PSMF and QPPV Oversight

An advanced guide to using the PSMF as a governance, oversight and risk management tool.

Audio Lesson 9 min

PSMF and QPPV Oversight

Introduction

The Qualified Person Responsible for Pharmacovigilance (QPPV) occupies a unique position within the pharmacovigilance system.

Unlike operational functions, the QPPV is not primarily responsible for performing pharmacovigilance activities.

Instead, the QPPV is responsible for maintaining oversight of those activities.

This distinction is important.

A QPPV does not need to process every case. A QPPV does not need to submit every report. A QPPV does not need to perform every audit.

However, the QPPV must understand how those activities are organised, governed and controlled.

The Pharmacovigilance System Master File (PSMF) is one of the most important tools available for achieving that oversight. In mature organisations, the PSMF functions as the operational map of the pharmacovigilance system and the repository linking high-level governance to operational evidence. For many QPPVs it becomes the single most valuable governance document within the organisation.

This article expands on how to build a PSMF that is inspection-ready, directly implementable and designed to support the QPPV in active governance and oversight, with practical checklists, a sample index and explicit links to supporting evidence and SOPs.

Why QPPVs Need the PSMF

Modern pharmacovigilance systems are increasingly complex. A typical organisation may include:

No individual can directly observe every pharmacovigilance activity. Oversight therefore depends upon structured governance mechanisms. The PSMF helps the QPPV understand:

Without a reliable, evidence-linked system description, effective oversight becomes significantly more difficult. The PSMF must therefore be both descriptive and demonstrable: describing structures, processes and responsibilities, and directly pointing to documentary evidence (SOPs, contracts, audit reports, metrics) that an inspector or the QPPV can review rapidly.

Regulatory Context

European regulators require a PSMF as part of Good Pharmacovigilance Practices (GVP), specifically GVP Module II, and the QPPV is referenced across GVP Module I. The PSMF plays a central role during pharmacovigilance inspections (GVP Module III). Key regulatory expectations include:

While GVP documents set the EU baseline, global organisations should map the PSMF to other regional and national requirements (e.g., health authority expectations for the US, Japan, Canada), and include local variations in the evidence pack linked from the PSMF.

The Difference Between Management and Oversight

Operational management focuses on:

Oversight focuses on:

The QPPV operates primarily within the second category. The PSMF supports this role because it describes governance structures, oversight mechanisms, responsibilities and escalation pathways — and connects them to the records that prove they function.

The PSMF as a Governance Map

A useful way to think about the PSMF is as a governance map. Every major section answers an oversight question.

PSMF Area QPPV Question
QPPV Section Who is accountable?
Organisation Structure Who performs activities?
Vendor Inventory Which activities are outsourced?
Product Inventory What is within scope?
Systems Inventory Where does data reside?
Audit Programme How is effectiveness verified?
CAPA Framework How are failures addressed?

Viewed this way, the PSMF becomes much more than a regulatory requirement — it becomes a structured oversight tool that links statements to evidence.

Understanding System Scope

One of the most important responsibilities of a QPPV is understanding the scope of the pharmacovigilance system. Questions include:

The PSMF provides visibility regarding these boundaries. This becomes particularly important during acquisitions, divestments, organisational restructuring and new market entry. Without a clear understanding of scope, oversight can quickly become fragmented.

Vendor Oversight

Vendor oversight is one of the most significant challenges facing modern QPPVs. Activities frequently outsourced include:

The PSMF must list each vendor, describe contracted pharmacovigilance responsibilities, identify the oversight activities in place (audits, KPIs, SLAs, scheduled reviews), and link to objective evidence: contracts, technical annexes, audit reports, KPI dashboards, CAPA records and vendor qualification documents.

A vendor inventory that also links to evidence provides one of the quickest and most inspection-relevant ways to assess organisational complexity and resilience.

Using the PSMF to Identify Risk

Experienced QPPVs rarely view the PSMF as a static document. Instead, they use it to identify areas of potential risk. Examples include:

The PSMF often reveals these risks more clearly than operational metrics alone when each risk is linked to supporting evidence and governance actions.

