Vendor Audits in Pharmacovigilance
- Vendor Audits in Pharmacovigilance
- Introduction
- Why Vendor Audits Matter
- The Regulatory Perspective
- Audits Within the Vendor Oversight Lifecycle
- Audit Objectives
- Risk-Based Audit Planning
- Audit Types
- Audit Scope
- Audit Preparation
- Conducting the Audit
- Audit Findings
- Finding Classification
- CAPA Management
- Follow-Up Activities
- Common Audit Mistakes
- The QPPV Perspective
- Inspection Perspective
- Characteristics of Mature Audit Programmes
- Inspection-Readiness Checklist (Concise and Operational)
- Standard Audit Report Template — Operational and Inspection-Focused
- Governance and Escalation — Operational Expectations
- Key Takeaways
- References
Introduction
Outsourcing pharmacovigilance activities creates dependency.
When critical activities are performed by third parties, organisations must demonstrate that those activities remain under effective control.
Governance meetings, KPIs and contractual agreements contribute to oversight.
However, these mechanisms often rely heavily upon information provided by the vendor.
Audits provide something different.
They provide independent verification.
For this reason, vendor audits remain one of the most important tools within a mature pharmacovigilance oversight framework.
Why Vendor Audits Matter
Vendor oversight requires evidence.
An organisation may believe:
- Processes are functioning
- Reporting timelines are being met
- Quality systems are effective
An audit helps determine whether those assumptions are correct.
Vendor audits help answer questions such as:
- Are procedures being followed?
- Are controls operating effectively?
- Are responsibilities understood?
- Are compliance risks managed appropriately?
The objective is not simply to identify deficiencies.
The objective is to understand whether outsourced activities remain under control.
The Regulatory Perspective
Regulators generally expect organisations to maintain oversight of outsourced activities.
Inspectors frequently review:
- Audit programmes
- Audit schedules
- Audit reports
- CAPAs
- Follow-up activities
The absence of audits does not automatically indicate non-compliance.
However, organisations should be able to explain how oversight effectiveness is verified.
Audits are often one of the strongest forms of evidence.
Primary regulatory references for audit expectations include GVP Module I (Pharmacovigilance Systems and Their Quality Systems), GVP Module III (Pharmacovigilance Inspections), ICH Q9 (Quality Risk Management), PIC/S guidance on pharmacovigilance inspections and regional legislative frameworks (e.g., Regulation (EC) No 726/2004, Directive 2001/83/EC). These documents set expectations for demonstrated risk-based oversight, documented evidence of control and effective corrective action.
Audits Within the Vendor Oversight Lifecycle
Vendor audits should not be viewed as isolated events.
They form part of a broader oversight lifecycle.
Vendor Qualification
↓
Risk Assessment
↓
Contracting
↓
Onboarding
↓
Oversight
↓
Audit
↓
CAPA
↓
Continuous Improvement
An audit provides an opportunity to test whether governance assumptions remain valid.
Audit Objectives
Audit objectives vary depending on the vendor relationship.
Common objectives include:
- Assessing compliance
- Evaluating controls
- Verifying contractual obligations
- Reviewing quality systems
- Assessing risk management
- Identifying improvement opportunities
A clear objective improves audit effectiveness.
Risk-Based Audit Planning
Not all vendors require the same audit frequency.
Audit planning should generally be driven by risk.
Examples include:
Low-Risk Vendors
May require:
- Limited audits
- Remote reviews
- Periodic assessments
Medium-Risk Vendors
May require:
- Scheduled audits
- Focused reviews
High-Risk Vendors
May require:
- More frequent audits
- Broader audit scope
Critical Vendors
May require:
- Enhanced audit programmes
- Senior management visibility
- Follow-up reviews
Risk-based planning improves resource allocation.
For additional information see:
[[vendor-risk-assessment]]
Audit Types
Several audit approaches may be used.
On-Site Audits
Auditors visit the vendor's facilities.
