Safety Specification

A comprehensive guide to the Safety Specification and its role as the scientific foundation of the Risk Management Plan.

Audio Lesson 12 min

Safety Specification

Introduction

The Safety Specification is the scientific foundation of the Risk Management Plan (RMP). It describes the current understanding of a medicinal product's safety profile and identifies the risks and uncertainties that require ongoing management.

Every important pharmacovigilance activity and every risk minimisation measure within an RMP should be traceable to the Safety Specification. If a risk is not considered important enough to appear in the Safety Specification, it is unlikely to justify additional risk management activities.

The purpose of the Safety Specification is therefore not merely to describe adverse reactions. Its purpose is to identify the safety concerns that are important for the ongoing evaluation and management of the product's benefit-risk balance.

Why the Safety Specification Exists

At the time of marketing authorisation, knowledge of a product's safety profile is incomplete.

Clinical trials provide important information but have limitations:

Important uncertainties frequently remain after approval.

The Safety Specification identifies these uncertainties and determines which risks require further monitoring, investigation or risk minimisation.

The Role of the Safety Specification Within the RMP

The Safety Specification sits at the centre of the RMP.

A simplified model is:

Safety Specification
        ↓
Safety Concerns
        ↓
Pharmacovigilance Plan
        ↓
Risk Minimisation Plan

The Safety Specification drives the remainder of the document.

Changes to safety concerns frequently trigger changes to pharmacovigilance activities and risk minimisation measures.

Objectives of the Safety Specification

The Safety Specification seeks to:

The objective is not to create a comprehensive list of all adverse reactions.

Rather, the objective is to identify issues that are important for ongoing risk management.

Sources of Information

The Safety Specification draws information from multiple sources.

These may include:

The resulting assessment should reflect the totality of available evidence.

Historical Development

Historically, RMPs often contained extensive lists of safety issues.

Over time, regulatory expectations evolved toward a more focused approach.

Modern RMPs emphasise:

The emphasis is increasingly on relevance rather than volume.

Components of the Safety Specification

The Safety Specification generally evaluates:

The most important output is the identification of safety concerns.

Safety Concerns

Safety concerns represent issues that are important for risk management purposes.

Three categories are used:

Important Identified Risks

Risks for which sufficient evidence supports a causal relationship with the product and which are important for ongoing risk management.

Important Potential Risks

Risks for which evidence suggests a possible association but uncertainty remains.

Missing Information

Important gaps in knowledge relevant to understanding product safety.

These categories form the core of the Safety Specification.

What Makes a Risk Important?

Not every adverse reaction qualifies as an important risk.

Importance is generally determined by factors such as:

A common misunderstanding is that all listed adverse reactions should appear within the Safety Specification.

This is not the case.

Only risks important for risk management purposes should be included.

Important Identified Risks

An Important Identified Risk is a risk for which sufficient evidence supports an association with the product.

Examples may include:

The designation requires both evidence and importance.

A causal relationship alone is insufficient.

Important Potential Risks

An Important Potential Risk exists when available information suggests a possible association but available evidence remains insufficient for confirmation.

Examples may arise from:

Potential risks frequently require additional pharmacovigilance activities.

Missing Information

Missing Information represents areas where knowledge is insufficient.

Examples may include:

Missing Information should be clinically relevant and capable of influencing understanding of product safety.

Relationship to Signal Management

Signal management is one of the principal drivers of Safety Specification updates.

Signals may result in:

Consequently, the Safety Specification should not be viewed as a static section.

It evolves continuously throughout the product lifecycle.

Relationship to Benefit-Risk Evaluation

The Safety Specification contributes directly to benefit-risk evaluation.

The importance of a safety concern depends upon:

The same adverse reaction may have different significance depending upon the product and indication.

For this reason, risk characterisation should always occur within a benefit-risk framework.

Relationship to Additional Pharmacovigilance Activities

Additional pharmacovigilance activities should be linked to specific safety concerns.

Examples include:

A useful regulatory principle is:

Every activity should address a safety concern.

Activities without a clear rationale are difficult to justify.

