Signal Management Governance
- Signal Management Governance
- Introduction
- Why Governance Matters
- Governance Within the Signal Management Lifecycle
- Defining Responsibilities
- Decision-Making Authority
- Signal Review Committees
- Escalation Pathways
- Emerging Safety Issues
- Governance Documentation
- Integration With Benefit-Risk Evaluation
- Integration With Risk Management Systems
- Role of Senior Management
- Role of the QPPV
- Outsourced Signal Management Activities
- Governance During Inspections
- Common Governance Weaknesses
- Characteristics of Mature Governance Frameworks
- Responsibility Matrix (RACI) for Signal Management
- Implementing the RACI in Practice (practical details)
- Inspection‑Ready Checklist for Signal Management Governance
- Practical Steps to Assemble an Inspection Pack (operational implementation)
- Governance Discussion: Integration, Delegation and Oversight
- Common Inspection Questions and Evidence Mapping
- Key Takeaways
- References
Introduction
Signal management is often described in terms of technical activities such as signal detection, validation and assessment. However, signal management is also a governance process. Decisions regarding emerging safety concerns may influence product information, risk minimisation activities, regulatory communications and benefit-risk evaluations. Consequently, organisations require mechanisms to ensure that important signal-related decisions are made consistently, reviewed appropriately and documented adequately.
Governance provides the framework through which these activities are coordinated. It establishes responsibilities, defines decision-making authority, determines escalation requirements and ensures that significant safety concerns receive appropriate organisational visibility.
An effective governance framework does not replace scientific judgement. Rather, it provides a structured environment in which scientific judgement can be exercised consistently and transparently.
Why Governance Matters
Signal management activities frequently involve uncertainty. Decisions may need to be made using incomplete information, conflicting evidence or emerging observations that have not yet been fully characterised.
Without defined governance structures, organisations may encounter problems such as inconsistent decision-making, unclear accountability or delayed escalation of important safety concerns.
Governance contributes to:
- Accountability
- Consistency
- Transparency
- Oversight
- Regulatory compliance
The objective is not to create unnecessary bureaucracy. The objective is to ensure that safety-related decisions are visible, documented and appropriately reviewed.
Governance Within the Signal Management Lifecycle
Governance should support every stage of signal management.
A simplified lifecycle may be represented as:
Signal Detection
↓
Signal Validation
↓
Signal Assessment
↓
Decision Making
↓
Action or Closure
At each stage, governance arrangements help determine:
- Who performs the activity
- Who reviews the activity
- Who approves conclusions
- Who receives escalations
The level of governance required may vary depending upon the significance of the signal and the complexity of the product portfolio.
Defining Responsibilities
One of the primary objectives of governance is the allocation of responsibilities.
Signal management activities often involve multiple functions, including:
- Pharmacovigilance
- Safety physicians
- Epidemiologists
- Regulatory affairs
- Medical affairs
- Quality personnel
Roles should be defined clearly.
Ambiguity regarding responsibilities frequently contributes to delays, duplication of effort and inspection findings.
Organisations should be able to explain who is responsible for:
- Detection activities
- Validation decisions
- Signal assessments
- Escalation decisions
- Regulatory communications
These responsibilities should be reflected within procedures and governance documents.
Decision-Making Authority
Governance frameworks should define how decisions are made and who has authority to make them.
Examples of decisions may include:
- Whether a signal should be validated
- Whether additional assessment is required
- Whether escalation is necessary
- Whether regulatory action should be proposed
Not all decisions require the same level of review.
Routine signal closures may be managed at operational level, whereas signals with potential public health implications may require review by senior governance bodies.
Clearly defined decision-making authority helps ensure consistency and accountability.
Signal Review Committees
Many organisations utilise formal committees to support signal management activities.
Committee structures vary considerably between organisations but commonly include multidisciplinary participation.
Examples include:
- Signal Review Committees
- Safety Management Teams
- Product Safety Committees
- Benefit-Risk Review Committees
The purpose of such committees is not merely to review data.
They provide a forum for discussion, challenge and collective decision-making.
Committee structures are particularly valuable when evaluating signals with significant uncertainty or potential regulatory implications.
Escalation Pathways
Escalation is a critical governance function.
Most organisations review numerous observations during routine signal management activities. Only a subset of these observations require broader organisational visibility.
Governance frameworks should therefore define:
- Escalation criteria
- Escalation timelines
- Escalation recipients
- Documentation requirements
Escalation criteria may include:
- Potential public health impact
- Significant benefit-risk implications
- Emerging safety issues
- Potential regulatory action
- Significant media interest
The objective is to ensure that important concerns receive appropriate attention while avoiding unnecessary escalation of routine matters.