Advantages:
- Direct observation
- Staff interviews
- Process verification
Challenges:
- Cost
- Travel requirements
- Resource intensity
Remote Audits
Conducted virtually.
Advantages:
- Efficiency
- Lower cost
- Faster scheduling
Challenges:
- Reduced visibility
- Limited observation opportunities
Hybrid Audits
Combine remote and on-site elements.
Increasingly common within modern audit programmes.
Audit Scope
Audit scope should reflect vendor risk and activity type.
Examples include:
Case Processing Vendors
Potential scope:
- Case intake
- Data entry
- Quality review
- Reporting compliance
Literature Monitoring Vendors
Potential scope:
- Search strategies
- Screening processes
- Documentation
Safety Database Vendors
Potential scope:
- Data integrity
- Validation
- Security
- Change management
The scope should focus on areas creating the greatest risk.
Audit Preparation
Effective audits begin long before the audit date.
Preparation commonly includes:
- Reviewing agreements
- Reviewing previous audits
- Reviewing KPIs
- Reviewing deviations
- Reviewing CAPAs
Preparation helps focus attention on higher-risk areas.
Practical implementation details: - Maintain a vendor audit dossier that contains contracts, SLAs, previous audit reports, KPIs, process maps and risk assessments. Use a consistent folder structure and file naming convention (e.g., VendorName_Audit_YYYYMMDD_Report_v1.pdf). - Prepare an audit plan and checklist derived from the risk assessment and previous findings. Include specific case samples or samples of records to be reviewed on-site or provided remotely. - Confirm access, data protection constraints and redaction expectations in advance; obtain NDAs if necessary. - Schedule time for evidence collection and establish secure file transfer mechanisms (SFTP, encrypted email, secure portals).
Conducting the Audit
Typical activities include:
Opening Meeting
Defines:
- Objectives
- Scope
- Expectations
Document Review
Examines:
- Procedures
- Training records
- Quality records
- Governance records
Interviews
Assesses:
- Understanding
- Roles
- Responsibilities
Process Verification
Confirms whether activities operate as described.
Closing Meeting
Summarises observations and findings.
Practical tips: - Use process mapping exercises to verify handoffs. - Validate a sample of actual case records against expected timelines and database entries. - Observe live activities where permissible (e.g., case triage) or request system screen-recordings if remote.
Audit Findings
Findings vary considerably.
Examples include:
Documentation Issues
- Missing records
- Incomplete procedures
Compliance Issues
- Reporting delays
- Process deviations
Governance Issues
- Weak oversight
- Unclear responsibilities
Quality Issues
- Training gaps
- CAPA weaknesses
The significance of a finding depends on both severity and risk.
Finding Classification
Many organisations classify findings.
Example:
| Classification | Description |
|---|---|
| Critical | Immediate significant risk |
| Major | Significant weakness |
| Minor | Limited impact |
| Observation | Improvement opportunity |
Consistent classification supports risk-based follow-up.
Below is an operationalised classification schema with regulatory context, expected sponsor actions, timelines and inspection relevance.
Classification definitions, expected timelines and required evidence (summary)
- Critical
- Definition: A condition that presents an immediate and substantial risk to patient safety, regulatory compliance, or the integrity of pharmacovigilance activities (e.g., failure to report serious ADRs, system compromises affecting case data).
- Regulatory context: Inspectors regard Critical findings as high priority; immediate containment and notification to competent authorities may be required.
- Immediate actions expected: Containment within 24–72 hours; preliminary CAPA/containment plan within 5 working days; full CAPA plan within 10 working days.
- Target closure: 30–60 calendar days depending on complexity, with earlier regulatory notification if required.
- Required evidence: Incident/containment logs, impacted case list, emergency CAPA, root cause analysis (RCA), implementation evidence (SOPs, code changes), reprocessing results, effectiveness checks, management escalation minutes.
-
Follow-up expectations: Sponsor QA verification and evidence submission; possible re-audit or independent review; immediate notification to QPPV and regulatory bodies as appropriate.