PSMF Reviews from a QPPV Perspective

Many organisations conduct formal PSMF reviews. Experienced QPPVs ask not only whether the document is complete, but whether it still reflects reality. Key review questions:

The PSMF review should be evidence-led: every descriptive statement should be verifiable by a referenced document.

The PSMF During Inspections

Inspectors frequently assess whether the QPPV understands the pharmacovigilance system. The PSMF is central to that assessment. Common inspection questions may include:

Inspectors will probe not only what the PSMF says, but whether evidence exists that the system operates as described (audits, CAPA, metrics, change controls, validation records). A PSMF that links descriptions to accessible evidence will materially shorten inspection time and reduce the risk of findings.

The PSMF During Organisational Change

Organisational change is often when the value of the PSMF is most apparent. Examples where the PSMF must be proactively used and updated include:

In each case, the PSMF helps preserve and demonstrate how the pharmacovigilance system operates.

The PSMF as Institutional Memory

One of the most underappreciated functions of the PSMF is preserving organisational knowledge. People leave. Roles change. Systems evolve. The PSMF helps ensure that understanding of the pharmacovigilance system survives those transitions. Mature organisations treat the PSMF as a strategic asset rather than a compliance document.

What Inspectors Expect from the QPPV

Inspectors generally do not expect the QPPV to memorise every annex. They do expect the QPPV to understand:

The PSMF should support that understanding and make evidence available quickly. If the document exists but does not help the QPPV perform oversight, its value is limited.

Characteristics of Strong QPPV Oversight

Strong oversight commonly includes:

The PSMF supports each of these capabilities when it is maintained as an evidence-linked, living document.

Common Oversight Weaknesses

Common deficiencies include:

These weaknesses often become apparent during inspections and can be remediated by linking PSMF content to documentary evidence and defined governance processes.

Inspection-Ready PSMF: Practical Checklist

The following checklist is intended to be used immediately prior to and during inspections. Each checklist item includes the types of evidence inspectors commonly request and suggested operational SOPs or documents to cite. Organise evidence in an inspection folder with the same numbering system as the PSMF index for rapid retrieval.

Legend: - Evidence: examples of documents (file naming examples in parentheses). - SOP: suggested SOP identifier examples; adapt to local organisation numbering.

  1. Executive Summary and PSMF Control
  2. Evidence: PSMF control page, version log, Table of Contents, location of full evidence repository (PSMF_Control_v3.2.pdf; PSMF_Version_History.xlsx).
  3. SOP: SOP-PV-PSMF-001 PSMF Maintenance; SOP-DOC-CTL-001 Document Management.
  4. Inspection relevance: Inspector expects to see latest version, change history and owner.

  5. QPPV Identification and Accountability

  6. Evidence: QPPV CV (signed), appointment letter, job description, delegation log, contact details (QPPV_CV_2026-01.pdf; Appointment_QPPV_2023-10.pdf; Delegation_Log.xlsx).
  7. SOP: SOP-PV-GOV-001 QPPV Responsibilities.
  8. Inspection relevance: Confirms legal/regulatory accountability and direct line to evidence of delegation.

  9. Organisational Structure and Roles

  10. Evidence: Organisational chart with names/roles, roles and responsibilities matrix (RACI), staff CVs for key roles (OrgChart_PV_2026.pdf; RACI_PV_2026.xlsx).
  11. SOP: SOP-PV-ORG-001 Roles and Responsibilities.
  12. Inspection relevance: Demonstrates clear assignment of PV responsibilities across affiliates and functions.

  13. Product Inventory and Scope

  14. Evidence: Master product list with MA numbers, countries, authorised indications, global safety contacts (Product_Master_List.xlsx; MA_Licence_Evidence folder).
  15. SOP: SOP-PV-PROD-001 Product Lifecycle Management.
  16. Inspection relevance: Verifies what is in scope for the PSMF and PV system.

  17. Systems Inventory and Data Flow

  18. Evidence: Inventory of PV systems/databases, hosting contracts, screenshots of system master configuration (Systems_Inventory.xlsx; SafetyDB_Hosting_Agreement_2024.pdf; SafetyDB_Config_Snapshot.png).
  19. SOP: SOP-IT-SYS-VAL-001 System Validation; SOP-PV-IT-001 Data Management.
  20. Inspection relevance: Confirms where data resides and controls are in place.

