PSMF Vendor and SDEA Management

A practical guide to vendor inventories, outsourcing oversight, SDEA governance and inspection readiness within the PSMF.

Audio Lesson 12 min

PSMF Vendor and SDEA Management

Introduction

Modern pharmacovigilance systems rarely operate entirely in-house.

Many organisations outsource activities such as:

As outsourcing increases, governance becomes more complex. Regulators expect the Pharmacovigilance System Master File (PSMF) to describe not only what is performed but who performs it and how the Marketing Authorisation Holder (MAH) retains oversight and accountability.

This article explains how to represent outsourced arrangements within the PSMF, how to govern Safety Data Exchange Agreements (SDEAs), and how to prepare inspection‑ready evidence. An inspection‑ready annex is included combining: a vendor‑inventory template, a detailed SDEA clause checklist, and an oversight evidence checklist to elevate the PSMF to textbook and inspection-ready quality.

A Fundamental Regulatory Principle

One of the most important principles in pharmacovigilance is:

Outsourcing activities does not outsource responsibility.

The MAH remains accountable for compliance regardless of delegation. This principle underpins expectations in EMA GVP Module I, GVP Module II (PSMF), and pharmacovigilance inspection guidance. Inspectors will assess whether the MAH has established and maintained effective control and oversight over outsourced activities.

Why Vendors Matter Within the PSMF

The PSMF aims to provide a complete, current description of how the PV system operates. If a vendor performs part of that system, inspectors need visibility regarding:

Without this information the PSMF is incomplete and the MAH cannot demonstrate effective oversight.

Vendor Inventories: purpose and structure

A vendor inventory is often one of the most important annexes of the PSMF. Its purpose is to provide clear, searchable visibility into outsourced pharmacovigilance activities and associated governance.

A mature vendor inventory contains both administrative data and quality/risk information and is maintained as a live document under document control. Common practical features include:

Consistent field definitions and completion rules are essential to avoid ambiguity during inspections.

Core fields and definitions (summary)

Many organisations include the fields shown below. Detailed template and completion guidance are provided in the inspection‑ready annex.

Field Purpose
Vendor legal name Official contracting party
Trading name / DBA Operational name if different
Country(ies) of operation Location(s) where PV activities are performed
PV activities performed Short standardized activity codes (e.g., CASE_PROC, LIT_MON)
Products covered MAH products or product groups
Criticality / risk rating Risk-based category (Critical/Major/Minor)
Contract type & reference SDEA, Master Service Agreement (MSA), SLA, statement of work
SDEA present? Yes/No/NA and version/date
Contract status Active/Expired/Terminated/Transitioning
Contract effective & review dates Date fields for monitoring renewals
Oversight owner (MAH) PV lead responsible for oversight and documentation
Key vendor contacts PV operations contact(s) at vendor
Audit status Last audit date, type (on-site/remote/desk), and findings status
KPIs & performance indicators Link or summary of agreed KPIs
Escalation pathway QPPV/Head of PV contact and response time commitments
Evidence links Links to contract, SDEA, audit report, KPI reports, CAPAs

Which vendors should be included?

Include vendors performing activities capable of affecting pharmacovigilance compliance or patient safety. When assessing inclusion, consider whether the activity may:

Examples: case processing providers, literature monitoring vendors, safety database vendors, call-centres, medical information providers, local affiliate PV providers, marketing authorisation management support.

Document rationale for exclusion of vendors (e.g., purely logistics vendors with no PV interaction).

Vendor classification and risk assessment

A risk-based classification helps prioritise oversight effort. Typical approach:

Risk assessment should be documented and revisited when activities change (product lifecycle, geographic expansion), and should feed into audit frequency, SLA rigor, and escalation expectations.

SDEAs: purpose and regulatory context

Safety Data Exchange Agreements (SDEAs) formally define the exchange, responsibilities, timing, and handling of safety information between parties. EMA GVP and inspection guidance emphasise that SDEAs are necessary where safety information is exchanged.

Key regulatory elements expected in SDEAs include:

SDEAs do not replace underlying contractual arrangements (MSA/SLA) but provide the PV-specific interface.

Oversight responsibilities and governance

Vendor management is an ongoing governance responsibility, not a one-off exercise. A robust governance model includes:

Governance should be documented in a PV Vendor Management SOP and reflected within the PSMF cross-references.