Emerging Safety Issues
Emerging safety issues frequently represent the highest level of signal-related escalation.
Governance arrangements should clearly describe:
- How potential ESIs are identified
- Who evaluates them
- Who is informed
- How decisions are documented
Because emerging safety issues may require accelerated assessment and communication, governance arrangements should support timely review without compromising scientific rigour.
Inspectors often examine ESI governance arrangements in detail.
Governance Documentation
Documentation provides evidence that governance activities have occurred.
Examples of governance records include:
- Committee agendas
- Meeting minutes
- Decision logs
- Escalation records
- Action trackers
- Assessment approvals
Documentation should allow reconstruction of:
- What information was reviewed
- Who reviewed it
- What conclusions were reached
- What actions were agreed
Governance decisions that cannot be reconstructed may be difficult to defend during inspections.
Integration With Benefit-Risk Evaluation
Signal management governance should not operate independently from broader pharmacovigilance governance.
Important signals may influence:
- PSUR conclusions
- Risk Management Plans
- Benefit-risk assessments
- Product information
- Regulatory submissions
Governance structures should therefore facilitate communication between signal management activities and other pharmacovigilance processes.
Inspectors frequently assess whether this integration exists in practice rather than only within procedures.
Integration With Risk Management Systems
Signal management and risk management systems are closely connected.
Signals may lead to:
- Identification of new risks
- Reclassification of potential risks
- Additional pharmacovigilance activities
- Additional risk minimisation measures
Governance frameworks should support communication between signal management functions and personnel responsible for risk management activities.
Failure to integrate these activities may result in inconsistent safety strategies.
Role of Senior Management
The degree of senior management involvement varies between organisations.
Routine signal activities generally do not require executive review.
However, significant safety concerns may require visibility at higher organisational levels, particularly when:
- Public health implications exist
- Major regulatory actions are anticipated
- Product information changes are proposed
- Significant business impacts may occur
Governance arrangements should define circumstances in which senior management involvement is required.
Role of the QPPV
The QPPV occupies an important position within signal management governance.
The QPPV is not normally responsible for conducting signal detection analyses or leading routine signal assessments. However, the QPPV should maintain visibility of significant signal-related activities and understand how governance arrangements support identification and management of safety concerns.
Inspectors commonly explore:
- Which signals are escalated to the QPPV
- How escalation occurs
- How emerging safety issues are communicated
- How benefit-risk implications are reviewed
The expectation is generally one of oversight rather than operational ownership.
A QPPV should be able to explain how the governance framework enables visibility of important safety concerns.
Outsourced Signal Management Activities
Signal management activities may be partially outsourced to vendors or service providers.
Examples include:
- Statistical signal detection
- Literature monitoring
- Epidemiological support
- Safety data analysis
Governance arrangements should ensure that outsourced activities remain visible and subject to appropriate oversight.
The Marketing Authorisation Holder retains responsibility for pharmacovigilance compliance irrespective of outsourcing arrangements.
Vendor governance should therefore include:
- Performance monitoring
- Escalation pathways
- Quality oversight
- Communication mechanisms
Governance During Inspections
Inspectors frequently assess governance arrangements because governance provides evidence that signal management activities operate in a controlled and consistent manner.
Inspection discussions may focus on:
- Committee structures
- Escalation records
- Decision-making processes
- QPPV visibility
- Governance documentation
Findings are often associated with weak governance implementation rather than deficiencies in technical signal management methodology.
The ability to explain how decisions are made and escalated is therefore particularly important.
Common Governance Weaknesses
Several governance deficiencies recur across inspections.
Examples include:
Unclear Responsibilities
Personnel cannot explain who owns specific activities.
Poor Escalation Processes
Important concerns are not communicated appropriately.
Weak Documentation
Governance decisions cannot be reconstructed.
Limited QPPV Visibility
Significant signals do not receive adequate oversight.
Fragmented Decision-Making
Different functions reach conclusions independently without coordinated review.
Poor Integration
Signal management outputs do not influence broader benefit-risk activities.
These weaknesses often reduce confidence in the overall pharmacovigilance system.
Characteristics of Mature Governance Frameworks
Mature signal management governance frameworks generally demonstrate:
- Clearly defined responsibilities
- Formal decision-making processes
- Effective escalation pathways
- Appropriate QPPV visibility
- Strong documentation practices
- Integration with benefit-risk activities
- Consistent implementation across products
Such frameworks support both regulatory compliance and effective safety oversight.
