RMP Governance and Version Control
- RMP Governance and Version Control
- Introduction
- Why Governance Matters
- Governance Objectives
- RMP Ownership and Organisational Roles
- Global and Local Ownership Models
- Governance Committees and Decision Thresholds
- Relationship to Signal Management and Product Information
- Version Control Principles
- Change Management and Traceability
- Regulatory Context
- Inspection Focus Areas
- Characteristics of Mature Governance Systems
- Appendix: Inspection‑Ready Change Control Pack for RMPs (single consolidated appendix)
- Key Takeaways
- References
Introduction
Risk Management Plans are among the most complex pharmacovigilance documents maintained throughout the lifecycle of a medicinal product. Unlike many regulatory documents, RMPs evolve continuously as new safety information becomes available and as regulatory obligations change.
A single product may have multiple related risk management documents across different jurisdictions and regulatory procedures. Updates may be triggered by signal assessments, study results, product information changes, new indications or regulatory requests.
Effective governance and version control are therefore essential. Without them, organisations may struggle to maintain consistency, implement changes appropriately or demonstrate regulatory compliance.
Why Governance Matters
Governance provides the framework through which RMP decisions are reviewed, approved and implemented.
The objective is to ensure that:
- Safety concerns remain justified
- Updates are scientifically supported
- Regulatory commitments are tracked
- Global and local documents remain aligned
- Responsibilities are clearly defined
Governance is particularly important because RMP decisions frequently affect pharmacovigilance activities, risk minimisation measures and benefit-risk evaluation.
Governance Objectives
A mature governance framework should support:
- Scientific consistency
- Regulatory compliance
- Document integrity
- Change control
- Accountability
- Inspection readiness
The goal is not administrative control for its own sake. The goal is to ensure that risk management activities remain accurate, current and defensible.
RMP Ownership and Organisational Roles
Ownership should be defined clearly.
Different organisations allocate responsibilities differently, but ownership commonly involves collaboration among:
- Pharmacovigilance (PV) / Global Safety
- Risk Management functions
- Regulatory Affairs (Global and Regional)
- Safety Physicians / Medical Leads
- Quality / Document Control
- Qualified Person Responsible for Pharmacovigilance (QPPV)
- Local Affiliates / Country PV leads
- Legal / Compliance (where relevant)
The governance framework should identify:
- Document owner (primary accountable person for content)
- Scientific approver(s)
- Regulatory approver(s)
- Local implementation owners
- Document Controller (maintains controlled copies, archives)
Ambiguity regarding ownership is a common source of lifecycle management problems.
Global and Local Ownership Models
Large multinational organisations frequently operate multiple ownership layers. A typical structure:
Global Core RMP Owner ↓ Regional RMP Leads ↓ Local Affiliates
This structure allows global consistency while supporting local regulatory obligations. Governance must explicitly define which version is authoritative for regulatory submissions, and how local adaptations are created, approved and archived.
Governance Committees and Decision Thresholds
Many organisations review significant RMP changes through governance committees such as:
- Safety Management Teams
- Product Safety Committees
- Benefit-Risk Committees
- Risk Management Committees
Use defined decision thresholds to determine committee escalation. Typical thresholds include:
- Addition/removal of Important Identified or Potential Risks
- New pharmacovigilance or risk minimisation studies
- Changes likely to affect labelling or market access
- Major regulatory commitments or responses to enforcement actions
Committees provide documented rationale and senior oversight for significant changes. Minutes, consistent attendance records, and explicit decisions with action owners are inspection focal points.
Relationship to Signal Management and Product Information
Signal outcomes and product information changes are primary triggers for RMP updates. Governance must demonstrate a formal interface with signal management and regulatory labelling processes, including:
- Formal intake of signal outcomes into RMP change pipeline
- Assessment templates linking signal conclusion to RMP sections
- Cross-references between PI labelling changes and RMP updates
Inspectors often request the pathway from signal to RMP update and expect to see impact assessments and timelines.
Version Control Principles
Version control ensures the organisation can identify:
- Current versions
- Historical versions
- Change history and rationale
- Approval status and signatories
- Submission and archiving status
A robust versioning system prevents conflicting content across jurisdictions and supports inspection readiness.
