Risk-Based Audit Planning in Pharmacovigilance
A pharmacovigilance audit programme cannot examine every process, product, affiliate, vendor and computerised system with equal depth at all times. Risk-based audit planning is the method used to decide where independent assurance is most needed, what should be audited first, and how audit scope and timing should change as the pharmacovigilance system changes.
- Risk-Based Audit Planning in Pharmacovigilance
- Purpose and Regulatory Framework
- Strategic, Tactical and Operational Planning
- Building the Audit Universe
- Defining Auditable Units
- Risk Factors Used in Prioritisation
- Quantitative Scoring: Useful Tool, Not Regulatory Requirement
- Translating Risk Into Audit Priority
- Audit Frequency Is a Consequence of Risk
- Dynamic Re-Planning
- Vendor Audit Prioritisation
- Affiliate and Local-System Prioritisation
- Using Historical Performance
- Illustrative Risk-Prioritisation Example
- Audit Scope Should Follow the Risk Hypothesis
- Auditor Competence and Independence
- Governance of the Audit Plan
- Potential Failure Modes
- Inspection Considerations
- Practical Risk-Based Planning Checklist
- Key Takeaways
- References
- Regulatory Note
Purpose and Regulatory Framework
GVP Module IV — Pharmacovigilance audits (Rev. 1) supports a risk-based approach to pharmacovigilance auditing. It describes strategic, tactical and operational planning and emphasises that audit activities should focus on areas where risk to the pharmacovigilance system and its objectives is greatest.
The core regulatory principle is therefore not that every auditable unit receives a numerical score or is audited within a prescribed calendar cycle. GVP does not mandate a universal five-point risk matrix, fixed factor weights, a three-year audit cycle or annual audits of particular vendors.
Instead, the organisation should be able to explain why its audit strategy is reasonable in light of:
- patient-safety and public-health consequences;
- regulatory obligations;
- complexity and criticality of processes;
- historical performance;
- significant changes;
- outsourced activities;
- previous audits and inspections;
- deviations, CAPAs and compliance trends; and
- other information that affects the likelihood or consequence of control failure.
A documented methodology helps make those decisions consistent and traceable, but the methodology is a means to risk-based judgement rather than the regulatory objective itself.
Strategic, Tactical and Operational Planning
GVP Module IV distinguishes different levels of audit planning.
Strategic audit planning
Strategic planning takes the broadest view of the pharmacovigilance system. It identifies the principal areas that need independent assurance over an appropriate planning horizon and considers the organisation's structure, products, processes, systems, partners and changing risk environment.
Strategic planning answers questions such as:
- Which parts of the pharmacovigilance system carry the greatest potential consequences if they fail?
- Where does the organisation depend heavily on third parties or complex interfaces?
- Which major changes are expected?
- What do prior audits, inspections and compliance data suggest about persistent weaknesses?
- Are emerging risks creating assurance gaps not covered by the existing programme?
Tactical audit planning
Tactical planning converts the broader strategy into a set of audit engagements and priorities. It determines which auditable units should be examined, the relative timing of audits and whether the planned coverage still reflects current risk.
This is where an audit universe and risk-assessment model are commonly used.
Operational planning
Operational planning defines the individual audit: objective, scope, criteria, methods, sampling, resources and logistics. A high-risk area may justify a broad end-to-end audit, whereas a more focused concern may be better addressed through a targeted thematic audit.
The three levels should connect. An individual audit should exist because it serves a risk-based programme objective, not simply because the same audit was performed in the previous year.
Building the Audit Universe
An audit universe is a structured representation of the processes, organisational units, systems and outsourced activities that could be subject to audit. It helps prevent important areas from disappearing from view simply because they are not currently scheduled.
Typical auditable domains include:
- ICSR intake, processing, quality control and submission;
- literature monitoring;
- signal management;
- aggregate reporting;
- RMP and risk-minimisation processes;
- PASS and other post-authorisation studies;
- the PSMF and pharmacovigilance governance;
- QPPV interfaces and oversight processes;
- affiliates and local pharmacovigilance activities;
- vendors and outsourced services;
- safety databases, interfaces and other critical computerised systems;
- training, deviations, CAPA and change control; and
- records management and business continuity where relevant to PV.
The audit universe should reflect the organisation's actual pharmacovigilance system. A company with centralised case processing and multiple affiliates will have a different risk architecture from a company that outsources most operational activity to a small number of strategic vendors.
Defining Auditable Units
The unit of audit should be meaningful enough to assess independently. Units that are too broad can conceal risk; units that are too granular can create an unmanageable audit universe.