Relationship to Additional Risk Minimisation Measures

Additional risk minimisation measures should also be linked to safety concerns.

Examples include:

The Safety Specification provides the scientific justification for these interventions.

Removal of Safety Concerns

Safety concerns may be removed when evidence demonstrates that they are no longer important for risk management purposes.

Removal decisions should be supported by:

The absence of recent reports alone is rarely sufficient.

Common Mistakes

Several recurring problems occur when developing Safety Specifications.

Excessive Numbers of Risks

Large lists of risks reduce focus and dilute risk management efforts.

Inclusion of Routine Adverse Reactions

Not all adverse reactions require inclusion as safety concerns.

Weak Justification

Risks are included without clear scientific rationale.

Failure to Remove Obsolete Concerns

Outdated risks remain indefinitely.

Poor Linkage to Activities

Additional activities are not linked to defined safety concerns.

These issues frequently attract regulatory scrutiny.

Inspection Considerations

Inspectors may review:

A recurring inspection theme is whether safety concerns remain scientifically justified.

Role of the QPPV

The QPPV should understand:

The QPPV is often expected to explain how safety concerns influence broader pharmacovigilance and risk management activities.

Characteristics of a Well-Written Safety Specification

A mature Safety Specification generally demonstrates:

The objective is not to create the longest possible list of risks.

The objective is to identify the risks that genuinely require active management.

Key Takeaways

The Safety Specification is the scientific foundation of the RMP.

It identifies important risks and uncertainties that require ongoing management.

The three core categories are Important Identified Risks, Important Potential Risks and Missing Information.

All major pharmacovigilance activities and risk minimisation measures should be linked to safety concerns described within the Safety Specification.

A well-developed Safety Specification supports effective risk management, benefit-risk evaluation and lifecycle management throughout the product's market presence.


Inspection‑ready checklist (concise)

Use this checklist to prepare an inspection package that demonstrates a defensible, governed Safety Specification and traceable RMP actions. Keep documents version‑controlled and ready to present.

  1. Governance and sign-off
  2. RMP/Safety Specification version history and approval log (names, roles, dates).
  3. Terms of reference and minutes for safety/benefit‑risk committee meetings that discussed the Safety Specification.
  4. QPPV sign‑off statement and record of internal approvals (medical, regulatory, legal, safety).

  5. Scientific rationale and evidence base

  6. Risk characterisation memos for each safety concern (concise summary, evidence sources, assessment of causality).
  7. Signal assessment reports and chronological integration into the Safety Specification.
  8. Key clinical study reports (CSR excerpts) and pivotal safety tables.
  9. Relevant non‑clinical reports that informed a risk.

  10. Linkage to activities

  11. Cross‑reference table mapping each safety concern to specific pharmacovigilance activities and risk minimisation measures (with rationale and timelines).
  12. Protocols and approvals for PASS, registries, active surveillance studies or additional safety analyses.
  13. Copies of educational materials, SmPC drafts showing proposed text, DHPC letters, checklist for controlled access or PPP documents.

  14. Implementation evidence

  15. Contracts or service agreements with CROs or vendors conducting PASS/registries.
  16. Study initiation, progress and final reports for ongoing/complete studies.
  17. Monitoring reports, key risk indicators (KRIs), metrics for RMM uptake (e.g., distribution logs, HCP training completion).

  18. Quality and compliance demonstration

  19. SOPs that govern Safety Specification updates, signal handling, and RMP change control.
  20. Audit reports, CAPA logs related to RMP activities.
  21. Training records for personnel responsible for the Safety Specification and linked activities.

  22. Traceability and lifecycle documentation

  23. RMP change log showing why and when risks were added, modified or removed.
  24. Benefit‑risk documentation showing how a safety concern affects product benefit‑risk (including any reclassification decisions).
  25. Communication logs with regulators (submissions, EMA/FDA meeting minutes, assessment outcomes).

  26. Readiness materials for the inspector

  27. Executive summary (1–2 pages) outlining key safety concerns, current evidence status, and planned/implemented activities.
  28. Short annotated extracts from main documents for rapid inspection (e.g., annotated RMP showing links).
  29. Contact list of personnel responsible for specific safety concerns and studies.