Key technical requirements for systems used to manage RMPs:
- Controlled Document Management System (DMS) with audit trail
- Unique document identifiers (ID)
- Automated version numbering and metadata capture (author, approver, dates)
- Read-only archived versions
- Controlled distribution lists and access rights
- Integration with eCTD or submission trackers where appropriate
Change Management and Traceability
Change control should be trigger-based, documented and auditable. Each change must be traceable from trigger through impact assessment, decision, implementation, regulatory submission (if applicable) and archive.
Typical triggers include:
- Signal assessments
- PASS results and interim analyses
- Regulatory requests or inspection findings
- New indications or country launches
- Safety-related labelling changes
- Corporate or legal obligations
For inspection readiness, organisations should retain:
- The original trigger documentation (e.g., signal assessment)
- Impact assessment form
- Drafts with tracked changes and comments
- Governance committee minutes or approvals
- Regulatory submission dossiers and cover letters
- Implementation evidence (e.g., communications to affiliates)
- Archived superseded versions
Regulatory Context
Key regulatory expectations and references include:
- EMA GVP Module V – Risk Management Systems (latest revision)
- EMA RMP Template and related Q&A documents
- Commission Implementing Regulation (EU) No 520/2012
- ICH E2E Pharmacovigilance Planning
- Local regulatory guidance (for US, JP, CN, etc.) where relevant
These documents set expectations for content, lifecycle management and inspection-ready documentation. Inspectors increasingly expect explicit demonstration of governance, traceability and oversight.
Inspection Focus Areas
Inspectors commonly review:
- Ownership arrangements and role clarity
- Version histories and controlled copies
- Traceability from trigger to final decision
- Change control records and impact assessments
- Governance committee minutes and approvals
- Consistency between RMP, PI, and local documents
- Tracking and closure of regulatory commitments
- Use and configuration of DMS (audit trails)
Failures in these areas frequently result in findings and corrective action plans.
Characteristics of Mature Governance Systems
Mature RMP governance demonstrates:
- Well-documented roles and responsibilities
- Standard operating procedures (SOPs) for RMP changes
- A single source of truth for the core RMP
- Structured review and approval pathways
- Electronic systems supporting versioning and audit trails
- Routine internal audits and training
- Clear escalation routes for high-risk changes
Appendix: Inspection‑Ready Change Control Pack for RMPs (single consolidated appendix)
This appendix is an inspection‑ready, single-pack resource designed to be retained with each RMP master file. It contains a practical change-control checklist, an actionable RACI matrix, a versioning convention table, and a sample change log that demonstrates traceability from trigger to approval and archive. Organisations may adapt role titles to local nomenclature but should preserve the governance concepts and traceability features.
A. Change-Control Checklist (Inspection‑Ready)
Use this checklist as part of every RMP update. Retain completed items as evidence.
- Identification and Metadata
- [ ] Document ID (unique, global)
- [ ] Current version number and effective date
- [ ] Product name, MAH/holder, company code
- [ ] Document owner and contact details
-
Inspection relevance: Inspectors check metadata to confirm authoritative version.
-
Trigger Documentation
- [ ] Source of change (signal record, study report, regulatory letter, PI change notice)
- [ ] Date of trigger
- [ ] Link to original documents (attachments or hyperlinks in DMS)
-
Inspection relevance: Demonstrates why the change was initiated.
-
Impact Assessment
- [ ] Completed RMP impact assessment form (standard template)
- [ ] Determination of affected sections (safety concerns, PV activities, RMMs)
- [ ] Local impact matrix (list of affected affiliates/jurisdictions)
- [ ] Need for additional studies or commitments flagged
-
Practical detail: Use a standard risk-impact scoring (e.g., likelihood Ă— consequence) to prioritise speed of response.
-
Drafting and Change Tracking
- [ ] Draft created in controlled authoring environment
- [ ] Tracked changes retained (redline vs clean)
- [ ] Cross-reference table updated (RMP sections ↔ PI changes ↔ study results)
-
Inspection relevance: Inspectors expect to see how content evolved.