For example, "vendors" may be too broad because a call-centre provider, global safety-database host and specialist epidemiology vendor have very different risk profiles. Conversely, treating every minor subcontractor as a separate strategic audit unit may add administrative detail without improving assurance.
A useful auditable unit normally has:
- a definable process or responsibility;
- identifiable ownership or interfaces;
- evidence that can be examined;
- plausible failure modes; and
- a relationship to pharmacovigilance obligations or system objectives.
Risk Factors Used in Prioritisation
Organisations may use qualitative assessment, quantitative scoring or a hybrid method. Commonly useful factors include:
| Risk factor | What it asks |
|---|---|
| Patient-safety impact | If the control fails, could important safety information be missed, delayed or mishandled? |
| Regulatory impact | Could failure cause material non-compliance or inability to meet an obligation? |
| Data integrity | Does the activity create or transform safety-critical data? |
| Complexity and interfaces | Are there many hand-offs, systems, countries or organisations involved? |
| Volume and exposure | Does the process operate at a scale that increases consequence or detectability challenges? |
| Historical performance | What do audits, inspections, deviations and CAPA history show? |
| Change | Has there been a migration, acquisition, reorganisation, new product or major process change? |
| Outsourcing | How dependent is the MAH on an external party, and how visible is performance? |
| Detectability | Would failure be discovered through routine controls before it causes harm or non-compliance? |
No factor carries a universal regulatory weight. The organisation should select factors that reflect its pharmacovigilance system and explain how they influence prioritisation.
Quantitative Scoring: Useful Tool, Not Regulatory Requirement
Numerical scoring can make prioritisation more reproducible, but it can also create false precision. A calculated score of 3.8 is not inherently more regulatory than an evidence-based qualitative conclusion of "high risk."
If a numerical model is used, the organisation should be able to explain:
- what each score means;
- why factors were chosen;
- whether weights reflect genuine differences in consequence;
- what evidence supports the score;
- how thresholds were set; and
- when expert judgement can override the calculated result.
The audit plan should not become captive to arithmetic when new evidence clearly changes risk.
Translating Risk Into Audit Priority
Risk assessment becomes useful only when it changes audit decisions. The link between the assessed risk and the planned assurance activity should therefore be explicit.
A higher-risk auditable unit may justify:
- earlier audit timing;
- broader scope;
- deeper sampling;
- specialist auditor expertise;
- examination of connected interfaces; or
- follow-up activity after remediation.
A lower-risk unit may reasonably receive less frequent or more focused assurance when other controls provide sufficient visibility.
The important point is proportionality. A fixed rule such as "all critical vendors are audited every 12 months" may look rigorous but can be less risk-based than a model that considers current performance, prior audit results, major change, other monitoring and the consequences of failure.
Audit Frequency Is a Consequence of Risk
GVP Module IV does not establish universal annual, biennial or three-year audit frequencies for MAH pharmacovigilance processes or vendors.
Frequency should follow the risk assessment and assurance needs. An area may need earlier re-audit after a serious deficiency or major system change. Another high-impact but stable area may be adequately controlled through a combination of periodic audit and strong continuous monitoring. A lower-risk area may be audited less often unless risk information changes.
The organisation should be able to explain why the timing is appropriate now. Simply stating that an audit is "due" because of a historical cycle does not demonstrate that current risk was considered.
Dynamic Re-Planning
Risk-based planning must be capable of changing during the planning period. Important triggers can include:
- regulatory inspection findings;
- critical or recurring audit findings;
- significant CAPA failure;
- safety-database migration or replacement;
- acquisition, merger or organisational restructuring;
- transfer of pharmacovigilance activities between vendors;
- deterioration in reporting or quality metrics;
- important safety issues revealing process weakness;
- changes in product portfolio or geographic scope;
- business-continuity events; or
- evidence that an anticipated risk has materially decreased.
A dynamic plan does not mean constantly changing the audit schedule without discipline. Material changes should be documented with their rationale so that the final audit programme remains reconstructable.
Vendor Audit Prioritisation
Vendors should be assessed according to the pharmacovigilance activities they perform and the consequences if those activities fail.
A useful vendor-risk assessment may consider:
- whether the vendor receives or processes safety information;
- whether it operates a critical pharmacovigilance system;
- volume and geographic scope;
- degree of subcontracting;
- contractual complexity and interface quality;
- prior performance, deviations and CAPA history;
- recent or planned system changes;
- data integrity and availability;
- business continuity; and
- how much effective oversight is available through other mechanisms.
Audit is one assurance method within vendor oversight. Routine performance monitoring, reconciliation, governance meetings, issue escalation and change control also generate evidence. The decision to audit should consider what uncertainty remains after those controls.