  21. Vendor and Outsourcing Inventory

  22. Evidence: Vendor register with contract links, scope of work (SoW), delegated responsibilities, SLA/KPI reports, audit reports and CAPA for each vendor (Vendor_Register.xlsx; Contract_VendorX_CaseProcessing.pdf; VendorX_Audit_2025-05.pdf).
  23. SOP: SOP-PV-VENDOR-001 Vendor Management; SOP-PV-AUDIT-001 Vendor Auditing.
  24. Inspection relevance: Proves oversight and control over outsourced activities.

  25. Case Processing and Safety Database Operations

  26. Evidence: Case processing SOP(s), sample anonymised ICSRs (redacted), reconciliation logs, intake logs, ICSR transmission logs (SOP-PV-CASE-001.pdf; Sample_ICSRs_redacted.zip; ICSR_Transmission_Log_2026.xlsx).
  27. SOP: SOP-PV-CASE-001 Individual Case Processing; SOP-PV-RECON-001 Reconciliation.
  28. Inspection relevance: Demonstrates how cases are handled end-to-end and evidence of timeliness and reporting.

  29. Expedited Reporting and Local Reporting

  30. Evidence: Expedited reporting SOP, examples of expedited reports submitted to regulators, notification logs, local representative letters (SOP-PV-EXP-001.pdf; Expedited_Report_Example_RED.pdf; Expedited_Reporting_Log.xlsx).
  31. SOP: SOP-PV-EXP-001 Expedited Reporting.
  32. Inspection relevance: Confirms compliance with reporting timelines and notification pathways.

  33. Aggregate Reporting (PSUR/PBRER)

  34. Evidence: Aggregate reporting SOP, PSUR/PBRER submission history and schedule, sign-off forms, PV input to regulatory dossiers (SOP-PV-AGG-001.pdf; PSUR_Submission_History.xlsx; PBRER_QA_Signoff.pdf).
  35. SOP: SOP-PV-AGG-001 Aggregate Reports.
  36. Inspection relevance: Demonstrates systems for periodic reporting and authorisation of reports.

  37. Signal Management and Safety Surveillance

    • Evidence: Signal management SOP, signal logs, examples of signal assessments and resulting actions, literature surveillance outputs (SOP-PV-SIG-001.pdf; Signal_Log.xlsx; Literature_Search_Report_2025.pdf).
    • SOP: SOP-PV-SIG-001 Signal Management.
    • Inspection relevance: Evidence of active safety surveillance and decision-making.
  38. Risk Management and PV Plans

    • Evidence: RMPs (current), risk minimisation plans and evidence of implementation, risk assessment reports (RMP_ProductA_2024.pdf; RMP_Implementation_Evidence.zip).
    • SOP: SOP-PV-RMP-001 Risk Management.
    • Inspection relevance: Shows that identified risks are managed and monitored.
  39. Audit and Inspection Programmes

    • Evidence: Audit schedule, audit reports (internal and vendor), CAPA logs and verification records, inspection history and responses (Audit_PV_Programme_2026.pdf; Audit_Report_VendorX_2025-06.pdf; CAPA_Log.xlsx; Inspection_Response_2024.pdf).
    • SOP: SOP-PV-AUDIT-001 Audit Management; SOP-PV-CAPA-001 CAPA.
    • Inspection relevance: Demonstrates verification of systems and closure of findings.
  40. CAPA and Quality Management

    • Evidence: CAPA procedures, open and closed CAPA lists, evidence of CAPA effectiveness checks (CAPA_Overview.xlsx; CAPA_Documentation.pdf).
    • SOP: SOP-PV-CAPA-001 CAPA.
    • Inspection relevance: Evidence of quality improvement and problem resolution.
  41. Training and Competency

    • Evidence: Training matrix, completed training records for PV staff and vendors, training materials (Training_Matrix_PV.xlsx; Training_Record_JohnDoe.pdf).
    • SOP: SOP-PV-TRAIN-001 Training and Competency.
    • Inspection relevance: Confirms staff are trained to perform PV tasks.
  42. Business Continuity and Disaster Recovery