-
Major
- Definition: A significant weakness that could lead to non-compliance or increased risk to pharmacovigilance operations if not corrected (e.g., systemic deviations in case processing, incomplete validation of a critical system).
- Regulatory context: Inspectors expect clear corrective action, timelines and evidence of remediation and verification.
- Immediate actions expected: CAPA plan within 10–15 working days.
- Target closure: 30–90 calendar days depending on root cause complexity.
- Required evidence: RCA, action plan, revised procedures, training records, reworked case samples, validation/qualification evidence for system changes, effectiveness checks.
-
Follow-up expectations: Regular governance review; verification by sponsor QA; potential targeted reassessment.
-
Minor
- Definition: A weakness with limited compliance impact; more of a deficiency than a systemic risk (e.g., isolated procedural omissions).
- Regulatory context: Inspectors expect corrective action but may regard these as lower priority.
- Immediate actions expected: CAPA plan within 20–30 working days.
- Target closure: 60–120 calendar days.
- Required evidence: RCA (scaled), corrective actions, training refresh evidence, sample checks.
-
Follow-up expectations: Verified by vendor QA; closure confirmed during subsequent audits or periodic assessments.
-
Observation
- Definition: Improvement opportunities or best-practice suggestions that do not currently pose compliance risk.
- Regulatory context: Observations are noted but usually not escalated unless recurring.
- Immediate actions expected: Management consideration; action within normal improvement cycles.
- Target closure: Implemented by next audit cycle or as part of continuous improvement initiatives.
- Required evidence: Management responses or inclusion in improvement roadmap.
- Follow-up expectations: Tracked but not necessarily subject to formal CAPA unless trends emerge.
Consistent classification supports inspection narratives and enables prioritised governance escalation.
CAPA Management
An audit is valuable only if findings lead to improvement.
Corrective and Preventive Actions should:
- Address root causes
- Prevent recurrence
- Be tracked to completion
Weak CAPAs often focus on symptoms.
Strong CAPAs improve systems.
Practical implementation details: - Require root cause analysis using structured techniques (5 Whys, Fishbone, Pareto) and document outputs. - Use a central CAPA register with unique IDs, owners, status, target dates, attached evidence and effectiveness check dates. Integrate this register with the vendor oversight governance dashboard. - Define measurable success criteria for each CAPA (e.g., "0 reporting breaches in 3 months", "100% retraining completion, attested by test scores"). - Use tiered verification: vendor self-verification (evidence upload), sponsor QA review and verification, and for Critical findings consider third-party verification or re-audit.
For additional information see:
[[vendor-capas]]
Follow-Up Activities
Audit closure should not mark the end of oversight.
Follow-up activities may include:
- CAPA review
- Effectiveness checks
- Targeted reassessments
- Additional monitoring
The objective is sustained improvement.
Implementation specifics: - Schedule effectiveness checks at defined intervals (e.g., 30, 90, 180 days) based on classification and risk. - Maintain an evidence trail: for each closed CAPA attach RCA, implemented change, training records, metrics demonstrating effectiveness and QA verification. - Escalate overdue CAPAs according to governance thresholds (e.g., any Critical CAPA overdue by 5 business days escalates to QPPV and Chief Compliance Officer).
Common Audit Mistakes
Several weaknesses occur repeatedly.
Checklist Auditing
Audits become procedural rather than risk-focused.
Excessive Scope
Too many areas are reviewed superficially.
Weak Root Cause Analysis
Findings are identified but not understood.
Poor Follow-Up
CAPAs remain open or ineffective.
Lack of Risk Prioritisation
Resources are allocated inefficiently.
These weaknesses reduce audit value.
The QPPV Perspective
The QPPV may not personally perform vendor audits.
However, visibility remains important.
Examples include:
- Critical findings
- Significant compliance risks
- High-risk vendors
- Escalated CAPAs
Audit outcomes often provide valuable insight into oversight effectiveness.
