RMP Governance and Version Control

A practical guide to RMP governance, document ownership, change control, global-to-local management and regulatory expectations.

Audio Lesson 11 min

RMP Governance and Version Control

Introduction

Risk Management Plans are among the most complex pharmacovigilance documents maintained throughout the lifecycle of a medicinal product. Unlike many regulatory documents, RMPs evolve continuously as new safety information becomes available and as regulatory obligations change.

A single product may have multiple related risk management documents across different jurisdictions and regulatory procedures. Updates may be triggered by signal assessments, study results, product information changes, new indications or regulatory requests.

Effective governance and version control are therefore essential. Without them, organisations may struggle to maintain consistency, implement changes appropriately or demonstrate regulatory compliance.

Why Governance Matters

Governance provides the framework through which RMP decisions are reviewed, approved and implemented.

The objective is to ensure that:

Governance is particularly important because RMP decisions frequently affect pharmacovigilance activities, risk minimisation measures and benefit-risk evaluation.

Governance Objectives

A mature governance framework should support:

The goal is not administrative control for its own sake. The goal is to ensure that risk management activities remain accurate, current and defensible.

RMP Ownership and Organisational Roles

Ownership should be defined clearly.

Different organisations allocate responsibilities differently, but ownership commonly involves collaboration among:

The governance framework should identify:

Ambiguity regarding ownership is a common source of lifecycle management problems.

Global and Local Ownership Models

Large multinational organisations frequently operate multiple ownership layers. A typical structure:

Global Core RMP Owner ↓ Regional RMP Leads ↓ Local Affiliates

This structure allows global consistency while supporting local regulatory obligations. Governance must explicitly define which version is authoritative for regulatory submissions, and how local adaptations are created, approved and archived.

Governance Committees and Decision Thresholds

Many organisations review significant RMP changes through governance committees such as:

Use defined decision thresholds to determine committee escalation. Typical thresholds include:

Committees provide documented rationale and senior oversight for significant changes. Minutes, consistent attendance records, and explicit decisions with action owners are inspection focal points.

Relationship to Signal Management and Product Information

Signal outcomes and product information changes are primary triggers for RMP updates. Governance must demonstrate a formal interface with signal management and regulatory labelling processes, including:

Inspectors often request the pathway from signal to RMP update and expect to see impact assessments and timelines.

Version Control Principles

Version control ensures the organisation can identify:

A robust versioning system prevents conflicting content across jurisdictions and supports inspection readiness.

Key technical requirements for systems used to manage RMPs:

Change Management and Traceability

Change control should be trigger-based, documented and auditable. Each change must be traceable from trigger through impact assessment, decision, implementation, regulatory submission (if applicable) and archive.

Typical triggers include:

For inspection readiness, organisations should retain:

Regulatory Context

Key regulatory expectations and references include:

These documents set expectations for content, lifecycle management and inspection-ready documentation. Inspectors increasingly expect explicit demonstration of governance, traceability and oversight.

Inspection Focus Areas

Inspectors commonly review:

Failures in these areas frequently result in findings and corrective action plans.

Characteristics of Mature Governance Systems

Mature RMP governance demonstrates:

Appendix: Inspection‑Ready Change Control Pack for RMPs (single consolidated appendix)

This appendix is an inspection‑ready, single-pack resource designed to be retained with each RMP master file. It contains a practical change-control checklist, an actionable RACI matrix, a versioning convention table, and a sample change log that demonstrates traceability from trigger to approval and archive. Organisations may adapt role titles to local nomenclature but should preserve the governance concepts and traceability features.

A. Change-Control Checklist (Inspection‑Ready)

Use this checklist as part of every RMP update. Retain completed items as evidence.

  1. Identification and Metadata
  2. [ ] Document ID (unique, global)
  3. [ ] Current version number and effective date
  4. [ ] Product name, MAH/holder, company code
  5. [ ] Document owner and contact details
  6. Inspection relevance: Inspectors check metadata to confirm authoritative version.

  7. Trigger Documentation

  8. [ ] Source of change (signal record, study report, regulatory letter, PI change notice)
  9. [ ] Date of trigger
  10. [ ] Link to original documents (attachments or hyperlinks in DMS)
  11. Inspection relevance: Demonstrates why the change was initiated.

  12. Impact Assessment

  13. [ ] Completed RMP impact assessment form (standard template)
  14. [ ] Determination of affected sections (safety concerns, PV activities, RMMs)
  15. [ ] Local impact matrix (list of affected affiliates/jurisdictions)
  16. [ ] Need for additional studies or commitments flagged
  17. Practical detail: Use a standard risk-impact scoring (e.g., likelihood Ă— consequence) to prioritise speed of response.

  18. Drafting and Change Tracking

  19. [ ] Draft created in controlled authoring environment
  20. [ ] Tracked changes retained (redline vs clean)
  21. [ ] Cross-reference table updated (RMP sections ↔ PI changes ↔ study results)
  22. Inspection relevance: Inspectors expect to see how content evolved.