-
Stakeholder Review
- [ ] Scientific review completed (Safety Physician / Medical Lead)
- [ ] PV review completed (Global Safety)
- [ ] Regulatory review (Global/Regional)
- [ ] Legal/Compliance review (if required)
- [ ] QPPV informed and/or approval obtained
-
Practical detail: Set review timelines (e.g., 5–10 working days for routine changes, shorter for urgent safety issues).
-
Governance and Approval
- [ ] Governance committee approval (when threshold met) with minutes
- [ ] Sign-off by nominated approvers (electronic signature timestamped)
- [ ] Approval rationale documented
-
Inspection relevance: Approval evidence must be traceable and stored.
-
Implementation and Communication
- [ ] Global implementation plan (who, what, when)
- [ ] Local implementation instructions for affiliates
- [ ] Regulatory submission plan (e.g., EU-RMP via EVWeb/eSubmission, eCTD dossier)
- [ ] Communications log (emails to affiliates, training records)
-
Practical detail: For EU submissions, map RMP version to variation type/category.
-
Regulatory Submission and Tracking
- [ ] Submission dossier prepared and version-matched
- [ ] Regulatory submission reference number recorded
- [ ] Acknowledgement / outcome captured
-
Inspection relevance: Inspectors will check that submitted RMPs match approved versions.
-
Archiving and Retention
- [ ] Superseded version archived as read-only with metadata
- [ ] Archive location and retention period noted (in line with local regulations)
- [ ] Access control verified
-
Practical detail: Store complete packet (trigger docs, drafts, approvals, submission artefacts) together to facilitate inspection.
-
Post-Implementation Review
- [ ] Effectiveness evaluation scheduled (if RMMs changed)
- [ ] Commitment tracker updated (study start/completion dates)
- [ ] Lessons learned recorded
- Inspection relevance: Evidence of follow-up and closure of commitments is routinely requested.
Checklist format: Save as a completed PDF or exported record in the DMS and attach to the archived RMP version.
B. RACI Matrix (Single-Appendix Version)
This RACI matrix maps common activities for an RMP lifecycle to roles. Use it to clarify responsibilities and to demonstrate governance during inspections. Adapt role names to your organisation but keep RACI allocations explicit.
| Activity / Role | Global RMP Owner | Regional RMP Lead | Local Affiliate | PV Lead / Safety | Regulatory Affairs | QPPV | Safety Physician / Medical Lead | Document Control / DMS Admin | Governance Committee Chair | Legal/Compliance |
|---|---|---|---|---|---|---|---|---|---|---|
| Identify Trigger (signal, PI change, study result) | A | R | C | R | C | I | R | I | I | C |
| Perform Impact Assessment | R | C | C | A | C | I | R | I | I | C |
| Draft RMP Update | R | C | C | A | C | I | C | I | I | C |
| Scientific Review | C | C | I | A | C | I | R | I | I | C |
| Regulatory Review & Submission Preparation | C | C | I | C | A | I | I | C | I | C |
| Governance Committee Approval (if required) | I | C | I | C | C | I | C | I | A | C |
| Final Approval / Sign-off | A | I | I | C | C | R/A* | I | I | I | I |
| Implement Global Changes | R | C | C | C | I | I | I | R | I | I |
| Local Adaptation / Local Implementation | I | R | A | C | C | I | I | I | I | I |
| Update Commitment Tracker / PASS registry | R | C | C | A | I | I | I | I | I | I |
| Archive Superseded Versions | I | I | I | I | I | I | I | A | I | I |
Legend: - R = Responsible (does the work) - A = Accountable (owns the decision) - C = Consulted (two-way communication) - I = Informed (one-way notification)
*Final approval: In some organisations the QPPV is accountable for overall pharmacovigilance governance; in others, the Global RMP Owner holds accountability. This should be explicitly defined per product and reflected in SOPs.
Inspection relevance: Provide signed RACI in the MAH's governance file. Inspectors will verify that actual practice matches the declared RACI.
C. Versioning Convention Table (Template for Inspection)
A consistent versioning convention must be defined and applied. Record the convention in SOPs and show examples in the RMP appendix.