Governance discussion: - Define RACI for audit lifecycle: who requests and sponsors audits (Clinical Safety Lead / PV Head), who executes audits (QA/audit team), who reviews & accepts findings (Sponsor QA, QPPV) and who oversees closure (Vendor Management / PV Operations). - Ensure senior management and QPPV receive concise escalations for Critical and Major findings with timelines and mitigation measures. - Integrate audit outcomes into periodic governance (e.g., quarterly PV oversight committee), ensuring trending and risk re-assessment drives audit frequency adjustments.
Inspection Perspective
Inspectors frequently review:
- Audit schedules
- Audit reports
- CAPA records
- Follow-up activities
A common question is:
How does the organisation know the vendor is operating effectively?
Audit evidence often forms a significant part of the answer.
Inspection relevance — what inspectors commonly expect to see: - Evidence that audits are planned based on risk and that frequency/scope reflect that risk. - Audit reports that document objective observations, classifications, risk impact and clear CAPAs with timelines. - Evidence of timely CAPA implementation and effective verification. - Documentation demonstrating QPPV and senior management oversight for serious findings. - Traceability of how audit findings translate into system changes, training and improved performance metrics. - Retention of audit records consistent with regional requirements and sponsor document retention policy.
Practical note: during inspections, be prepared to present the vendor audit dossier, CAPA register entries and evidence packages (redacted as needed) and to explain governance escalation decisions.
Characteristics of Mature Audit Programmes
High-performing organisations generally demonstrate:
Risk-Based Planning
Audit frequency reflects risk.
Clear Objectives
Audits focus on meaningful risks.
Competent Auditors
Auditors understand pharmacovigilance requirements.
Effective CAPAs
Findings drive improvement.
Continuous Improvement
Audit results influence governance activities.
These characteristics improve both compliance and oversight.
Inspection-Readiness Checklist (Concise and Operational)
Use this checklist to prepare sponsor and vendor documentation ahead of an inspection. The checklist is intentionally concise; each item should map to a specific evidence file or system location.
Documentation and Records - Current contract, SLA and statement of work (signed) for each critical vendor (file: VendorName_Contract_signed.pdf). - Latest vendor risk assessment and audit schedule (file: VendorName_RiskAssessment_YYYYMMDD.pdf). - Most recent audit report(s) and related annexes (file: VendorName_AuditReport_YYYYMMDD.pdf). - CAPA register entries related to vendor findings with supporting evidence attachments (file: VendorName_CAPARegister.xlsx + attachments folder). - Relevant SOPs and process maps (vendor and sponsor-facing) in effect at time of audit (file: SOP_VendorCaseProcessing_vX.pdf). - System validation/qualification documents for critical PV systems used by vendor (IQ/OQ/PQ/Validation Summary). - Data transfer agreements and evidence of secure data transfers (SFTP logs, access control lists). - Records of data integrity checks, system access logs and audit trails for safety databases. - Case examples sampled during the audit with redaction applied as required (case lists and demonstrated reconciliation to database entries).
People and Training - Organisational charts showing PV-responsible roles and escalation paths. - Training matrices and selected training records for staff performing PV tasks (completed training evidence + dates). - Declarations of independence for vendor QA/auditor involved in the audit.
Governance and Oversight - Minutes of key governance meetings where vendor performance was discussed (quality committee, PV oversight) including attendees (file: PVOversight_Minutes_YYYYMMDD.pdf). - KPI trending reports and supplier scorecards for the audit period. - Management escalation emails/records for Critical/Major findings with confirmation of QPPV notification.
Evidence Management and Accessibility - Centralised evidence repository location and access instructions for inspectors (portal details, redaction policy). - Evidence index or audit evidence tracker mapping each finding to supporting documents and storage location. - Retention policy showing record retention periods and legal/regulatory basis.
Operational Readiness - Contact list for vendor audit lead, vendor QA and sponsor audit lead (with availability during inspection). - A prepared narrative and timeline for any open Critical/Major CAPAs (containment, RCA, implementation, verification). - Pre-prepared redacted evidence packages for rapid inspector review, with clear labelling and cross-references.
