PSMF Annexes Guide
- PSMF Annexes Guide
- Introduction
- Why Annexes Exist
- The Real Purpose of Annexes
- Typical Annex Categories
- Annex Content and Inspection Relevance
- Annex Governance and Roles
- Version-Control Policy for PSMF Annexes (Operational)
- File Naming, Storage and Indexing (Practical)
- Inspection-Readiness Checklist (Operational and Annex-Specific)
- Standard Annex Templates: Minimum Required Fields
- Template: QPPV Annex (Minimum Fields)
- Template: Organisational Structure Annex (Minimum Fields)
- Template: Product Inventory Annex (Minimum Fields โ table format)
- Template: Vendor Inventory Annex (Minimum Fields โ table format)
- Template: Computerised System Annex (Minimum Fields โ table format)
- Template: Audit Programme Annex (Minimum Fields)
- Template: CAPA Annex (Minimum Fields โ table format)
- Template: Inspection History Annex (Minimum Fields โ table format)
- Evidence Linking and Traceability
- Practical Operational Practices
- Governance Discussion
- Inspection Relevance and How Inspectors Will Use Annexes
- What Great Annexes Look Like (Operational Summary)
- Key Takeaways
- References
Introduction
For many pharmacovigilance professionals, the annexes are the most challenging part of the Pharmacovigilance System Master File (PSMF).
The main body of the PSMF typically changes relatively infrequently; the annexes often change continuously as new products are launched, vendors engaged, audits completed, CAPAs opened and closed, and organisational structures evolve. Annexes therefore frequently become the first part of the PSMF to fall out of date โ a significant issue because inspectors often rely upon annexes to determine whether the PSMF accurately reflects operational reality.
Mature organisations treat annex maintenance as a governance activity rather than an administrative exercise. This guide explains annex purpose and content and adds practical, inspection-ready implementation detail: a version-control policy, an inspection-readiness checklist, and standard annex templates with minimum required fields. The aim is to make annexes operationally actionable and inspection-ready.
Why Annexes Exist
Certain information changes frequently โ product and vendor inventories, audit schedules, inspection histories, organisational charts. Embedding this information directly within the main body would make the PSMF difficult to maintain. Annexes separate stable information from dynamic information: the main body explains how the PV system works; annexes provide evidence and operational detail.
Regulatory context: EMA GVP Module II describes the PSMF structure and expects that the PSMF includes supporting documentation that demonstrates how the PV system operates. Annexes fulfil that expectation by providing the operational granularity inspectors need to verify compliance with Directive 2001/83/EC, Regulation (EC) No 726/2004 and associated implementing regulations.
The Real Purpose of Annexes
Inspectors often regard annexes as the most operationally useful part of the PSMF because they answer practical questions about scope, responsibilities and controls. Effective annexes bridge governance narratives and operational reality โ allowing inspectors to verify that what the organisation declares in the main body is implemented in practice.
Typical Annex Categories
Core annex categories commonly found in mature PSMFs include:
- QPPV information
- Organisational structures
- Product inventories
- Vendor inventories
- Computerised systems
- Audit programmes and reports
- CAPA registers
- Inspection history
The remainder of this guide describes inspection relevance, governance expectations and practical templates for these annexes, then presents a version-control policy and an inspection-readiness checklist to operationalise maintenance activities.
Annex Content and Inspection Relevance
Below are concise descriptions of common annexes with inspection-focused comments and key expectations.
QPPV Information Annex
Typical minimum content: - Full name, title - Contact information and primary location - Professional qualifications and licence/status where applicable - Delegation/deputy arrangements (names, contact details, delegated responsibilities) - Appointment start date and status (active/left, interim) Inspection relevance: Inspectors verify appointment and availability of the QPPV and deputies, consistency across documents, and evidence of delegated authority. Missing or out-of-date QPPV information frequently attracts attention.
Organisational Structure Annex
Typical minimum content: - High-level PV organisational chart(s) showing reporting lines relevant to PV activities - List of PV function owners and role descriptions - Affiliate and regional responsibilities where applicable Inspection relevance: Inspectors use charts to select interviewees and confirm responsibility allocation. Charts should be current and correspond with contact lists and delegation logs.
Product Inventory Annex
Typical minimum content: - Product name (trade and non-proprietary) - Marketing authorisation number(s) - Authorisation holder / MAH - Countries/jurisdictions covered - Route(s) of administration, dosage forms - Current product status (launched, withdrawn, discontinued) - Safety contact / safety owner Inspection relevance: Inspectors use product inventories to define scope of inspection and to see whether the organisation has oversight for all listed products. Discrepancies between product lists and regulatory filings or contracts are common findings.