Affiliate and Local-System Prioritisation
Affiliates can carry different risk according to local regulatory requirements, product exposure, reporting volumes, organisational stability and the complexity of interfaces with the global pharmacovigilance system.
Risk may increase where:
- several local intake channels exist;
- responsibilities are split between affiliates and distributors;
- local legislation creates distinct reporting requirements;
- staff turnover is high;
- previous reconciliations identified missed cases;
- the affiliate recently changed organisation or systems; or
- local activities are poorly visible to central governance.
A regional rotation can be an efficient operational approach, but geography alone should not determine priority.
Using Historical Performance
Historical audit and inspection data are powerful risk inputs, but they require interpretation.
A previous major finding that has been effectively corrected may still justify targeted follow-up, but it should not automatically keep the auditable unit permanently at the highest risk level. Conversely, absence of previous findings is weak reassurance if the process has never been audited, has changed substantially, or is difficult to monitor.
Historical inputs can include:
- prior audit findings;
- regulatory inspection outcomes;
- repeat findings;
- CAPA effectiveness results;
- deviations and incidents;
- compliance metrics;
- complaints or reconciliation failures; and
- known control weaknesses.
The question is not "how many findings occurred?" but what do they tell us about current control reliability?
Illustrative Risk-Prioritisation Example
The following is an illustrative model, not a GVP-prescribed scoring system.
Suppose an MAH is comparing three potential audits:
- a global ICSR intake process after a major system migration;
- a mature literature-screening vendor with stable performance; and
- a recently acquired affiliate with unclear local-to-global reconciliation.
The ICSR process has high patient-safety and regulatory consequences, high change exposure and large volume. The acquired affiliate has lower overall volume but high uncertainty, weak visibility and a new interface. The literature vendor is important but stable, with recent satisfactory audit evidence and strong ongoing monitoring.
A defensible plan might therefore prioritise the ICSR process and affiliate before repeating the literature-vendor audit. The decision does not require a universal numerical threshold. It requires documented reasoning showing why the first two currently represent greater assurance gaps.
If the organisation uses a numerical model, the same conclusion can be supported by scores. The numbers should make the reasoning reproducible, not replace it.
Audit Scope Should Follow the Risk Hypothesis
Risk-based planning affects not only whether an audit occurs but also what the audit examines.
For the migrated ICSR system, the risk hypothesis may concern case loss at interfaces, incorrect clock starts or transmission failures. A generic audit covering every case-processing SOP equally would dilute attention. A targeted audit could instead follow cases through source intake, migration logic, reconciliation, workflow configuration and regulatory submission.
For a vendor with repeated change-notification failures, the audit may focus on governance, subcontracting, change control and escalation rather than re-testing unrelated operational details.
A well-designed scope therefore translates the risk assessment into testable audit objectives.
Auditor Competence and Independence
Risk-based planning also identifies when specialist competence is required. Auditing a pharmacoepidemiology study, safety database migration or complex signal-detection system may require expertise beyond general pharmacovigilance auditing.
The audit function should consider whether the available team has appropriate knowledge and independence and whether specialist or external support is needed.
Competence should be proportionate to the audit objective. There is no universal requirement that every audit team contain the same functions or qualifications.
Governance of the Audit Plan
The audit plan should be appropriately authorised within the organisation's quality system, but GVP does not prescribe one universal approval chain. Senior management and relevant pharmacovigilance leadership should receive information necessary to understand the assurance strategy, while the audit function retains appropriate independence.
The QPPV may provide risk information and should have visibility of significant assurance gaps, but universal QPPV sign-off of every audit plan is not a generic EU requirement.
For the QPPV interface, see [[qppv-and-audit-oversight]].
Potential Failure Modes
The following are illustrative failure modes, not published inspection findings.
| Failure mode | Why it weakens audit planning | Better approach |
|---|---|---|
| Using a fixed three-year cycle for every auditable unit | Ignores current risk and change | Set timing according to documented assurance need |
| Applying numerical scoring without evidence | Creates false precision | Link each assessment to current data and rationale |
| Treating calculated score as unchallengeable | Arithmetic may lag real-world risk | Permit documented expert judgement and re-prioritisation |
| Auditing every high-risk vendor annually by policy | Calendar can replace actual risk assessment | Consider criticality, performance, change and other oversight evidence |
| Keeping the plan unchanged after a major system migration | Assurance no longer reflects current risk | Trigger re-assessment when material changes occur |
| Counting prior findings without assessing significance | Finding numbers can misrepresent control reliability | Examine recurrence, scope, consequence and CAPA effectiveness |
| Defining an audit universe so broadly that risks disappear | Large categories obscure distinct interfaces | Use auditable units that have meaningful processes and failure modes |
| Defining hundreds of trivial auditable units | Administrative burden can overwhelm strategic judgement | Use proportionate granularity |
| Auditing familiar areas because they are easy to schedule | Creates assurance in low-uncertainty areas while high-uncertainty areas remain untested | Allocate resources to the most important assurance gaps |
Inspection Considerations
Inspectors may review the pharmacovigilance audit programme to understand whether independent assurance is genuinely risk-based.