Practical implementation suggestions: - Maintain an "inspection pack" for each critical vendor updated quarterly. - Ensure evidence is accessible electronically and preserved in read-only format to prevent post-inspection remediation claims. - Test retrieval of key documents monthly as part of oversight KPIs.
Inspection relevance: - Inspectors often request a chronological timeline from issue identification to closure; maintain an event timeline for significant findings. - Be prepared to show how CAPAs were prioritised, implemented and verified, including who reviewed and approved closure.
Standard Audit Report Template — Operational and Inspection-Focused
Below is a standardised audit report structure designed for pharmacovigilance vendor audits. The template includes the core content plus guidance on classification, timelines, required evidence and follow-up expectations that inspectors typically review.
Report header - Report title: Vendor Audit Report — [Vendor Name] - Report ID: [VendorName_Audit_YYYYMMDD_vX] - Sponsor: [Company Name] (QPPV: [Name]) - Vendor: [Vendor Name], site/location - Audit period/dates: [On-site dates / remote dates] - Lead auditor(s): [Name(s), function] - Audit team: [Members and competencies] - Distribution list: [Sponsor QA, QPPV, PV Head, Vendor QA, Business Owner, Legal if applicable]
Executive summary (<= 1 page) - Purpose and scope (concise) - Summary of key findings and their potential impact on patient safety/regulatory compliance - Overall audit rating (if used) and immediate actions required
Background and context - Vendor activities covered (e.g., ICSRs, literature screening, database hosting) - Contractual obligations relevant to scope (reference to agreement sections) - Relevant previous audit history and CAPA status - Risk categorisation of vendor at time of audit
Audit scope and methodology - Detailed scope (processes, systems, time periods) - Sampling methodology (number and selection criteria for cases, documents) - Documentation reviewed (list) - Interviews conducted (roles) - Tools used (checklists, observation forms)
Findings (structured and traceable) - For each finding include: - Finding ID (e.g., FIND-001) - Title - Classification (Critical/Major/Minor/Observation) - Location (process/system) - Description (what was observed; include evidence references) - Impact/risk assessment (brief) - Regulatory relevance (cite GVP/ICH/PIC/S where applicable) - Root cause hypothesis (if identified during audit) - Immediate / containment actions taken (if any) - Recommended actions (sponsor & vendor responsibilities)
Example entry: - FIND-001 — Delayed reporting of serious ICSRs - Classification: Critical - Location: Case processing queue, Vendor X - Description: 4/20 sampled serious ICSRs exceeded regulatory reporting timelines; system timestamps indicate case creation delayed. - Evidence: Sample case IDs (redacted), system logs (evidence ref 3), KPI report period Q1. - Impact: Potential patient safety and regulatory reporting non-compliance. - Regulation: GVP I; national reporting timelines. - Immediate action: Vendor quarantined backlog; sponsor notified (timestamped email). - Recommended action: RCA, immediate rework of backlog, review of intake SOP, QA verification and escalation to QPPV.
Findings summary table - Provide a concise table listing all findings with classification, owner and target CAPA date.
Required evidence and attachments (indexed) - Numbered attachments such as procedure extracts, sample case exports (redacted), system validation reports, training records, governance minutes. Provide an evidence index mapping each finding to attachment IDs.
Vendor response (if included) - Vendor's preliminary responses, proposed CAPAs and target dates. Note whether the vendor accepted the finding and action plan.
Sponsor assessment and actions - Sponsor QA review comments, acceptance of vendor CAPA, sponsor-led actions (e.g., additional monitoring, change in oversight frequency), and escalation to QPPV if applicable.