Vendor Inventory Annex
Typical minimum content: - Vendor name and legal entity - Activity performed (e.g., case processing, literature screening, signal detection) - Contract reference and effective dates - Criticality / risk classification - Oversight owner within PV - Last oversight activity (audit, monitoring visit) and result Inspection relevance: Inspectors compare vendor inventories with contracts and oversight evidence. Missing vendors or lack of oversight records are common inspection issues.
Computerised System Annex
Typical minimum content: - System name and owner - Function (safety database, document management, etc.) - Hosting environment (cloud/on-premise/3rd-party) - Validation status and key validation documents (IQ/OQ/PQ or CSV summary) - Data flow descriptions and system interfaces Inspection relevance: Inspectors review system inventories to understand data flows, responsibilities and validated status. Evidence of validation, change control and access management should be available.
Audit Programme Annex
Typical minimum content: - Audit schedule and scope - Completed audits with dates and audit types (PV audit, vendor audit) - Summary of findings and link to CAPAs - Audit owners and next review dates Inspection relevance: Inspectors assess whether the audit programme is risk-proportional and executed. They look for closed-loop CAPAs and action tracking.
CAPA Annex
Typical minimum content: - CAPA identifier - Issue description and root cause summary - Actions planned, milestones and owners - Status and evidence of closure (deliverables, verification) - Link to originating event (audit, inspection, complaint) Inspection relevance: Inspectors examine the CAPA system for effective root cause analysis and verification. Repeated similar CAPAs or open CAPAs without evidence of verification are red flags.
Inspection History Annex
Typical minimum content: - Authority name - Inspection dates and scope - Inspection outcome(s) - Significant observations and actions taken (CAPAs) - Current status of outstanding actions Inspection relevance: Inspectors expect accurate historic records. Consistency between the PSMF inspection history and actual regulatory correspondence is essential.
Annex Governance and Roles
Good annex governance turns reactive maintenance into proactive control. Key elements:
- Defined ownership: Each annex must have a named owner (title and person) responsible for content, updates and evidence.
- Review cycles: Annexes should have a documented review frequency (e.g., monthly for vendor inventory, quarterly for product inventory, annually for QPPV and organisational charts), and the review due dates must be visible.
- Update triggers: Specify events that require immediate updates (product launch/withdrawal, vendor contract change, audit finding, inspection, M&A activity, QPPV change).
- Change control integration: Significant annex changes (e.g., addition of high-criticality vendor, change in QPPV) should be routed through the established change control process.
- Evidence linkage: Annex entries should link to source documents (contracts, MA documents, audit reports) stored and retrievable in the quality system.
- Training and competence: Annex owners and contributors should be trained on relevant SOPs and inspection expectations.
- Periodic independent verification: PV quality or compliance functions should periodically validate annex accuracy against source systems (e.g., ERP, supplier master data, regulatory records).
Regulatory context: EMA GVP Modules IโIII and applicable local regulations expect PV systems to be adequately resourced, documented and controlled. Annex governance demonstrates this in practice.
Version-Control Policy for PSMF Annexes (Operational)
A robust version-control policy is central to inspection readiness. Below is an implementable policy designed to meet regulatory and inspection expectations.
Policy objectives: - Ensure traceability of changes. - Provide a clear audit trail for inspectors. - Maintain a single source of truth while allowing controlled updates.
Essential components:
- Document identification and scope
- Each annex must use a standard identifier: PSMF-ANNEX-[TYPE]-[ORG]-[YYYYMMDD]-v[MAJOR.MINOR]
-
Example: PSMF-ANNEX-VENDOR-ACME-20250615-v1.2
-
Versioning convention
- Major.Minor format: increment minor for administrative/typographical updates; increment major for substantive content changes affecting responsibilities, scope, or regulatory statements.
-
Examples:
- v1.0 initial release
- v1.1 minor correction
- v2.0 significant content change (new vendor category, new country coverage)
-
Metadata requirements (stored on the document header or as a tracked metadata page)
- Annex title and identifier
- Version number
- Effective date
- Previous version reference
- Author(s)
- Annex owner (role + person)
- Approver(s) (e.g., Head of PV, QPPV)
- Change summary (one-paragraph description)
- Reason for change (trigger)
- Related change control or CAPA ID (if applicable)
- Review due date
- Distribution list
-
Document location (link to repository)
-
Change control and approval
- All major changes require change control form submission and approval by designated approvers (Head of PV, Quality, QPPV where applicable).