  23. Stakeholder Review

  24. [ ] Scientific review completed (Safety Physician / Medical Lead)
  25. [ ] PV review completed (Global Safety)
  26. [ ] Regulatory review (Global/Regional)
  27. [ ] Legal/Compliance review (if required)
  28. [ ] QPPV informed and/or approval obtained
  29. Practical detail: Set review timelines (e.g., 5–10 working days for routine changes, shorter for urgent safety issues).

  30. Governance and Approval

  31. [ ] Governance committee approval (when threshold met) with minutes
  32. [ ] Sign-off by nominated approvers (electronic signature timestamped)
  33. [ ] Approval rationale documented
  34. Inspection relevance: Approval evidence must be traceable and stored.

  35. Implementation and Communication

  36. [ ] Global implementation plan (who, what, when)
  37. [ ] Local implementation instructions for affiliates
  38. [ ] Regulatory submission plan (e.g., EU-RMP via EVWeb/eSubmission, eCTD dossier)
  39. [ ] Communications log (emails to affiliates, training records)
  40. Practical detail: For EU submissions, map RMP version to variation type/category.

  41. Regulatory Submission and Tracking

  42. [ ] Submission dossier prepared and version-matched
  43. [ ] Regulatory submission reference number recorded
  44. [ ] Acknowledgement / outcome captured
  45. Inspection relevance: Inspectors will check that submitted RMPs match approved versions.

  46. Archiving and Retention

  47. [ ] Superseded version archived as read-only with metadata
  48. [ ] Archive location and retention period noted (in line with local regulations)
  49. [ ] Access control verified
  50. Practical detail: Store complete packet (trigger docs, drafts, approvals, submission artefacts) together to facilitate inspection.

  51. Post-Implementation Review

    • [ ] Effectiveness evaluation scheduled (if RMMs changed)
    • [ ] Commitment tracker updated (study start/completion dates)
    • [ ] Lessons learned recorded
    • Inspection relevance: Evidence of follow-up and closure of commitments is routinely requested.

Checklist format: Save as a completed PDF or exported record in the DMS and attach to the archived RMP version.

B. RACI Matrix (Single-Appendix Version)

This RACI matrix maps common activities for an RMP lifecycle to roles. Use it to clarify responsibilities and to demonstrate governance during inspections. Adapt role names to your organisation but keep RACI allocations explicit.

Activity / Role Global RMP Owner Regional RMP Lead Local Affiliate PV Lead / Safety Regulatory Affairs QPPV Safety Physician / Medical Lead Document Control / DMS Admin Governance Committee Chair Legal/Compliance
Identify Trigger (signal, PI change, study result) A R C R C I R I I C
Perform Impact Assessment R C C A C I R I I C
Draft RMP Update R C C A C I C I I C
Scientific Review C C I A C I R I I C
Regulatory Review & Submission Preparation C C I C A I I C I C
Governance Committee Approval (if required) I C I C C I C I A C
Final Approval / Sign-off A I I C C R/A* I I I I
Implement Global Changes R C C C I I I R I I
Local Adaptation / Local Implementation I R A C C I I I I I
Update Commitment Tracker / PASS registry R C C A I I I I I I
Archive Superseded Versions I I I I I I I A I I

Legend: - R = Responsible (does the work) - A = Accountable (owns the decision) - C = Consulted (two-way communication) - I = Informed (one-way notification)

*Final approval: In some organisations the QPPV is accountable for overall pharmacovigilance governance; in others, the Global RMP Owner holds accountability. This should be explicitly defined per product and reflected in SOPs.

Inspection relevance: Provide signed RACI in the MAH's governance file. Inspectors will verify that actual practice matches the declared RACI.

C. Versioning Convention Table (Template for Inspection)

A consistent versioning convention must be defined and applied. Record the convention in SOPs and show examples in the RMP appendix.

Key fields to capture for each RMP file:

Recommended versioning convention:

Type of change Version increment Example Notes
Initial publication 1.0.0 1.0.0 First approved RMP
Major content change (safety concern added/removed, new PASS) Major +1, Minor reset, Patch 0 2.0.0 → 3.0.0 Requires full review/committee if threshold met
Moderate content change (rewording of risk descriptions, new monitoring activities) Minor +1, Patch reset 2.1.0 → 2.2.0 Scientific review required; may not require committee
Administrative change (typos, update of contacts, date changes) Patch +1 2.2.0 → 2.2.1 Fast-track with documented rationale
Emergency safety update (urgent safety restriction) Major +1 (with emergency flag) 3.0.0 (EMG) Use “EMG” or an urgent flag in metadata; follow expedited governance SOP
Local annex update (country-specific adaptation) Annex separate numbering: Annex v1.0 Annex-UK-1.0 Link annex to parent RMP ID

Practical implementation details: - Enforce versioning via DMS templates; prevent manual renaming. - Include the version in the filename: e.g., PROJ-012-RMP_v3.0.0_2026-05-01.pdf - Maintain a version control table within the document header and in the appendix. - Record change rationale in the change log and in the DMS metadata.

Inspection relevance: Inspectors will open multiple versions to verify evolution and consistency across submissions; inconsistent numbering or missing metadata is a common finding.

