Pharmacovigilance Audits

A comprehensive guide to pharmacovigilance audits, audit planning, governance, oversight and continuous improvement.

Audio Lesson 12 min

Pharmacovigilance Audits

Introduction

Pharmacovigilance systems exist to protect patients.

To achieve this objective, organisations establish:

However, a fundamental question remains:

How does an organisation know whether those controls are actually working?

Pharmacovigilance audits help answer that question.

Audits provide structured, independent assessment of whether pharmacovigilance activities are operating effectively and in accordance with regulatory expectations.

For mature organisations, audits are not merely compliance activities.

They are essential governance tools.

Well-designed audit programmes provide visibility regarding:

As pharmacovigilance systems become increasingly complex, the importance of auditing continues to grow.

What Is a Pharmacovigilance Audit?

A pharmacovigilance audit is a systematic, independent and documented assessment of pharmacovigilance activities.

The purpose of the audit is to determine whether:

Several characteristics distinguish auditing from routine operational review.

A useful way to think about audits is:

Audits provide assurance regarding the effectiveness of the pharmacovigilance system.

Audits Versus Inspections

Although related, audits and inspections are fundamentally different activities.

A simple distinction is:

Activity Conducted By Purpose
Audit Organisation Assurance and improvement
Inspection Regulator Compliance assessment

Inspectors frequently review audit programmes and outcomes to evaluate whether an organisation learns from its own assessments. Strong audit programmes therefore improve inspection readiness; however, audits should not exist solely to prepare for inspections.

Why Audits Exist and Their Purpose

Every system contains risk. Audits identify issues before they result in significant consequences (compliance failures, patient safety incidents, inspection observations) and transform findings into organisational learning. Beyond identification, audits provide assurance that processes are appropriately designed, performed and controlled.

The Pharmacovigilance Audit Universe

Auditable areas commonly include:

The audit universe provides the foundation for risk-based planning.

Risk-Based Audit Planning

Risk-based planning recognises that not every activity creates equal risk. Audit resources should be allocated proportionally to regulatory impact, patient safety potential, system complexity, dependency and historical performance. A documented risk assessment methodology, including criteria and weighting, is required to justify audit scope and frequency.

Audit Programmes and Multi-Year Planning

An audit programme defines how audit activities are organised over time and typically includes objectives, an auditable universe, risk assessment methods, schedules and governance arrangements. Multi-year cycles (commonly three years) support balanced coverage, allow for repeat and follow-up audits, and accommodate emerging risks.

Internal, Vendor and Affiliate Audits

Internal audits provide visibility and drive improvement. Vendor audits assess outsourced activities and vendor quality systems to ensure adequate control. Affiliate audits verify that local pharmacovigilance activities align with global expectations and local regulatory requirements. All audit types require documented agreements, clear escalation pathways and evidence that CAPAs are effective.

Findings, Root Cause and CAPAs

Findings should be classified consistently (e.g., critical/major/minor/observation) and accompanied by root cause analysis. CAPAs must address underlying causes, be measurable, have defined owners, timelines and include effectiveness verification. Without effective verification, CAPAs may create a false sense of compliance.

Audit programmes should be measured using KPIs such as coverage, timeliness, open/overdue findings, repeat findings and CAPA effectiveness. Trend analysis reveals systemic issues more reliably than isolated observations. Audits are a primary source of assurance for the QPPV, who should have visibility of significant findings and remediation progress.

Inspection Perspective

Inspectors expect audit programmes to be risk-based, independent, integrated into governance and demonstrably effective. Evidence inspectors commonly request includes the audit charter, multi-year schedules, individual audit reports, CAPA records, effectiveness verification documentation and management meeting minutes reflecting audit outcomes.


Practical Implementation: Making Your Audit Programme Inspection-Ready

This section provides actionable artefacts and templates you can adopt or adapt to implement an inspection-ready pharmacovigilance audit programme. Included are an Audit Charter, a sample multi-year audit schedule, audit plan and audit report templates, checklists for common audit types, CAPA and effectiveness verification templates, an audit evidence matrix, governance arrangements and notes on inspection relevance.

These materials are written to align with regulatory expectations in ICH and EU GVP (Modules I, II, III, IV) and international guidance such as ICH Q9 and national pharmacovigilance inspection frameworks. Organisations should map all templates to local regulations (e.g., FDA, UK MHRA, EMA) and product-specific commitments as needed.

Audit Charter (Template)

Purpose - Establish the authority, scope and responsibilities of the pharmacovigilance audit function. - Ensure audits provide independent, objective assurance to senior management and the QPPV.

Scope - Internal pharmacovigilance activities, vendor and affiliate operations, systems and quality processes described in the audit universe.