CAPA expectations and timelines (per classification) - Critical: containment documented within 24–72 hours; preliminary CAPA within 5 working days; full CAPA within 10 working days; closure & effectiveness verification within 30–60 days. Sponsor QA verification required; consider regulatory notification. - Major: CAPA plan within 10–15 working days; target closure 30–90 days; sponsor QA verification on completion. - Minor: CAPA plan within 20–30 working days; target closure 60–120 days; closure confirmed by vendor QA and sponsor sample verification. - Observation: Vendor to consider and integrate within improvement cycles; inclusion in next audit evidenced.
Verification and evidence requirements (per classification) - Critical: RCA report, containment logs, list of affected cases and reprocessing results, SOPs revised, training records demonstrating competence, system change validation, QA verification letter, minutes of management escalation. - Major: RCA, action plan, revised documents, training completion evidence, sample evidence of corrected processing, change control records and verification. - Minor: Documented corrective actions, training sign-off, sample checks show correction. - Observation: Management response or acknowledgement; improvement plan entry.
Follow-up and monitoring expectations - CAPA owner and sponsor oversight responsibilities - Effectiveness check dates to be scheduled (e.g., 30, 90, 180 days) with predefined metrics - Reporting cadence to sponsor PV oversight committee - Conditions for re-audit (e.g., re-audit required if Critical or repeated Major findings)
Conclusions and overall assessment - Concise statement on overall vendor control and residual risk - Recommendations for governance and schedule adjustments
Signatures and approvals - Lead auditor, sponsor QA reviewer, vendor QA acknowledgement, QPPV (if escalated) - Date of final report issuance
Annexes - Detailed checklist used - Full list of documents reviewed - Interview lists - Complete evidence index with file names and locations - Vendor corrective action plan (if received)
Practical implementation details for the report: - Issue a draft report within 10–15 working days of audit completion; allow vendor 10 working days to comment on factual accuracy. - Final report to be issued within 20–30 calendar days, including sponsor QA review and acceptance of vendor responses. - Use consistent formatting and a standard numbering convention for findings and attachments to facilitate inspection requests.
Inspection relevance: - Inspectors will examine the audit report structure, the link between findings and evidence, the timeliness and adequacy of CAPAs and the governance approvals. Well-structured reports reduce inspector queries and demonstrate control.
Governance and Escalation — Operational Expectations
- Define and document escalation thresholds: e.g., Critical findings automatically escalate to QPPV and Chief Compliance Officer within 24 hours; Major findings escalated to PV Head and Sponsor QA within 3 business days.
- Establish a PV Oversight Committee with defined membership (QPPV, Head of PV, QA Head, Procurement, Business Owner) meeting monthly or quarterly depending on vendor risk to review open CAPAs, trending and audit outcomes.
- Ensure that CAPA closure criteria require documented evidence of effectiveness and QA sign-off. Do not accept mere completion statements without objective evidence.
- Maintain a vendor performance dashboard including audit status, open/overdue CAPAs, KPI trends and risk score that supports governance decisions and inspection queries.
Key Takeaways
- Vendor audits provide independent verification of outsourced activities.
- Audit planning should be risk-based.
- Audit scope should reflect vendor activities and risk profile.
- Findings should lead to meaningful CAPAs and improvement.
- Follow-up activities are essential.
- Audit programmes support vendor oversight, inspection readiness and QPPV governance.
- Mature organisations use audits to strengthen systems rather than merely identify deficiencies.
- Incorporating a concise inspection-readiness checklist and a standardised audit report template improves audit quality, regulatory transparency and inspection preparedness.
References
- EMA Good Pharmacovigilance Practices (GVP) Module I – Pharmacovigilance Systems and Their Quality Systems.
- EMA Good Pharmacovigilance Practices (GVP) Module III – Pharmacovigilance Inspections.
- EMA Good Pharmacovigilance Practices (GVP) Module II – Pharmacovigilance System Master File.
- Regulation (EC) No 726/2004.
- Directive 2001/83/EC.
- Commission Implementing Regulation (EU) No 520/2012.
- ICH Q9 Quality Risk Management.
- PIC/S Guidance on Pharmacovigilance Inspections.
- Relevant regional legislation and guidance (as applicable per operating jurisdiction).