Practical oversight activities and artifacts

Routine oversight commonly includes:

Preserve evidence in a controlled, searchable structure with access controls and an index for inspection.

How inspectors assess vendor oversight

Inspectors commonly request:

Inspectors will look for alignment across documents—fields and statements in the PSMF should match SDEAs, the vendor inventory, and oversight records. Discrepancies are a common cause of adverse findings.

Common inspection findings (condensed)

Mitigations include keeping a curated inspection pack and an index mapped to the PSMF.

Key takeaways

References

  1. EMA Good Pharmacovigilance Practices (GVP) Module I – Pharmacovigilance Systems and Their Quality Systems.
  2. EMA Good Pharmacovigilance Practices (GVP) Module II – Pharmacovigilance System Master File.
  3. EMA Good Pharmacovigilance Practices (GVP) Module III – Pharmacovigilance Inspections.
  4. Regulation (EC) No 726/2004.
  5. Directive 2001/83/EC.
  6. Commission Implementing Regulation (EU) No 520/2012.
  7. EMA Questions and Answers on Pharmacovigilance System Master Files.

Annex A — Inspection‑Ready Annex: Vendor Inventory Template, SDEA Clause Checklist, and Oversight Evidence Checklist

This annex is designed to be included in the PSMF (or referenced as a controlled attachment) and to serve as the single source of truth for inspectors and internal governance. It contains three parts:

Use this annex as a working tool: maintain the master file with version control, and create inspection packs that extract the current snapshot and supporting evidence.


Part 1 — Vendor Inventory Template (inspection‑ready)

Instructions: - Maintain as a single controlled spreadsheet (CSV/Excel) under document control and link each row to the folder(s) containing supporting documents. - Each field is mandatory unless indicated as optional; provide "NA" where not applicable. - Update on a defined cadence (recommended: monthly review for critical vendors; quarterly for major; annually for minor), and whenever a contractual or operational change occurs. - Maintain an amendment log and date stamp each change. - Provide a printable PSMF annex snapshot for inspections (PDF) together with an index of linked evidence.

Template fields (column headings) and completion guidance:

  1. Vendor_ID
  2. Unique identifier (e.g., V001) used across systems.
  3. Vendor_Legal_Name
  4. Official name as per contract.
  5. Vendor_Trading_Name (optional)
  6. Vendor_Address_Country
  7. Primary country(ies) where PV activities take place.
  8. PV_Activity_Code(s)
  9. Standardised codes (e.g., CASE_PROC, LIT_MON, DB_HOST, CALL_CTR, MI_SVC, AGG_REP, SIGNAL_SUPPORT).
  10. PV_Activities_Description
  11. Concise description of activities and interfaces (e.g., "Case receipt and data entry into vendor DB; transmission to MAH via secure SFTP").
  12. MAH_Product_Scope
  13. Products covered (list or "All MAH products" if applicable).
  14. Contract_Type
  15. SDEA/MSA/SLA/Other (specify).
  16. Contract_Reference
  17. Contract number and version.
  18. Contract_Effective_Date
  19. Contract_Expiry_or_Renewal_Date
  20. SDEA_Present (Y/N/NA)
  21. SDEA_Version_Date
  22. Data_Transfer_Method
  23. (e.g., E2B(R3) XML via secure messaging, encrypted SFTP, manual PDF/email) — include format details.
  24. Acknowledgement_Mechanism
  25. Receipt ack required? (Y/N) Mechanism (automated, manual).
  26. Criticality_Rating
  27. Critical/Major/Minor and brief justification (one line).
  28. Oversight_Owner (Name & Role)
  29. MAH PV contact responsible for oversight.
  30. Key_Vendor_Contacts
  31. Name, role, email, phone (PV lead at vendor).
  32. SLA/KPI_Link
  33. Link or reference to KPI schedule and thresholds.
  34. Last_Audit_Date
  35. Date and type (on-site/remote/desk).
  36. Audit_Findings_Status
  37. Acceptable/Minor_CAPA/Open_CAPA/Pending (brief summary).
  38. Last_Governance_Meeting
  39. Date and key decisions (one-line summary).
  40. Recent_Performance_Notes
  41. Summary (e.g., delays in case transmission, recurring data format issues).
  42. Escalation_Pathway
  43. QPPV contact and escalation timelines; internal escalation flow (link).
  44. Data_Privacy_Jurisdiction_Notes
  45. Cross-border transfer considerations and restrictions.
  46. Business_Continuity_and_Exit_Plans
  47. Link or status (available/under_development/NA).
  48. Evidence_Links_Index
  49. Link(s) to contract, SDEA, audit report, KPI reports, CAPA evidence, change notifications.
  50. Last_Inventory_Review_Date
  51. Next_Scheduled_Review_Date
  52. Comments
  53. Free text for short notes.

