PSMF Annexes Guide

A practical guide to understanding, maintaining and governing PSMF annexes within a pharmacovigilance system.

Take test

PSMF Annexes Guide

Table of Contents

Introduction

For many pharmacovigilance professionals, the annexes are the most challenging part of the Pharmacovigilance System Master File (PSMF).

The main body of the PSMF typically changes relatively infrequently; the annexes often change continuously as new products are launched, vendors engaged, audits completed, CAPAs opened and closed, and organisational structures evolve. Annexes therefore frequently become the first part of the PSMF to fall out of date โ€” a significant issue because inspectors often rely upon annexes to determine whether the PSMF accurately reflects operational reality.

Mature organisations treat annex maintenance as a governance activity rather than an administrative exercise. This guide explains annex purpose and content and adds practical, inspection-ready implementation detail: a version-control policy, an inspection-readiness checklist, and standard annex templates with minimum required fields. The aim is to make annexes operationally actionable and inspection-ready.

Why Annexes Exist

Certain information changes frequently โ€” product and vendor inventories, audit schedules, inspection histories, organisational charts. Embedding this information directly within the main body would make the PSMF difficult to maintain. Annexes separate stable information from dynamic information: the main body explains how the PV system works; annexes provide evidence and operational detail.

Regulatory context: EMA GVP Module II describes the PSMF structure and expects that the PSMF includes supporting documentation that demonstrates how the PV system operates. Annexes fulfil that expectation by providing the operational granularity inspectors need to verify compliance with Directive 2001/83/EC, Regulation (EC) No 726/2004 and associated implementing regulations.

The Real Purpose of Annexes

Inspectors often regard annexes as the most operationally useful part of the PSMF because they answer practical questions about scope, responsibilities and controls. Effective annexes bridge governance narratives and operational reality โ€” allowing inspectors to verify that what the organisation declares in the main body is implemented in practice.

Typical Annex Categories

Core annex categories commonly found in mature PSMFs include:

The remainder of this guide describes inspection relevance, governance expectations and practical templates for these annexes, then presents a version-control policy and an inspection-readiness checklist to operationalise maintenance activities.

Annex Content and Inspection Relevance

Below are concise descriptions of common annexes with inspection-focused comments and key expectations.

QPPV Information Annex

Typical minimum content: - Full name, title - Contact information and primary location - Professional qualifications and licence/status where applicable - Delegation/deputy arrangements (names, contact details, delegated responsibilities) - Appointment start date and status (active/left, interim) Inspection relevance: Inspectors verify appointment and availability of the QPPV and deputies, consistency across documents, and evidence of delegated authority. Missing or out-of-date QPPV information frequently attracts attention.

Organisational Structure Annex

Typical minimum content: - High-level PV organisational chart(s) showing reporting lines relevant to PV activities - List of PV function owners and role descriptions - Affiliate and regional responsibilities where applicable Inspection relevance: Inspectors use charts to select interviewees and confirm responsibility allocation. Charts should be current and correspond with contact lists and delegation logs.

Product Inventory Annex

Typical minimum content: - Product name (trade and non-proprietary) - Marketing authorisation number(s) - Authorisation holder / MAH - Countries/jurisdictions covered - Route(s) of administration, dosage forms - Current product status (launched, withdrawn, discontinued) - Safety contact / safety owner Inspection relevance: Inspectors use product inventories to define scope of inspection and to see whether the organisation has oversight for all listed products. Discrepancies between product lists and regulatory filings or contracts are common findings.

Vendor Inventory Annex

Typical minimum content: - Vendor name and legal entity - Activity performed (e.g., case processing, literature screening, signal detection) - Contract reference and effective dates - Criticality / risk classification - Oversight owner within PV - Last oversight activity (audit, monitoring visit) and result Inspection relevance: Inspectors compare vendor inventories with contracts and oversight evidence. Missing vendors or lack of oversight records are common inspection issues.