D. Sample Change Log (Traceability Demonstration)

Below is a sample change log demonstrating full traceability from trigger to approval and archive. This example is formatted to be inspection-ready; store as a PDF or export to the DMS with the archived RMP.

Sample change log headings:

Sample entries (table):

Log # Trigger ID & Date Trigger Source / Ref Impact Assessment Summary (date) Draft & Tracked Changes Reviews (dates) Governance Decision (date, ref) Final Approval (name, role, date/time) Regulatory Submission (ref) Implementation Evidence Archive (DMS path, date) Follow-up Actions
001 TRG-2025-047 2025-03-12 Signal assessment: increased reports of hepatic events (SIG-2025-03) Assessed as potential important identified risk; RMP sections 2.2, 4.1 affected (ImpactForm-2025-03-12) Draft v2.1.0 (Author: S. Lee) with redline changes saved in DMS draft workspace PV review 2025-03-15; Safety MD 2025-03-18; RegAff 2025-03-19 Safety Committee meeting 2025-03-22; Minutes SC-2025-03 (Decision: add Important Identified Risk & request targeted PASS) Approver: Dr. M. Patel (Global RMP Owner) 2025-03-24T09:45Z (e-sign) EU submission Variation V-2025-031 submitted 2025-03-26; EMA ack 2025-04-02 (ACK-EMA-2025-031) Affiliate notification email 2025-03-25 (EmailID 2025-03-AFF-NOTIF); Local annex template sent 2025-03-26 DMS:/Archive/PROJ-012/RMP/PROJ-012-RMP_v2.1.0_2025-03-24.pdf archived by DocCtrl 2025-03-24 Start PASS protocol development (Commitment CT-2025-07)
002 TRG-2025-099 2025-09-01 Labelling change: new contraindication in EMA PI (PI-2025-08-31) Minor textual alignment; no new safety concerns; update RMP section 3 and cross-reference to PI (ImpactForm-2025-09-02) Draft v2.2.0 (Author: A. Gomez) PV review 2025-09-04; RegAff 2025-09-05 No committee required per threshold matrix (email record TH-2025-09-07) Approver: Regional Lead (EEMA) 2025-09-07T11:20Z (e-sign) Submitted as part of routine PSUR cycle PSUR-2025-Q3 (Submission ref S-2025-PSUR) Affiliate communication: Local PI update guidance 2025-09-08 DMS:/Archive/PROJ-012/RMP/PROJ-012-RMP_v2.2.0_2025-09-07.pdf archived by DocCtrl 2025-09-07 Update local annexes within 30 days
003 TRG-2026-01-EMG 2026-01-14 Urgent safety report: fatal anaphylaxis case (PSURURG-2026-01) Emergency change; immediate labelling action and RMP update to include new risk description (ImpactForm-2026-01-14) Emergency draft v3.0.0-EMG (Author: PV Team Lead) Rapid review: Safety MD 2026-01-14; QPPV on-call 2026-01-14 Emergency Safety Meeting 2026-01-15; Minutes ESG-2026-01 (Decision: urgent RMP update, immediate communication to HAs) Final approval: QPPV (Dr. H. Rossi) 2026-01-15T02:30Z (e-sign, emergency SOP reference) Regulator notifications submitted (EMA Rapid Alert RA-2026-01; US FDA MedWatch notification) Immediate distributor recall communication and updated PI posted 2026-01-15; affiliate safety alert 2026-01-15 DMS:/Archive/PROJ-012/RMP/PROJ-012-RMP_v3.0.0-EMG_2026-01-15.pdf archived by DocCtrl 2026-01-15 Initiate expedited PASS (Commitment CT-2026-01); monitor implementation weekly

Practical detail: Each row must have live links or DMS references to the source documents (signal assessment, meeting minutes, submission packages). During inspection, provide a bundle where the log entries are hyperlinked to the evidence.

Inspection relevance: Inspectors will select one or more log entries and expect to see the complete chain of records. Lack of meeting minutes, absence of approvals, or missing submission acknowledgements are frequent causes of findings.

E. Governance and Escalation Rules (Implementation Guidance)

Inspection relevance: Regulators expect to see that emergency changes follow a controlled, pre-authorised process and that retrospective governance documents exist.

F. Practical Implementation Tips

Key Takeaways

This Appendix provides a single, inspection-ready pack that demonstrates transparent decision-making, traceability from trigger to archive, and clear governance. It is intended to be stored with the RMP master file and reproduced for inspection or regulatory audit. Inspectors will expect to access the entire chain of evidence and to see that governance operates in accordance with declared SOPs and RACI assignments.

References

  1. EMA Good Pharmacovigilance Practices (GVP) Module V – Risk Management Systems.
  2. EMA Risk Management Plan Template.
  3. Commission Implementing Regulation (EU) No 520/2012.
  4. Regulation (EC) No 726/2004.
  5. Directive 2001/83/EC.
  6. ICH E2E Pharmacovigilance Planning.
  7. EMA Guidance on Risk Management Systems.
  8. CIOMS IX Practical Approaches to Risk Minimisation.

Last reviewed: 2026-06-11