Responsibility Matrix (RACI) for Signal Management
A clear responsibility matrix (RACI) is an operationally useful and inspection-relevant governance artifact. The matrix clarifies who is Responsible (R), Accountable (A), Consulted (C) and Informed (I) at each step of the signal lifecycle. The matrix should be referenced in the Signal Management SOP and maintained as a controlled document.
Key roles used in the sample RACI below: - PV Ops = Pharmacovigilance Operations - SP = Safety Physician / Medical Reviewer - Epi = Epidemiology - RA = Regulatory Affairs - MA = Medical Affairs - Q = Quality Assurance - QPPV = Qualified Person for Pharmacovigilance - PSL = Product Safety Lead / Global Safety Lead - Clin Dev = Clinical Development - Vendor = External vendor / CRO - SM = Senior Management - Legal = Legal / Compliance
Note: ensure a single Accountable (A) per row in practice. The sample below is a template; organisations should map roles to their local titles.
| Task / Decision | PV Ops | SP | Epi | RA | MA | Q | QPPV | PSL | Clin Dev | Vendor | SM | Legal |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Routine signal detection | R | I | C | I | I | I | I | C | I | R | I | I |
| Initial triage / validation | R | C | C | I | I | I | I | A | I | C | I | I |
| Signal prioritisation | R | C | C | I | C | I | I | A | I | I | I | I |
| Detailed signal assessment | R | A | C | I | C | I | C | C | C | C | I | I |
| Epidemiological study scoping / request | R | C | A | I | I | I | I | C | C | R | I | I |
| ESI (Emerging Safety Issue) designation | R | C | C | I | I | I | A | C | I | I | I | I |
| Convene signal review committee | R | C | C | I | C | I | A | C | I | I | I | I |
| Committee decision / approval | I | C | C | C | C | C | A | R | I | I | I | I |
| Regulatory notification / submission (safety) | R | C | C | A | C | I | C | C | I | I | I | C |
| PI / Label change proposal | R | A | C | C | C | I | C | C | I | I | I | C |
| RMP / PSUR input related to signal | R | C | A | C | C | I | C | C | C | I | I | I |
| Risk minimisation measure decision | R | A | C | C | C | I | C | C | I | I | I | C |
| External / public communications | R | C | C | A | A | I | C | C | I | I | I | C |
| Vendor oversight / performance monitoring | I | I | I | I | I | A | I | R | I | R | I | I |
| Documentation & retention (assessment files) | R | C | C | I | I | A | I | C | I | I | I | I |
| Escalation to senior management | R | C | C | I | I | I | A | C | I | I | I | I |
| QPPV sign-off for significant actions | I | C | C | I | I | I | A | C | I | I | I | I |
| Inspection response & evidence collation | R | C | C | C | C | A | I | C | I | I | I | C |
| Training & competence records | R | I | I | I | I | A | I | I | I | I | I | I |
Implementation notes for the RACI: - A single accountable role should be identified for each task; the A is ultimately answerable. - “Responsible” (R) denotes the role executing the activity; multiple R roles may exist where co-ownership is explicit but this is best avoided for critical decisions. - “Consulted” (C) are subject matter experts who must be involved in the decision process; their input should be documented. - “Informed” (I) will receive outcomes and decisions and must be recorded in communication logs. - The RACI should be version controlled and included as part of the Signal Management SOP and governance pack submitted during inspections. - When activities are outsourced, the MAH remains Accountable even where Vendor is Responsible; contracts and QA agreements must reflect this allocation.
Implementing the RACI in Practice (practical details)
- Map local job titles to RACI roles: create a role-to-person index with current incumbents, contact details and delegated authorities.
- Include delegation of tasks in GxP delegation logs or organisational charters. Retain signed delegation records for inspection.
- Incorporate the RACI into the Signal Management SOP and cross-reference it in Committee Charters, QPPV oversight procedures and vendor quality agreements.
- Use a controlled template for decision logs that aligns to the RACI fields (e.g., who performed the action (R), who approved (A), consulted (C), informed (I)).
- Update the RACI during organisational change and at least annually; record changes in the document control system.
- Train relevant personnel on the RACI and make the matrix readily available in the pharmacovigilance intranet or quality management system.
- Apply the RACI in routine exercises and mock inspections to test whether responsibilities operate as described.
