Vendor Audits in Pharmacovigilance

A comprehensive guide to vendor audits, audit planning, execution, findings, CAPAs and vendor oversight governance.

Audio Lesson 10 min

Vendor Audits in Pharmacovigilance

Introduction

Outsourcing pharmacovigilance activities creates dependency.

When critical activities are performed by third parties, organisations must demonstrate that those activities remain under effective control.

Governance meetings, KPIs and contractual agreements contribute to oversight.

However, these mechanisms often rely heavily upon information provided by the vendor.

Audits provide something different.

They provide independent verification.

For this reason, vendor audits remain one of the most important tools within a mature pharmacovigilance oversight framework.

Why Vendor Audits Matter

Vendor oversight requires evidence.

An organisation may believe:

An audit helps determine whether those assumptions are correct.

Vendor audits help answer questions such as:

The objective is not simply to identify deficiencies.

The objective is to understand whether outsourced activities remain under control.

The Regulatory Perspective

Regulators generally expect organisations to maintain oversight of outsourced activities.

Inspectors frequently review:

The absence of audits does not automatically indicate non-compliance.

However, organisations should be able to explain how oversight effectiveness is verified.

Audits are often one of the strongest forms of evidence.

Primary regulatory references for audit expectations include GVP Module I (Pharmacovigilance Systems and Their Quality Systems), GVP Module III (Pharmacovigilance Inspections), ICH Q9 (Quality Risk Management), PIC/S guidance on pharmacovigilance inspections and regional legislative frameworks (e.g., Regulation (EC) No 726/2004, Directive 2001/83/EC). These documents set expectations for demonstrated risk-based oversight, documented evidence of control and effective corrective action.

Audits Within the Vendor Oversight Lifecycle

Vendor audits should not be viewed as isolated events.

They form part of a broader oversight lifecycle.

Vendor Qualification
        ↓
Risk Assessment
        ↓
Contracting
        ↓
Onboarding
        ↓
Oversight
        ↓
Audit
        ↓
CAPA
        ↓
Continuous Improvement

An audit provides an opportunity to test whether governance assumptions remain valid.

Audit Objectives

Audit objectives vary depending on the vendor relationship.

Common objectives include:

A clear objective improves audit effectiveness.

Risk-Based Audit Planning

Not all vendors require the same audit frequency.

Audit planning should generally be driven by risk.

Examples include:

Low-Risk Vendors

May require:

Medium-Risk Vendors

May require:

High-Risk Vendors

May require:

Critical Vendors

May require:

Risk-based planning improves resource allocation.

For additional information see:

[[vendor-risk-assessment]]

Audit Types

Several audit approaches may be used.

On-Site Audits

Auditors visit the vendor's facilities.

Advantages:

Challenges:

Remote Audits

Conducted virtually.

Advantages:

Challenges:

Hybrid Audits

Combine remote and on-site elements.

Increasingly common within modern audit programmes.

Audit Scope

Audit scope should reflect vendor risk and activity type.

Examples include:

Case Processing Vendors

Potential scope:

Literature Monitoring Vendors

Potential scope:

Safety Database Vendors

Potential scope:

The scope should focus on areas creating the greatest risk.

Audit Preparation

Effective audits begin long before the audit date.

Preparation commonly includes:

Preparation helps focus attention on higher-risk areas.

Practical implementation details: - Maintain a vendor audit dossier that contains contracts, SLAs, previous audit reports, KPIs, process maps and risk assessments. Use a consistent folder structure and file naming convention (e.g., VendorName_Audit_YYYYMMDD_Report_v1.pdf). - Prepare an audit plan and checklist derived from the risk assessment and previous findings. Include specific case samples or samples of records to be reviewed on-site or provided remotely. - Confirm access, data protection constraints and redaction expectations in advance; obtain NDAs if necessary. - Schedule time for evidence collection and establish secure file transfer mechanisms (SFTP, encrypted email, secure portals).

Conducting the Audit

Typical activities include:

Opening Meeting

Defines:

Document Review

Examines:

Interviews

Assesses:

Process Verification

Confirms whether activities operate as described.

Closing Meeting

Summarises observations and findings.

Practical tips: - Use process mapping exercises to verify handoffs. - Validate a sample of actual case records against expected timelines and database entries. - Observe live activities where permissible (e.g., case triage) or request system screen-recordings if remote.

Audit Findings

Findings vary considerably.