Key fields to capture for each RMP file:
- Document ID: PROJ-XXXX-RMP
- Version number: Major.Minor.Patch (see table below)
- Effective date: YYYY-MM-DD
- Status: Draft / For Approval / Approved / Submitted / Archived
- Author, Author department
- Approver(s), Role
- Change summary (short)
- Submission reference (if applicable)
- Archive location (DMS path)
Recommended versioning convention:
| Type of change | Version increment | Example | Notes |
|---|---|---|---|
| Initial publication | 1.0.0 | 1.0.0 | First approved RMP |
| Major content change (safety concern added/removed, new PASS) | Major +1, Minor reset, Patch 0 | 2.0.0 → 3.0.0 | Requires full review/committee if threshold met |
| Moderate content change (rewording of risk descriptions, new monitoring activities) | Minor +1, Patch reset | 2.1.0 → 2.2.0 | Scientific review required; may not require committee |
| Administrative change (typos, update of contacts, date changes) | Patch +1 | 2.2.0 → 2.2.1 | Fast-track with documented rationale |
| Emergency safety update (urgent safety restriction) | Major +1 (with emergency flag) | 3.0.0 (EMG) | Use “EMG” or an urgent flag in metadata; follow expedited governance SOP |
| Local annex update (country-specific adaptation) | Annex separate numbering: Annex v1.0 | Annex-UK-1.0 | Link annex to parent RMP ID |
Practical implementation details: - Enforce versioning via DMS templates; prevent manual renaming. - Include the version in the filename: e.g., PROJ-012-RMP_v3.0.0_2026-05-01.pdf - Maintain a version control table within the document header and in the appendix. - Record change rationale in the change log and in the DMS metadata.
Inspection relevance: Inspectors will open multiple versions to verify evolution and consistency across submissions; inconsistent numbering or missing metadata is a common finding.
D. Sample Change Log (Traceability Demonstration)
Below is a sample change log demonstrating full traceability from trigger to approval and archive. This example is formatted to be inspection-ready; store as a PDF or export to the DMS with the archived RMP.
Sample change log headings:
- Log entry number
- Trigger ID and date
- Trigger source/document reference
- Impact assessment summary and date
- Drafting history reference (draft IDs, authors)
- Stakeholder reviews (names, departments, dates)
- Governance decision (committee, date, minutes ref)
- Final approval (approver name, role, e-signature timestamp)
- Regulatory submission (yes/no, submission ref)
- Implementation actions (who, when)
- Archive reference (DMS path, archived by, date)
- Notes / follow-up actions
Sample entries (table):
| Log # | Trigger ID & Date | Trigger Source / Ref | Impact Assessment Summary (date) | Draft & Tracked Changes | Reviews (dates) | Governance Decision (date, ref) | Final Approval (name, role, date/time) | Regulatory Submission (ref) | Implementation Evidence | Archive (DMS path, date) | Follow-up Actions |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 001 | TRG-2025-047 2025-03-12 | Signal assessment: increased reports of hepatic events (SIG-2025-03) | Assessed as potential important identified risk; RMP sections 2.2, 4.1 affected (ImpactForm-2025-03-12) | Draft v2.1.0 (Author: S. Lee) with redline changes saved in DMS draft workspace | PV review 2025-03-15; Safety MD 2025-03-18; RegAff 2025-03-19 | Safety Committee meeting 2025-03-22; Minutes SC-2025-03 (Decision: add Important Identified Risk & request targeted PASS) | Approver: Dr. M. Patel (Global RMP Owner) 2025-03-24T09:45Z (e-sign) | EU submission Variation V-2025-031 submitted 2025-03-26; EMA ack 2025-04-02 (ACK-EMA-2025-031) | Affiliate notification email 2025-03-25 (EmailID 2025-03-AFF-NOTIF); Local annex template sent 2025-03-26 | DMS:/Archive/PROJ-012/RMP/PROJ-012-RMP_v2.1.0_2025-03-24.pdf archived by DocCtrl 2025-03-24 | Start PASS protocol development (Commitment CT-2025-07) |