Inspectors commonly request the above documents. Preparing them in advance—with hyperlinks between documents where possible—shortens inspection time and demonstrates robust governance.


This decision table maps each Safety Specification category to pragmatic evidence thresholds, proportional pharmacovigilance interventions, recommended risk‑minimisation actions and inspection‑relevant documentation. Use it as a governance tool to support consistent, inspection‑ready decisions.

Note: thresholds are pragmatic, inspection‑oriented criteria designed to support defensible decisions; adjust to product‑specific context and regulatory guidance (e.g., EMA GVP Module V, ICH E2E).

Safety Specification category Practical evidence thresholds (inspection‑oriented) Recommended pharmacovigilance actions (proportional) Recommended risk‑minimisation actions (proportional) Timelines and documentation for inspection
Important Identified Risk — High evidence Multiple convergent sources indicating causality: clinical trial signal with consistent post‑marketing reports, biological plausibility, dechallenge/rechallenge or robust epidemiology (e.g., adjusted RR ≥2 with robust design) Immediate routine and targeted PV: update SmPC/PI; implement targeted signal monitoring; perform expedited periodic aggregate reviews; consider formal epidemiology if magnitude uncertain Urgent SmPC/PI change; DHPC if public health impact high; implement additional RMMs (contraindication, controlled access, mandatory education) as needed Immediate regulatory submission (within days–weeks), risk characterisation memo, signal assessment report, RMP update, minutes of safety committee; inspection expects evidence synthesis and communication plan
Important Identified Risk — Moderate evidence Strong case series, disproportionality (ROR/PRR with consistent case narrative), supportive non‑clinical data, limited epidemiology Enhanced spontaneous monitoring, focused database analyses, targeted observational studies (cohort, case‑control) SmPC update if warranted; develop targeted educational material; implement monitoring checklists for HCPs; consider restricted use if severity high Protocols for observational studies within 1–3 months, study SOPs, interim analysis plan and timelines; inspection expects rationale for chosen PV actions
Important Potential Risk — Signal present but uncertain Signal detected (disproportionality, single serious case, class effect) but inconsistent/insufficient evidence; mechanistic plausibility may be present Formally document signal, perform causality assessment, prioritise epidemiology or PASS if signal persists; increase case ascertainment (e.g., follow‑up forms) Consider targeted communications to investigators/registries to improve ascertainment; contingency planning for RMM if confirmed Signal assessment report, prioritisation decision, planned study protocol or feasibility assessment; inspection expects documented signal decision process and timelines
Important Potential Risk — Low immediate credibility Single isolated report without supporting evidence, no plausible mechanism Routine PV monitoring and periodic aggregation; low priority for immediate studies No additional RMMs beyond routine information in SmPC unless new data emerges Signal log entry, rationale for de‑prioritisation, monitoring plan; inspection expects documented rationale and trigger thresholds for re‑evaluation
Missing Information — High public health relevance Population(s) with substantial exposure and no/limited data (e.g., pregnancy, long‑term use in chronic disease, paediatrics where indication will likely be used) Initiate targeted data collection (pregnancy registry, paediatric PK/PD study, long‑term follow‑up), implement active surveillance where feasible Implement informed prescribing guidance; pregnancy prevention programme (PPP) in case of teratogenic risk; label cautions and HCP education Protocols and feasibility assessments within 3 months; registry/PPP agreements and sample size justification; inspection expects plans and timelines and evidence of enrolment/start
Missing Information — Low immediate relevance Theoretical uncertainty with limited expected exposure (rare off‑label use) Routine PV and consideration of post‑authorisation study only if exposure increases Routine labeling language; no immediate RMMs Documentation of decision, monitoring plan; inspection expects evidence‑based rationale

Practical implementation: operationalising the decision table

Follow these operational steps to apply the decision table consistently and in an inspection‑ready manner.