-
Minor administrative updates may follow a simplified approval path (owner + QA approval).
-
Electronic records and audit trail
- Annexes maintained in an electronic document management system (EDMS) with version history, time-stamped edits and user audit trail.
-
If stored outside EDMS, maintain supplementary change log file with identical metadata.
-
Archiving and retention
- Retain previous versions according to the organisationโs document retention schedule and regulatory requirements (minimum 5โ10 years or as per local regulation).
-
Archive must be searchable and accessible for inspection.
-
Access and distribution control
- Define access levels: read-only for inspected versions, edit access restricted to authenticated owners and designated editors.
-
Maintain "inspection copy" protocol: a time-stamped PDF of the annex at the time of inspection request, labelled as an official inspection version.
-
Emergency updates and interim evidence
- If a critical change occurs (e.g., QPPV leaves), an interim annex update should be created with clear versioning (e.g., v2.0i for interim) and expedited approval. Change control should follow within a defined timeframe (e.g., 30 days).
Inspection relevance: Inspectors expect to see clear version histories, approver signatures and links to the change control record. Absence of these elements may be interpreted as poor control or undocumented changes.
File Naming, Storage and Indexing (Practical)
- Standard filename: PSMF-ANNEX-[TYPE]-[Org]-v[MAJOR.MINOR]-YYYYMMDD.pdf
- Maintain a central PSMF annex index (master table of contents) with live links, last review date, owner and current version.
- Store finalised annex PDFs in a read-only inspection folder and keep editable source files in a controlled folder accessible only to editors.
- Provide inspectors with a single consolidated PSMF package and a printed or electronic annex index that maps annex entries to source evidence (contracts, MA documents, audit reports).
Inspection-Readiness Checklist (Operational and Annex-Specific)
The checklist below is intended to be used by PV Quality or Annex Owners to assert inspection readiness. Use this as a working document and evidence pack template.
General preparation (apply to all annexes) - [ ] Annex has a current version and effective date recorded per version-control policy. - [ ] Annex owner is named and has evidence of delegation and training. - [ ] Change log is complete and linked to change control/CAPA where applicable. - [ ] Source documents linked and retrievable (contracts, MA evidence, audit reports). - [ ] Annex reviewed within defined review frequency; next review date recorded. - [ ] PDF inspection copy available and stored in the inspection folder. - [ ] Cross-references in the main body of the PSMF are consistent with annex content. - [ ] Evidence of independent verification by PV Quality or Compliance within the last 12 months. - [ ] Supporting evidence for any assertions (e.g., vendor audit report, QPPV appointment letter) available and indexed.
Annex-specific checklist items
QPPV Annex - [ ] QPPV appointment letter(s) available and signed. - [ ] Deputy appointment(s) and delegation logs present. - [ ] Contact details verified against HR records. - [ ] CVs and qualification evidence available (if requested). - Inspection tip: Be prepared to provide evidence of QPPV availability and delegation during interview.
Organisational Structure Annex - [ ] Up-to-date organisational charts (global and regional PV owners). - [ ] Role descriptions and delegation matrices linked. - [ ] Evidence of reporting lines (org system snapshot or HR export). - Inspection tip: Ensure chart aligns with personnel present in the facility.
Product Inventory Annex - [ ] Product list reconciled with regulatory registrations and commercial lists. - [ ] MA numbers and current authorisation status documented. - [ ] Safety owner for each product identified. - [ ] Evidence for new launches or withdrawals included. - Inspection tip: Provide quick filters or pivot views for inspectors to focus on their jurisdiction.
Vendor Inventory Annex - [ ] Vendor contracts and master service agreements accessible. - [ ] Evidence of vendor qualification (audit/assessment reports) included. - [ ] Latest oversight activity recorded and linked (monitoring reports). - [ ] Criticality/risk classification rationales documented. - Inspection tip: Be able to demonstrate vendor oversight for highest-risk vendors.
Computerised System Annex - [ ] System inventory with validation status and key validation documents. - [ ] Data flow diagrams and system owner contact provided. - [ ] Evidence of backup, disaster recovery and user access control available. - Inspection tip: Bring system diagrams and validation summary reports.
Audit Programme Annex - [ ] Current audit schedule and completed audits accessible. - [ ] Audit reports and executive summaries indexed. - [ ] Linkage between audit findings and CAPAs visible. - Inspection tip: Provide sampling of audit evidence and verification of CAPA effectiveness.
CAPA Annex - [ ] CAPA register up to date with status, owners and closure evidence. - [ ] Root cause analyses and verification activities indexed. - Inspection tip: Demonstrate closure evidence and verification results.