Computerised System Annex

Typical minimum content: - System name and owner - Function (safety database, document management, etc.) - Hosting environment (cloud/on-premise/3rd-party) - Validation status and key validation documents (IQ/OQ/PQ or CSV summary) - Data flow descriptions and system interfaces Inspection relevance: Inspectors review system inventories to understand data flows, responsibilities and validated status. Evidence of validation, change control and access management should be available.

Audit Programme Annex

Typical minimum content: - Audit schedule and scope - Completed audits with dates and audit types (PV audit, vendor audit) - Summary of findings and link to CAPAs - Audit owners and next review dates Inspection relevance: Inspectors assess whether the audit programme is risk-proportional and executed. They look for closed-loop CAPAs and action tracking.

CAPA Annex

Typical minimum content: - CAPA identifier - Issue description and root cause summary - Actions planned, milestones and owners - Status and evidence of closure (deliverables, verification) - Link to originating event (audit, inspection, complaint) Inspection relevance: Inspectors examine the CAPA system for effective root cause analysis and verification. Repeated similar CAPAs or open CAPAs without evidence of verification are red flags.

Inspection History Annex

Typical minimum content: - Authority name - Inspection dates and scope - Inspection outcome(s) - Significant observations and actions taken (CAPAs) - Current status of outstanding actions Inspection relevance: Inspectors expect accurate historic records. Consistency between the PSMF inspection history and actual regulatory correspondence is essential.

Annex Governance and Roles

Good annex governance turns reactive maintenance into proactive control. Key elements:

Regulatory context: EMA GVP Modules Iโ€“III and applicable local regulations expect PV systems to be adequately resourced, documented and controlled. Annex governance demonstrates this in practice.

Version-Control Policy for PSMF Annexes (Operational)

A robust version-control policy is central to inspection readiness. Below is an implementable policy designed to meet regulatory and inspection expectations.

Policy objectives: - Ensure traceability of changes. - Provide a clear audit trail for inspectors. - Maintain a single source of truth while allowing controlled updates.

Essential components:

  1. Document identification and scope
  2. Each annex must use a standard identifier: PSMF-ANNEX-[TYPE]-[ORG]-[YYYYMMDD]-v[MAJOR.MINOR]
  3. Example: PSMF-ANNEX-VENDOR-ACME-20250615-v1.2

  4. Versioning convention

  5. Major.Minor format: increment minor for administrative/typographical updates; increment major for substantive content changes affecting responsibilities, scope, or regulatory statements.
  6. Examples:

    • v1.0 initial release
    • v1.1 minor correction
    • v2.0 significant content change (new vendor category, new country coverage)
  7. Metadata requirements (stored on the document header or as a tracked metadata page)

  8. Annex title and identifier
  9. Version number
  10. Effective date
  11. Previous version reference
  12. Author(s)
  13. Annex owner (role + person)
  14. Approver(s) (e.g., Head of PV, QPPV)
  15. Change summary (one-paragraph description)
  16. Reason for change (trigger)
  17. Related change control or CAPA ID (if applicable)
  18. Review due date
  19. Distribution list
  20. Document location (link to repository)

  21. Change control and approval

  22. All major changes require change control form submission and approval by designated approvers (Head of PV, Quality, QPPV where applicable).
  23. Minor administrative updates may follow a simplified approval path (owner + QA approval).

  24. Electronic records and audit trail

  25. Annexes maintained in an electronic document management system (EDMS) with version history, time-stamped edits and user audit trail.
  26. If stored outside EDMS, maintain supplementary change log file with identical metadata.

  27. Archiving and retention

  28. Retain previous versions according to the organisationโ€™s document retention schedule and regulatory requirements (minimum 5โ€“10 years or as per local regulation).
  29. Archive must be searchable and accessible for inspection.

  30. Access and distribution control

  31. Define access levels: read-only for inspected versions, edit access restricted to authenticated owners and designated editors.
  32. Maintain "inspection copy" protocol: a time-stamped PDF of the annex at the time of inspection request, labelled as an official inspection version.

  33. Emergency updates and interim evidence

  34. If a critical change occurs (e.g., QPPV leaves), an interim annex update should be created with clear versioning (e.g., v2.0i for interim) and expedited approval. Change control should follow within a defined timeframe (e.g., 30 days).