| 002 | TRG-2025-099 2025-09-01 | Labelling change: new contraindication in EMA PI (PI-2025-08-31) | Minor textual alignment; no new safety concerns; update RMP section 3 and cross-reference to PI (ImpactForm-2025-09-02) | Draft v2.2.0 (Author: A. Gomez) | PV review 2025-09-04; RegAff 2025-09-05 | No committee required per threshold matrix (email record TH-2025-09-07) | Approver: Regional Lead (EEMA) 2025-09-07T11:20Z (e-sign) | Submitted as part of routine PSUR cycle PSUR-2025-Q3 (Submission ref S-2025-PSUR) | Affiliate communication: Local PI update guidance 2025-09-08 | DMS:/Archive/PROJ-012/RMP/PROJ-012-RMP_v2.2.0_2025-09-07.pdf archived by DocCtrl 2025-09-07 | Update local annexes within 30 days |
| 003 | TRG-2026-01-EMG 2026-01-14 | Urgent safety report: fatal anaphylaxis case (PSURURG-2026-01) | Emergency change; immediate labelling action and RMP update to include new risk description (ImpactForm-2026-01-14) | Emergency draft v3.0.0-EMG (Author: PV Team Lead) | Rapid review: Safety MD 2026-01-14; QPPV on-call 2026-01-14 | Emergency Safety Meeting 2026-01-15; Minutes ESG-2026-01 (Decision: urgent RMP update, immediate communication to HAs) | Final approval: QPPV (Dr. H. Rossi) 2026-01-15T02:30Z (e-sign, emergency SOP reference) | Regulator notifications submitted (EMA Rapid Alert RA-2026-01; US FDA MedWatch notification) | Immediate distributor recall communication and updated PI posted 2026-01-15; affiliate safety alert 2026-01-15 | DMS:/Archive/PROJ-012/RMP/PROJ-012-RMP_v3.0.0-EMG_2026-01-15.pdf archived by DocCtrl 2026-01-15 | Initiate expedited PASS (Commitment CT-2026-01); monitor implementation weekly |
Practical detail: Each row must have live links or DMS references to the source documents (signal assessment, meeting minutes, submission packages). During inspection, provide a bundle where the log entries are hyperlinked to the evidence.
Inspection relevance: Inspectors will select one or more log entries and expect to see the complete chain of records. Lack of meeting minutes, absence of approvals, or missing submission acknowledgements are frequent causes of findings.
E. Governance and Escalation Rules (Implementation Guidance)
- Define explicit thresholds for committee review and emergency escalation in the SOP (e.g., immediate QPPV notification within 24 hours for fatal or life‑threatening events).
- Maintain an escalation contact list with 24/7 on-call roles (QPPV, Head of PV).
- Use a colour-coded priority field in the change log (Low / Medium / High / Emergency).
- For emergency changes, maintain a parallel emergency SOP that documents deviation from standard timelines and requires post-event justification and retrospective committee review.
Inspection relevance: Regulators expect to see that emergency changes follow a controlled, pre-authorised process and that retrospective governance documents exist.
F. Practical Implementation Tips
- Templates: Create standard templates for impact assessments, draft change summaries, committee minutes and submission checklists. Require their use and store completed templates with the archived RMP.
- Training: Train stakeholders on the RACI, SOPs, and DMS procedures; retain training records linked to the RMP file.
- Audit Trails: Configure DMS to capture author, editor, reviewer, approver, date/time and reason for change. Export audit trails for inspection on request.
- Linkage: Ensure cross-document linkage between the RMP, PI, PSURs, PASS protocols, and regulatory submission artefacts to demonstrate systemic consistency.
- Retention: Align retention periods to the longest applicable regulatory requirement; ensure archived RMPs remain retrievable for inspections and are protected from alteration.
Key Takeaways
This Appendix provides a single, inspection-ready pack that demonstrates transparent decision-making, traceability from trigger to archive, and clear governance. It is intended to be stored with the RMP master file and reproduced for inspection or regulatory audit. Inspectors will expect to access the entire chain of evidence and to see that governance operates in accordance with declared SOPs and RACI assignments.
References
- EMA Good Pharmacovigilance Practices (GVP) Module V – Risk Management Systems.
- EMA Risk Management Plan Template.
- Commission Implementing Regulation (EU) No 520/2012.
- Regulation (EC) No 726/2004.
- Directive 2001/83/EC.
- ICH E2E Pharmacovigilance Planning.
- EMA Guidance on Risk Management Systems.
- CIOMS IX Practical Approaches to Risk Minimisation.