Authority - Auditors report administratively to the Head of Quality/Independent Audit Office and functionally to the QPPV and audit steering body. - Right to access records, staff, systems, premises (subject to confidentiality and data protection).

Independence and Objectivity - Audit personnel must be independent of audited activities. Where independence cannot be absolute (small organisations), record mitigating controls (rotational staffing, external subject matter experts (SMEs), third-party reviews).

Responsibilities - Audit team: plan and execute audits, issue reports, follow-up on CAPAs. - Audited functions: cooperate, provide evidence, accept constructive findings, implement CAPAs. - Audit steering committee: approve multi-year plan, prioritise audits, review significant findings and resourcing. - QPPV: receive reports of critical/major findings, ensure appropriate escalation and regulatory notifications where required.

Audit Methodology - Risk-based planning process (documented scoring criteria). - Audit execution standards (sampling, evidence collection, interview techniques). - Report writing standards, finding classification, root cause expectations, CAPA quality criteria and effectiveness verification approach.

Confidentiality and Data Protection - Handling of personal data (ICSRs) follows applicable privacy laws; redaction of patient identifiers in audit working papers as required.

Resourcing and Competency - Minimum competence requirements for auditors (pharmacovigilance experience, audit training, regulatory knowledge). - Use of external auditors for specialized areas (GCP interface, IT validation).

Reporting and Escalation - Report distribution list (auditee, QPPV, Head of PV, Head of Quality, Legal as required). - Criteria for immediate escalation (e.g., critical finding, patient safety risk, significant reporting failure).

Review and Charter Revision - Charter reviewed at least annually and after significant organisational change.

Inspection Relevance - Inspectors commonly request the audit charter to confirm independence, authority and governance. Ensure version-controlled charter is available and signed by senior management.


Sample Multi-Year Audit Schedule (3-Year Example)

Notes: - Frequency: A = Annual; B = Biennial; 3Y = Every 3 years; F = Follow-up as required. - Prioritisation should be risk-weighted and justified in the audit programme.

Auditable Area Year 1 Year 2 Year 3 Frequency
ICSR Case Processing (Global) A A A Annual
PSMF Review & Update A Annual
Signal Management Process A Biennial
Aggregate Reports (PBRERs/PSURs) A (sample) A Annual/3Y (rotating by product)
Vendor: Case Processing Center A F A Annual + follow-up
Vendor: Safety Database Provider A Biennial
Affiliate Pharmacovigilance Compliance (regional rotation) Region 1 Region 2 Region 3 Rotating annual
Quality Systems (Training, Deviations, CAPA) A A A Annual
IT / PV System Validation & Change Control A A 3-year cycle for full review; annual spot-checks
Risk Management Plan Implementation A Biennial
Pharmacovigilance Governance and Management Review A A A Annual
Clinical trials interface / safety reporting A (if active trials) A Annual/3Y depending on portfolio
Literature Surveillance & Signal Detection Tools A Biennial

Audit schedules should be accompanied by a documented risk assessment and rationale for allocation of audit frequency to each area. Audit planning must also account for regulatory commitments, inspection history and product lifecycle changes (e.g., new launch, safety signal).

Inspection Relevance - Provide inspectors a multi-year schedule showing coverage and rationale. Inspectors will cross-reference schedule with completed audits and open/closed CAPAs.


Audit Plan Template (Use for each individual audit)

Header - Audit title - Audit reference number - Date of plan - Audit lead and team - Auditee and contact(s) - Audit type: Internal / Vendor / Affiliate / Remote / On-site - Related regulatory references and GVP modules - PSMF section(s) referenced (if applicable)

Audit Objective - Clear statement (e.g., "Assess the adequacy and effectiveness of ICSR intake and processing for product X in accordance with SOPs, GVP and local regulations").

Scope - Processes, products, sites, time period, systems and documents in scope. - Boundaries and exclusions.

Audit Criteria - SOPs, regulations, contractual obligations, MAH responsibilities, industry guidance.

Methodology - Sampling approach (e.g., random stratified, judgmental, full 100% review for high risk). - Number of ICSRs to review and selection rationale (e.g., 30 consecutive cases per country). - Documents to review (SOPs, logs, PSMF, training records, database reports). - Interviews planned (roles and number). - Evidence collection methods (screenshots, system extracts, signed copies).

Key Audit Areas / Checklist Items - List of focus areas mapped to risk (e.g., case intake timeliness, seriousness assessment, expectedness and causality, expedited reporting timeliness, reconciliation with clinical safety team).

Logistics and Timeline - Start and end dates, opening meeting, fieldwork days, closing meeting. - Access and pre-read requirements (e.g., provide sample cases, SOP list, metrics 5 days prior).

Deliverables - Draft report publication timeline (e.g., draft report within 10 working days of closing meeting). - Final report issuance (e.g., within 20 working days after management response). - CAPA submission and tracking requirements.

