

Maintain a master version history as both a front-matter PSMF page and a controlled record in the document management system. Example table columns and sample entry:

Operational rules for version control - Major changes: Increment major version (e.g., 3.1 → 4.0) when structure or governance materially changes. - Minor changes: Increment minor version (e.g., 3.1 → 3.2) for editorial updates, minor clarifications, CV updates. - Approval: Every new version must be approved by the QPPV (or acting QPPV) and recorded in the version history. - Audit trail: Keep the previous versions accessible in read-only archive for inspection. Do not overwrite historic files without preserving a copy.

Evidence Retention Register — Practical Template

The evidence retention register maps each evidence identifier (EVID-####) to retention rules, owner and location. Example rows:

Operational guidance - Map retention to legal minimums and internal business needs. Where law is silent, adopt conservative retention (life of product + minimum 5 years). - Ensure disposal authorisation is dual signatory (PV + Legal or Compliance). - Maintain a searchable register accessible to inspectors on request.

Implementation Steps — How to Make the PSMF Inspection-Ready in 30 Days

Day 1–7: Ownership and inventory - Appoint a PSMF owner (document control) and a small cross-functional team (PV operations, QPPV office, legal, IT). - Produce a master inventory of all PSMF items and current evidence identifiers.

Day 8–14: Version control and index - Create or update the master version history and lock a read-only archive of the previous version. - Build the PSMF index described above and assign evidence IDs.

Day 15–21: Evidence gathering and retention mapping - Populate evidence items for the top-priority inspection risks (QPPV appointment, delegation log, SOPs, vendor audits, recent inspection responses). - Complete the evidence retention register with owners and retention periods.

Day 22–28: Produce inspection pack and test - Assemble a short inspection pack: PSMF cover, version history, QPPV appointment, delegation log, governance minutes, 3–5 representative evidence files. - Conduct an internal mock inspection walkthrough with the QPPV and senior management to validate ease of retrieval and content completeness.

Day 29–30: Finalise access and controls - Ensure controlled access to master files, audit logging, backup and redaction protocols. - Publish the new PSMF version with QPPV signature and preserve archives.

Governance Considerations

Inspection Relevance — Distinctive Evidence and How Inspectors Use It

Inspectors look for coherence: the PSMF narrative must align with the evidence presented. Discrepancies commonly trigger follow-up requests. Be prepared to show: - That the PSMF is the "single source of truth" for PV governance: show the index, master version history and evidence cross-reference. - Live demonstration: Inspectors may request to see live KPIs, the safety database, or a demonstration of how the QPPV would access vendor data—have read-only access prepared and a named staff member to perform the demonstration. - Traceability: For any claim in the PSMF (e.g., "QPPV attended monthly governance meeting"), provide a minute with signature and a corresponding calendar entry.

Final Notes on Frequency, Oversight and Inspection Readiness

A PSMF that accurately documents QPPV oversight and contains an inspection-ready index, version control and evidence retention register significantly reduces inspection risk. Combine immediate updates for material changes with scheduled reviews that explicitly validate PSMF content. Maintain a controlled archive of prior versions and a searchable evidence register so that any assertion in the PSMF can be substantiated promptly during an inspection.

Last reviewed: June 2026

Last reviewed: 2026-06-07