Regulatory context and inspection relevance: - EMA GVP Module IX expects that signal management is subject to defined responsibilities and governance, with appropriate QPPV oversight—an explicit RACI meets this expectation for clarity. - Inspectors will look for evidence that the roles in the RACI map to actual practice: committee minutes that show attendance of declared members; decision records that identify the accountable person; signed approvals. - Discrepancies between the RACI and practical evidence (e.g., different person approving minutes) are a common inspection finding.
Inspection‑Ready Checklist for Signal Management Governance
The checklist below groups items inspectors routinely request. For each item include the "Document Name", "Version", "Location", and "Responsible Person". Maintain both electronic and where required, a locked “inspection pack” copy.
Organise the pack with a table of contents and cross-reference index to enable rapid retrieval of evidence during inspection.
Checklist categories: Governance Documents, Committee Evidence, Signal Records, Escalation & Communication, QPPV & Senior Management Oversight, Vendor Oversight, Training & Competence, Quality & Audit Evidence, Metrics & Management Review.
Governance Documents
- [ ] Signal Management SOP — current version and controlled previous versions (with change history)
- Evidence: SOP PDF, Document control record
- [ ] Committee charters (Signal Review Committee, Product Safety Committee, etc.)
- Evidence: charters with approved signatures, membership rosters
- [ ] RACI / Responsibility matrix
- Evidence: controlled RACI document and role-to-person index
- [ ] Escalation procedure and criteria (documented thresholds with examples)
- Evidence: SOP excerpt, escalation flowchart
- [ ] QPPV oversight procedure and delegation log
- Evidence: QPPV delegation statements, CV, contact details
Committee Evidence
- [ ] Meeting agendas and meeting packs (for selected period)
- Evidence: dated agendas with distribution lists
- [ ] Meeting minutes with attendance and action items
- Evidence: minutes signed/approved by chair, attendance list, conflicts of interest declarations
- [ ] Decision approvals and recorded votes / consensus statements
- Evidence: decision log, approval emails or signatures
- [ ] Action trackers showing owner, due date, closure evidence
- Evidence: action log entries with closure documentation
Inspection relevance: inspectors will verify that minutes record who was consulted, who approved, what data were reviewed, and that actions were closed or tracked.
Signal Records and Assessments
- [ ] Signal validation and triage records
- Evidence: validation forms, underlying data extracts, date-stamped records
- [ ] Full assessments (narratives, causality reasoning, literature searches, epidemiology inputs)
- Evidence: assessment reports with author, approver and version control
- [ ] Prioritisation records and scoring with rationale
- Evidence: prioritisation tool outputs, committee scoring sheets
- [ ] ESI designation records and timelines
- Evidence: ESI log, communication records, QPPV notification
- [ ] Regulatory actions / submissions linked to signals
- Evidence: CIOMS reports, expedited notifications, variations, letters to regulators
Inspection relevance: inspectors will reconstruct decision-making pathways — ensure all source materials and intermediate analyses are retained and referenced.
Escalation & Communication Records
- [ ] Escalation emails, logs and timelines (who was notified, when, and how)
- Evidence: timestamped communications, acknowledged receipts
- [ ] External communications (Dear HCP letters, press releases, Health Authority correspondence)
- Evidence: final approved versions, approvals, dissemination logs
- [ ] Internal briefings to senior management and cross-functional committees
- Evidence: presentations, briefing notes, distribution list
QPPV & Senior Management Oversight
- [ ] Records of QPPV consultations and sign-offs for significant actions
- Evidence: sign-off statements, email approvals, meeting minutes
- [ ] Evidence of senior management briefings when required by escalation criteria
- Evidence: meeting minutes, memos, risk assessments with senior approvals
- [ ] Delegation of authority records (who may act in QPPV absence)
- Evidence: delegation letters, alternate QPPV arrangements
Inspection relevance: inspectors expect to see the QPPV informed and actively involved where regulation requires.
Vendor Oversight & Outsourcing
- [ ] Contracts, Pharmacovigilance Agreements and Quality Agreements with vendors
- Evidence: signed agreements, SLA metrics, KPIs
- [ ] Vendor performance reports and oversight minutes
- Evidence: KPI reports, vendor QA review minutes, corrective action records
- [ ] Evidence of vendor escalation pathways and how vendor outputs feed into MAH governance
- Evidence: example vendor-generated signals and subsequent MAH actions
Inspection relevance: regulators will verify that MAH oversight of vendors is active and evidenced; accountability cannot be delegated away.