Practical implementation tips: - Build a dashboard view for the QPPV showing critical vendors, upcoming renewals, and overdue audits. - Integrate procurement systems or GRC (governance, risk and compliance) tools where available to reduce manual effort. - Ensure vendor contact details are validated at onboarding and at each governance meeting.


Part 2 — SDEA Clause Checklist (detailed, inspection‑ready)

For each SDEA included in the PSMF, provide a checklist indicating whether the clause exists, the SDEA clause reference (page/section), practical expectations for content, rationale (regulatory or inspection relevance), and typical evidence inspectors request.

Checklist format (row per clause):

  1. Parties and Scope
  2. Expected: Legal parties named; scope defines activities covered by the SDEA.
  3. Rationale: Clarity on responsibility boundaries; aligns with contract.
  4. Evidence: Signed SDEA, cross-reference to MSA/SOW.

  5. Definitions and Interpretations

  6. Expected: Clear definitions for ICSR, SUSAR, expedited reportable events, follow-up information.
  7. Rationale: Consistent interpretation avoids under/over-reporting.
  8. Evidence: SDEA text; examples of applied definitions in case handling.

  9. Regulatory Responsibilities and Allocation

  10. Expected: Explicit allocation of MAH vs vendor responsibility (e.g., who assesses seriousness, expectedness, causality, and final submission responsibility).
  11. Rationale: Delegation cannot transfer regulatory obligation.
  12. Evidence: SDEA clauses, sample case where the delegation was applied, QPPV sign-off.

  13. Reporting Requirements and Timelines

  14. Expected: Timelines for vendor to transmit suspected ICSRs to MAH (e.g., within X hours of receipt), MAH transmission to authorities, and any expedited reporting obligations.
  15. Rationale: Timeliness is key for compliance.
  16. Evidence: Transmission logs, timestamped email or system acknowledgements, KPI reports showing timeliness.

  17. Data Format and Transfer Mechanisms

  18. Expected: Specified format (E2B(R3), CSV, PDF), secure transfer method, templates, validation checks.
  19. Rationale: Prevents data loss and format-related processing delays.
  20. Evidence: Technical data maps, sample transmitted files, validation error logs.

  21. Receipt Acknowledgement and Tracking

  22. Expected: Mechanism for acknowledgement and reconciliation (automated receipt ack or manual).
  23. Rationale: Ensures data receipt and supports audit trail.
  24. Evidence: Acknowledgement records, reconciliation documentation.

  25. Follow‑up Information and Responsibilities

  26. Expected: Process and timelines for vendor to provide follow-up data and assigned responsibilities for initiating and providing it.
  27. Rationale: Completeness of ICSRs depends on follow-up.
  28. Evidence: Examples of follow-up transmissions and timelines.

  29. Duplicate Handling and Recordkeeping

  30. Expected: Process to identify and manage duplicate ICSRs, include deduplication responsibilities.
  31. Rationale: Avoids duplicate regulatory reports.
  32. Evidence: Deduplication procedures, sample case audit trail.

  33. Urgent Escalation Pathways

  34. Expected: Defined escalation triggers (e.g., death, cluster events, product quality linked to safety), and contact details with agreed response times.
  35. Rationale: Rapid communication for urgent safety issues.
  36. Evidence: Escalation logs, evidence of escalation during incidents.