Confidentiality and Data Protection - Handling of PHI, anonymisation requirements.

Escalation Criteria - Describe when immediate escalation to QPPV is required.

Approval - Audit lead signature and date - Audit steering committee approval line (if required)

Inspection Relevance - Audit plans should reference regulatory criteria (e.g., GVP Module IV) and be version controlled. Inspectors often expect to see audit plans in relation to executed audits.

Sample Audit Plan Excerpt (Case Processing) - Objective: Evaluate 30 ICSRs processed between 01‑01‑2025 and 31‑03‑2025 for timeliness and completeness. - Criteria: SOPs PV‑001, GVP Module VI, local MAH reporting timelines. - Method: Random selection of 30 ICSRs stratified by seriousness and reporter type; review of database entries, source documents and submission receipts; interviews with case processors and team lead.


Audit Report Template (Structure and Guidance)

Title Page - Audit title, reference, date of report, audit lead, auditee and distribution list.

Executive Summary - Brief statement of purpose, scope, key findings (high level), overall audit conclusion and recommended priority actions.

Background - Context for the audit (reason, previous related audits, regulatory triggers).

Scope and Objectives - Restate scope, criteria and period covered.

Methodology - Sampling details, documents reviewed, interviews, any limitations (e.g., access restrictions, incomplete data).

Findings Summary Table (High-Level) - Tabular summary showing number of findings by classification (Critical / Major / Minor / Observation).

Detailed Findings Section For each finding provide: - Finding ID - Title (concise) - Description (evidence-based, include references to SOPs/regulations/records) - Classification (with justification) - Impact (patient safety, regulatory, business) - Root Cause (analysis) - Proposed Corrective and Preventive Action(s) (owner, due date) - Priority (High / Medium / Low) - Evidence of immediate mitigation (if any) - References (documents, screenshots, case IDs)

CAPA Acceptance and Response - Auditee management response to findings, acceptance of proposed CAPAs, commitments and timelines.

Follow-up and Effectiveness Verification Plan - How and when effectiveness will be verified (e.g., re-audit, metrics review), success criteria.

Conclusions and Recommendations - Overall statement of system effectiveness and recommendations for governance, resourcing or structural changes.

Attachments - Audit checklist, working papers index, list of documents reviewed, interview list, evidence extracts (redacted as necessary).

Distribution and Closure - Report approval signatures, distribution list, planned follow-up date.

Inspection Relevance - Inspectors frequently inspect the trail from findings to CAPA closure and effectiveness verification. Maintain direct links between findings, CAPA registration, evidence of implementation and effectiveness review.


Practical Checklists (Selected, Adaptable)

Use these as starting points; tailor to organisation, product and local law.

Checklist: ICSR Case Processing (Key Items) - Intake: Are all intake channels documented and monitored? - Triage: Is seriousness, expectedness and causality assessed per SOP? - Timeliness: Are reporting timelines met (ICSR receipt to SUSAR/CIOMS/Expedited reporting deadlines)? - Data Quality: Are required fields complete and source documents available? - Follow-up: Is follow-up documented and timelines met? - Transmission: Are transmissions to authorities/vendors documented and validated? - Reconciliation: Are database reconciliations performed (e.g., inbound eCRFs, clinical trials, vendor vs MAH)? - Training: Do staff have current training records for relevant SOPs? - Documentation: Are deviations/notifications logged and appropriately escalated? Inspection Note: Prepare redacted copies of sample ICSRs and submission receipts as evidence.

Checklist: Vendor Oversight - Contractual obligations: Are PV responsibilities clearly defined in the contract? - SLA metrics: Are KPIs defined, monitored and trended? - Audit history: Date of last vendor audit and open/closed findings. - Data flow: Is data transfer secure and validated? - Change control: Is vendor change control documented and impact assessed? - Escalation: Are governance and escalation paths documented? - Business continuity: Is continuity and disaster recovery adequate? Inspection Note: Inspectors will request the oversight plan, recent vendor audit report and CAPA evidence.

Checklist: Affiliate Pharmacovigilance - Local PV responsibilities: Are local reporting timelines and laws documented? - Training: Local training completion for staff involved in PV. - PSMF local sections: Are local PV activities captured and accessible? - Escalation: Are escalation routes to MAH and QPPV clear? - Record keeping: Are local case files retained and auditable? Inspection Note: Inspectors may verify local compliance with country-specific requirements; have local SOPs and evidence ready.

Checklist: PSMF and Governance - PSMF accuracy: Are listed sites, processes and contacts current? - Availability: Is the PSMF readily retrievable for inspection? - Management Review: Are PV management reviews documented and dated? - QPPV visibility: Are QPPV responsibilities and oversight activities documented? Inspection Note: The PSMF is a common inspection target; ensure change history and distribution records are current.