Inspection History Annex - [ ] Full record of past inspections, outcomes and follow-up actions included. - [ ] Evidence of regulatory correspondence and CAPAs resulting from inspections available. - Inspection tip: Provide timeline and current status on open items.
Presentation and logistics - [ ] Consolidated annex index and navigator ready for inspectors. - [ ] Dedicated annex owner(s) prepared to present and speak to their annex. - [ ] Digital and printed copies available per inspector request. - [ ] Workspace and access to source documents arranged and tested.
Frequency and ownership - Annex owners should run this checklist at a prescribed cadence: monthly (vendor, product inventories), quarterly (system inventory, audit programme), annually (organisational chart, QPPV annex), or triggered by change events.
Inspection relevance: Inspectors expect well-indexed evidence, traceable links and trained annex owners who can speak credibly to annex content. The checklist demonstrates an organised, controlled approach.
Standard Annex Templates: Minimum Required Fields
The templates below are intentionally pragmatic and contain minimum fields that should be present in any inspection-ready annex. Organisations may extend fields as needed, but minimums should always be present and consistently formatted.
Note: For each annex, maintain a linked evidence field that references source documents stored in the document repository.
Template: QPPV Annex (Minimum Fields)
- Annex ID
- Version / Effective date
- QPPV name
- Title / role
- Contact details (email / phone / location)
- Appointment letter reference (file ID)
- Appointment effective date
- Deputy name(s) and contact details
- Delegation summary (what is delegated)
- QPPV availability statement (hours / on-call)
- Licence / qualification reference (if applicable)
- Related SOPs and delegation matrix (file links)
- Last review date
- Annex owner and approver
- Evidence links (appointment letter, CV, delegation log)
Template: Organisational Structure Annex (Minimum Fields)
- Annex ID
- Version / Effective date
- High-level organisational chart (embedded image or file link)
- List of PV functional owners (name / title / responsibility)
- Reporting lines summary
- Affiliate/regional responsibilities (table)
- Delegation of duties overview
- HR roster snapshot reference (file ID)
- Last review date
- Annex owner and approver
- Evidence links (org system export, role descriptions)
Template: Product Inventory Annex (Minimum Fields โ table format)
- Annex ID
- Version / Effective date
- Product (trade name)
- Non-proprietary name
- MAH / authorisation holder
- MA number(s)
- Countries / jurisdictions covered
- Status (launched / withdrawn / suspended)
- Route(s) of administration
- Safety owner (name / role)
- Date added / Date last updated
- Source document references (MA certificate, launch memo)
- Risk classification (optional)
- Annex owner and approver
Template: Vendor Inventory Annex (Minimum Fields โ table format)
- Annex ID
- Version / Effective date
- Vendor legal name
- Site location(s)
- Activity performed
- Contract reference and effective dates
- Criticality / risk class
- Oversight owner (name / role)
- Last oversight date and summary
- Last audit date and result (if applicable)
- Open issues / CAPA link
- Evidence links (contract, audit report)
- Date added / Date last updated
- Annex owner and approver
Template: Computerised System Annex (Minimum Fields โ table format)
- Annex ID
- Version / Effective date
- System name
- Owner / custodian
- Function(s) (safety DB, DMS, signal tool)
- Hosting environment (cloud / vendor / on-premise)
- Validation status (validated / under validation)
- Key validation documents (file refs)
- Interfaces (systems connected)
- Data flow diagram reference
- Access control owner
- Backup and disaster recovery summary
- Last change control summary
- Date added / Date last updated
- Annex owner and approver
Template: Audit Programme Annex (Minimum Fields)
- Annex ID
- Version / Effective date
- Audit schedule (annual plan)
- Completed audits table (audit ID, date, scope, lead auditor)
- Key findings summary per audit (high level)
- CAPA linkage (Capa ID)
- Audit owner and contact
- Next audit dates
- Evidence links (reports, summaries)
- Date added / Date last updated
- Annex owner and approver
Template: CAPA Annex (Minimum Fields โ table format)
- Annex ID
- Version / Effective date
- CAPA ID
- Origin (audit / inspection / complaint / other)
- Date opened
- Description of issue
- Root cause summary
- Action(s) planned (with milestones and owners)
- Verification method and evidence
- Status (open / in progress / verified closed)
- Date closed (if applicable)
- Related documentation (file refs)
- Annex owner and approver
Template: Inspection History Annex (Minimum Fields โ table format)
- Annex ID
- Version / Effective date
- Authority name
- Inspection dates
- Scope
- Facility/location (if applicable)
- Outcome (no findings / observations / critical)
- Significant observations (summary)
- CAPAs or actions taken (Capa IDs)
- Current status of actions
- Correspondence references (letters)
- Annex owner and approver
Evidence Linking and Traceability
For inspection readiness, every annex entry should be traceable to source evidence. Implement a referencing convention:
- Evidence reference format: EV-[TYPE]-[YYYYMMDD]-[SEQ]
- Example: EV-CONTRACT-20250612-01
- Maintain an evidence index mapping EV-IDs to stored files, location and access instructions.