  37. Signal Detection and Aggregate Reporting Interfaces

    • Expected: Requirements for vendor to notify MAH of patterns or aggregated safety data and guidance on what constitutes a signal.
    • Rationale: Interfaces support timely signal detection.
    • Evidence: Signal notification examples, minutes of discussions on aggregated observations.
  38. Audit and Inspection Rights

    • Expected: MAH right to audit vendor (on-site/remote), vendor obligations to support regulatory inspections, and notification period.
    • Rationale: Demonstrates control and verification ability.
    • Evidence: Audit reports, inspection assistance logs, executed audit scope.
  39. Change Management and Notification

    • Expected: Requirement for vendor to notify MAH of material changes (staff, systems, processes) with predefined notice periods and assessment obligations.
    • Rationale: Changes can materially affect compliance.
    • Evidence: Change notifications, impact assessments, acceptance or mitigation records.
  40. Data Protection and Confidentiality

    • Expected: Data privacy clauses covering cross-border transfers, data subjects' rights, and encryption/protection measures.
    • Rationale: Legal compliance and patient confidentiality.
    • Evidence: Data transfer agreements, encryption details, DPA (Data Processing Agreement).
  41. Business Continuity and Disaster Recovery

    • Expected: Continuity plans, recovery time objectives (RTO), and failover arrangements for PV-critical systems.
    • Rationale: Maintains reporting capability during outages.
    • Evidence: BCP/DR documents, test reports, incident response logs.
  42. Termination and Exit Management

    • Expected: Exit transition arrangements, data transfer and format on termination, timelines and responsibilities.
    • Rationale: Ensures continuity of PV obligations during vendor change.
    • Evidence: Exit plan, executed data transfer records in past transitions.
  43. Training and Personnel Competency

    • Expected: Vendor staff training requirements, record retention, and change control when key staff leave.
    • Rationale: Competence is critical for correct case handling.
    • Evidence: Training matrices, sample training records for staff handling PV.
  44. Liability and Indemnity (PV-relevant aspects)

    • Expected: Clauses clarifying liabilities in relation to PV tasks (where possible within law).
    • Rationale: Aligns incentives and clarifies responsibilities.
    • Evidence: Contract clauses and risk assessments.
  45. Record Retention and Access Rights

    • Expected: Retention periods consistent with MAH obligations and inspection rights for inspectors.
    • Rationale: Evidence availability during inspection.
    • Evidence: Retention schedule and archived records retrieval logs.
  46. Performance Metrics and KPIs

    • Expected: Agreed KPIs for timeliness, completeness, quality; reporting cadence; remedy provisions for KPI failures.
    • Rationale: Enables objective oversight.
    • Evidence: KPI reports, SLA breach notices, CAPA records.
  47. Applicable Law and Dispute Resolution (PV impact)

    • Expected: Jurisdiction and dispute resolution details, including interim measures to ensure PV continuity during disputes.
    • Rationale: Avoids interruptions to PV reporting.
    • Evidence: Contract text, contingency plans invoked during disputes.

For each clause, the MAH should store a checklist indicating: Clause present? (Y/N); SDEA location (page/section); Last review date; Evidence example(s) (with links); and any open actions (e.g., clause to be amended).

Practical implementation: - During SDEA drafting, map each clause to internal SOPs and to responsibilities in the vendor inventory. - Where SDEAs cross-reference system specifications, include a technical annex to the SDEA and keep versioned specifications with the vendor.

Inspection relevance: - Inspectors will look for explicit SDEA clauses for key items (timelines, data formats, audit rights). The absence of clauses or weak language is a frequent finding. Provide a redacted copy for inspection early in the process or as requested.


Part 3 — Oversight Evidence Checklist (inspection‑ready)

This checklist describes the evidence that should be retained, the recommended frequency of generation/review, and practical guidance on sample selection for inspection. Store evidence with unique identifiers referenced from the vendor inventory Evidence_Links_Index.

  1. Signed SDEA and Related Contracts
  2. Evidence: Signed SDEA, MSA, SLA, statements of work.
  3. Frequency: At contract signing and maintained current.
  4. Inspection sample: Current signed SDEA for critical vendors and the SDEA in force at time of last audit.

  5. Vendor Inventory Snapshot (current)

  6. Evidence: Exported PDF of the vendor inventory with version header.
  7. Frequency: Current snapshot for each inspection; monthly archived snapshots recommended.
  8. Inspection sample: Current and the snapshot at the time of most recent major change.

  9. Audit Reports and CAPA Documentation

  10. Evidence: Audit plan, audit report, corrective action plan, evidence of CAPA closure and effectiveness checks.
  11. Frequency: Audit frequency based on risk (critical: every 1–2 years; major: 2–3 years; minor: as needed).
  12. Inspection sample: Most recent audit report and evidence of CAPA closure for a critical vendor.