Examples include:

Documentation Issues

Compliance Issues

Governance Issues

Quality Issues

The significance of a finding depends on both severity and risk.

Finding Classification

Many organisations classify findings.

Example:

Classification Description
Critical Immediate significant risk
Major Significant weakness
Minor Limited impact
Observation Improvement opportunity

Consistent classification supports risk-based follow-up.

Below is an operationalised classification schema with regulatory context, expected sponsor actions, timelines and inspection relevance.

Classification definitions, expected timelines and required evidence (summary)

Consistent classification supports inspection narratives and enables prioritised governance escalation.

CAPA Management

An audit is valuable only if findings lead to improvement.

Corrective and Preventive Actions should:

Weak CAPAs often focus on symptoms.

Strong CAPAs improve systems.

Practical implementation details: - Require root cause analysis using structured techniques (5 Whys, Fishbone, Pareto) and document outputs. - Use a central CAPA register with unique IDs, owners, status, target dates, attached evidence and effectiveness check dates. Integrate this register with the vendor oversight governance dashboard. - Define measurable success criteria for each CAPA (e.g., "0 reporting breaches in 3 months", "100% retraining completion, attested by test scores"). - Use tiered verification: vendor self-verification (evidence upload), sponsor QA review and verification, and for Critical findings consider third-party verification or re-audit.

For additional information see:

[[vendor-capas]]

Follow-Up Activities

Audit closure should not mark the end of oversight.

Follow-up activities may include:

The objective is sustained improvement.

Implementation specifics: - Schedule effectiveness checks at defined intervals (e.g., 30, 90, 180 days) based on classification and risk. - Maintain an evidence trail: for each closed CAPA attach RCA, implemented change, training records, metrics demonstrating effectiveness and QA verification. - Escalate overdue CAPAs according to governance thresholds (e.g., any Critical CAPA overdue by 5 business days escalates to QPPV and Chief Compliance Officer).

Common Audit Mistakes

Several weaknesses occur repeatedly.

Checklist Auditing

Audits become procedural rather than risk-focused.

Excessive Scope

Too many areas are reviewed superficially.

Weak Root Cause Analysis

Findings are identified but not understood.

Poor Follow-Up

CAPAs remain open or ineffective.

Lack of Risk Prioritisation

Resources are allocated inefficiently.

These weaknesses reduce audit value.

The QPPV Perspective

The QPPV may not personally perform vendor audits.

However, visibility remains important.

Examples include:

Audit outcomes often provide valuable insight into oversight effectiveness.

Governance discussion: - Define RACI for audit lifecycle: who requests and sponsors audits (Clinical Safety Lead / PV Head), who executes audits (QA/audit team), who reviews & accepts findings (Sponsor QA, QPPV) and who oversees closure (Vendor Management / PV Operations). - Ensure senior management and QPPV receive concise escalations for Critical and Major findings with timelines and mitigation measures. - Integrate audit outcomes into periodic governance (e.g., quarterly PV oversight committee), ensuring trending and risk re-assessment drives audit frequency adjustments.

Inspection Perspective

Inspectors frequently review:

A common question is:

How does the organisation know the vendor is operating effectively?

Audit evidence often forms a significant part of the answer.

Inspection relevance — what inspectors commonly expect to see: - Evidence that audits are planned based on risk and that frequency/scope reflect that risk. - Audit reports that document objective observations, classifications, risk impact and clear CAPAs with timelines. - Evidence of timely CAPA implementation and effective verification. - Documentation demonstrating QPPV and senior management oversight for serious findings. - Traceability of how audit findings translate into system changes, training and improved performance metrics. - Retention of audit records consistent with regional requirements and sponsor document retention policy.

Practical note: during inspections, be prepared to present the vendor audit dossier, CAPA register entries and evidence packages (redacted as needed) and to explain governance escalation decisions.

Characteristics of Mature Audit Programmes

High-performing organisations generally demonstrate:

Risk-Based Planning

Audit frequency reflects risk.

Clear Objectives

Audits focus on meaningful risks.

Competent Auditors

Auditors understand pharmacovigilance requirements.

Effective CAPAs

Findings drive improvement.

Continuous Improvement

Audit results influence governance activities.

These characteristics improve both compliance and oversight.

Inspection-Readiness Checklist (Concise and Operational)

Use this checklist to prepare sponsor and vendor documentation ahead of an inspection. The checklist is intentionally concise; each item should map to a specific evidence file or system location.