Inspectors will expect to see direct links between annex entries and the evidence index. Where direct links cannot be embedded (paper or legacy systems), provide a clear map and rapid retrieval process.
Practical Operational Practices
- Single source of truth: Maintain one authoritative annex dataset; use exports to generate read-only inspection packages.
- Automation: Where possible, populate inventories from master data systems (ERP, safety database) and reconcile regularly to reduce manual error.
- Dashboards: Provide quick-reference dashboards for inspectors (product counts by country, vendor risk heatmaps, outstanding CAPA metrics).
- Readability: Use consistent formatting, standardized column headers and a simple legend for codes and statuses.
- Training: Run periodic refresher sessions for annex owners on document control, evidence retrieval, and inspection expectations.
- Simulation: Conduct mock inspections that focus specifically on annex content and annex-owner interviews.
Governance Discussion
Effective annex governance requires interplay between PV operations, quality/compliance, legal, IT and commercial functions. Key governance responsibilities include:
- PV Operations: Responsible for content accuracy and day-to-day updates.
- PV Quality / Compliance: Periodic independent verification, audit sampling and assurance reporting to senior management.
- Legal/Contracts: Source of vendor contracts and material change notifications.
- IT/Systems: Ensures systems listed in the system annex are validated, supported and that data flows are documented.
- Commercial/Marketing: Works with PV to update product launches or withdrawals.
- Senior management: Receives periodic annex status reports and approves governance frameworks.
A governance forum (e.g., monthly PV governance meeting) should review annex health metrics (stale entries, open CAPAs linked to annexes, overdue reviews) and escalate risks to executive leadership where necessary.
Regulatory context: Inspectors increasingly evaluate governance structures. Demonstrating that annex maintenance is embedded in governance โ with clear owners, review metrics and independent verification โ reduces the risk of inspection findings.
Inspection Relevance and How Inspectors Will Use Annexes
Inspectors will use annexes to:
- Define inspection scope quickly (product lists, jurisdictions)
- Identify interview candidates (org charts, QPPV/deputies)
- Understand data integrity and system validation (system annex)
- Verify outsourced activities and oversight (vendor annex)
- Follow up on past observations and CAPAs (inspection history, CAPA annex)
- Assess audit programme robustness and evidence of corrective action
Prepare to demonstrate: traceability, up-to-date contact information, evidence of oversight and verification of annex accuracy. A structured annex index and a documented version-control trail simplify inspector navigation and reduce friction during on-site reviews.
What Great Annexes Look Like (Operational Summary)
Great annexes are: - Accurate and aligned with source documents - Current and time-stamped with auditable versions - Complete with minimum required fields and evidence links - Owned and reviewed on a documented cadence - Indexed and presented for rapid inspection use - Integrated into governance and change control processes
Mature annex frameworks support day-to-day governance and inspection readiness, rather than being mere artefacts prepared only for regulatory visits.
Key Takeaways
- Annexes provide the operational detail supporting the PSMF and are essential to inspection evidence.
- Implement a clear version-control policy with metadata, change control linkage, and archival practice to meet inspection expectations.
- Use an inspection-readiness checklist to validate annex completeness, evidence linkage and owner preparedness.
- Adopt standardized annex templates with minimum required fields to ensure consistency and inspection-readiness.
- Govern annex maintenance through defined ownership, review cycles, independent verification and integration with quality systems.
- Well-maintained annexes reduce inspection risk, improve the QPPVโs ability to oversee the PV system and support organisational compliance.
References
- EMA Good Pharmacovigilance Practices (GVP) Module II โ Pharmacovigilance System Master File.
- EMA Good Pharmacovigilance Practices (GVP) Module I โ Pharmacovigilance Systems and Their Quality Systems.
- EMA Good Pharmacovigilance Practices (GVP) Module III โ Pharmacovigilance Inspections.
- Regulation (EC) No 726/2004.
- Directive 2001/83/EC.
- Commission Implementing Regulation (EU) No 520/2012.
- EMA Questions and Answers on Pharmacovigilance System Master Files.