Checklist: Signal Management - Process: Is signal detection, validation and prioritisation defined and implemented? - Documentation: Are signal evaluation reports retained and dated? - Decision-making: Are multidisciplinary meetings documented with actions and timelines? - Metrics: Are signal detection KPIs monitored? Inspection Note: Provide representative signal files and outcomes.

Checklist: Safety Database / IT Systems - Validation: Is system validation in place (IQ/OQ/PQ) and archived? - Access control: Are user access logs and role-based permissions documented? - Change control: Are changes authorised and tested? - Data integrity: Are audit trails enabled and reviewed? Inspection Note: Inspectors often request validation documents, change logs and access reports.

Audit Evidence Matrix (Template) - Column headings: Evidence ID | Document Title | Owner | Date | Location (electronic folder/path) | Redacted copy on file? | Audit(s) referencing this evidence

Maintaining a searchable evidence matrix accelerates audit execution and inspection responses.


CAPA Tracking and Effectiveness Verification (Template & Guidance)

CAPA Record Fields - CAPA ID - Finding ID(s) linked - Root cause(s) - Corrective Action(s) - Preventive Action(s) - Owner(s) - Planned start date / due date - Implementation evidence (attachments) - Verification method (re-audit, trend metrics, records review) - Verification date - Verification outcome (effective / partially effective / ineffective) - Closure approval (name, title, date)

Effectiveness Verification Examples - Re-audit of process within defined timeframe (e.g., 3–6 months). - Statistical trend analysis (e.g., reduction in late reporting events by X%). - Process metric thresholds defined (e.g., ≄95% on-time reporting). - Documentary evidence (updated SOP, training records, minutes).

Inspection Relevance - Inspectors will check CAPA traceability: link from finding to action to evidence and verification. Ensure CAPA records are dated, owned and include objective verification criteria.


Governance, Oversight and Management Integration

Audit Governance Structure - Audit Steering Committee: Oversees multi-year plan, approves priorities, reviews significant findings and resource allocation. Include QPPV, Head of Quality, Head of PV, Head of Compliance, Legal as appropriate. - Operational Oversight: Day-to-day scheduling, auditor assignments, quality control of audit reports. - Management Review: Regular PV management reviews should include audit programme performance, open/overdue findings, CAPA effectiveness and trends.

Reporting Lines and QPPV Role - The QPPV must be informed of critical/major findings and hold assurance that CAPAs addressing patient safety and regulatory impact are implemented and effective. - Provide QPPV dashboard items: Critical findings, major CAPAs overdue >30 days, repeat findings and trend summaries.

Escalation Pathways - Define criteria for immediate escalation (e.g., critical patient safety risk, systemic failure in expedited reporting). - Specify escalation recipients and expected timelines for action.

Inspection Relevance - Inspectors expect audit outcomes to be integrated into management review and decision-making. Provide management meeting minutes that reference audit findings and demonstrate executive engagement.


Audit Programme Metrics and Reporting Dashboard (Suggested KPIs)

Include thresholds in governance documents and ensure metrics are reviewed quarterly.

Inspection Relevance - Inspectors may review KPIs to assess whether the audit function is effective and used for governance. Be prepared to justify thresholds and remedial actions for adverse trends.


Making Audit Records Inspection-Ready

Key considerations for record-keeping and inspection readiness:

Prepare an "inspection pack" for audit-related inspections including: - Audit charter (signed) - Multi-year audit schedule with completed audits highlighted - 3–5 most recent audit reports (internal and vendor) - CAPA register extract showing status and evidence - PSMF section on audits and quality system - Management review minutes referencing audit outcomes


Inspection Relevance: What Inspectors Commonly Look For

Inspectors will evaluate not only the existence of audit activities but their effectiveness and integration into governance. Commonly requested items include:

Ensure documentation demonstrates that audit findings lead to measurable improvement and that the QPPV receives sufficient assurance.


Implementation Checklist for Organisations (Quick Start)


Key Takeaways

References

  1. EMA Good Pharmacovigilance Practices (GVP) Module IV – Pharmacovigilance Audits.
  2. EMA Good Pharmacovigilance Practices (GVP) Module I – Pharmacovigilance Systems and Their Quality Systems.
  3. EMA Good Pharmacovigilance Practices (GVP) Module II – Pharmacovigilance System Master File.
  4. EMA Good Pharmacovigilance Practices (GVP) Module III – Pharmacovigilance Inspections.
  5. Regulation (EC) No 726/2004.
  6. Directive 2001/83/EC.
  7. Commission Implementing Regulation (EU) No 520/2012.
  8. ICH Q9 Quality Risk Management.
  9. ICH E2E Pharmacovigilance Planning.

Last reviewed: 2026-06-11