    • Evidence: Business continuity plans, DR test reports, contingency plans for vendor failure (BCP_PV_2025.pdf; DR_Test_Report_2025-11.pdf).
    • SOP: SOP-PV-BCP-001 Business Continuity.
    • Inspection relevance: Demonstrates preparedness for critical interruptions.
  43. Data Protection and Confidentiality

    • Evidence: DPAs, privacy SOPs, data access logs, data redaction policies (DPA_VendorX.pdf; SOP-PV-DATA-001.pdf).
    • SOP: SOP-PV-DATA-001 Data Protection.
    • Inspection relevance: Ensures patient data is handled in accordance with law and policy.
  44. Change Control and System Migrations

    • Evidence: Change control records, validation of migrations, reconciliation records post-migration (Change_Control_Log.xlsx; Migration_Validation_Report.pdf).
    • SOP: SOP-IT-CHANGE-001 Change Control; SOP-PV-IT-VAL-001 System Validation.
    • Inspection relevance: Confirms controlled changes and data integrity.
  45. Local Regulatory Interactions

    • Evidence: Local agency correspondence, PV contact lists for affiliates, local qualified person delegations, translations where relevant (Local_Authority_Correspondence.zip; Local_Contacts.xlsx).
    • SOP: SOP-PV-LOCAL-001 Local Regulatory Interactions.
    • Inspection relevance: Shows interaction with national authorities and local compliance.
  46. Metrics and Oversight Reports

    • Evidence: PV KPIs, governance dashboards, minutes from PV governance committees and QPPV reports to senior management (KPI_Dashboard_Jan-Jun_2026.pdf; PV_Committee_Minutes_2026-05.pdf).
    • SOP: SOP-PV-METRICS-001 Metrics and Reporting.
    • Inspection relevance: Demonstrates ongoing oversight and escalation mechanisms.
  47. Legal and Regulatory Documentation

    • Evidence: Marketing authorisations, variations, regulatory commitments, references to relevant legislation (MA_Documents.zip; Regulatory_Commitments.xlsx).
    • SOP: SOP-PV-REG-001 Regulatory Interactions.
    • Inspection relevance: Confirms legal basis of products and commitments.
  48. Archive and Retention

    • Evidence: Archive procedures, retention schedule, location of archived PSMF versions (SOP-DOC-ARCHIVE-001.pdf; Archive_Index.xlsx).
    • SOP: SOP-DOC-ARCHIVE-001 Document Retention.
    • Inspection relevance: Demonstrates compliance with document retention expectations and availability of previous evidence when required.
  49. Evidence Index and Cross-References

    • Evidence: A single, searchable index mapping PSMF sections to evidence (PSMF_Evidence_Index.xlsx).
    • SOP: SOP-PV-PSMF-001 PSMF Maintenance.
    • Inspection relevance: Essential for rapid evidence retrieval during inspections.

Use the checklist as a pre-inspection validation routine; ensure all evidence files are labelled consistently and linked to the PSMF index. Prepare both electronic and, where necessary, printed evidence packs arranged by PSMF section numbers.

Sample PSMF Index (Section-to-Evidence Mapping)

The following sample index aligns a PSMF section structure to specific evidence and SOPs. This index is suitable for use as a template in an electronic document management system (e.g., eTMF, SharePoint). Use file naming conventions consistently (e.g., SectionNumber_DocumentTitle_Version_Date.ext).

