RMP Governance and Version Control

Explains how organisations can maintain traceability, version integrity, regulatory consistency and QPPV oversight across the RMP lifecycle while distinguishing required outcomes from company-specific governance models.

Take test

RMP Governance and Version Control

An RMP is both a scientific document and a controlled regulatory record. Its content can change when safety concerns evolve, pharmacovigilance activities are added or completed, risk minimisation measures are revised, new indications are authorised or regulators request changes. Governance and version control exist to make those changes traceable and to ensure that the version being discussed, submitted and implemented is the correct one.

Purpose and Regulatory Context

GVP Module V Rev. 2 describes the RMP as a dynamic document that should be updated when new information changes the risk-management system or when required by the competent authority. EMA's post-authorisation RMP procedural guidance, updated in July 2026, explains when an updated RMP may need to accompany regulatory procedures.

Neither GVP Module V nor EMA procedural guidance mandates a universal corporate committee structure, a particular document-management platform, a fixed version-numbering convention or routine QPPV signature on every RMP draft. Those are organisational controls.

The regulatory outcomes that governance must support are more fundamental:

Governance Begins With Clear Decision Rights

Several functions may contribute to an RMP: pharmacovigilance, safety physicians, epidemiology, regulatory affairs, clinical development, risk-management specialists, medical affairs and local affiliates. The organisation therefore needs a clear answer to three questions:

  1. Who is responsible for preparing and maintaining the document?
  2. Who provides scientific and regulatory input to material changes?
  3. Who has authority to approve the version that enters a regulatory procedure?

The exact answers can differ between companies. A small MAH may operate through a few named individuals; a large organisation may use product safety teams and formal governance committees. The quality criterion is not organisational complexity but clarity, traceability and effectiveness.

What Version Control Must Achieve

A controlled RMP process should allow the organisation to distinguish at least:

Confusion between these states can lead to regulatory inconsistency. For example, a later internal draft may contain a proposed safety concern that was never submitted, while an older submitted version may remain the regulatory baseline until a procedure is completed.

Version control therefore needs both document identity and regulatory status. A filename alone is rarely enough.

The Trigger-to-Version Chain

A useful governance model is:

trigger → impact assessment → drafting → review → approval → submission → regulatory outcome → implementation → archive.

Triggers can include:

The traceability objective is to preserve why the change occurred and what happened next.

Scientific and Regulatory Change Control

RMP change control should not become a bureaucratic substitute for scientific reasoning. The core of the impact assessment is to determine whether new evidence changes:

A signal conclusion that adds an important identified risk, for example, may affect several RMP sections and may also require product-information or risk-minimisation changes. A purely administrative change may affect metadata without altering the scientific content.

The level of review should be proportionate to the significance of the change. There is no EMA requirement that every typographical correction undergo the same governance route as addition of a major safety concern.

Relationship With Product Information

The RMP and product information serve different functions but must not contradict one another.

The SmPC describes authorised conditions of use and communicates known risks and precautions. The RMP explains which safety concerns require active management and what pharmacovigilance or risk minimisation is planned. A change to one document may therefore require assessment of the other, but not every labelling change automatically requires an RMP update.

The appropriate question is whether the underlying risk-management system has changed materially.

Relationship With the PSUR/PBRER

Periodic benefit-risk evaluation can generate conclusions that affect the RMP. Conversely, ongoing RMP commitments can provide important context for the PSUR/PBRER.

Good governance should make it possible to reconcile:

The objective is scientific consistency rather than forced textual identity between documents.

Global and Local Risk-Management Documents

Multinational organisations may maintain EU RMPs alongside other regional risk-management documents. The EU RMP should not be treated as a universal global master where another jurisdiction has different legal concepts, formats or commitments.

A useful governance model distinguishes:

Local adaptations should remain linked to their regulatory basis so that differences are deliberate rather than accidental.