Documentation and Records - Current contract, SLA and statement of work (signed) for each critical vendor (file: VendorName_Contract_signed.pdf). - Latest vendor risk assessment and audit schedule (file: VendorName_RiskAssessment_YYYYMMDD.pdf). - Most recent audit report(s) and related annexes (file: VendorName_AuditReport_YYYYMMDD.pdf). - CAPA register entries related to vendor findings with supporting evidence attachments (file: VendorName_CAPARegister.xlsx + attachments folder). - Relevant SOPs and process maps (vendor and sponsor-facing) in effect at time of audit (file: SOP_VendorCaseProcessing_vX.pdf). - System validation/qualification documents for critical PV systems used by vendor (IQ/OQ/PQ/Validation Summary). - Data transfer agreements and evidence of secure data transfers (SFTP logs, access control lists). - Records of data integrity checks, system access logs and audit trails for safety databases. - Case examples sampled during the audit with redaction applied as required (case lists and demonstrated reconciliation to database entries).

People and Training - Organisational charts showing PV-responsible roles and escalation paths. - Training matrices and selected training records for staff performing PV tasks (completed training evidence + dates). - Declarations of independence for vendor QA/auditor involved in the audit.

Governance and Oversight - Minutes of key governance meetings where vendor performance was discussed (quality committee, PV oversight) including attendees (file: PVOversight_Minutes_YYYYMMDD.pdf). - KPI trending reports and supplier scorecards for the audit period. - Management escalation emails/records for Critical/Major findings with confirmation of QPPV notification.

Evidence Management and Accessibility - Centralised evidence repository location and access instructions for inspectors (portal details, redaction policy). - Evidence index or audit evidence tracker mapping each finding to supporting documents and storage location. - Retention policy showing record retention periods and legal/regulatory basis.

Operational Readiness - Contact list for vendor audit lead, vendor QA and sponsor audit lead (with availability during inspection). - A prepared narrative and timeline for any open Critical/Major CAPAs (containment, RCA, implementation, verification). - Pre-prepared redacted evidence packages for rapid inspector review, with clear labelling and cross-references.

Practical implementation suggestions: - Maintain an "inspection pack" for each critical vendor updated quarterly. - Ensure evidence is accessible electronically and preserved in read-only format to prevent post-inspection remediation claims. - Test retrieval of key documents monthly as part of oversight KPIs.

Inspection relevance: - Inspectors often request a chronological timeline from issue identification to closure; maintain an event timeline for significant findings. - Be prepared to show how CAPAs were prioritised, implemented and verified, including who reviewed and approved closure.

Standard Audit Report Template — Operational and Inspection-Focused

Below is a standardised audit report structure designed for pharmacovigilance vendor audits. The template includes the core content plus guidance on classification, timelines, required evidence and follow-up expectations that inspectors typically review.

Report header - Report title: Vendor Audit Report — [Vendor Name] - Report ID: [VendorName_Audit_YYYYMMDD_vX] - Sponsor: [Company Name] (QPPV: [Name]) - Vendor: [Vendor Name], site/location - Audit period/dates: [On-site dates / remote dates] - Lead auditor(s): [Name(s), function] - Audit team: [Members and competencies] - Distribution list: [Sponsor QA, QPPV, PV Head, Vendor QA, Business Owner, Legal if applicable]

Executive summary (<= 1 page) - Purpose and scope (concise) - Summary of key findings and their potential impact on patient safety/regulatory compliance - Overall audit rating (if used) and immediate actions required

Background and context - Vendor activities covered (e.g., ICSRs, literature screening, database hosting) - Contractual obligations relevant to scope (reference to agreement sections) - Relevant previous audit history and CAPA status - Risk categorisation of vendor at time of audit

Audit scope and methodology - Detailed scope (processes, systems, time periods) - Sampling methodology (number and selection criteria for cases, documents) - Documentation reviewed (list) - Interviews conducted (roles) - Tools used (checklists, observation forms)

Findings (structured and traceable) - For each finding include: - Finding ID (e.g., FIND-001) - Title - Classification (Critical/Major/Minor/Observation) - Location (process/system) - Description (what was observed; include evidence references) - Impact/risk assessment (brief) - Regulatory relevance (cite GVP/ICH/PIC/S where applicable) - Root cause hypothesis (if identified during audit) - Immediate / containment actions taken (if any) - Recommended actions (sponsor & vendor responsibilities)