Training & Competence Records
- [ ] Training records for personnel responsible for signal management activities
- Evidence: training matrices, completion certificates, curricula
- [ ] CVs / role descriptions for key personnel (QPPV, Product Safety Lead, Committee chairs)
- Evidence: current CVs, role descriptions, responsibilities
- [ ] Records of mock exercises or scenario-based training (e.g., emergent ESI drills)
- Evidence: exercise reports, lessons learned
Quality & Audit Evidence
- [ ] Internal audit reports related to signal management and follow-up CAPAs
- Evidence: audit report, CAPA plan, closure evidence
- [ ] Management review minutes referencing signal management metrics
- Evidence: management review records, action items
- [ ] Change control records for SOPs, RACI or governance documents
- Evidence: change requests, approvals, implementation evidence
Inspection relevance: auditors will link persistent governance weaknesses to prior audits and CAPA effectiveness.
Metrics & KPIs
- [ ] Signal lifecycle KPIs (detection-to-validation timelines, time-to-escalation)
- Evidence: KPI dashboards, trend analyses
- [ ] Committee attendance and decision-rate metrics
- Evidence: periodic reports, exceptions logged and explained
Evidence Retention & Accessibility
- [ ] Record retention policy and retrieval logs
- Evidence: policy, examples of retrieval requests, backup/archive status
- [ ] Cross-referenced index mapping SOP sections to evidence files
- Evidence: index spreadsheet, hyperlinks to electronic records
Practical Steps to Assemble an Inspection Pack (operational implementation)
- Create a controlled index with hyperlinked documents or a printable binder of evidence items matching the checklist categories above.
- For each checklist entry record: Document title, version, date, owner, location (physical or electronic), and a short note explaining relevance (e.g., “committee minutes demonstrating QPPV sign-off for Signal X”).
- Pre-select representative signals (e.g., one routine closure, one ESI, one signal leading to PI change) and compile a signal dossier for each that includes detection outputs, validation documents, assessment, committee outcomes and regulatory correspondence.
- Keep a “sample set” of vendor deliverables linked to the signal dossiers to demonstrate integration and oversight.
- Ensure action trackers are current at the time of inspection and provide closure evidence for historical actions.
Regulatory context: EMA inspectors and other regulators expect easy reconstruction of the decision trail. Pack organisation that maps directly to the signal lifecycle and the RACI accelerates inspection reviews and reduces the likelihood of findings.
Governance Discussion: Integration, Delegation and Oversight
- Delegation: governance should show where tasks are delegated and where ultimate accountability rests. Delegation logs and contractual clauses should be explicit and consistent with the RACI.
- Change control: any change to the signal governance model (committee composition, SOP changes, RACI updates) should follow change control with impact assessment, documented approvals and training updates.
- Governance metrics: use KPIs to demonstrate governance effectiveness (e.g., median time to triage, percentage of signals escalated to QPPV, closure rates). Regulators may request trend data during inspections.
- Continuous improvement: governance artifacts (RACI, SOPs, committee charters) should be reviewed after significant events (e.g., an ESI) to capture lessons learned; records of such reviews are inspection-relevant evidence.
Common Inspection Questions and Evidence Mapping
- Q: Who is accountable for deciding to notify regulators about a signal?
- Evidence: RACI mapping, committee minutes showing decision, QPPV sign-off, submission documents.
- Q: How are vendors integrated into the signal process?
- Evidence: contractual agreements, QA oversight minutes, examples of vendor outputs incorporated into signal assessments.
- Q: How does the organisation ensure the QPPV sees significant signals?
- Evidence: escalation logs, QPPV notification emails, signed assessments, committee attendance.
Document these question–evidence linkages in the inspection pack to facilitate rapid responses.
Key Takeaways
- A formal RACI clarifies accountabilities and supports consistent signal management decisions; it should be controlled and referenced in SOPs.
- Inspectors expect traceability: a clear decision trail from detection through assessment, committee review, QPPV sign-off and regulatory action or closure.
- An inspection‑ready checklist, pre-populated with documents and cross-references, demonstrates governance implementation and facilitates effective inspection responses.
References
- EMA Good Pharmacovigilance Practices (GVP) Module IX – Signal Management.
- EMA Good Pharmacovigilance Practices (GVP) Module I – Pharmacovigilance Systems and Their Quality Systems.
- EMA Good Pharmacovigilance Practices (GVP) Module V – Risk Management Systems.
- Commission Implementing Regulation (EU) No 520/2012.
- Regulation (EC) No 726/2004.
- Directive 2001/83/EC.
- CIOMS VIII Practical Aspects of Signal Detection in Pharmacovigilance.
- ICH E2E Pharmacovigilance Planning.
- ICH E2C(R2) Periodic Benefit-Risk Evaluation Report.