  1. PSMF Control
  2. File: 1_PSMF_Control_v3.2_2026-05-01.pdf
  3. Evidence: Version history, approval sign-off, PSMF owner
  4. SOPs: SOP-PV-PSMF-001

  5. QPPV and Deputies

  6. File: 2_QPPV_CV_Appointment_2026-01.pdf
  7. Evidence: CV, appointment letter, proof of availability (contact logs)
  8. SOPs: SOP-PV-GOV-001

  9. Organisational Structure

  10. File: 3_OrgChart_PV_2026-04.pdf
  11. Evidence: Org chart, RACI matrix, key role CVs
  12. SOPs: SOP-PV-ORG-001

  13. Products and Scope

  14. File: 4_ProductMasterList_2026-04-15.xlsx
  15. Evidence: Product master list, MA copies
  16. SOPs: SOP-PV-PROD-001

  17. Safety Databases and IT Systems

  18. File: 5_SystemsInventory_2026-04.pdf
  19. Evidence: Hosting agreements, validation summary, access control lists
  20. SOPs: SOP-IT-SYS-VAL-001; SOP-PV-IT-001

  21. Outsourcing and Vendors

  22. File: 6_Vendor_Register_2026-05.xlsx
  23. Evidence: Contracts, SoWs, vendor audits, KPI reports
  24. SOPs: SOP-PV-VENDOR-001

  25. Case Processing

  26. File: 7_SOP_CaseProcessing_v5.0_2025-11-01.pdf
  27. Evidence: Sample redacted ICSRs, reconciliation logs
  28. SOPs: SOP-PV-CASE-001

  29. Expedited Reporting

  30. File: 8_SOP_ExpeditedReporting_v3.1_2025-09-01.pdf
  31. Evidence: Expedited report examples, submission logs
  32. SOPs: SOP-PV-EXP-001

  33. Aggregate Reporting

  34. File: 9_PSUR_Schedule_2026.xlsx
  35. Evidence: PSUR/PBRER submission records, sign-off sheets
  36. SOPs: SOP-PV-AGG-001

  37. Signal Management

    • File: 10_Signal_Log_2026.xlsx
    • Evidence: Signal assessments, decision records
    • SOPs: SOP-PV-SIG-001
  38. Audit Programme and Reports

    • File: 11_Audit_Programme_2026.pdf
    • Evidence: Audit reports, CAPA logs
    • SOPs: SOP-PV-AUDIT-001; SOP-PV-CAPA-001
  39. Training

    • File: 12_Training_Matrix_2026.xlsx
    • Evidence: Training completion certificates, curricula
    • SOPs: SOP-PV-TRAIN-001
  40. Business Continuity and Disaster Recovery

    • File: 13_BCP_DR_2025.pdf
    • Evidence: DR test results, contingency plans for vendor failure
    • SOPs: SOP-PV-BCP-001
  41. Data Protection

    • File: 14_DPA_Vendors_2024.pdf
    • Evidence: Data processing agreements, privacy notices
    • SOPs: SOP-PV-DATA-001
  42. Local Regulatory Interactions

    • File: 15_Local_Regulatory_Correspondence.zip
    • Evidence: Letters, notifications, translations as needed
    • SOPs: SOP-PV-LOCAL-001
  43. Metrics and Governance

    • File: 16_KPI_Dashboard_Q1_2026.pdf
    • Evidence: PV committee minutes, QPPV reports to senior management
    • SOPs: SOP-PV-METRICS-001
  44. Archive and Retention

    • File: 17_Archive_Index_2026.xlsx
    • Evidence: Archived PSMF versions, retention schedule
    • SOPs: SOP-DOC-ARCHIVE-001

This sample index should be adapted to the organisation's structure and system of record. Each entry must include the physical or digital path (URL or repository ID) to the evidence.

Practical Implementation Details

  1. Version control and ownership
  2. Assign a single named owner for the PSMF (the PSMF Owner), typically reporting to the QPPV.
  3. Maintain a version control log with date, author, summary of changes, and approver (file: PSMF_Version_History.xlsx).
  4. Review cycle: full PSMF review annually; targeted updates within 30 days of major change (vendor change, acquisition, change to QPPV, system migration). Document the review rationale.

  5. Evidence linkage and indexing

  6. Maintain an evidence index that maps PSMF text to evidence files (PSMF_Evidence_Index.xlsx). Use stable file identifiers and hyperlinks to records in the document management system.
  7. Where evidence cannot be included (confidential or large files), include a clear reference and location and ensure access is available for inspection.

  8. Document management and access

  9. Store the PSMF and evidence in a controlled document management system with audit trails.
  10. Define access rights: QPPV and deputies full access; inspectors read-only or temporary access during inspections.
  11. Provide a PDF snapshot of the current PSMF for quick review and an evidence index for inspectors.