Example entry: - FIND-001 — Delayed reporting of serious ICSRs - Classification: Critical - Location: Case processing queue, Vendor X - Description: 4/20 sampled serious ICSRs exceeded regulatory reporting timelines; system timestamps indicate case creation delayed. - Evidence: Sample case IDs (redacted), system logs (evidence ref 3), KPI report period Q1. - Impact: Potential patient safety and regulatory reporting non-compliance. - Regulation: GVP I; national reporting timelines. - Immediate action: Vendor quarantined backlog; sponsor notified (timestamped email). - Recommended action: RCA, immediate rework of backlog, review of intake SOP, QA verification and escalation to QPPV.

Findings summary table - Provide a concise table listing all findings with classification, owner and target CAPA date.

Required evidence and attachments (indexed) - Numbered attachments such as procedure extracts, sample case exports (redacted), system validation reports, training records, governance minutes. Provide an evidence index mapping each finding to attachment IDs.

Vendor response (if included) - Vendor's preliminary responses, proposed CAPAs and target dates. Note whether the vendor accepted the finding and action plan.

Sponsor assessment and actions - Sponsor QA review comments, acceptance of vendor CAPA, sponsor-led actions (e.g., additional monitoring, change in oversight frequency), and escalation to QPPV if applicable.

CAPA expectations and timelines (per classification) - Critical: containment documented within 24–72 hours; preliminary CAPA within 5 working days; full CAPA within 10 working days; closure & effectiveness verification within 30–60 days. Sponsor QA verification required; consider regulatory notification. - Major: CAPA plan within 10–15 working days; target closure 30–90 days; sponsor QA verification on completion. - Minor: CAPA plan within 20–30 working days; target closure 60–120 days; closure confirmed by vendor QA and sponsor sample verification. - Observation: Vendor to consider and integrate within improvement cycles; inclusion in next audit evidenced.

Verification and evidence requirements (per classification) - Critical: RCA report, containment logs, list of affected cases and reprocessing results, SOPs revised, training records demonstrating competence, system change validation, QA verification letter, minutes of management escalation. - Major: RCA, action plan, revised documents, training completion evidence, sample evidence of corrected processing, change control records and verification. - Minor: Documented corrective actions, training sign-off, sample checks show correction. - Observation: Management response or acknowledgement; improvement plan entry.

Follow-up and monitoring expectations - CAPA owner and sponsor oversight responsibilities - Effectiveness check dates to be scheduled (e.g., 30, 90, 180 days) with predefined metrics - Reporting cadence to sponsor PV oversight committee - Conditions for re-audit (e.g., re-audit required if Critical or repeated Major findings)

Conclusions and overall assessment - Concise statement on overall vendor control and residual risk - Recommendations for governance and schedule adjustments

Signatures and approvals - Lead auditor, sponsor QA reviewer, vendor QA acknowledgement, QPPV (if escalated) - Date of final report issuance

Annexes - Detailed checklist used - Full list of documents reviewed - Interview lists - Complete evidence index with file names and locations - Vendor corrective action plan (if received)

Practical implementation details for the report: - Issue a draft report within 10–15 working days of audit completion; allow vendor 10 working days to comment on factual accuracy. - Final report to be issued within 20–30 calendar days, including sponsor QA review and acceptance of vendor responses. - Use consistent formatting and a standard numbering convention for findings and attachments to facilitate inspection requests.

Inspection relevance: - Inspectors will examine the audit report structure, the link between findings and evidence, the timeliness and adequacy of CAPAs and the governance approvals. Well-structured reports reduce inspector queries and demonstrate control.

Governance and Escalation — Operational Expectations

Key Takeaways

References

  1. EMA Good Pharmacovigilance Practices (GVP) Module I – Pharmacovigilance Systems and Their Quality Systems.
  2. EMA Good Pharmacovigilance Practices (GVP) Module III – Pharmacovigilance Inspections.
  3. EMA Good Pharmacovigilance Practices (GVP) Module II – Pharmacovigilance System Master File.
  4. Regulation (EC) No 726/2004.
  5. Directive 2001/83/EC.
  6. Commission Implementing Regulation (EU) No 520/2012.
  7. ICH Q9 Quality Risk Management.
  8. PIC/S Guidance on Pharmacovigilance Inspections.
  9. Relevant regional legislation and guidance (as applicable per operating jurisdiction).

Last reviewed: 2026-06-11