QPPV Oversight

The QPPV should have sufficient visibility of material RMP changes to maintain oversight of the pharmacovigilance system. This includes awareness of important safety concerns, significant additional pharmacovigilance activities, major risk minimisation measures and relevant regulatory commitments.

That does not create a universal requirement for QPPV signature on every RMP version, impact assessment or change-control record. Companies should define an oversight model that gives the QPPV meaningful access to significant information without converting oversight into indiscriminate document approval.

The following controls are useful but organisation-specific:

The control should solve a real traceability problem. Elaborate version-numbering schemes add little value if the organisation still cannot identify which RMP was submitted in a particular procedure.

Potential Failure Modes

The following are illustrative failure modes, not published inspection findings.

Failure mode Consequence
Treating an internal draft as the regulatory baseline scientific and regulatory teams may implement unagreed content
Updating only one RMP section related PV activities, RMMs or summaries become inconsistent
Requiring the same approval path for every change governance becomes slow without improving control
Using global templates without jurisdictional assessment local regulatory commitments may be overwritten or missed
Relying on filenames as the only version control submitted, approved and working versions can be confused
QPPV signing everything paperwork may replace meaningful oversight
Archiving without change rationale historical decisions cannot be reconstructed

Inspection Considerations

An inspector could reasonably ask the organisation to demonstrate which RMP was applicable at a particular time, why it changed, what evidence supported the change, how regulatory outcomes were incorporated and whether consequential activities were implemented.

The useful evidence is therefore the decision trail, not a particular corporate template. Depending on the organisation this may include change records, tracked changes, governance minutes, submission correspondence, regulatory outcomes, commitment trackers and archived versions.

Practical Review Checklist

This checklist is recommended practice, not an EMA-prescribed control.

  1. Can the current regulatory RMP version be identified unambiguously?
  2. Can submitted and working versions be distinguished?
  3. Is each material change linked to a scientific or regulatory trigger?
  4. Were all affected RMP sections assessed?
  5. Were related product-information, PSUR/PBRER and implementation consequences considered?
  6. Are local differences traceable to a regulatory or implementation reason?
  7. Is the review pathway proportionate to the significance of the change?
  8. Does the QPPV have appropriate visibility of material changes?
  9. Can historical versions and decisions be reconstructed?
  10. Are obsolete versions protected against unintended use?

Key Takeaways

RMP governance exists to preserve scientific and regulatory control as the risk-management system changes.

EU guidance requires an accurate, current and appropriately updated RMP, but it does not prescribe a universal committee, RACI, electronic platform, numbering scheme or QPPV signature model.

The most important traceability chain is trigger → decision → version → submission → regulatory outcome → implementation.

Version status matters as much as version number. Organisations must know which document is a draft, which was submitted and which reflects the current agreed risk-management system.

References

  1. European Medicines Agency. Guideline on good pharmacovigilance practices (GVP) Module V — Risk management systems (Rev. 2). EMA/838713/2011 Rev. 2.
  2. European Medicines Agency. Guidance on the format of the risk management plan in the EU — integrated format (Rev. 2.0.1). EMA/164014/2018 Rev. 2.0.1.
  3. European Medicines Agency. Risk management plans (RMP) in post-authorisation phase: questions and answers. European Medicines Agency post-authorisation procedural advice, EMEA-H-19984/03 Rev. 118, updated 13 July 2026.
  4. European Union. Commission Implementing Regulation (EU) No 520/2012, consolidated version current at 12 February 2026.
  5. European Union. Directive 2001/83/EC, as amended.
  6. European Union. Regulation (EC) No 726/2004, as amended.

Regulatory Note

This article distinguishes the regulatory outcomes required of RMP lifecycle management from company-specific governance and document-control practices. As of 8 September 2026, GVP Module V Rev. 2, the integrated RMP format Rev. 2.0.1 and EMA post-authorisation procedural advice Rev. 118 remain the principal published EU references for these topics.

Revision History

Last reviewed: 2026-09-08