  1. Evidence collation and central repository
  2. Maintain a single controlled repository for all safety evidence (clinical, non‑clinical, literature, post‑marketing reports, epidemiology).
  3. Use structured templates for risk characterisation memos containing: clinical description, frequency, severity, latency, dechallenge/rechallenge, biological plausibility, alternative explanations, and quantitative estimates.

  4. Standardised evidence grading

  5. Adopt a pragmatic grading scale for evidence strength (e.g., High / Moderate / Low) with objective criteria: reproducibility, temporality, plausibility, supporting epidemiology.
  6. Define trigger thresholds for escalation (e.g., signal score or disproportionality metric plus case quality) and document these in SOPs.

  7. Decision governance

  8. Convene an independent safety/benefit‑risk committee for decisions on reclassification (composition: QPPV, PV lead, clinical safety physician, epidemiologist, regulatory affairs, medical affairs).
  9. Require written minutes and action items with timelines and responsible owners for all RMP/Safety Specification decisions.

  10. Mapping and traceability

  11. Create and maintain a cross‑reference matrix: each Safety Specification entry → specific PV activities → RMMs → evidence expected → completion status.
  12. Use this matrix to generate RMP updates and inspection packages.

  13. Study initiation and monitoring

  14. For recommended PV studies (PASS, registries), document feasibility, protocol, statistical analysis plan, sample size rationale, timelines and interim reporting schedule.
  15. Ensure contracts with CROs include reporting obligations, audit rights, and data access clauses for inspection.

  16. Risk‑minimisation implementation

  17. RMMs must be accompanied by implementation plans, dissemination metrics (e.g., number of HCPs trained, materials distributed), and effectiveness evaluation measures.
  18. For high‑impact RMMs (e.g., PPP, controlled access), prepare SOPs for enrolment, compliance monitoring, and escalation if non‑adherence is detected.

  19. Documentation and change control

  20. All Safety Specification changes must follow formal change control: change request, impact assessment (including regulatory), approved implementation plan, and versioned RMP.
  21. Archive superseded versions and maintain an auditable trail for inspectors.

  22. Metrics and KPIs

  23. Define KPIs to demonstrate activity effectiveness: study enrolment rates, time to SmPC update, number of risk communication events, KRI thresholds, RMM uptake metrics.
  24. Report KPIs periodically to governance committees and retain reports as inspection evidence.

Regulatory context and inspection relevance

Regulatory expectations relevant to Safety Specifications and the decision logic include:

Inspection relevance — what inspectors commonly seek:

Preparing the inspection package described under the checklist and demonstrating the application of the decision table will address the majority of inspection queries related to the Safety Specification.


Governance considerations

A robust governance framework ensures defensible Safety Specification decisions and inspection readiness.

Key governance elements:

Well‑defined governance reduces subjectivity in classifying safety concerns and supports consistent application of the decision table.


Document package to prepare for an inspection (minimum)

Prepare the following documents for each safety concern in the Safety Specification:

Link these documents and make them searchable for rapid inspector review.


Example: applying the decision table (brief workflow)

  1. Signal detection: PV team records signal in log with initial assessment.
  2. Triage: apply evidence thresholds—does the signal meet criteria for Important Potential Risk?
  3. Escalation: if above threshold, convene safety committee within defined timeframe.
  4. Decision: classify as Identified/Potential/ Missing Information and record rationale.
  5. Actions: assign PV activities and RMM development according to the decision table.
  6. Documentation: produce risk characterisation memo, study protocol (if required), and updated RMP.
  7. Implementation and monitoring: execute studies/RMMs, collect KPIs, report to committee.
  8. Reassessment: periodic reclassification as new evidence accrues; maintain change log and regulatory submissions.

References

  1. EMA Good Pharmacovigilance Practices (GVP) Module V – Risk Management Systems.
  2. EMA Risk Management Plan Template.
  3. Commission Implementing Regulation (EU) No 520/2012.
  4. Regulation (EC) No 726/2004.
  5. Directive 2001/83/EC.
  6. ICH E2E Pharmacovigilance Planning.
  7. EMA Guidance on Safety Concerns and Risk Management Planning.

Last reviewed: 2026-06-11