Inspection relevance: Inspectors expect to see clear version histories, approver signatures and links to the change control record. Absence of these elements may be interpreted as poor control or undocumented changes.

File Naming, Storage and Indexing (Practical)

Inspection-Readiness Checklist (Operational and Annex-Specific)

The checklist below is intended to be used by PV Quality or Annex Owners to assert inspection readiness. Use this as a working document and evidence pack template.

General preparation (apply to all annexes)

Annex-specific checklist items

QPPV Annex

Organisational Structure Annex

Product Inventory Annex

Vendor Inventory Annex

Computerised System Annex

Audit Programme Annex

CAPA Annex

Inspection History Annex

Presentation and logistics

Frequency and ownership

Inspection relevance: Inspectors expect well-indexed evidence, traceable links and trained annex owners who can speak credibly to annex content. The checklist demonstrates an organised, controlled approach.

Standard Annex Templates: Minimum Required Fields

The templates below are intentionally pragmatic and contain minimum fields that should be present in any inspection-ready annex. Organisations may extend fields as needed, but minimums should always be present and consistently formatted.

Note: For each annex, maintain a linked evidence field that references source documents stored in the document repository.

Template: QPPV Annex (Minimum Fields)

Template: Organisational Structure Annex (Minimum Fields)

Template: Product Inventory Annex (Minimum Fields โ€” table format)

Template: Vendor Inventory Annex (Minimum Fields โ€” table format)

Template: Computerised System Annex (Minimum Fields โ€” table format)

Template: Audit Programme Annex (Minimum Fields)

Template: CAPA Annex (Minimum Fields โ€” table format)

Template: Inspection History Annex (Minimum Fields โ€” table format)

Evidence Linking and Traceability

For inspection readiness, every annex entry should be traceable to source evidence. Implement a referencing convention:

Inspectors will expect to see direct links between annex entries and the evidence index. Where direct links cannot be embedded (paper or legacy systems), provide a clear map and rapid retrieval process.

Practical Operational Practices

Governance Discussion

Effective annex governance requires interplay between PV operations, quality/compliance, legal, IT and commercial functions. Key governance responsibilities include:

A governance forum (e.g., monthly PV governance meeting) should review annex health metrics (stale entries, open CAPAs linked to annexes, overdue reviews) and escalate risks to executive leadership where necessary.

Regulatory context: Inspectors increasingly evaluate governance structures. Demonstrating that annex maintenance is embedded in governance โ€” with clear owners, review metrics and independent verification โ€” reduces the risk of inspection findings.

Inspection Relevance and How Inspectors Will Use Annexes

Inspectors will use annexes to:

Prepare to demonstrate: traceability, up-to-date contact information, evidence of oversight and verification of annex accuracy. A structured annex index and a documented version-control trail simplify inspector navigation and reduce friction during on-site reviews.

What Great Annexes Look Like (Operational Summary)

Great annexes are: - Accurate and aligned with source documents - Current and time-stamped with auditable versions - Complete with minimum required fields and evidence links - Owned and reviewed on a documented cadence - Indexed and presented for rapid inspection use - Integrated into governance and change control processes

Mature annex frameworks support day-to-day governance and inspection readiness, rather than being mere artefacts prepared only for regulatory visits.

Key Takeaways

References

  1. EMA Good Pharmacovigilance Practices (GVP) Module II โ€“ Pharmacovigilance System Master File.

Regulatory Note

This article is educational. Binding obligations arise from applicable legislation and marketing-authorisation conditions. GVP and national-authority publications describe regulatory expectations for implementation. Suggested operating models, frequencies, thresholds, scorecards, matrices, checklists and scenarios are illustrative or recommended practice unless a legal provision is expressly identified.

Commission Implementing Regulation (EU) No 520/2012 was amended, and the consolidated text applicable from 12 February 2026 should be read with current guidance. EMA states that affected GVP modules will be revised. Verify current legislation, guidance, national requirements, contracts and product-specific commitments before operational use.

Revision History

Last reviewed: 2026-09-04