Relevant inspection questions could include:
- How was the audit universe constructed?
- Which information sources are used to assess risk?
- Why were particular audits selected or deferred?
- How do previous findings and CAPA effectiveness affect priority?
- What happens when major organisational or system changes occur mid-cycle?
- How are outsourced activities incorporated into audit planning?
- Can the organisation explain differences in audit frequency between similar vendors or affiliates?
- Is the audit scope linked to the risk that justified the engagement?
- How are audit-plan changes documented?
- Is auditor competence appropriate to specialised high-risk topics?
The objective is to demonstrate reasoned prioritisation and traceability, not to present a complex scoring spreadsheet for its own sake.
Practical Risk-Based Planning Checklist
The following checklist is recommended operational practice.
Audit universe
- Does the universe reflect the actual pharmacovigilance system, including important outsourced activities and computerised systems?
- Are auditable units defined at a useful level of granularity?
- Are new vendors, affiliates, systems and processes added when the system changes?
Risk assessment
- Are patient-safety and regulatory consequences considered explicitly?
- Are historical performance, change and detectability included where relevant?
- Is the evidence supporting each risk judgement current?
- If numerical scoring is used, are factor definitions and thresholds understood?
- Can expert judgement override a score when documented evidence supports it?
Prioritisation and scope
- Is there a clear link between assessed risk and audit timing?
- Does audit scope test the risk hypothesis rather than reproduce a generic checklist?
- Are specialist competence needs identified before the audit is scheduled?
- Are high-risk interfaces between functions or organisations visible in the plan?
Dynamic management
- Are there triggers for reassessment after major change, inspection findings or CAPA failure?
- Are material changes to the plan documented with rationale?
- Does completed audit evidence feed back into future risk assessment?
Governance
- Is the audit strategy authorised through the organisation's quality system without compromising audit independence?
- Do the QPPV and relevant senior management have visibility of significant assurance gaps?
- Can the organisation reconstruct why each major audit decision was made?
Key Takeaways
Risk-based audit planning is the mechanism by which limited audit resources are directed toward the areas where independent assurance matters most.
GVP Module IV supports strategic, tactical and operational planning but does not prescribe universal numerical risk models, factor weights, three-year cycles or fixed vendor-audit frequencies.
A defensible audit plan links current evidence about patient-safety impact, regulatory consequence, complexity, historical performance, change, outsourcing and detectability to decisions about audit priority and scope.
The plan must be dynamic. Major system changes, inspections, CAPA failures and new performance information can justify re-prioritisation before the original planning period ends.
Quantitative scoring can improve consistency but should not create false precision. The quality of the evidence and reasoning remains more important than the sophistication of the arithmetic.
References
- European Medicines Agency. Guideline on good pharmacovigilance practices (GVP) Module IV — Pharmacovigilance audits (Rev. 1). EMA/228028/2012 Rev. 1. https://www.ema.europa.eu/en/documents/scientific-guideline/guideline-good-pharmacovigilance-practices-gvp-module-iv-pharmacovigilance-audits-rev-1_en.pdf
- European Medicines Agency. Guideline on good pharmacovigilance practices (GVP) Module I — Pharmacovigilance systems and their quality systems. EMA/541760/2011.
- European Medicines Agency. Guideline on good pharmacovigilance practices (GVP) Module III — Pharmacovigilance inspections. EMA/119871/2012 Rev. 1.
- European Union. Commission Implementing Regulation (EU) No 520/2012, consolidated version current at 12 February 2026.
- European Union. Directive 2001/83/EC, as amended.
- European Union. Regulation (EC) No 726/2004, as amended.
Regulatory Note
This article distinguishes the risk-based audit principles in GVP Module IV from organisation-specific scoring models, audit cycles and governance structures. As of 8 September 2026, GVP Module IV Rev. 1 remains EMA's published pharmacovigilance-audit module. EMA has indicated that GVP modules are being reviewed following Commission Implementing Regulation (EU) 2025/1466; current guidance should therefore be checked before establishing or materially revising a live audit programme.