  13. KPI Reports and Performance Dashboards

  14. Evidence: KPI datasets, dashboards, and governance meeting minutes showing KPI review and decisions.
  15. Frequency: KPI reporting cadence as per SLA (monthly recommended for critical).
  16. Inspection sample: Last 6–12 months of KPI data and minutes showing trend review.

  17. Transmission Logs and ICSR Examples

  18. Evidence: Secure transfer logs, E2B files, system audit trails, timestamped receipts, reconciliation reports. Provide redacted sample ICSRs demonstrating the transmission and acknowledgement chain.
  19. Frequency: Continuous; maintain rolling archive.
  20. Inspection sample: 3–5 redacted ICSRs spanning different scenarios (initial receipt, follow-up, expedited) with full audit trail.

  21. Governance Meeting Minutes

  22. Evidence: Minutes from vendor governance meetings, including action items and assigned owners.
  23. Frequency: Per governance schedule (monthly/quarterly).
  24. Inspection sample: Last 6 months for critical vendors, last 12 months for major vendors.

  25. Change Notifications and Impact Assessments

  26. Evidence: Notifications of vendor system/process changes, MAH impact assessments, mitigation actions.
  27. Frequency: As changes occur.
  28. Inspection sample: Any critical change in the last 24 months and the MAH assessment of its PV impact.

  29. Incident and Escalation Records

  30. Evidence: Records of PV incidents escalated to MAH, timelines of response, decisions taken.
  31. Frequency: As incidents occur.
  32. Inspection sample: All escalations meeting the SDEA urgent criteria in the past 24 months.

  33. Business Continuity and Disaster Recovery Tests

  34. Evidence: BCP/DR plans, test reports and outcomes demonstrating failover for PV-critical functions.
  35. Frequency: Annual tests recommended.
  36. Inspection sample: Most recent test report and any resulting action plans.

  37. Staff Training and Competency Records

    • Evidence: Training matrices, completed training records for staff handling PV matters, and competency assessments.
    • Frequency: Onboarding and periodic refresher (annual or as per SOP).
    • Inspection sample: Training records for staff involved in sampled ICSRs.
  38. Data Privacy and Transfer Agreements

    • Evidence: Data Processing Agreements, legal basis for transfers (e.g., SCCs), evidence of consent or anonymisation where required.
    • Frequency: When transfers arise or contracts are renewed.
    • Inspection sample: Relevant DPAs for vendors transferring data across jurisdictions.
  39. Exit and Transition Plans (where applicable)

    • Evidence: Exit plan, recent successful data handover evidence, migration validation.
    • Frequency: At contract termination or vendor change.
    • Inspection sample: Most recent executed exit plan or migration evidence if a vendor has been replaced.
  40. Documentation Control Evidence

    • Evidence: Document control records showing versioning, author, approver, and distribution of SDEA, SOPs, and inventory.
    • Frequency: On document change.
    • Inspection sample: Version history for the SDEA and the vendor inventory.
  41. QPPV Oversight Evidence

    • Evidence: QPPV declarations, approvals, or meeting notes indicating QPPV awareness of vendor arrangements and critical issues.
    • Frequency: Periodic review and after critical incidents.
    • Inspection sample: QPPV sign-off on inventory or minutes showing QPPV involvement in oversight decisions.
  42. Reconciliation and Quality Control Checks

    • Evidence: Reconciliation reports between vendor and MAH databases (case counts, fields mapped) showing resolution of discrepancies.
    • Frequency: Regular (monthly for critical).
    • Inspection sample: Last 6 reconciliations and evidence of resolution for discrepancies.

Practical guidance for inspection packs: - Prepare a zipped inspection pack for each critical vendor containing: vendor inventory row PDF, signed SDEA and contract, last audit report and CAPA evidence, KPI reports for last 12 months, 3 redacted ICSRs with full transmission logs, governance minutes for past 12 months, and BCP/DR evidence. - Maintain an index file (PDF) mapping each item to its location within the PSMF annex and internal repositories. - Ensure redaction retains critical metadata (timestamps, case IDs if internal) while masking personal identifiers as required.

Retention and retrieval: - Align retention with applicable national requirements for PV records, and ensure the ability to retrieve evidence within the timeline inspectors may request (often short notice). A 24–72 hour retrieval capability for critical vendor packs is recommended.


Governance and Implementation Considerations


End of Annex A.

Last reviewed: 2026-06-11