  12. Labeling and naming conventions

  13. Use “SectionNumber_DocumentTitle_Version_Date” naming to allow inspectors to rapidly correlate PSMF sections and evidence.
  14. Maintain consistent metadata (owner, effective date, review date, retention date).

  15. Redaction and patient confidentiality

  16. Prepare redacted examples of ICSRs for inspection (obscure direct identifiers while preserving clinical content).
  17. Maintain DPA and data privacy evidence accessible.

  18. Evidence granularity

  19. For each control statement in the PSMF, include a direct reference to at least one primary piece of evidence (SOP, contract, audit report) and at least one operational record (audit log, KPI, meeting minutes).
  20. Example: For vendor oversight, link to the contract (primary) and the most recent vendor audit report with CAPA closure evidence (operational).

  21. PSMF Change control

  22. Use a formal change control process for PSMF updates (SOP-IT-CHANGE-001). Significant changes should be documented in the version history and approved by the QPPV.

  23. Inspection packs and dry runs

  24. Maintain a pre-prepared inspection pack summarising the PSMF with the top 20 evidence documents required for fast review. Update this quarterly.
  25. Conduct internal inspection dry runs annually: QPPV to walk through PSMF and evidence with the inspection support team.

  26. Audit trail and historical versions

  27. Keep previous versions of the PSMF accessible for a defined retention period. Provide evidence of historical decisions where relevant (e.g., prior vendor arrangements).
  28. Annotate what changed and why between versions.

  29. Linking governance to operations

    • Ensure PV governance minutes reference actions, owners and due dates. Link minutes to CAPA registers and KPI trends.
    • Example: A PV Committee decision to escalate a signal should reference the signal log entry, the risk assessment, and the CAPA.

Governance Considerations

Metrics and Oversight Evidence

Include a standard set of PV metrics in the PSMF evidence package and link them to governance actions:

For each KPI, document the data source, calculation method and frequency of review. Store KPI dashboards and governance meeting minutes in the evidence repository.

Inspection Relevance: Typical Findings and How the PSMF Prevents Them

Inspectors commonly find: - Incomplete vendor listings or absence of contracts demonstrating PV responsibilities. - Outdated organisational charts or absence of delegation evidence. - PSMF text that does not match operational practice. - Missing evidence of CAPA closure. - Poor linkage between governance minutes and actions.

A PSMF that maps every statement to direct evidence, and that the QPPV can navigate under pressure, reduces the likelihood and severity of these findings.

PSMF statement: “Vendor X performs initial case intake and processing under SoW dated 2024-06.”

Evidence links you must include: - Contract: Contract_VendorX_SoW_CaseProcessing_2024-06.pdf (primary). - Delegation: Delegation_Letter_VendorX_2024-06.pdf. - SOP reference: SOP-PV-VENDOR-001 (Vendor Management), SOP-PV-CASE-001 (Case Processing) — include SOP file names. - Operational evidence: VendorX_Audit_Report_2025-11.pdf; KPI_Report_VendorX_Q1_2026.pdf; Sample_ICSRs_from_VendorX_redacted.zip. - Governance evidence: PV_Committee_Minutes_2025-12.pdf referencing the vendor oversight review.

Having those files linked by the section number in the PSMF index allows an inspector to verify the statement in minutes of minutes.

Preparing the QPPV for Inspection Using the PSMF

Key Takeaways

References

  1. EMA Good Pharmacovigilance Practices (GVP) Module I – Pharmacovigilance Systems and Their Quality Systems.
  2. EMA Good Pharmacovigilance Practices (GVP) Module II – Pharmacovigilance System Master File.
  3. EMA Good Pharmacovigilance Practices (GVP) Module III – Pharmacovigilance Inspections.
  4. Regulation (EC) No 726/2004.
  5. Directive 2001/83/EC.
  6. Commission Implementing Regulation (EU) No 520/2012.
  7. EMA Questions and Answers on Pharmacovigilance System Master Files.

Last reviewed: 2026-06-11